)]}'
{"id":"openstack%2Fcyborg~992292","triplet_id":"openstack%2Fcyborg~master~I959ced4bb01234ea94caef072966d4dfda681df9","project":"openstack/cyborg","branch":"master","topic":"bp/consistent-and-secure-rbac","attention_set":{},"removed_from_attention_set":{"11604":{"account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"last_update":"2026-07-21 11:45:02.000000000","reason":"\u003cGERRIT_ACCOUNT_11604\u003e replied on the change","reason_account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},"34452":{"account":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"last_update":"2026-07-21 09:30:52.000000000","reason":"\u003cGERRIT_ACCOUNT_34452\u003e replied on the change","reason_account":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}},"28006":{"account":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"last_update":"2026-07-21 10:35:09.000000000","reason":"removed on reply"},"12393":{"account":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"last_update":"2026-07-21 06:59:24.000000000","reason":"\u003cGERRIT_ACCOUNT_12393\u003e replied on the change","reason_account":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"}}},"hashtags":[],"change_id":"I959ced4bb01234ea94caef072966d4dfda681df9","subject":"Add SRBAC base rules and enforce_new_defaults override","status":"MERGED","created":"2026-06-08 15:33:48.000000000","updated":"2026-07-21 12:51:23.000000000","submitted":"2026-07-21 12:49:43.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":46,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"992292-bp/consistent-and-secure-rbac","meta_rev_id":"eeec7093d09b60ea77e3dac16a036e35fb249d97","_number":992292,"virtual_id_number":992292,"owner":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":0,"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-07-21 12:49:42.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":2,"date":"2026-07-21 11:45:02.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":1,"date":"2026-07-21 10:34:26.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":1,"date":"2026-07-21 10:34:26.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":1,"date":"2026-07-21 11:45:02.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":0,"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"}],"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-08 17:16:51.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-06-22 08:35:11.000000000","updated_by":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"reviewer":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"state":"CC"},{"updated":"2026-06-26 06:24:47.000000000","updated_by":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"reviewer":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"state":"REVIEWER"},{"updated":"2026-07-01 10:21:00.000000000","updated_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"reviewer":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"state":"REVIEWER"}],"messages":[{"id":"8b72d754ae302327b8a18c8abaeb03ebd7ec86f1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-08 15:33:48.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"c9accc4b9dd315eeab35d5f15049b45950885ccb","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-08 17:16:51.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2fb2499d6a1f464e8d375e0125c06d43\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/07b87b65138840dbb8ce2b582d604f9a : SUCCESS in 7m 17s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/6b2fa8ea247048e2869561c1823f4bf4 : SUCCESS in 2m 51s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/01ada1cb877f43a8aa4c4e1cbf6b8c5e : SUCCESS in 8m 18s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/fbe18e8fa69f4f0fa339f14bf2639034 : SUCCESS in 3m 48s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/254545f1b4cc4e21af1fd71c0bfe6477 : SUCCESS in 4m 10s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/e2b83c56def4435782331e6c7bc80ffd : SUCCESS in 3m 51s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/373fd8f877724ee9ade2032975c5ebfa : SUCCESS in 5m 13s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/402017bfc8434a638076f4801ee393e1 : SUCCESS in 23m 44s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/b1b3b7e0c51548059e682ab5eb77d8bd : SUCCESS in 32m 53s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/b6f61f49cc194f878aae0dfc1fa04986 : SUCCESS in 57m 45s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/7ea622c7c7fd41d2abefd377d8ad5d65 : SUCCESS in 55m 45s","accounts_in_message":[],"_revision_number":1},{"id":"82c509f38780b1939f405fb1eb4a9f3be3004736","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-08 17:58:39.000000000","message":"Topic set to bp/consistent-and-secure-rbac","accounts_in_message":[],"_revision_number":1},{"id":"91817428f17e485abb204a9a74e8f6b193bd59b4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 16:55:28.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"dbb627d2bba858963c3a18525d1828348992ca64","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 16:57:38.000000000","message":"Uploaded patch set 3: New patch set was added with same tree, parent tree, and commit message as Patch Set 2.","accounts_in_message":[],"_revision_number":3},{"id":"924567088d993eb6888961a2dc88207c3d1e0eea","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 17:43:55.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/d403d02ea5f648b0a5edc514d18b5aeb\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/702604a73cf04c74a61bda6d38be2f3b : SUCCESS in 5m 41s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/f89382dd7e5848898ec1d01fa2d3c4aa : SUCCESS in 5m 44s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1815fc75811d41b482aef8fb1c32b6bc : SUCCESS in 8m 21s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5aef67201ed24364ae69edf0fb64d3e3 : SUCCESS in 6m 11s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/d5188d0796fd4aae89dff10d2549b5ab : SUCCESS in 3m 31s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/47f57e01d2b8424490edaccf1d489843 : SUCCESS in 3m 31s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/18ee4647167e4e8f9a5e9b3e00f34f84 : SUCCESS in 6m 05s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/0baee0a8cc9f45f2957c804f9aa07b4f : SUCCESS in 31m 21s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/6be9cc6b3c2d4b38af71f860f18cf4ac : SUCCESS in 33m 12s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/5f5f78b54dff4e8daa784df7349e85a3 : SUCCESS in 43m 41s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/450c3bd03f654211b6a4139287ccbb06 : SUCCESS in 25m 31s","accounts_in_message":[],"_revision_number":3},{"id":"a81e2fe39702c962615dc8483cb594b68d11ce1b","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-22 08:35:02.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"ffe1d4e873154189c589fe8f089b36d6e691f1fb","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 08:35:11.000000000","message":"Patch Set 3:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":3},{"id":"eabdf4678256dab43c1ba8375ebc77c34f6e0965","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 09:29:37.000000000","message":"Patch Set 3:\n\nBuild failed (automatic-ci pipeline). To rerun just this ci comment\n\"teim-ci: auto\". To rerun other ci jobs comment \"recheck\".\nNote this ci does run on \"recheck\".\n\nhttps://zuul.teim.app/t/main/buildset/2607e27347fa4bd3ab53d4f5c898d050\n\n- teim-code-review https://zuul.teim.app/t/main/build/26411ebd49ce443ab6c344d65211b887 : TIMED_OUT in 31m 03s","accounts_in_message":[],"_revision_number":3},{"id":"105a946c506ab1dd087d96cb17ce92e01ff8e9ca","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-22 23:45:31.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"afc8475965afe87410e48cc610880d5dde9d77f7","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 23:45:44.000000000","message":"Patch Set 3:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":3},{"id":"2afdf54bcf4d72b30d132d472b2b7dae4c4926b8","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-23 00:00:54.000000000","message":"Patch Set 3:\n\n(7 comments)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/16ca7fb04a3a4a9baee0807dded5dc72\n\n- teim-code-review https://zuul.teim.app/t/main/build/5f4e396852fc47c7939dceee8cf15e46 : SUCCESS in 12m 14s\n\nWarning:\n  PolicyFixture calls set_defaults(CONF) without enforce_new_defaults\u003dFalse before init_enforcer re-sets it, creating fragile ordering coupling Impact: If someone refactors PolicyFixture to skip init_enforcer or changes set_defaults ordering, tests could silently run with enforce_new_defaults\u003dTrue, producing results that don\u0027t match production behavior. Recommendation: Have PolicyFixture explicitly set enforce_new_defaults\u003dFalse to match production defaults rather than relying on init_enforcer\u0027s internal call. This makes the test configuration self-documenting and resilient to refactoring.","accounts_in_message":[],"_revision_number":3},{"id":"a8d580fbf771e5c69698f25792a70245e40d8776","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-26 06:24:47.000000000","message":"Patch Set 3: Code-Review+1\n\n(8 comments)","accounts_in_message":[],"_revision_number":3},{"id":"3aa97fd838ca94f42e070c047cebee30a519a497","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-26 11:23:40.000000000","message":"Patch Set 3:\n\n(6 comments)","accounts_in_message":[],"_revision_number":3},{"id":"64ce77bc242bc364a4e2c8c5f80f1b1f0cc4aedd","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-29 10:21:20.000000000","message":"Patch Set 3:\n\n(2 comments)","accounts_in_message":[],"_revision_number":3},{"id":"d0827719c683d2893b7e2489923b4487d3814a9d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-30 11:06:18.000000000","message":"Uploaded patch set 4.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":4},{"id":"03dedf7268ee3b01e2d916a7d40fe7e7806469e8","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-30 11:07:23.000000000","message":"Patch Set 4:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":4},{"id":"630795ed5bb8283f083e955f02cfc3f51fc34a15","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-30 11:08:35.000000000","message":"Patch Set 4:\n\n(4 comments)","accounts_in_message":[],"_revision_number":4},{"id":"f0f476be61e688da5669e910e804dddf78fa60d3","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-30 11:19:44.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"a376d1f08b2b962b2786bdcfdb29955428f7997f","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-30 11:38:29.000000000","message":"Patch Set 4:\n\n(5 comments)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/6de304118067494ebee7616bc93553ed\n\n- teim-code-review https://zuul.teim.app/t/main/build/64937ee8d5014940a6c0c0fd37015ca7 : SUCCESS in 16m 27s\n\nWarning:\n  Removing role:administrator from admin_api and from the ContextHook is_admin check is a backward-incompatible change for any deployment that assigned the non-standard \u0027administrator\u0027 role. The release note documents this, but there is no code-level deprecation warning or fallback. Impact: Deployments using \u0027administrator\u0027 will silently lose admin access after upgrade. The release note covers this, but operators who skip release notes or automate upgrades could experience an outage with no runtime warning indicating the cause. Recommendation: This is acceptable given the release-note documentation, but consider adding a startup log warning for one release cycle if is_admin detection sees \u0027administrator\u0027 but not \u0027admin\u0027 in roles, to aid operator migration diagnostics.\n  The enforce_new_defaults\u003dFalse override is set in two places (authorize_wsgi.init_enforcer and policy_fixture.PolicyFixture). If one is updated and the other forgotten, production and test behavior will diverge silently. Impact: A future patch that flips the production default to True but misses the test fixture would cause tests to keep passing with legacy behavior while production enforces new defaults, masking authorization regressions. Recommendation: Add a brief comment in policy_fixture.py noting it must mirror the init_enforcer default, or derive both from a single shared constant. Track the override removal in the 2027.1 milestone per the release note.","accounts_in_message":[],"_revision_number":4},{"id":"7d719455d56169446c4aab384a7c2dabfc9e6482","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-30 12:11:41.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/366e643b7a184976b68886400a9d62d0\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f0903d8e51a94f5abee9819455b6aa2d : SUCCESS in 4m 03s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d057370ce3014454a65621c8a3f8f56a : SUCCESS in 3m 56s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/635d1d17ed5141eebce459605db73967 : SUCCESS in 6m 21s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/4fde1f959ea940ea8048ba1aac9bb492 : SUCCESS in 3m 41s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/0b692455eca0436d90530c8d7b8edd6d : SUCCESS in 3m 39s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/d80361abb39a4985979a46680a04e6b3 : SUCCESS in 5m 38s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/7ed201159a4c4242a0a4b4be7ba3f53f : SUCCESS in 6m 07s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/91e980fb1b684d9c8beba4f38033e470 : SUCCESS in 39m 16s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/21b7cc2b63814256841990e43923457f : SUCCESS in 22m 04s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/62ea5840b05d464595f70f289517b5d3 : SUCCESS in 55m 24s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/9363fb45ce8940f48df20bb8c7bdad9e : SUCCESS in 59m 00s","accounts_in_message":[],"_revision_number":4},{"id":"1b84dbe0b59b96a3c03456b2303a233240741c16","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-07-01 10:21:00.000000000","message":"Patch Set 4: Code-Review+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"7d0480930d4bf91edfba81c94a01af61e3122657","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-07-02 08:26:22.000000000","message":"Patch Set 4: Code-Review+1","accounts_in_message":[],"_revision_number":4},{"id":"861fe129f6c9ddfc5aad174bce85aeef61c00a86","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-06 22:23:10.000000000","message":"Patch Set 4: Workflow-1\n\n(4 comments)","accounts_in_message":[],"_revision_number":4},{"id":"f5354a6daa00aa8eae046df3dacaafd07a57188a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-20 14:41:16.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n* Workflow-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"7e9f3e3f76a1a17035bd5e36845cea70bea19a04","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 14:41:57.000000000","message":"Patch Set 5:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":5},{"id":"bc4cca2d33973ee1de447f68b2fe0c249b1efc3d","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-20 14:48:48.000000000","message":"Patch Set 5:\n\n(3 comments)","accounts_in_message":[],"_revision_number":5},{"id":"83ae0ccbc3d55716b8a7434fddae1612d3ed98f5","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 15:50:34.000000000","message":"Patch Set 5:\n\n(1 comment)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/82f7ff97facf427e945debc189ea4f9a\n\n- teim-code-review https://zuul.teim.app/t/main/build/d279dc37cc7f43b8922a21f1bc1e3886 : SUCCESS in 9m 36s","accounts_in_message":[],"_revision_number":5},{"id":"c27298b3f2b9a2189a0fe37eb39388391d6343bc","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-20 15:56:00.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/4ea4b7583a234e8da920bc3c0a15a4ba\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/59f332dba3484761acd5d4f9c21324d1 : SUCCESS in 5m 47s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/9e51d95b5f934068954034e9235785e9 : SUCCESS in 3m 52s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f3c96ddb441d403397b6ab7d95bc48a0 : SUCCESS in 8m 27s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e17f1e1954e24bf9908c28b44f5690ba : SUCCESS in 4m 22s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/ad7d25cacf674aa993833df8ed500d38 : SUCCESS in 3m 25s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/cca283c162b94c14a24db01aec2bcbea : SUCCESS in 3m 38s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/2aa8818c033047e4b53f9de457a40915 : SUCCESS in 6m 00s (non-voting)\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/2cd5f493205d41c9a3ea430a65e3c1a8 : SUCCESS in 4m 22s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/bddd023a32db49e4860f1bb09f0fee23 : SUCCESS in 1h 03m 50s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/0222f55e1f764646abf2db24bb0cc8ea : SUCCESS in 41m 54s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/3489ce2c8fc74e178f037fb8d1dc6523 : SUCCESS in 1h 08m 15s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/e84f55ccce4f4430bd7bd7e20f0a7e3d : SUCCESS in 40m 15s","accounts_in_message":[],"_revision_number":5},{"id":"34151400db590851f9600ed58c85ec2155f1574f","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-20 21:11:19.000000000","message":"Patch Set 5: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"d3104f8d3eeaee25baa60ecaa34cf80d0f18ed15","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-07-21 06:59:24.000000000","message":"Patch Set 5: Code-Review+1","accounts_in_message":[],"_revision_number":5},{"id":"cf7fa2a83253b31f4f143d3eb6edfbd9e0165331","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-07-21 09:30:52.000000000","message":"Patch Set 5: Code-Review+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"0395d17edf4ed54b270973d2db6ea928b2b925ed","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-21 10:34:26.000000000","message":"Uploaded patch set 6: Patch Set 5 was rebased.\n\nCopied Votes:\n* Code-Review+1, Code-Review+2 (copy condition: \"**changekind:TRIVIAL_REBASE** OR is:MIN\")\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":6},{"id":"06eff2a5644a0868cfa670d6e90cfea7267f9dba","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-21 10:35:09.000000000","message":"Patch Set 6:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":6},{"id":"da0922dfefcb9e22aa87c7932b97b1a13203efe8","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-21 10:58:30.000000000","message":"Patch Set 6:\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/d4772af72c8843ac8d7f63f162facc90\n\n- teim-code-review https://zuul.teim.app/t/main/build/c0d8a438f8d9486f98309e68663d3501 : SUCCESS in 11m 31s","accounts_in_message":[],"_revision_number":6},{"id":"766464085ae6ffea82e76c2eada31d15588d4c94","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 11:44:55.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/268217c0443d4b5f8a1a3cdd4b3588a2\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/21dfbd1ae87c40ccb3ad7a2ab35517f8 : SUCCESS in 4m 55s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3ffec1fe54124dc19ae333661e333a12 : SUCCESS in 4m 42s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f467767ea1404c30bbb3c3f401adeff7 : SUCCESS in 7m 55s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/470f0f413a2b475f86385fb4653f8c5f : SUCCESS in 4m 23s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/b0e8b1c4c0944520842310c50769e958 : SUCCESS in 3m 58s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/707e84d839d44a10a96858945f18f4c9 : SUCCESS in 5m 54s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/99ab8e4c06e24d19a2af5b3a83219376 : SUCCESS in 6m 39s (non-voting)\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/862146b9bf864556a916bb68c48c84bf : SUCCESS in 4m 01s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/1f5f779994e149c58f508baec367d436 : SUCCESS in 53m 53s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/c90a365957da4e9992f2d12e55ba03db : SUCCESS in 43m 52s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/4f2e9236aa984dd39e20c0632360cba0 : SUCCESS in 1h 01m 04s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/6951277e89b64d43927920120ab5023d : SUCCESS in 53m 15s","accounts_in_message":[],"_revision_number":6},{"id":"de2a57994a0022b2880291c5d5295d3b6f077217","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-21 11:45:02.000000000","message":"Patch Set 6: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":6},{"id":"554dc92d95e67e0f76fcc9c63b963503aa1c2d3a","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 11:45:33.000000000","message":"Patch Set 6: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":6},{"id":"d90ba3e84bd7148daf3bd605dbd7b415eb756221","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:49:42.000000000","message":"Patch Set 6: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/4aa59eb6beef459ea42761bc32c5c6de\n\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/8cf1d81de461422399d860712cb02a87 : SUCCESS in 3m 56s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/88ace536d52442488d695dfbe6ed5734 : SUCCESS in 8m 44s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/c757ecec81544579b6d3023ca5d54f20 : SUCCESS in 3m 35s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/ffa7101f0004415d8604d016b43946b2 : SUCCESS in 3m 35s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/cea25b04e76243b6afb3ebf5d1f0c65f : SUCCESS in 3m 25s\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/eee6db313a73403987fbe099f506d6e1 : SUCCESS in 3m 44s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/6507ab5db9104a7f9587189b223fc988 : SUCCESS in 58m 00s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/401ceeddab5b4d759f67000d352e9a13 : SUCCESS in 34m 34s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/bf4857ecf3814b9aac5b26130d458bd3 : SUCCESS in 44m 42s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/abd8c18531b74cb6927090b9fb80043b : SUCCESS in 52m 33s","accounts_in_message":[],"_revision_number":6},{"id":"3a3ab53f749eced2c803b2d2ab8428263176b153","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:49:43.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":6},{"id":"eeec7093d09b60ea77e3dac16a036e35fb249d97","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:51:23.000000000","message":"Patch Set 6:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/a06ada6fceb844f98681bee55449b016\n\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/5dfb3e14b6e641a4b4978a90a3c9aa80 : SUCCESS in 1m 06s\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/fbfcb93fc80f47d1a3b71238ffff66b3 : SUCCESS in 1m 11s","accounts_in_message":[],"_revision_number":6}],"current_revision_number":6,"current_revision":"78234921755dd7ab6a4bacb0e583aa16db4261b7","revisions":{"5e889a7d598046fd69b3d8118c6d167dcad16b42":{"kind":"REWORK","_number":1,"created":"2026-06-08 15:33:48.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/92/992292/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/92/992292/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/92/992292/1"}}},"commit":{"parents":[{"commit":"233f2a5b7e396c24bf15ae22f8cf64a480666f5c","subject":"Merge \"pci: add OWNER_CYBORG constant and fix trait\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/233f2a5b7e396c24bf15ae22f8cf64a480666f5c"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 10:45:01.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 15:33:11.000000000","tz":60},"subject":"Add SRBAC base rules and enforce_new_defaults override","message":"Add SRBAC base rules and enforce_new_defaults override\n\nAdd project_manager_or_admin and project_member_or_service base rules\nwith their supporting service_api and project_manager_api rules to\ncyborg/policies/base.py. These rules are required by the subsequent\npolicy migration patches for devices, deployables, attributes, and\nARQs.\n\nRemove the non-standard role:administrator alias from admin_api,\naligning with the Keystone bootstrap role set used by Nova and other\nservices.\n\nOverride enforce_new_defaults to False in Cyborg\u0027s default\nconfiguration so that existing deployments continue to work during\nthe SRBAC transition window. Operators can opt in to the new defaults\nby setting enforce_new_defaults\u003dTrue explicitly. Since oslo.policy\nnow defaults enforce_new_defaults to True, this explicit override is\nrequired to preserve backward-compatible authorization during the\nmigration.\n\nAdd project_manager_context and project_service_context to the policy\ntest base class for use by subsequent policy migration test patches.\nUpdate ARQ create test authorized contexts to account for the\ndeprecated bridge widening under enforce_new_defaults\u003dFalse.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I959ced4bb01234ea94caef072966d4dfda681df9\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/5e889a7d598046fd69b3d8118c6d167dcad16b42"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/5e889a7d598046fd69b3d8118c6d167dcad16b42"}]},"branch":"refs/heads/master"},"1d5b1414f5d399aac2b565bcd2810fddf86cd050":{"kind":"REWORK","_number":2,"created":"2026-06-10 16:55:28.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/92/992292/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/92/992292/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/92/992292/2"}}},"commit":{"parents":[{"commit":"ce8c1bde4a9f0cc75ffeb1f649f21af76b7fe551","subject":"Use request context as policy target","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/ce8c1bde4a9f0cc75ffeb1f649f21af76b7fe551"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 10:45:01.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 16:48:45.000000000","tz":60},"subject":"Add SRBAC base rules and enforce_new_defaults override","message":"Add SRBAC base rules and enforce_new_defaults override\n\nAdd project_manager_or_admin and project_member_or_service base rules\nwith their supporting service_api and project_manager_api rules to\ncyborg/policies/base.py. These rules are required by the subsequent\npolicy migration patches for devices, deployables, attributes, and\nARQs.\n\nRemove the non-standard role:administrator alias from admin_api,\naligning with the Keystone bootstrap role set used by Nova and other\nservices.\n\nOverride enforce_new_defaults to False in Cyborg\u0027s default\nconfiguration so that existing deployments continue to work during\nthe SRBAC transition window. Operators can opt in to the new defaults\nby setting enforce_new_defaults\u003dTrue explicitly. Since oslo.policy\nnow defaults enforce_new_defaults to True, this explicit override is\nrequired to preserve backward-compatible authorization during the\nmigration.\n\nAdd project_manager_context and project_service_context to the policy\ntest base class for use by subsequent policy migration test patches.\nUpdate ARQ create test authorized contexts to account for the\ndeprecated bridge widening under enforce_new_defaults\u003dFalse.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I959ced4bb01234ea94caef072966d4dfda681df9\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/1d5b1414f5d399aac2b565bcd2810fddf86cd050"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/1d5b1414f5d399aac2b565bcd2810fddf86cd050"}]},"branch":"refs/heads/master"},"44aeac64279753a95ca7a40ec70ac0f030ea3ffa":{"kind":"NO_CHANGE","_number":3,"created":"2026-06-10 16:57:38.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/92/992292/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/92/992292/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/92/992292/3"}}},"commit":{"parents":[{"commit":"f67f7b6964058fb5505dc86ded6d63ec8e1ca98f","subject":"Use request context as policy target","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/f67f7b6964058fb5505dc86ded6d63ec8e1ca98f"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 10:45:01.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 16:57:22.000000000","tz":60},"subject":"Add SRBAC base rules and enforce_new_defaults override","message":"Add SRBAC base rules and enforce_new_defaults override\n\nAdd project_manager_or_admin and project_member_or_service base rules\nwith their supporting service_api and project_manager_api rules to\ncyborg/policies/base.py. These rules are required by the subsequent\npolicy migration patches for devices, deployables, attributes, and\nARQs.\n\nRemove the non-standard role:administrator alias from admin_api,\naligning with the Keystone bootstrap role set used by Nova and other\nservices.\n\nOverride enforce_new_defaults to False in Cyborg\u0027s default\nconfiguration so that existing deployments continue to work during\nthe SRBAC transition window. Operators can opt in to the new defaults\nby setting enforce_new_defaults\u003dTrue explicitly. Since oslo.policy\nnow defaults enforce_new_defaults to True, this explicit override is\nrequired to preserve backward-compatible authorization during the\nmigration.\n\nAdd project_manager_context and project_service_context to the policy\ntest base class for use by subsequent policy migration test patches.\nUpdate ARQ create test authorized contexts to account for the\ndeprecated bridge widening under enforce_new_defaults\u003dFalse.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I959ced4bb01234ea94caef072966d4dfda681df9\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/44aeac64279753a95ca7a40ec70ac0f030ea3ffa"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/44aeac64279753a95ca7a40ec70ac0f030ea3ffa"}]},"branch":"refs/heads/master"},"5c87780376305d4180f2708082464b3d5dae9513":{"kind":"REWORK","_number":4,"created":"2026-06-30 11:06:18.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/92/992292/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/92/992292/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/92/992292/4"}}},"commit":{"parents":[{"commit":"6b516433c40345cad39cd19044e314a0f0773e65","subject":"Use request context as policy target","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/6b516433c40345cad39cd19044e314a0f0773e65"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 10:45:01.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-29 17:36:05.000000000","tz":60},"subject":"Add SRBAC base rules and enforce_new_defaults override","message":"Add SRBAC base rules and enforce_new_defaults override\n\nAdd project_manager_or_admin and project_member_or_service base rules\nwith their supporting service_api and project_manager_api rules to\ncyborg/policies/base.py. These rules are required by the subsequent\npolicy migration patches for devices, deployables, attributes, and\nARQs.\n\nRemove the non-standard role:administrator alias from admin_api,\naligning with the Keystone bootstrap role set used by Nova and other\nservices.\n\nOverride enforce_new_defaults to False in Cyborg\u0027s default\nconfiguration so that existing deployments continue to work during\nthe SRBAC transition window. Operators can opt in to the new defaults\nby setting enforce_new_defaults\u003dTrue explicitly. Since oslo.policy\nnow defaults enforce_new_defaults to True, this explicit override is\nrequired to preserve backward-compatible authorization during the\nmigration.\n\nAdd project_manager_context and project_service_context to the policy\ntest base class for use by subsequent policy migration test patches.\nUpdate ARQ create test authorized contexts to account for the\ndeprecated bridge widening under enforce_new_defaults\u003dFalse.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I959ced4bb01234ea94caef072966d4dfda681df9\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/5c87780376305d4180f2708082464b3d5dae9513"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/5c87780376305d4180f2708082464b3d5dae9513"}]},"branch":"refs/heads/master"},"9023b12f545f11022d4d009884275f6f94c806f2":{"kind":"REWORK","_number":5,"created":"2026-07-20 14:41:16.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/92/992292/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/92/992292/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/92/992292/5"}}},"commit":{"parents":[{"commit":"2afb66469506b5a2ddea685e4713fc333eddebc1","subject":"Use request context as policy target","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/2afb66469506b5a2ddea685e4713fc333eddebc1"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 10:45:01.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-07-20 12:18:34.000000000","tz":60},"subject":"Add SRBAC base rules and enforce_new_defaults override","message":"Add SRBAC base rules and enforce_new_defaults override\n\nAdd project_manager_or_admin and project_member_or_service base rules\nwith their supporting service_api and project_manager_api rules to\ncyborg/policies/base.py. These rules are required by the subsequent\npolicy migration patches for devices, deployables, attributes, and\nARQs.\n\nRemove the non-standard role:administrator alias from admin_api,\naligning with the Keystone bootstrap role set used by Nova and other\nservices.\n\nOverride enforce_new_defaults to False in Cyborg\u0027s default\nconfiguration so that existing deployments continue to work during\nthe SRBAC transition window. Operators can opt in to the new defaults\nby setting enforce_new_defaults\u003dTrue explicitly. Since oslo.policy\nnow defaults enforce_new_defaults to True, this explicit override is\nrequired to preserve backward-compatible authorization during the\nmigration.\n\nAdd project_manager_context and project_service_context to the policy\ntest base class for use by subsequent policy migration test patches.\nUpdate ARQ create test authorized contexts to account for the\ndeprecated bridge widening under enforce_new_defaults\u003dFalse.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I959ced4bb01234ea94caef072966d4dfda681df9\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/9023b12f545f11022d4d009884275f6f94c806f2"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/9023b12f545f11022d4d009884275f6f94c806f2"}]},"branch":"refs/heads/master"},"78234921755dd7ab6a4bacb0e583aa16db4261b7":{"kind":"TRIVIAL_REBASE","_number":6,"created":"2026-07-21 10:34:26.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/92/992292/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/92/992292/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/92/992292/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/92/992292/6"}}},"commit":{"parents":[{"commit":"9b059f40a6664182f197c4953b72abba885f4c9d","subject":"Use request context as policy target","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/9b059f40a6664182f197c4953b72abba885f4c9d"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 10:45:01.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-07-21 10:31:49.000000000","tz":60},"subject":"Add SRBAC base rules and enforce_new_defaults override","message":"Add SRBAC base rules and enforce_new_defaults override\n\nAdd project_manager_or_admin and project_member_or_service base rules\nwith their supporting service_api and project_manager_api rules to\ncyborg/policies/base.py. These rules are required by the subsequent\npolicy migration patches for devices, deployables, attributes, and\nARQs.\n\nRemove the non-standard role:administrator alias from admin_api,\naligning with the Keystone bootstrap role set used by Nova and other\nservices.\n\nOverride enforce_new_defaults to False in Cyborg\u0027s default\nconfiguration so that existing deployments continue to work during\nthe SRBAC transition window. Operators can opt in to the new defaults\nby setting enforce_new_defaults\u003dTrue explicitly. Since oslo.policy\nnow defaults enforce_new_defaults to True, this explicit override is\nrequired to preserve backward-compatible authorization during the\nmigration.\n\nAdd project_manager_context and project_service_context to the policy\ntest base class for use by subsequent policy migration test patches.\nUpdate ARQ create test authorized contexts to account for the\ndeprecated bridge widening under enforce_new_defaults\u003dFalse.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I959ced4bb01234ea94caef072966d4dfda681df9\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/78234921755dd7ab6a4bacb0e583aa16db4261b7"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/78234921755dd7ab6a4bacb0e583aa16db4261b7"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
