Dear Sven Am 07.05.13 13:47, schrieb Sven Van Caekenberghe:
On 07 May 2013, at 12:11, Marcus Denker <marcus.denker@inria.fr> wrote:
On May 7, 2013, at 12:06 PM, Camillo Bruni <camillobruni@gmail.com> wrote:
On 2013-05-07, at 11:15, Sven Van Caekenberghe <sven@stfx.eu> wrote:
On 07 May 2013, at 07:42, no-reply@ci.inria.fr wrote:
https://ci.inria.fr/pharo/job/Pharo-3.0-Update-Step-2-Validation/./label=win...
2 regressions found. Zinc.Tests.ZnClientTests.testRedirect Zinc.Tests.ZnClientTests.testRedirectDontFollow
These tests assume that http://www.pharo-project.org is a redirect. The website seems to behave a bit different now, I'll have to investigate. Any pointers as to what changed are welcome.
I think we updated the DNS to point directly to the same server as pharo.org.
But this was the same like before⦠they both point to cmsbox, who does whatever they do.
Indeed, whatever they do, it is very weird.
[...]
In other words we get a 403, Forbidden. Browsers seem fine. Only Zinc fails. Note how only 3 headers are sent, this is almost minimal. Let's seen what happens if we pretend to be curl:
[...]
How about that !? I would expected a friendlier response from a CMS written in Pharo ;-)
I CC'd cmsbox & Christoph, maybe he can ask his tech team if they can explain this.
We are sorry that our server configuration had unforeseen side effects. Your observations are absolutely correct: our security officer blocked these requests based on IP and user agent string which is the reason why your tests now fail. First of all: we did not know what the purpose of these requests was. We just saw regularly strange hits within a small time range like "/page-that-will-never-ever-exist/?C=M%3BO%3DD" that we could not explain and which were never announced to us. As the Cmsbox of pharo-project.org was aggressively attacked (thousands of requests) last weekend by robots and even killed several times (out of memory) we were heavily restricting what comes through to the Cmsbox and what not. And these requests did not make it... sorry. But: please note that our infrastructure is not a playground. It is a productive environment for hundreds of websites which is the reason that we became very careful about security attacks. Using mod_security for Apache and other tools we are restricting access to cmsbox websites as there are a lot of unwanted visitors out there. Besides, a Pharo image cannot handle unlimited requests and we cannot load balancing to infinity. Therefore we focus to keep the existing resources free for real website visitors and some legitimate (and unfortunately rarely intelligent) robots. Of course we are willing to discuss solutions which fulfil some criteria such as a rate limit (max. request count per minute) and we will allow these requests to get through again. Do you have propositions how this could be integrated within this test suite? Or could not be a separate Pharo image on a testing environment we would provide be a better solution for such a test suite? Thank you for your understanding! Chris -- Christoph Wysseier netstyle.ch GmbH, CEO