Project

General

Profile

Activity

From 05/08/2019 to 06/06/2019

06/06/2019

06:35 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> In regard to data type serialization, I wonder if the 4GL uses the same approach as for raw-trans...
Igor Skornyakov
06:21 PM Feature #3810: SECURITY-POLICY and other security features
In regard to data type serialization, I wonder if the 4GL uses the same approach as for raw-transfer (see #3549). I ... Greg Shah
05:22 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
.> No, don't use Java serialization since it won't be compatible. I understand there are some unkn...
Igor Skornyakov
05:04 PM Feature #3810: SECURITY-POLICY and other security features
> I'm not sure that we have to replace the current implementation of the :EXPORT-PRINCIPAL based on Java serializatio... Greg Shah
04:37 PM Feature #3810: SECURITY-POLICY and other security features
I've analyzed the result of the @CLIENT-PRINCIPAL:EXPORT-PRINCIPAL@ method.
It seems that it is a byte array started...
Igor Skornyakov
01:02 PM Feature #3753: I18N additions
Greg Shah wrote:
> TODO: Stanislav notes the following:
>
> > When a longchar/clob value is assigned to a clob fi...
Eric Faulhaber
12:51 PM Feature #3753: I18N additions
TODO: Stanislav notes the following:
> When a longchar/clob value is assigned to a clob field, it is implicitly co...
Greg Shah
12:52 PM Feature #3855: implement equivalent support for REST (classic appserver, PASOE REST and WEB trans...
I like the plan. From a 4GL development perspective, it seems quite easy. I wonder why the wizard is needed. Greg Shah
11:13 AM Feature #3855: implement equivalent support for REST (classic appserver, PASOE REST and WEB trans...
The high-level approach for implementing the REST services is this:
# use the .paar resources to identify any expose...
Constantin Asofiei
11:11 AM Feature #3855: implement equivalent support for REST (classic appserver, PASOE REST and WEB trans...
Marian, another issue: the @.paar@ archive has a @mapping.xml@ file with some info like:... Constantin Asofiei
10:52 AM Feature #3855: implement equivalent support for REST (classic appserver, PASOE REST and WEB trans...
Marian, I need an example of a @openapi.openedge.export@ annotation for internal procedures, functions (if is possibl... Constantin Asofiei

06/05/2019

03:24 PM Feature #3810: SECURITY-POLICY and other security features
Remaining features:... Igor Skornyakov
02:59 PM Feature #3810: SECURITY-POLICY and other security features
Please summarize what features/work remains TODO (it seems like most things, if not all of them, are complete). Greg Shah
02:29 PM Feature #3810: SECURITY-POLICY and other security features
Branch 3810b rebased to the trunk. Started regression testing Igor Skornyakov

06/04/2019

03:55 PM Feature #3810: SECURITY-POLICY and other security features
1. Implemented and tested conversion and runtime support for:... Igor Skornyakov
01:51 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Yes, errors reported by @ant javadoc@ related to the code you wrote for this task.
Go...
Igor Skornyakov
01:46 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Constantin, do you mean errors reported by @javadoc@ ...
Yes, errors reported by @ant java...
Constantin Asofiei
01:45 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Igor, before your next merge, please check/fix javadoc issues related to the 3810 code. ...
Igor Skornyakov
01:15 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> MESASGE statement with more complex code (which, as in this case, may raise an ERROR), i...
Igor Skornyakov
01:11 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Constantin Asofiei wrote:
> > Please post a 4GL snippet so I can better understand this.
...
Constantin Asofiei
01:07 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Please post a 4GL snippet so I can better understand this.
Well, for example, if the ...
Igor Skornyakov
12:57 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Thank you Constantin. My question was about FWD Java code. I use 4GL test which redirects o...
Constantin Asofiei
12:55 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Is an ERROR condition raised? Are you trying to fix an argument validation error?
>
>...
Igor Skornyakov
12:49 PM Feature #3810: SECURITY-POLICY and other security features
On 6/4/19 7:45 PM, ias wrote:
> Gentlemen,
> Which is the right ErrorManager method to be invoked to show error mes...
Constantin Asofiei
11:10 AM Feature #3810: SECURITY-POLICY and other security features
Igor, before your next merge, please check/fix javadoc issues related to the 3810 code. Thanks. Constantin Asofiei
12:55 PM Feature #3751: implement support for OO 4GL and structured error handling
This is related to #3809, notes 107-111.
Yes, I unified the options (APPEND/BY-REF/BY-VAL/BIND) for both param defs ...
Ovidiu Maxiniuc
12:32 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg Shah wrote:
> When it makes sense, we should rationalize these to have a @PARAMETER@ parent. This is not too ha...
Constantin Asofiei
12:30 PM Feature #3751: implement support for OO 4GL and structured error handling
When it makes sense, we should rationalize these to have a @PARAMETER@ parent. This is not too hard in the parser. T... Greg Shah
12:03 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg Shah wrote:
> > The problem here is that the arguments are not parented by a PARAMETER node, they are on the sa...
Constantin Asofiei
12:01 PM Feature #3751: implement support for OO 4GL and structured error handling
> The problem here is that the arguments are not parented by a PARAMETER node, they are on the same level. And NO-ERR... Greg Shah
11:41 AM Feature #3751: implement support for OO 4GL and structured error handling
Greg Shah wrote:
> 1. In @collect_parameters.rules@, the change for @DYNAMIC-NEW ... NO-ERROR@ just ignores the keyw...
Constantin Asofiei
11:33 AM Feature #3751: implement support for OO 4GL and structured error handling
3751b was merged to trunk rev 11313 and archived. Constantin Asofiei
10:00 AM Feature #3751: implement support for OO 4GL and structured error handling
Are you ready to rebase and merge? I'd like to pick up your changes in 4069a. Greg Shah

06/03/2019

07:26 PM Feature #3751: implement support for OO 4GL and structured error handling
Code Review Task Branch 3751b Revision 11315
I'm fine with the changes. Do you want to merge to trunk?
Please ...
Greg Shah
07:13 PM Feature #3751: implement support for OO 4GL and structured error handling
Code Review Task Branvch 3751a Revision 11334
I realize this is happening after the merge to trunk. Sorry about t...
Greg Shah
02:53 AM Feature #3751: implement support for OO 4GL and structured error handling
3751b 11315 passed runtime/conversion testing. Constantin Asofiei

05/31/2019

06:00 PM Feature #3751: implement support for OO 4GL and structured error handling
Please review 3751b rev 11315. Constantin Asofiei
05:13 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> Search @rules/@ for @"wrap"@ to see how this annotation will cause unknown value and primitive ty...
Igor Skornyakov
05:12 PM Feature #3810: SECURITY-POLICY and other security features
Search @rules/@ for @"wrap"@ to see how this annotation will cause unknown value and primitive types to be emitted as... Greg Shah
05:00 PM Feature #3810: SECURITY-POLICY and other security features
How can we force generation @new character()@ as the method argument value if a @?@ literal is provided in the 4GL co... Igor Skornyakov
12:44 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> It supports the @_user@ table. I assume that is what is meant.
Yes, I meant @_user@. Thank you.
Igor Skornyakov
12:39 PM Feature #3810: SECURITY-POLICY and other security features
It supports the @_user@ table. I assume that is what is meant. Greg Shah
12:22 PM Feature #3810: SECURITY-POLICY and other security features
Does FWD have standard support for a @user@ table?
Thank you.
Igor Skornyakov
08:05 AM Feature #3810: SECURITY-POLICY and other security features
Marian Edu wrote:
> If you don't have the database created you can do it from there as well - in data dictionary cre...
Igor Skornyakov
07:57 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Marian,
> My question was about Progress. How can a create and populate @fwd@ database u...
Marian Edu
07:41 AM Feature #3810: SECURITY-POLICY and other security features
Marian Edu wrote:
> Hi Igor,
>
> not sure how you can do that in FWD but in Progress we have a 'fwd' database wh...
Igor Skornyakov
07:38 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Marian,
> The @get-client.p@ test fails in my runs. I understand that this happens because...
Marian Edu
06:15 AM Feature #3810: SECURITY-POLICY and other security features
Marian,
The @get-client.p@ test fails in my runs. I understand that this happens because I've not provided the "fwd"...
Igor Skornyakov
03:00 AM Feature #3810: SECURITY-POLICY and other security features
Marian Edu wrote:
> Test cases for security related functions are in 'security' folder in bazaar repository, below w...
Igor Skornyakov
02:23 AM Feature #3810: SECURITY-POLICY and other security features
Test cases for security related functions are in 'security' folder in bazaar repository, below what we've tested so f... Marian Edu

05/30/2019

02:41 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> There are some weird errors in your setup, for example @server.log@ has:
> ...
Ovidiu Maxiniuc
02:41 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> It seems that we have no support for the @CLIENT-PRINCIPAL:INITIALIZE@ method. There is no ...
Greg Shah
02:38 PM Feature #3810: SECURITY-POLICY and other security features
It seems that we have no support for the @CLIENT-PRINCIPAL:INITIALIZE@ method. There is no even @INITIALIZE@ keyword ... Igor Skornyakov
02:32 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> That is PASSED since that test is expected to fail.
Oh, sorry - I remember that this test is s...
Igor Skornyakov
02:23 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> After the re-indexing of DBs the only test which fails in multiple runs of the ChUI regress...
Greg Shah
01:30 PM Feature #3810: SECURITY-POLICY and other security features
Marian,
Can you please help me to create a simple test with the session registry which supports authentication (I un...
Igor Skornyakov
12:34 PM Feature #3810: SECURITY-POLICY and other security features
After the re-indexing of DBs the only test which fails in multiple runs of the ChUI regression testing of the 3810b i... Igor Skornyakov

05/29/2019

04:51 PM Feature #3751: implement support for OO 4GL and structured error handling
Created task branch 3751b from trunk rev 11311.
Rev 11312 contains some OO changes and a batch of misc changes.
Constantin Asofiei
11:44 AM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> No problem. Just use @gso_20090909_2_29_3a_master@ and @rfq_20090909_2_29_3a_master@ as...
Igor Skornyakov
11:42 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Now it is *much* better - only 3 @tc@ tests failed (@tc_po_item_018@, @tc_job_002@, @tc_job...
Constantin Asofiei
11:36 AM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> There are some weird errors in your setup, for example @server.log@ has:
> * run the ma...
Igor Skornyakov
05:10 AM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> If the latest 3810b is OK (and it contains your correct changes), I think we will go ahe...
Igor Skornyakov
04:57 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> It seems that 3810b is in a normal shape. When I try to rebase it I get "No revisions to re...
Constantin Asofiei
04:50 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Constantin Asofiei wrote:
> > Igor Skornyakov wrote:
> > > Thank you Constantin, but I di...
Igor Skornyakov
04:17 AM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> There are some weird errors in your setup, for example @server.log@ has:
> [...]
> whi...
Igor Skornyakov
04:14 AM Feature #3810: SECURITY-POLICY and other security features
There are some weird errors in your setup, for example @server.log@ has:... Constantin Asofiei
03:48 AM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Igor Skornyakov wrote:
> > Thank you Constantin, but I did not mean to update the trunk...
Igor Skornyakov
03:43 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Thank you Constantin, but I did not mean to update the trunk as it was not approved.
Sorr...
Constantin Asofiei
03:38 AM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Your rebase is wrong... what commands did you use?
>
> The steps are these:
> * chec...
Igor Skornyakov

05/28/2019

04:51 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Branch 3810b rebased to the trunk rev. 11311.
> Committed revision 11327
Your rebase is w...
Constantin Asofiei
04:11 PM Feature #3810: SECURITY-POLICY and other security features
Finished implementation and testing runtime support for all new attributes and methods of the @CLIENT-PRINCIPAL@ exce... Igor Skornyakov
09:38 AM Feature #3810: SECURITY-POLICY and other security features
Branch 3810b rebased to the trunk rev. 11311.
Committed revision 11327
Igor Skornyakov

05/27/2019

05:28 PM Feature #3810: SECURITY-POLICY and other security features
Added runtime support for the @CLIENT-PRINCIPAL@ new attributes. SEAL() method updated to use these attributes.
Br...
Igor Skornyakov
12:52 PM Feature #3810: SECURITY-POLICY and other security features
In multiple runs of the regression testing, the following tests consistently fail:... Igor Skornyakov
01:33 PM Feature #3751: implement support for OO 4GL and structured error handling
3751a was merged to trunk rev 11311 and was archived. This commit includes mostly changes related to #3751 and other... Constantin Asofiei
08:48 AM Feature #3751: implement support for OO 4GL and structured error handling
Constantin Asofiei wrote:
> Greg, a quick question: shouldn't the extent property have a no-arg getter? Currently w...
Greg Shah

05/24/2019

05:20 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg, a quick question: shouldn't the extent property have a no-arg getter? Currently we emit only an indexed getter. Constantin Asofiei
02:13 PM Feature #3751: implement support for OO 4GL and structured error handling
Another OO-related issue: OO properties when they act as OUTPUT arguments for 4GL statements, like @IMPORT@ or @RUN P... Constantin Asofiei
04:48 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Constantin Asofiei wrote:
> > What is the new name? @clientPrincipal.p@? Rename it to i.e....
Igor Skornyakov
04:40 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> What is the new name? @clientPrincipal.p@? Rename it to i.e. @clientp.p@ and make sure t...
Igor Skornyakov
04:33 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Igor Skornyakov wrote:
> > Constantin Asofiei wrote:
> > > Is your program named @client_...
Constantin Asofiei
04:27 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Constantin Asofiei wrote:
> > Is your program named @client_principal.p@? If so, please r...
Igor Skornyakov
04:21 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Is your program named @client_principal.p@? If so, please rename the program to somethi...
Igor Skornyakov
04:13 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> It seems that we have a problem with the conversion of the @CREATE CLIENT-PRINCIPAL@ state...
Constantin Asofiei
04:12 PM Feature #3810: SECURITY-POLICY and other security features
It seems that we have a problem with the conversion of the @CREATE CLIENT-PRINCIPAL@ statement. The following snippe... Igor Skornyakov
02:35 PM Feature #3810: SECURITY-POLICY and other security features
Marian, thank you for the notes.
I believe that at the external interface for RAW and MEMPTR, we do implement as...
Greg Shah
06:59 AM Feature #3810: SECURITY-POLICY and other security features
Marian Edu wrote:
> I probably don't know the details here but in 4GL there is a difference between memptr and raw v...
Igor Skornyakov
05:03 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Greg Shah wrote:
> > No, I mean that it is intentional that we are ignoring the @len@ in t...
Marian Edu
09:31 AM Feature #3753: I18N additions
> Are 4GL system error messages translated, too? (we have been assuming YES, that CURRENT-LANGUAGE will select differ... Greg Shah

05/23/2019

03:37 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> No, I mean that it is intentional that we are ignoring the @len@ in the @memptr.writeByteRange()@...
Igor Skornyakov
03:07 PM Feature #3810: SECURITY-POLICY and other security features
> The len parameter was added because of the ArrayIndexBoundException was thrown in some cases which runs OK with 4GL... Greg Shah
02:39 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> Code Review Task Branch 3810b Revision 11318
>
> 1. In @AuditPolicyManager@, @SecurityOps@, @S...
Igor Skornyakov
01:55 PM Feature #3810: SECURITY-POLICY and other security features
I've just noticed that albeit 4GL validation of the value of the @SECURITY-POLICY:SYMMETRIC-ENCRYPTION-ALGORITHM@ is ... Igor Skornyakov
11:47 AM Feature #3810: SECURITY-POLICY and other security features
Code Review Task Branch 3810b Revision 11318
1. In @AuditPolicyManager@, @SecurityOps@, @SecurityPolicyManager@, @...
Greg Shah
11:19 AM Feature #3753: I18N additions
TODO: We need to check the FWD runtime for references like this: @a_string.getBytes(Charset.forName("ISO-8859-1"))@ (... Greg Shah

05/22/2019

01:21 PM Feature #3810: SECURITY-POLICY and other security features
As we finished with cryptography may be it makes sense to merge 3810b and do the rest in the 3810c? Igor Skornyakov
01:04 PM Feature #3810: SECURITY-POLICY and other security features
Well done! Greg Shah
12:47 PM Feature #3810: SECURITY-POLICY and other security features
Well, the @AUDIT-POLICY:ENCRYPT-AUDIT-MAC-KEY@ algorithm is indeed *very* simple.
1. Using a long string of identica...
Igor Skornyakov
10:58 AM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> > The P2J tail is different from one generated by 4GL. This affects 24- and 32-bytes keys with MD...
Igor Skornyakov
10:30 AM Feature #3810: SECURITY-POLICY and other security features
> The P2J tail is different from one generated by 4GL. This affects 24- and 32-bytes keys with MD5 and SHA-1. I do no... Greg Shah
10:26 AM Feature #3810: SECURITY-POLICY and other security features
> > I've added the tail generation for the GENERATE-PBE-KEY. The tail is generated using the first 8 bytes of the PBK... Igor Skornyakov
10:14 AM Feature #3810: SECURITY-POLICY and other security features
> I've added the tail generation for the GENERATE-PBE-KEY. The tail is generated using the first 8 bytes of the PBKDF... Greg Shah

05/21/2019

01:27 PM Feature #3810: SECURITY-POLICY and other security features
Well, it seems that @ENCRYPT-AUDIT-MAC-KEY@ is something *very* simple. A quote from https://community.progress.com/c... Igor Skornyakov
11:30 AM Feature #3810: SECURITY-POLICY and other security features
Do we need to provide binary compatibility for the @AUDIT-POLICY:ENCRYPT-AUDIT-MAC-KEY@ (see note #96)? Or it is suff... Igor Skornyakov
08:41 AM Feature #3810: SECURITY-POLICY and other security features
I've added the tail generation for the @GENERATE-PBE-KEY@. The tail is generated using the first 8 bytes of the PBKDF... Igor Skornyakov
07:40 AM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> At this point we are trying to finish this work permanently instead of deferring it until later. ...
Igor Skornyakov
07:33 AM Feature #3810: SECURITY-POLICY and other security features
> Maybe it makes sense to discuss it with our customers?
At this point we are trying to finish this work permanent...
Greg Shah
07:31 AM Feature #3810: SECURITY-POLICY and other security features
So far I cannot understand what @AUDIT-POLICY:ENCRYPT-AUDIT-MAC-KEY@ actually does. What I see is that it returns a h... Igor Skornyakov
05:38 AM Feature #3810: SECURITY-POLICY and other security features
As I see on the Internet people do discuss the problem of decrypting data encrypted by 4GL using other programming la... Igor Skornyakov
05:09 AM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> On the one hand, I can see the value in generating a more cryptographically correct key instead o...
Igor Skornyakov
04:58 AM Feature #3810: SECURITY-POLICY and other security features
> Does it makes sense to try supporting binary compatibility for such "corner cases"?
On the one hand, I can see t...
Greg Shah
01:56 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> The situation with @GENERATE-PBE-KEY@ looks a little bit strange. Formally it "Generates a ...
Marian Edu

05/20/2019

06:09 PM Feature #3810: SECURITY-POLICY and other security features
The situation with @GENERATE-PBE-KEY@ looks a little bit strange. Formally it "Generates a password-based encryption ... Igor Skornyakov
04:17 PM Feature #3810: SECURITY-POLICY and other security features
Added runtime support for @GENERATE-PBE-KEY@ and @GENERATE-PBE-SALT@. Branch 3810b rev.113361.
Added @uast/securit...
Igor Skornyakov
03:42 PM Feature #3810: SECURITY-POLICY and other security features
If we want to generate a 24-byte key using MD5 the 4GL @GENERATE-PBE-KEY@ generated 24 bytes where the first 16 bytes... Igor Skornyakov
02:52 PM Feature #3810: SECURITY-POLICY and other security features
Well, I will run these tests but at this moment they add nothing to my test. In addition, my test generates a detaile... Igor Skornyakov
02:37 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> I'm not referencing the @testcases/uast/security/@. This is a different "Testcases Project":/pro...
Igor Skornyakov
02:21 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Greg Shah wrote:
> > Igor: Have you tried running the testcases mentioned in #3810-42? Th...
Greg Shah
02:18 PM Feature #3810: SECURITY-POLICY and other security features
I've implemented runtime support for @GENERATE-PBE-KEY@. In most cases, the results of running converted test are bin... Igor Skornyakov
02:10 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> Igor: Have you tried running the testcases mentioned in #3810-42? This is different from the @te...
Igor Skornyakov
01:55 PM Feature #3810: SECURITY-POLICY and other security features
Igor: Have you tried running the testcases mentioned in #3810-42? This is different from the @testcases/uast/@ direc... Greg Shah
01:47 PM Feature #3810: SECURITY-POLICY and other security features
The 4GL code fragment... Igor Skornyakov
11:03 AM Feature #3810: SECURITY-POLICY and other security features
Contrary to what I wrote in note #75, the length of the key generated by @GENERATE-PBE-KEY@ depends on the value of t... Igor Skornyakov
08:06 AM Feature #3810: SECURITY-POLICY and other security features
Marian Edu wrote:
> It turns out the handling of IV is implemented based on the cipher key length, if provided IV ra...
Igor Skornyakov
08:00 AM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> Please test a case where the encrypt and decrypt are done in separate programs. These separate p...
Igor Skornyakov
07:31 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Maybe it is the right time to add a full implementation of @GENERATE-PBE-KEY@/@GENERATE-PBE...
Greg Shah
07:28 AM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> It appears that 4GL ignores the "length" of @RAW@ when uses it as IV and, instead of paddin...
Marian Edu
07:17 AM Feature #3810: SECURITY-POLICY and other security features
> It appears that 4GL ignores the "length" of @RAW@ when uses it as IV and, instead of padding just uses what it find... Greg Shah
05:54 AM Feature #3810: SECURITY-POLICY and other security features
@GENERATE-PBE-KEY@ always generates 16 bytes using first 8 bytes of salt (if provided), presumably padding salt with ... Igor Skornyakov
04:24 AM Feature #3810: SECURITY-POLICY and other security features
Maybe it is the right time to add a full implementation of @GENERATE-PBE-KEY@/@GENERATE-PBE-SALT@/@MESSAGE-DIGEST@ as... Igor Skornyakov
02:36 PM Feature #3751: implement support for OO 4GL and structured error handling
Rebased 3751a from trunk rev 11310 - new rev 11328. Constantin Asofiei
02:22 PM Feature #3751: implement support for OO 4GL and structured error handling
Constantin Asofiei wrote:
> * dataset dereference, h-ds::bufname (Ovidiu, this will be part of #3908).
OK, I will...
Ovidiu Maxiniuc
02:16 PM Feature #3751: implement support for OO 4GL and structured error handling
3751a rev 11326 contains my latest changes. The @p2j/oo@ classes contains many Java sources for 4GL converted skelet... Constantin Asofiei

05/19/2019

05:13 AM Feature #3810: SECURITY-POLICY and other security features
Branch 3810b updated. Rev. 11315. The @uast/security/crypto.p@ test updated as well, revision 1854. Igor Skornyakov
04:31 AM Feature #3810: SECURITY-POLICY and other security features
It appears that 4GL ignores the "length" of @RAW@ when uses it as IV and, instead of padding just uses what it finds ... Igor Skornyakov

05/18/2019

03:23 PM Feature #3810: SECURITY-POLICY and other security features
Indeed, if the cipher requires IV but it is not provided, 4GL uses "all zeroes" IV. Thanks again to Constantin for a ... Igor Skornyakov
03:11 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> In 4GL, encrypt something without setting the IV and try decrypting it with a fully-zero...
Igor Skornyakov
03:04 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> I've found another issue. JCR doesn't support AES w/o IV. On encryption, it generates rando...
Constantin Asofiei
03:02 PM Feature #3810: SECURITY-POLICY and other security features
I've found another issue. JCR doesn't support AES w/o IV. On encryption, it generates random IV if not provided, and ... Igor Skornyakov

05/17/2019

04:56 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> The @SECURITY-POLICY:SYMMETRIC-ENCRYPTION-IV@ is a readable attribute. What is the value when th...
Igor Skornyakov
04:52 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> A simple test shows that if the IV length for the encrypt and decrypt differs, 4GL dec...
Igor Skornyakov
04:50 PM Feature #3810: SECURITY-POLICY and other security features
Since the encryption in the short IV case can still be decrypted, we can assume that the padding is not random.
Th...
Greg Shah
04:45 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> This assumption is wrong - we use padding with zeroes and get a different result. In my tes...
Constantin Asofiei
04:42 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> My assumption is that they would padded it with zeroes. Please test this in FWD and 4GL...
Igor Skornyakov
04:38 PM Feature #3810: SECURITY-POLICY and other security features
It is possible to try to figure what exactly 4GL does with short IVs using "brute force attack". If the algorithm is ... Igor Skornyakov
04:36 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Constantin Asofiei wrote:
> > OK, so the algorithm requires 16 bytes IV. How does 4GL beh...
Constantin Asofiei
04:32 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> OK, so the algorithm requires 16 bytes IV. How does 4GL behave if you give a shorter IV...
Igor Skornyakov
04:29 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Constantin Asofiei wrote:
> > You mean the IV's length is set to i.e 8 instead of 16, or t...
Constantin Asofiei
04:29 PM Feature #3810: SECURITY-POLICY and other security features
The fixes committed to the branch 3810b rev. 11313. Igor Skornyakov
04:28 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> You mean the IV's length is set to i.e 8 instead of 16, or that you set the length to 16...
Igor Skornyakov
04:19 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> The only difference is the result of the encryption when the provided IV is shorter than re...
Constantin Asofiei
04:18 PM Feature #3810: SECURITY-POLICY and other security features
The converted test passed completely. The only difference is the result of the encryption when the provided IV is sho... Igor Skornyakov
03:36 PM Feature #3810: SECURITY-POLICY and other security features
Both problems mentioned in note #53 were the result of appending zero when converting @Text@ to @raw@ in the Security... Igor Skornyakov
02:54 PM Feature #3810: SECURITY-POLICY and other security features
After fixing @BinaryData.setString()@ and @raw.writeByteRange@ the test is running.
I see some discrepancies at the ...
Igor Skornyakov
02:05 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> Go ahead as proposed. A @len == -1@ can mean copy to the end of the data.
OK, thank you.
Igor Skornyakov
02:02 PM Feature #3810: SECURITY-POLICY and other security features
Go ahead as proposed. A @len == -1@ can mean copy to the end of the data. Greg Shah
01:46 PM Feature #3810: SECURITY-POLICY and other security features
In addition. The additional @len@ parameter can be just ignored in @blob@ and @memptr@ which also implement @writeByt... Igor Skornyakov
01:34 PM Feature #3810: SECURITY-POLICY and other security features
When running converted @security/crypto.p@ (attached) I've got @ArrayIndexOutOfBoundsException@ in the converted frag... Igor Skornyakov
09:49 AM Feature #3810: SECURITY-POLICY and other security features
Added quotes from the mail conversation with Marian:
On 5/17/19 8:31 AM, Marian Edu wrote:
> Hi Igor,
> you're r...
Igor Skornyakov
03:38 PM Feature #2135: implement COPY-LOB language statement
Eric Faulhaber wrote:
> I'm implementing @SourceLob@ and @TargetLob@ c'tors which accept @Object@ to handle the POLY...
Eric Faulhaber
03:04 PM Feature #2135: implement COPY-LOB language statement
I'm implementing @SourceLob@ and @TargetLob@ c'tors which accept @Object@ to handle the POLY case. Eric Faulhaber
10:40 AM Feature #2135: implement COPY-LOB language statement
>> But your point is well taken that an extent can be passed at runtime, so do we need the signature to be Object for... Greg Shah
10:38 AM Feature #2135: implement COPY-LOB language statement
Constantin Asofiei wrote:
> Sorry, @b@ is a memptr, not a field.
Please post the full test case.
Eric Faulhaber
10:22 AM Feature #2135: implement COPY-LOB language statement
Greg Shah wrote:
> > Well, a POLY can always be an extent value (Java array)... that is another whole can of warms t...
Constantin Asofiei
10:18 AM Feature #2135: implement COPY-LOB language statement
> Well, a POLY can always be an extent value (Java array)... that is another whole can of warms to worry about.
It...
Greg Shah
09:59 AM Feature #2135: implement COPY-LOB language statement
Greg Shah wrote:
> All @POLY@ cases will be BDT, right? There is no other possibility for a field (@::@ or @BUFFER-...
Constantin Asofiei
09:55 AM Feature #2135: implement COPY-LOB language statement
Eric Faulhaber wrote:
> Constantin Asofiei wrote:
> > @b@ is @blob@ and @tt1.f1@ is char.
>
> So @b@ is a field?...
Constantin Asofiei
09:54 AM Feature #2135: implement COPY-LOB language statement
All @POLY@ cases will be BDT, right? There is no other possibility for a field (@::@ or @BUFFER-FIELD:BUFFER-VALUE()... Greg Shah
09:52 AM Feature #2135: implement COPY-LOB language statement
Constantin Asofiei wrote:
> @b@ is @blob@ and @tt1.f1@ is char.
So @b@ is a field? How is it defined?
Eric Faulhaber
09:46 AM Feature #2135: implement COPY-LOB language statement
Eric Faulhaber wrote:
> I did not actually add the casting in my recent work; this was there already with the old AP...
Constantin Asofiei
09:41 AM Feature #2135: implement COPY-LOB language statement
Eric Faulhaber wrote:
> Constantin Asofiei wrote:
> > The case is @copy-lob b to h:buffer-field(tt1.f1):buffer-valu...
Constantin Asofiei
09:41 AM Feature #2135: implement COPY-LOB language statement
I did not actually add the casting in my recent work; this was there already with the old API. What is the preferred ... Eric Faulhaber
09:39 AM Feature #2135: implement COPY-LOB language statement
Constantin Asofiei wrote:
> The case is @copy-lob b to h:buffer-field(tt1.f1):buffer-value.@
What are the data ty...
Eric Faulhaber
09:38 AM Feature #2135: implement COPY-LOB language statement
> And if is something other than LargeObject, runtime will fail badly.
True. It is my understanding that only CL...
Greg Shah
09:34 AM Feature #2135: implement COPY-LOB language statement
The case is @copy-lob b to h:buffer-field(tt1.f1):buffer-value.@
BTW, casting to LargeObject is not safe in the lo...
Constantin Asofiei
09:32 AM Feature #2135: implement COPY-LOB language statement
What is the test case? I tested with several forms of POLY. For example:... Eric Faulhaber
07:37 AM Feature #2135: implement COPY-LOB language statement
There is a case where the source or target in a COPY-LOB is POLY - in this case, we have a SourceLob(BaseDataType) at... Constantin Asofiei
01:52 PM Feature #3751: implement support for OO 4GL and structured error handling
Constantin Asofiei wrote:
> @USING path.to.empty.folder.*@ is valid in 4GL - but Java compiler complains that the pa...
Greg Shah
01:48 PM Feature #3751: implement support for OO 4GL and structured error handling
@USING path.to.empty.folder.*@ is valid in 4GL - but Java compiler complains that the package is empty, as there are ... Constantin Asofiei

05/16/2019

04:15 PM Feature #3751: implement support for OO 4GL and structured error handling
Constantin Asofiei wrote:
> Greg, in the @oo.json@ classes, do you have any other changes? Because some of them look...
Greg Shah
01:49 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg, in the @oo.json@ classes, do you have any other changes? Because some of them look that aren't implemented at a... Constantin Asofiei
10:37 AM Feature #3810: SECURITY-POLICY and other security features
> You force @raw-iv1@ to read @iv-len@ bytes but you have only the @"iv"@ text - and PUT-STRING will read past the @"... Igor Skornyakov
10:31 AM Feature #3810: SECURITY-POLICY and other security features
OK, the random bytes are originated by this:... Constantin Asofiei
10:25 AM Feature #3810: SECURITY-POLICY and other security features
Igor, you have a flow in your test:... Constantin Asofiei
10:13 AM Feature #3810: SECURITY-POLICY and other security features
> This sounds as if the current encryption/decryption just uses the current value of @SECURITY-POLICY:SYMMETRIC-ENCRY... Igor Skornyakov
10:09 AM Feature #3810: SECURITY-POLICY and other security features
> There is a strange behavior regarding IV. If the SECURITY-POLICY:SYMMETRIC-ENCRYPTION-IV attribute value was change... Greg Shah
09:56 AM Feature #3810: SECURITY-POLICY and other security features
Some 4GL testcases are being written to explore and demonstrate the features in this task. The testcases can be foun... Greg Shah
08:40 AM Feature #3810: SECURITY-POLICY and other security features
After thorough testing I've found the following:
1. In an OFB and CFB modes, and WITH RC4 ABL doesn't use padding, a...
Igor Skornyakov
09:21 AM Feature #3812: additions to SESSION system-handle
Status update for 4GL testcases development:
> Subject: Feature #3812 - additions to SESSION system-handle
> Date...
Greg Shah

05/15/2019

06:15 PM Feature #3751: implement support for OO 4GL and structured error handling
And something else to add: @@Override@ annotations are emitted for any method which has the @override@ option - this ... Constantin Asofiei
06:13 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg Shah wrote:
> I suspect the solution is something like this:
>
> 1. We need to process the builtin class ske...
Constantin Asofiei
09:44 PM Feature #3751: implement support for OO 4GL and structured error handling
> One other issue related to method overloading and overload suffix: when deriving from a builtin class (or even when... Greg Shah
04:18 PM Feature #3810: SECURITY-POLICY and other security features
Added full runtime support for @ENCRYPT@/@DECRYPT@ based on @SECURITY-POLICY@.
Branch 3810b rev.11311.
Igor Skornyakov

05/14/2019

07:00 PM Feature #3751: implement support for OO 4GL and structured error handling
Constantin Asofiei wrote:
> The previous way of keeping class definition dictionaries for each propath is completely...
Constantin Asofiei
06:56 PM Feature #3751: implement support for OO 4GL and structured error handling
The previous way of keeping class definition dictionaries for each propath is completely wrong, as it allows a @Class... Constantin Asofiei
04:26 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> We have noting so far, so we will need it implemented here. As far as in-memory that is OK, but ...
Igor Skornyakov
04:19 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Another question.
> Do we already have an implementation (stub) for the "ABL session domai...
Greg Shah
04:17 PM Feature #3810: SECURITY-POLICY and other security features
Igor Skornyakov wrote:
> Do I understand correctly that now it is time to provide "real" implementations of the @ENC...
Greg Shah
04:17 PM Feature #3810: SECURITY-POLICY and other security features
Another question.
Do we already have an implementation (stub) for the "ABL session domain registry" or it should be ...
Igor Skornyakov
04:11 PM Feature #3810: SECURITY-POLICY and other security features
Do I understand correctly that now it is time to provide "real" implementations of the @ENCRYPT@ and @DECRYPT@ functi... Igor Skornyakov
03:31 PM Feature #3810: SECURITY-POLICY and other security features
Added runtime support for @SECURITY-POLICY@ attributes.
Committed to the branch 3810b rev. 11310.
Synopsys:
If t...
Igor Skornyakov

05/13/2019

03:29 PM Feature #3751: implement support for OO 4GL and structured error handling
One other issue related to method overloading and overload suffix: when deriving from a builtin class (or even when y... Constantin Asofiei
09:23 AM Feature #3854: update appserver support with PASOE features
> From Marian:
>
> There is a bit of difference in how session managed/unmanaged modes works for the application se...
Greg Shah

05/11/2019

01:27 PM Feature #3751: implement support for OO 4GL and structured error handling
3751a was rebased from trunk rev 11308 - new rev 11312 Constantin Asofiei
07:15 AM Feature #3810: SECURITY-POLICY and other security features
Created task branch 3810b from trunk rev.11308 Igor Skornyakov
07:13 AM Feature #3810: SECURITY-POLICY and other security features
The branch 3810a was merged into the trunk rev. 11308 and archived. Igor Skornyakov
07:01 AM Feature #3810: SECURITY-POLICY and other security features
Rebased to the trunk rev. 11307. The new revision is 11318 Igor Skornyakov
06:39 AM Feature #3810: SECURITY-POLICY and other security features
Don'r forget to rebase. Constantin Asofiei
06:38 AM Feature #3810: SECURITY-POLICY and other security features
Hi Constantin. I will merge 3810a now. Igor Skornyakov
06:21 AM Feature #3810: SECURITY-POLICY and other security features
I've ran these and I think all are false-negatives - as they pass, except some with DB or other state dependencies.
...
Constantin Asofiei

05/10/2019

05:38 PM Feature #3810: SECURITY-POLICY and other security features
Try running some of these tests individually; there is a @run_single.sh@ and @majic_single.xml@ in @majic_baseline/@ ... Constantin Asofiei
10:49 AM Feature #3810: SECURITY-POLICY and other security features
The results of regression testing (2 runs)"
1. All @gso_ctrlc_tests@ passed in both runs.
2. All @gso_ctrlc_3way_te...
Igor Skornyakov
05:09 PM Feature #3753: I18N additions
Branch @3753a@ was merged to trunk as revno @11307@ then it was archived. Eugenie Lyzenko
05:00 PM Feature #3753: I18N additions
Greg Shah wrote:
> You can merge to trunk.
OK. Starting the merge process.
Eugenie Lyzenko
04:58 PM Feature #3753: I18N additions
You can merge to trunk. Greg Shah
04:43 PM Feature #3753: I18N additions
Testing completed. No regression has been found. The results: @3753a_11332_32748a0_20190510_evl.zip@.
So far the b...
Eugenie Lyzenko
02:17 PM Feature #3753: I18N additions
One main round of the runtime testing passed, started another one to exclude false failing tests. The @CTRL-C@ part i... Eugenie Lyzenko
08:11 PM Feature #3753: I18N additions
Task branch @3753a@ has been updated for review to revisions @11332@.
Fixed the regression in @character.java@ and...
Eugenie Lyzenko
03:22 PM Feature #3751: implement support for OO 4GL and structured error handling
I'm OK with the change, except that the manipulation of the type and text needs to use @saveAndReplaceTypeAndText()@ ... Greg Shah
02:51 PM Feature #3751: implement support for OO 4GL and structured error handling
Constantin Asofiei wrote:
> This is a valid class definition: @class "Imo.Windows.Support.LookupSupport"@. The clas...
Constantin Asofiei
02:32 PM Feature #3751: implement support for OO 4GL and structured error handling
This is a valid class definition: @class "Imo.Windows.Support.LookupSupport"@. The class name will be considered wit... Constantin Asofiei

05/09/2019

07:35 PM Feature #3753: I18N additions
Conversion passed, source are identical except one added new call to @setNoMap()@ which is OK considering @NO-MAP@ op... Eugenie Lyzenko
04:56 PM Feature #3753: I18N additions
> If the conversion will be OK can we include the changes for @4010@ and @4066@ into @3753a@ branch to speed up the f... Greg Shah
03:25 PM Feature #3753: I18N additions
Greg,
The conversion testing is in progress.
If the conversion will be OK can we include the changes for @4010@...
Eugenie Lyzenko
12:51 PM Feature #3753: I18N additions
I'm OK with changes. Minor fixing.
Task branch @3753a@ has been updated for review to revisions @11331@.
This i...
Eugenie Lyzenko
09:08 AM Feature #3753: I18N additions
Revision 11330 fixes a bug in my management of the caching flag. Greg Shah
06:47 AM Feature #3753: I18N additions
Code Review Task Branch 3753a Revision 11328
The changes are a good step.
I have reworked the code to make @S...
Greg Shah
05:45 PM Feature #3751: implement support for OO 4GL and structured error handling
There is an issue which has been in the back of my head and bugging me for a while: we solve method name collisions (... Constantin Asofiei
01:07 PM Feature #3751: implement support for OO 4GL and structured error handling
Code Review Task Branch 3751a Revision 11308
I'm good with the changes. There is quite a bit there!
The @Class...
Greg Shah
03:31 PM Feature #3810: SECURITY-POLICY and other security features
Regression testing started. Igor Skornyakov
03:21 PM Feature #3810: SECURITY-POLICY and other security features
Everything looks good. Please run ChUI regression testing (both conversion and runtime). Greg Shah
02:55 PM Feature #3810: SECURITY-POLICY and other security features
means that the converted code won't compile because there are no stubs.
Fixed
> 2. @AuditControlManager@ and @Aud...
Igor Skornyakov
02:20 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> Ovidiu: Please apply your patch from #4073 to 3810a.
Committed as revision 11316 in branch 3810a.
Ovidiu Maxiniuc
01:51 PM Feature #3810: SECURITY-POLICY and other security features
OK.
Ovidiu: Please apply your patch from #4073 to 3810a.
Igor: After your code review resolutions (and Ovidiu...
Greg Shah
01:40 PM Feature #3810: SECURITY-POLICY and other security features
Constantin Asofiei wrote:
> Also, considering #4073 issue: as HandleCommon was extended with new interfaces, the run...
Constantin Asofiei
01:39 PM Feature #3810: SECURITY-POLICY and other security features
Greg Shah wrote:
> Once the code review items are resolved, I think it makes sense to merge this branch into 3751a (...
Constantin Asofiei
01:23 PM Feature #3810: SECURITY-POLICY and other security features
Once the code review items are resolved, I think it makes sense to merge this branch into 3751a (and then dead-archiv... Greg Shah
01:21 PM Feature #3810: SECURITY-POLICY and other security features
Code Review Task Branch 3810a Revision 11314
Good update.
1. The gaps marking for the new items should have run...
Greg Shah

05/08/2019

05:57 PM Feature #3751: implement support for OO 4GL and structured error handling
Created task branch 3751a from trunk rev 11306.
Rev 11307 contains a batch of OO and some misc fixes. Any file wit...
Constantin Asofiei
05:45 PM Feature #3751: implement support for OO 4GL and structured error handling
> Greg, is there a reason why @fixups/stream_references.rules@ wouldn't be ran by @annotations_prep.rules@? The code ... Greg Shah
05:18 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg, is there a reason why @fixups/stream_references.rules@ wouldn't be ran by @annotations_prep.rules@? The code I ... Constantin Asofiei
04:17 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg Shah wrote:
> Your approach makes sense, though the "feature" does not make any sense. It is like an implicit ...
Constantin Asofiei
04:12 PM Feature #3751: implement support for OO 4GL and structured error handling
Your approach makes sense, though the "feature" does not make any sense. It is like an implicit static version of a ... Greg Shah
04:09 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg Shah wrote:
> Do you have an example to help me understand what you mean?
This class:...
Constantin Asofiei
04:02 PM Feature #3751: implement support for OO 4GL and structured error handling
> We need to 'hard-link' it to the proper method definition... and this can only be done by analysing the full table ... Greg Shah
03:59 PM Feature #3751: implement support for OO 4GL and structured error handling
> @DEF STREAM rpt.@ in a 4GL class can be used from both static and instance methods - and the static usage will have... Greg Shah
03:54 PM Feature #3751: implement support for OO 4GL and structured error handling
Greg Shah wrote:
> > So, as TABLE parameters allow collisions, and target resolution is done via the temp-table stru...
Constantin Asofiei
03:51 PM Feature #3751: implement support for OO 4GL and structured error handling
> So, as TABLE parameters allow collisions, and target resolution is done via the temp-table structure, in case of co... Greg Shah
05:20 AM Feature #3751: implement support for OO 4GL and structured error handling
@DEF STREAM rpt.@ in a 4GL class can be used from both static and instance methods - and the static usage will have a... Constantin Asofiei
 

Also available in: Atom