)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"94ee1e2e845151a3c0a1fa28a55312a5d30f4af7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"3bf6d2a8_c30b156f","updated":"2026-07-02 17:21:35.000000000","message":"+1 for now this should pass ci but lest see","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"bc983a02d69303a920d964cfa87891b5bda42c6a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"f78cdabf_33c58973","updated":"2026-07-02 17:33:30.000000000","message":"This looks OK to me","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"b5f181b8b7ed365717180f028cb7b31d4dc838de","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"90a91629_ba15d94e","updated":"2026-07-02 17:28:57.000000000","message":"lgtm, hoping all tests are good on this","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"ac718606b6c7410bb4e964632f68846ce4651e97","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"35efbce4_3bb43007","updated":"2026-07-02 22:39:50.000000000","message":"ill check back on this in my morning but i jsut fixed a few minor issue","commit_id":"02f10e5bc3471c53cab1c563a1962b9939186f51"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"a813cde83c47898e77dc0b9fbcb042dd6f257b06","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"bbc0daf6_dd79bd11","updated":"2026-07-03 13:47:18.000000000","message":"looks good!","commit_id":"02f10e5bc3471c53cab1c563a1962b9939186f51"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"d31c5ce1c8bb31892ed3dfbfaffd1f2eebc6aa72","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"6ab4ce0e_5159a6e3","updated":"2026-07-08 00:52:33.000000000","message":"recheck","commit_id":"02f10e5bc3471c53cab1c563a1962b9939186f51"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"505f7bad61e22c95372c52cc263404ac8b40952f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"baaf8b16_1d853a6a","updated":"2026-07-09 07:43:28.000000000","message":"recheck","commit_id":"02f10e5bc3471c53cab1c563a1962b9939186f51"},{"author":{"_account_id":12393,"name":"chandan kumar","display_name":"Chandan Kumar","email":"chkumar@redhat.com","username":"chkumar246"},"change_message_id":"045874c08ea0fa8d71c40d71c716fd744da1d94e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"6449a5e1_0bac6d8d","updated":"2026-07-08 10:10:35.000000000","message":"recheck mirror issue","commit_id":"02f10e5bc3471c53cab1c563a1962b9939186f51"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"1514ddd7f20aa079ff96a5a6b6e09373aab9029e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"f13eee90_79027976","updated":"2026-07-08 12:01:25.000000000","message":"recheck ovh mirror issue","commit_id":"02f10e5bc3471c53cab1c563a1962b9939186f51"}],"cyborg/policies/device_profiles.py":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"6f27c0d49b7f5a38657445637edc4d54df2a4028","unresolved":false,"context_lines":[{"line_number":33,"context_line":"    name\u003d\u0027cyborg:device_profile:get_all\u0027,"},{"line_number":34,"context_line":"    check_str\u003dbase.deprecated_default,"},{"line_number":35,"context_line":"    deprecated_reason\u003d("},{"line_number":36,"context_line":"        \u0027request admin_or_owmer rule is too strict for listing device_profile\u0027"},{"line_number":37,"context_line":"    ),"},{"line_number":38,"context_line":"    deprecated_since\u003dversionutils.deprecated.WALLABY,"},{"line_number":39,"context_line":")"}],"source_content_type":"text/x-python","patch_set":1,"id":"05283736_595c10d8","line":36,"updated":"2026-07-02 17:31:11.000000000","message":"The deprecated_reason strings in device_profiles.py contain a typo \u0027admin_or_owmer\u0027 (missing \u0027n\u0027). This is pre-existing but the surrounding comment block was edited in this patch, making it a natural moment to fix it.\n\n**Severity**: SUGGESTION | **Confidence**: 0.9\n\n**Benefit**: Corrects a misspelling that surfaces in oslopolicy-policy-generator and operator-facing deprecation output, improving professionalism of generated policy documentation.\n\n**Recommendation**:\nChange \u0027admin_or_owmer rule is too strict\u0027 to \u0027admin_or_owner rule is too strict\u0027 on line 36 (deprecated_get_all). The same typo does not appear in the other deprecated_reason strings.","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"ac718606b6c7410bb4e964632f68846ce4651e97","unresolved":false,"context_lines":[{"line_number":33,"context_line":"    name\u003d\u0027cyborg:device_profile:get_all\u0027,"},{"line_number":34,"context_line":"    check_str\u003dbase.deprecated_default,"},{"line_number":35,"context_line":"    deprecated_reason\u003d("},{"line_number":36,"context_line":"        \u0027request admin_or_owmer rule is too strict for listing device_profile\u0027"},{"line_number":37,"context_line":"    ),"},{"line_number":38,"context_line":"    deprecated_since\u003dversionutils.deprecated.WALLABY,"},{"line_number":39,"context_line":")"}],"source_content_type":"text/x-python","patch_set":1,"id":"0fa7ba66_bd106bdd","line":36,"in_reply_to":"05283736_595c10d8","updated":"2026-07-02 22:39:50.000000000","message":"damit :) ya i shoudl fix that while im here but also i slight sad that codespell didnt catch this.","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"}],"doc/source/configuration/policy-concepts.rst":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"6f27c0d49b7f5a38657445637edc4d54df2a4028","unresolved":false,"context_lines":[{"line_number":189,"context_line":"Backward Compatibility"},{"line_number":190,"context_line":"----------------------"},{"line_number":191,"context_line":""},{"line_number":192,"context_line":"During the development period (Victoria and Wallaby releases), the new and old"},{"line_number":193,"context_line":"policy both worked for backward compatibility by supporting the old defaults"},{"line_number":194,"context_line":"and allowing operators to disable scope enforcement temporarily. Scope"},{"line_number":195,"context_line":"enforcement is now always enabled when a policy defines ``scope_types``."}],"source_content_type":"text/x-rst","patch_set":1,"id":"48e20183_00ba8fb5","line":192,"updated":"2026-07-02 17:31:11.000000000","message":"The backward-compatibility section still references \u0027Victoria and Wallaby releases\u0027 in the past tense alongside the statement that scope is now always enforced, which reads slightly awkwardly for a current-era reader.\n\n**Severity**: SUGGESTION | **Confidence**: 0.7\n\n**Benefit**: Improves clarity of the migration narrative so operators understand the historical context versus the current always-enforced state.\n\n**Recommendation**:\nConsider a minor wording pass to separate the historical backward-compatibility window from the current unconditional-enforcement statement. Not blocking.","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"}],"releasenotes/notes/fix-rule-allow-device-apis-lp2143263.yaml":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"94ee1e2e845151a3c0a1fa28a55312a5d30f4af7","unresolved":true,"context_lines":[{"line_number":12,"context_line":"    APIs."},{"line_number":13,"context_line":"upgrade:"},{"line_number":14,"context_line":"  - |"},{"line_number":15,"context_line":"    Cyborg API policies now declare ``scope_types\u003d[\u0027project\u0027]`` and reject"},{"line_number":16,"context_line":"    Keystone system-scoped tokens via oslo.policy scope enforcement. Use"},{"line_number":17,"context_line":"    project-scoped tokens for Cyborg APIs; prefer custom policy rules if you"},{"line_number":18,"context_line":"    need different access behavior."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"973be94f_a7f9be64","line":18,"range":{"start_line":15,"start_character":4,"end_line":18,"end_character":35},"updated":"2026-07-02 17:21:35.000000000","message":"im 50/50 on if this is correct\n\non master we added this release note as part fo the cve fixes a few week ago so i think updating it makes sesne on master only since the config option is going awasy before the next actual relase.\n\non the stable brnache however im not going to change this\n\nso im oing to keep this update so that we dont have contradictory advices in the same release","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"b5f181b8b7ed365717180f028cb7b31d4dc838de","unresolved":true,"context_lines":[{"line_number":12,"context_line":"    APIs."},{"line_number":13,"context_line":"upgrade:"},{"line_number":14,"context_line":"  - |"},{"line_number":15,"context_line":"    Cyborg API policies now declare ``scope_types\u003d[\u0027project\u0027]`` and reject"},{"line_number":16,"context_line":"    Keystone system-scoped tokens via oslo.policy scope enforcement. Use"},{"line_number":17,"context_line":"    project-scoped tokens for Cyborg APIs; prefer custom policy rules if you"},{"line_number":18,"context_line":"    need different access behavior."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"cfc71b9a_e5fa4e55","line":18,"range":{"start_line":15,"start_character":4,"end_line":18,"end_character":35},"in_reply_to":"973be94f_a7f9be64","updated":"2026-07-02 17:28:57.000000000","message":"i think it make sense to correct the not released release notes","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"72d3c0bbbb7263cb22932998a424656bb3d996ad","unresolved":false,"context_lines":[{"line_number":12,"context_line":"    APIs."},{"line_number":13,"context_line":"upgrade:"},{"line_number":14,"context_line":"  - |"},{"line_number":15,"context_line":"    Cyborg API policies now declare ``scope_types\u003d[\u0027project\u0027]`` and reject"},{"line_number":16,"context_line":"    Keystone system-scoped tokens via oslo.policy scope enforcement. Use"},{"line_number":17,"context_line":"    project-scoped tokens for Cyborg APIs; prefer custom policy rules if you"},{"line_number":18,"context_line":"    need different access behavior."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"b9250503_efde8b80","line":18,"range":{"start_line":15,"start_character":4,"end_line":18,"end_character":35},"in_reply_to":"cfc71b9a_e5fa4e55","updated":"2026-07-02 22:41:04.000000000","message":"Acknowledged","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"}],"releasenotes/notes/remove-enforce-scope-usage-8d5c4b2f6a0e1b3c.yaml":[{"author":{"_account_id":28006,"name":"teim-ci","display_name":"teim-ci","email":"ci@seanmooney.info","username":"ci-sean-mooney","status":"this is a third-party ci account run by sean-k-mooney on irc\nhosted at zuul.teim.app"},"tag":"autogenerated:zuul:automatic-ci","change_message_id":"6f27c0d49b7f5a38657445637edc4d54df2a4028","unresolved":false,"context_lines":[{"line_number":2,"context_line":"upgrade:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Cyborg no longer supports disabling policy scope enforcement. oslo.policy"},{"line_number":5,"context_line":"    always enforces ``scope_types`` when they are defined on policy rules."},{"line_number":6,"context_line":"    Cyborg APIs continue to declare project scope, so callers must use"},{"line_number":7,"context_line":"    project-scoped tokens instead of system-scoped tokens."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e51a673b_c4b533fd","line":5,"updated":"2026-07-02 17:31:11.000000000","message":"The new upgrade release note describes scope becoming unconditionally enforced but does not provide explicit guidance for operators who currently rely on enforce_scope\u003dFalse. Those deployments may break on upgrade when oslo.policy removes the option.\n\n**Severity**: WARNING | **Confidence**: 0.8\n\n**Impact**: Operators with enforce_scope\u003dFalse today (to allow system-scoped tokens during migration) will see those tokens rejected after upgrade with no documented remediation step beyond \u0027use project-scoped tokens\u0027.\n\n**Suggestion**:\nAdd a brief sentence to the upgrade note pointing operators to audit for system-scoped token usage and migrate callers to project-scoped tokens before upgrading, mirroring the guidance the old runtime warning provided.","commit_id":"708b28c122e8d2e8ab802db2f0ae0de048512cce"}]}
