)]}'
{".zuul.yaml":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"07c3b8f9be15e671779efe4c81144857bf1e12f7","unresolved":true,"context_lines":[{"line_number":119,"context_line":"        post-config:"},{"line_number":120,"context_line":"          $CYBORG_CONF:"},{"line_number":121,"context_line":"            oslo_policy:"},{"line_number":122,"context_line":"              enforce_scope: true"},{"line_number":123,"context_line":"              enforce_new_defaults: true"},{"line_number":124,"context_line":"        test-config:"},{"line_number":125,"context_line":"          $TEMPEST_CONFIG:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"4fb4b345_95c4ccdc","line":122,"range":{"start_line":122,"start_character":13,"end_line":122,"end_character":33},"updated":"2026-06-08 17:51:31.000000000","message":"this is actully our default in code so technically we only need to enable the new defaults","commit_id":"20b6d6f0d646330cad50f94cd005f65375356476"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"632586f90b8c1d658202b63e015f171e09f6db22","unresolved":false,"context_lines":[{"line_number":119,"context_line":"        post-config:"},{"line_number":120,"context_line":"          $CYBORG_CONF:"},{"line_number":121,"context_line":"            oslo_policy:"},{"line_number":122,"context_line":"              enforce_scope: true"},{"line_number":123,"context_line":"              enforce_new_defaults: true"},{"line_number":124,"context_line":"        test-config:"},{"line_number":125,"context_line":"          $TEMPEST_CONFIG:"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"92833727_859d6ed5","line":122,"range":{"start_line":122,"start_character":13,"end_line":122,"end_character":33},"in_reply_to":"4fb4b345_95c4ccdc","updated":"2026-06-29 10:17:01.000000000","message":"Acknowledged","commit_id":"20b6d6f0d646330cad50f94cd005f65375356476"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"07c3b8f9be15e671779efe4c81144857bf1e12f7","unresolved":true,"context_lines":[{"line_number":140,"context_line":"        - cyborg-tempest-ipv6"},{"line_number":141,"context_line":"        - cyborg-grenade"},{"line_number":142,"context_line":"        - cyborg-grenade-skip-level-always"},{"line_number":143,"context_line":"        - cyborg-tempest-srbac:"},{"line_number":144,"context_line":"            voting: false"},{"line_number":145,"context_line":"    gate:"},{"line_number":146,"context_line":"      jobs:"},{"line_number":147,"context_line":"        - cyborg-tempest-py3"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"b1118a1e_2f4e0748","line":144,"range":{"start_line":143,"start_character":4,"end_line":144,"end_character":25},"updated":"2026-06-08 17:51:31.000000000","message":"realisticly im not planning to merge this until tis gree so ill proably remove this when we get to that point.","commit_id":"20b6d6f0d646330cad50f94cd005f65375356476"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"747e48c5e5dfd350beddb9d1f5394ea530b1d66e","unresolved":false,"context_lines":[{"line_number":140,"context_line":"        - cyborg-tempest-ipv6"},{"line_number":141,"context_line":"        - cyborg-grenade"},{"line_number":142,"context_line":"        - cyborg-grenade-skip-level-always"},{"line_number":143,"context_line":"        - cyborg-tempest-srbac:"},{"line_number":144,"context_line":"            voting: false"},{"line_number":145,"context_line":"    gate:"},{"line_number":146,"context_line":"      jobs:"},{"line_number":147,"context_line":"        - cyborg-tempest-py3"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7089270c_6a7424bc","line":144,"range":{"start_line":143,"start_character":4,"end_line":144,"end_character":25},"in_reply_to":"b1118a1e_2f4e0748","updated":"2026-06-30 12:27:58.000000000","message":"Done","commit_id":"20b6d6f0d646330cad50f94cd005f65375356476"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"632586f90b8c1d658202b63e015f171e09f6db22","unresolved":true,"context_lines":[{"line_number":116,"context_line":"    vars:"},{"line_number":117,"context_line":"      devstack_local_conf:"},{"line_number":118,"context_line":"        post-config:"},{"line_number":119,"context_line":"          $CYBORG_CONF_FILE:"},{"line_number":120,"context_line":"            oslo_policy:"},{"line_number":121,"context_line":"              enforce_scope: true"},{"line_number":122,"context_line":"              enforce_new_defaults: true"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"ff8c40c6_be3cdfe7","line":119,"range":{"start_line":119,"start_character":11,"end_line":119,"end_character":27},"updated":"2026-06-29 10:17:01.000000000","message":"Adding a note here: https://review.opendev.org/c/openstack/cyborg/+/979805 (Rename devstack CYBORG_CONF_FILE to CYBORG_CONF for consistency) merges fist, we need to rename it to CYBORG_CONF.","commit_id":"a4a6b3c552c4ce82bc3c50b328e6375bf127ee4a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"747e48c5e5dfd350beddb9d1f5394ea530b1d66e","unresolved":false,"context_lines":[{"line_number":116,"context_line":"    vars:"},{"line_number":117,"context_line":"      devstack_local_conf:"},{"line_number":118,"context_line":"        post-config:"},{"line_number":119,"context_line":"          $CYBORG_CONF_FILE:"},{"line_number":120,"context_line":"            oslo_policy:"},{"line_number":121,"context_line":"              enforce_scope: true"},{"line_number":122,"context_line":"              enforce_new_defaults: true"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"59961ebc_679f4a37","line":119,"range":{"start_line":119,"start_character":11,"end_line":119,"end_character":27},"in_reply_to":"05a300c3_1ce20c76","updated":"2026-06-30 12:27:58.000000000","message":"Done","commit_id":"a4a6b3c552c4ce82bc3c50b328e6375bf127ee4a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"442c1ed24da9f67e258ec7235177d67473cdbc94","unresolved":true,"context_lines":[{"line_number":116,"context_line":"    vars:"},{"line_number":117,"context_line":"      devstack_local_conf:"},{"line_number":118,"context_line":"        post-config:"},{"line_number":119,"context_line":"          $CYBORG_CONF_FILE:"},{"line_number":120,"context_line":"            oslo_policy:"},{"line_number":121,"context_line":"              enforce_scope: true"},{"line_number":122,"context_line":"              enforce_new_defaults: true"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"05a300c3_1ce20c76","line":119,"range":{"start_line":119,"start_character":11,"end_line":119,"end_character":27},"in_reply_to":"ff8c40c6_be3cdfe7","updated":"2026-06-29 12:53:02.000000000","message":"oh good point let me merge that now and then ill rebase this since  mel asked me to add bug refence to the first patch anyway","commit_id":"a4a6b3c552c4ce82bc3c50b328e6375bf127ee4a"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"20016fbdc8e873489ab28d3cafe0d639ef6a15ac","unresolved":false,"context_lines":[{"line_number":124,"context_line":"          $TEMPEST_CONFIG:"},{"line_number":125,"context_line":"            enforce_scope:"},{"line_number":126,"context_line":"              cyborg: true"},{"line_number":127,"context_line":"      tempest_test_regex: cyborg_tempest_plugin"},{"line_number":128,"context_line":""},{"line_number":129,"context_line":"- project:"},{"line_number":130,"context_line":"    templates:"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"a5428626_e86b5f68","line":127,"updated":"2026-06-23 01:31:34.000000000","message":"tempest_test_regex is redundantly redeclared. cyborg-tempest-base already sets it to cyborg_tempest_plugin in its vars (line 32), and cyborg-tempest-srbac inherits the same value via cyborg-tempest-py3 -\u003e cyborg-multinode-tempest -\u003e cyborg-tempest-base.\n\n**Severity**: SUGGESTION | **Confidence**: 0.9\n\n**Benefit**: Removing the redundant line reduces maintenance burden: if the regex ever changes in the base job the SRBAC job would silently keep the stale value. It also keeps the vars block focused on what is actually new (devstack_local_conf SRBAC settings).\n\n**Recommendation**:\nDelete the tempest_test_regex line from the cyborg-tempest-srbac vars block. The inherited value from cyborg-tempest-base is identical. If a narrower regex (e.g. cyborg_tempest_plugin.tests.api as the commit message suggests) is actually intended, keep the line but change the value accordingly.","commit_id":"a4a6b3c552c4ce82bc3c50b328e6375bf127ee4a"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2d50984138171e320d08a5df2a333494495ceadb","unresolved":false,"context_lines":[{"line_number":110,"context_line":"      Cyborg tempest job with enforce_scope and enforce_new_defaults"},{"line_number":111,"context_line":"      enabled for SRBAC policy testing."},{"line_number":112,"context_line":"    vars:"},{"line_number":113,"context_line":"      devstack_local_conf:"},{"line_number":114,"context_line":"        post-config:"},{"line_number":115,"context_line":"          $CYBORG_CONF:"},{"line_number":116,"context_line":"            oslo_policy:"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"b9ba1f8d_ef67e3ab","line":113,"updated":"2026-06-30 13:39:09.000000000","message":"The new job defines a top-level vars.devstack_local_conf block that relies on Zuul dict-merge with the inherited cyborg_base_vars (which defines devstack services and localrc). This works but the merge behavior is implicit.\n\n**Severity**: SUGGESTION | **Confidence**: 0.8\n\n**Benefit**: Making the intent explicit reduces ambiguity for future maintainers editing the job and makes the SRBAC-specific overrides visually distinct from the inherited base configuration.\n\n**Recommendation**:\nOptionally add a one-line comment above the vars block noting that devstack_local_conf deep-merges with the parent cyborg_base_vars (post-config and test-config merge; base services/localrc are inherited unchanged). No behavioral change required; purely a clarity improvement.","commit_id":"83f856c7173d4b19a9b67d157a52267adb9d45b0"},{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"2d50984138171e320d08a5df2a333494495ceadb","unresolved":false,"context_lines":[{"line_number":134,"context_line":"        - cyborg-tempest-ipv6"},{"line_number":135,"context_line":"        - cyborg-grenade"},{"line_number":136,"context_line":"        - cyborg-grenade-skip-level-always"},{"line_number":137,"context_line":"        - cyborg-tempest-srbac"},{"line_number":138,"context_line":"    gate:"},{"line_number":139,"context_line":"      jobs:"},{"line_number":140,"context_line":"        - cyborg-tempest-py3"}],"source_content_type":"text/x-yaml","patch_set":6,"id":"53d364e6_80a28dcf","line":137,"updated":"2026-06-30 13:39:09.000000000","message":"The new cyborg-tempest-srbac job is added as voting in both check and gate with no initial non-voting stabilization period, yet it exercises newly-migrated SRBAC policies (preceding commits in the series just converted them to DocumentedRuleDefault).\n\n**Severity**: WARNING | **Confidence**: 0.7\n\n**Impact**: If the SRBAC tests or the enforce_scope/enforce_new_defaults policy defaults are not yet stable, a red srbac job will block unrelated patches from merging since it is voting in both check and gate. New tempest jobs are often landed non-voting first and flipped to voting once green on master.\n\n**Suggestion**:\nConsider gating this behind voting: false initially for the first patch in the series, or confirm with the tempest-plugin Depends-On that test_srbac.py is already reliably green on master before relying on it as a gate. If the SRBAC tests are already proven stable, leaving it voting is acceptable; document that decision in the commit message.","commit_id":"83f856c7173d4b19a9b67d157a52267adb9d45b0"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"37597a0f5812503b2f682c2d84e1d6ef2b70aff0","unresolved":true,"context_lines":[{"line_number":125,"context_line":"          $CYBORG_CONF:"},{"line_number":126,"context_line":"            oslo_policy:"},{"line_number":127,"context_line":"              enforce_new_defaults: true"},{"line_number":128,"context_line":"        test-config:"},{"line_number":129,"context_line":"          $TEMPEST_CONFIG:"},{"line_number":130,"context_line":"            enforce_scope:"},{"line_number":131,"context_line":"              cyborg: true"},{"line_number":132,"context_line":""},{"line_number":133,"context_line":"- project:"},{"line_number":134,"context_line":"    templates:"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"298697a4_0f70074f","line":131,"range":{"start_line":128,"start_character":8,"end_line":131,"end_character":26},"updated":"2026-07-20 21:24:41.000000000","message":"oh i need to update this when i update the tempest change tomorrow\n\nbut for now this will work\n\nthis will be using a differnet section/name now tat enforce scope is always true","commit_id":"03b65fa0e85bd16ad8d9ccf4a60ca5a36cd9deef"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"77bc8097a13121154daea2da6c489b632c0abbff","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"0780cd41_f143be61","updated":"2026-06-08 18:55:14.000000000","message":"recheck updated patches","commit_id":"284fc59f91fc709eef96209b16fadcc4ff713c80"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"632586f90b8c1d658202b63e015f171e09f6db22","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"b317da9e_3fc8173b","updated":"2026-06-29 10:17:01.000000000","message":"Looks good.\n\nBelow is test results:\nTempest results from cyborg-tempest-srbac https://review.opendev.org/c/openstack/cyborg/+/992332 \nhttps://5126e99bb555fcd10074-f8d3aa66ce3962c6e3c5c35044bdfdd4.ssl.cf1.rackcdn.com/openstack/21ccea317c924406b12ce9ab3cc22cc5/job-output.txt\n\nhttps://5126e99bb555fcd10074-f8d3aa66ce3962c6e3c5c35044bdfdd4.ssl.cf1.rackcdn.com/openstack/21ccea317c924406b12ce9ab3cc22cc5/controller/logs/tempest_conf.txt\n```\n[enforce_scope]\ncyborg \u003d True\n```\nand\nhttps://5126e99bb555fcd10074-f8d3aa66ce3962c6e3c5c35044bdfdd4.ssl.cf1.rackcdn.com/openstack/21ccea317c924406b12ce9ab3cc22cc5/controller/logs/etc/cyborg/cyborg_conf.txt\n```\n[oslo_policy]\nenforce_new_defaults \u003d True\nenforce_scope \u003d True\npolicy_file \u003d /etc/cyborg/policy.yaml\n```\n\narq tests:\n```\n  SRBAC tests proving new arq policies work:\n  - test_service_create_and_delete_arq — ok (service satisfies project_member_or_service)\n  - test_service_cannot_list_arqs — ok (service lacks reader role)\n  - test_admin_can_read_arqs — ok (admin via implied reader) \n  - test_admin_can_write_arqs — ok (admin via implied member)\n  - test_reader_can_list_arqs — ok (reader satisfies project_reader_or_admin)\n  - test_reader_cannot_create_arq — ok (reader lacks member)\n  - test_reader_cannot_delete_arq — ok (reader lacks member)\n```\nDevice policies test:\n\n```\n  SRBAC tests for device policies:\n  - test_admin_can_read_devices — ok (admin via implied manager)\n  - test_reader_cannot_list_devices — ok (reader lacks manager)\n  - test_member_cannot_list_devices — ok (member lacks manager)\n\n```\n\nDeployables tests:\n\n```\n  SRBAC tests for deployables:\n  - test_admin_can_read_deployables — ok (admin via implied manager)\n  - test_reader_cannot_list_deployables — ok (reader lacks manager)\n  - test_member_cannot_list_deployables — ok (member lacks manager)\n\n```\nAttributes tests:\n```\n  SRBAC tests for attribites:\n  - test_admin_can_list_attributes — ok (admin via implied manager)\n  - test_reader_cannot_list_attributes — ok (reader lacks manager)\n  - test_member_cannot_list_attributes — ok (member lacks manager)\n```\n\nDevice profile tests.\n```\n  SRBAC tests for device profile:\n  - test_reader_can_list_device_profiles — ok (reader satisfies project_reader_or_admin)\n  - test_member_cannot_create_device_profile — ok (member lacks admin)\n  - test_reader_cannot_create_device_profile — ok (reader lacks admin)\n  - test_member_cannot_delete_device_profile — ok (member lacks admin)\n  - test_reader_cannot_delete_device_profile — ok (reader lacks admin)\n```","commit_id":"a4a6b3c552c4ce82bc3c50b328e6375bf127ee4a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"d085049e9c028516ff7be71e7b35b9569779bb3e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"2fe5d1ff_97f3baea","updated":"2026-06-22 08:35:47.000000000","message":"teim-ci: auto","commit_id":"a4a6b3c552c4ce82bc3c50b328e6375bf127ee4a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"d77e2b58da22a26a7624e537ff2f046eeb1d48ec","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"e16daa16_a4ed7c66","updated":"2026-06-22 23:46:07.000000000","message":"teim-ci: auto","commit_id":"a4a6b3c552c4ce82bc3c50b328e6375bf127ee4a"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"61a32f2fb2b3c30f3753c3c9d3fa6ea8414b6228","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"e0c15165_08a90b38","updated":"2026-07-20 21:23:06.000000000","message":"recheck depency was in merge conflict","commit_id":"03b65fa0e85bd16ad8d9ccf4a60ca5a36cd9deef"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"926b2ef059a5ca5b9dcd96cf331b3e84042ef0a5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"e91b99ba_9024cf3f","updated":"2026-07-21 13:24:12.000000000","message":"https://a4bb4f71283ac627cd09-716c2febf7f730d66787c22f3ed0da3e.ssl.cf2.rackcdn.com/openstack/48a13f3270704ac89f0fa9ae42ba8a80/testr_results.html All srbac tests passing.\n\nthank you for updating the patch.","commit_id":"b08ddd4c974a2bf9d2ec4b531b5011bf002d341f"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2df68a8f4495bed3083eb7d8eaca8cada065d4ad","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"27df9942_d99a7e87","updated":"2026-07-21 20:48:50.000000000","message":"recheck","commit_id":"b08ddd4c974a2bf9d2ec4b531b5011bf002d341f"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2cec0577ea377c6b5c2ab6b0eb42743e10eae437","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"5b5f3561_f409a935","updated":"2026-07-21 19:42:52.000000000","message":"recheck flaky reboot test","commit_id":"b08ddd4c974a2bf9d2ec4b531b5011bf002d341f"}]}
