)]}'
{"id":"openstack%2Fcyborg~987680","triplet_id":"openstack%2Fcyborg~master~I56f04adcfe270f02dfd6511a1aea1074e3d2dedb","project":"openstack/cyborg","branch":"master","topic":"bug/2144056","attention_set":{},"removed_from_attention_set":{"11604":{"account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"last_update":"2026-05-07 17:22:35.000000000","reason":"\u003cGERRIT_ACCOUNT_11604\u003e replied on the change","reason_account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}}},"hashtags":[],"change_id":"I56f04adcfe270f02dfd6511a1aea1074e3d2dedb","subject":"Fix rule:allow policy bypass on device/deployable/attribute APIs","status":"MERGED","created":"2026-05-07 15:05:05.000000000","updated":"2026-05-07 18:30:46.000000000","submitted":"2026-05-07 18:28:38.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":1,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"987680-bug/2144056","meta_rev_id":"9b8fdacb256d1e12e2504448ef5a740ffa662b34","_number":987680,"virtual_id_number":987680,"owner":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-05-07 18:28:37.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"recommended":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"all":[{"value":1,"date":"2026-05-07 15:39:09.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":2,"date":"2026-05-07 17:22:35.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":1,"date":"2026-05-07 17:34:13.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-07 15:39:09.000000000","updated_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"reviewer":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"state":"REVIEWER"},{"updated":"2026-05-07 16:25:54.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"645991aeee17ec95cc71c3cf06c591de0cd7cc5c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-05-07 15:05:05.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"f2fc5976551f51da5865a4c542f17c0682c0d249","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-05-07 15:39:09.000000000","message":"Patch Set 1: Code-Review+1","accounts_in_message":[],"_revision_number":1},{"id":"fa63eddc9cd4d97a26abbe267a29ab2b23ccff75","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-07 16:25:54.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/031d85f2a93045fda25aa855a810e761\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/b3c8a73fd5ba4d21ae3710404de77649 : SUCCESS in 4m 31s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/264d7c185b8e435eaa1ae2c3116593d7 : SUCCESS in 2m 36s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4f27ba0cf9a448588252d680930fa667 : SUCCESS in 5m 21s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/980579f408304c418acf4bd22c8b96ed : SUCCESS in 2m 35s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/f6b370ec81134fafa4aca07e932db6f3 : SUCCESS in 2m 53s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/a8f33720ae134fe198c9ae135f2e6fa2 : SUCCESS in 2m 43s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/4974159de5c94049b9d48916d1d00ba3 : SUCCESS in 3m 58s (non-voting)\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/8b724da9918a47d2805ef248ff0db836 : SUCCESS in 30m 03s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/7f814ade87c849f9888123d47b2cdb9b : SUCCESS in 32m 59s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/0e5c509bb71447e6a8a293550581376e : SUCCESS in 37m 54s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/78b3f477cbdb4285974f52f3d49ed4e9 : SUCCESS in 1h 03m 58s","accounts_in_message":[],"_revision_number":1},{"id":"8e189e4ff3350d406a2a6613f5a80a4909436960","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-05-07 17:22:35.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"96c4c554522ec86f72573e2750032c2b2fdfe6e7","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-05-07 17:34:09.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"5799406c49b08263d4a436f87570478117d24dd5","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-05-07 17:34:13.000000000","message":"Patch Set 1: Workflow+1","accounts_in_message":[],"_revision_number":1},{"id":"d9a9bc25986e0212f036ab39624c9636e1189ec9","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-07 17:34:58.000000000","message":"Patch Set 1: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":1},{"id":"b470559c5628e9cb4af71a99f2c2449dd072e261","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-07 18:28:37.000000000","message":"Patch Set 1: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f3deff539abc4159b6252731a226ca61\n\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/783d8422554d4af4af1e4a781b6152f6 : SUCCESS in 4m 19s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/3e32dda932f54f0aa977fa276283b5fe : SUCCESS in 4m 35s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/167a47d1fbff482a9ea15f105b820445 : SUCCESS in 3m 21s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/ae34383de77f493ca387d59e977112d7 : SUCCESS in 4m 26s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/160d58fa74e14b5fa14f8e47f969ee77 : SUCCESS in 3m 23s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/e34ea6431b7b46a296552c0d7f207705 : SUCCESS in 28m 50s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/f51c4d4b32d6402ea68bf9382f3c4f9f : SUCCESS in 24m 04s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/6a2b15e9388841b0ad9bc397812dcfae : SUCCESS in 48m 55s","accounts_in_message":[],"_revision_number":1},{"id":"40f48fa3d59f8ae82decb998cb98be3eb6dcdabf","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-07 18:28:38.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":1},{"id":"9b8fdacb256d1e12e2504448ef5a740ffa662b34","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-07 18:30:46.000000000","message":"Patch Set 1:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/095eb93605a74239b31c0f9e8e6410ba\n\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/4398075813924db393f4a903c280c710 : SUCCESS in 39s\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/bbf9afc8e82f4c77b9f879b299d3b1a9 : SUCCESS in 49s","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"9c313b007fd09301b487ba500089636a09a02609","revisions":{"9c313b007fd09301b487ba500089636a09a02609":{"kind":"REWORK","_number":1,"created":"2026-05-07 15:05:05.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/80/987680/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/80/987680/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/80/987680/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/80/987680/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/80/987680/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/80/987680/1"}}},"commit":{"parents":[{"commit":"f111946df6713aa64efa29dd025d47839241c529","subject":"Merge \"Add Grenade upgrade support for Cyborg\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/f111946df6713aa64efa29dd025d47839241c529"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-03-04 18:52:56.000000000","tz":0},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-04-26 18:16:45.000000000","tz":0},"subject":"Fix rule:allow policy bypass on device/deployable/attribute APIs","message":"Fix rule:allow policy bypass on device/deployable/attribute APIs\n\nTen API endpoints in cyborg/common/policy.py used check_str\u003d\u0027rule:allow\u0027\n(@), which unconditionally authorises any authenticated Keystone user\nregardless of role, project membership, or scope. This allowed any\ntenant to enumerate the full accelerator hardware topology and trigger\nprivileged operations including FPGA reprogramming and hardware metadata\nmutation.\n\nReplace the unconditional rule:allow with role-checked rules available\non all maintained stable branches:\n\n  cyborg:arq:create          rule:allow -\u003e rule:project_member_or_admin\n  cyborg:device:get_one      rule:allow -\u003e rule:admin_api\n  cyborg:device:get_all      rule:allow -\u003e rule:admin_api\n  cyborg:deployable:get_one  rule:allow -\u003e rule:admin_api\n  cyborg:deployable:get_all  rule:allow -\u003e rule:admin_api\n  cyborg:deployable:program  rule:allow -\u003e rule:admin_api\n  cyborg:attribute:get_one   rule:allow -\u003e rule:admin_api\n  cyborg:attribute:get_all   rule:allow -\u003e rule:admin_api\n  cyborg:attribute:create    rule:allow -\u003e rule:admin_api\n  cyborg:attribute:delete    rule:allow -\u003e rule:admin_api\n\narq:create receives project_member_or_admin rather than admin_api\nbecause Nova forwards the end-user token when creating ARQs; admin_api\nwould break all non-admin instance launches.\n\nAlso remove the dead fpga_policies group (cyborg:fpga:{get_one,\nget_all,update}) whose rules were registered but never evaluated at\nruntime as no /v2/fpgas endpoint exists.\n\nAdd unit tests in cyborg/tests/unit/policies/ covering authorised and\nunauthorised contexts for each affected endpoint group, following the\npattern established by test_device_profiles.py.\n\nCVE-2026-40213\n\nCloses-Bug: #2143263\nAssisted-By: claude-code sonnet 4.6\nChange-Id: I56f04adcfe270f02dfd6511a1aea1074e3d2dedb\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/9c313b007fd09301b487ba500089636a09a02609"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/9c313b007fd09301b487ba500089636a09a02609"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
