)]}'
{"id":"openstack%2Fcyborg~992296","triplet_id":"openstack%2Fcyborg~master~Ic3c016148696929436e481b25045d6f3fb67beb7","project":"openstack/cyborg","branch":"master","topic":"bp/consistent-and-secure-rbac","attention_set":{},"removed_from_attention_set":{"11604":{"account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"last_update":"2026-07-21 11:45:41.000000000","reason":"\u003cGERRIT_ACCOUNT_11604\u003e replied on the change","reason_account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}},"34452":{"account":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"last_update":"2026-07-21 09:39:48.000000000","reason":"\u003cGERRIT_ACCOUNT_34452\u003e replied on the change","reason_account":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}},"12393":{"account":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"last_update":"2026-07-21 07:01:41.000000000","reason":"\u003cGERRIT_ACCOUNT_12393\u003e replied on the change","reason_account":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"}}},"hashtags":[],"change_id":"Ic3c016148696929436e481b25045d6f3fb67beb7","subject":"Migrate attribute policies to DocumentedRuleDefault","status":"MERGED","created":"2026-06-08 15:33:48.000000000","updated":"2026-07-21 12:55:03.000000000","submitted":"2026-07-21 12:55:03.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":13,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"992296-bp/consistent-and-secure-rbac","meta_rev_id":"7e664259be34b71192f06e94c4275ee8f2b5e2b1","_number":992296,"virtual_id_number":992296,"owner":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-07-21 12:55:03.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"recommended":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"all":[{"value":1,"date":"2026-07-21 10:34:26.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":2,"date":"2026-07-21 11:45:41.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":1,"date":"2026-07-21 10:34:26.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":0,"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},{"value":1,"date":"2026-07-21 11:45:41.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}],"CC":[{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-08 16:58:12.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-06-22 08:35:39.000000000","updated_by":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"reviewer":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"state":"CC"},{"updated":"2026-06-29 09:44:32.000000000","updated_by":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"reviewer":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"state":"REVIEWER"},{"updated":"2026-07-01 13:30:11.000000000","updated_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"reviewer":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"state":"REVIEWER"}],"messages":[{"id":"c362490b78db8b11bf29fe64b2d36c02b99b4511","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-08 15:33:48.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"5dcc13ea7da1e0d80a53486d40e26dd90078f279","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-08 16:58:12.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/6dfe2127e424459b9d577c889cb2e460\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/06a60a5adf0b414d9144a53451dfe666 : SUCCESS in 4m 42s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/832e5e2dc88f4dba9b84782f99cc1ecd : SUCCESS in 5m 57s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/9fb09a2731224d3ea8854fab48062b70 : SUCCESS in 8m 14s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/1b5627039402428b9d04ff06f112f20e : SUCCESS in 3m 41s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/476a9a15e47d4cde91eed7b48d9d1351 : SUCCESS in 2m 53s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/fa2babf814d24825b8c100b7e9df9105 : SUCCESS in 3m 44s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/754310607e154df9a5fc44276f2f5ba5 : SUCCESS in 5m 50s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/d891f1c8f82f4e96b894e75b438d0dbc : SUCCESS in 30m 09s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/728c11a14f1c45c98d9695b11ac9ef2c : SUCCESS in 28m 59s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/d5722f19adcb43428f1640a81430648a : SUCCESS in 56m 33s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/8e1021829ee14fb0afec5be344d1d0c9 : SUCCESS in 56m 21s","accounts_in_message":[],"_revision_number":1},{"id":"b96b3992b5e066d78e1e615f09c3c83d8c05817f","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-08 17:58:53.000000000","message":"Topic set to bp/consistent-and-secure-rbac","accounts_in_message":[],"_revision_number":1},{"id":"7dc247786ffc9ca03c99d765bec65dd3ad513936","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 16:55:28.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"103375822705702a6f883482b79edb3e88880ad1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 16:57:38.000000000","message":"Uploaded patch set 3: New patch set was added with same tree, parent tree, and commit message as Patch Set 2.","accounts_in_message":[],"_revision_number":3},{"id":"7b10791ee146b80b1f74d3c055e612622062d643","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-10 17:06:13.000000000","message":"Uploaded patch set 4: Patch Set 3 was rebased.","accounts_in_message":[],"_revision_number":4},{"id":"12a6427601e02f4f706bb3ee90f948182bb2c377","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-10 18:06:04.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/1e37c8439e2649039b2db21ae2996285\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/63502787cebb49678c637bc3aef7712d : SUCCESS in 4m 58s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/609a308238174c33b9134b87cf39eee6 : SUCCESS in 4m 29s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a83c20d3076f45b0969217c6896ab4ac : SUCCESS in 7m 54s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/657cbc6508ef4d5fa687dad2c1c58bc5 : SUCCESS in 3m 44s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/fd7066cb4ae24cb38b280f6afc4a7a1a : SUCCESS in 2m 52s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/93e04581a5f145faa7d431afe17fe70e : SUCCESS in 5m 59s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/61460adf658f4c96b56bea33cac83371 : SUCCESS in 8m 41s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/d7763d9bd0054837a17878570b46c402 : SUCCESS in 37m 07s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/4ff175dfa3984e1a9b4cbe91e428c3dc : SUCCESS in 33m 34s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/f6f654dfbb494ad6a7deab1c58e07431 : SUCCESS in 50m 20s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/1db7db92f33b4bb898751047c3289227 : SUCCESS in 53m 49s","accounts_in_message":[],"_revision_number":4},{"id":"e3c3e042701eba3f13298011b50a31d5fa06c5e9","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-22 08:35:25.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"996399ce5356d153760fce3e61104733a2a2df62","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 08:35:39.000000000","message":"Patch Set 4:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":4},{"id":"c377d8b0068442e6ee640e67181f26793bd4733b","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 10:21:45.000000000","message":"Patch Set 4:\n\nBuild failed (automatic-ci pipeline). To rerun just this ci comment\n\"teim-ci: auto\". To rerun other ci jobs comment \"recheck\".\nNote this ci does run on \"recheck\".\n\nhttps://zuul.teim.app/t/main/buildset/ea373af0ce734451ac8bcd6bec06b04d\n\n- teim-code-review https://zuul.teim.app/t/main/build/bef9bbc0625046979e408b5c1939c2ea : FAILURE in 4m 03s","accounts_in_message":[],"_revision_number":4},{"id":"547a01b630a58ae46d4db055d90a6f9dfc5b746c","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-22 23:45:55.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"d91e4bfb22e1edd27e2c108e96bde53179cd8df7","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-22 23:46:18.000000000","message":"Patch Set 4:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":4},{"id":"83f6973104bb180d7c9539124a61b40eb9bf0315","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-23 00:57:45.000000000","message":"Patch Set 4:\n\n(2 comments)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/e87046ccdf9b405ab97a0ddbd7d4fdc9\n\n- teim-code-review https://zuul.teim.app/t/main/build/c06445c40da94e62bbea6cd91394beb5 : SUCCESS in 15m 14s\n\nWarning:\n  The authorize_wsgi decorator (modified by sibling patch 992722) always uses the request context as the policy target. This patch\u0027s test context lists are correct, but inline comments in setUp() still reference the old need_target parameter, contradicting the actual behavior being tested. Impact: Future maintainers reading these tests will encounter contradictory documentation versus actual behavior, potentially leading to incorrect assumptions about how policy targets work in cyborg. Recommendation: Update all test comments in test_attributes.py to remove references to need_target and reflect that the authorize_wsgi decorator always passes context.project_id and context.user_id as the target for all operations.","accounts_in_message":[],"_revision_number":4},{"id":"b9bd92a8d08990a411316cdde2be05b498ac9542","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-29 09:44:32.000000000","message":"Patch Set 4: Code-Review+1\n\n(2 comments)","accounts_in_message":[],"_revision_number":4},{"id":"c12da84d292a17a913666931c7634641b11daf12","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-29 09:51:08.000000000","message":"Patch Set 4:\n\n(2 comments)","accounts_in_message":[],"_revision_number":4},{"id":"fa6fc431466fd1d8af2cc9b1a26eef8ac74b2dd5","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-06-29 10:10:47.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"21c5b59ec9fcf877d5c806b88b1de2ac3f07816d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-06-30 11:06:18.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"793f9074ecd526fb156d545dd1f26437ba33c67f","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-30 11:07:29.000000000","message":"Patch Set 5:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":5},{"id":"43c5580b4398ad877bb9f74cf44adafccf7ef18e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-30 12:04:52.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b370c67f4abc428db0cfe472d83a5e07\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/fc64a0ab9534468ebad2e9c63025e39b : SUCCESS in 5m 11s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3c220bfcadb54485aa140f299e9084a0 : SUCCESS in 3m 53s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8f41c2721d2946e893f56b1464f564a0 : SUCCESS in 9m 13s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/ea06fbbdf5924e57988cbb8c72bb6cc7 : SUCCESS in 3m 40s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/c1055db625d642a099cd1bcf836cc7b9 : SUCCESS in 2m 23s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/41e6df15883d46c9bd34fca6d065e785 : SUCCESS in 3m 50s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/56b06e62a1f5412d9cbbe5d71db4b938 : SUCCESS in 7m 12s (non-voting)\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/efc5d68719e34c5bb44905e97a7ffd0a : SUCCESS in 46m 37s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/5934fdf14dc4499f82baa7f281e6cef5 : SUCCESS in 22m 15s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/fa12c9f634654238a204000bc0df6526 : SUCCESS in 52m 02s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/8a3dacedf0dd4bfb8e863dfaab9af480 : SUCCESS in 45m 27s","accounts_in_message":[],"_revision_number":5},{"id":"28516ab65c10c3f49506ad8d926acf09de882772","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-06-30 13:06:17.000000000","message":"Patch Set 5:\n\n(3 comments)\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/9b822e61e8b943d58e756d979293e4f7\n\n- teim-code-review https://zuul.teim.app/t/main/build/b37af5385501484084a201a1ece41393 : SUCCESS in 15m 24s\n\nWarning:\n  The legacy cyborg/common/policy.py is deleted here. It previously held only the attribute_policies list; the device, deployable, and ARQ migrations already removed theirs. The releasenote deprecations accurately describes the removal and the bridge-based compatibility window through 2027.2. Impact: Removing the legacy module is the correct terminal step of the per-endpoint migration sequence, eliminating the last policy-in-code duplication so only the DocumentedRuleDefault definitions remain authoritative. Recommendation: Before merge, confirm with the broader SRBAC blueprint that no out-of-tree tooling, documentation, or sample policy.yaml references cyborg/common/policy.py (the in-tree grep is clean). No code action is needed within this change.","accounts_in_message":[],"_revision_number":5},{"id":"3f824cb562c94f1a2ea0ddb725d86a33505b1234","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-07-01 13:30:11.000000000","message":"Patch Set 5: Code-Review+1","accounts_in_message":[],"_revision_number":5},{"id":"6dcba88a6111c60dec61e83b269da289ceb162b9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-20 14:41:16.000000000","message":"Uploaded patch set 6.\n\nOutdated Votes:\n* Code-Review+1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":6},{"id":"3061307f60cf5b00bc6e4257832975d8914a7e23","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 14:42:02.000000000","message":"Patch Set 6:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":6},{"id":"a9cb7faf6dd292d25b81cf1a2d840dc98b78ce9d","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-20 15:47:29.000000000","message":"Patch Set 6: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/d89a939a6ee949e580c0214bb4d89f17\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/6b9b1b45d93b410393dcf7ee68d0dfd8 : SUCCESS in 4m 47s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/9890e628e47540b6bffe26fbc3875056 : SUCCESS in 3m 52s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/9975abb9caf7487884669abfd9c17d50 : SUCCESS in 8m 56s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/89c8921178014128b99bbaefca91ba27 : SUCCESS in 3m 50s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/9d19ad3822a246d28cfe3daf8a2fb2a8 : SUCCESS in 3m 39s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/a609e06437804feabf2575bbdeeae140 : SUCCESS in 5m 22s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/5cc83b1326b34ad4a46934e359e8e264 : SUCCESS in 6m 29s (non-voting)\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/237e458f0f6442258a950d09fa3cf338 : SUCCESS in 3m 56s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/e5dc68f529e54b65ba9d4c98fe7e6e78 : SUCCESS in 48m 19s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/22ae9daf868140a483ac7bc8805da83a : FAILURE in 43m 10s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/59f39a9719fd4c3eaa0bdb5b83ac0e6b : SUCCESS in 56m 39s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/94176a82ae614c958b785842ab35811d : SUCCESS in 59m 08s","accounts_in_message":[],"_revision_number":6},{"id":"4f995109ba9fcaf93fc560441162444979420bab","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 16:29:25.000000000","message":"Patch Set 6:\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/eefe1a1d3eb84cb3a3827354c1c9e270\n\n- teim-code-review https://zuul.teim.app/t/main/build/550333f084704a578f239434aa459449 : SUCCESS in 8m 36s","accounts_in_message":[],"_revision_number":6},{"id":"4faab592819c8e9db5a986e457ec2575757d805f","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-20 21:17:09.000000000","message":"Patch Set 6: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"2a44d0e3c784a95426e636d824cdf7b35b47807c","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 21:17:23.000000000","message":"Patch Set 6:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":6},{"id":"37422a5c403174b3bd50637ee01fbde699afdfe9","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-20 21:26:33.000000000","message":"Patch Set 6:\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/a2190817dba844a5b3801f78c9e372b9\n\n- teim-code-review https://zuul.teim.app/t/main/build/9878a3d6527042d88beedf6655879bba : SUCCESS in 7m 43s","accounts_in_message":[],"_revision_number":6},{"id":"34ab7df6de14767bea98b0ba89bb19b706b74eb1","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-20 22:08:49.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b27218722ef0424484a95c3ea0d1f652\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/eb8ff89f585b46c996c4f53278b6c3c0 : SUCCESS in 4m 17s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/6b2177ef965640d29ef3ae187612eafa : SUCCESS in 3m 45s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f63ab1a70f604477a1c8b582fc15a5d8 : SUCCESS in 7m 42s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/dd4c25805ae640e199b11725c1118c58 : SUCCESS in 3m 29s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/78d89239cb7e465e9b53ef6f8999dc2e : SUCCESS in 3m 59s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/05e1db12de1b406c8dd6b2628a489ec0 : SUCCESS in 3m 09s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/dbe77adfcb3f42028d93d86fda85e315 : SUCCESS in 6m 13s (non-voting)\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/8f1a8b52df464c4da0a69e2ba350da24 : SUCCESS in 3m 29s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/6db5207144194d55973f4277450d8b88 : SUCCESS in 39m 38s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/75a1f03c6e2e4c53ae9fcbf3216eb526 : SUCCESS in 40m 25s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/7fa9c18882804c24aeb3af2ebf9607aa : SUCCESS in 27m 47s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/5bf11afebfbb4ea193484571eb9c3f8f : SUCCESS in 49m 31s","accounts_in_message":[],"_revision_number":6},{"id":"17cc393f80d7423026ab56ac2e4a6ed96c97d466","author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"date":"2026-07-21 07:01:41.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"d299dbed2ed31d52f552fd5f87d615cd7879754a","author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"date":"2026-07-21 09:39:48.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"79525f30e2ac33084803dfb9fa0d6141ca89fd21","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-21 10:34:26.000000000","message":"Uploaded patch set 7: Patch Set 6 was rebased.\n\nCopied Votes:\n* Code-Review+1, Code-Review+2 (copy condition: \"**changekind:TRIVIAL_REBASE** OR is:MIN\")\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":7},{"id":"f990d0be52ecab13ca2b099b93f5115ea24b4623","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-21 10:35:17.000000000","message":"Patch Set 7:\n\nStarting automatic-ci jobs.","accounts_in_message":[],"_revision_number":7},{"id":"d6638ce60d03a436f741c733af2c02cec0ca5820","tag":"autogenerated:zuul:automatic-ci","author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"date":"2026-07-21 11:40:37.000000000","message":"Patch Set 7:\n\nBuild succeeded (automatic-ci pipeline).\nhttps://zuul.teim.app/t/main/buildset/4edc741850fc4b18bd744ac74285f2aa\n\n- teim-code-review https://zuul.teim.app/t/main/build/20edd86416c94124acf3ec5b67102b6c : SUCCESS in 7m 37s","accounts_in_message":[],"_revision_number":7},{"id":"2bbab1770af26eb9eb913dafe7bee7668d422815","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 11:45:01.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ae2413b81c984308a54bca8402b547f2\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/5e4311f6ffb4459f9c1b174e22f18c7b : SUCCESS in 5m 15s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/b889acc93a3b44408babb9784e1ff9f0 : SUCCESS in 5m 38s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/86da45af16af4263bbcc6b1691bc5c87 : SUCCESS in 7m 47s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/3bf76eed01374ecdaa51964544effdf9 : SUCCESS in 3m 33s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/2ec7803006f54994b97c49b60ab7704a : SUCCESS in 4m 01s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/9ec0834da57645248b9145372d703641 : SUCCESS in 4m 26s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/f7fb7735f33d4f9c993c8cdbcf63b0d8 : SUCCESS in 6m 59s (non-voting)\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/f4935930bb914d0ab47490852c5a00b7 : SUCCESS in 4m 14s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/42d793232b90406c8de1d6349606c34a : SUCCESS in 1h 01m 07s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/a21644e1baea45a7b465aa90a21ac62b : SUCCESS in 40m 48s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/69cfa75aa1354295a3c02f56032eb795 : SUCCESS in 54m 11s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/2450ac44de3a45eeb87981f0791373cf : SUCCESS in 54m 56s","accounts_in_message":[],"_revision_number":7},{"id":"8cb3218c7265448b7a25707f85acc143deeb6375","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2026-07-21 11:45:41.000000000","message":"Patch Set 7: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":7},{"id":"83077332bdcc2f5445e97513366d8b333725bdad","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 11:46:23.000000000","message":"Patch Set 7: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":7},{"id":"fb1dbc81bf85a4480aad0346c134c3c449c58fb9","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:55:03.000000000","message":"Patch Set 7: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/a355f31cb99049deaf566fe73c4af406\n\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3dacdc14fa054086812019646a81b6a2 : SUCCESS in 3m 58s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/6fd60d88bafb4a658bcf77d0eab4b20f : SUCCESS in 7m 56s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/0fa8b4296d3f4cb281bef3bcfad8d0c8 : SUCCESS in 3m 27s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/4e54aecd782d4a5d8f6e07f5e98a2590 : SUCCESS in 3m 50s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/8e426f21df5e4bc5a200eeab232d0f9e : SUCCESS in 4m 08s\n- openstack-tox-functional https://zuul.opendev.org/t/openstack/build/edf3f7a42371434195115cf0620ce72e : SUCCESS in 3m 45s\n- cyborg-tempest-py3 https://zuul.opendev.org/t/openstack/build/3eb9f85941924a4c974ee181801c4590 : SUCCESS in 54m 18s\n- cyborg-tempest-ipv6 https://zuul.opendev.org/t/openstack/build/b39f82b990c841f5879eff4c75ce1e15 : SUCCESS in 34m 28s\n- cyborg-grenade https://zuul.opendev.org/t/openstack/build/65c62eb0012947e78bba549e4baf4ea0 : SUCCESS in 57m 15s\n- cyborg-grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/c220353f9a344d9bbf6e218c90f1e958 : SUCCESS in 44m 04s","accounts_in_message":[],"_revision_number":7},{"id":"7e664259be34b71192f06e94c4275ee8f2b5e2b1","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-21 12:55:03.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":7}],"current_revision_number":7,"current_revision":"b12e90d26ad4f78088cbf68ea588a2e3e9a93dda","revisions":{"a076c5b1e03d0865bd17767c123b79b9863bf23c":{"kind":"REWORK","_number":1,"created":"2026-06-08 15:33:48.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/96/992296/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/96/992296/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/96/992296/1"}}},"commit":{"parents":[{"commit":"be82603c5f2cc06059c329515ba59ac236bdbcac","subject":"Migrate deployable policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/be82603c5f2cc06059c329515ba59ac236bdbcac"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:41:10.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 15:33:11.000000000","tz":60},"subject":"Migrate attribute policies to DocumentedRuleDefault","message":"Migrate attribute policies to DocumentedRuleDefault\n\nCreate cyborg/policies/attributes.py with DocumentedRuleDefault\nentries for all four attribute operations: get_one, get_all, create,\nand delete.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into accelerator capability metadata for capacity\nplanning. Attribute create and delete remain restricted to cloud\nadmins as attributes describe shared physical infrastructure\nproperties populated by cyborg-agent during hardware discovery.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new attribute policies\nand stop loading the legacy attribute_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: Ic3c016148696929436e481b25045d6f3fb67beb7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/a076c5b1e03d0865bd17767c123b79b9863bf23c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/a076c5b1e03d0865bd17767c123b79b9863bf23c"}]},"branch":"refs/heads/master"},"c16134a887e1860a8f41ed69e20482754dc7fbf8":{"kind":"REWORK","_number":2,"created":"2026-06-10 16:55:28.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/96/992296/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/96/992296/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/96/992296/2"}}},"commit":{"parents":[{"commit":"d8c3c99d6524fe2463e838dcf05c0df38493143b","subject":"Migrate deployable policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/d8c3c99d6524fe2463e838dcf05c0df38493143b"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:41:10.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 16:50:57.000000000","tz":60},"subject":"Migrate attribute policies to DocumentedRuleDefault","message":"Migrate attribute policies to DocumentedRuleDefault\n\nCreate cyborg/policies/attributes.py with DocumentedRuleDefault\nentries for all four attribute operations: get_one, get_all, create,\nand delete.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into accelerator capability metadata for capacity\nplanning. Attribute create and delete remain restricted to cloud\nadmins as attributes describe shared physical infrastructure\nproperties populated by cyborg-agent during hardware discovery.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new attribute policies\nand stop loading the legacy attribute_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: Ic3c016148696929436e481b25045d6f3fb67beb7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/c16134a887e1860a8f41ed69e20482754dc7fbf8"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/c16134a887e1860a8f41ed69e20482754dc7fbf8"}]},"branch":"refs/heads/master"},"164c6fa047d4a505647abb925f0a16dd3dd0b3e9":{"kind":"NO_CHANGE","_number":3,"created":"2026-06-10 16:57:38.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/96/992296/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/96/992296/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/96/992296/3"}}},"commit":{"parents":[{"commit":"21498cb3eedbf9bc03777d6fda9655ef46500d6d","subject":"Migrate deployable policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/21498cb3eedbf9bc03777d6fda9655ef46500d6d"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:41:10.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 16:57:22.000000000","tz":60},"subject":"Migrate attribute policies to DocumentedRuleDefault","message":"Migrate attribute policies to DocumentedRuleDefault\n\nCreate cyborg/policies/attributes.py with DocumentedRuleDefault\nentries for all four attribute operations: get_one, get_all, create,\nand delete.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into accelerator capability metadata for capacity\nplanning. Attribute create and delete remain restricted to cloud\nadmins as attributes describe shared physical infrastructure\nproperties populated by cyborg-agent during hardware discovery.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new attribute policies\nand stop loading the legacy attribute_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: Ic3c016148696929436e481b25045d6f3fb67beb7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/164c6fa047d4a505647abb925f0a16dd3dd0b3e9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/164c6fa047d4a505647abb925f0a16dd3dd0b3e9"}]},"branch":"refs/heads/master"},"0f2c16b562d0e257e65c59d3316c5da7cd8a3fae":{"kind":"TRIVIAL_REBASE","_number":4,"created":"2026-06-10 17:06:13.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/96/992296/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/96/992296/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/96/992296/4"}}},"commit":{"parents":[{"commit":"5422d1ca421b2ce779f6707dfec44970c1d5515e","subject":"Migrate deployable policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/5422d1ca421b2ce779f6707dfec44970c1d5515e"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:41:10.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-10 17:03:36.000000000","tz":60},"subject":"Migrate attribute policies to DocumentedRuleDefault","message":"Migrate attribute policies to DocumentedRuleDefault\n\nCreate cyborg/policies/attributes.py with DocumentedRuleDefault\nentries for all four attribute operations: get_one, get_all, create,\nand delete.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into accelerator capability metadata for capacity\nplanning. Attribute create and delete remain restricted to cloud\nadmins as attributes describe shared physical infrastructure\nproperties populated by cyborg-agent during hardware discovery.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new attribute policies\nand stop loading the legacy attribute_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: Ic3c016148696929436e481b25045d6f3fb67beb7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/0f2c16b562d0e257e65c59d3316c5da7cd8a3fae"}]},"branch":"refs/heads/master"},"090214c9b337a3ae881a841662a7d0e93eebb3d1":{"kind":"REWORK","_number":5,"created":"2026-06-30 11:06:18.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/96/992296/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/96/992296/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/96/992296/5"}}},"commit":{"parents":[{"commit":"f6401c96823cb9e6ce19eeac3a8d55b154859539","subject":"Migrate deployable policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/f6401c96823cb9e6ce19eeac3a8d55b154859539"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:41:10.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-29 17:36:05.000000000","tz":60},"subject":"Migrate attribute policies to DocumentedRuleDefault","message":"Migrate attribute policies to DocumentedRuleDefault\n\nCreate cyborg/policies/attributes.py with DocumentedRuleDefault\nentries for all four attribute operations: get_one, get_all, create,\nand delete.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into accelerator capability metadata for capacity\nplanning. Attribute create and delete remain restricted to cloud\nadmins as attributes describe shared physical infrastructure\nproperties populated by cyborg-agent during hardware discovery.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new attribute policies\nand stop loading the legacy attribute_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: Ic3c016148696929436e481b25045d6f3fb67beb7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/090214c9b337a3ae881a841662a7d0e93eebb3d1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/090214c9b337a3ae881a841662a7d0e93eebb3d1"}]},"branch":"refs/heads/master"},"c236410d41c88e163681b424db80278f021f8cb0":{"kind":"REWORK","_number":6,"created":"2026-07-20 14:41:16.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/96/992296/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/96/992296/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/96/992296/6"}}},"commit":{"parents":[{"commit":"9b30b75ff67f24444925eb8dab96374afbc9aad4","subject":"Migrate deployable policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/9b30b75ff67f24444925eb8dab96374afbc9aad4"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:41:10.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-07-20 13:15:17.000000000","tz":60},"subject":"Migrate attribute policies to DocumentedRuleDefault","message":"Migrate attribute policies to DocumentedRuleDefault\n\nCreate cyborg/policies/attributes.py with DocumentedRuleDefault\nentries for all four attribute operations: get_one, get_all, create,\nand delete.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into accelerator capability metadata for capacity\nplanning. Attribute create and delete remain restricted to cloud\nadmins as attributes describe shared physical infrastructure\nproperties populated by cyborg-agent during hardware discovery.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new attribute policies\nand stop loading the legacy attribute_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: Ic3c016148696929436e481b25045d6f3fb67beb7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/c236410d41c88e163681b424db80278f021f8cb0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/c236410d41c88e163681b424db80278f021f8cb0"}]},"branch":"refs/heads/master"},"b12e90d26ad4f78088cbf68ea588a2e3e9a93dda":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2026-07-21 10:34:26.000000000","uploader":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"ref":"refs/changes/96/992296/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/cyborg","ref":"refs/changes/96/992296/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/cyborg refs/changes/96/992296/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/cyborg refs/changes/96/992296/7"}}},"commit":{"parents":[{"commit":"06d95fcd1f2def9b45b5527109f85d4f394adc68","subject":"Migrate deployable policies to DocumentedRuleDefault","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/06d95fcd1f2def9b45b5527109f85d4f394adc68"}]}],"author":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-06-08 11:41:10.000000000","tz":60},"committer":{"name":"Sean Mooney","email":"work@seanmooney.info","date":"2026-07-21 10:31:49.000000000","tz":60},"subject":"Migrate attribute policies to DocumentedRuleDefault","message":"Migrate attribute policies to DocumentedRuleDefault\n\nCreate cyborg/policies/attributes.py with DocumentedRuleDefault\nentries for all four attribute operations: get_one, get_all, create,\nand delete.\n\nRead operations use project_manager_or_admin, granting the manager\npersona visibility into accelerator capability metadata for capacity\nplanning. Attribute create and delete remain restricted to cloud\nadmins as attributes describe shared physical infrastructure\nproperties populated by cyborg-agent during hardware discovery.\n\nEach new policy includes a deprecated_rule bridge matching the\ncurrent legacy check string (rule:admin_api) so that existing\ndeployments continue to work with enforce_new_defaults\u003dFalse.\n\nUpdate cyborg/policies/__init__.py to load the new attribute policies\nand stop loading the legacy attribute_policies list from\ncyborg/common/policy.py.\n\nPartial-Implements: blueprint consistent-and-secure-rbac\nAssisted-By: pi opus-4.6 (orchestrator)\nAssisted-By: pi sonnet-4.6 (implementer)\nAssisted-By: pi gpt-5.5 (reviewer)\nChange-Id: Ic3c016148696929436e481b25045d6f3fb67beb7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/b12e90d26ad4f78088cbf68ea588a2e3e9a93dda"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/cyborg/commit/b12e90d26ad4f78088cbf68ea588a2e3e9a93dda"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
