-
sarang
OK, so about the proposed security page
-
sarang
Hopefully someone better at design/UI/UX than I can help me understand the optimal layout for this
-
sarang
Separately from this, I can make a PR that at least includes the CLSAG blag post... when could this get built/deployed?
-
sarang
I need to coordinate this datetime with OSTIF, who will also be posting the report on their own site
-
sarang
As a courtesy we'll be releasing the report simultaneously-ish
-
niocbrrrrrr
UI/UX?
-
niocbrrrrrr
where is rehrar?
-
sarang
To be clear, let's separate the two projects here
-
sarang
Project A is posting the CLSAG blag post and the audit report in a PR
-
sarang
Project B is developing a security page with VRP information and all audit report links
-
sarang
Project A needs to be coordinated with OSTIF, who say they would be ready as soon as Friday
-
sarang
Project B can be done at our convenience
-
sarang
(but after Project A)
-
sarang
If I make a PR for Project A, how soon could it be deployed and live?
-
ErCiccione[m]1
sarang: Feel free to make a PR for A. There seems to be no clear agreement about how to show B. I can review A as soon as you make the PR, then we can ask luigi to merge and we should be able to deploy it soon after if necessary.
-
ErCiccione[m]1
About B. I think we can make a simple page divided in two, with a VRP section and an audits section, then we can replace the "Vulnerability Response" link at the top of Getmionero with a link to this new page. We should also link to it from the MRL page
-
ErCiccione[m]1
I can work at B as soon as we decide what we want to do.
-
ErCiccione[m]1
.merge+ #1104
-
xmr-pr
Added
-
xmr-pr
erciccione opened issue #1107: Create "I2P" Moneropedia entry
-
xmr-pr
-
xmr-pr
erciccione opened pull request #1108: README: updates + add 'Reviewing Process' section
-
xmr-pr
-
sarang
Yo
-
sarang
What is the best location in the source tree for the audit PDF, with the understanding that more will be added eventually?
-
sarang
And what's the proper way to reference these relative URLs in the markdown source for the blag post?
-
sarang
e.g. MRL papers live in `resources/research-lab/pubs`, but those don't need to be linked in posts
-
ErCiccione
I would say resources/research-lab/audits
-
sarang
OK; how to reference properly from the post markdown?
-
sarang
will a simple `href` to `/resources/research-lab/audits/...` work as expected?
-
sarang
Or is there some magic incantation required because of the underlying engine
-
ErCiccione
downloads.getmonero.org could be required. Let me double check, i'm not sure.
-
sarang
Of course we can move things around later if needed, but that sounds more annoying
-
sarang
ok
-
sarang
Putting them in the blag assets directory would work nicely, but that doesn't seem like the best place
-
ErCiccione
yeah use simply `/resources/research-lab/audits/...`
-
sarang
neat ok
-
sarang
Almost finished with the PR, but I can't push it until the release date
-
sarang
(since the report can't be made public until then)
-
sarang
Does Friday (tomorrow) work for that?
-
ErCiccione
No problem for me
-
sarang
Great
-
sarang
I'll coordinate that with OSTIF
-
ErCiccione
Sure, jsut ping me if i'm needed
-
ErCiccione
about downloads.getmonero i got confused, that's the separed box we use for downloads
-
sarang
Many thanks
-
ErCiccione
(downloads of the binaries only)
-
ErCiccione
np
-
sarang
I do remember there maybe being something about those existing PDFs being hosted on downloads, but perhaps I'm misremembering
-
ErCiccione
yeah there used to be some more stuff there IIRC, that's what confused me
-
sarang
Ah ok, but that got moved?
-
sarang
No reason to be hosting small stuff like PDFs off downloads
-
ErCiccione
The PDFs of the MRL are and were hosted in the research-lab/pubs folder AFAIK
-
sarang
Yeah, but for some reason I recall someone like fluffy or binary mentioning something about there being some odd way they were hosted
-
ErCiccione
oh yes we have two PDFs in downloads
-
sarang
ok
-
sarang
Doesn't seem to be of consequence here, at least
-
ErCiccione
the "annotated whitepaper" and "Brandon Goodell's Whitepaper Review"
-
sarang
got it
-
ErCiccione
I think fluffypony made a list of what's in the 'downloads' box some time ago, would be good to have that list handy. i'll check
-
sarang
Would it make sense to move those PDFs?
-
sarang
Just for consistency, and to make any changes easier in the future
-
sarang
(not for this PR, of course, but a separate one)
-
ErCiccione
I think so. I would be ok with that.
-
sarang
Does this mean the PDFs aren't even in the `monero-site` source tree?
-
sarang
(If not, that's a perfect reason to add them!)
-
ErCiccione
correct
-
ErCiccione
If nobody has nothing against it, i will add them both to /resources/research-lab
-
fluffypony
actually what might be good is to turn the downloads site into a Git repo
-
fluffypony
I'll work on that today
-
sarang
Still seems optimal to have research-related PDFs in a single location
-
sarang
IMO
-
sarang
In particular, it means they're in a repo that is managed by non-core people
-
ErCiccione
good indeed.
-
sarang
(even though core does the builds)
-
ErCiccione
Still seems optimal to have research-related PDFs in a single location <- yes i would move it either way
-
fluffypony
re: PDFs, we don't have any PDFs on downloads.getmonero.org except the CN whitepaper and the annotated CN whitepaper
-
fluffypony
and that's more for historical reasons
-
fluffypony
oh I see ErCiccione mentioned that already
-
sarang
Yeah, that's what we were referrring to
-
sarang
Moving those to the same place as the other MRL stuff seems reasonable
-
sarang
Of course, the newer preprints are just links to IACR anyway
-
fluffypony
yeah we can just have a redirect
-
ErCiccione
I'm making the PR right now (writing the commit description as we speak) let me know if we shouldn't do it for some reason
-
sarang
but we had also discussed making the source to those IACR preprints available on a repo too (they're on my github right now)
-
ErCiccione
do it = move the PDFs to the monero-site repo
-
sarang
(and noting that those IACR links are external)
-
ErCiccione
sarang: i think we can move forward with that once those sources are uploaded somewhere
-
ErCiccione
we were talking about a dedicated repo in monero-project IIRC
-
sarang
Yeah, it's on my list but I just haven't done it yet
-
sarang
that's on me
-
sarang
I still like the idea of keeping the IACR PDFs as external links
-
ErCiccione
Alright, no worries. It's not prioritary
-
sarang
as long as they're marked and the source is available (which it is)
-
ErCiccione
yeah specifying when links are external is in my TODO
-
sarang
"IACR could be compromised" is a good counterargument, but seems unlikely
-
sarang
and I don't think there exists a site that is viewed regularly by more security experts =p
-
fluffypony
-
fluffypony
created the repo
-
sarang
that was fast
-
sarang
Oh, it's empty
-
sarang
nvm
-
sarang
not that fast =p
-
fluffypony
lol
-
ErCiccione
-
selsta
fluffypony: what is supposed to be in monero-downloads repo?
-
fluffypony
the downloads
-
fluffypony
once I've finished scp'ing them from the server
-
dsc_
:O
-
selsta
but not CLI / GUI bins I guess?
-
selsta
else the repo will be huge
-
fluffypony
yes all of the bins
-
fluffypony
that's fine
-
fluffypony
it's not like everyone needs to grab the repo
-
sarang
What's the advantage of having them in this repo?
-
sarang
As opposed to packaged on the `monero` repo?
-
sarang
Maybe I'm missing the point
-
fluffypony
sarang: we don't want the monero repo to be like 500mb
-
selsta
if github allows that I guess
-
dsc_
git lfs
-
fluffypony
and it allows us to deploy changes a lot more easily
-
sarang
ah ok
-
selsta
isn’t the bin archive over 10gb?
-
selsta
> Repositories have a hard size limit of 100GB.
-
selsta
ok should work
-
fluffypony
selsta: I'm excluding blockchain.raw
-
fluffypony
since that's created by the daemon
-
fluffypony
also I just noticed that it's not been auto-updated since we moved to the new environment, cc pigeons
-
ErCiccione
.merge+ #993
-
xmr-pr
Added
-
sarang
fluffypony: so the point is that the actual server will have its content deployed right from the repo?
-
sarang
Instead of via some other manual method?
-
fluffypony
it's still manual deployment from that repo
-
fluffypony
in case the repo is compromised
-
fluffypony
but yes
-
xmr-pr
erciccione opened pull request #1109: Add whitepaper_annotated.pdf and whitepaper_review.pdf
-
xmr-pr
-
sarang
Right, not _totally_ automated!
-
sarang
But from the repo at least
-
ErCiccione
-
ErCiccione
A lot of nice stuff
-
ErCiccione
aaand automod blocked it
-
fluffypony
hah I take back my totally optimistic size estimate - it's more like 19gb excluding blockchain.raw
-
fluffypony
still, that comes in well under GitHub and Backhub's limits
-
selsta
fluffypony: the problem is that everyone who wants to add some PDF to the repo has to download 19GB if I understand this correctly
-
selsta
not sure if ideal
-
fluffypony
selsta: you can ask someone else to add it, or add it through GitHub's web interface
-
selsta
oki
-
fluffypony
it also makes it easier to deploy a new Monero website if anything happens
-
ErCiccione
selsta: PDFs shouldn't be uploaded there
-
ErCiccione
we are moving the only two which were there to monero-site
-
fluffypony
should we even bother redirecting or just leave them in that repo for historical backlinks to it?
-
fluffypony
any old backlinks aren't going to change now
-
ErCiccione
I would just leave them there
-
fluffypony
kk
-
ErCiccione
I just submitted the updated sitemap to google. I think they would re-crawl it anyway, but a little ping won't hurt
-
fluffypony
also one nice thing about this repo is that I just noticed nobody did the source tarball
-
fluffypony
for the 0.16.* releases
-
ErCiccione
We also don't give a link to download it from the website AFAIK.
-
fluffypony
yes but it's used by the auto-updater
-
fluffypony
if you build from source
-
dsc_
fluffypony: hi sir do you happen to have a box for `xmr-pr`
-
dsc_
our beloved bot needs a stable dedicated home
-
fluffypony
sure - pigeons should have a spot on one of the Monero servers
-
fluffypony
he just lacks time atm
-
fluffypony
I'll chat to him when he's around
-
dsc_
oh ok cool no hurries
-
selsta
fluffypony: the problem is
-
selsta
gui does not allow building without git repo
-
selsta
soo the sourceball is useless
-
selsta
until we fix this we didn’t create one
-
fluffypony
ok but for CLI?
-
selsta
yea CLI should work
-
selsta
I can do one for CLI in the future
-
sarang
Small PR to fix a link on an old post:
monero-project/monero-site #1110
-
sarang
Looks like the preview build doesn't show it since it's an older post, so I cannot test it
-
ErCiccione
Seems straightforward.
-
ErCiccione
.merge+ #1110
-
xmr-pr
Added
-
sarang
sweet
-
sarang
-
sarang
Anyone else get this weird link spacing?
-
sarang
-
selsta
try to clean cache
-
selsta
-
selsta
looks good here
-
» sarang withdraws his comment :D
-
sarang
Can the HTTP responses for these pages specify cache expirations?
-
fluffypony
yes
-
fluffypony
but it's in our best interest for them to be long-lived (in general)
-
ErCiccione
Isn't there a middle way? i think most of the people don't even know how to flush their cache and they end up weirded out by some broken css or something else
-
selsta
having a shorter expiration time for the css would make sense
-
selsta
other resources like images can stay the same