)]}'
{"id":"openstack%2Fcyborg~750273","triplet_id":"openstack%2Fcyborg~master~I3d1620ed66221873fbe5ea5a3b703395664072e2","project":"openstack/cyborg","branch":"master","topic":"policy-popup","hashtags":[],"change_id":"I3d1620ed66221873fbe5ea5a3b703395664072e2","subject":"Add new default roles in Device Profile API policies","status":"MERGED","created":"2020-09-08 04:00:03.000000000","updated":"2020-09-16 02:26:08.000000000","submitted":"2020-09-16 02:24:57.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":24,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"750273-1600223097489-b2ad87a5","meta_rev_id":"c5c66f936f3384b3cd6dc17823eb17187fb0cd92","_number":750273,"virtual_id_number":750273,"owner":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"value":0,"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},{"value":0,"_account_id":17813,"name":"wangzhh","email":"wzh_1993@126.com","username":"wangzhh"},{"value":0,"date":"2020-09-15 10:32:50.000000000","_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"value":0,"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"value":0,"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"value":0,"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2020-09-16 02:24:57.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"all":[{"value":0,"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"value":0,"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},{"value":0,"_account_id":17813,"name":"wangzhh","email":"wzh_1993@126.com","username":"wangzhh"},{"value":0,"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"value":2,"date":"2020-09-15 01:17:22.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"value":0,"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"value":0,"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2020-09-14 09:06:49.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"all":[{"value":0,"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"value":0,"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},{"value":0,"_account_id":17813,"name":"wangzhh","email":"wzh_1993@126.com","username":"wangzhh"},{"value":0,"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"value":0,"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"value":0,"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"value":0,"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":1,"date":"2020-09-15 06:01:10.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},{"_account_id":17813,"name":"wangzhh","email":"wzh_1993@126.com","username":"wangzhh"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2020-09-09 01:12:52.000000000","updated_by":{"_account_id":17813,"name":"wangzhh","email":"wzh_1993@126.com","username":"wangzhh"},"reviewer":{"_account_id":17813,"name":"wangzhh","email":"wzh_1993@126.com","username":"wangzhh"},"state":"REVIEWER"},{"updated":"2020-09-10 09:42:48.000000000","updated_by":{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},"reviewer":{"_account_id":14107,"name":"zhurong","email":"aaronzhu1121@gmail.com","username":"zhurong"},"state":"REVIEWER"},{"updated":"2020-09-10 09:42:55.000000000","updated_by":{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},"reviewer":{"_account_id":25738,"name":"Xinran WANG","email":"xin-ran.wang@intel.com","username":"Xinran"},"state":"REVIEWER"},{"updated":"2020-09-10 19:41:30.000000000","updated_by":{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},"reviewer":{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},"state":"REVIEWER"},{"updated":"2020-09-11 08:40:54.000000000","updated_by":{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},"reviewer":{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},"state":"REVIEWER"},{"updated":"2020-09-15 01:17:22.000000000","updated_by":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"reviewer":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"state":"REVIEWER"},{"updated":"2020-09-15 06:01:10.000000000","updated_by":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"reviewer":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"state":"REVIEWER"},{"updated":"2020-09-16 02:24:57.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"4442abdd1505dca395c84f7cf287470d9d2fca17","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-08 04:00:03.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"cd02ebdbb2c8a736c48c0b5d1145be0d71842d9c","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-08 04:01:00.000000000","message":"Topic set to policy-popup","accounts_in_message":[],"_revision_number":1},{"id":"1819b084b9837a500f81b2a868bda2b6490a2485","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-08 04:31:18.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/a3855563cfc24f8f918da86e9ed5fb12 : SUCCESS in 4m 46s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a716c345c6dc49a699fbc26f4ad06574 : SUCCESS in 5m 27s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/88c21c076a8d486a902d91bafb763056 : SUCCESS in 3m 16s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/d925e193bdcb4cc685e6a421b3bc871a : SUCCESS in 4m 08s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/7ac9d2da8abc4859b5cb57ba905125e3 : SUCCESS in 5m 48s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/13ea2c16011c496fbe398680d3015b29 : SUCCESS in 29m 44s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/25f7d4367fbe4883be6978886a457d33 : SUCCESS in 27m 51s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/25d8a3c3852548d28d9c873bcd4ff664 : SUCCESS in 3m 52s","accounts_in_message":[],"_revision_number":1},{"id":"4feb726e8e0eeaf67b4488e6f62c72e934bb7327","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-08 05:51:37.000000000","message":"Patch Set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"449359eb2a72ac2bdd739c040bee4a60d8baf18a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-08 06:22:58.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/2a4df0ac95c84b0eaaa875299e07e899 : SUCCESS in 4m 22s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a83f4b2633e24e8e96d281cfdd2f5b88 : SUCCESS in 4m 14s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/2bb49abe650540c494ac159108e0f63c : SUCCESS in 4m 33s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/eb5091420ffc4e5181ce0fe0cffc57df : SUCCESS in 5m 01s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f05cf9d6f4b944aa9146800a6bd527ce : SUCCESS in 6m 14s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/475bc310ce7f40afb504a7aae790640e : SUCCESS in 29m 04s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/5699db3697f8496fa345d55b282f1097 : SUCCESS in 29m 03s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/1d4338326e534f7f887f1503ef83d1d2 : SUCCESS in 4m 25s","accounts_in_message":[],"_revision_number":2},{"id":"f1378c07547ae778604f1dbc048977ff3d9159e0","author":{"_account_id":17813,"name":"wangzhh","email":"wzh_1993@126.com","username":"wangzhh"},"date":"2020-09-09 01:12:52.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"93f115e528b791c20981bef6d791cbb71d6867a6","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-10 02:56:59.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.","accounts_in_message":[],"_revision_number":3},{"id":"471a78f8d43557792856571a35dfa0df82fc014e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-10 03:32:02.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/1abb6351b6e6449b987f45933e1ad80d : SUCCESS in 4m 28s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/29f492f91afa48f0b88556f4a222ca31 : SUCCESS in 4m 30s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/fe6c6f5328944c07a717a86c9bf8dbca : SUCCESS in 4m 42s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/bd8f6315b4ed45489b56e866b53cc338 : SUCCESS in 4m 53s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/005b9deb56ca465e8a83c5a976fdce07 : SUCCESS in 18m 31s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/2ad485593a574edd834b0a50bdf4ff5c : SUCCESS in 32m 46s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/5ed19f659da4408baa4a8f6815fa21b2 : SUCCESS in 25m 35s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/cfd75d4cd6a24ef8b347f35fce5c7418 : SUCCESS in 3m 57s","accounts_in_message":[],"_revision_number":3},{"id":"1b2db3730d9dbb7efdf14f0c5df890c142ac2b08","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-10 09:41:29.000000000","message":"Patch Set 4: Patch Set 3 was rebased","accounts_in_message":[],"_revision_number":4},{"id":"dc3a1a7d9676e5c0094801821fbb2b5f9e87ff4b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-10 10:23:25.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/873237d9a43a48479fa8dbdee85dc02d : SUCCESS in 7m 22s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/33ff2d00bf894cb79e6d4653f2151b86 : FAILURE in 5m 17s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/5e9c5ea57b4c4b27b3d617246a7b0a31 : SUCCESS in 4m 23s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/fb33f117c23c40949ee95810c635a8fb : SUCCESS in 5m 58s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/175060e460bd453b88b747c8b7764b67 : SUCCESS in 20m 56s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/a6f628b207b84b748e66c94a2e6c4bc1 : SUCCESS in 26m 49s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/4eda9aa311d74b1c8e027e0b51397466 : SUCCESS in 35m 49s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/3e1bae066d2e446398a5994b5cff3849 : SUCCESS in 5m 38s\n\nWarning:\n  Comments left for invalid file cyborg/common/authorize_wsgi.py","accounts_in_message":[],"_revision_number":4},{"id":"10c7ed21e25c8fc9c800fda1517e28c863327b56","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-10 12:15:29.000000000","message":"Patch Set 5: Patch Set 4 was rebased","accounts_in_message":[],"_revision_number":5},{"id":"df4df71f56a1fb010871d10ab86242a88c91ff10","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-10 12:50:47.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/e06c4963bbc94ca69ee47ab2468b90e4 : SUCCESS in 5m 31s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/101c326dbece43518d3942c5c68ddd1a : SUCCESS in 4m 50s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/523069aecd5d429ca08e3759b6071a80 : SUCCESS in 4m 44s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/b863f67a544a41968621de848fc331af : SUCCESS in 4m 53s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8797c1c710824842a385596d53447d7d : SUCCESS in 18m 45s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/7b34c2ac870c486eb0b832412a9538da : SUCCESS in 29m 02s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/4c8a4ffa69e74cfb8073c8ae35974bcb : SUCCESS in 27m 12s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/6be75c9bfdc345acb6a6a7e18f7975dd : SUCCESS in 3m 28s","accounts_in_message":[],"_revision_number":5},{"id":"9447623a65316c1c885f19045ffae4498eb91148","author":{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},"date":"2020-09-10 19:41:30.000000000","message":"Patch Set 5: Code-Review+1","accounts_in_message":[],"_revision_number":5},{"id":"78e7812cabc29d94c7532c4a2b0bafc8024bde0a","author":{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},"date":"2020-09-11 02:41:32.000000000","message":"Patch Set 5:\n\n(10 comments)\n\nlooks goot but some small error.","accounts_in_message":[],"_revision_number":5},{"id":"f49f3ae95ad65b0e24c0ee3310306ef6f42b8d04","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-11 05:44:31.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"a3e3466757dcd19eb910e8d4f5a9461dab370c87","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-09-11 05:58:15.000000000","message":"Patch Set 5: Code-Review+2","accounts_in_message":[],"_revision_number":5},{"id":"8a9035d9dd712543024b688da9fddaf2cf13833b","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2020-09-11 06:32:53.000000000","message":"Patch Set 5:\n\n(2 comments)","accounts_in_message":[],"_revision_number":5},{"id":"0e77b0ab5d6812b2ac845e6da3834a3ff3a94a3a","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2020-09-11 07:11:19.000000000","message":"Patch Set 5: Code-Review-1\n\n(4 comments)\n\n-1 for the uncorrect deprecated_reason.","accounts_in_message":[],"_revision_number":5},{"id":"4aedeb3cd9c80d889be1dd75e510ba9eb35a560f","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2020-09-11 07:11:49.000000000","message":"Patch Set 5:\n\nand the spell error need to be fixed.","accounts_in_message":[],"_revision_number":5},{"id":"5a91498cfb782628bf0a8ce2fbb973df5a8d512e","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-11 07:45:01.000000000","message":"Patch Set 6: Published edit on patch set 5.","accounts_in_message":[],"_revision_number":6},{"id":"0eabd1e595c17aaae123a85476ab709bd1d7c7e2","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-11 07:50:55.000000000","message":"Patch Set 5:\n\n(1 comment)\n\n@wenping and Brin, I updated part of the key message error.\nI think we don\u0027t need to be so picky on spacing and exact word choice, as long as the message is understood. Otherwise, that\u0027s a waste of time.","accounts_in_message":[],"_revision_number":5},{"id":"91b10d304990bafd614fd65c368dd8dceda557ee","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-11 08:24:14.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/45ad49cad707480ea508d4c048ecd3fc : SUCCESS in 5m 22s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/1ec4c7a979f74a6596e27024dbc1e355 : SUCCESS in 4m 23s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/9165f29edab5417480f4112bfb0630c9 : SUCCESS in 5m 26s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/afff03aaec2a4f01b701d20df439f7fe : SUCCESS in 5m 27s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/5471c66a51b74b2fb1ca2f65328d463d : SUCCESS in 13m 39s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/a7e9e4a3f3594836bb34aa2bba72caa0 : SUCCESS in 28m 57s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/4d257c52647a4b70aa608443817640fb : SUCCESS in 31m 22s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/7223354d9f0747ef83eb9f7de8136ced : SUCCESS in 4m 38s","accounts_in_message":[],"_revision_number":6},{"id":"5d2e76a23c3c15d02260266dd1c8e6211819b625","author":{"_account_id":31412,"name":"Wenping Song","email":"songwenping@inspur.com","username":"songwenping"},"date":"2020-09-11 08:40:54.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"9aebc1f877ab5a1f83761e841ac4a2bcf7531e0a","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-11 10:04:21.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"34ab6f46461b2904fe73c6d611c5447ed6dd391e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-11 10:40:41.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/eb04815e77a34972b4f280bd1770f44c : SUCCESS in 4m 14s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/15f7baa8abad4201ac1e6ca08980bd85 : SUCCESS in 3m 43s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/40222be60f044c0b9f9cb2016f363db7 : SUCCESS in 6m 16s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/49891db5ff5b497eb74605c204b29f2d : SUCCESS in 4m 16s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/605dc22ad20a4475a797ba8108c15806 : SUCCESS in 14m 35s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/4e913a03f3a34f5cb8a64af1bc55e002 : SUCCESS in 27m 41s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/a6e6a75294e343e687796135b9673b00 : SUCCESS in 30m 59s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/dabad06f51a14f85802da0603d8e3049 : SUCCESS in 5m 46s","accounts_in_message":[],"_revision_number":7},{"id":"e18699e96bcc42358232dba998ae0541bfa1eb67","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2020-09-12 03:31:02.000000000","message":"Patch Set 7:\n\n\u003e (1 comment)\n \u003e \n \u003e @wenping and Brin, I updated part of the key message error.\n \u003e I think we don\u0027t need to be so picky on spacing and exact word\n \u003e choice, as long as the message is understood. Otherwise, that\u0027s a\n \u003e waste of time.\n\nI dont think so, there are so many spelling error, why can\u0027t we do better? If cyborg\u0027s core people don\u0027t do it yet, will other contributors take it seriously?","accounts_in_message":[],"_revision_number":7},{"id":"1a96204dbb06b3a58ade2e23ecf422b19b02bb9c","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-14 08:37:15.000000000","message":"Uploaded patch set 8.","accounts_in_message":[],"_revision_number":8},{"id":"1b9b3ec400b8473c63369760f6154fa4e6bdb45e","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-09-14 09:06:49.000000000","message":"Patch Set 8: Code-Review+2","accounts_in_message":[],"_revision_number":8},{"id":"e4ac0d299cbcedad758164cfb5ace072fc6f3b23","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-14 09:14:38.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/1a35f1077f8a434bb67183c3de394267 : SUCCESS in 5m 23s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/63c20dbb0d044671be389dc729a0372f : SUCCESS in 8m 42s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/d416ba1797994987965cf225713ff8f7 : SUCCESS in 5m 33s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/b3daead098f34699b45ff136996bc99d : SUCCESS in 3m 54s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/40e3e9dc77584404a6e426ba963bb3e2 : SUCCESS in 16m 40s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/737fbd64f2d6422eac8833b679d41edd : SUCCESS in 29m 22s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/27139b868f654b6ca9d8480e6f63be21 : SUCCESS in 29m 01s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/a7ab543fc2aa41a2a5d681b832e5455f : SUCCESS in 4m 54s","accounts_in_message":[],"_revision_number":8},{"id":"d6b8562a0c87c04d4577b218ffd2e0246685cd0f","author":{"_account_id":26458,"name":"Brin Zhang","email":"zhangbailin@inspur.com","username":"zhangbailin"},"date":"2020-09-15 01:17:22.000000000","message":"Patch Set 8: Code-Review+2\n\n(3 comments)\n\nlgtm, thanks","accounts_in_message":[],"_revision_number":8},{"id":"cd9a96b332b84a7efd9515ef2b62d248735b90da","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-09-15 06:01:10.000000000","message":"Patch Set 8: Workflow+1","accounts_in_message":[],"_revision_number":8},{"id":"0992441a15be5689c76ec63b853e1da9f710265c","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-15 06:01:39.000000000","message":"Patch Set 8: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":8},{"id":"9b9224ad1204ce6bc10b2d6d1e981589848a099f","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-15 06:40:40.000000000","message":"Patch Set 8: Verified-2\n\nBuild failed (gate pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/f59183fd1caf495089f041529c39bacc : FAILURE in 3m 26s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/55fbd25f76e340b1a11a226da2e08486 : FAILURE in 4m 06s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/ec03696ada4e47bb86f756b7abec09b5 : SUCCESS in 5m 02s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a6ede9d8cd974afe9fdac69fe9293fb0 : SUCCESS in 23m 43s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/fa092f6f1c2640ec88a067bbd41e77a9 : SUCCESS in 34m 55s","accounts_in_message":[],"_revision_number":8},{"id":"933a99d3af53fb958a1324baa36fcd8201924262","author":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"date":"2020-09-15 10:32:50.000000000","message":"Patch Set 8:\n\n(3 comments)\n\nrecheck","accounts_in_message":[],"_revision_number":8},{"id":"4379d289144b8b1be4870259891771d80acd9303","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-09-15 10:44:08.000000000","message":"Patch Set 8:\n\nrecheck","accounts_in_message":[],"_revision_number":8},{"id":"079df56e77a35cccf127ed2efc601b4329a7c3ff","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-15 11:06:23.000000000","message":"Patch Set 8: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/0f7a7b7ff8104490ae94844faee6bfe8 : SUCCESS in 4m 39s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/bff3d946e4904201b0c5925d343b4cf8 : SUCCESS in 3m 33s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/e8b8ca7ed2674f828e272d20981845a5 : FAILURE in 3m 36s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/98dcc5352b8348e8b33dcbe6b91ff0bc : FAILURE in 3m 42s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c2f0b415de2e4e1599dd0a3705c0a86f : SUCCESS in 12m 43s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/d20d7764307f44308c3270c2e93374c4 : FAILURE in 11m 45s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/10e42eb5d7bd480694c9f4977294c23d : FAILURE in 11m 07s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/719ef66924524b44a7c87dccb8c55f81 : FAILURE in 3m 29s","accounts_in_message":[],"_revision_number":8},{"id":"6888724017db6a8f1ce1f9066351ddb189cfb508","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-09-15 12:51:18.000000000","message":"Patch Set 8:\n\nrecheck","accounts_in_message":[],"_revision_number":8},{"id":"fc31c11b224fb56c499e177d62ae4bedc1ecd06b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-15 13:06:59.000000000","message":"Patch Set 8:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/25f7e2b308a24138b483e8b6c66119d9 : FAILURE in 4m 43s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e4c23d37795749db9d9d77ade17e82ce : POST_FAILURE in 4m 06s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/4c65937202e1469195e809c7ec2a4827 : FAILURE in 3m 27s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/345beb41df8940f6979883982dae481e : FAILURE in 4m 34s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/5e5dd7b5e4244fbb8de6c0570abac11e : FAILURE in 13m 28s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/2bd2cc4bcf8a4a3aba3722a31ed2331f : FAILURE in 11m 30s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/b67226c18c4c44a493bc42ee3e173447 : POST_FAILURE in 14m 20s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/97e2ebf636e04d61bf9b6594bf1b815d : SUCCESS in 3m 49s","accounts_in_message":[],"_revision_number":8},{"id":"4faa4f9c9cea65a0b3aa19a8a318cc20dd2be45c","author":{"_account_id":28748,"name":"chenker","email":"chen.ke14@zte.com.cn","username":"chenke"},"date":"2020-09-16 01:21:23.000000000","message":"Patch Set 8:\n\nrecheck","accounts_in_message":[],"_revision_number":8},{"id":"3253e01d0c659c71b36a239ae16ab825be47f903","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-16 02:02:45.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/423b2b6d454e4aca8f27728180b36079 : SUCCESS in 4m 16s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a3c2168aaa6d438c8a5510d5f28523f1 : SUCCESS in 5m 00s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/0de3905c936a45cbad5b2f6dbe53cd7f : SUCCESS in 5m 02s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/18a33a9649fe4ba0b48414e70b84f183 : SUCCESS in 5m 23s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8a4fff506fb546e9ac4963b747918776 : SUCCESS in 16m 52s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/6d4663f0e93445c8beb8a375da62968a : SUCCESS in 32m 12s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/82437050abcf461b939f7048a3afb355 : SUCCESS in 39m 01s (non-voting)\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/46c094942e62401c8876a0e470eb03c7 : SUCCESS in 3m 46s","accounts_in_message":[],"_revision_number":8},{"id":"302feaba01ef98e233f3f09c5332f4657c5d3c4f","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-16 02:02:59.000000000","message":"Patch Set 8: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":8},{"id":"4e3e9229709ddec15d291218fc1de0e1da5c2f2a","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-16 02:24:57.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":8},{"id":"3d264e7579a7fa4249c3bc56533ff2b5acacb6d3","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-16 02:24:57.000000000","message":"Patch Set 8: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/9c2055e16f4d469a87e4ce3612e42d74 : SUCCESS in 3m 46s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/d494161368614cdaa41e4f532c019608 : SUCCESS in 4m 01s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/a8956d40c4374bc58594ef8cf50376fe : SUCCESS in 3m 33s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/cc733bf9c20e4874a59335d0e4dc9694 : SUCCESS in 13m 15s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/2c6be99b85a84e2eb400a4cc7b87f713 : SUCCESS in 20m 49s","accounts_in_message":[],"_revision_number":8},{"id":"c5c66f936f3384b3cd6dc17823eb17187fb0cd92","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-09-16 02:26:08.000000000","message":"Patch Set 8:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e93ecbd057ab4e4e96dfc22539abb05c : SUCCESS in 51s","accounts_in_message":[],"_revision_number":8}],"current_revision_number":8,"current_revision":"b1c223afd8fbd5821ab3dea26a33b28212165288","revisions":{"8c6c1aac7a7efc4af3454f23c3ee4c643f45257e":{"kind":"REWORK","_number":1,"created":"2020-09-08 04:00:03.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/1"}}},"commit":{"parents":[{"commit":"7858a272fae4bc1f119a4abe7c0566cb3b6e58e6","subject":"Suppress policy deprecated warnings in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/7858a272fae4bc1f119a4abe7c0566cb3b6e58e6"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:59:45.000000000","tz":480},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer role is too strict forlisting device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/8c6c1aac7a7efc4af3454f23c3ee4c643f45257e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/8c6c1aac7a7efc4af3454f23c3ee4c643f45257e"}]},"branch":"refs/heads/master"},"17c5c4064b518e63da11ee13aab24a280db88b9d":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2020-09-08 05:51:37.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/2"}}},"commit":{"parents":[{"commit":"7858a272fae4bc1f119a4abe7c0566cb3b6e58e6","subject":"Suppress policy deprecated warnings in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/7858a272fae4bc1f119a4abe7c0566cb3b6e58e6"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"YumengBao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 05:51:29.000000000","tz":0},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer role is too strict forlisting device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\n\nAdd new default rules and mapping in policy base class\n\nCyborg Policy Default Refresh is one of the planned blueprints for victoria\nrelease, the specification[0] has been merged in ussuri. To be brief, we need\nto do the followings to incorporate authorization scopes into cyborg:\n1. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n2. Add the following applicable six personas to cyborg and deprecate old ones:\n   * project reader\n   * project member\n   * project admin\n   * system reader\n   * system admin\n   * system admin or owner\n   * system or project reader\n3. Rewrite check string(authorization rules) using new personas for all APIs\n4. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n5. Update policy documentation on cyborg-doc page\n\nThis patch refreshed cyborg default RBAC policy to scoped RBAC policy, and\nreorganized the policy framework into a more logical way:\n    1) added five personas to basic policies and deprecated legacy roles\n    2) extract API_policies from policy.py to indenpendent policy files\n    3) extract authorize_wsgi.py out from policy.py\n\n[0]https://specs.openstack.org/openstack/cyborg-specs/specs/ussuri/approved/policy-defaults-refresh.html\n\nStory: 2007024\nTask: 40834\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/17c5c4064b518e63da11ee13aab24a280db88b9d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/17c5c4064b518e63da11ee13aab24a280db88b9d"}]},"branch":"refs/heads/master"},"349b7c4f19be6c9947512b2d1bc6db87d37d7199":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2020-09-10 02:56:59.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/3"}}},"commit":{"parents":[{"commit":"ac6e0f31e3f3135c3d37e5c94820d499a5b37f6a","subject":"Suppress policy deprecated warnings in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/ac6e0f31e3f3135c3d37e5c94820d499a5b37f6a"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 07:44:12.000000000","tz":480},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer role is too strict forlisting device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\n\nAdd new default rules and mapping in policy base class\n\nCyborg Policy Default Refresh is one of the planned blueprints for victoria\nrelease, the specification[0] has been merged in ussuri. To be brief, we need\nto do the followings to incorporate authorization scopes into cyborg:\n1. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n2. Add the following applicable six personas to cyborg and deprecate old ones:\n   * project reader\n   * project member\n   * project admin\n   * system reader\n   * system admin\n   * system admin or owner\n   * system or project reader\n3. Rewrite check string(authorization rules) using new personas for all APIs\n4. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n5. Update policy documentation on cyborg-doc page\n\nThis patch refreshed cyborg default RBAC policy to scoped RBAC policy, and\nreorganized the policy framework into a more logical way:\n    1) added five personas to basic policies and deprecated legacy roles\n    2) extract API_policies from policy.py to indenpendent policy files\n    3) extract authorize_wsgi.py out from policy.py\n\n[0]https://specs.openstack.org/openstack/cyborg-specs/specs/ussuri/approved/policy-defaults-refresh.html\n\nStory: 2007024\nTask: 40834\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/349b7c4f19be6c9947512b2d1bc6db87d37d7199"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/349b7c4f19be6c9947512b2d1bc6db87d37d7199"}]},"branch":"refs/heads/master"},"23498d237b1c9e0b41907e6b02d9927e79581932":{"kind":"TRIVIAL_REBASE","_number":4,"created":"2020-09-10 09:41:29.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/4"}}},"commit":{"parents":[{"commit":"1cd0f2399b9950978de73211af430c6837b4ad4c","subject":"Suppress policy deprecated warnings in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/1cd0f2399b9950978de73211af430c6837b4ad4c"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"YumengBao","email":"yumeng_bao@yahoo.com","date":"2020-09-10 09:41:29.000000000","tz":0},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer role is too strict forlisting device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\n\nAdd new default rules and mapping in policy base class\n\nCyborg Policy Default Refresh is one of the planned blueprints for victoria\nrelease, the specification[0] has been merged in ussuri. To be brief, we need\nto do the followings to incorporate authorization scopes into cyborg:\n1. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n2. Add the following applicable six personas to cyborg and deprecate old ones:\n   * project reader\n   * project member\n   * project admin\n   * system reader\n   * system admin\n   * system admin or owner\n   * system or project reader\n3. Rewrite check string(authorization rules) using new personas for all APIs\n4. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n5. Update policy documentation on cyborg-doc page\n\nThis patch refreshed cyborg default RBAC policy to scoped RBAC policy, and\nreorganized the policy framework into a more logical way:\n    1) added five personas to basic policies and deprecated legacy roles\n    2) extract API_policies from policy.py to indenpendent policy files\n    3) extract authorize_wsgi.py out from policy.py\n\n[0]https://specs.openstack.org/openstack/cyborg-specs/specs/ussuri/approved/policy-defaults-refresh.html\n\nStory: 2007024\nTask: 40834\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/23498d237b1c9e0b41907e6b02d9927e79581932"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/23498d237b1c9e0b41907e6b02d9927e79581932"}]},"branch":"refs/heads/master"},"4a92acc916603858e909bb61df12d9750be18dff":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2020-09-10 12:15:29.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/5"}}},"commit":{"parents":[{"commit":"ab7073ff47596698076751db673b36f237e8621c","subject":"Suppress policy deprecated warnings in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/ab7073ff47596698076751db673b36f237e8621c"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"YumengBao","email":"yumeng_bao@yahoo.com","date":"2020-09-10 12:15:29.000000000","tz":0},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer role is too strict forlisting device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\n\nAdd new default rules and mapping in policy base class\n\nCyborg Policy Default Refresh is one of the planned blueprints for victoria\nrelease, the specification[0] has been merged in ussuri. To be brief, we need\nto do the followings to incorporate authorization scopes into cyborg:\n1. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n2. Add the following applicable six personas to cyborg and deprecate old ones:\n   * project reader\n   * project member\n   * project admin\n   * system reader\n   * system admin\n   * system admin or owner\n   * system or project reader\n3. Rewrite check string(authorization rules) using new personas for all APIs\n4. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n5. Update policy documentation on cyborg-doc page\n\nThis patch refreshed cyborg default RBAC policy to scoped RBAC policy, and\nreorganized the policy framework into a more logical way:\n    1) added five personas to basic policies and deprecated legacy roles\n    2) extract API_policies from policy.py to indenpendent policy files\n    3) extract authorize_wsgi.py out from policy.py\n\n[0]https://specs.openstack.org/openstack/cyborg-specs/specs/ussuri/approved/policy-defaults-refresh.html\n\nStory: 2007024\nTask: 40834\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/4a92acc916603858e909bb61df12d9750be18dff"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/4a92acc916603858e909bb61df12d9750be18dff"}]},"branch":"refs/heads/master"},"e3d371bde3c682cd08aadddf1991f06069052030":{"kind":"REWORK","_number":6,"created":"2020-09-11 07:45:01.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/6"}}},"commit":{"parents":[{"commit":"ab7073ff47596698076751db673b36f237e8621c","subject":"Suppress policy deprecated warnings in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/ab7073ff47596698076751db673b36f237e8621c"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"YumengBao","email":"yumeng_bao@yahoo.com","date":"2020-09-11 07:44:54.000000000","tz":0},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer role is too strict forlisting device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\n\nAdd new default rules and mapping in policy base class\n\nCyborg Policy Default Refresh is one of the planned blueprints for victoria\nrelease, the specification[0] has been merged in ussuri. To be brief, we need\nto do the followings to incorporate authorization scopes into cyborg:\n1. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n2. Add the following applicable six personas to cyborg and deprecate old ones:\n   * project reader\n   * project member\n   * project admin\n   * system reader\n   * system admin\n   * system admin or owner\n   * system or project reader\n3. Rewrite check string(authorization rules) using new personas for all APIs\n4. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n5. Update policy documentation on cyborg-doc page\n\nThis patch refreshed cyborg default RBAC policy to scoped RBAC policy, and\nreorganized the policy framework into a more logical way:\n    1) added five personas to basic policies and deprecated legacy roles\n    2) extract API_policies from policy.py to indenpendent policy files\n    3) extract authorize_wsgi.py out from policy.py\n\n[0]https://specs.openstack.org/openstack/cyborg-specs/specs/ussuri/approved/policy-defaults-refresh.html\n\nStory: 2007024\nTask: 40834\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/e3d371bde3c682cd08aadddf1991f06069052030"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/e3d371bde3c682cd08aadddf1991f06069052030"}]},"branch":"refs/heads/master"},"5a4ff80fe946986dd7713bef3479416677f91477":{"kind":"REWORK","_number":7,"created":"2020-09-11 10:04:21.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/7"}}},"commit":{"parents":[{"commit":"660b252c9169af3ab3d41c3137240a0b96bdb403","subject":"Suppress policy deprecated warnings in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/660b252c9169af3ab3d41c3137240a0b96bdb403"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-11 06:27:42.000000000","tz":480},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer role is too strict forlisting device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\n\nAdd new default rules and mapping in policy base class\n\nCyborg Policy Default Refresh is one of the planned blueprints for victoria\nrelease, the specification[0] has been merged in ussuri. To be brief, we need\nto do the followings to incorporate authorization scopes into cyborg:\n1. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n2. Add the following applicable six personas to cyborg and deprecate old ones:\n   * project reader\n   * project member\n   * project admin\n   * system reader\n   * system admin\n   * system admin or owner\n   * system or project reader\n3. Rewrite check string(authorization rules) using new personas for all APIs\n4. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn’t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n5. Update policy documentation on cyborg-doc page\n\nThis patch refreshed cyborg default RBAC policy to scoped RBAC policy, and\nreorganized the policy framework into a more logical way:\n    1) added five personas to basic policies and deprecated legacy roles\n    2) extract API_policies from policy.py to indenpendent policy files\n    3) extract authorize_wsgi.py out from policy.py\n\n[0]https://specs.openstack.org/openstack/cyborg-specs/specs/ussuri/approved/policy-defaults-refresh.html\n\nStory: 2007024\nTask: 40834\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/5a4ff80fe946986dd7713bef3479416677f91477"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/5a4ff80fe946986dd7713bef3479416677f91477"}]},"branch":"refs/heads/master"},"b1c223afd8fbd5821ab3dea26a33b28212165288":{"kind":"REWORK","_number":8,"created":"2020-09-14 08:37:15.000000000","uploader":{"_account_id":24872,"name":"YumengBao","email":"yumeng_bao@yahoo.com","username":"Yumeng_Bao"},"ref":"refs/changes/73/750273/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/73/750273/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/73/750273/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/73/750273/8"}}},"commit":{"parents":[{"commit":"1e46f9be323a3b634ed6cabbd068dc99df84878f","subject":"Merge \"Suppress policy deprecated warnings in tests\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/1e46f9be323a3b634ed6cabbd068dc99df84878f"}]}],"author":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-08 03:29:38.000000000","tz":480},"committer":{"name":"Yumeng Bao","email":"yumeng_bao@yahoo.com","date":"2020-09-14 08:36:55.000000000","tz":480},"subject":"Add new default roles in Device Profile API policies","message":"Add new default roles in Device Profile API policies\n\nThis adds new default roles in device_profile API policies.\n\n- GET is default with system or project reader role\n- Rest all APIs are system admin role\n\nTest cases have been added to cover new defaults as well as\nfor deprecated rules.\n\n- Backward compatibility:\n    Old Rules and Defaults will keep working as it is because they\n    are added as deprecated rules and marked for removal in future\n    release. This means Existing deployement will keep working till\n    deprecated rules are there.\n\n- Below warning can be seen by operator to migrate the old policies\n  to new one:\n\n/cyborg/.tox/py36/lib/python3.6/site-packages/oslo_policy/policy.py:731:\nUserWarning: Policy \"cyborg:device_profile:get_all\":\"rule:admin_or_owner\"\nwas deprecated in W in favor of\n\"cyborg:device_profile:get_all\":\"rule:system_or_project_reader\".\nReason: request admin_or_owmer rule is too strict for listing device_profile.\nEither ensure your deployment is ready for the new default or copy/paste the\ndeprecated policy into your policy file and maintain it manually.\n\nAdd new default rules and mapping in policy base class\n\nCyborg Policy Default Refresh is one of the planned blueprints for victoria\nrelease, the specification[0] has been merged in ussuri. To be brief, we need\nto do the followings to incorporate authorization scopes into cyborg:\n1. Add protection test for all APIs.\n   A protection test is similar to an API test, but purely focused on the\n   authoritative outcome.In other words, protection testing is sufficient when\n   we can assert that a user is or isn\u0027t allowed to do or see something. For\n   example, Users with a reader role on the system or a project shouldn’t be\n   able to make writable changes.\n2. Add the following applicable personas to cyborg and deprecate old ones:\n   * project reader\n   * project member\n   * project admin\n   * system reader\n   * system admin\n   * system admin or owner\n   * system or project reader\n3. Rewrite check string(authorization rules) using new personas for all APIs\n4. Update policy documentation on cyborg-doc page\n\nThis patch refreshed cyborg default RBAC policy to scoped RBAC policy, and\nreorganized the policy framework into a more logical way:\n    1) added five personas to basic policies and deprecated legacy roles\n    2) extract API_policies from policy.py to indenpendent policy files\n    3) extract authorize_wsgi.py out from policy.py\n\n[0]https://specs.openstack.org/openstack/cyborg-specs/specs/ussuri/approved/policy-defaults-refresh.html\n\nStory: 2007024\nTask: 40834\n\nChange-Id: I3d1620ed66221873fbe5ea5a3b703395664072e2\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/b1c223afd8fbd5821ab3dea26a33b28212165288"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/b1c223afd8fbd5821ab3dea26a33b28212165288"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
