)]}'
{"id":"openstack%2Fbarbican~942016","triplet_id":"openstack%2Fbarbican~master~I2efaecee979b42a485f15438ad0c7fd5fce9071d","project":"openstack/barbican","branch":"master","attention_set":{},"removed_from_attention_set":{"8864":{"account":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"last_update":"2025-04-17 16:17:25.000000000","reason":"Change was abandoned"}},"hashtags":[],"change_id":"I2efaecee979b42a485f15438ad0c7fd5fce9071d","subject":"WIP: Make secrets owned by service if service token is sent","status":"ABANDONED","created":"2025-02-17 22:36:43.000000000","updated":"2025-04-17 16:17:25.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"3942f63c87df7bbb878cb100465a57007590b93f","_number":942016,"virtual_id_number":942016,"owner":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":-1,"date":"2025-02-17 23:22:51.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2025-02-17 23:22:51.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"056a278316520a60dc56685d66a3835574bf342c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"date":"2025-02-17 22:36:43.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"75d8b21349564d3467bf5255f149220b6bbd42ce","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-02-17 23:22:51.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/5cd6c77192c64d1da6ef15a755055446\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/9b50ce4f6b0a4c718589d0085aed1b84 : SUCCESS in 4m 24s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/d52efc1ee5c74cf38948913e14f1a4c1 : SUCCESS in 3m 47s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/bb414e02a10045de81cdb93fa69c69d4 : SUCCESS in 5m 18s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/24c235638c084f2ba9a4296f7abbbf86 : SUCCESS in 4m 49s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/be2c579dfd314d178719bbc28e1fc5dc : SUCCESS in 6m 05s\n- barbican-tox-functional https://zuul.opendev.org/t/openstack/build/7b3392df377d4cdf86d9dcb7cdabb6b7 : SUCCESS in 39m 12s\n- barbican-vault-tox-functional https://zuul.opendev.org/t/openstack/build/97e53a351b0c4af9a14c3a50601d90d5 : SUCCESS in 38m 38s (non-voting)\n- barbican-grenade https://zuul.opendev.org/t/openstack/build/3f003b3ab54c4206b8a9d403e1d3cc42 : FAILURE in 30m 26s (non-voting)\n- barbican-tempest-plugin-simple-crypto https://zuul.opendev.org/t/openstack/build/8508d5fc95f9419cbb213d217d6742b5 : SUCCESS in 35m 57s\n- barbican-tempest-plugin-simple-crypto-jammy https://zuul.opendev.org/t/openstack/build/8615a28806134af08210b8e1d55b428f : SUCCESS in 34m 44s\n- barbican-tempest-plugin-simple-crypto-secure-rbac https://zuul.opendev.org/t/openstack/build/06c918d8cb2a40bfaf98abe77bd28547 : SUCCESS in 21m 54s\n- barbican-tempest-plugin-simple-crypto-ipv6-only https://zuul.opendev.org/t/openstack/build/df2cdd6777dd49668786a5055c9131cc : SUCCESS in 38m 29s\n- barbican-tox-functional-fips https://zuul.opendev.org/t/openstack/build/ad2f27bee822430e92123a13f6e65f4b : SUCCESS in 40m 13s (non-voting)\n- octavia-v2-dsvm-tls-barbican https://zuul.opendev.org/t/openstack/build/17d469c47b964261bdc5f07b37a4f086 : FAILURE in 25m 21s\n- octavia-v2-dsvm-tls-barbican-secure-rbac https://zuul.opendev.org/t/openstack/build/db3a44794d3d46c2a1dd30fb45be90ca : FAILURE in 44m 09s","accounts_in_message":[],"_revision_number":1},{"id":"3942f63c87df7bbb878cb100465a57007590b93f","tag":"autogenerated:gerrit:abandon","author":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"date":"2025-04-17 16:17:25.000000000","message":"Abandoned\n\nChange of approach, Nova will just send its own service token as the user.","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"cebdbd0fc8ee43404f1f850a10b07650698f0174","revisions":{"cebdbd0fc8ee43404f1f850a10b07650698f0174":{"kind":"REWORK","_number":1,"created":"2025-02-17 22:36:43.000000000","uploader":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"ref":"refs/changes/16/942016/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/barbican","ref":"refs/changes/16/942016/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/barbican refs/changes/16/942016/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/barbican refs/changes/16/942016/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/barbican refs/changes/16/942016/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/barbican refs/changes/16/942016/1"}}},"commit":{"parents":[{"commit":"55c758eb7c119d043a3b1365f4864308e60dd978","subject":"Merge \"Remove unused versionbuild script\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/barbican/commit/55c758eb7c119d043a3b1365f4864308e60dd978"}]}],"author":{"name":"Artom Lifshitz","email":"alifshit@redhat.com","date":"2025-02-17 22:22:13.000000000","tz":0},"committer":{"name":"Artom Lifshitz","email":"alifshit@redhat.com","date":"2025-02-17 22:36:36.000000000","tz":0},"subject":"WIP: Make secrets owned by service if service token is sent","message":"WIP: Make secrets owned by service if service token is sent\n\nLive migration of vTPM instances is currently impossible because the\nsecret used to encrypt the vTPM state is stored in Barbican and is\nowned by the instance\u0027s owner. An admin performing a live migration\ndoes not have access to that secret, and thus Nova, acting on admin\u0027s\nbehalf with their Keystone token, cannot access the Barbican secret in\norder to set it up in Libvirt on the destination host.\n\nIn the Nova vTPM live migration spec [1], it was agreed that one of\nthe ways to make vTPM instances live-migratable is to make the\nBarbican secret owned by Nova itself. To achieve that, Nova sends\nits service token to Barbican when creating the vTPM state encryption\nsecret on the user\u0027s behalf. Because this has a security impact for\nthe user, they can control whether they accept this lesser security in\nexchange for live migration (by using image properties).\n\nPreviously, Barbican set the creator_id of a secret to the user_id.\nThis patches makes it so that if a service token is received when\ncreating a secret, the service\u0027s user_id becomes the secret owner.\n\nThe related Castellan change to actually send the service token\nconditionally is at [2].\n\n[1] https://specs.openstack.org/openstack/nova-specs/specs/2025.1/approved/vtpm-live-migration.html\n[2] https://review.opendev.org/c/openstack/castellan/+/942015\n\nImplements: blueprint vtpm-live-migration\nChange-Id: I2efaecee979b42a485f15438ad0c7fd5fce9071d\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/barbican/commit/cebdbd0fc8ee43404f1f850a10b07650698f0174"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/barbican/commit/cebdbd0fc8ee43404f1f850a10b07650698f0174"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
