)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"c12da84d292a17a913666931c7634641b11daf12","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"65610d8f_43f334ee","updated":"2026-06-29 09:51:08.000000000","message":"Looks good\n\n\nNotes:\n- Deprecated rule added for get_one, get_all, create and delete with admin_api to cyborg/policies/attributes.py\n- DocumentRuleDefault added with project manager role for get_one and get_all, admin role for create and delete.","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"b9bd92a8d08990a411316cdde2be05b498ac9542","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"16ba42b8_d2def168","updated":"2026-06-29 09:44:32.000000000","message":"Looks good.\n\nNotes:\n\n- Deprecated rule added for get_one, get_all, create and delete with admin_api to cyborg/policies/attributes.py\n- DocumentRuleDefault added with project manager role for get_one and get_all, admin role for create and delete.","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"547a01b630a58ae46d4db055d90a6f9dfc5b746c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"2950ed7f_4d7aaad5","updated":"2026-06-22 23:45:55.000000000","message":"teim-ci: auto","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"e3c3e042701eba3f13298011b50a31d5fa06c5e9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"8ab8fede_8e4f26df","updated":"2026-06-22 08:35:25.000000000","message":"teim-ci: auto","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"fa6fc431466fd1d8af2cc9b1a26eef8ac74b2dd5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"db878ace_57d084ad","in_reply_to":"65610d8f_43f334ee","updated":"2026-06-29 10:10:47.000000000","message":"Tempest results from cyborg-tempest-srbac https://review.opendev.org/c/openstack/cyborg/+/992332 \nhttps://5126e99bb555fcd10074-f8d3aa66ce3962c6e3c5c35044bdfdd4.ssl.cf1.rackcdn.com/openstack/21ccea317c924406b12ce9ab3cc22cc5/job-output.txt\n```\n  SRBAC tests for attribites:\n  - test_admin_can_list_attributes — ok (admin via implied manager)\n  - test_reader_cannot_list_attributes — ok (reader lacks manager)\n  - test_member_cannot_list_attributes — ok (member lacks manager)\n```","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"4faab592819c8e9db5a986e457ec2575757d805f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"5934c489_8a26129c","updated":"2026-07-20 21:17:09.000000000","message":"recheck flaky reboot test","commit_id":"c236410d41c88e163681b424db80278f021f8cb0"}],"cyborg/common/policy.py":[{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"b9bd92a8d08990a411316cdde2be05b498ac9542","unresolved":false,"context_lines":[{"line_number":1,"context_line":"# Copyright 2017 Huawei Technologies Co.,LTD."},{"line_number":2,"context_line":"# All Rights Reserved."},{"line_number":3,"context_line":"#"},{"line_number":4,"context_line":"#    Licensed under the Apache License, Version 2.0 (the \"License\"); you may"}],"source_content_type":"text/x-python","patch_set":4,"id":"a5d4617b_f286ee31","side":"PARENT","line":1,"updated":"2026-06-29 09:44:32.000000000","message":"Since all the policies are already migrated to cyborg/policies/attributes.py so this file serves no purpose.","commit_id":"5422d1ca421b2ce779f6707dfec44970c1d5515e"}],"cyborg/policies/attributes.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"83f6973104bb180d7c9539124a61b40eb9bf0315","unresolved":false,"context_lines":[{"line_number":38,"context_line":"    ),"},{"line_number":39,"context_line":"    deprecated_since\u003d\u00272026.2\u0027,"},{"line_number":40,"context_line":")"},{"line_number":41,"context_line":"deprecated_create \u003d policy.DeprecatedRule("},{"line_number":42,"context_line":"    name\u003d\u0027cyborg:attribute:create\u0027,"},{"line_number":43,"context_line":"    check_str\u003d\u0027rule:admin_api\u0027,"},{"line_number":44,"context_line":"    deprecated_reason\u003d("}],"source_content_type":"text/x-python","patch_set":4,"id":"ed071584_c6013758","line":41,"updated":"2026-06-23 00:57:45.000000000","message":"Deprecated_rule bridges for create/delete use check_str\u003d\u0027rule:admin_api\u0027 while the new default (base.ADMIN) is also \u0027rule:admin_api\u0027. The bridge is identical to the new default, making it a behavioral no-op under enforce_new_defaults\u003dFalse.\n\n**Severity**: SUGGESTION | **Confidence**: 0.9\n\n**Benefit**: Removing the no-op bridges or adding a clarifying comment would reduce confusion about why a rule is deprecated to itself. However, this pattern is consistent with sibling files (devices.py, deployables.py), so keeping it maintains series consistency.\n\n**Recommendation**:\nConsider either: (a) keep for series consistency since devices.py and deployables.py use the same pattern for their admin-only operations, or (b) add a brief comment noting that the deprecated bridge is intentionally identical because the check_str is unchanged, serving only to trigger oslo.policy deprecation logging for operators tracking the migration.","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"28516ab65c10c3f49506ad8d926acf09de882772","unresolved":false,"context_lines":[{"line_number":39,"context_line":"    ),"},{"line_number":40,"context_line":"    deprecated_since\u003dversionutils.deprecated.GAZPACHO,"},{"line_number":41,"context_line":")"},{"line_number":42,"context_line":"deprecated_create \u003d policy.DeprecatedRule("},{"line_number":43,"context_line":"    name\u003d\u0027cyborg:attribute:create\u0027,"},{"line_number":44,"context_line":"    check_str\u003d\u0027rule:admin_api\u0027,"},{"line_number":45,"context_line":"    deprecated_reason\u003d("}],"source_content_type":"text/x-python","patch_set":5,"id":"aa5a504d_72453d68","line":42,"updated":"2026-06-30 13:06:17.000000000","message":"The create/delete deprecated_reason says admin_api \u0027is retained as the default\u0027, but both the deprecated bridge check_str and the new endpoint check_str (base.ADMIN) resolve to rule:admin_api. Nothing changes for write ops, so the bridge is a no-op and the message is slightly misleading.\n\n**Severity**: SUGGESTION | **Confidence**: 0.8\n\n**Benefit**: Clearer deprecation messaging helps operators auditing oslo.policy warnings understand whether write-op behavior is actually changing during the SRBAC transition.\n\n**Recommendation**:\nConsider rewording the create/delete deprecated_reason to state explicitly that the new default intentionally remains admin-only and the bridge exists only to emit the standard SRBAC deprecation notice, so the message does not imply a behavioral change that is not occurring.","commit_id":"090214c9b337a3ae881a841662a7d0e93eebb3d1"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"28516ab65c10c3f49506ad8d926acf09de882772","unresolved":false,"context_lines":[{"line_number":63,"context_line":"attribute_policies \u003d ["},{"line_number":64,"context_line":"    policy.DocumentedRuleDefault("},{"line_number":65,"context_line":"        name\u003d\u0027cyborg:attribute:get_all\u0027,"},{"line_number":66,"context_line":"        check_str\u003dbase.PROJECT_MANAGER_OR_ADMIN,"},{"line_number":67,"context_line":"        description\u003d\u0027Retrieve all attribute records\u0027,"},{"line_number":68,"context_line":"        operations\u003d["},{"line_number":69,"context_line":"            {\u0027path\u0027: \u0027/v2/attributes\u0027, \u0027method\u0027: \u0027GET\u0027},"}],"source_content_type":"text/x-python","patch_set":5,"id":"04819a61_3e44f3b0","line":66,"updated":"2026-06-30 13:06:17.000000000","message":"The new enforce_new_defaults\u003dTrue read-authorized set omits project_reader_context, correctly reflecting that get_all/get_one require role:manager, matching the device and deployable migrations. There is no reader read path for attributes, unlike ARQs.\n\n**Severity**: SUGGESTION | **Confidence**: 0.7\n\n**Benefit**: Confirming the persona choice is deliberate and documented avoids later debate about whether attributes should be reader-visible like ARQs.\n\n**Recommendation**:\nNo code change required. If not already captured elsewhere, add a one-line design note (module docstring or blueprint) stating that attribute metadata is manager-only because it exposes physical-infrastructure capacity details, distinguishing it from per-project ARQs which remain reader-visible.","commit_id":"090214c9b337a3ae881a841662a7d0e93eebb3d1"}],"cyborg/tests/unit/policies/test_attributes.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"83f6973104bb180d7c9539124a61b40eb9bf0315","unresolved":false,"context_lines":[{"line_number":66,"context_line":"        # same widening pattern as get_all."},{"line_number":67,"context_line":"        # create uses need_target\u003dFalse but both new default and"},{"line_number":68,"context_line":"        # deprecated bridge are admin_api, so no widening occurs."},{"line_number":69,"context_line":"        # delete uses need_target\u003dTrue with no _get_resource"},{"line_number":70,"context_line":"        # (target {}), admin-only."},{"line_number":71,"context_line":"        self.admin_only_authorized_contexts \u003d ["},{"line_number":72,"context_line":"            self.legacy_admin_context,"}],"source_content_type":"text/x-python","patch_set":4,"id":"0d8a2258_8c6d1b8b","line":69,"updated":"2026-06-23 00:57:45.000000000","message":"Test comment at line 69 says \u0027delete uses need_target\u003dTrue with no _get_resource (target {}), admin-only\u0027 but sibling patch 992722 removed need_target entirely. The decorator now always uses context.project_id/user_id as target. The comment is factually wrong.\n\n**Severity**: WARNING | **Confidence**: 0.9\n\n**Impact**: The stale comment misleads developers about how policy targets are constructed. It implies delete passes an empty target dict {}, but the target always carries the caller\u0027s project_id. Test behavior is correct (admin-only) but the reasoning is wrong.\n\n**Suggestion**:\nRewrite the comment to reflect the current authorize_wsgi behavior: all four operations (get_all, get_one, create, delete) use the request context as the policy target. For create and delete the check_str is rule:admin_api (role:admin), so only admin contexts pass regardless of target.","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"c12da84d292a17a913666931c7634641b11daf12","unresolved":false,"context_lines":[{"line_number":79,"context_line":"    @mock.patch(\u0027cyborg.objects.Attribute.get_by_filter\u0027, autospec\u003dTrue)"},{"line_number":80,"context_line":"    def test_get_all_attributes_success(self, mock_list):"},{"line_number":81,"context_line":"        mock_list.return_value \u003d [self.fake_attr_obj]"},{"line_number":82,"context_line":"        for context in self.read_all_authorized_contexts:"},{"line_number":83,"context_line":"            headers \u003d self.gen_headers(context)"},{"line_number":84,"context_line":"            response \u003d self.get_json(ATTRIBUTE_URL, headers\u003dheaders)"},{"line_number":85,"context_line":"            self.assertIsInstance(response[\u0027attributes\u0027], list)"}],"source_content_type":"text/x-python","patch_set":4,"id":"295523ef_33f8c696","line":82,"range":{"start_line":82,"start_character":28,"end_line":82,"end_character":57},"updated":"2026-06-29 09:51:08.000000000","message":"+1 for renaming to read_all_authorized_contexts","commit_id":"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"28516ab65c10c3f49506ad8d926acf09de882772","unresolved":false,"context_lines":[{"line_number":46,"context_line":"        # project_id:%(project_id)s). The project_id:%(project_id)s"},{"line_number":47,"context_line":"        # branch therefore matches every project-scoped context. Only"},{"line_number":48,"context_line":"        # system-scoped contexts are rejected by enforce_scope\u003dTrue."},{"line_number":49,"context_line":"        self.read_all_authorized_contexts \u003d ["},{"line_number":50,"context_line":"            self.legacy_admin_context,"},{"line_number":51,"context_line":"            self.project_admin_context,"},{"line_number":52,"context_line":"            self.legacy_owner_context,"}],"source_content_type":"text/x-python","patch_set":5,"id":"c969c9c2_d09109dc","line":49,"updated":"2026-06-30 13:06:17.000000000","message":"The legacy AttributePolicyTest read_all_authorized_contexts list includes project_service_context and project_foo_context, which pass reads only via the DEPRECATED_ADMIN_OR_OWNER bridge widening under enforce_new_defaults\u003dFalse, not via the intended persona rule.\n\n**Severity**: SUGGESTION | **Confidence**: 0.7\n\n**Benefit**: Makes the transitional, widened nature of the legacy-defaults test explicit, reducing the chance a future contributor reads the list as the intended end-state authorization matrix.\n\n**Recommendation**:\nOptionally split the legacy read-authorized list into intended persona contexts (admin, manager) versus additionally-allowed-by-bridge contexts (member, reader, foo, other-project-member, service) with a brief inline note that the latter drop out once bridges are removed in 2027.2. Cosmetic; current assertions are functionally correct.","commit_id":"090214c9b337a3ae881a841662a7d0e93eebb3d1"}]}
