)]}'
{"id":"openstack%2Fcinderlib~847623","triplet_id":"openstack%2Fcinderlib~stable%2Fwallaby~I0278b42785d14f92a521e6deff872dcba6505270","project":"openstack/cinderlib","branch":"stable/wallaby","topic":"fix-privsep-wallaby","attention_set":{},"removed_from_attention_set":{"10459":{"account":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"last_update":"2022-06-27 14:10:18.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"I0278b42785d14f92a521e6deff872dcba6505270","subject":"Fix privsep issues inside virtual env","status":"MERGED","created":"2022-06-24 21:48:29.000000000","updated":"2022-06-27 14:11:52.000000000","submitted":"2022-06-27 14:10:18.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":2,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"847623-fix-privsep-wallaby","meta_rev_id":"e682ad00b7c3d0b11394cdc05ae01ef6a9ef1e8c","_number":847623,"virtual_id_number":847623,"owner":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:gate","value":2,"date":"2022-06-27 14:10:18.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},{"value":0,"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},"all":[{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2022-06-27 11:08:50.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},{"value":2,"date":"2022-06-27 12:20:05.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"},"all":[{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},{"value":1,"date":"2022-06-27 12:20:05.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},{"value":0,"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Gate Blocker Fix / Urgent Change"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2022-06-24 21:48:29.000000000","updated_by":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"reviewer":{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},"state":"CC"},{"updated":"2022-06-25 00:43:22.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2022-06-27 11:08:50.000000000","updated_by":{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},"reviewer":{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},"state":"REVIEWER"},{"updated":"2022-06-27 12:20:05.000000000","updated_by":{"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"},"reviewer":{"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"},"state":"REVIEWER"}],"messages":[{"id":"cad70bf5583ff04402f566b1ea2385ffce8d207b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"date":"2022-06-24 21:48:29.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"57a03d81a9cfcd43c48d0db6c64b1a1610fd0f3d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},"date":"2022-06-24 22:50:01.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"e1a820194a65c2d23265ccd41dc5a5ba6af00435","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-06-25 00:43:22.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/e404958fe64d45c185a77315bfc413ee : SUCCESS in 2m 23s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4a8bed1f73cd4e90aca0adb418159984 : SUCCESS in 9m 05s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/67a0cd29088e49b2bc64296a16631c57 : SUCCESS in 5m 14s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/1364bc1a76264978bfa5688a73cc207c : SUCCESS in 4m 16s\n- cinderlib-tox-py36 https://zuul.opendev.org/t/openstack/build/c602c6d6994d4d5bb5135332b93142d6 : SUCCESS in 7m 49s\n- cinderlib-tox-py37 https://zuul.opendev.org/t/openstack/build/88acb1ffb92847ee9f88b2c99cf2b7c0 : SUCCESS in 7m 57s\n- cinderlib-lvm-functional https://zuul.opendev.org/t/openstack/build/665e2ce0312c4d478808ec00bc0be43e : SUCCESS in 10m 51s\n- cinderlib-ceph-functional https://zuul.opendev.org/t/openstack/build/d01aa109ae054848b2f19cdf5afa6575 : SUCCESS in 11m 15s\n- os-brick-src-tempest-lvm-lio-barbican https://zuul.opendev.org/t/openstack/build/a8780961d04447b2b8adc1cc5d28e1c6 : SUCCESS in 1h 47m 49s","accounts_in_message":[],"_revision_number":2},{"id":"eb7fc8d7095147ad152da30dfa6e770478f1facb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"date":"2022-06-27 10:39:57.000000000","message":"Uploaded patch set 3: Commit message was updated.","accounts_in_message":[],"_revision_number":3},{"id":"469b26f5f754542287d6c6b9d2720ef6b8c77d6a","author":{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},"date":"2022-06-27 11:08:50.000000000","message":"Patch Set 3: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"7b1fa868633b31902f25a7a1a9e76a390a3f91af","author":{"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"},"date":"2022-06-27 12:20:05.000000000","message":"Patch Set 3: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"309653cfa42906a11130509b5e96d8a712c9a13b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-06-27 12:31:37.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/02af35001e1241a7bf03402b41dd4c25 : SUCCESS in 2m 21s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/9742e8d3b3724d2d99d704f4d8cb19a8 : SUCCESS in 7m 23s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/bd668c776f1c46a4b3b349674382aed6 : SUCCESS in 5m 16s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/74fefd9a71e54772af863b52b41b272b : SUCCESS in 4m 10s\n- cinderlib-tox-py36 https://zuul.opendev.org/t/openstack/build/1b03c0910e554ea48b59c1b793920129 : SUCCESS in 6m 59s\n- cinderlib-tox-py37 https://zuul.opendev.org/t/openstack/build/9480636e668440068fca1513b12fa2c5 : SUCCESS in 8m 52s\n- cinderlib-lvm-functional https://zuul.opendev.org/t/openstack/build/003947c42fe54026b38522aabe9f89bb : SUCCESS in 11m 56s\n- cinderlib-ceph-functional https://zuul.opendev.org/t/openstack/build/8bc536ab64294d5b896b858943f66061 : SUCCESS in 8m 47s\n- os-brick-src-tempest-lvm-lio-barbican https://zuul.opendev.org/t/openstack/build/df6cb6ed69eb473ca376ea593ebc86b9 : SUCCESS in 1h 45m 05s","accounts_in_message":[],"_revision_number":3},{"id":"b63ff05278570d38d63ad48a9eeb136a9ce1fcf8","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-06-27 12:32:19.000000000","message":"Patch Set 3: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":3},{"id":"e5089eb082616771e3841dd81953e3bbaced63ef","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-06-27 14:10:18.000000000","message":"Patch Set 3: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/24103e14b3564536abed351991b02cfe : SUCCESS in 2m 10s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/0b24975ec3724480b67b461d76d418e4 : SUCCESS in 5m 31s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/0f3b742157bf4b63ba1753c7ba250385 : SUCCESS in 3m 55s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/83af02f12c324ae7857dcd02b19224cd : SUCCESS in 5m 59s\n- cinderlib-tox-py36 https://zuul.opendev.org/t/openstack/build/20cb1e6d95034779bf9b0fb3ee249da9 : SUCCESS in 11m 16s\n- cinderlib-tox-py37 https://zuul.opendev.org/t/openstack/build/521f3e41339d4fe1a722321dab6b0a2e : SUCCESS in 11m 59s\n- cinderlib-lvm-functional https://zuul.opendev.org/t/openstack/build/e5033e0897cd4bbba9bb65cf28e3361a : SUCCESS in 13m 07s\n- cinderlib-ceph-functional https://zuul.opendev.org/t/openstack/build/0833e547372f455a8a1dc674d414bd5e : SUCCESS in 9m 33s\n- os-brick-src-tempest-lvm-lio-barbican https://zuul.opendev.org/t/openstack/build/b55bb33681b84cf2b30f5ac2868db134 : SUCCESS in 1h 30m 15s","accounts_in_message":[],"_revision_number":3},{"id":"adc8f131ae1ad82841b09d10ff0613a2966b8300","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-06-27 14:10:18.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":3},{"id":"e682ad00b7c3d0b11394cdc05ae01ef6a9ef1e8c","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-06-27 14:11:52.000000000","message":"Patch Set 3:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1b2e199ebb95409eb76bfcc8614e319d : SUCCESS in 50s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/b660f0c0158c45ed9a70ac8eac10d15e : SUCCESS in 1m 11s","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"1b58a5fb9af8d0beca964eee91f0e0040f21cb23","revisions":{"b7aff905ef9f53106ad6cbd6c992836069161d83":{"kind":"REWORK","_number":1,"created":"2022-06-24 21:48:29.000000000","uploader":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"ref":"refs/changes/23/847623/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cinderlib","ref":"refs/changes/23/847623/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/1"}}},"commit":{"parents":[{"commit":"efdacb65e95b0491a5bbb8b0d05e87ed1d18cecb","subject":"Migrate jobs from CentOS 8 to CentOS 8 Stream","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/efdacb65e95b0491a5bbb8b0d05e87ed1d18cecb"}]}],"author":{"name":"Gorka Eguileor","email":"geguileo@redhat.com","date":"2022-06-22 12:58:55.000000000","tz":120},"committer":{"name":"Luigi Toscano","email":"ltoscano@redhat.com","date":"2022-06-24 21:48:20.000000000","tz":120},"subject":"Fix privsep issues inside virtual env","message":"Fix privsep issues inside virtual env\n\nWhen a virtual environment is created with the \"--system-site-packages\"\noption and privsep is installed on the system privsep will only use the\nsystem packages and completely ignore the ones in the virtual\nenvironment.\n\nThis results in errors such as the ones we see:\n\n- In the Ussuri gate: ModuleNotFoundError: No module named\n  \u0027os_brick.privileged.rootwrap\u0027\n\n- In the Wallaby gate: ModuleNotFoundError: No module named\n  \u0027os_brick.privileged.nvmeof\u0027\n\nThis happens because os-brick and cinder are starting privsep using the\n\"privsep-helper\" mechanism, and privsep was not installed in the virtual\nenv because it was already present system wide, so the \"privsep-helper\"\nthat is executed is the one from \"/usr/local/bin/privsep-helper\".\n\nThis python script \"privsep-helper\" ignores the virtual environment and\nforces usage of the system\u0027s python, for example in a Wallaby\ninstallation this could be \"#!/usr/bin/python3.6\".\n\nSince it ignores the virtual environment it won\u0027t use its packages and\nanything that\u0027s not present on system wide will not be found, and if\nfound it may be executing different code.\n\nThis patch fixes this issue by replacing the helper used to start\nprivsep with our own command.\n\nThis command is the same as the one usually installed in /usr/local/bin\nbut using /usr/bin/env to select the python to use.\n\nThis new script has been included as data in the cinderlib namespace\ninstead of making it install as a system script (like the original\nprivsep command) because we don\u0027t want to polute the system wide\nbinaries directory just for a corner case.\n\nWe also need to preserve user site-packages for the running Python when\ncalling root from the virtual environment, since the packages installed\non the virtual environment with \"--system-site-packages\" would have\ntaken those into consideration during the installation and not the ones\npresent on the root user.\n\nTo help debug issues at the gate all functional tests are now running\nwith debug logs.\n\nChange-Id: I0278b42785d14f92a521e6deff872dcba6505270\nRelated-Bug: #1958159\nCloses-Bug: #1979534\n(cherry picked from commit 4d784d23a91f789918929ca397910f3121fa166e)\n(cherry picked from commit 4fc56c815b0e9e4d3706dca14bbe54fbb4866272)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/b7aff905ef9f53106ad6cbd6c992836069161d83"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/b7aff905ef9f53106ad6cbd6c992836069161d83"}]},"branch":"refs/heads/stable/wallaby"},"9223528e19b8a8da041bd6d0eb4f9db6c03d2761":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2022-06-24 22:50:01.000000000","uploader":{"_account_id":9535,"name":"Gorka Eguileor","email":"geguileo@redhat.com","username":"Gorka"},"ref":"refs/changes/23/847623/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cinderlib","ref":"refs/changes/23/847623/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/2"}}},"commit":{"parents":[{"commit":"efdacb65e95b0491a5bbb8b0d05e87ed1d18cecb","subject":"Migrate jobs from CentOS 8 to CentOS 8 Stream","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/efdacb65e95b0491a5bbb8b0d05e87ed1d18cecb"}]}],"author":{"name":"Gorka Eguileor","email":"geguileo@redhat.com","date":"2022-06-22 12:58:55.000000000","tz":120},"committer":{"name":"Gorka Eguileor","email":"geguileo@redhat.com","date":"2022-06-24 22:49:09.000000000","tz":120},"subject":"DNM: Fix privsep issues inside virtual env","message":"DNM: Fix privsep issues inside virtual env\n\nDo not merge because we don\u0027t have the patches proposed and merged in\nother stable branches.  Using this patch to test that it fixes\ncinder/stable/wallaby jobs\n\nWhen a virtual environment is created with the \"--system-site-packages\"\noption and privsep is installed on the system privsep will only use the\nsystem packages and completely ignore the ones in the virtual\nenvironment.\n\nThis results in errors such as the ones we see:\n\n- In the Ussuri gate: ModuleNotFoundError: No module named\n  \u0027os_brick.privileged.rootwrap\u0027\n\n- In the Wallaby gate: ModuleNotFoundError: No module named\n  \u0027os_brick.privileged.nvmeof\u0027\n\nThis happens because os-brick and cinder are starting privsep using the\n\"privsep-helper\" mechanism, and privsep was not installed in the virtual\nenv because it was already present system wide, so the \"privsep-helper\"\nthat is executed is the one from \"/usr/local/bin/privsep-helper\".\n\nThis python script \"privsep-helper\" ignores the virtual environment and\nforces usage of the system\u0027s python, for example in a Wallaby\ninstallation this could be \"#!/usr/bin/python3.6\".\n\nSince it ignores the virtual environment it won\u0027t use its packages and\nanything that\u0027s not present on system wide will not be found, and if\nfound it may be executing different code.\n\nThis patch fixes this issue by replacing the helper used to start\nprivsep with our own command.\n\nThis command is the same as the one usually installed in /usr/local/bin\nbut using /usr/bin/env to select the python to use.\n\nThis new script has been included as data in the cinderlib namespace\ninstead of making it install as a system script (like the original\nprivsep command) because we don\u0027t want to polute the system wide\nbinaries directory just for a corner case.\n\nWe also need to preserve user site-packages for the running Python when\ncalling root from the virtual environment, since the packages installed\non the virtual environment with \"--system-site-packages\" would have\ntaken those into consideration during the installation and not the ones\npresent on the root user.\n\nTo help debug issues at the gate all functional tests are now running\nwith debug logs.\n\nChange-Id: I0278b42785d14f92a521e6deff872dcba6505270\nRelated-Bug: #1958159\nCloses-Bug: #1979534\n(cherry picked from commit 4d784d23a91f789918929ca397910f3121fa166e)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/9223528e19b8a8da041bd6d0eb4f9db6c03d2761"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/9223528e19b8a8da041bd6d0eb4f9db6c03d2761"}]},"branch":"refs/heads/stable/wallaby"},"1b58a5fb9af8d0beca964eee91f0e0040f21cb23":{"kind":"NO_CODE_CHANGE","_number":3,"created":"2022-06-27 10:39:57.000000000","uploader":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"ref":"refs/changes/23/847623/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cinderlib","ref":"refs/changes/23/847623/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cinderlib refs/changes/23/847623/3"}}},"commit":{"parents":[{"commit":"efdacb65e95b0491a5bbb8b0d05e87ed1d18cecb","subject":"Migrate jobs from CentOS 8 to CentOS 8 Stream","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/efdacb65e95b0491a5bbb8b0d05e87ed1d18cecb"}]}],"author":{"name":"Gorka Eguileor","email":"geguileo@redhat.com","date":"2022-06-22 12:58:55.000000000","tz":120},"committer":{"name":"Luigi Toscano","email":"ltoscano@redhat.com","date":"2022-06-27 10:39:50.000000000","tz":120},"subject":"Fix privsep issues inside virtual env","message":"Fix privsep issues inside virtual env\n\nWhen a virtual environment is created with the \"--system-site-packages\"\noption and privsep is installed on the system privsep will only use the\nsystem packages and completely ignore the ones in the virtual\nenvironment.\n\nThis results in errors such as the ones we see:\n\n- In the Ussuri gate: ModuleNotFoundError: No module named\n  \u0027os_brick.privileged.rootwrap\u0027\n\n- In the Wallaby gate: ModuleNotFoundError: No module named\n  \u0027os_brick.privileged.nvmeof\u0027\n\nThis happens because os-brick and cinder are starting privsep using the\n\"privsep-helper\" mechanism, and privsep was not installed in the virtual\nenv because it was already present system wide, so the \"privsep-helper\"\nthat is executed is the one from \"/usr/local/bin/privsep-helper\".\n\nThis python script \"privsep-helper\" ignores the virtual environment and\nforces usage of the system\u0027s python, for example in a Wallaby\ninstallation this could be \"#!/usr/bin/python3.6\".\n\nSince it ignores the virtual environment it won\u0027t use its packages and\nanything that\u0027s not present on system wide will not be found, and if\nfound it may be executing different code.\n\nThis patch fixes this issue by replacing the helper used to start\nprivsep with our own command.\n\nThis command is the same as the one usually installed in /usr/local/bin\nbut using /usr/bin/env to select the python to use.\n\nThis new script has been included as data in the cinderlib namespace\ninstead of making it install as a system script (like the original\nprivsep command) because we don\u0027t want to polute the system wide\nbinaries directory just for a corner case.\n\nWe also need to preserve user site-packages for the running Python when\ncalling root from the virtual environment, since the packages installed\non the virtual environment with \"--system-site-packages\" would have\ntaken those into consideration during the installation and not the ones\npresent on the root user.\n\nTo help debug issues at the gate all functional tests are now running\nwith debug logs.\n\nChange-Id: I0278b42785d14f92a521e6deff872dcba6505270\nRelated-Bug: #1958159\nCloses-Bug: #1979534\n(cherry picked from commit 4d784d23a91f789918929ca397910f3121fa166e)\n(cherry picked from commit 4fc56c815b0e9e4d3706dca14bbe54fbb4866272)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/1b58a5fb9af8d0beca964eee91f0e0040f21cb23"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cinderlib/commit/1b58a5fb9af8d0beca964eee91f0e0040f21cb23"}]},"branch":"refs/heads/stable/wallaby"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"OK","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"OK","applied_by":{"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"}},{"label":"Workflow","status":"OK","applied_by":{"_account_id":27615,"name":"Rajat Dhasmana","email":"rajatdhasmana@gmail.com","username":"whoami-rajat"}},{"label":"Review-Priority","status":"MAY"}]}],"submit_requirements":[]}
