)]}'
{"id":"openstack%2Fdesignate~1001113","triplet_id":"openstack%2Fdesignate~stable%2F2026.1~Id39956b744023a591fcd2c4098a9e29fcd9cfdf8","project":"openstack/designate","branch":"stable/2026.1","attention_set":{"31664":{"account":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"last_update":"2026-08-17 18:03:30.000000000","reason":"\u003cGERRIT_ACCOUNT_22623\u003e replied on the change","reason_account":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}}},"removed_from_attention_set":{"22623":{"account":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},"last_update":"2026-08-17 18:03:30.000000000","reason":"\u003cGERRIT_ACCOUNT_22623\u003e replied on the change","reason_account":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}}},"hashtags":[],"change_id":"Id39956b744023a591fcd2c4098a9e29fcd9cfdf8","subject":"Fix newline validation gap in TXT/SPF/NAPTR causing AXFR DoS","status":"NEW","created":"2026-08-17 10:58:58.000000000","updated":"2026-08-17 18:03:30.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"07e97d9aa208dcf7773fabef224c425ced4d2045","_number":1001113,"virtual_id_number":1001113,"owner":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-08-17 12:23:57.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2026-08-17 18:03:30.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":2},"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Gate Blocker Fix / Urgent Change"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-17 11:01:24.000000000","updated_by":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"reviewer":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},"state":"REVIEWER"},{"updated":"2026-08-17 12:23:57.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"a21484b4aef36f9a014e6e73be1b84fbf0de2bff","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"date":"2026-08-17 10:58:58.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"42bed1f9641f415118832164ff10a73f1687f550","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-17 12:23:57.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/8c8e3fdab0624919945292b8f2744e37\n\n- designate-bind9-core https://zuul.opendev.org/t/openstack/build/836fb1c86d9f49bdb241e932973a07d6 : SUCCESS in 41m 57s\n- designate-bind9-with-keystone-default-roles https://zuul.opendev.org/t/openstack/build/5f809538230e4996bb845698f0efe50d : SUCCESS in 51m 15s\n- designate-pdns4-core https://zuul.opendev.org/t/openstack/build/65809ccab6cf4f45ac3890a1d27533f3 : SUCCESS in 47m 47s\n- designate-bind9-multipool https://zuul.opendev.org/t/openstack/build/46944abd40044aa79356f1b90f8b5586 : SUCCESS in 19m 38s\n- designate-grenade-bind9 https://zuul.opendev.org/t/openstack/build/e88011d3eec2414e9f5e0ba47e9e8b7d : SUCCESS in 1h 19m 27s\n- designate-grenade-pdns4 https://zuul.opendev.org/t/openstack/build/66ccaabb02cc4ad9ad20380d575a3be5 : SUCCESS in 57m 18s\n- designate-grenade-bind9-skip-level https://zuul.opendev.org/t/openstack/build/5916330992e240dfb55e669cd1dc431a : SUCCESS in 58m 34s\n- designate-grenade-pdns4-skip-level https://zuul.opendev.org/t/openstack/build/982cd6ad21454c38a615c498aa60f88b : SUCCESS in 51m 48s\n- designate-bind9-core-catalog-zones https://zuul.opendev.org/t/openstack/build/503eb5676a4749298726874fa2074c27 : SUCCESS in 44m 46s (non-voting)\n- designate-only-ipv6-pdns4 https://zuul.opendev.org/t/openstack/build/5fc9be62bfbe479b9dc36af8d50bc9d6 : SUCCESS in 47m 20s\n- designate-only-ipv6-bind9 https://zuul.opendev.org/t/openstack/build/4eb691b73f6949858e2ea614f4d1dae9 : SUCCESS in 32m 32s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c2dc1379409b44b085dad02e13023f1d : SUCCESS in 6m 06s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/0282bcb6b5d147b49cea87fcbf87e681 : SUCCESS in 3m 10s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/9371a72b20544e0d8ed7322137f4fb16 : SUCCESS in 3m 36s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/4a62113951f94ad0888e133f41d844bb : SUCCESS in 6m 28s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/7d6ae7304d6442ba9b9087e1486bceb9 : SUCCESS in 4m 37s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a17b39cc6e6945ec8282771487147723 : SUCCESS in 4m 25s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/19d2ee983a4f4e4e8b6087ecf8cda0ee : SUCCESS in 4m 37s\n- neutron-tempest-plugin-designate-scenario https://zuul.opendev.org/t/openstack/build/438553ca3026421899f04c4f7b16b3ef : SUCCESS in 33m 02s\n- designate-tox-dnspython-latest https://zuul.opendev.org/t/openstack/build/ee6edd755c9949cd840c8ad32a57d728 : SUCCESS in 5m 10s","accounts_in_message":[],"_revision_number":1},{"id":"07e97d9aa208dcf7773fabef224c425ced4d2045","author":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},"date":"2026-08-17 18:03:30.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"02475bc17b65226dacc30716b5dad069f9d14315","revisions":{"02475bc17b65226dacc30716b5dad069f9d14315":{"kind":"REWORK","_number":1,"created":"2026-08-17 10:58:58.000000000","uploader":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"ref":"refs/changes/13/1001113/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/designate","ref":"refs/changes/13/1001113/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/designate refs/changes/13/1001113/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/designate refs/changes/13/1001113/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/designate refs/changes/13/1001113/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/designate refs/changes/13/1001113/1"}}},"commit":{"parents":[{"commit":"d4b703bb4637e6e740e4b401eac6e9308769c39f","subject":"Fix cross-tenant/cross-pool zone ownership bypass","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/designate/commit/d4b703bb4637e6e740e4b401eac6e9308769c39f"}]}],"author":{"name":"Omer","email":"oschwart@redhat.com","date":"2026-07-31 09:05:50.000000000","tz":120},"committer":{"name":"Omer","email":"oschwart@redhat.com","date":"2026-08-17 10:58:33.000000000","tz":120},"subject":"Fix newline validation gap in TXT/SPF/NAPTR causing AXFR DoS","message":"Fix newline validation gap in TXT/SPF/NAPTR causing AXFR DoS\n\nTXT and SPF record validation never rejected a literal newline\ncharacter in the value, and NAPTR\u0027s flags/service/regexp field\nregexes were anchored with a trailing $, which (without\nre.MULTILINE) matches immediately before a trailing newline\nrather than strictly at the end of the string. A value crafted\neither way passed designate\u0027s validation but later broke\ndnspython\u0027s tokenizer with \"newline in quoted string\" when\nmdns/handler.py rendered it during AXFR.\n\nmdns/handler.py\u0027s dns.rrset.from_text_list() call had no\nexception handling, so that parse failure raised unhandled during\nAXFR rendering and aborted the entire zone transfer. Since any\nproject with recordset-create permission on a zone -- including a\nproject a PRIMARY zone has been shared with -- could create such\na value, this let one project\u0027s malformed recordset permanently\nblock publication of every other recordset in the same zone,\nincluding recordsets belonging to other projects.\n\nReject literal newlines in TXT and SPF validation, and anchor the\nNAPTR field regexes with \\Z instead of $. As defense in depth,\nmdns/handler.py now catches a parse failure and skips just the\noffending recordset (with an error log identifying it) both while\nrendering an AXFR response and while answering a direct record\nquery, instead of aborting the whole response.\n\nCloses-Bug: #2162105\nGenerated-By: Claude Code 5 Sonnet\nChange-Id: Id39956b744023a591fcd2c4098a9e29fcd9cfdf8\nSigned-off-by: Omer \u003coschwart@redhat.com\u003e\n(cherry picked from commit 2b70b1c85c30d0fc5cd4e44aedcf0da7250a9d47)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/designate/commit/02475bc17b65226dacc30716b5dad069f9d14315"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/designate/commit/02475bc17b65226dacc30716b5dad069f9d14315"}]},"branch":"refs/heads/stable/2026.1"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}},{"label":"Workflow","status":"MAY"},{"label":"Review-Priority","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Review-Priority","description":"Review priority","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"-label:Review-Priority\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":[],"failing_atoms":["label:Review-Priority\u003dMIN"],"atom_explanations":{"label:Review-Priority\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
