)]}'
{"id":"openstack%2Fcyborg~992294","triplet_id":"openstack%2Fcyborg~master~I023e57130c3c5b2c262530480288a2bed50c0389","project":"openstack/cyborg","branch":"master","topic":"bp/consistent-and-secure-rbac","attention_set":{},"removed_from_attention_set":{"11604":{"account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"last_update":"2026-07-21 11:45:24.000000000","reason":"\u003cGERRIT_ACCOUNT_11604\u003e replied on the change","reason_account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},"34452":{"account":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"last_update":"2026-07-21 09:36:30.000000000","reason":"\u003cGERRIT_ACCOUNT_34452\u003e replied on the change","reason_account":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}},"28006":{"account":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"last_update":"2026-06-30 12:28:34.000000000","reason":"removed on reply"},"12393":{"account":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"last_update":"2026-07-21 07:01:05.000000000","reason":"\u003cGERRIT_ACCOUNT_12393\u003e replied on the change","reason_account":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"}}},"hashtags":[],"change_id":"I023e57130c3c5b2c262530480288a2bed50c0389","subject":"Migrate device policies to DocumentedRuleDefault","status":"MERGED","created":"2026-06-08 15:33:48.000000000","updated":"2026-07-21 12:52:30.000000000","submitted":"2026-07-21 12:49:47.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":15,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"992294-bp/consistent-and-secure-rbac","meta_rev_id":"bb864a6cbe13c0360c1f347ebc80f3214267997f","_number":992294,"virtual_id_number":992294,"owner":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-07-21 12:49:46.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"recommended":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"all":[{"value":1,"date":"2026-07-21 10:34:26.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":2,"date":"2026-07-21 11:45:24.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":1,"date":"2026-07-21 10:34:26.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":1,"date":"2026-07-21 11:45:24.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}],"CC":[{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-08 17:02:16.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-06-22 08:35:31.000000000","updated_by":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"reviewer":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"state":"CC"},{"updated":"2026-06-26 08:26:08.000000000","updated_by":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"reviewer":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"state":"REVIEWER"},{"updated":"2026-07-01 13:21:11.000000000","updated_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"reviewer":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"state":"REVIEWER"}],"messages":[{"id":"7f5bb0fcaf85378fbd8b35cd17626939ddb92c7e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-08 15:33:48.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"15539dd59614a98a2180d31522713df21dae3463","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-08 17:02:16.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/adb189e624f846a4a525d1a49483b96d\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c7db965a956e4bd0bb08206b6c360fe0 : SUCCESS in 7m 06s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3a6183909b024b0291d4d4d435daf217 : SUCCESS in 4m 55s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/68991ae17b4649458710294f8e28dead : SUCCESS in 7m 53s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/694ff0b35d584ed988c1aaa2aafed2e2 : SUCCESS in 4m 03s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/b9f20fd4451f47bf839f3933993baae0 : SUCCESS in 3m 43s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/66c09e06a5224182b9060dd61c6eb7be : SUCCESS in 4m 30s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/81b142fd8edf416eac27f4c705d76e85 : SUCCESS in 5m 22s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/89af5fef93664e64ac1ea12c7b6404b2 : SUCCESS in 31m 29s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/e0cd31a2716d4aef8a0f8eab9f2295df : SUCCESS in 34m 08s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/237d305655104ac9b0ae8de778450ef8 : SUCCESS in 1h 01m 59s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/5f1fd39e40654e979ea4c92d3dc4d624 : SUCCESS in 1h 05m 00s","accounts_in_message":[],"_revision_number":1},{"id":"e844105988e5a35b9457e983c64baf7f71924dbd","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-08 17:58:46.000000000","message":"Topic set to bp/consistent-and-secure-rbac","accounts_in_message":[],"_revision_number":1},{"id":"907aaa1e7b2b1f460b48ae03fdd8a0818a4e6da4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 16:55:28.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"3da7601a40fadd76fcc1cff0c431bb7def79ca73","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 16:57:38.000000000","message":"Uploaded patch set 3: New patch set was added with same tree, parent tree, and commit message as Patch Set 2.","accounts_in_message":[],"_revision_number":3},{"id":"5268171c2991f65c9334531448bf3168fc861b01","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 17:06:13.000000000","message":"Uploaded patch set 4: Patch Set 3 was rebased.","accounts_in_message":[],"_revision_number":4},{"id":"383530b1da214b4d042bf74756de4a28a2f67c49","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 18:10:18.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/cf1ffa475d2d42e79200f012f5a4770f\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/7bff62e0a4764dddb3eaa350700082e1 : SUCCESS in 3m 32s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/c38c10a4a3614a0d96f041b8a0727b0e : SUCCESS in 5m 58s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/612e89a0ee23459db69c633cff43c269 : SUCCESS in 4m 19s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/88b649f06a134a99ab0311deb2dcdefc : SUCCESS in 4m 13s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/9fc69e72b732456fa235dca00c9c6ee0 : SUCCESS in 3m 50s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/1db21c4061be4b92ade397bcc5bec30f : SUCCESS in 4m 00s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/1f2dcf8e6a3443428e5be468a6e2d752 : SUCCESS in 6m 29s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/026a617235fe4ef0b58f4c0ecc01e304 : SUCCESS in 31m 24s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/aee180469fd64015a2d61cb81c0eb42c : SUCCESS in 29m 00s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/161276d7d67a459a8b3800b35d96669f : SUCCESS in 55m 36s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/a0830d295ebc45c6932ecf0b2a1ce77f : SUCCESS in 57m 23s","accounts_in_message":[],"_revision_number":4},{"id":"4a3a22811188ec92f390154003ac2315816f188a","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-22 08:35:15.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"667289aba36b40a96b102f63c30caa41f50897a8","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 08:35:31.000000000","message":"Patch Set 4:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":4},{"id":"1b4db4f1724c15bc278b3fbb5ac7ea8454b25e0b","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 10:13:48.000000000","message":"Patch Set 4:\n\nBuild failed (automatic-ci pipeline). To rerun just this ci comment\n\"teim-ci: auto\". To rerun other ci jobs comment \"recheck\".\nNote this ci does run on \"recheck\".\n\nhttps://zuul.teim.app/t/main/buildset/40659096e65e43f48f61adafdda50c5c\n\n- teim-code-review https://zuul.teim.app/t/main/build/1a5e07a915d54e8f8ec862b653fb50de : FAILURE in 16m 33s","accounts_in_message":[],"_revision_number":4},{"id":"e9ac7d3ac2a9524ac18c12da08ccd37c7e752a6b","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-22 23:45:42.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"0a740ad5cb200b02cbfc9d4491fd74bf5e1fc8b8","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 23:45:54.000000000","message":"Patch Set 4:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":4},{"id":"b64cfdaf565e299b18525ca26cdb4be634b604d1","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-23 00:27:35.000000000","message":"Patch Set 4:\n\n(3 comments)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/bb51436df0a14bcab453fccf24f3467e\n\n- teim-code-review https://zuul.teim.app/t/main/build/484bede90fcf4f4a9b45737a3e6fd86f : SUCCESS in 12m 36s\n\nWarning:\n  The ARQ test file (test_arqs.py) includes explicit system-scope rejection tests (test_list_arq_system_scope_forbidden, test_create_arq_system_scope_forbidden) that assert the handler is never called for system-scoped tokens. The device tests lack equivalent explicit system-scope tests. Impact: While system-scoped contexts are covered by the computed unauthorized context sets, the explicit system-scope tests provide stronger assertions (verifying the handler/mock is never invoked) and serve as clearer regression guards for scope enforcement. Recommendation: Consider adding test_get_all_devices_system_scope_forbidden and test_disable_device_system_scope_forbidden in a follow-up for parity with the ARQ test pattern, though the current coverage via set-difference is functionally adequate.","accounts_in_message":[],"_revision_number":4},{"id":"d80bdd31d97bdb1a4ec344a8e6fb693a01982148","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-26 08:26:08.000000000","message":"Patch Set 4: Code-Review+1\n\n(3 comments)","accounts_in_message":[],"_revision_number":4},{"id":"1e6fbfef0eb3c626eaa61c5c1cf8260f8bebc9a9","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-26 08:34:12.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"aeb39f3ba65cf314974788c6a40ec10db7b85961","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-26 11:37:33.000000000","message":"Patch Set 4:\n\n(2 comments)","accounts_in_message":[],"_revision_number":4},{"id":"e9cb67dcbf6e59f7f6357dfc21e56d7489204efc","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-29 10:07:51.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"3e7171b584f6eaaccceca7c7f20fd87f1c665bc0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-30 11:06:18.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"2dce4dccef1d73c22da84d881f2d59ae35ed7eeb","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-30 11:07:26.000000000","message":"Patch Set 5:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":5},{"id":"6fedbc76e011c65f0b5b38b56b275c1822a48a73","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-30 11:11:12.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"7ca5feabafc98ef6e46876836fe554ecea079a9e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-30 12:07:41.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/559e7e739499467e924d3bf728c7ac7f\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c09ecd599c5a428a89262d8823d8b634 : SUCCESS in 5m 55s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/63ee842466eb4bc296c05974a29cae76 : SUCCESS in 3m 33s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8c3891733a8b4f7494471854bd2c483e : SUCCESS in 7m 25s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/50163d923a9b4abd9673ef4b79340af8 : SUCCESS in 3m 38s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/7360b3638a2f47b6bcb3bcb3f7aedb8b : SUCCESS in 4m 55s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/17d16836a7b9493697559bc651a592ca : SUCCESS in 5m 41s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/f9e15f65363849dbaf8f3abdfb572bfa : SUCCESS in 5m 20s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/249ce2aff22d495dbc7eb7b6ee4b2c77 : SUCCESS in 36m 42s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/7015020c205c4c0a81b9ee5c80afee71 : SUCCESS in 28m 12s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/c2e1a8a0786f4cdd8dd7388fb97eafb6 : SUCCESS in 54m 12s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/b361a2b5f4694b39bcb48a321c4dab55 : SUCCESS in 55m 22s","accounts_in_message":[],"_revision_number":5},{"id":"8a67c20ee916c99d613d7e33e192294395aab94c","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-30 12:28:34.000000000","message":"Patch Set 5:\n\nBuild failed (automatic-ci pipeline). To rerun just this ci comment\n\"teim-ci: auto\". To rerun other ci jobs comment \"recheck\".\nNote this ci does run on \"recheck\".\n\nhttps://zuul.teim.app/t/main/buildset/9bed0342db4148f8a35dcaf0cc1514c7\n\n- teim-code-review https://zuul.teim.app/t/main/build/bbad587fd47748aba47c538bab5e5f0f : TIMED_OUT in 31m 15s","accounts_in_message":[],"_revision_number":5},{"id":"037f302153cfa4f6c2fdd3cf9b840b1adcb4c257","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-07-01 13:21:11.000000000","message":"Patch Set 5: Code-Review+1","accounts_in_message":[],"_revision_number":5},{"id":"d6d90f0122b922971a896f0b8c25e59b8bbb608f","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-06 23:01:31.000000000","message":"Patch Set 5: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"798f813510ee81d79b61d188844d29b563ff5f86","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-07-07 04:30:28.000000000","message":"Patch Set 5: Code-Review+1","accounts_in_message":[],"_revision_number":5},{"id":"fa166866dd5dbaa484d5047250e1429778e95100","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-20 14:41:16.000000000","message":"Uploaded patch set 6.\n\nOutdated Votes:\n* Code-Review+1, Code-Review+2 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":6},{"id":"40af06d572a4cd2801c3f3f0d8f672d14cdd64a5","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 14:42:01.000000000","message":"Patch Set 6:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":6},{"id":"a3a91f79dc0f57326953ad38a37f544cad557573","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-20 15:46:39.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f4b5c7e6ec154de786797e54ebea9479\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/a4f6b210b4134718a4590832745a5cbf : SUCCESS in 5m 00s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/8fbb2ce497b747e7a44fa403174f81c2 : SUCCESS in 4m 26s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a2c2e05316444ac2a1f5fa84e96e1b4d : SUCCESS in 7m 50s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5f4ef60597d94d02970457ac694c7455 : SUCCESS in 3m 37s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/1def4df8c9214fd2883b67a775097582 : SUCCESS in 4m 30s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/78f7a04c78904551affd91f5f6bf60b8 : SUCCESS in 5m 35s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/0f7f6bd89be74d31afef776d8970e48d : SUCCESS in 5m 47s (non-voting)\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/fa70efe2b17846b6b4052ea73ff8da79 : SUCCESS in 4m 58s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/b4d11861065a47a58416d76f91c5f59f : SUCCESS in 40m 34s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/558fffda10cb40f4a76a95129fd96f07 : SUCCESS in 43m 43s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/f56fd0a4a53943219727a00e7604472a : SUCCESS in 54m 14s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/dd1fb76e64c4426889d446b56c286713 : SUCCESS in 58m 58s","accounts_in_message":[],"_revision_number":6},{"id":"2b6f10ebae62fa0b7e28977b87d4869afd1bf59d","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 16:13:24.000000000","message":"Patch Set 6:\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/595e0f44ddea434486531dfab5c0b4c4\n\n- teim-code-review https://zuul.teim.app/t/main/build/63c39f9c95e54e7e99261ee2925ce468 : SUCCESS in 10m 06s","accounts_in_message":[],"_revision_number":6},{"id":"d4c14bbad9b42843dbe2d2bb4870f14fc0d16d4b","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-20 21:15:25.000000000","message":"Patch Set 6: Code-Review+2","accounts_in_message":[],"_revision_number":6},{"id":"fcac31ca56dfbdefa031d34d54a501f98dcf0b98","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-07-21 07:01:05.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"7bf5fa348af9e99a4c70ed809b53a3ffa1723d3e","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-07-21 09:36:30.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"4338ef145e5cdd62da74ab6ba5161e2707d495e1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-21 10:34:26.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.\n\nCopied Votes:\n* Code-Review+1, Code-Review+2 (copy condition: \"**changekind:TRIVIAL_REBASE** OR is:MIN\")\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":7},{"id":"4e9d04a5004ab52b2f69fed655d1e4a42f97a462","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-21 10:35:13.000000000","message":"Patch Set 7:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":7},{"id":"58eb2eb3581a9194b68940ac5eec98aea05a118a","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-21 11:23:11.000000000","message":"Patch Set 7:\n\n(1 comment)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/c72620e57a954204bacb28b7498234e9\n\n- teim-code-review https://zuul.teim.app/t/main/build/42471ce029744e299b153060d38f8354 : SUCCESS in 9m 57s","accounts_in_message":[],"_revision_number":7},{"id":"15f00ae58b47ec6c59247a3eac22894f6831b624","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 11:39:14.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f8cef25976d64503aa6746b957e85d6f\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/4d75ceeba38d424784c33e817a43cd03 : SUCCESS in 5m 46s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/02f55e2f6887410986df94f609789d41 : SUCCESS in 4m 21s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/93e356731c9844abb2372d69da045e66 : SUCCESS in 7m 34s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/b65cfaf4c95e4ba78905e6ea9ed8602a : SUCCESS in 4m 03s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/d5bde2583dde4b1e850aa8ce84ef9267 : SUCCESS in 3m 43s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/4c62d1ef4f934fe1b2587f0695718c50 : SUCCESS in 5m 44s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/e1e78369bd0e4a479f86edcea88b1c58 : SUCCESS in 6m 29s (non-voting)\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/8cd3a6dab1d740b890a58cac2ca96377 : SUCCESS in 4m 01s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/992d636b2063459ba01d3a88ab280da8 : SUCCESS in 52m 01s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/3faddcefcbce44f48cdca48b268e3e3d : SUCCESS in 55m 13s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/df8c5387eaa94ede9785ca06ea4f0803 : SUCCESS in 56m 33s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/259a3e83c52c48abaae4bbc73aac0d9b : SUCCESS in 56m 44s","accounts_in_message":[],"_revision_number":7},{"id":"0f3c24b65fb95e8ac5ae0d9fdc99842cf2c3fd89","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-21 11:45:24.000000000","message":"Patch Set 7: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":7},{"id":"40eb370fa45ceaf33054c16b73345a155fe05311","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 11:46:00.000000000","message":"Patch Set 7: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":7},{"id":"7766a6ea09bbc2b7338fffaa8225ce7801cab68f","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:49:46.000000000","message":"Patch Set 7: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2f3a8c9bea294e6aaf5329941d27aaad\n\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/da8e8f23281541a6989f8e3652a3e3e6 : SUCCESS in 4m 54s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/9cb3d37b654c44aaba97ac8c2213472c : SUCCESS in 7m 52s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/038cbf00f46b45f5bd950f069aa044a8 : SUCCESS in 3m 16s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/663dec5264be46f09b3048e33f7d61b6 : SUCCESS in 3m 51s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/7601d1cb73ea43499835bc0216641da5 : SUCCESS in 3m 54s\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/840def73e27e406bb7da100bf61cdfd8 : SUCCESS in 3m 46s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/4bfc815a480548fb8d5a9e1f4902dd3e : SUCCESS in 54m 14s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/06d8b5e0b3094ffdb3962867ff846c56 : SUCCESS in 38m 34s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/254cb76b788244b597d8d62dbd31228d : SUCCESS in 57m 11s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/3047f33c7bb545d9a05c58852aba839d : SUCCESS in 52m 01s","accounts_in_message":[],"_revision_number":7},{"id":"f8467b07b210a4c0669731d6688a4201c8fdaaff","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:49:47.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":7},{"id":"bb864a6cbe13c0360c1f347ebc80f3214267997f","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:52:30.000000000","message":"Patch Set 7:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/a9adea1294b348d0bf56001580e73567\n\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/b204422433234ac393c107bd422dc797 : SUCCESS in 54s\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ab1a41828da6420facba87d475b83276 : SUCCESS in 54s","accounts_in_message":[],"_revision_number":7}],"current_revision_number":7,"current_revision":"1ddb15cdcadfceac30cdff52f37185736688b8bc","revisions":{"c05027f228bda26556be58e039bf1a54ae595857":{"kind":"REWORK","_number":1,"created":"2026-06-08 15:33:48.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/94/992294/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/94/992294/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/94/992294/1"}}},"commit":{"parents":[{"commit":"1bf5211b73f8498980cec6d581e446b1a6992ea4","subject":"Migrate ARQ policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/1bf5211b73f8498980cec6d581e446b1a6992ea4"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:26:06.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 15:33:11.000000000","tz":60},"subject":"Migrate device policies to DocumentedRuleDefault","message":"Migrate device policies to DocumentedRuleDefault\n\nCreate cyborg/policies/devices.py with DocumentedRuleDefault entries\nfor all four device operations: get_one, get_all, disable, and\nenable.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into hardware topology for capacity planning and\ntroubleshooting. Device disable and enable remain restricted to\ncloud admins as they affect shared physical infrastructure.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new device policies\nand stop loading the legacy device_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I023e57130c3c5b2c262530480288a2bed50c0389\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/c05027f228bda26556be58e039bf1a54ae595857"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/c05027f228bda26556be58e039bf1a54ae595857"}]},"branch":"refs/heads/master"},"0eeba13d30ce4f111157c0b07ca8a36f31a7f130":{"kind":"REWORK","_number":2,"created":"2026-06-10 16:55:28.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/94/992294/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/94/992294/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/94/992294/2"}}},"commit":{"parents":[{"commit":"299f535650212494561eda0969885009904ae8d8","subject":"Migrate ARQ policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/299f535650212494561eda0969885009904ae8d8"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:26:06.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 16:49:44.000000000","tz":60},"subject":"Migrate device policies to DocumentedRuleDefault","message":"Migrate device policies to DocumentedRuleDefault\n\nCreate cyborg/policies/devices.py with DocumentedRuleDefault entries\nfor all four device operations: get_one, get_all, disable, and\nenable.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into hardware topology for capacity planning and\ntroubleshooting. Device disable and enable remain restricted to\ncloud admins as they affect shared physical infrastructure.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new device policies\nand stop loading the legacy device_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I023e57130c3c5b2c262530480288a2bed50c0389\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/0eeba13d30ce4f111157c0b07ca8a36f31a7f130"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/0eeba13d30ce4f111157c0b07ca8a36f31a7f130"}]},"branch":"refs/heads/master"},"aa0db467949188d941eb5440478dd9eb2cc06641":{"kind":"NO_CHANGE","_number":3,"created":"2026-06-10 16:57:38.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/94/992294/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/94/992294/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/94/992294/3"}}},"commit":{"parents":[{"commit":"2419f96816e0eb9c36fc8f9c03b38ae049b980e0","subject":"Migrate ARQ policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/2419f96816e0eb9c36fc8f9c03b38ae049b980e0"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:26:06.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 16:57:22.000000000","tz":60},"subject":"Migrate device policies to DocumentedRuleDefault","message":"Migrate device policies to DocumentedRuleDefault\n\nCreate cyborg/policies/devices.py with DocumentedRuleDefault entries\nfor all four device operations: get_one, get_all, disable, and\nenable.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into hardware topology for capacity planning and\ntroubleshooting. Device disable and enable remain restricted to\ncloud admins as they affect shared physical infrastructure.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new device policies\nand stop loading the legacy device_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I023e57130c3c5b2c262530480288a2bed50c0389\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/aa0db467949188d941eb5440478dd9eb2cc06641"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/aa0db467949188d941eb5440478dd9eb2cc06641"}]},"branch":"refs/heads/master"},"a64a3a88ca6adf2abc3112b8e22fe7e39c5a69ae":{"kind":"TRIVIAL_REBASE","_number":4,"created":"2026-06-10 17:06:13.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/94/992294/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/94/992294/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/94/992294/4"}}},"commit":{"parents":[{"commit":"024b06d6e6047beffe2536c7f2b6c1bebeb6d979","subject":"Migrate ARQ policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/024b06d6e6047beffe2536c7f2b6c1bebeb6d979"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:26:06.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 17:03:36.000000000","tz":60},"subject":"Migrate device policies to DocumentedRuleDefault","message":"Migrate device policies to DocumentedRuleDefault\n\nCreate cyborg/policies/devices.py with DocumentedRuleDefault entries\nfor all four device operations: get_one, get_all, disable, and\nenable.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into hardware topology for capacity planning and\ntroubleshooting. Device disable and enable remain restricted to\ncloud admins as they affect shared physical infrastructure.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new device policies\nand stop loading the legacy device_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I023e57130c3c5b2c262530480288a2bed50c0389\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/a64a3a88ca6adf2abc3112b8e22fe7e39c5a69ae"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/a64a3a88ca6adf2abc3112b8e22fe7e39c5a69ae"}]},"branch":"refs/heads/master"},"d84b6ad47faebd1bc0c810574dd9e5b3e69a3bb9":{"kind":"REWORK","_number":5,"created":"2026-06-30 11:06:18.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/94/992294/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/94/992294/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/94/992294/5"}}},"commit":{"parents":[{"commit":"2819fa5cc5b2de8a4b1fed30070c37164e636313","subject":"Migrate ARQ policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/2819fa5cc5b2de8a4b1fed30070c37164e636313"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:26:06.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-29 17:36:05.000000000","tz":60},"subject":"Migrate device policies to DocumentedRuleDefault","message":"Migrate device policies to DocumentedRuleDefault\n\nCreate cyborg/policies/devices.py with DocumentedRuleDefault entries\nfor all four device operations: get_one, get_all, disable, and\nenable.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into hardware topology for capacity planning and\ntroubleshooting. Device disable and enable remain restricted to\ncloud admins as they affect shared physical infrastructure.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new device policies\nand stop loading the legacy device_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I023e57130c3c5b2c262530480288a2bed50c0389\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/d84b6ad47faebd1bc0c810574dd9e5b3e69a3bb9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/d84b6ad47faebd1bc0c810574dd9e5b3e69a3bb9"}]},"branch":"refs/heads/master"},"4ae887c29ab4d89cc519548a103c889045731624":{"kind":"REWORK","_number":6,"created":"2026-07-20 14:41:16.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/94/992294/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/94/992294/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/94/992294/6"}}},"commit":{"parents":[{"commit":"c5198427e0d4be881bb31caf86e580c7e40f5a8b","subject":"Migrate ARQ policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/c5198427e0d4be881bb31caf86e580c7e40f5a8b"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:26:06.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-07-20 12:59:34.000000000","tz":60},"subject":"Migrate device policies to DocumentedRuleDefault","message":"Migrate device policies to DocumentedRuleDefault\n\nCreate cyborg/policies/devices.py with DocumentedRuleDefault entries\nfor all four device operations: get_one, get_all, disable, and\nenable.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into hardware topology for capacity planning and\ntroubleshooting. Device disable and enable remain restricted to\ncloud admins as they affect shared physical infrastructure.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new device policies\nand stop loading the legacy device_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I023e57130c3c5b2c262530480288a2bed50c0389\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/4ae887c29ab4d89cc519548a103c889045731624"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/4ae887c29ab4d89cc519548a103c889045731624"}]},"branch":"refs/heads/master"},"1ddb15cdcadfceac30cdff52f37185736688b8bc":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-21 10:34:26.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/94/992294/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/94/992294/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/94/992294/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/94/992294/7"}}},"commit":{"parents":[{"commit":"389bb972168f3fcb8fc1c22bd2cf98dfffe3dbeb","subject":"Migrate ARQ policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/389bb972168f3fcb8fc1c22bd2cf98dfffe3dbeb"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:26:06.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-07-21 10:31:49.000000000","tz":60},"subject":"Migrate device policies to DocumentedRuleDefault","message":"Migrate device policies to DocumentedRuleDefault\n\nCreate cyborg/policies/devices.py with DocumentedRuleDefault entries\nfor all four device operations: get_one, get_all, disable, and\nenable.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into hardware topology for capacity planning and\ntroubleshooting. Device disable and enable remain restricted to\ncloud admins as they affect shared physical infrastructure.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new device policies\nand stop loading the legacy device_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: I023e57130c3c5b2c262530480288a2bed50c0389\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/1ddb15cdcadfceac30cdff52f37185736688b8bc"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/1ddb15cdcadfceac30cdff52f37185736688b8bc"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
