)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"77f038690fe1fdabacdfd5db27d0cf34d0ff6a68","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"469267ee_68c9f6f2","updated":"2026-06-22 08:35:40.000000000","message":"teim-ci: auto","commit_id":"26a4b8f71ad1fd3ce7760337f58f265b8a310d90"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"5d577ea40c6e8103d80212e5eb677315a827e7df","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"5e1a976e_b9d60722","updated":"2026-06-22 23:46:00.000000000","message":"teim-ci: auto","commit_id":"26a4b8f71ad1fd3ce7760337f58f265b8a310d90"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"98d3c3d338425fc59afc9f1918f86ac12786a504","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"5a5603ab_d22d2750","updated":"2026-07-02 08:37:54.000000000","message":"Ah this patch needs update based on teim-ci and Joan conversation.","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"c804438b9b5036c1b05d6cdfb73a54b820146b42","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"0ed3b696_cb256c03","updated":"2026-07-02 08:21:47.000000000","message":"The doc update is concise and clear.\n\nI have also verified https://storage.gra.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_f64/openstack/f64afce5ba1e43588cb03ad1a387714f/docs/configuration/policy-concepts.html#endpoint-persona-mapping `Endpoint-Persona Mapping` with the code implementation\n```\nARQ endpoints from code (992293, cyborg/policies/arqs.py):\n  - cyborg:arq:get_all → base.PROJECT_READER_OR_ADMIN — doc says project_reader_or_admin ✓\n  - cyborg:arq:get_one → base.PROJECT_READER_OR_ADMIN — doc says project_reader_or_admin ✓\n  - cyborg:arq:create → base.PROJECT_MEMBER_OR_SERVICE — doc says project_member_or_service ✓\n  - cyborg:arq:delete → base.PROJECT_MEMBER_OR_SERVICE — doc says project_member_or_service ✓\n  - cyborg:arq:update → base.PROJECT_MEMBER_OR_SERVICE — doc says project_member_or_service ✓\n\n  Device profile endpoints from code (992292, cyborg/policies/device_profiles.py):\n  - cyborg:device_profile:get_all → base.PROJECT_READER_OR_ADMIN — doc says project_reader_or_admin ✓\n  - cyborg:device_profile:get_one → base.PROJECT_READER_OR_ADMIN — doc says project_reader_or_admin ✓\n  - cyborg:device_profile:create → base.ADMIN — doc says admin_api ✓\n  - cyborg:device_profile:delete → base.ADMIN — doc says admin_api ✓ (covers both by-uuid and by-name)\n\n  Device endpoints from code (992294, cyborg/policies/devices.py):\n  - cyborg:device:get_all → base.PROJECT_MANAGER_OR_ADMIN — doc says project_manager_or_admin ✓\n  - cyborg:device:get_one → base.PROJECT_MANAGER_OR_ADMIN — doc says project_manager_or_admin ✓\n  - cyborg:device:disable → base.ADMIN — doc says admin_api ✓\n  - cyborg:device:enable → base.ADMIN — doc says admin_api ✓\n\n  Deployable endpoints from code (992295, cyborg/policies/deployables.py):\n  - cyborg:deployable:get_all → base.PROJECT_MANAGER_OR_ADMIN — doc says project_manager_or_admin ✓\n  - cyborg:deployable:get_one → base.PROJECT_MANAGER_OR_ADMIN — doc says project_manager_or_admin ✓\n  - cyborg:deployable:program → base.ADMIN — doc says admin_api ✓\n\n  Attribute endpoints from code (992296, cyborg/policies/attributes.py):\n  - cyborg:attribute:get_all → base.PROJECT_MANAGER_OR_ADMIN — doc says project_manager_or_admin ✓\n  - cyborg:attribute:get_one → base.PROJECT_MANAGER_OR_ADMIN — doc says project_manager_or_admin ✓\n  - cyborg:attribute:create → base.ADMIN — doc says admin_api ✓\n  - cyborg:attribute:delete → base.ADMIN — doc says admin_api ✓\n\n``` \nAll 21 endpoints matches.\n\nIt looks good.","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"62434b3867688c18a170df074e9c7ada2370a3f6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"aa0e3ab6_3e3dfd37","updated":"2026-07-21 07:04:26.000000000","message":"Docs looks good. Here is the rendered version of the doc: https://ca768874132bdf15c4e3-b818c7a6c3b5b0701ea16d988cbfb8d4.ssl.cf1.rackcdn.com/openstack/6353c14dd51949c5977384e30cbea384/docs/configuration/policy-concepts.html","commit_id":"5a9d4fe49d3caafe173a8f96abbfad83796024ed"}],"doc/source/configuration/policy-concepts.rst":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"b4732f572dde423e2f5c31fbadebaa21b7274d15","unresolved":false,"context_lines":[{"line_number":250,"context_line":"2026.2), oslo.policy evaluates the new check string OR the legacy bridge, so"},{"line_number":251,"context_line":"existing tokens that passed before continue to pass."},{"line_number":252,"context_line":""},{"line_number":253,"context_line":"The deprecated bridge check strings are:"},{"line_number":254,"context_line":""},{"line_number":255,"context_line":"- ARQ reads: ``rule:admin_or_owner``"},{"line_number":256,"context_line":"  (``is_admin:True or project_id:%(project_id)s``)"}],"source_content_type":"text/x-rst","patch_set":4,"id":"881634a6_2e0f39e5","line":253,"updated":"2026-06-23 01:16:01.000000000","message":"Device profile deprecated-rule bridges are omitted from the Backward Compatibility section. Device profiles use different bridges than the rule:admin_api listed for devices: reads use rule:admin_or_owner, create/delete use rule:is_admin (device_profiles.py lines 33-65).\n\n**Severity**: WARNING | **Confidence**: 0.9\n\n**Impact**: Operators may miscalculate which legacy tokens will work for device_profile endpoints during the transition. Device profile reads (rule:admin_or_owner) are broader than admin_api, and create/delete (rule:is_admin) use a different legacy path.\n\n**Suggestion**:\nAdd device_profile entries to the deprecated bridge list. For example: \u0027Device profile reads: rule:admin_or_owner\u0027 and \u0027Device profile create/delete: rule:is_admin\u0027. Alternatively, enumerate all five resource types explicitly with their respective bridges.","commit_id":"26a4b8f71ad1fd3ce7760337f58f265b8a310d90"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"752cd1e90214bf05582a170a2ee6357cac4e2ccb","unresolved":false,"context_lines":[{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Policy scope enforcement is controlled by two oslo.policy flags:"},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"- :oslo.config:option:`oslo_policy.enforce_scope` — defaults to ``True``"},{"line_number":21,"context_line":"  in Cyborg. System-scoped tokens are rejected."},{"line_number":22,"context_line":"- :oslo.config:option:`oslo_policy.enforce_new_defaults` — defaults to"},{"line_number":23,"context_line":"  ``False`` in Cyborg during the 2026.2 transition window. When ``False``,"}],"source_content_type":"text/x-rst","patch_set":5,"id":"878fd7d8_677df29c","line":20,"updated":"2026-06-30 13:28:55.000000000","message":"Doc claims enforce_scope defaults to True, but authorize_wsgi.py:65 only overrides enforce_new_defaults and never sets enforce_scope\u003dTrue, so Cyborg inherits oslo.policy\u0027s library default of False. The test test_init_enforcer_warns_when_scope_enforcement_disabled confirms it is off by default.\n\n**Severity**: HIGH | **Confidence**: 0.9\n\n**Risk**: Operators will believe system-scoped tokens are rejected out of the box. In reality they are accepted with only a warning log, bypassing project-level isolation - a security-relevant misstatement in a document operators use to assess their posture and plan role assignments.\n\n**Priority**: Before merge\n**Why This Matters**: The premise of the page (only project-scoped tokens are accepted) is undermined by the actual default. An operator could deploy Cyborg believing scope is enforced while leaving system-scoped access open.\n\n**Recommendation**:\nCoordinate with dependent code patch 992292: ensure policy_opts.set_defaults(CONF, enforce_new_defaults\u003dFalse, enforce_scope\u003dTrue) is actually called in authorize_wsgi.py, OR revise lines 20-21 and 263-266 to state enforce_scope defaults to False and document enabling it as an explicit migration step. Do not ship a doc asserting a default the code does not provide.","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"752cd1e90214bf05582a170a2ee6357cac4e2ccb","unresolved":false,"context_lines":[{"line_number":29,"context_line":"-----"},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"Cyborg uses the following Keystone roles. Keystone\u0027s implied-role"},{"line_number":32,"context_line":"hierarchy means each role automatically includes the roles below it:"},{"line_number":33,"context_line":"``admin`` → ``manager`` → ``member`` → ``reader``. The ``service``"},{"line_number":34,"context_line":"role is separate and has no implication chain. Refer to the"},{"line_number":35,"context_line":"`Keystone service API protection`_ documentation for the full"}],"source_content_type":"text/x-rst","patch_set":5,"id":"e0c47d4d_689ba14a","line":32,"updated":"2026-06-30 13:28:55.000000000","message":"The page states hierarchy admin-\u003emanager-\u003emember-\u003ereader and calls manager a standard Keystone bootstrap role. Keystone\u0027s default bootstrap only creates admin, member, reader (chain admin-\u003emember-\u003ereader); manager is not in the default bootstrap or implied chain and must be created manually.\n\n**Severity**: WARNING | **Confidence**: 0.8\n\n**Impact**: Operators may skip creating the manager role or skip establishing the manager-\u003emember-\u003ereader implications, causing project_manager_or_admin rules to silently fail for intended users or behave inconsistently across deployments.\n\n**Suggestion**:\nClarify that admin, member, and reader are Keystone bootstrap roles with default implications, while manager is a project-defined role that must be explicitly created with implied-role links (openstack implied role create manager member). Reword the \u0027standard Keystone bootstrap roles available since the Yoga release\u0027 claim for the manager role accordingly.","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"},{"author":{"_account_id":34452,"name":"Joan Gilabert","display_name":"jgilaber","email":"jgilaber@redhat.com","username":"jgilaber"},"change_message_id":"4a31e166248f6a307e73b622b20ca62915603b97","unresolved":false,"context_lines":[{"line_number":29,"context_line":"-----"},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"Cyborg uses the following Keystone roles. Keystone\u0027s implied-role"},{"line_number":32,"context_line":"hierarchy means each role automatically includes the roles below it:"},{"line_number":33,"context_line":"``admin`` → ``manager`` → ``member`` → ``reader``. The ``service``"},{"line_number":34,"context_line":"role is separate and has no implication chain. Refer to the"},{"line_number":35,"context_line":"`Keystone service API protection`_ documentation for the full"}],"source_content_type":"text/x-rst","patch_set":5,"id":"8747b79c_c341fae3","line":32,"in_reply_to":"e0c47d4d_689ba14a","updated":"2026-07-01 13:54:56.000000000","message":"AFAICT this is not correct, as the linked keystone document (https://docs.openstack.org/keystone/latest/admin/service-api-protection.html) states that `In addition to admin, member, and reader role, from 2023.2 (Bobcat) release keystone will provide the service and manager roles by default as well.`","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"752cd1e90214bf05582a170a2ee6357cac4e2ccb","unresolved":false,"context_lines":[{"line_number":181,"context_line":"   * - ``GET /v2/accelerator_requests``"},{"line_number":182,"context_line":"     - ``cyborg:arq:get_all``"},{"line_number":183,"context_line":"     - ``project_reader_or_admin``"},{"line_number":184,"context_line":"   * - ``GET /v2/accelerator_requests/{uuid}``"},{"line_number":185,"context_line":"     - ``cyborg:arq:get_one``"},{"line_number":186,"context_line":"     - ``project_reader_or_admin``"},{"line_number":187,"context_line":"   * - ``POST /v2/accelerator_requests``"}],"source_content_type":"text/x-rst","patch_set":5,"id":"8689abb4_795dcc08","line":184,"updated":"2026-06-30 13:28:55.000000000","message":"The mapping table uses generic path placeholders (e.g. {uuid}) that differ from the path tokens in the DocumentedRuleDefault operations (e.g. {arqs_uuid}, {device_profiles_uuid}). Using the exact code tokens lets operators cross-reference against the sample policy file without ambiguity.\n\n**Severity**: SUGGESTION | **Confidence**: 0.9\n\n**Benefit**: Improves traceability between this table, the generated sample-policy.yaml, and the policy code, reducing operator confusion when matching endpoints to rules.\n\n**Recommendation**:\nMirror the path parameter names used in cyborg/policies/*.py operations (e.g. {arqs_uuid}, {device_profiles_uuid}), or note explicitly that the {uuid} placeholder is normalized for readability.","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"240d3d9e944392575c384943efadb8720eeac97d","unresolved":true,"context_lines":[{"line_number":257,"context_line":"- ARQ create: ``rule:project_member_or_admin``"},{"line_number":258,"context_line":"- ARQ writes: ``rule:admin_or_owner``"},{"line_number":259,"context_line":"- Device, deployable, attribute endpoints: ``rule:admin_api``"},{"line_number":260,"context_line":"- Device profile reads: ``rule:admin_or_owner``"},{"line_number":261,"context_line":"- Device profile create/delete: ``rule:is_admin``"},{"line_number":262,"context_line":""},{"line_number":263,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":5,"id":"bb613d04_c75e022d","line":260,"updated":"2026-06-30 12:27:15.000000000","message":"hum ok this is incorrect device profiles use reader for reads","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"85c8eed84e261a28a0402859035dcd8fedd7a8c6","unresolved":false,"context_lines":[{"line_number":257,"context_line":"- ARQ create: ``rule:project_member_or_admin``"},{"line_number":258,"context_line":"- ARQ writes: ``rule:admin_or_owner``"},{"line_number":259,"context_line":"- Device, deployable, attribute endpoints: ``rule:admin_api``"},{"line_number":260,"context_line":"- Device profile reads: ``rule:admin_or_owner``"},{"line_number":261,"context_line":"- Device profile create/delete: ``rule:is_admin``"},{"line_number":262,"context_line":""},{"line_number":263,"context_line":".. note::"}],"source_content_type":"text/x-rst","patch_set":5,"id":"e7e72380_247289f5","line":260,"in_reply_to":"bb613d04_c75e022d","updated":"2026-07-20 14:51:44.000000000","message":"Done","commit_id":"46dd2d3d73d3aa4a9a3ab3621a6bb62eac485f94"}]}
