)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"a8f3def4_d8066ae8","updated":"2026-06-26 06:24:47.000000000","message":"Looks good, Few improvements suggested based on the teim-ci review comments.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"a81e2fe39702c962615dc8483cb594b68d11ce1b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"361fd96a_d64e259f","updated":"2026-06-22 08:35:02.000000000","message":"teim-ci: auto","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"105a946c506ab1dd087d96cb17ce92e01ff8e9ca","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"8915c48c_6256d922","updated":"2026-06-22 23:45:31.000000000","message":"teim-ci: auto","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"change_message_id":"1b84dbe0b59b96a3c03456b2303a233240741c16","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"cc24148c_416f450c","updated":"2026-07-01 10:21:00.000000000","message":"lgtm","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"change_message_id":"cf7fa2a83253b31f4f143d3eb6edfbd9e0165331","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"2b548e76_1c42c682","updated":"2026-07-21 09:30:52.000000000","message":"lgtm","commit_id":"9023b12f545f11022d4d009884275f6f94c806f2"}],"cyborg/policies/base.py":[{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":false,"context_lines":[{"line_number":127,"context_line":"default_policies \u003d ["},{"line_number":128,"context_line":"    policy.RuleDefault("},{"line_number":129,"context_line":"        name\u003d\u0027admin_api\u0027,"},{"line_number":130,"context_line":"        check_str\u003d\u0027role:admin or role:administrator\u0027,"},{"line_number":131,"context_line":"        description\u003d\u0027Legacy rule for cloud admin access\u0027,"},{"line_number":132,"context_line":"    ),"},{"line_number":133,"context_line":"    policy.RuleDefault("}],"source_content_type":"text/x-python","patch_set":3,"id":"f4b1d797_93bd54b9","side":"PARENT","line":130,"range":{"start_line":130,"start_character":19,"end_line":130,"end_character":51},"updated":"2026-06-26 06:24:47.000000000","message":"thank you for adding the detailed release notes.","commit_id":"f67f7b6964058fb5505dc86ded6d63ec8e1ca98f"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","unresolved":false,"context_lines":[{"line_number":109,"context_line":"PROJECT_READER \u003d \u0027rule:project_reader_api\u0027"},{"line_number":110,"context_line":"PROJECT_MEMBER_OR_ADMIN \u003d \u0027rule:project_member_or_admin\u0027"},{"line_number":111,"context_line":"PROJECT_READER_OR_ADMIN \u003d \u0027rule:project_reader_or_admin\u0027"},{"line_number":112,"context_line":"SERVICE \u003d \u0027role:service\u0027"},{"line_number":113,"context_line":"PROJECT_MANAGER_OR_ADMIN \u003d \u0027rule:project_manager_or_admin\u0027"},{"line_number":114,"context_line":"PROJECT_MEMBER_OR_SERVICE \u003d \u0027rule:project_member_or_service\u0027"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"d2dc34c8_38fdbd20","line":112,"updated":"2026-06-23 00:00:54.000000000","message":"New policy constants SERVICE, PROJECT_MANAGER_OR_ADMIN, PROJECT_MEMBER_OR_SERVICE are defined but not referenced by production code yet\n\n**Severity**: SUGGESTION | **Confidence**: 0.7\n\n**Benefit**: A brief comment noting these are for subsequent policy migration patches would prevent confusion about dead code during review.\n\n**Recommendation**:\nAdd a comment above the new constants indicating they are introduced for bp/consistent-and-secure-rbac follow-up patches (device, deployable, attribute, ARQ policy migration) to clarify they are intentionally unreferenced.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","unresolved":false,"context_lines":[{"line_number":109,"context_line":"PROJECT_READER \u003d \u0027rule:project_reader_api\u0027"},{"line_number":110,"context_line":"PROJECT_MEMBER_OR_ADMIN \u003d \u0027rule:project_member_or_admin\u0027"},{"line_number":111,"context_line":"PROJECT_READER_OR_ADMIN \u003d \u0027rule:project_reader_or_admin\u0027"},{"line_number":112,"context_line":"SERVICE \u003d \u0027role:service\u0027"},{"line_number":113,"context_line":"PROJECT_MANAGER_OR_ADMIN \u003d \u0027rule:project_manager_or_admin\u0027"},{"line_number":114,"context_line":"PROJECT_MEMBER_OR_SERVICE \u003d \u0027rule:project_member_or_service\u0027"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"87fd9bb1_a6029a30","line":112,"updated":"2026-06-23 00:00:54.000000000","message":"SERVICE constant uses raw check string (\u0027role:service\u0027) while all other constants use rule references (\u0027rule:xxx\u0027), breaking the naming pattern\n\n**Severity**: SUGGESTION | **Confidence**: 0.8\n\n**Benefit**: Consistency with the established pattern aids maintainability. The service_api rule already maps to role:service, so consumers should reference rule:service_api. Since SERVICE is unused in the codebase, renaming is low-risk.\n\n**Recommendation**:\nEither change SERVICE to reference the named rule (SERVICE_API \u003d \u0027rule:service_api\u0027) for consistency, or add a comment explaining why this constant uses a raw check string while others reference rules.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3aa97fd838ca94f42e070c047cebee30a519a497","unresolved":true,"context_lines":[{"line_number":109,"context_line":"PROJECT_READER \u003d \u0027rule:project_reader_api\u0027"},{"line_number":110,"context_line":"PROJECT_MEMBER_OR_ADMIN \u003d \u0027rule:project_member_or_admin\u0027"},{"line_number":111,"context_line":"PROJECT_READER_OR_ADMIN \u003d \u0027rule:project_reader_or_admin\u0027"},{"line_number":112,"context_line":"SERVICE \u003d \u0027role:service\u0027"},{"line_number":113,"context_line":"PROJECT_MANAGER_OR_ADMIN \u003d \u0027rule:project_manager_or_admin\u0027"},{"line_number":114,"context_line":"PROJECT_MEMBER_OR_SERVICE \u003d \u0027rule:project_member_or_service\u0027"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"ce4c0156_bde78109","line":112,"in_reply_to":"01356434_837cfe5b","updated":"2026-06-26 11:23:40.000000000","message":"tehcnically this is not require yet\n\nthe apis that use ROJECT_MEMBER_OR_SERVICE will eventully jsut use service in a release or two\n\nso i can drop it for now but also yes this shoudl be rule:service_api\ninstead of duplicating the check string","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":true,"context_lines":[{"line_number":109,"context_line":"PROJECT_READER \u003d \u0027rule:project_reader_api\u0027"},{"line_number":110,"context_line":"PROJECT_MEMBER_OR_ADMIN \u003d \u0027rule:project_member_or_admin\u0027"},{"line_number":111,"context_line":"PROJECT_READER_OR_ADMIN \u003d \u0027rule:project_reader_or_admin\u0027"},{"line_number":112,"context_line":"SERVICE \u003d \u0027role:service\u0027"},{"line_number":113,"context_line":"PROJECT_MANAGER_OR_ADMIN \u003d \u0027rule:project_manager_or_admin\u0027"},{"line_number":114,"context_line":"PROJECT_MEMBER_OR_SERVICE \u003d \u0027rule:project_member_or_service\u0027"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"01356434_837cfe5b","line":112,"in_reply_to":"87fd9bb1_a6029a30","updated":"2026-06-26 06:24:47.000000000","message":"\u003e SERVICE constant uses raw check string (\u0027role:service\u0027) while all other constants use rule references (\u0027rule:xxx\u0027), breaking the naming pattern\n\u003e \n\u003e **Severity**: SUGGESTION | **Confidence**: 0.8\n\u003e \n\u003e **Benefit**: Consistency with the established pattern aids maintainability. The service_api rule already maps to role:service, so consumers should reference rule:service_api. Since SERVICE is unused in the codebase, renaming is low-risk.\n\u003e \n\u003e **Recommendation**:\n\u003e Either change SERVICE to reference the named rule (SERVICE_API \u003d \u0027rule:service_api\u0027) for consistency, or add a comment explaining why this constant uses a raw check string while others reference rules.\n\nI have check rest of the series, It is not used anywhere. Can we drop it? I also check the node code base. I am not sure here.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"630795ed5bb8283f083e955f02cfc3f51fc34a15","unresolved":false,"context_lines":[{"line_number":109,"context_line":"PROJECT_READER \u003d \u0027rule:project_reader_api\u0027"},{"line_number":110,"context_line":"PROJECT_MEMBER_OR_ADMIN \u003d \u0027rule:project_member_or_admin\u0027"},{"line_number":111,"context_line":"PROJECT_READER_OR_ADMIN \u003d \u0027rule:project_reader_or_admin\u0027"},{"line_number":112,"context_line":"SERVICE \u003d \u0027role:service\u0027"},{"line_number":113,"context_line":"PROJECT_MANAGER_OR_ADMIN \u003d \u0027rule:project_manager_or_admin\u0027"},{"line_number":114,"context_line":"PROJECT_MEMBER_OR_SERVICE \u003d \u0027rule:project_member_or_service\u0027"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"c6401442_f2f9f326","line":112,"in_reply_to":"ce4c0156_bde78109","updated":"2026-06-30 11:08:35.000000000","message":"Done","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":false,"context_lines":[{"line_number":109,"context_line":"PROJECT_READER \u003d \u0027rule:project_reader_api\u0027"},{"line_number":110,"context_line":"PROJECT_MEMBER_OR_ADMIN \u003d \u0027rule:project_member_or_admin\u0027"},{"line_number":111,"context_line":"PROJECT_READER_OR_ADMIN \u003d \u0027rule:project_reader_or_admin\u0027"},{"line_number":112,"context_line":"SERVICE \u003d \u0027role:service\u0027"},{"line_number":113,"context_line":"PROJECT_MANAGER_OR_ADMIN \u003d \u0027rule:project_manager_or_admin\u0027"},{"line_number":114,"context_line":"PROJECT_MEMBER_OR_SERVICE \u003d \u0027rule:project_member_or_service\u0027"},{"line_number":115,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"331fb449_2262e2a0","line":112,"in_reply_to":"d2dc34c8_38fdbd20","updated":"2026-06-26 06:24:47.000000000","message":"These policy contstants are used here https://review.opendev.org/c/openstack/cyborg/+/992293/4/cyborg/policies/arqs.py in Migrate ARQ policies to DocumentedRuleDefault patch.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","unresolved":false,"context_lines":[{"line_number":130,"context_line":"default_policies \u003d ["},{"line_number":131,"context_line":"    policy.RuleDefault("},{"line_number":132,"context_line":"        name\u003d\u0027admin_api\u0027,"},{"line_number":133,"context_line":"        check_str\u003d\u0027role:admin\u0027,"},{"line_number":134,"context_line":"        description\u003d\u0027Legacy rule for cloud admin access\u0027,"},{"line_number":135,"context_line":"    ),"},{"line_number":136,"context_line":"    policy.RuleDefault("}],"source_content_type":"text/x-python","patch_set":3,"id":"67d194fe_acb88800","line":133,"updated":"2026-06-23 00:00:54.000000000","message":"ContextHook (hooks.py:96) still sets is_admin\u003dTrue for \u0027administrator\u0027 role, creating split-brain with admin_api policy that no longer recognizes role:administrator\n\n**Severity**: WARNING | **Confidence**: 0.8\n\n**Impact**: Under enforce_new_defaults\u003dFalse, \u0027administrator\u0027-only users still get admin access via the is_admin:True bridge. But once enforce_new_defaults\u003dTrue is enabled, they lose access because admin_api no longer matches role:administrator and the bridge is gone.\n\n**Suggestion**:\nConsider updating ContextHook in cyborg/api/hooks.py line 96 to only set is_admin for \u0027admin\u0027 role, or add a comment explaining the hooks.py administrator check is retained for the transition window and will be removed when new defaults are enforced.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3aa97fd838ca94f42e070c047cebee30a519a497","unresolved":true,"context_lines":[{"line_number":130,"context_line":"default_policies \u003d ["},{"line_number":131,"context_line":"    policy.RuleDefault("},{"line_number":132,"context_line":"        name\u003d\u0027admin_api\u0027,"},{"line_number":133,"context_line":"        check_str\u003d\u0027role:admin\u0027,"},{"line_number":134,"context_line":"        description\u003d\u0027Legacy rule for cloud admin access\u0027,"},{"line_number":135,"context_line":"    ),"},{"line_number":136,"context_line":"    policy.RuleDefault("}],"source_content_type":"text/x-python","patch_set":3,"id":"708fe748_1ff02ebf","line":133,"in_reply_to":"5c153ac8_dde236de","updated":"2026-06-26 11:23:40.000000000","message":"ah i missed that yes\n\ni need to investage why those hooks exist becuase i thihnk its likley incorrect\nfrom there usage the look to be api middeleware\n\nhttps://github.com/openstack/cyborg/blob/master/cyborg/api/app.py#L45-L52\n\nbut if that is the case tehy shoudlnto be enabeld like that\nand instead shoudl be stored in \nhttps://github.com/openstack/cyborg/tree/master/cyborg/api/middleware\nand configure via \nhttps://github.com/openstack/cyborg/blob/master/etc/cyborg/api-paste.ini\n\nso ill fix that but ill need to add cleanign up the hooks to my techdebt list","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":false,"context_lines":[{"line_number":130,"context_line":"default_policies \u003d ["},{"line_number":131,"context_line":"    policy.RuleDefault("},{"line_number":132,"context_line":"        name\u003d\u0027admin_api\u0027,"},{"line_number":133,"context_line":"        check_str\u003d\u0027role:admin\u0027,"},{"line_number":134,"context_line":"        description\u003d\u0027Legacy rule for cloud admin access\u0027,"},{"line_number":135,"context_line":"    ),"},{"line_number":136,"context_line":"    policy.RuleDefault("}],"source_content_type":"text/x-python","patch_set":3,"id":"5c153ac8_dde236de","line":133,"in_reply_to":"67d194fe_acb88800","updated":"2026-06-26 06:24:47.000000000","message":"\u003e ContextHook (hooks.py:96) still sets is_admin\u003dTrue for \u0027administrator\u0027 role, creating split-brain with admin_api policy that no longer recognizes role:administrator\n\u003e \n\u003e **Severity**: WARNING | **Confidence**: 0.8\n\u003e \n\u003e **Impact**: Under enforce_new_defaults\u003dFalse, \u0027administrator\u0027-only users still get admin access via the is_admin:True bridge. But once enforce_new_defaults\u003dTrue is enabled, they lose access because admin_api no longer matches role:administrator and the bridge is gone.\n\u003e \n\u003e **Suggestion**:\n\u003e Consider updating ContextHook in cyborg/api/hooks.py line 96 to only set is_admin for \u0027admin\u0027 role, or add a comment explaining the hooks.py administrator check is retained for the transition window and will be removed when new defaults are enforced.\n\nI think it is a valid comment, In case we update this patch, we should drop `or \u0027administrator\u0027 in roles` from https://github.com/openstack/cyborg/blob/master/cyborg/api/hooks.py#L96C37-L96C64.\n\nWe have a release note added there already for keystone administrator removal.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"630795ed5bb8283f083e955f02cfc3f51fc34a15","unresolved":false,"context_lines":[{"line_number":130,"context_line":"default_policies \u003d ["},{"line_number":131,"context_line":"    policy.RuleDefault("},{"line_number":132,"context_line":"        name\u003d\u0027admin_api\u0027,"},{"line_number":133,"context_line":"        check_str\u003d\u0027role:admin\u0027,"},{"line_number":134,"context_line":"        description\u003d\u0027Legacy rule for cloud admin access\u0027,"},{"line_number":135,"context_line":"    ),"},{"line_number":136,"context_line":"    policy.RuleDefault("}],"source_content_type":"text/x-python","patch_set":3,"id":"4347d2b9_c36fe912","line":133,"in_reply_to":"708fe748_1ff02ebf","updated":"2026-06-30 11:08:35.000000000","message":"Done","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"a376d1f08b2b962b2786bdcfdb29955428f7997f","unresolved":false,"context_lines":[{"line_number":169,"context_line":"        check_str\u003d\u0027role:manager and project_id:%(project_id)s\u0027,"},{"line_number":170,"context_line":"        description\u003d\u0027Default rule for project manager APIs.\u0027,"},{"line_number":171,"context_line":"    ),"},{"line_number":172,"context_line":"    policy.RuleDefault("},{"line_number":173,"context_line":"        \u0027project_manager_or_admin\u0027,"},{"line_number":174,"context_line":"        \u0027rule:project_manager_api or rule:admin_api\u0027,"},{"line_number":175,"context_line":"        \u0027Default rule for project manager or admin APIs.\u0027,"}],"source_content_type":"text/x-python","patch_set":4,"id":"03e8ac7e_d23280ee","line":172,"updated":"2026-06-30 11:38:29.000000000","message":"project_manager_or_admin and project_member_or_service both declare deprecated_rule\u003dDEPRECATED_ADMIN_OR_OWNER, but neither rule existed before this patch. Attaching a DeprecatedRule to a brand-new rule has no deprecation-bridging effect and will produce misleading generated policy sample output.\n\n**Severity**: WARNING | **Confidence**: 0.7\n\n**Impact**: oslo.policy uses deprecated_rule to bridge an OLD policy being replaced by a NEW one. Applying it to a rule with no prior version is semantically incorrect; the generated sample policy file will show a deprecation relationship that does not exist.\n\n**Suggestion**:\nRemove the deprecated_rule\u003dDEPRECATED_ADMIN_OR_OWNER argument from the four newly-introduced base rules (service_api, project_manager_api, project_manager_or_admin, project_member_or_service) since they have no legacy predecessor. Keep deprecated_rule only on rules that genuinely replace an existing deprecated rule.","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"861fe129f6c9ddfc5aad174bce85aeef61c00a86","unresolved":false,"context_lines":[{"line_number":169,"context_line":"        check_str\u003d\u0027role:manager and project_id:%(project_id)s\u0027,"},{"line_number":170,"context_line":"        description\u003d\u0027Default rule for project manager APIs.\u0027,"},{"line_number":171,"context_line":"    ),"},{"line_number":172,"context_line":"    policy.RuleDefault("},{"line_number":173,"context_line":"        \u0027project_manager_or_admin\u0027,"},{"line_number":174,"context_line":"        \u0027rule:project_manager_api or rule:admin_api\u0027,"},{"line_number":175,"context_line":"        \u0027Default rule for project manager or admin APIs.\u0027,"}],"source_content_type":"text/x-python","patch_set":4,"id":"af279fca_a36f1d2f","line":172,"in_reply_to":"03e8ac7e_d23280ee","updated":"2026-07-06 22:23:10.000000000","message":"i undersatnd why it rasied this, its ture this is a new rule but it will be replacing existing usage of admin or owner in later files.\n\nso the bridge is for that future work.","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"a376d1f08b2b962b2786bdcfdb29955428f7997f","unresolved":false,"context_lines":[{"line_number":175,"context_line":"        \u0027Default rule for project manager or admin APIs.\u0027,"},{"line_number":176,"context_line":"        deprecated_rule\u003dDEPRECATED_ADMIN_OR_OWNER,"},{"line_number":177,"context_line":"    ),"},{"line_number":178,"context_line":"    policy.RuleDefault("},{"line_number":179,"context_line":"        \u0027project_member_or_service\u0027,"},{"line_number":180,"context_line":"        \u0027rule:project_member_api or rule:service_api\u0027,"},{"line_number":181,"context_line":"        \u0027Default rule for project member or service APIs.\u0027,"}],"source_content_type":"text/x-python","patch_set":4,"id":"61b6d181_67fe61f0","line":178,"updated":"2026-06-30 11:38:29.000000000","message":"project_member_or_service reuses DEPRECATED_ADMIN_OR_OWNER as its deprecated bridge. The service role has no project_id binding, so the legacy bridge\u0027s project_id:%(project_id)s clause can never match a pure service token. This bridge is semantically mismatched for service-role authorization.\n\n**Severity**: WARNING | **Confidence**: 0.8\n\n**Impact**: Under enforce_new_defaults\u003dFalse, oslo.policy ORs this rule with admin_or_owner. A service-role caller that is not also admin will not pass the bridge (the project_id clause cannot match a pure service token). Service-to-service access may not take effect until enforce_new_defaults\u003dTrue.\n\n**Suggestion**:\nConfirm whether service-role callers are expected to work under legacy defaults today. If service tokens must function during the transition, consider a dedicated deprecated bridge without the project_id constraint, or document that service-role support requires opting in to new defaults. Add a comment clarifying the bridge is intentionally limited.","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"}],"cyborg/policies/device_profiles.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","unresolved":false,"context_lines":[{"line_number":55,"context_line":"    ),"},{"line_number":56,"context_line":"    deprecated_since\u003dversionutils.deprecated.WALLABY,"},{"line_number":57,"context_line":")"},{"line_number":58,"context_line":"deprecated_delete \u003d policy.DeprecatedRule("},{"line_number":59,"context_line":"    name\u003d\u0027cyborg:device_profile:delete\u0027,"},{"line_number":60,"context_line":"    check_str\u003dbase.deprecated_is_admin,"},{"line_number":61,"context_line":"    deprecated_reason\u003d("}],"source_content_type":"text/x-python","patch_set":3,"id":"46c7f5b1_c8cb7cad","line":58,"updated":"2026-06-23 00:00:54.000000000","message":"deprecated_delete bridge tightened from admin_or_owner to is_admin under enforce_new_defaults\u003dFalse, breaking backward compatibility for device profile deletion without release note documentation\n\n**Severity**: HIGH | **Confidence**: 0.9\n\n**Risk**: Non-admin project members who could delete device profiles via the deprecated admin_or_owner bridge lose access immediately upon deploying this change, even without opting in to enforce_new_defaults\u003dTrue. This contradicts the stated backward-compatibility goal.\n\n**Priority**: Before merge\n**Why This Matters**: The commit states enforce_new_defaults\u003dFalse preserves existing deployments. But this deprecated_delete change tightens the bridge itself, causing a behavioral regression for deployments where non-admin users delete device profiles, with no release note warning.\n\n**Recommendation**:\nEither (a) revert deprecated_delete to base.deprecated_default to preserve the old bridge during transition and tighten in the follow-up migration patch, or (b) add a release note upgrade entry documenting that device_profile:delete access is tightened for non-admin users in this release.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3aa97fd838ca94f42e070c047cebee30a519a497","unresolved":true,"context_lines":[{"line_number":55,"context_line":"    ),"},{"line_number":56,"context_line":"    deprecated_since\u003dversionutils.deprecated.WALLABY,"},{"line_number":57,"context_line":")"},{"line_number":58,"context_line":"deprecated_delete \u003d policy.DeprecatedRule("},{"line_number":59,"context_line":"    name\u003d\u0027cyborg:device_profile:delete\u0027,"},{"line_number":60,"context_line":"    check_str\u003dbase.deprecated_is_admin,"},{"line_number":61,"context_line":"    deprecated_reason\u003d("}],"source_content_type":"text/x-python","patch_set":3,"id":"a1d77b0e_a31a689e","line":58,"in_reply_to":"3db7d7a6_5e0b2c51","updated":"2026-06-26 11:23:40.000000000","message":"so the effect didnt actully change\n\ndevice provifle are not owned resouces so they could only be mange via the admin before because they didnt have an assocated project.\nso there isnt actlly a chang ein behvior im just being more explcit about the actual semantics\n\nits sort of related to \nhttps://review.opendev.org/c/openstack/cyborg/+/992722/2 it was onoly workign because fo the admin part","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":true,"context_lines":[{"line_number":55,"context_line":"    ),"},{"line_number":56,"context_line":"    deprecated_since\u003dversionutils.deprecated.WALLABY,"},{"line_number":57,"context_line":")"},{"line_number":58,"context_line":"deprecated_delete \u003d policy.DeprecatedRule("},{"line_number":59,"context_line":"    name\u003d\u0027cyborg:device_profile:delete\u0027,"},{"line_number":60,"context_line":"    check_str\u003dbase.deprecated_is_admin,"},{"line_number":61,"context_line":"    deprecated_reason\u003d("}],"source_content_type":"text/x-python","patch_set":3,"id":"3db7d7a6_5e0b2c51","line":58,"in_reply_to":"46c7f5b1_c8cb7cad","updated":"2026-06-26 06:24:47.000000000","message":"+1 to include this in release notes.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"64ce77bc242bc364a4e2c8c5f80f1b1f0cc4aedd","unresolved":false,"context_lines":[{"line_number":55,"context_line":"    ),"},{"line_number":56,"context_line":"    deprecated_since\u003dversionutils.deprecated.WALLABY,"},{"line_number":57,"context_line":")"},{"line_number":58,"context_line":"deprecated_delete \u003d policy.DeprecatedRule("},{"line_number":59,"context_line":"    name\u003d\u0027cyborg:device_profile:delete\u0027,"},{"line_number":60,"context_line":"    check_str\u003dbase.deprecated_is_admin,"},{"line_number":61,"context_line":"    deprecated_reason\u003d("}],"source_content_type":"text/x-python","patch_set":3,"id":"f184989a_89a3ca45","line":58,"in_reply_to":"a1d77b0e_a31a689e","updated":"2026-06-29 10:21:20.000000000","message":"Acknowledged","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"}],"cyborg/tests/unit/api/base.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","unresolved":false,"context_lines":[{"line_number":152,"context_line":"            \u0027X-User-Domain-Name\u0027: ct.get(\"domain_name\") or \"no_domain\","},{"line_number":153,"context_line":"            \u0027X-Auth-Token\u0027: ct.get(\"auth_token\")"},{"line_number":154,"context_line":"            or \"b9764005b8c145bf972634fb16a826e8\","},{"line_number":155,"context_line":"            \u0027X-Roles\u0027: \u0027,\u0027.join(ct[\u0027roles\u0027])"},{"line_number":156,"context_line":"            if isinstance(ct.get(\u0027roles\u0027), list) and ct[\u0027roles\u0027]"},{"line_number":157,"context_line":"            else ct.get(\u0027roles\u0027) or role,"},{"line_number":158,"context_line":"        }"}],"source_content_type":"text/x-python","patch_set":3,"id":"191737c3_16aed278","line":155,"updated":"2026-06-23 00:00:54.000000000","message":"Three-line conditional for X-Roles in gen_headers mixes direct indexing ct[\u0027roles\u0027] with safe access ct.get(\u0027roles\u0027), making it fragile if refactored\n\n**Severity**: WARNING | **Confidence**: 0.7\n\n**Impact**: The expression is functionally correct for all edge cases, but mixing ct[\u0027roles\u0027] and ct.get(\u0027roles\u0027) in the same conditional is fragile if someone refactors without understanding the isinstance guard. The complex inline conditional also obscures intent.\n\n**Suggestion**:\nExtract to a local variable for clarity: roles_val \u003d ct.get(\u0027roles\u0027); if isinstance(roles_val, list) and roles_val: x_roles \u003d \u0027,\u0027.join(roles_val) else: x_roles \u003d roles_val or role","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3aa97fd838ca94f42e070c047cebee30a519a497","unresolved":true,"context_lines":[{"line_number":152,"context_line":"            \u0027X-User-Domain-Name\u0027: ct.get(\"domain_name\") or \"no_domain\","},{"line_number":153,"context_line":"            \u0027X-Auth-Token\u0027: ct.get(\"auth_token\")"},{"line_number":154,"context_line":"            or \"b9764005b8c145bf972634fb16a826e8\","},{"line_number":155,"context_line":"            \u0027X-Roles\u0027: \u0027,\u0027.join(ct[\u0027roles\u0027])"},{"line_number":156,"context_line":"            if isinstance(ct.get(\u0027roles\u0027), list) and ct[\u0027roles\u0027]"},{"line_number":157,"context_line":"            else ct.get(\u0027roles\u0027) or role,"},{"line_number":158,"context_line":"        }"}],"source_content_type":"text/x-python","patch_set":3,"id":"cac066eb_108eee9f","line":155,"in_reply_to":"191737c3_16aed278","updated":"2026-06-26 11:23:40.000000000","message":"ya that makes sesne to normalise.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"630795ed5bb8283f083e955f02cfc3f51fc34a15","unresolved":false,"context_lines":[{"line_number":152,"context_line":"            \u0027X-User-Domain-Name\u0027: ct.get(\"domain_name\") or \"no_domain\","},{"line_number":153,"context_line":"            \u0027X-Auth-Token\u0027: ct.get(\"auth_token\")"},{"line_number":154,"context_line":"            or \"b9764005b8c145bf972634fb16a826e8\","},{"line_number":155,"context_line":"            \u0027X-Roles\u0027: \u0027,\u0027.join(ct[\u0027roles\u0027])"},{"line_number":156,"context_line":"            if isinstance(ct.get(\u0027roles\u0027), list) and ct[\u0027roles\u0027]"},{"line_number":157,"context_line":"            else ct.get(\u0027roles\u0027) or role,"},{"line_number":158,"context_line":"        }"}],"source_content_type":"text/x-python","patch_set":3,"id":"fe61bb13_f5871a51","line":155,"in_reply_to":"cac066eb_108eee9f","updated":"2026-06-30 11:08:35.000000000","message":"Done","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"a376d1f08b2b962b2786bdcfdb29955428f7997f","unresolved":false,"context_lines":[{"line_number":140,"context_line":"            role \u003d \"admin\""},{"line_number":141,"context_line":"        else:"},{"line_number":142,"context_line":"            role \u003d \"user\""},{"line_number":143,"context_line":"        roles_val \u003d ct.get(\u0027roles\u0027)"},{"line_number":144,"context_line":"        if isinstance(roles_val, list):"},{"line_number":145,"context_line":"            x_roles \u003d \u0027,\u0027.join(roles_val) if roles_val else role"},{"line_number":146,"context_line":"        else:"}],"source_content_type":"text/x-python","patch_set":4,"id":"2e8edb45_3a766ca2","line":143,"updated":"2026-06-30 11:38:29.000000000","message":"The gen_headers roles handling in tests/unit/api/base.py uses falsiness to fall back for the roles list (roles_val if roles_val else role). An empty list [] is falsy, so an explicitly-empty roles list silently falls back to the default role, potentially masking a test that intends to send no roles.\n\n**Severity**: SUGGESTION | **Confidence**: 0.7\n\n**Benefit**: Making the fallback explicit (checking for None rather than falsiness) would prevent an intended empty-roles test context from silently receiving the default role, improving test fidelity.\n\n**Recommendation**:\nConsider distinguishing None from [] explicitly: use an explicit None check for the list branch and join even when empty, or add a comment documenting that an empty roles list is equivalent to the default role by design.","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"861fe129f6c9ddfc5aad174bce85aeef61c00a86","unresolved":true,"context_lines":[{"line_number":140,"context_line":"            role \u003d \"admin\""},{"line_number":141,"context_line":"        else:"},{"line_number":142,"context_line":"            role \u003d \"user\""},{"line_number":143,"context_line":"        roles_val \u003d ct.get(\u0027roles\u0027)"},{"line_number":144,"context_line":"        if isinstance(roles_val, list):"},{"line_number":145,"context_line":"            x_roles \u003d \u0027,\u0027.join(roles_val) if roles_val else role"},{"line_number":146,"context_line":"        else:"}],"source_content_type":"text/x-python","patch_set":4,"id":"b1d63694_6ef73443","line":143,"in_reply_to":"2e8edb45_3a766ca2","updated":"2026-07-06 22:23:10.000000000","message":"hum this does not bite us now but it could in the future","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"bc4cca2d33973ee1de447f68b2fe0c249b1efc3d","unresolved":false,"context_lines":[{"line_number":140,"context_line":"            role \u003d \"admin\""},{"line_number":141,"context_line":"        else:"},{"line_number":142,"context_line":"            role \u003d \"user\""},{"line_number":143,"context_line":"        roles_val \u003d ct.get(\u0027roles\u0027)"},{"line_number":144,"context_line":"        if isinstance(roles_val, list):"},{"line_number":145,"context_line":"            x_roles \u003d \u0027,\u0027.join(roles_val) if roles_val else role"},{"line_number":146,"context_line":"        else:"}],"source_content_type":"text/x-python","patch_set":4,"id":"b8a92514_ca0dfab3","line":143,"in_reply_to":"b1d63694_6ef73443","updated":"2026-07-20 14:48:48.000000000","message":"Done","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"f0f476be61e688da5669e910e804dddf78fa60d3","unresolved":true,"context_lines":[{"line_number":136,"context_line":"        \"\"\""},{"line_number":137,"context_line":"        ct \u003d context.to_dict()"},{"line_number":138,"context_line":"        ct.update(kw)"},{"line_number":139,"context_line":"        if ct.get(\"is_admin\"):"},{"line_number":140,"context_line":"            role \u003d \"admin\""},{"line_number":141,"context_line":"        else:"},{"line_number":142,"context_line":"            role \u003d \"user\""},{"line_number":143,"context_line":"        roles_val \u003d ct.get(\u0027roles\u0027)"},{"line_number":144,"context_line":"        if isinstance(roles_val, list):"},{"line_number":145,"context_line":"            x_roles \u003d \u0027,\u0027.join(roles_val) if roles_val else role"},{"line_number":146,"context_line":"        else:"},{"line_number":147,"context_line":"            x_roles \u003d roles_val or role"},{"line_number":148,"context_line":"        headers \u003d {"},{"line_number":149,"context_line":"            \u0027X-User-Name\u0027: ct.get(\"user_name\") or \"user\","},{"line_number":150,"context_line":"            \u0027X-User-Id\u0027: ct.get(\"user_id\")"}],"source_content_type":"text/x-python","patch_set":4,"id":"14552058_13b9794a","line":147,"range":{"start_line":139,"start_character":0,"end_line":147,"end_character":39},"updated":"2026-06-30 11:19:44.000000000","message":"nit: while this is safe i do not like initallisign varible only in an iff so both of thise shoudl ideally be refactored\n\n\n```suggestion\n        role \u003d \"user\"\n        if ct.get(\"is_admin\"):\n            role \u003d \"admin\"\n        roles_val \u003d ct.get(\u0027roles\u0027)\n        x_roles \u003d role\n        if isinstance(roles_val, list):\n            x_roles \u003d \u0027,\u0027.join(roles_val) if roles_val else role\n        else:\n            x_roles \u003d roles_val or role\n```","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"bc4cca2d33973ee1de447f68b2fe0c249b1efc3d","unresolved":false,"context_lines":[{"line_number":136,"context_line":"        \"\"\""},{"line_number":137,"context_line":"        ct \u003d context.to_dict()"},{"line_number":138,"context_line":"        ct.update(kw)"},{"line_number":139,"context_line":"        if ct.get(\"is_admin\"):"},{"line_number":140,"context_line":"            role \u003d \"admin\""},{"line_number":141,"context_line":"        else:"},{"line_number":142,"context_line":"            role \u003d \"user\""},{"line_number":143,"context_line":"        roles_val \u003d ct.get(\u0027roles\u0027)"},{"line_number":144,"context_line":"        if isinstance(roles_val, list):"},{"line_number":145,"context_line":"            x_roles \u003d \u0027,\u0027.join(roles_val) if roles_val else role"},{"line_number":146,"context_line":"        else:"},{"line_number":147,"context_line":"            x_roles \u003d roles_val or role"},{"line_number":148,"context_line":"        headers \u003d {"},{"line_number":149,"context_line":"            \u0027X-User-Name\u0027: ct.get(\"user_name\") or \"user\","},{"line_number":150,"context_line":"            \u0027X-User-Id\u0027: ct.get(\"user_id\")"}],"source_content_type":"text/x-python","patch_set":4,"id":"57a76353_d5384d4b","line":147,"range":{"start_line":139,"start_character":0,"end_line":147,"end_character":39},"in_reply_to":"14552058_13b9794a","updated":"2026-07-20 14:48:48.000000000","message":"Done","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"}],"cyborg/tests/unit/policies/base.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"a376d1f08b2b962b2786bdcfdb29955428f7997f","unresolved":false,"context_lines":[{"line_number":42,"context_line":"        # The service role is separate (no implication)."},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"        # legacy default role: \"default:admin_or_owner\""},{"line_number":45,"context_line":"        self.legacy_admin_context \u003d cyborg_context.RequestContext("},{"line_number":46,"context_line":"            user_id\u003d\"legacy_admin\","},{"line_number":47,"context_line":"            project_id\u003dself.admin_project_id,"},{"line_number":48,"context_line":"            roles\u003d[\u0027admin\u0027, \u0027manager\u0027, \u0027member\u0027, \u0027reader\u0027],"}],"source_content_type":"text/x-python","patch_set":4,"id":"1fc8604d_0dc1c62c","line":45,"updated":"2026-06-30 11:38:29.000000000","message":"The role list construction in policy test contexts (e.g. roles\u003d[\u0027admin\u0027,\u0027manager\u0027,\u0027member\u0027,\u0027reader\u0027]) duplicates the implied-role chain across every context. If Keystone\u0027s implied-role model changes, each context must be updated independently.\n\n**Severity**: SUGGESTION | **Confidence**: 0.7\n\n**Benefit**: Centralizing the role chains as module-level constants (e.g. ADMIN_ROLES, MEMBER_ROLES) would reduce duplication, make the implied-role model a single source of truth, and make future role-implication changes a one-line edit.\n\n**Recommendation**:\nDefine constants such as ALL_ROLES\u003d[\u0027admin\u0027,\u0027manager\u0027,\u0027member\u0027,\u0027reader\u0027], MEMBER_ROLES\u003d[\u0027member\u0027,\u0027reader\u0027], READER_ROLES\u003d[\u0027reader\u0027] at class or module level and reference them in each RequestContext constructor. This is a readability and maintainability improvement, not a correctness issue.","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"861fe129f6c9ddfc5aad174bce85aeef61c00a86","unresolved":false,"context_lines":[{"line_number":42,"context_line":"        # The service role is separate (no implication)."},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"        # legacy default role: \"default:admin_or_owner\""},{"line_number":45,"context_line":"        self.legacy_admin_context \u003d cyborg_context.RequestContext("},{"line_number":46,"context_line":"            user_id\u003d\"legacy_admin\","},{"line_number":47,"context_line":"            project_id\u003dself.admin_project_id,"},{"line_number":48,"context_line":"            roles\u003d[\u0027admin\u0027, \u0027manager\u0027, \u0027member\u0027, \u0027reader\u0027],"}],"source_content_type":"text/x-python","patch_set":4,"id":"1b4c2853_ef517568","line":45,"in_reply_to":"1fc8604d_0dc1c62c","updated":"2026-07-06 22:23:10.000000000","message":"we could but no in this case it think tis clearer to have the roles listed\ndirectly but  if this was not in base.py i would agree","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"861fe129f6c9ddfc5aad174bce85aeef61c00a86","unresolved":true,"context_lines":[{"line_number":116,"context_line":"        )"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"        self.project_service_context \u003d cyborg_context.RequestContext("},{"line_number":119,"context_line":"            user_id\u003d\"project_service\","},{"line_number":120,"context_line":"            project_id\u003dself.project_id,"},{"line_number":121,"context_line":"            roles\u003d[\u0027service\u0027],"},{"line_number":122,"context_line":"        )"},{"line_number":123,"context_line":""}],"source_content_type":"text/x-python","patch_set":4,"id":"0e0140ca_dc4d7cc0","line":120,"range":{"start_line":119,"start_character":0,"end_line":120,"end_character":39},"updated":"2026-07-06 22:23:10.000000000","message":"hum. so fo rthe service person the project_id shoudl not mage the project under test as this is testing nova calling cyborg with its own service token as the user token instead fo using the actual end users token.\n\nso the service role is intened to allow cross project access the saem way that admin does.","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"bc4cca2d33973ee1de447f68b2fe0c249b1efc3d","unresolved":false,"context_lines":[{"line_number":116,"context_line":"        )"},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"        self.project_service_context \u003d cyborg_context.RequestContext("},{"line_number":119,"context_line":"            user_id\u003d\"project_service\","},{"line_number":120,"context_line":"            project_id\u003dself.project_id,"},{"line_number":121,"context_line":"            roles\u003d[\u0027service\u0027],"},{"line_number":122,"context_line":"        )"},{"line_number":123,"context_line":""}],"source_content_type":"text/x-python","patch_set":4,"id":"e4a086a9_4aa32f49","line":120,"range":{"start_line":119,"start_character":0,"end_line":120,"end_character":39},"in_reply_to":"0e0140ca_dc4d7cc0","updated":"2026-07-20 14:48:48.000000000","message":"Done","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"}],"cyborg/tests/unit/policies/test_arqs.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","unresolved":false,"context_lines":[{"line_number":40,"context_line":"        # With enforce_new_defaults\u003dFalse (Cyborg\u0027s default), oslo.policy"},{"line_number":41,"context_line":"        # ORs the new check string with the deprecated bridge"},{"line_number":42,"context_line":"        # (admin_or_owner: is_admin:True or project_id:%(project_id)s)."},{"line_number":43,"context_line":"        # ARQ create uses need_target\u003dFalse so the target project_id"},{"line_number":44,"context_line":"        # equals the caller\u0027s project_id, meaning every project-scoped"},{"line_number":45,"context_line":"        # context passes via the deprecated bridge. Only system-scoped"},{"line_number":46,"context_line":"        # contexts are rejected (by enforce_scope\u003dTrue)."}],"source_content_type":"text/x-python","patch_set":3,"id":"14d3827c_746284b2","line":43,"updated":"2026-06-23 00:00:54.000000000","message":"Test comment in test_arqs.py references need_target\u003dFalse, a parameter that no longer exists in authorize_wsgi\n\n**Severity**: WARNING | **Confidence**: 0.9\n\n**Impact**: The comment \u0027ARQ create uses need_target\u003dFalse\u0027 describes removed functionality. Contributors reading this test will search for need_target and find nothing, causing confusion about the authorization flow.\n\n**Suggestion**:\nUpdate the comment to reflect current implementation. Replace the need_target reference with: \u0027ARQ create uses the request context as the policy target (project_id equals caller project_id), meaning every project-scoped context passes via the deprecated bridge.\u0027","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":false,"context_lines":[{"line_number":40,"context_line":"        # With enforce_new_defaults\u003dFalse (Cyborg\u0027s default), oslo.policy"},{"line_number":41,"context_line":"        # ORs the new check string with the deprecated bridge"},{"line_number":42,"context_line":"        # (admin_or_owner: is_admin:True or project_id:%(project_id)s)."},{"line_number":43,"context_line":"        # ARQ create uses need_target\u003dFalse so the target project_id"},{"line_number":44,"context_line":"        # equals the caller\u0027s project_id, meaning every project-scoped"},{"line_number":45,"context_line":"        # context passes via the deprecated bridge. Only system-scoped"},{"line_number":46,"context_line":"        # contexts are rejected (by enforce_scope\u003dTrue)."}],"source_content_type":"text/x-python","patch_set":3,"id":"b5c73487_5bd1d28f","line":43,"in_reply_to":"14d3827c_746284b2","updated":"2026-06-26 06:24:47.000000000","message":"\u003e Test comment in test_arqs.py references need_target\u003dFalse, a parameter that no longer exists in authorize_wsgi\n\u003e \n\u003e **Severity**: WARNING | **Confidence**: 0.9\n\u003e \n\u003e **Impact**: The comment \u0027ARQ create uses need_target\u003dFalse\u0027 describes removed functionality. Contributors reading this test will search for need_target and find nothing, causing confusion about the authorization flow.\n\u003e \n\u003e **Suggestion**:\n\u003e Update the comment to reflect current implementation. Replace the need_target reference with: \u0027ARQ create uses the request context as the policy target (project_id equals caller project_id), meaning every project-scoped context passes via the deprecated bridge.\u0027\n\n+1 to include incase we update the patch.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"630795ed5bb8283f083e955f02cfc3f51fc34a15","unresolved":false,"context_lines":[{"line_number":40,"context_line":"        # With enforce_new_defaults\u003dFalse (Cyborg\u0027s default), oslo.policy"},{"line_number":41,"context_line":"        # ORs the new check string with the deprecated bridge"},{"line_number":42,"context_line":"        # (admin_or_owner: is_admin:True or project_id:%(project_id)s)."},{"line_number":43,"context_line":"        # ARQ create uses need_target\u003dFalse so the target project_id"},{"line_number":44,"context_line":"        # equals the caller\u0027s project_id, meaning every project-scoped"},{"line_number":45,"context_line":"        # context passes via the deprecated bridge. Only system-scoped"},{"line_number":46,"context_line":"        # contexts are rejected (by enforce_scope\u003dTrue)."}],"source_content_type":"text/x-python","patch_set":3,"id":"d22010a7_0f6b9e27","line":43,"in_reply_to":"a326e143_6df53bf0","updated":"2026-06-30 11:08:35.000000000","message":"Done","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3aa97fd838ca94f42e070c047cebee30a519a497","unresolved":true,"context_lines":[{"line_number":40,"context_line":"        # With enforce_new_defaults\u003dFalse (Cyborg\u0027s default), oslo.policy"},{"line_number":41,"context_line":"        # ORs the new check string with the deprecated bridge"},{"line_number":42,"context_line":"        # (admin_or_owner: is_admin:True or project_id:%(project_id)s)."},{"line_number":43,"context_line":"        # ARQ create uses need_target\u003dFalse so the target project_id"},{"line_number":44,"context_line":"        # equals the caller\u0027s project_id, meaning every project-scoped"},{"line_number":45,"context_line":"        # context passes via the deprecated bridge. Only system-scoped"},{"line_number":46,"context_line":"        # contexts are rejected (by enforce_scope\u003dTrue)."}],"source_content_type":"text/x-python","patch_set":3,"id":"a326e143_6df53bf0","line":43,"in_reply_to":"b5c73487_5bd1d28f","updated":"2026-06-26 11:23:40.000000000","message":"yep this is valid\nplease mark the comment as unresloved in the future if you want to highlight it\n\nwhen a comment is marked as aresult you are saying that nothign need to be doen so while i do skim resolved comment it very easy to miss them","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"a376d1f08b2b962b2786bdcfdb29955428f7997f","unresolved":false,"context_lines":[{"line_number":52,"context_line":"            self.project_reader_context,"},{"line_number":53,"context_line":"            self.other_project_member_context,"},{"line_number":54,"context_line":"            self.project_foo_context,"},{"line_number":55,"context_line":"            self.project_manager_context,"},{"line_number":56,"context_line":"            self.project_service_context,"},{"line_number":57,"context_line":"        ]"},{"line_number":58,"context_line":"        self.create_unauthorized_contexts \u003d list("}],"source_content_type":"text/x-python","patch_set":4,"id":"4aa332ae_a617e5d5","line":55,"updated":"2026-06-30 11:38:29.000000000","message":"In test_arqs.py the service-role context (project_service_context) is added to create_authorized_contexts, but the rule under test is project_member_or_admin whose deprecated bridge (admin_or_owner) requires is_admin:True or a matching project_id. A pure service token satisfies neither.\n\n**Severity**: WARNING | **Confidence**: 0.7\n\n**Impact**: If the service context cannot actually pass the bridge, the test asserts behavior that does not reflect real authorization. Conversely, if it does pass, the bridge is wider than intended. Either way the expectation is unclear and could mask an authorization gap for ARQ creation.\n\n**Suggestion**:\nVerify whether project_service_context should be authorized for ARQ create under the current rules. If service tokens are not meant to create ARQs yet, move it to the unauthorized list. If they are, add an assertion comment explaining exactly which clause authorizes the service role.","commit_id":"5c87780376305d4180f2708082464b3d5dae9513"}],"releasenotes/notes/srbac-persona-migration-5d1a48ee7c479629.yaml":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","unresolved":false,"context_lines":[{"line_number":18,"context_line":""},{"line_number":19,"context_line":"    The transition timeline is:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    * **2026.2** -- new defaults available, ``enforce_new_defaults``"},{"line_number":22,"context_line":"      defaults to ``False``. Operators may opt in early."},{"line_number":23,"context_line":"    * **2027.1** -- the override will be removed and new defaults"},{"line_number":24,"context_line":"      will be enforced by default. Operators not yet ready can set"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"296ac9a6_ddee1d9c","line":21,"updated":"2026-06-23 00:00:54.000000000","message":"Release note references version milestones (2026.2, 2027.1, 2027.2) without clarifying the OpenStack release cycle naming scheme\n\n**Severity**: SUGGESTION | **Confidence**: 0.7\n\n**Benefit**: OpenStack release notes typically reference cycle names for operator clarity. Using version numbers alone could cause confusion when mapping to release names.\n\n**Recommendation**:\nConsider adding OpenStack release cycle names alongside the version numbers, or verify that version-number-only references are the convention for Cyborg release notes.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a8d580fbf771e5c69698f25792a70245e40d8776","unresolved":true,"context_lines":[{"line_number":18,"context_line":""},{"line_number":19,"context_line":"    The transition timeline is:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    * **2026.2** -- new defaults available, ``enforce_new_defaults``"},{"line_number":22,"context_line":"      defaults to ``False``. Operators may opt in early."},{"line_number":23,"context_line":"    * **2027.1** -- the override will be removed and new defaults"},{"line_number":24,"context_line":"      will be enforced by default. Operators not yet ready can set"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"699ffc45_c162365a","line":21,"in_reply_to":"296ac9a6_ddee1d9c","updated":"2026-06-26 06:24:47.000000000","message":"I was checking nova releasenotes\n```\nchandankumar@fedora:~/programming/nova/releasenotes/notes$ git grep 2026.2\nthreading-by-default-conductor-compute-082fb63ba023bcbe.yaml:    When you are upgrading to 2026.2 (Hibiscus) or newer the default\nchandankumar@fedora:~/programming/nova/releasenotes/notes$ pwd\n/home/chandankumar/programming/nova/releasenotes/notes\nchandankumar@fedora:~/programming/nova/releasenotes/notes$ git grep 2025.1\ndistributed-discover-hosts-perodic-b983f528516dec14.yaml:    to a value greater than 0 in at most one scheduler, with the 2025.1\nepoxy-prelude-f164cc03b742cfc5.yaml:    The OpenStack 2025.1 Epoxy (Nova 31.0.0) release includes many new features\nepoxy-prelude-f164cc03b742cfc5.yaml:    (2025.1).\nepoxy-prelude-f164cc03b742cfc5.yaml:    As a reminder, OpenStack 2025.1 is a `Skip-Level-Upgrade Release`__\nepoxy-prelude-f164cc03b742cfc5.yaml:      .. __: https://docs.openstack.org/nova/latest/reference/api-microversion-history.html#maximum-in-2025-1-epoxy\nflamingo-prelude-22a2782315ce0808.yaml:  required actions to upgrade your cloud from 31.0.0 (2025.1) to 32.0.0\nflamingo-prelude-22a2782315ce0808.yaml:  do rolling-upgrade from 2024.2, you first need to upgrade to 2025.1.\nflamingo-prelude-22a2782315ce0808.yaml:    `v2.100 \u003chttps://docs.openstack.org/nova/latest/reference/api-microversion-history.html#maximum-in-2025-1-epoxy-and-2025-2-flamingo\u003e`_.\ngazpacho-prelude-1c2b533501ce2afd.yaml:  do rolling-upgrades from 2025.1 Epoxy directly by skipping to upgrade to\n```\nThey specify release cycle name. It is not mandatory, good to mention for end users.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3aa97fd838ca94f42e070c047cebee30a519a497","unresolved":true,"context_lines":[{"line_number":18,"context_line":""},{"line_number":19,"context_line":"    The transition timeline is:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    * **2026.2** -- new defaults available, ``enforce_new_defaults``"},{"line_number":22,"context_line":"      defaults to ``False``. Operators may opt in early."},{"line_number":23,"context_line":"    * **2027.1** -- the override will be removed and new defaults"},{"line_number":24,"context_line":"      will be enforced by default. Operators not yet ready can set"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"a513cab0_84b90f8e","line":21,"in_reply_to":"699ffc45_c162365a","updated":"2026-06-26 11:23:40.000000000","message":"so iffically the name of the release is 2025.1 and the code name is Epoxy\n\nthe number which is the ofciial name of the release is requried and the code name is optional.\n\nwe also sometime give the package verion.\n\ni chosoe to only use the number as we dont knwo the name for the 2027.1 and 2027.2 release yet.","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"64ce77bc242bc364a4e2c8c5f80f1b1f0cc4aedd","unresolved":false,"context_lines":[{"line_number":18,"context_line":""},{"line_number":19,"context_line":"    The transition timeline is:"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    * **2026.2** -- new defaults available, ``enforce_new_defaults``"},{"line_number":22,"context_line":"      defaults to ``False``. Operators may opt in early."},{"line_number":23,"context_line":"    * **2027.1** -- the override will be removed and new defaults"},{"line_number":24,"context_line":"      will be enforced by default. Operators not yet ready can set"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"a1490926_325916fc","line":21,"in_reply_to":"a513cab0_84b90f8e","updated":"2026-06-29 10:21:20.000000000","message":"Acknowledged","commit_id":"44aeac64279753a95ca7a40ec70ac0f030ea3ffa"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"83ae0ccbc3d55716b8a7434fddae1612d3ed98f5","unresolved":false,"context_lines":[{"line_number":26,"context_line":"    * **2027.2** -- the deprecated legacy rules and bridges will be"},{"line_number":27,"context_line":"      removed."},{"line_number":28,"context_line":"  - |"},{"line_number":29,"context_line":"    The ``manager`` and ``service`` roles must exist in Keystone"},{"line_number":30,"context_line":"    (both available by default since 2023.2 (Bobcat)). The ``service`` role"},{"line_number":31,"context_line":"    must be assigned to Nova\u0027s service account for the service-token gate"},{"line_number":32,"context_line":"    to function."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"83ea8235_115616fa","line":29,"updated":"2026-07-20 15:50:34.000000000","message":"The release note claims both the \u0027manager\u0027 and \u0027service\u0027 roles are \u0027available by default since 2023.2 (Bobcat)\u0027. The \u0027service\u0027 role IS part of the Keystone bootstrap set, but the \u0027manager\u0027 role is NOT a standard Keystone bootstrap role. Keystone bootstrap creates only admin, member, reader, and s...\n\n**Severity**: WARNING | **Confidence**: 0.8\n\n**Impact**: Operators reading the release note may believe the manager role already exists in their Keystone deployment. If they do not create it, the project_manager_api rule (role:manager and project_id:%(project_id)s) and project_manager_or_admin rule will never match any user, making the manager persona...\n\n**Suggestion**:\nSeparate the two roles in the release note. Clarify that \u0027service\u0027 is a standard Keystone bootstrap role, while \u0027manager\u0027 must be created explicitly by operators (e.g., via \u0027openstack role create manager\u0027 and setting up implied roles: manager implies member). Reference Nova\u0027s SRBAC operator documentation for the manager role setup procedure.","commit_id":"9023b12f545f11022d4d009884275f6f94c806f2"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"34151400db590851f9600ed58c85ec2155f1574f","unresolved":false,"context_lines":[{"line_number":26,"context_line":"    * **2027.2** -- the deprecated legacy rules and bridges will be"},{"line_number":27,"context_line":"      removed."},{"line_number":28,"context_line":"  - |"},{"line_number":29,"context_line":"    The ``manager`` and ``service`` roles must exist in Keystone"},{"line_number":30,"context_line":"    (both available by default since 2023.2 (Bobcat)). The ``service`` role"},{"line_number":31,"context_line":"    must be assigned to Nova\u0027s service account for the service-token gate"},{"line_number":32,"context_line":"    to function."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"feb385d6_8c7fa12e","line":29,"in_reply_to":"83ea8235_115616fa","updated":"2026-07-20 21:11:19.000000000","message":"it does for all stable branches that are still supported","commit_id":"9023b12f545f11022d4d009884275f6f94c806f2"}]}
