)]}'
{"id":"openstack%2Fcyborg~700568","triplet_id":"openstack%2Fcyborg~master~Ia1f9acbbd176180cb5fe97b1a2eee5f98a95dea6","project":"openstack/cyborg","branch":"master","topic":"security_check_with_bandit","hashtags":[],"change_id":"Ia1f9acbbd176180cb5fe97b1a2eee5f98a95dea6","subject":"Introduce bandit security linter","status":"MERGED","created":"2019-12-25 10:32:09.000000000","updated":"2020-01-14 04:01:24.000000000","submitted":"2020-01-14 03:58:49.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":6,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"700568-1578974329907-a981c286","meta_rev_id":"d10aadf1716aacf151f8834799eb6d96230ae79d","_number":700568,"virtual_id_number":700568,"owner":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},{"value":0,"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"value":0,"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"value":0,"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"value":0,"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2020-01-14 03:58:49.000000000","post_submit":true,"permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},"recommended":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"all":[{"value":1,"date":"2020-01-07 04:50:22.000000000","permitted_voting_range":{"min":1,"max":2},"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},{"value":0,"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"value":2,"date":"2020-01-14 03:28:38.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"value":0,"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"value":2,"date":"2020-01-07 02:01:16.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},"all":[{"value":0,"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},{"value":0,"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"value":1,"date":"2020-01-14 03:28:38.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"value":0,"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"value":0,"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2020-01-04 01:58:17.000000000","updated_by":{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},"reviewer":{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},"state":"REVIEWER"},{"updated":"2020-01-07 02:01:16.000000000","updated_by":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"reviewer":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"state":"REVIEWER"},{"updated":"2020-01-07 04:50:22.000000000","updated_by":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"reviewer":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"state":"REVIEWER"},{"updated":"2020-01-14 03:28:38.000000000","updated_by":{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},"reviewer":{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},"state":"REVIEWER"},{"updated":"2020-01-14 03:58:49.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"9b705731bb3dcb138f9e6bf01a6c3ead4536f714","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2019-12-25 10:32:09.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"fcfe8fb32d603255e5be164ebbbaf7e2ecffc8c0","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-12-25 11:31:07.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- build-openstack-api-ref https://zuul.opendev.org/t/openstack/build/4e8276b08e5a4b65892615f12f28fee0 : SUCCESS in 3m 16s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/754ffff7fe5c4313bcc3eeb261a36611 : SUCCESS in 3m 57s\n- requirements-check https://zuul.opendev.org/t/openstack/build/7bb7ba536d46426eab2748b921b88a8b : SUCCESS in 2m 26s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/675aa990252143b0aee8b39624f09ed2 : SUCCESS in 3m 22s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/92dcb7f225a546d2993b37dac3a63165 : SUCCESS in 3m 20s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/764359c0835e4fefb0d5d1b69eb172a3 : SUCCESS in 5m 26s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/52ff1fa18ac142828e9ff445554941f9 : SUCCESS in 3m 50s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d5f2ca3c2a89460fbfa1a5ca01aacc2a : SUCCESS in 3m 54s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/1dc4f97aa30449f9ba39806f4bf7ef3c : SUCCESS in 30m 03s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/33bf6df719364937a097ed796c8d8154 : SUCCESS in 29m 58s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/8898887649ba4e3680a40b0a9cf7003a : FAILURE in 3m 35s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"a3aa82f3ec04890c4342fa20107e0283443a4828","author":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"date":"2019-12-26 02:11:22.000000000","message":"Patch Set 1:\n\nUsing static analysis for security is a good idea. Also, other projects like Nova are using bandit [1]. However, I have some questions whether bandit is the best tool for the job, and whether we should investigate other tools.\n\n* Bandit may apparently generate many false positives [1], i.e., report issues that don\u0027t exist. In fact, there is evidence that Nova hit that issue [3]. One can apparently suppress false positives using \u0027# nosec\u0027 comments, but:\n  * that still requires some developer thought and discussion for that, and\n  * #nosec can suppress real issues, as [2] says.\n\n* There are alternatives like pysa from Facebook [4]. Has anybody looked into that? It works differently: while bandit uses AST, pysa uses control/data flow graphs, which can be more accurate. \n\n[1] https://github.com/openstack/nova/blob/14872caae1a51c7015dd7c509d0173df2e943ed4/tox.ini#L215\n[2] https://smarketshq.com/avoiding-injection-with-taint-analysis-1e55429e207b\n[3] https://bugs.launchpad.net/nova/+bug/1701712\n[4] https://pyre-check.org/docs/pysa-basics.html","accounts_in_message":[],"_revision_number":1},{"id":"c35f260b12aca7be4f41e70bb6dae463eac78941","author":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"date":"2019-12-26 02:24:35.000000000","message":"Patch Set 1:\n\n\u003e * Bandit may apparently generate many false positives [1], i.e.,\n\nOops, meant [2].\n\n \u003e [2] https://smarketshq.com/avoiding-injection-with-taint-analysis-1e55429e207b","accounts_in_message":[],"_revision_number":1},{"id":"4edbf308d5ed960870d0828808e2e5b196ff22b3","author":{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},"date":"2019-12-26 07:00:10.000000000","message":"Patch Set 1: Code-Review-1\n\n\u003e Using static analysis for security is a good idea. Also, other\n \u003e projects like Nova are using bandit [1]. However, I have some\n \u003e questions whether bandit is the best tool for the job, and whether\n \u003e we should investigate other tools.\n \u003e \n \u003e * Bandit may apparently generate many false positives [1], i.e.,\n \u003e report issues that don\u0027t exist. In fact, there is evidence that\n \u003e Nova hit that issue [3]. One can apparently suppress false\n \u003e positives using \u0027# nosec\u0027 comments, but:\n \u003e * that still requires some developer thought and discussion for\n \u003e that, and\n \u003e * #nosec can suppress real issues, as [2] says.\n \u003e \n \u003e * There are alternatives like pysa from Facebook [4]. Has anybody\n \u003e looked into that? It works differently: while bandit uses AST, pysa\n \u003e uses control/data flow graphs, which can be more accurate.\n \u003e \n \u003e [1] https://github.com/openstack/nova/blob/14872caae1a51c7015dd7c509d0173df2e943ed4/tox.ini#L215\n \u003e [2] https://smarketshq.com/avoiding-injection-with-taint-analysis-1e55429e207b\n \u003e [3] https://bugs.launchpad.net/nova/+bug/1701712\n \u003e [4] https://pyre-check.org/docs/pysa-basics.html\n\nHi Sundar, I think add a tool to check the code and make the code more security, or ever not more security just make the code more standard, is always a good thing.\n\n-1 is to the setting, checked the log, the tests files didn\u0027t been ingored, should setting like below to ingore the tests files:\ncommands \u003d bandit -r cyborg -x cyborg/tests/* -n 5 -ll","accounts_in_message":[],"_revision_number":1},{"id":"9dd44ec8c02a38e9728a02f1310215070480feb6","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2019-12-26 09:21:14.000000000","message":"Topic set to security_check_with_bandit","accounts_in_message":[],"_revision_number":1},{"id":"3b0a134c27644a3e4f76c233d56d773da5738bb2","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2019-12-30 06:16:15.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"f92c114c7f2526cf78e22c924456be08d34139d5","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-12-30 07:12:20.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- build-openstack-api-ref https://zuul.opendev.org/t/openstack/build/41b956f9ddc344cfaabb058f26ffa78a : SUCCESS in 5m 34s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/b0ac614e6eea4b7b888186dbb388ea86 : SUCCESS in 8m 33s\n- requirements-check https://zuul.opendev.org/t/openstack/build/8888a7ef542a4845b4dfc39f6e5911b7 : SUCCESS in 5m 18s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d5a11e6c1b76487a8c4fd20c33a39ecd : SUCCESS in 5m 32s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/f7cb9849dba64a5c9ea0062ee74f8e8e : SUCCESS in 7m 52s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/e50737c55227497a93e060ce6b5b966c : SUCCESS in 7m 19s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/1b5627e78d084382b7cccc9ef59367c6 : SUCCESS in 8m 07s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/411f93bca19d4d1a814f4923d092af68 : SUCCESS in 5m 58s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/2ef0a0d801e54f6c9b94c9c3c747861e : SUCCESS in 34m 15s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/028c03b330af4a1ebcd636d9928a537c : SUCCESS in 50m 50s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/4065dbef6dab4eaaa11e08a9209afe7e : FAILURE in 5m 57s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"20f2323f7632d2d92c63360980d8b5e5e9a036f3","author":{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},"date":"2020-01-02 01:34:05.000000000","message":"Patch Set 2: Code-Review+1","accounts_in_message":[],"_revision_number":2},{"id":"83cbdd9ac9f920305083b81123717b8d0d15e20f","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-01-03 03:29:56.000000000","message":"Patch Set 2: Code-Review-1\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"19413832c734614f97d41164de0c8e529b1251c6","author":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"date":"2020-01-03 06:56:16.000000000","message":"Patch Set 2:\n\n\u003e Hi Sundar, I think add a tool to check the code and make the code\n \u003e more security, or ever not more security just make the code more\n \u003e standard, is always a good thing.\n\nOf course, security is good. My question was, whether bandit is the best tool for that. No objections if everybody else agrees to it, or there is no data to choose a better tool.","accounts_in_message":[],"_revision_number":2},{"id":"fad53a295cd6dbb6c63736a61b8c6547ee1d67de","author":{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},"date":"2020-01-04 01:58:17.000000000","message":"Patch Set 2: -Code-Review","accounts_in_message":[],"_revision_number":2},{"id":"933429435dae4bd11bd0905d3ebf6b33b6d88b74","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-01-06 03:49:54.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"f62cd55ecd0db1482df873e16348775d5bd8e89c","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-01-06 03:51:43.000000000","message":"Patch Set 2:\n\n(3 comments)\n\nThanks chenker for the review!\npls see the update.","accounts_in_message":[],"_revision_number":2},{"id":"9708df77149cda6c847055d2b6baeec373c23848","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-01-06 04:26:07.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- build-openstack-api-ref https://zuul.opendev.org/t/openstack/build/3ea5f0aad84b43f196f6c19fded40393 : SUCCESS in 3m 33s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/38f7539e5c2146e397642f97cb7efa4b : SUCCESS in 3m 58s\n- requirements-check https://zuul.opendev.org/t/openstack/build/9b212ebaa56f427583babfd4db62b02e : SUCCESS in 2m 42s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/5600324ec71940dea60f722b70eb282b : SUCCESS in 3m 32s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/795392f282da4f2583cd6f4dccdbb5b0 : SUCCESS in 4m 04s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/0b3fe800900641478fddbe858d840aa5 : SUCCESS in 3m 36s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/7b0c2e3ea8e146d39928b68a09f73be1 : SUCCESS in 3m 56s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a293ffc61dee458982ea2b03821eb8a4 : SUCCESS in 3m 46s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/9536d9cc374747d480e2f6a5a2e93f9a : SUCCESS in 29m 33s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/11c8075c9e03439d92f7b9e50f44b5bc : SUCCESS in 31m 08s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/9e74cf41167e4a2d945d1d02bf4c14c0 : FAILURE in 3m 22s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"89f12bd93b159eccd35982eeef5390eff8f788bd","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-01-06 06:44:02.000000000","message":"Patch Set 2:\n\n\u003e Using static analysis for security is a good idea. Also, other\n \u003e projects like Nova are using bandit [1]. However, I have some\n \u003e questions whether bandit is the best tool for the job, and whether\n \u003e we should investigate other tools.\n \u003e \n \u003e * Bandit may apparently generate many false positives [1], i.e.,\n \u003e report issues that don\u0027t exist. In fact, there is evidence that\n \u003e Nova hit that issue [3]. One can apparently suppress false\n \u003e positives using \u0027# nosec\u0027 comments, but:\n \u003e * that still requires some developer thought and discussion for\n \u003e that, and\n \u003e * #nosec can suppress real issues, as [2] says.\n \u003e \n \u003e * There are alternatives like pysa from Facebook [4]. Has anybody\n \u003e looked into that? It works differently: while bandit uses AST, pysa\n \u003e uses control/data flow graphs, which can be more accurate.\n \u003e \n \u003e [1] https://github.com/openstack/nova/blob/14872caae1a51c7015dd7c509d0173df2e943ed4/tox.ini#L215\n \u003e [2] https://smarketshq.com/avoiding-injection-with-taint-analysis-1e55429e207b\n \u003e [3] https://bugs.launchpad.net/nova/+bug/1701712\n \u003e [4] https://pyre-check.org/docs/pysa-basics.html\n\nHi Sundar, not yet looked into other tools except bandit.\nseems pysa also does type check, as is said on its official page: \"Pyre is a fast, scalable type checker for large Python 3 codebases, designed to help improve code quality and development speed by flagging type errors interactively in your terminal or favorite editor. We follow the typing standards introduced in PEP484 and PEP526.\" Will be that too much for us? It\u0027s an urgent need to have a security check before production usage of cyborg. Bandit is simple and makes sense.","accounts_in_message":[],"_revision_number":2},{"id":"9734ec89e30e554db56e8a716bf651217d2a48d9","author":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"date":"2020-01-06 23:03:37.000000000","message":"Patch Set 3:\n\n\u003e Hi Sundar, not yet looked into other tools except bandit.\n\nOK\n\n \u003e seems pysa also does type check, as is said on its official page:\n \u003e ...\n \u003e  Will be that too much for us? \n\nMy understanding is pyre does type checking but pysa is a subset that only does static analysis. \n\nLooks like none of us have experience or done studies on alternatives. So, let\u0027s go with bandit for now.","accounts_in_message":[],"_revision_number":3},{"id":"dbe154d9b9fb93425c9ee16f6215d843dd86abcd","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-01-07 02:01:16.000000000","message":"Patch Set 3: Code-Review+2\n\nYe. Let\u0027s go with bandit check. if there is a better one in the future, we can introduce it again.","accounts_in_message":[],"_revision_number":3},{"id":"ab4c19c60f6b117a46642baed7ea13e5fa76216a","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-01-07 02:31:52.000000000","message":"Patch Set 3:\n\nrecheck","accounts_in_message":[],"_revision_number":3},{"id":"56d7baccaa92a4be6db974508c6221fc8361c029","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-01-07 03:08:53.000000000","message":"Patch Set 3:\n\nBuild succeeded (check pipeline).\n\n- build-openstack-api-ref https://zuul.opendev.org/t/openstack/build/63ca331eb04b4fca8c91c004839c975b : SUCCESS in 5m 09s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/76f9185421dd47ea82be0ca9221bbada : SUCCESS in 5m 04s\n- requirements-check https://zuul.opendev.org/t/openstack/build/a312eccbcf624119bd8a7cf9586bb843 : SUCCESS in 3m 07s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/22b6907651ef450bb09e50fac763b858 : SUCCESS in 4m 00s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/9e64fa5b82a74ac89d02888eec3eaf59 : SUCCESS in 3m 27s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/ca31f9f060c6452d9fbedc059da6bb23 : SUCCESS in 3m 31s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/305689f17da3441483335f333fcc3641 : SUCCESS in 4m 16s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a42a9c24c4464d1a82e36a2aeb86144b : SUCCESS in 4m 25s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/bd805720da3a48a28d808a3f97634a12 : SUCCESS in 28m 57s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/86627fee0fcc469d801a3b11b9f48fd0 : SUCCESS in 31m 48s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/9c38829b11dc4901af7524d6dbb12825 : FAILURE in 3m 48s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"40144ea24798b2c15e873ec984cad163fd31c0dc","author":{"_account_id":21672,"name":"Sundar Nadathur","email":"sundar.nadathur@intel.com","username":"nsundar"},"date":"2020-01-07 04:50:22.000000000","message":"Patch Set 3: Code-Review+1\n\nLet others also review.","accounts_in_message":[],"_revision_number":3},{"id":"d201450742eebfe0675d47283e414cd8368215da","author":{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},"date":"2020-01-14 03:28:38.000000000","message":"Patch Set 3: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":3},{"id":"3c20235b455181a82dbb88107895fc66fee357bb","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-01-14 03:28:52.000000000","message":"Patch Set 3: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":3},{"id":"96370e1d8ef6cef696db2e12b54a0ac839113958","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-01-14 03:58:49.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":3},{"id":"24eb2428778f39aa99ceaf215822324102f48239","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-01-14 03:58:49.000000000","message":"Patch Set 3: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- build-openstack-api-ref https://zuul.opendev.org/t/openstack/build/3188ed64219d4e859cfdc2e6b419a065 : SUCCESS in 3m 49s\n- requirements-check https://zuul.opendev.org/t/openstack/build/5d6027ac01094efd8537332d8b19e47a : SUCCESS in 4m 36s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/08635e1ce5c84cb582a2379c9dfcafdd : SUCCESS in 6m 34s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/705ea358ff20459381b393efca9b2e7f : SUCCESS in 4m 14s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/a8f977c3bd44453eaec8588151b40de8 : SUCCESS in 6m 06s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/e0275382375d4f798e6636a96aa6d815 : SUCCESS in 3m 43s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/085d1d5c24b6497eb13681f00ca61cfb : SUCCESS in 6m 27s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/d9bec1b1a714427aa6d8920111f7c28b : SUCCESS in 28m 38s","accounts_in_message":[],"_revision_number":3},{"id":"d10aadf1716aacf151f8834799eb6d96230ae79d","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-01-14 04:01:24.000000000","message":"Patch Set 3:\n\nBuild succeeded (promote pipeline).\n\n- promote-api-ref https://zuul.opendev.org/t/openstack/build/43ac4237786840f18823fa1a772e2fb5 : SUCCESS in 1m 03s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/be81446493e048c0aca118a01f284c92 : SUCCESS in 1m 09s\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/fec8979ff1ab4982a973ac3f1ccb82fe : SUCCESS in 1m 33s","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"d765a344ee54b08791ab06149f3e1652e456ac06","revisions":{"119dfda82cf5094278677b09be170cb3ce645c4c":{"kind":"REWORK","_number":1,"created":"2019-12-25 10:32:09.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/68/700568/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/68/700568/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/68/700568/1"}}},"commit":{"parents":[{"commit":"98539c70cd8335284a370189d6e258500419bbbf","subject":"Merge \"Remove \u0027base object\u0027 that no longer exist\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/98539c70cd8335284a370189d6e258500419bbbf"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2019-12-25 10:07:23.000000000","tz":-480},"committer":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2019-12-25 10:07:23.000000000","tz":-480},"subject":"Introduce bandit security linter","message":"Introduce bandit security linter\n\nCyborg now does not have a code security check, which may connive at\npossible security issues. For example, shell-related operations for drivers\nmay be insecure. Current \"sudo lspci -nnn -D\" in huawei ascend driver code[0]\nis insecure, but there is no any job/test that can check the potential security\nissues. So this patch introduces bandit as a code security check.\n\n[0]:https://github.com/openstack/cyborg/blob/master/cyborg/accelerator/drivers/aichip/huawei/ascend.py#L69\n\nChange-Id: Ia1f9acbbd176180cb5fe97b1a2eee5f98a95dea6\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/119dfda82cf5094278677b09be170cb3ce645c4c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/119dfda82cf5094278677b09be170cb3ce645c4c"}]},"branch":"refs/heads/master"},"d37b0f8288bd36f7312f2d01b507b8e19bf10a94":{"kind":"REWORK","_number":2,"created":"2019-12-30 06:16:15.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/68/700568/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/68/700568/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/68/700568/2"}}},"commit":{"parents":[{"commit":"f361adf39f46da9a06b1c7ef0fe0c5a6440817dd","subject":"Merge \"Modify api-paste.ini v1 to v2\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/f361adf39f46da9a06b1c7ef0fe0c5a6440817dd"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2019-12-25 10:07:23.000000000","tz":-480},"committer":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2019-12-30 06:15:57.000000000","tz":-480},"subject":"Introduce bandit security linter","message":"Introduce bandit security linter\n\nCyborg now does not have a code security check, which may connive at\npossible security issues. For example, shell-related operations for drivers\nmay be insecure. Current \"sudo lspci -nnn -D\" in huawei ascend driver code[0]\nis insecure, but there is no any job/test that can check the potential security\nissues. So this patch introduces bandit as a code security check.\n\n[0]:https://github.com/openstack/cyborg/blob/master/cyborg/accelerator/drivers/aichip/huawei/ascend.py#L69\n\nChange-Id: Ia1f9acbbd176180cb5fe97b1a2eee5f98a95dea6\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/d37b0f8288bd36f7312f2d01b507b8e19bf10a94"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/d37b0f8288bd36f7312f2d01b507b8e19bf10a94"}]},"branch":"refs/heads/master"},"d765a344ee54b08791ab06149f3e1652e456ac06":{"kind":"REWORK","_number":3,"created":"2020-01-06 03:49:54.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/68/700568/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/68/700568/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/68/700568/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/68/700568/3"}}},"commit":{"parents":[{"commit":"7fd8aac788c008cc288c68f723eccb64952c09a2","subject":"Merge \"Improve objects/device.py UT coverage from 82% to 100%\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/7fd8aac788c008cc288c68f723eccb64952c09a2"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2019-12-25 10:07:23.000000000","tz":-480},"committer":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-01-06 03:49:22.000000000","tz":-480},"subject":"Introduce bandit security linter","message":"Introduce bandit security linter\n\nCyborg now does not have a code security check, which may connive at\npossible security issues. For example, shell-related operations for drivers\nmay be insecure. Current \"sudo lspci -nnn -D\" in huawei ascend driver code[0]\nis insecure, but there is no any job/test that can check the potential security\nissues. So this patch introduces bandit as a code security check.\n\n[0]:https://github.com/openstack/cyborg/blob/master/cyborg/accelerator/drivers/aichip/huawei/ascend.py#L69\n\nChange-Id: Ia1f9acbbd176180cb5fe97b1a2eee5f98a95dea6\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/d765a344ee54b08791ab06149f3e1652e456ac06"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/d765a344ee54b08791ab06149f3e1652e456ac06"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
