)]}'
{"id":"openstack%2Fcyborg~987699","triplet_id":"openstack%2Fcyborg~stable%2F2025.1~I56f04adcfe270f02dfd6511a1aea1074e3d2dedb","project":"openstack/cyborg","branch":"stable/2025.1","topic":"bug/2144056","attention_set":{},"removed_from_attention_set":{"11604":{"account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"last_update":"2026-05-08 12:45:01.000000000","reason":"\u003cGERRIT_ACCOUNT_11604\u003e replied on the change","reason_account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}}},"hashtags":[],"change_id":"I56f04adcfe270f02dfd6511a1aea1074e3d2dedb","subject":"Fix rule:allow policy bypass on device/deployable/attribute APIs","status":"MERGED","created":"2026-05-07 15:05:59.000000000","updated":"2026-05-08 14:03:50.000000000","submitted":"2026-05-08 14:01:31.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":1,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"987699-bug/2144056","meta_rev_id":"32fd7200962e76ade1b966d0eb7cb025de86f452","_number":987699,"virtual_id_number":987699,"owner":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-05-08 14:01:31.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"recommended":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"all":[{"value":1,"date":"2026-05-07 15:44:09.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":2,"date":"2026-05-08 12:45:01.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":1,"date":"2026-05-08 12:45:01.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-07 15:44:09.000000000","updated_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"reviewer":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"state":"REVIEWER"},{"updated":"2026-05-07 15:58:01.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"a75e646d805a5657cebd64190aa7804915fd48e3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-05-07 15:05:59.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"682c33cc8470a574ed776c02eb3435cdaccdcb57","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-05-07 15:44:09.000000000","message":"Patch Set 1: Code-Review+1","accounts_in_message":[],"_revision_number":1},{"id":"03597215365749aa7c72f9c2c5424a3bedaa0733","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-07 15:58:01.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/60928a531b8c4c3d9debcbb559d9aac7\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/a215088588014ce58294607da5b65b68 : SUCCESS in 4m 49s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/753db74ee39241aeba4ba9e2a387b370 : SUCCESS in 2m 20s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c1f06f85d7f449708db62914e550d5c9 : SUCCESS in 4m 55s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/62c1c70785f8415f917cce18495f6e6d : FAILURE in 5m 02s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/2b708964926748358ca1a0baa3e56481 : SUCCESS in 5m 31s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/b02b654b6c1a44e59b0cd186f3fd63d4 : SUCCESS in 3m 57s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/891d92f5046a40e681a0e6c741473faa : SUCCESS in 26m 51s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/03f8dc82bdd040b2ab49e6b1d66c1bf1 : SUCCESS in 31m 03s\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/a37cc3e89c3d4f77970f7f873ca3b0d2 : SUCCESS in 4m 30s","accounts_in_message":[],"_revision_number":1},{"id":"73d1f580183ac20cbe1bbeca2b5d925d3a1e1c38","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-05-08 12:45:01.000000000","message":"Patch Set 1: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"2cde7308b3dfef3010dd6c4626eb0bb2c753985c","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-08 13:24:29.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/178a6b4a4f364a56bad0fb4bfc0c52e6\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/946a03d2245540ec889f4903b623e189 : SUCCESS in 4m 36s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/555bc6a92e3e42fb8f6a2f008bb82de0 : SUCCESS in 2m 09s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/9c496e8ee94d42dc81c5a87723bb816e : SUCCESS in 7m 31s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/f937efafd5b14eb5b483e6ebc949dd87 : SUCCESS in 3m 43s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/2e983dc1fc9e48489b1e647bbfc321cc : SUCCESS in 3m 27s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/f6bbc07134104b50942297ac4e7d8429 : SUCCESS in 2m 53s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/038e53c62f4446d5822a47bf7fa9b69c : SUCCESS in 30m 14s\n- cyborg-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/3250df6866154965b45ee0698a7b3ec9 : SUCCESS in 32m 25s\n- cyborg-tox-bandit https://zuul.opendev.org/t/openstack/build/31f563b37b31451691dac14cfc34a05e : SUCCESS in 3m 27s","accounts_in_message":[],"_revision_number":1},{"id":"9752318b3e9f7ea016d8a4f598c0200ffcdc9997","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-08 13:25:23.000000000","message":"Patch Set 1: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":1},{"id":"684c8b3b7088677233faf7417cabc3925989510e","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-08 14:01:31.000000000","message":"Patch Set 1: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/e5e3e2ba321f459a92c751567cc25401\n\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/73d7dd359a324839b3b8ec1fdf558c98 : SUCCESS in 3m 21s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/0957447a75e14a16bab1129296d9a1cb : SUCCESS in 4m 30s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/6ed081e3b5a9428e8911d6ac30281376 : SUCCESS in 3m 55s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/6a1e5fcf83d443c482c6e5adb9990a43 : SUCCESS in 6m 14s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/24a3d077202a443cafa823974bdacfed : SUCCESS in 4m 14s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/d0dff4a0671448f5a96a74722a4699d8 : SUCCESS in 29m 08s","accounts_in_message":[],"_revision_number":1},{"id":"f0bf264b80e0f69e206a8fc59a4b95963877cef7","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-08 14:01:31.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":1},{"id":"32fd7200962e76ade1b966d0eb7cb025de86f452","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-08 14:03:50.000000000","message":"Patch Set 1:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/a9156232e1b9456aa7b5590f381bcc8b\n\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/45aa42269f524c28ba08c6192be3e8d9 : SUCCESS in 46s\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/0d5fc6ae1404495fa7f360e5765b1bd8 : SUCCESS in 52s","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"8d0d61687f3782cc84fc34a5139f12f34e5eea7e","revisions":{"8d0d61687f3782cc84fc34a5139f12f34e5eea7e":{"kind":"REWORK","_number":1,"created":"2026-05-07 15:05:59.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/99/987699/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/99/987699/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/99/987699/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/99/987699/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/99/987699/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/99/987699/1"}}},"commit":{"parents":[{"commit":"52e7fe86b8fdf5af8ebc8c9c0e05336141f36a8f","subject":"Fix cyborg-status upgrade check tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/52e7fe86b8fdf5af8ebc8c9c0e05336141f36a8f"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-04-26 18:24:39.000000000","tz":0},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-04-26 18:26:01.000000000","tz":0},"subject":"Fix rule:allow policy bypass on device/deployable/attribute APIs","message":"Fix rule:allow policy bypass on device/deployable/attribute APIs\n\nTen API endpoints in cyborg/common/policy.py used check_str\u003d\u0027rule:allow\u0027\n(@), which unconditionally authorises any authenticated Keystone user\nregardless of role, project membership, or scope. This allowed any\ntenant to enumerate the full accelerator hardware topology and trigger\nprivileged operations including FPGA reprogramming and hardware metadata\nmutation.\n\nReplace the unconditional rule:allow with role-checked rules available\non all maintained stable branches:\n\n  cyborg:arq:create          rule:allow -\u003e rule:project_member_or_admin\n  cyborg:device:get_one      rule:allow -\u003e rule:admin_api\n  cyborg:device:get_all      rule:allow -\u003e rule:admin_api\n  cyborg:deployable:get_one  rule:allow -\u003e rule:admin_api\n  cyborg:deployable:get_all  rule:allow -\u003e rule:admin_api\n  cyborg:deployable:program  rule:allow -\u003e rule:admin_api\n  cyborg:attribute:get_one   rule:allow -\u003e rule:admin_api\n  cyborg:attribute:get_all   rule:allow -\u003e rule:admin_api\n  cyborg:attribute:create    rule:allow -\u003e rule:admin_api\n  cyborg:attribute:delete    rule:allow -\u003e rule:admin_api\n\narq:create receives project_member_or_admin rather than admin_api\nbecause Nova forwards the end-user token when creating ARQs; admin_api\nwould break all non-admin instance launches.\n\nAlso remove the dead fpga_policies group (cyborg:fpga:{get_one,\nget_all,update}) whose rules were registered but never evaluated at\nruntime as no /v2/fpgas endpoint exists.\n\nAdd unit tests in cyborg/tests/unit/policies/ covering authorised and\nunauthorised contexts for each affected endpoint group, following the\npattern established by test_device_profiles.py.\n\nCVE-2026-40213\n\nCloses-Bug: #2143263\nAssisted-By: claude-code sonnet 4.6\nChange-Id: I56f04adcfe270f02dfd6511a1aea1074e3d2dedb\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n(cherry picked from commit 9c313b007fd09301b487ba500089636a09a02609)\n(cherry picked from commit 8aad73b158c2c8210f38747686b03e1f1c5fbeb9)\n(cherry picked from commit b958c6bc75b51a1a644ef62c7c2a88ae1497ba54)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/8d0d61687f3782cc84fc34a5139f12f34e5eea7e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/8d0d61687f3782cc84fc34a5139f12f34e5eea7e"}]},"branch":"refs/heads/stable/2025.1"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
