)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":38371,"name":"Kumar Tadepalli","display_name":"Kumar Tadepalli","email":"kumart.lead@gmail.com","username":"kumart","status":"NetApp"},"change_message_id":"8e7cf5a3601e54cfaaa2175e54d74645bb95bb2b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"5b7fdfd1_b6d50115","updated":"2026-07-31 03:53:21.000000000","message":"Please address the comment.","commit_id":"0d94d698d6f3a723b9fb9d1d618196783ad5fc0c"},{"author":{"_account_id":38371,"name":"Kumar Tadepalli","display_name":"Kumar Tadepalli","email":"kumart.lead@gmail.com","username":"kumart","status":"NetApp"},"change_message_id":"cb99ed3371d18459d69009da69e87c6fa1c4712b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"5bf70330_592bd2ee","updated":"2026-07-31 04:15:54.000000000","message":"LGTM.","commit_id":"711c2a48764b2539ff0c6e799ae6183a5e375dae"},{"author":{"_account_id":4523,"name":"Eric Harney","email":"eharney@redhat.com","username":"eharney"},"change_message_id":"8ca313751f7c18ac0bc02f166459655141181d72","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"aa361c18_3e5673cb","updated":"2026-08-03 14:32:04.000000000","message":"recheck\n\npy314 unit test timeout","commit_id":"711c2a48764b2539ff0c6e799ae6183a5e375dae"},{"author":{"_account_id":38371,"name":"Kumar Tadepalli","display_name":"Kumar Tadepalli","email":"kumart.lead@gmail.com","username":"kumart","status":"NetApp"},"change_message_id":"17efdeb484a898befc5c93adeadffe6c62ab50c1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"25fd6445_fa891e64","updated":"2026-08-05 05:27:51.000000000","message":"LGTM.","commit_id":"762f3a21db94362764b4c57a8d626d9e45941364"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"7ea4f6e8afa45dac26e1bc13c810a608fb3cee75","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"8413d7f8_cf600113","updated":"2026-08-05 04:34:31.000000000","message":"recheck","commit_id":"762f3a21db94362764b4c57a8d626d9e45941364"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"42a13337fe0b956cab89720e4543540e977f567f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"b4249f4c_2c4129fe","updated":"2026-08-05 10:15:38.000000000","message":"recheck","commit_id":"6176ce494aa3cd67ecc86d580338d103041d0d6f"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"0b350e0f_8df26d85","updated":"2026-08-12 15:46:44.000000000","message":"Release note needs an `upgrade:` section - see inline.\nYou also still document `netapp_transport_type \u003d http` in to `.inc` files.\nThe commit footer should say `Related-Bug: #2157914`, not `Related pattern`","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":36180,"name":"Gireesh Awasthi","display_name":"Gireesh","email":"gawasthi2010@gmail.com","username":"agireesh","status":"NetApp"},"change_message_id":"fbea1f2a282f57a18460171d37e35b39e0e9e9c1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"aca94ac8_e72c2ea6","updated":"2026-08-06 12:55:29.000000000","message":"Thanks Anoop for working on this, changes looks good for me..!","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"abc0c588084b0bb625442dd8bf0c99eef1cdba91","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"068f181b_63db0063","updated":"2026-08-06 12:22:46.000000000","message":"recheck","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"5c0028b63bf67b3086a796c202782328d4e3850e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"26baef26_18a89a8c","updated":"2026-08-10 04:04:23.000000000","message":"recheck","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"f93590d5c2ef902185df97eed0918429a89506d6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"c933f6de_16201c9b","updated":"2026-08-06 12:37:33.000000000","message":"recheck","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"c6dafd5b510d9801773ff55b4c2f744f703652d2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"efb6b210_42d0dbbc","updated":"2026-08-12 14:17:58.000000000","message":"recheck","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"4b382313_127559a6","updated":"2026-08-13 14:53:36.000000000","message":"Clearing resolved comments","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"d0975fa667cd6424a0cb8c4eb3ac86f606abb721","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"b471784d_7fb0c877","updated":"2026-08-13 14:51:13.000000000","message":"Good update - everything covered. \nOne slight issue has been created - you are double logging the warning errors. See the inline comments","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"d1e7bee1e2047d9d45c03e419f18c8c33da66b22","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"ab005031_a24dc4a3","updated":"2026-08-13 14:54:12.000000000","message":"I\u0027ll give this a +1, but it ould be good to fix the last comments from PS9","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"0660893cef40c6ec36c4dfadec5af2f4622b8806","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"edcc0a2e_309e0288","updated":"2026-08-14 13:48:53.000000000","message":"Nearly there - only a couple of minor nits really... so not giving a -1, just leaving it at 0 until these are resolved, especially the docs related ones","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"3beb0e57202a41fed584fa37484d8d736755cc31","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"0784eede_e7558de4","updated":"2026-08-14 06:32:20.000000000","message":"Thanks Simon for the reviewing. Very good catches. I have addressed all the comments.","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"86f8fa72f3b4604444ac302e11aeb5a980948c12","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"652d05f7_40c65ee8","updated":"2026-08-17 17:11:43.000000000","message":"One minor docs things that you can address if you do another PS","commit_id":"ba818871aacaccc83fc03fa6bf1a965425dfdfee"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"9c9d1593c046ee74ae615deb7c3f11093c4a2216","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"62d9ccab_797868d5","updated":"2026-08-17 10:29:43.000000000","message":"Run-NetApp CI","commit_id":"ba818871aacaccc83fc03fa6bf1a965425dfdfee"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"7210de46872582237c9d84743acb21966a761397","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"c7c0e352_d12e9f45","updated":"2026-08-17 08:31:59.000000000","message":"Thanks Simon. Addressed the comments.","commit_id":"ba818871aacaccc83fc03fa6bf1a965425dfdfee"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"62dd5cfc9274cd6b2e951109d6108dbf09f2d3c4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"469afc6e_12ca4482","updated":"2026-08-18 09:37:54.000000000","message":"@simon@everpuredata.com - Addressed your comment.","commit_id":"e07c074df9819ced54008f730f5e53881e568437"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"f4d57a455c1ebc15106395c557f69e8f4c99f156","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"dc9b72b5_2d73fcea","updated":"2026-08-18 14:52:17.000000000","message":"All good - thanks for getting to all these so promptly.\n\n@anoop.shukla@netapp.com One suggestion - change the NetApp CI to use `https`, as it is currently using `http`.","commit_id":"e07c074df9819ced54008f730f5e53881e568437"},{"author":{"_account_id":39225,"name":"Prudhvi","display_name":"Prudhvi","email":"prudhvi.openstack@gmail.com","username":"Prudhvi"},"change_message_id":"33d35bbb4be23e27339d86290cfc2aa343f3b771","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"c4852fa2_cf47c6a5","updated":"2026-08-18 10:25:05.000000000","message":"Run-NetApp CI","commit_id":"e07c074df9819ced54008f730f5e53881e568437"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"a68176757c2babc7adfa86ccbfbd4b543dfeb051","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"a30a5939_28a55d42","updated":"2026-08-18 09:48:11.000000000","message":"recheck","commit_id":"e07c074df9819ced54008f730f5e53881e568437"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"3bf1b8eda74dd7c143d972b92a50ee1302b7a173","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"536402f5_de533a8f","in_reply_to":"dc9b72b5_2d73fcea","updated":"2026-08-19 11:42:17.000000000","message":"We will take that up once the patch is merged. Thanks Simon.","commit_id":"e07c074df9819ced54008f730f5e53881e568437"}],"cinder/tests/unit/volume/drivers/netapp/test_common.py":[{"author":{"_account_id":4523,"name":"Eric Harney","email":"eharney@redhat.com","username":"eharney"},"change_message_id":"6969edd722573c1ea95e7a2ee4b835a1d10aa0be","unresolved":false,"context_lines":[{"line_number":91,"context_line":""},{"line_number":92,"context_line":"        na_common.NetAppDriver(configuration\u003dconfig)"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"        na_common.LOG.warning.assert_called_once()"},{"line_number":95,"context_line":"        _, warning_data \u003d na_common.LOG.warning.call_args[0]"},{"line_number":96,"context_line":"        self.assertEqual(\u0027netapp_transport_type\u0027, warning_data[\u0027option\u0027])"},{"line_number":97,"context_line":"        self.assertEqual(\u0027http\u0027, warning_data[\u0027protocol\u0027])"}],"source_content_type":"text/x-python","patch_set":2,"id":"8ec3398b_93e2dc31","line":94,"updated":"2026-08-03 14:31:56.000000000","message":"This is likely to break as other LOGs are added later, and will need to look for actual text in the log message. But, probably fine for now.","commit_id":"711c2a48764b2539ff0c6e799ae6183a5e375dae"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"d0975fa667cd6424a0cb8c4eb3ac86f606abb721","unresolved":true,"context_lines":[{"line_number":93,"context_line":""},{"line_number":94,"context_line":"        na_common.NetAppDriver(configuration\u003dconfig)"},{"line_number":95,"context_line":""},{"line_number":96,"context_line":"        cmode_utils.LOG.warning.assert_called_once()"},{"line_number":97,"context_line":"        warning_msg, warning_data \u003d cmode_utils.LOG.warning.call_args[0]"},{"line_number":98,"context_line":"        self.assertIn(\u0027netapp_transport_type is set to http\u0027, warning_msg)"},{"line_number":99,"context_line":"        self.assertEqual(\u0027DEFAULT\u0027, warning_data[\u0027backend\u0027])"}],"source_content_type":"text/x-python","patch_set":9,"id":"e5463110_4f471015","line":96,"updated":"2026-08-13 14:51:13.000000000","message":"nit: look at the comment for `common.py:68`.this passes here as `crete_driver` is mocked, so the driver\u0027s `do_setup` never runs.","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"3beb0e57202a41fed584fa37484d8d736755cc31","unresolved":false,"context_lines":[{"line_number":93,"context_line":""},{"line_number":94,"context_line":"        na_common.NetAppDriver(configuration\u003dconfig)"},{"line_number":95,"context_line":""},{"line_number":96,"context_line":"        cmode_utils.LOG.warning.assert_called_once()"},{"line_number":97,"context_line":"        warning_msg, warning_data \u003d cmode_utils.LOG.warning.call_args[0]"},{"line_number":98,"context_line":"        self.assertIn(\u0027netapp_transport_type is set to http\u0027, warning_msg)"},{"line_number":99,"context_line":"        self.assertEqual(\u0027DEFAULT\u0027, warning_data[\u0027backend\u0027])"}],"source_content_type":"text/x-python","patch_set":9,"id":"d2a3cd05_6baf170e","line":96,"in_reply_to":"e5463110_4f471015","updated":"2026-08-14 06:32:20.000000000","message":"Addressed this in the PS10","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"}],"cinder/tests/unit/volume/drivers/netapp/test_options.py":[{"author":{"_account_id":38371,"name":"Kumar Tadepalli","display_name":"Kumar Tadepalli","email":"kumart.lead@gmail.com","username":"kumart","status":"NetApp"},"change_message_id":"8e7cf5a3601e54cfaaa2175e54d74645bb95bb2b","unresolved":true,"context_lines":[{"line_number":15,"context_line":"from cinder.tests.unit import test"},{"line_number":16,"context_line":"import cinder.tests.unit.volume.drivers.netapp.fakes as na_fakes"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"class NetAppOptionsTestCase(test.TestCase):"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    def test_transport_type_default_is_https(self):"}],"source_content_type":"text/x-python","patch_set":1,"id":"16b707d9_4c5ecfbb","line":18,"updated":"2026-07-31 03:53:21.000000000","message":"I think we don\u0027t need UT for options as all are constants.\nEither remove this or add other options UT as well.","commit_id":"0d94d698d6f3a723b9fb9d1d618196783ad5fc0c"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"6b0a3134b88aaaca29a940024f6001b22f6afa05","unresolved":false,"context_lines":[{"line_number":15,"context_line":"from cinder.tests.unit import test"},{"line_number":16,"context_line":"import cinder.tests.unit.volume.drivers.netapp.fakes as na_fakes"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"class NetAppOptionsTestCase(test.TestCase):"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    def test_transport_type_default_is_https(self):"}],"source_content_type":"text/x-python","patch_set":1,"id":"fd9daaa5_b4b69fa6","line":18,"in_reply_to":"0f18e855_41c4e61d","updated":"2026-07-31 04:05:18.000000000","message":"Done","commit_id":"0d94d698d6f3a723b9fb9d1d618196783ad5fc0c"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"99f170bf6e45373f368e43f8b8fdbb730fd5d437","unresolved":true,"context_lines":[{"line_number":15,"context_line":"from cinder.tests.unit import test"},{"line_number":16,"context_line":"import cinder.tests.unit.volume.drivers.netapp.fakes as na_fakes"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"class NetAppOptionsTestCase(test.TestCase):"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    def test_transport_type_default_is_https(self):"}],"source_content_type":"text/x-python","patch_set":1,"id":"0f18e855_41c4e61d","line":18,"in_reply_to":"16b707d9_4c5ecfbb","updated":"2026-07-31 03:58:51.000000000","message":"Agreed. Will remove this UT.","commit_id":"0d94d698d6f3a723b9fb9d1d618196783ad5fc0c"}],"cinder/volume/drivers/netapp/common.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":64,"context_line":"        config.append_config_values(options.netapp_transport_opts)"},{"line_number":65,"context_line":"        na_utils.check_flags(NetAppDriver.REQUIRED_FLAGS, config)"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"        if config.netapp_transport_type \u003d\u003d \u0027http\u0027:"},{"line_number":68,"context_line":"            LOG.warning(\u0027The %(option)s option is set to %(protocol)s for \u0027"},{"line_number":69,"context_line":"                        \u0027backend %(backend)s. This is an insecure \u0027"},{"line_number":70,"context_line":"                        \u0027transport and is not recommended for production.\u0027,"}],"source_content_type":"text/x-python","patch_set":8,"id":"1f28832d_3aacd19f","line":67,"updated":"2026-08-12 15:46:44.000000000","message":"This lives in NetAppDriver.__new__, so it only fires for the unified proxy driver.\n\nA backend configured with `volume_driver \u003d cinder.volume.drivers.netapp.dataontap.nfs_cmode.NetAppCmodeNfsDriver` (or the iscsi/fc/nvme classes) never goes through here and gets no warning at all - those classes append `netapp_transport_opts` themselves in `block_base/nfs_base/\nnvme_library.dot_utils.get_client_for_backend` or the drivers\u0027 `do_setup` would cover every load path, and would be the natural home for the `ssl_cert_verify \u003d False` warning too.","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":64,"context_line":"        config.append_config_values(options.netapp_transport_opts)"},{"line_number":65,"context_line":"        na_utils.check_flags(NetAppDriver.REQUIRED_FLAGS, config)"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"        if config.netapp_transport_type \u003d\u003d \u0027http\u0027:"},{"line_number":68,"context_line":"            LOG.warning(\u0027The %(option)s option is set to %(protocol)s for \u0027"},{"line_number":69,"context_line":"                        \u0027backend %(backend)s. This is an insecure \u0027"},{"line_number":70,"context_line":"                        \u0027transport and is not recommended for production.\u0027,"}],"source_content_type":"text/x-python","patch_set":8,"id":"3bd4596f_339762f1","line":67,"in_reply_to":"1f28832d_3aacd19f","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":65,"context_line":"        na_utils.check_flags(NetAppDriver.REQUIRED_FLAGS, config)"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"        if config.netapp_transport_type \u003d\u003d \u0027http\u0027:"},{"line_number":68,"context_line":"            LOG.warning(\u0027The %(option)s option is set to %(protocol)s for \u0027"},{"line_number":69,"context_line":"                        \u0027backend %(backend)s. This is an insecure \u0027"},{"line_number":70,"context_line":"                        \u0027transport and is not recommended for production.\u0027,"},{"line_number":71,"context_line":"                        {\u0027option\u0027: \u0027netapp_transport_type\u0027,"}],"source_content_type":"text/x-python","patch_set":8,"id":"38c037a4_5c9e4fa4","line":68,"updated":"2026-08-12 15:46:44.000000000","message":"Nit: `%(option)s` and `%(protocol)s` are interpolating string literals - just inline them:\n```\nLOG.warning(\u0027netapp_transport_type is set to http for backend \u0027\n            \u0027%(backend)s. This is an insecure transport and is not \u0027\n            \u0027recommended for production.\u0027,\n            {\u0027backend\u0027: config.config_group or \u0027DEFAULT\u0027})\n```","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":65,"context_line":"        na_utils.check_flags(NetAppDriver.REQUIRED_FLAGS, config)"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"        if config.netapp_transport_type \u003d\u003d \u0027http\u0027:"},{"line_number":68,"context_line":"            LOG.warning(\u0027The %(option)s option is set to %(protocol)s for \u0027"},{"line_number":69,"context_line":"                        \u0027backend %(backend)s. This is an insecure \u0027"},{"line_number":70,"context_line":"                        \u0027transport and is not recommended for production.\u0027,"},{"line_number":71,"context_line":"                        {\u0027option\u0027: \u0027netapp_transport_type\u0027,"}],"source_content_type":"text/x-python","patch_set":8,"id":"c02e9d41_1f5541f3","line":68,"in_reply_to":"38c037a4_5c9e4fa4","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"d0975fa667cd6424a0cb8c4eb3ac86f606abb721","unresolved":true,"context_lines":[{"line_number":25,"context_line":"from cinder import exception"},{"line_number":26,"context_line":"from cinder.i18n import _"},{"line_number":27,"context_line":"from cinder.volume import driver"},{"line_number":28,"context_line":"from cinder.volume.drivers.netapp.dataontap.utils import utils as cmode_utils"},{"line_number":29,"context_line":"from cinder.volume.drivers.netapp import options"},{"line_number":30,"context_line":"from cinder.volume.drivers.netapp import utils as na_utils"},{"line_number":31,"context_line":""}],"source_content_type":"text/x-python","patch_set":9,"id":"bc235281_8ed4bdc1","line":28,"updated":"2026-08-13 14:51:13.000000000","message":"you can remove this line when you look at the comment for line 68","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"3beb0e57202a41fed584fa37484d8d736755cc31","unresolved":false,"context_lines":[{"line_number":25,"context_line":"from cinder import exception"},{"line_number":26,"context_line":"from cinder.i18n import _"},{"line_number":27,"context_line":"from cinder.volume import driver"},{"line_number":28,"context_line":"from cinder.volume.drivers.netapp.dataontap.utils import utils as cmode_utils"},{"line_number":29,"context_line":"from cinder.volume.drivers.netapp import options"},{"line_number":30,"context_line":"from cinder.volume.drivers.netapp import utils as na_utils"},{"line_number":31,"context_line":""}],"source_content_type":"text/x-python","patch_set":9,"id":"d20d10e5_a8fc3974","line":28,"in_reply_to":"bc235281_8ed4bdc1","updated":"2026-08-14 06:32:20.000000000","message":"Address the issue in latest PS","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"d0975fa667cd6424a0cb8c4eb3ac86f606abb721","unresolved":true,"context_lines":[{"line_number":65,"context_line":"        config.append_config_values(options.netapp_transport_opts)"},{"line_number":66,"context_line":"        na_utils.check_flags(NetAppDriver.REQUIRED_FLAGS, config)"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"        cmode_utils.warn_insecure_netapp_transport_options(config)"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"        app_version \u003d na_utils.OpenStackInfo().info()"},{"line_number":71,"context_line":"        LOG.info(\u0027OpenStack OS Version Info: %(info)s\u0027,"}],"source_content_type":"text/x-python","patch_set":9,"id":"36e61e8f_96a06a08","line":68,"updated":"2026-08-13 14:51:13.000000000","message":"given you have added this to `do_setup` for all the driver bases, this is redundant and duplictaes the warning messages. The unit tests don\u0027t catch this becuase `create_driver` is mocked.","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"3beb0e57202a41fed584fa37484d8d736755cc31","unresolved":false,"context_lines":[{"line_number":65,"context_line":"        config.append_config_values(options.netapp_transport_opts)"},{"line_number":66,"context_line":"        na_utils.check_flags(NetAppDriver.REQUIRED_FLAGS, config)"},{"line_number":67,"context_line":""},{"line_number":68,"context_line":"        cmode_utils.warn_insecure_netapp_transport_options(config)"},{"line_number":69,"context_line":""},{"line_number":70,"context_line":"        app_version \u003d na_utils.OpenStackInfo().info()"},{"line_number":71,"context_line":"        LOG.info(\u0027OpenStack OS Version Info: %(info)s\u0027,"}],"source_content_type":"text/x-python","patch_set":9,"id":"f2333ec1_d1d841d0","line":68,"in_reply_to":"36e61e8f_96a06a08","updated":"2026-08-14 06:32:20.000000000","message":"Done","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"}],"cinder/volume/drivers/netapp/dataontap/block_base.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"0660893cef40c6ec36c4dfadec5af2f4622b8806","unresolved":true,"context_lines":[{"line_number":152,"context_line":"        return reserved_percentage"},{"line_number":153,"context_line":""},{"line_number":154,"context_line":"    def do_setup(self, context):"},{"line_number":155,"context_line":"        cmode_utils.warn_insecure_netapp_transport_options("},{"line_number":156,"context_line":"            self.configuration)"},{"line_number":157,"context_line":"        if self.configuration.netapp_private_key_file or\\"},{"line_number":158,"context_line":"                self.configuration.netapp_certificate_file:"}],"source_content_type":"text/x-python","patch_set":10,"id":"d79539f8_cee67c5e","line":155,"updated":"2026-08-14 13:48:53.000000000","message":"Nothing assert this, or the same calls in `nfs_base` and `nvme_library`. The helper logic is tested, but not this wiring.\nAdd a `mock_object + assert_called_once_with(self.configuration)` in the existing `test_do_setup_san_configured` (test_block_base.py:937), `test_do_setup` (test_nfs_base.py:75) and `test_do_setup_san_unconfigured` (test_nvme_library.py:90) would close it.","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"7210de46872582237c9d84743acb21966a761397","unresolved":false,"context_lines":[{"line_number":152,"context_line":"        return reserved_percentage"},{"line_number":153,"context_line":""},{"line_number":154,"context_line":"    def do_setup(self, context):"},{"line_number":155,"context_line":"        cmode_utils.warn_insecure_netapp_transport_options("},{"line_number":156,"context_line":"            self.configuration)"},{"line_number":157,"context_line":"        if self.configuration.netapp_private_key_file or\\"},{"line_number":158,"context_line":"                self.configuration.netapp_certificate_file:"}],"source_content_type":"text/x-python","patch_set":10,"id":"490f5386_5ce9ee33","line":155,"in_reply_to":"d79539f8_cee67c5e","updated":"2026-08-17 08:31:59.000000000","message":"Done","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"}],"cinder/volume/drivers/netapp/dataontap/client/api.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":208,"context_line":"            response.raise_for_status()"},{"line_number":209,"context_line":"        except requests.HTTPError as e:"},{"line_number":210,"context_line":"            raise NaApiError(e.response.status_code, e.response.reason)"},{"line_number":211,"context_line":"        except Exception:"},{"line_number":212,"context_line":"            LOG.exception(\"Error communicating with NetApp filer.\")"},{"line_number":213,"context_line":"            raise NaApiError(\u0027Unexpected error\u0027)"},{"line_number":214,"context_line":""}],"source_content_type":"text/x-python","patch_set":8,"id":"a907714c_1fdfdfee","line":211,"updated":"2026-08-12 15:46:44.000000000","message":"Now that verification failures are the expected new failure mode, `requests.exceptions.SSLError` falling into this bare `except Exception` -\u003e `NaApiError(\u0027Unexpected error\u0027)` is going to generate bug reports rather than config fixes. Worth an explicit branch above this one that names the relevant options:\n```\nexcept requests.exceptions.SSLError as e:\n    LOG.error(\"TLS verification failed for NetApp server %(host)s: \"                \n              \"%(err)s. Set netapp_ssl_cert_path to the CA bundle for \"                 \n              \"this system, or netapp_ssl_cert_verify\u003dFalse to disable \"\n              \"verification (not recommended).\",\n              {\u0027host\u0027: self._host, \u0027err\u0027: e})\nraise NaApiError(\u0027TLS verification failed\u0027)\n```","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":208,"context_line":"            response.raise_for_status()"},{"line_number":209,"context_line":"        except requests.HTTPError as e:"},{"line_number":210,"context_line":"            raise NaApiError(e.response.status_code, e.response.reason)"},{"line_number":211,"context_line":"        except Exception:"},{"line_number":212,"context_line":"            LOG.exception(\"Error communicating with NetApp filer.\")"},{"line_number":213,"context_line":"            raise NaApiError(\u0027Unexpected error\u0027)"},{"line_number":214,"context_line":""}],"source_content_type":"text/x-python","patch_set":8,"id":"dd813b18_5af44bc0","line":211,"in_reply_to":"a907714c_1fdfdfee","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":319,"context_line":"        else:"},{"line_number":320,"context_line":"            self._session.auth \u003d auth.HTTPBasicAuth("},{"line_number":321,"context_line":"                self._username, self._password)"},{"line_number":322,"context_line":"            if not self._ssl_cert_verify:"},{"line_number":323,"context_line":"                self._session.verify \u003d False"},{"line_number":324,"context_line":"            elif isinstance(self._ssl_cert_path, str):"},{"line_number":325,"context_line":"                self._session.verify \u003d self._ssl_cert_path"}],"source_content_type":"text/x-python","patch_set":8,"id":"dbeca2ed_dc117cfe","line":322,"updated":"2026-08-12 15:46:44.000000000","message":"This new `_ssl_cert_verify` check only guards the basic-auth branch. The cert-auth branch above (line 311) derives `verify` entirely from `_certificate_host_validation`/`_ca_certificate_file` and never consults `_ssl_cert_verify; RestNaServer`. `_build_session` does the same at line 823 via `_create_certificate_auth_handler()`. So with client-certificate auth configure\nd, `netapp_ssl_cert_verify \u003d False` silently does nothing - while the new help text promises the option \"Applies to both the REST and legacy ZAPI clients.\"\n\nEither honour it in both branches, or scope the help text to basic auth. As-is the option quietly lies for cert-auth backends, which is the worst outcome for a security option.","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":319,"context_line":"        else:"},{"line_number":320,"context_line":"            self._session.auth \u003d auth.HTTPBasicAuth("},{"line_number":321,"context_line":"                self._username, self._password)"},{"line_number":322,"context_line":"            if not self._ssl_cert_verify:"},{"line_number":323,"context_line":"                self._session.verify \u003d False"},{"line_number":324,"context_line":"            elif isinstance(self._ssl_cert_path, str):"},{"line_number":325,"context_line":"                self._session.verify \u003d self._ssl_cert_path"}],"source_content_type":"text/x-python","patch_set":8,"id":"eb014724_16fdb36a","line":322,"in_reply_to":"dbeca2ed_dc117cfe","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":694,"context_line":"            na_utils.setup_api_trace_pattern(api_trace_pattern)"},{"line_number":695,"context_line":""},{"line_number":696,"context_line":"        if not ssl_cert_verify:"},{"line_number":697,"context_line":"            self._ssl_verify \u003d False"},{"line_number":698,"context_line":"        elif ssl_cert_path is not None:"},{"line_number":699,"context_line":"            self._ssl_verify \u003d ssl_cert_path"},{"line_number":700,"context_line":"        else:"}],"source_content_type":"text/x-python","patch_set":8,"id":"647b5dbd_ee6bcec4","line":697,"updated":"2026-08-12 15:46:44.000000000","message":"The three-branch `_ssl_verify truth table here and the changed transport default above have no direct test coverage - `test_api.py` only exercises the ZAPI `_build_session`.\n\nPlease mirror `test_build_session_with_basic_auth`\u0027s ddt matrix for `RestNaServer.__init__`, plus a default-transport assertion like the new `test_init_defaults_https_and_ssl_cert_verify`.","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":694,"context_line":"            na_utils.setup_api_trace_pattern(api_trace_pattern)"},{"line_number":695,"context_line":""},{"line_number":696,"context_line":"        if not ssl_cert_verify:"},{"line_number":697,"context_line":"            self._ssl_verify \u003d False"},{"line_number":698,"context_line":"        elif ssl_cert_path is not None:"},{"line_number":699,"context_line":"            self._ssl_verify \u003d ssl_cert_path"},{"line_number":700,"context_line":"        else:"}],"source_content_type":"text/x-python","patch_set":8,"id":"fd58825e_39f27f95","line":697,"in_reply_to":"647b5dbd_ee6bcec4","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"0660893cef40c6ec36c4dfadec5af2f4622b8806","unresolved":true,"context_lines":[{"line_number":856,"context_line":"    def _create_certificate_auth_handler(self):"},{"line_number":857,"context_line":"        \"\"\"Creates and returns a certificate auth handler.\"\"\""},{"line_number":858,"context_line":"        cert \u003d (self._certificate_file, self._private_key_file)"},{"line_number":859,"context_line":"        if self._ssl_verify is False:"},{"line_number":860,"context_line":"            return cert, False"},{"line_number":861,"context_line":"        self._certificate_host_validation \u003d self._session.verify"},{"line_number":862,"context_line":"        if self._certificate_file and self._private_key_file \\"}],"source_content_type":"text/x-python","patch_set":10,"id":"f60c9786_81710705","line":859,"updated":"2026-08-14 13:48:53.000000000","message":"`False` is always the case. Lines 321 and 322 do this slightly differently, so maybe use that way. \nThis current way implies that `_ssl_verify` could be `True` at some point, which it can\u0027t","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"7210de46872582237c9d84743acb21966a761397","unresolved":false,"context_lines":[{"line_number":856,"context_line":"    def _create_certificate_auth_handler(self):"},{"line_number":857,"context_line":"        \"\"\"Creates and returns a certificate auth handler.\"\"\""},{"line_number":858,"context_line":"        cert \u003d (self._certificate_file, self._private_key_file)"},{"line_number":859,"context_line":"        if self._ssl_verify is False:"},{"line_number":860,"context_line":"            return cert, False"},{"line_number":861,"context_line":"        self._certificate_host_validation \u003d self._session.verify"},{"line_number":862,"context_line":"        if self._certificate_file and self._private_key_file \\"}],"source_content_type":"text/x-python","patch_set":10,"id":"8ab7851b_34a54b1e","line":859,"in_reply_to":"f60c9786_81710705","updated":"2026-08-17 08:31:59.000000000","message":"Done","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"}],"cinder/volume/drivers/netapp/dataontap/client/client_base.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":50,"context_line":"                transport_type\u003d\u0027https\u0027,"},{"line_number":51,"context_line":"                port\u003dkwargs[\u0027port\u0027],"},{"line_number":52,"context_line":"                ssl_cert_path\u003dssl_cert_path,"},{"line_number":53,"context_line":"                ssl_cert_verify\u003dssl_cert_verify,"},{"line_number":54,"context_line":"                private_key_file\u003dprivate_key_file,"},{"line_number":55,"context_line":"                certificate_file\u003dcertificate_file,"},{"line_number":56,"context_line":"                ca_certificate_file\u003dca_certificate_file,"}],"source_content_type":"text/x-python","patch_set":8,"id":"51796585_39e5f5cf","line":53,"updated":"2026-08-12 15:46:44.000000000","message":"Passing `ssl_cert_verify` into the two cert-auth constructors is currently a no-op (see `api.py:322`). Fine to leave once that is resolved, but as-is it reads as working plumbing.","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":50,"context_line":"                transport_type\u003d\u0027https\u0027,"},{"line_number":51,"context_line":"                port\u003dkwargs[\u0027port\u0027],"},{"line_number":52,"context_line":"                ssl_cert_path\u003dssl_cert_path,"},{"line_number":53,"context_line":"                ssl_cert_verify\u003dssl_cert_verify,"},{"line_number":54,"context_line":"                private_key_file\u003dprivate_key_file,"},{"line_number":55,"context_line":"                certificate_file\u003dcertificate_file,"},{"line_number":56,"context_line":"                ca_certificate_file\u003dca_certificate_file,"}],"source_content_type":"text/x-python","patch_set":8,"id":"21dc49b9_6fd61518","line":53,"in_reply_to":"51796585_39e5f5cf","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"}],"cinder/volume/drivers/netapp/dataontap/nfs_base.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"d0975fa667cd6424a0cb8c4eb3ac86f606abb721","unresolved":true,"context_lines":[{"line_number":94,"context_line":"    def do_setup(self, context):"},{"line_number":95,"context_line":"        super(NetAppNfsDriver, self).do_setup(context)"},{"line_number":96,"context_line":"        self._context \u003d context"},{"line_number":97,"context_line":"        cmode_utils.warn_insecure_netapp_transport_options("},{"line_number":98,"context_line":"            self.configuration)"},{"line_number":99,"context_line":"        if self.configuration.netapp_private_key_file or\\"},{"line_number":100,"context_line":"                self.configuration.netapp_certificate_file:"}],"source_content_type":"text/x-python","patch_set":9,"id":"69da63c9_c6702735","line":97,"updated":"2026-08-13 14:51:13.000000000","message":"This is the call to keep and its equivalents in block_base and nvme_libary - they do the work, which is now duplicated by `common.py:68`, which should be removed.","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"3beb0e57202a41fed584fa37484d8d736755cc31","unresolved":false,"context_lines":[{"line_number":94,"context_line":"    def do_setup(self, context):"},{"line_number":95,"context_line":"        super(NetAppNfsDriver, self).do_setup(context)"},{"line_number":96,"context_line":"        self._context \u003d context"},{"line_number":97,"context_line":"        cmode_utils.warn_insecure_netapp_transport_options("},{"line_number":98,"context_line":"            self.configuration)"},{"line_number":99,"context_line":"        if self.configuration.netapp_private_key_file or\\"},{"line_number":100,"context_line":"                self.configuration.netapp_certificate_file:"}],"source_content_type":"text/x-python","patch_set":9,"id":"51c0b264_cf0431c2","line":97,"in_reply_to":"69da63c9_c6702735","updated":"2026-08-14 06:32:20.000000000","message":"Done","commit_id":"40dd40672f5d9af0bb889ea5c55050e8f76cdb2a"}],"cinder/volume/drivers/netapp/options.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":79,"context_line":"                     \"verification. If not informed, the Mozilla Root \""},{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"},{"line_number":85,"context_line":"                      \u0027system will not be verified. This is useful when the \u0027"}],"source_content_type":"text/x-python","patch_set":8,"id":"cd118be9_ede927f0","line":82,"updated":"2026-08-12 15:46:44.000000000","message":"Two things on the new option:\n\n1. There is a startup warning for `netapp_transport_type \u003d http` but none for `netapp_ssl_cert_verify \u003d False`, which is the setting operators will actually reach for after this change (per the thread below on cert expiry). Both insecure choices deserve the same visible warning.\n\n2. \"Applies to both the REST and legacy ZAPI clients\" is accurate for basic auth but not for the client-certificate paths - see the comment on api.py:322","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":79,"context_line":"                     \"verification. If not informed, the Mozilla Root \""},{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"},{"line_number":85,"context_line":"                      \u0027system will not be verified. This is useful when the \u0027"}],"source_content_type":"text/x-python","patch_set":8,"id":"82453877_5847595e","line":82,"in_reply_to":"cd118be9_ede927f0","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":36171,"name":"jayaanand borra","display_name":"jayaanand borra","email":"jayaanand.borra@netapp.com","username":"jayaanan","status":"netapp"},"change_message_id":"7aafca763e7f52bd4242999b550c6cb2aa5bdcb5","unresolved":true,"context_lines":[{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"},{"line_number":85,"context_line":"                      \u0027system will not be verified. This is useful when the \u0027"},{"line_number":86,"context_line":"                      \u0027storage system uses a self-signed certificate. \u0027"}],"source_content_type":"text/x-python","patch_set":8,"id":"003a2d12_a626c3de","line":83,"updated":"2026-08-06 04:05:55.000000000","message":"this is disruptive operation...In case of certificate expiry entire data-center provisioning operations are blocked? Is this fine","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"583848b588e637001b78d4ca5c935a7550a91acf","unresolved":false,"context_lines":[{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"},{"line_number":85,"context_line":"                      \u0027system will not be verified. This is useful when the \u0027"},{"line_number":86,"context_line":"                      \u0027storage system uses a self-signed certificate. \u0027"}],"source_content_type":"text/x-python","patch_set":8,"id":"99210a7e_e9cdb49a","line":83,"in_reply_to":"003a2d12_a626c3de","updated":"2026-08-06 12:20:32.000000000","message":"Yes. In that case, user can set the ssl_cert_verify to false. As the description already warns about setting it to false. Atleast, that would be a known risk that the user is taking and betters the security stance. If the certificate is forged using man in the middle attack, ssl_cert_verify\u003dTrue ensures that such forged certificates are not accepted.","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"f93590d5c2ef902185df97eed0918429a89506d6","unresolved":true,"context_lines":[{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"},{"line_number":85,"context_line":"                      \u0027system will not be verified. This is useful when the \u0027"},{"line_number":86,"context_line":"                      \u0027storage system uses a self-signed certificate. \u0027"}],"source_content_type":"text/x-python","patch_set":8,"id":"8f6950ce_85aca47d","line":83,"in_reply_to":"003a2d12_a626c3de","updated":"2026-08-06 12:37:33.000000000","message":"Yes. In that case, user can set the ssl_cert_verify to false. As the description says","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"},{"line_number":85,"context_line":"                      \u0027system will not be verified. This is useful when the \u0027"},{"line_number":86,"context_line":"                      \u0027storage system uses a self-signed certificate. \u0027"}],"source_content_type":"text/x-python","patch_set":8,"id":"feae857d_7c102d87","line":83,"in_reply_to":"8f6950ce_85aca47d","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"86f8fa72f3b4604444ac302e11aeb5a980948c12","unresolved":true,"context_lines":[{"line_number":78,"context_line":"                     \"used as the trust anchor for HTTPS certificate \""},{"line_number":79,"context_line":"                     \"verification. If not informed, the Mozilla Root \""},{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"}],"source_content_type":"text/x-python","patch_set":11,"id":"2eaf3164_7f1365f5","line":81,"updated":"2026-08-17 17:11:43.000000000","message":"`netapp_ssl_cert_path` is only consulted for username/password authentication, so \"Applies to both REST and legacy ZAPI clients\" is still an overclaim for certificate-auth backends.\n\nWith client certificates configured, neither client ever looks at this option: `NaServer._build_session` takes its trust anchor from `_ca_certificate_file` at api.py:323-328, and `RestNaServer._create_certificate_auth_handler` does the same at api.py:861-869. `_ssl_cert_path` / `_ssl_verify-as-path` is only reached in the basic-auth branches. So an operator who configures `netapp_private_key_file` + `netapp_certificate_file` and sets `netapp_ssl_cert_path` gets no error and no effect — the option is silently ignored.\n\nSuggest replacing the last sentence with something like:\n\n```\n\"Certificates are used by default. Applies to both \"\n\"REST and legacy ZAPI clients when using username and \"\n\"password authentication; with certificate \"\n\"authentication the trust anchor is \"\n\"netapp_ca_certificate_file instead.\")),\n```\nWorth doing in this patch rather than as a follow-up, because PS11 copied this help text verbatim into the two new config-table rows — `cinder-netapp_cdot_iscsi.inc:32` and `cinder-netapp_cdot_nfs.inc:34` — so the claim now appears in three places. Those two lines need the same edit.\n\nDocs-only, no functional consequence — feel free to defer if you\u0027d rather not respin for it, but the fix is three one-line edits.","commit_id":"ba818871aacaccc83fc03fa6bf1a965425dfdfee"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"62dd5cfc9274cd6b2e951109d6108dbf09f2d3c4","unresolved":true,"context_lines":[{"line_number":78,"context_line":"                     \"used as the trust anchor for HTTPS certificate \""},{"line_number":79,"context_line":"                     \"verification. If not informed, the Mozilla Root \""},{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"}],"source_content_type":"text/x-python","patch_set":11,"id":"d3f45639_89d76e85","line":81,"in_reply_to":"2eaf3164_7f1365f5","updated":"2026-08-18 09:37:54.000000000","message":"Agreed — netapp_ssl_cert_path is only consulted on the username/password auth paths; cert-auth backends use netapp_ca_certificate_file for the trust anchor. PS12 scopes the help text in options.py and the two .inc rows as you suggested. Thanks for catching that before merge.","commit_id":"ba818871aacaccc83fc03fa6bf1a965425dfdfee"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"a42e5e2363caa90f72a239c2c854e57c283e7fbb","unresolved":false,"context_lines":[{"line_number":78,"context_line":"                     \"used as the trust anchor for HTTPS certificate \""},{"line_number":79,"context_line":"                     \"verification. If not informed, the Mozilla Root \""},{"line_number":80,"context_line":"                     \"Certificates are used by default. Applies to both \""},{"line_number":81,"context_line":"                     \"REST and legacy ZAPI clients.\")),"},{"line_number":82,"context_line":"    cfg.BoolOpt(\u0027netapp_ssl_cert_verify\u0027,"},{"line_number":83,"context_line":"                default\u003dTrue,"},{"line_number":84,"context_line":"                help\u003d(\u0027If set to False, the SSL certificate of the storage \u0027"}],"source_content_type":"text/x-python","patch_set":11,"id":"82998d23_3ce373ed","line":81,"in_reply_to":"d3f45639_89d76e85","updated":"2026-08-18 09:38:13.000000000","message":"Done","commit_id":"ba818871aacaccc83fc03fa6bf1a965425dfdfee"}],"doc/source/configuration/tables/cinder-netapp_cdot_iscsi.inc":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"0660893cef40c6ec36c4dfadec5af2f4622b8806","unresolved":true,"context_lines":[{"line_number":34,"context_line":"     - (String) The storage protocol to be used on the data path with the storage system."},{"line_number":35,"context_line":"   * - ``netapp_transport_type`` \u003d ``https``"},{"line_number":36,"context_line":"     - (String) The transport protocol used when communicating with the storage system or proxy server."},{"line_number":37,"context_line":"   * - ``netapp_ssl_cert_verify`` \u003d ``True``"},{"line_number":38,"context_line":"     - (Boolean) If set to False, the SSL certificate of the storage system will not be verified."},{"line_number":39,"context_line":"   * - ``netapp_vserver`` \u003d ``None``"},{"line_number":40,"context_line":"     - (String) This option specifies the virtual storage server (Vserver) name on the storage cluster on which provisioning of block storage volumes should occur."}],"source_content_type":"text/x-c++src","patch_set":10,"id":"10d2e19e_9393cec8","line":37,"updated":"2026-08-14 13:48:53.000000000","message":"not in alphabetic order - move to between `netapp_snapmirror_quiesce_timeout` and `netapp_storage_family`.\nAlso `netapp_ssl_cert_path` is completely missing from this table.","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"7210de46872582237c9d84743acb21966a761397","unresolved":false,"context_lines":[{"line_number":34,"context_line":"     - (String) The storage protocol to be used on the data path with the storage system."},{"line_number":35,"context_line":"   * - ``netapp_transport_type`` \u003d ``https``"},{"line_number":36,"context_line":"     - (String) The transport protocol used when communicating with the storage system or proxy server."},{"line_number":37,"context_line":"   * - ``netapp_ssl_cert_verify`` \u003d ``True``"},{"line_number":38,"context_line":"     - (Boolean) If set to False, the SSL certificate of the storage system will not be verified."},{"line_number":39,"context_line":"   * - ``netapp_vserver`` \u003d ``None``"},{"line_number":40,"context_line":"     - (String) This option specifies the virtual storage server (Vserver) name on the storage cluster on which provisioning of block storage volumes should occur."}],"source_content_type":"text/x-c++src","patch_set":10,"id":"727aa1cc_9cc0c2a8","line":37,"in_reply_to":"10d2e19e_9393cec8","updated":"2026-08-17 08:31:59.000000000","message":"Done","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"}],"doc/source/configuration/tables/cinder-netapp_cdot_nfs.inc":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"0660893cef40c6ec36c4dfadec5af2f4622b8806","unresolved":true,"context_lines":[{"line_number":36,"context_line":"     - (String) The storage protocol to be used on the data path with the storage system."},{"line_number":37,"context_line":"   * - ``netapp_transport_type`` \u003d ``https``"},{"line_number":38,"context_line":"     - (String) The transport protocol used when communicating with the storage system or proxy server."},{"line_number":39,"context_line":"   * - ``netapp_ssl_cert_verify`` \u003d ``True``"},{"line_number":40,"context_line":"     - (Boolean) If set to False, the SSL certificate of the storage system will not be verified."},{"line_number":41,"context_line":"   * - ``netapp_vserver`` \u003d ``None``"},{"line_number":42,"context_line":"     - (String) This option specifies the virtual storage server (Vserver) name on the storage cluster on which provisioning of block storage volumes should occur."}],"source_content_type":"text/x-c++src","patch_set":10,"id":"8168e6e7_6f11c88f","line":39,"updated":"2026-08-14 13:48:53.000000000","message":"Same here - wrong location and missing paramter","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"7210de46872582237c9d84743acb21966a761397","unresolved":false,"context_lines":[{"line_number":36,"context_line":"     - (String) The storage protocol to be used on the data path with the storage system."},{"line_number":37,"context_line":"   * - ``netapp_transport_type`` \u003d ``https``"},{"line_number":38,"context_line":"     - (String) The transport protocol used when communicating with the storage system or proxy server."},{"line_number":39,"context_line":"   * - ``netapp_ssl_cert_verify`` \u003d ``True``"},{"line_number":40,"context_line":"     - (Boolean) If set to False, the SSL certificate of the storage system will not be verified."},{"line_number":41,"context_line":"   * - ``netapp_vserver`` \u003d ``None``"},{"line_number":42,"context_line":"     - (String) This option specifies the virtual storage server (Vserver) name on the storage cluster on which provisioning of block storage volumes should occur."}],"source_content_type":"text/x-c++src","patch_set":10,"id":"f1bbb429_35cf43f3","line":39,"in_reply_to":"8168e6e7_6f11c88f","updated":"2026-08-17 08:31:59.000000000","message":"Done","commit_id":"e4b6a1fc0beac9614d042887282270e4be0944a3"}],"releasenotes/notes/netapp-https-default-2157914.yaml":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"11f99347090ea93d6750b83e468f34907432f036","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"security:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    NetApp ONTAP client defaults now use HTTPS transport by default for both"},{"line_number":5,"context_line":"    REST and legacy ZAPI paths."}],"source_content_type":"text/x-yaml","patch_set":8,"id":"c0c747f5_1a445d5e","line":2,"updated":"2026-08-12 15:46:44.000000000","message":"This needs an `upgrade:` section alongside `security:`. `netapp_use_legacy_client` defaults to `True`, so ZAPI is the default client path, and that path previously did `verify \u003d ssl_cert_path` if `isinstance(str) else False` — i.e. no verification at all. After this change the default is HTTPS plus verification against the Mozilla roots. ONTAP ships with a self-signed certificate out of the box, so for most existing deployments the driver will stop connecting on upgrade until the operator either sets `netapp_ssl_cert_verify \u003d False` or installs a real CA chain.\n\nA second, narrower break: anyone who explicitly set `netapp_server_port \u003d 80` while relying on the old `http` default will now attempt HTTPS against port 80.\n\nNeither is a reason not to do this, but both are action-required items that operators need to read before upgrading, not discover from a failed `do_setup`. \nI\u0027d suggest an `upgrade:` section naming both cases and the exact config to set.","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"acf7001118b2fdb565033cf6bd9154dba125b994","unresolved":false,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"security:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    NetApp ONTAP client defaults now use HTTPS transport by default for both"},{"line_number":5,"context_line":"    REST and legacy ZAPI paths."}],"source_content_type":"text/x-yaml","patch_set":8,"id":"c4ac601f_91ff2cc1","line":2,"in_reply_to":"c0c747f5_1a445d5e","updated":"2026-08-13 14:53:36.000000000","message":"Done","commit_id":"9688c220979de542ff9183b8aeaf5c72769e015e"}]}
