| 07:05 | <matjas> | “Like all of the WHATWG specs, it initially looks like the aftermath of a cluster bomb in a scrabble factory, but once you’ve read it for the 5th time and wiped the blood from your eyes, it’s actually pretty interesting” — http://www.html5rocks.com/en/tutorials/speed/script-loading/ |
| 09:31 | <zcorpan> | so webkit/blink allow insertRule() for cross-origin style sheets but gecko/presto don't |
| 09:33 | <zcorpan> | ie10 allows it as well |
| 10:03 | <Ms2ger> | MikeSmit1, ping |
| 10:05 | <MikeSmit1> | yup |
| 10:06 | <Ms2ger> | Something fun about the list archives |
| 10:06 | <Ms2ger> | I hit [ respond to this message ] on http://lists.w3.org/Archives/Public/public-webappsec-testsuite/2013Jun/0001.html |
| 10:07 | MikeSmith | looks |
| 10:07 | <jgraham> | MikeSmith: (btw, while you are here, were you going to send Rebecca a list of tests for TestTWF Tokyo?) |
| 10:07 | <jgraham> | *test areas |
| 10:07 | <Ms2ger> | But the In reply to link at http://lists.w3.org/Archives/Public/public-test-infra/2013AprJun/0095.html managed to end up broken |
| 10:07 | <Ms2ger> | It links to http://www.w3.org/mid/%3C370C9BEB4DD6154FA963E2F79ADC6F2E27AEAD7F⊙Dcec%3E |
| 10:07 | <Ms2ger> | Where it should be http://www.w3.org/mid/370C9BEB4DD6154FA963E2F79ADC6F2E27AEAD7F⊙Dcec (without the <>) |
| 10:08 | <MikeSmith> | jgraham: didn't yet but if you have time, can you? |
| 10:08 | <MikeSmith> | I'm on my mobile |
| 10:08 | <jgraham> | MikeSmith: I guess I can try and do that. I don't remember what we decided though |
| 10:08 | <Ms2ger> | Logs are your friend :) |
| 10:09 | <jgraham> | Indeed :) |
| 10:09 | <Ms2ger> | And hallvors had some stuff too in #webapps |
| 10:09 | <MikeSmith> | w didn't decide -- just bounced a few ideas |
| 10:09 | <MikeSmith> | hallvors mentioned xhr tests |
| 10:10 | <Ms2ger> | (Somehow I suspect none of them will want to review the webappsec PRs) |
| 10:11 | <MikeSmith> | Ms2ger: no clue on that archive weirdness. I'll alert the systems team |
| 10:11 | <hallvors> | I sent Rebecca an E-mail and she replied. |
| 10:11 | <Ms2ger> | MikeSmith, ta |
| 10:12 | <Ms2ger> | I asked her about box-sizing on IRC; she wanted to hear what fantasai thought, but fantasai didn't want to think |
| 10:12 | <odinho> | WAT! |
| 10:12 | <hallvors> | They have a list of stuff to focus on (some of it especially related to Japanese issues, which seems like a good idea) |
| 10:12 | <odinho> | I wanted help with CORS tests :P -- And EventSource-fix for mozilla. |
| 10:12 | <Ms2ger> | hallvors, marquee? ;) |
| 10:12 | <jgraham> | hallvors: You already sent an XHR list? |
| 10:13 | <jgraham> | https://etherpad.mozilla.org/VkkW1BU54C |
| 10:13 | <jgraham> | Did we decide form elements? |
| 10:13 | <hallvors> | I just point out the list I already put in a comment on https://github.com/w3c/web-platform-tests/pull/128 |
| 10:18 | <jgraham> | I feel like suggesting applet is too cruel |
| 10:25 | <jgraham> | hallvors: Do you have any recollection of whether the script scheduling tests tested XML? |
| 10:25 | <jgraham> | http://www.whatwg.org/specs/web-apps/current-work/multipage/the-xhtml-syntax.html#parsing-xhtml-documents "When an XML parser" |
| 10:27 | <Ms2ger> | You were talking cruel? |
| 10:27 | jgraham | is sad that those are still under old-tests |
| 10:27 | <jgraham> | Well it's less bad than the HTML case :) |
| 10:30 | <jgraham> | The amount of stuff still under old-tests/submissions/ is sadness |
| 10:30 | <Ms2ger> | Getting Aryeh's reflection tests merged would be nice too... |
| 10:33 | <Ms2ger> | Lovely: https://www.w3.org/Bugs/Public/show_bug.cgi?id=22291 |
| 10:34 | jgraham | is glad that bz doesn't want to be a supervillan |
| 10:35 | <jgraham> | Also, getting people to address issues on existing pull requests/reviews is a good idea |
| 10:40 | <Ms2ger> | Is there any way to get a diff that doesn't cut off all the text in https://github.com/dontcallmedom/web-platform-tests/commit/1179ab58108d5fb7e0eb2ef55fe90b2401be9cb3 ? |
| 10:44 | <odinho> | 12:37 < jgraham> Also, getting people to address issues on existing pull requests/reviews is a good idea <<--- this what I wanted with the CORS tests |
| 11:11 | <jgraham> | Hmm, there are some nicy easy looking reviews for anyone that knows CSP |
| 11:15 | <jgraham> | I wonder if we have a policy about UA-specific cruft in tests |
| 11:16 | <jgraham> | abarth has submitted CSP tests with X-WebKit headers in |
| 11:18 | <Ms2ger> | I believe the policy is "no" |
| 11:18 | <jgraham> | So do I |
| 11:18 | <jgraham> | Not sure we have it written down anywhere though |
| 11:19 | <jochen__> | that might just an oversight |
| 11:19 | <jochen__> | given that blink wants to go prefix-less nowadays |
| 11:30 | <hsivonen> | Are there now X-WebKit headers??? |
| 11:30 | <hsivonen> | or just did you just mean WebKit-specific X-Foo? |
| 11:32 | <jgraham> | Well |
| 11:33 | <jgraham> | The test has Content-Security-Policy, X-Content-Security-Policy and X-WebKit-Content-Security-Policy |
| 11:33 | <jgraham> | Oh, sorry |
| 11:33 | <hsivonen> | sadness |
| 11:33 | <jgraham> | X-WebKit-CSP |
| 12:16 | <hallvors> | jgraham: sorry, didn't see question "Do you have any recollection of whether the script scheduling tests tested XML?" before |
| 12:16 | <hallvors> | but I'm pretty sure the answer is "no, they don't" |
| 12:37 | <hsivonen> | what should my schedule expactiations be for the CSS WG processing http://lists.w3.org/Archives/Public/public-css-testsuite/2012Dec/0000.html and publishing a revised version of the CSS 2.1 test suite? |
| 12:37 | <hsivonen> | *expectations |
| 12:37 | <hsivonen> | it's harmful to have outdated test suites out there |
| 12:41 | <Ms2ger> | TabAtkins, ^ |
| 12:42 | <hsivonen> | some more UTF-16 uselessness: https://bugzilla.mozilla.org/show_bug.cgi?id=879753 |
| 13:52 | <GPHemsley> | Safari is the most frustrating browser when it comes to unsupported MIME types... |
| 13:53 | <GPHemsley> | it just downloads everything it doesn't recognize automatically |
| 13:53 | <GPHemsley> | so now I have a whole downloads folder of Safari cruft |
| 13:53 | <GPHemsley> | all without my consent |
| 13:55 | <zewt> | asking for user consent seems to be a dying idea |
| 13:55 | <zewt> | remember when things would actually ask permission before updating? yeah i can hardly remember that myself |
| 14:01 | <GPHemsley> | oh cynicism |
| 14:16 | <zewt> | skype nagged me to update (to a version I knew had an unusable UI) over and over, then it just updated without asking |
| 14:18 | <GPHemsley> | ah |
| 14:18 | <GPHemsley> | but I'm more concerned about Safari downloading something that |
| 14:18 | <GPHemsley> | 's potentially unsafe |
| 16:06 | <GPHemsley> | Hixie_: Oh, one reason that the context change is more than editorial is because it should refer directly to mimesniff |
| 16:07 | <GPHemsley> | http://mimesniff.spec.whatwg.org/#context-specific-sniffing |
| 16:07 | <GPHemsley> | (I'm fleshing these out) |
| 16:12 | <Hixie_> | what difference will it require in implementations? |
| 16:13 | <GPHemsley> | assuming the implementations are not already interoperable, it will require them to become so |
| 16:13 | <GPHemsley> | in terms of when/what/how to sniff in each context |
| 16:13 | <GPHemsley> | because the contexts do not all have the same rules |
| 16:13 | <GPHemsley> | (or won't, when they're actually written) |
| 16:13 | <Hixie_> | doesn't HTML already explicitly say which rules to use when? |
| 16:16 | <GPHemsley> | only for certain contexts |
| 16:16 | <GPHemsley> | not for others |
| 16:16 | <GPHemsley> | but I still concede this is still ~90% editorial |
| 16:17 | <Hixie_> | which doesn't it specify it for? |
| 16:19 | <GPHemsley> | I think browsing, image, and audio/video specified |
| 16:19 | <GPHemsley> | but the rest aren't, AFAIK |
| 16:19 | <Hixie_> | do any of the rest do any sniffing at all? |
| 16:20 | <GPHemsley> | perhaps not yet, but they should—these are edge cases that perhaps people haven't considered yet |
| 16:20 | <Hixie_> | i'm pretty sure i've considered them :-) |
| 16:21 | <GPHemsley> | there are a number of issues on file with Mozilla about how to sniff in the style context that I'm tackling now |
| 16:22 | <Hixie_> | style context? |
| 16:22 | <GPHemsley> | see, you have no definition ;) |
| 16:23 | <GPHemsley> | the "style context" is whenever a stylesheet is loaded |
| 16:23 | <GPHemsley> | in HTML, that's mostly <link rel=stylesheet> |
| 16:23 | <Hixie_> | that shouldn't sniff at all |
| 16:23 | <GPHemsley> | in CSS, it's @import |
| 16:23 | <GPHemsley> | what happens if the resource is served without a Content-Type header? |
| 16:23 | <Hixie_> | treat as text/css |
| 16:24 | <GPHemsley> | that has security implications |
| 16:24 | <GPHemsley> | if an untagged HTML file is treated as text/css, unexpected things can happen |
| 16:24 | <Hixie_> | like what? |
| 16:25 | <Hixie_> | you can't read the DOM unless it's same origin |
| 16:25 | <GPHemsley> | https://bugzilla.mozilla.org/show_bug.cgi?id=560388 |
| 16:25 | <GPHemsley> | https://bugzilla.mozilla.org/show_bug.cgi?id=562377 |
| 16:26 | <Hixie_> | that first one seems to apply to all "contexts", it's just about distinguishing bogus from missing |
| 16:27 | <Hixie_> | that second one seems to just say that i was wrong about the no-type case |
| 16:27 | <Hixie_> | it should be treated as bogus |
| 16:28 | <GPHemsley> | sorry, was trying to have two conversations at once |
| 16:29 | <GPHemsley> | apparently that's hard |
| 16:29 | <GPHemsley> | anyway |
| 16:29 | <GPHemsley> | the bottom line with 562377 was that the style context can't use the same sniffing rules as the browsing context |
| 16:30 | <GPHemsley> | err |
| 16:30 | <GPHemsley> | 560388 |
| 16:30 | <Hixie_> | seems like the conclusion is that it shouldn't sniff at all |
| 16:30 | <Hixie_> | it definitely shouldn't use the same sniffing rules as the browsing context, nobody is suggesting it should, as far as i can tell |
| 16:30 | <Hixie_> | certainly not the spec, right? |
| 16:31 | <GPHemsley> | well, that's the part I'm trying to clarify |
| 16:31 | <GPHemsley> | with these contexts |
| 16:31 | <GPHemsley> | but no, I don't think HTML says it should |
| 16:31 | <GPHemsley> | mimesniff used to seem that way, though |
| 16:31 | <GPHemsley> | which is the part I'm working on now |
| 16:35 | <Hixie_> | i think if mimesniff just provides algorithms, and doesn't invoke any of them itself, it's quite sufficient |
| 16:39 | <GPHemsley> | Hixie_: I'm not sure what you mean; what is it currently invoking (or what do you think I want it to be invoking)? |
| 16:39 | <Hixie_> | i'm not saying it is or will |
| 16:39 | <Hixie_> | was just being complete in my description |
| 16:39 | <GPHemsley> | ah |
| 16:39 | <GPHemsley> | well, yeah, then I agree |
| 16:40 | <Hixie_> | this context stuff seems like a very convoluted way of doing it :-) |
| 16:40 | <GPHemsley> | really? convoluted how? I thought it makes things clearer |
| 16:40 | <GPHemsley> | (and annevk seemed to like it) |
| 16:41 | <Hixie_> | "run sniffing algorithm #3 for resource /x/, to obtain sniffed type /y/" seems nice and trivial and doesn't involve having to define contexts |
| 16:41 | <GPHemsley> | if you always fetch through the lens of a context, you never have confusion as to which set of rules to follow |
| 16:41 | <GPHemsley> | I mean, it's just a name |
| 16:41 | <Hixie_> | if you always just call the sniffing algorithm directly there's no confusion either :-) |
| 16:42 | <Hixie_> | what is confused today? |
| 16:42 | <GPHemsley> | this modularizes the sniffing algorithm so that you don't have one big complex thing |
| 16:42 | <Hixie_> | we don't have one big complex thing today either do we? |
| 16:42 | <GPHemsley> | like I said, prior to the context stuff I added today, it seemed like the MIME sniffing algorithm should be used everywhere |
| 16:43 | <GPHemsley> | which, as written, is/was not appropriate |
| 16:43 | <Hixie_> | oh well i'm fine with adding non-normative text that says "don't use this unless you have a legacy compat reason to do so" |
| 16:43 | <Hixie_> | i kinda assumed we already had that |
| 16:43 | <GPHemsley> | I think a lot of this issue is bogged down by legacy terminology |
| 16:44 | <GPHemsley> | in that "sniffing" is a bit of a misnomer for my current vision of this spec |
| 16:44 | <Hixie_> | (re "anne likes it" -- anne has a habit of making these same kinds of "simplifications" that require tons of changes to html too :-P) |
| 16:44 | <GPHemsley> | my current vision of this spec is to describe how to determine the MIME type of a file—whether through sniffing or otherwise |
| 16:45 | <Hixie_> | the mime type of a file without sniffing is trivial |
| 16:45 | <Hixie_> | it's the value of the Content-Type header |
| 16:46 | <GPHemsley> | it's not always that simple |
| 16:46 | <GPHemsley> | but I feel like we could argue this around in circles |
| 16:47 | <GPHemsley> | this is mostly about terminological homogenization |
| 16:48 | <GPHemsley> | Hixie_: Did you see this? http://lists.w3.org/Archives/Public/public-webappsec/2013Jun/0027.html |
| 16:49 | <GPHemsley> | also, the "How to use a context" set of steps on the wiki page? |
| 16:49 | <Hixie_> | i don't object to stuff like this in general |
| 16:49 | <GPHemsley> | I can't tell if you're objecting to the idea, or just the cost-benefit ratio of adding it to the HTML spec :P |
| 16:50 | <Hixie_> | i just object to it while we have higher-priority stuff missing or broken |
| 16:50 | <Hixie_> | the latter |
| 16:50 | <Hixie_> | i'm not updating the HTML spec for this kind of stuff any time soon (like, coming year, probably) |
| 16:50 | <Hixie_> | i've got a ton of higher-priority stuff |
| 16:50 | <GPHemsley> | that's fine |
| 16:50 | <Hixie_> | same with anne's fetch spec, that's why he has the "legacy" algorithms |
| 16:51 | <Hixie_> | or as i call them, "the algorithms" :-P |
| 16:51 | <GPHemsley> | heh |
| 16:52 | <Hixie_> | btw if you want something more important to do, the editing spec is in dire need of an editor |
| 16:52 | <Hixie_> | since aryeh has had to move on to other things |
| 16:52 | <GPHemsley> | link? |
| 16:52 | <Ms2ger> | https://dvcs.w3.org/hg/editing |
| 16:52 | <Hixie_> | ...ms2ger beat me to it |
| 16:52 | <GPHemsley> | ugh, you want me to work with the W3C? >_> |
| 16:53 | <Ms2ger> | It's a CG |
| 16:53 | <Hixie_> | it's in a cg, like html |
| 16:53 | <Hixie_> | if you want to merge it with the whatwg cg that's fine by me |
| 16:53 | <GPHemsley> | I have to admit, I've remained relatively ignorant of the bureaucracy over there |
| 16:54 | <Hixie_> | there's basically none for cgs |
| 16:54 | <Hixie_> | if you did want to work on that spec and wanted to skip all bureaucracy, you could just take it and make it a whatwg spec the same way as the mime sniffing spec |
| 16:54 | <Hixie_> | since it's an open license spec |
| 16:55 | <Hixie_> | and the old version is not maintained |
| 16:56 | <GPHemsley> | FFR, this was more the type of I link I was interested in: https://dvcs.w3.org/hg/editing/raw-file/tip/editing.html |
| 16:56 | <GPHemsley> | ;) |
| 16:56 | <GPHemsley> | but apparently the styling is broken |
| 16:56 | <Hixie_> | oh i thought that's what Ms2ger gave, my bad :-) |
| 16:59 | <GPHemsley> | does the whatwg stylesheet prevent cross-site loading? |
| 16:59 | <Hixie_> | not in theory, but there might be cross-protocol blocking going on |
| 16:59 | <Hixie_> | whatwg is not https: |
| 17:00 | <GPHemsley> | ah |
| 17:00 | <GPHemsley> | indeed, Aurora is giving me a half shield |
| 17:01 | <GPHemsley> | there we go |
| 17:01 | <GPHemsley> | "This is an open issue. All issues other than this one are non-normative. " |
| 17:01 | <GPHemsley> | somewhat paradoxical |
| 17:04 | <GPHemsley> | oh, this would take me ages to understand... |
| 17:04 | <Hixie_> | that's how you know it's important :-P |
| 17:04 | <GPHemsley> | I've never even *used* HTML editing |
| 17:06 | <GPHemsley> | you'd _definitely_ have to pay me to work on this :P |
| 17:06 | <Hixie_> | hah |
| 17:09 | <Ms2ger> | That's how he sucked in Aryeh, and we know how that ended... |
| 17:12 | <GPHemsley> | I mean, I'm generous with my time, but I'm not *this* generous ;) |
| 17:12 | <Hixie_> | :-) |
| 17:13 | <GPHemsley> | I do have bills that I need paid |
| 20:14 | <GPHemsley> | It's always fun to see which sites are parsing Accept-Language incorrectly |
| 20:15 | <GPHemsley> | and by "fun" I mean "sad" |
| 20:21 | <Hixie_> | isn't it harder to find some parsing it right? :-) |
| 20:32 | <GPHemsley> | probably... but there's a clear distinction between parsing it wrong and not parsing it right, and my particular Accept-Language settings bring that to light |
| 22:47 | <Hixie_> | https://www.w3.org/Bugs/Public/show_bug.cgi?id=21964 ?? |
| 22:49 | <miketaylr> | O_o |
| 22:54 | <Hixie_> | heycam|away: ping |
| 22:55 | <Hixie_> | heycam|away: ping https://www.w3.org/Bugs/Public/show_bug.cgi?id=21946 |
| 23:16 | <zewt> | stream of consciousness bugs |
| 23:22 | <zewt> | what the heck does "font security" even mean? are people encoding passwords as character widths in fonts? heh |
| 23:23 | <zewt> | seems like a bizarre pair of words |
| 23:30 | <Hixie_> | zewt: i guess you could get Roboto 3.0's font metrics out of Google before Google announced it, or something |
| 23:30 | <Hixie_> | (i've no idea if Roboto has a 3.0 or if it's even a Google-made font) |
| 23:37 | GPHemsley | wishes Hixie_ would clarify his commit messages a bit |
| 23:39 | <Hixie_> | which ones? |
| 23:39 | <Hixie_> | most of hte patches seems self-explanatory |
| 23:40 | <Hixie_> | r7941's was a mistake (s/Example/Allow/) |
| 23:40 | <Hixie_> | but for the editorial ones... |
| 23:40 | <Hixie_> | they're fixing editorial problems |
| 23:40 | <GPHemsley> | the patches come after the click ;) |
| 23:40 | <Hixie_> | what more can i say |
| 23:41 | <GPHemsley> | "clarification" and "match reality" are rather non-descript when all you see is the commit message |
| 23:42 | <GPHemsley> | just saying |
| 23:42 | <Hixie_> | what would you suggest instead? |
| 23:42 | <Hixie_> | i'm open to making it better, but i'm not sure how to |
| 23:42 | <Hixie_> | short of just putting the diff in the commit message... |
| 23:43 | <GPHemsley> | just add a few words about which small part of the humongous spec you're changing ;) |
| 23:43 | <GPHemsley> | keep in mind that many people (or just me?) follow along via Twitter |
| 23:43 | <GPHemsley> | you gotta click the link to see the patch |
| 23:44 | <GPHemsley> | "clarify X" or "make Y match reality" would be a major improvement |
| 23:44 | <Hixie_> | i don't know what section it is half the time |
| 23:44 | <GPHemsley> | heh |
| 23:44 | <Hixie_> | but i'll try to include a vague idea of what topic it might be :-) |
| 23:45 | <Hixie_> | at least for the non-editorial or "clarification" ones |
| 23:45 | <GPHemsley> | much appreciated |
| 23:47 | <GPHemsley> | because otherwise it turns out like this: http://imgur.com/IU2z3bz |
| 23:49 | <Hixie_> | yeah, well, given the kind of crap i've been fixing today, that's about right :-) |
| 23:52 | <GPHemsley> | :P |