)]}'
{"id":"openstack%2Fdesignate~1001114","triplet_id":"openstack%2Fdesignate~stable%2F2025.2~Id39956b744023a591fcd2c4098a9e29fcd9cfdf8","project":"openstack/designate","branch":"stable/2025.2","attention_set":{},"removed_from_attention_set":{"31664":{"account":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"last_update":"2026-08-18 16:47:51.000000000","reason":"\u003cGERRIT_ACCOUNT_31664\u003e replied on the change","reason_account":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"}},"22623":{"account":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},"last_update":"2026-08-17 18:03:27.000000000","reason":"\u003cGERRIT_ACCOUNT_22623\u003e replied on the change","reason_account":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}}},"hashtags":[],"change_id":"Id39956b744023a591fcd2c4098a9e29fcd9cfdf8","subject":"Fix newline validation gap in TXT/SPF/NAPTR causing AXFR DoS","status":"MERGED","created":"2026-08-17 11:00:19.000000000","updated":"2026-08-18 18:20:04.000000000","submitted":"2026-08-18 18:19:01.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":1,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1001114","meta_rev_id":"0fc1fb7ffb7d33fa6194130a4330449d22ead66e","_number":1001114,"virtual_id_number":1001114,"owner":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-08-18 18:19:00.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"all":[{"value":2,"date":"2026-08-18 16:47:51.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2026-08-17 18:03:27.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"all":[{"value":1,"date":"2026-08-18 16:47:51.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"recommended":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"all":[{"value":1,"date":"2026-08-18 16:47:51.000000000","permitted_voting_range":{"min":1,"max":2},"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Gate Blocker Fix / Urgent Change"},"description":"","value":1,"default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-17 11:01:29.000000000","updated_by":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"reviewer":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},"state":"REVIEWER"},{"updated":"2026-08-17 12:07:37.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"4624c590b5367d257bee25f5c9bb6b089ad08eea","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"date":"2026-08-17 11:00:19.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"0fe1931edacfc2298fbbbffe8a70f150119ceb0c","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-17 12:07:37.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/565998625f0c4d4bb1e21a846329c827\n\n- designate-grenade-bind9 https://zuul.opendev.org/t/openstack/build/24fe85e82db54dbf963f55007db6b340 : SUCCESS in 58m 36s\n- designate-grenade-pdns4 https://zuul.opendev.org/t/openstack/build/ebf1666e6db341b0a5924f192a5b5a07 : SUCCESS in 1h 06m 06s\n- designate-grenade-bind9-skip-level https://zuul.opendev.org/t/openstack/build/540a167e6ae343c4b92015e180a59435 : FAILURE in 41m 13s (non-voting)\n- designate-grenade-pdns4-skip-level https://zuul.opendev.org/t/openstack/build/62f6c28e9aa149d49d7342583d777cdb : FAILURE in 33m 01s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/5cf352b9b0ce4b66a242e15caced4c7e : SUCCESS in 8m 08s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/f9b022187ca347bd9b183db3b9d16567 : SUCCESS in 3m 09s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/66cb8b2d01ff47328a62a8bb3a26b92b : SUCCESS in 5m 08s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/069dd42ef57b4e10ae0f32ac2f0deb72 : SUCCESS in 5m 22s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/517fc3bc5ae847089e15234c70f8253f : SUCCESS in 7m 23s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/99302ad88b884ca99eb0472bc4a6354d : SUCCESS in 8m 08s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ee7e3cc6a28c4817887abe2c5b2a5ff7 : SUCCESS in 6m 08s\n- neutron-tempest-plugin-designate-scenario https://zuul.opendev.org/t/openstack/build/fb0b9141ca5a4c9c85889580965cd725 : SUCCESS in 30m 44s\n- designate-tox-dnspython-latest https://zuul.opendev.org/t/openstack/build/bb4a1be537bf481dbe990e651ed141a6 : SUCCESS in 6m 50s","accounts_in_message":[],"_revision_number":1},{"id":"f79d3ca87ca1e8cc7d0f57c3f7262548628019de","author":{"_account_id":22623,"name":"Erik Olof Gunnar Andersson","email":"eandersson@blizzard.com","username":"eoandersson"},"date":"2026-08-17 18:03:27.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"d7647d5593664ac29ad7af4063bc8639af393bd0","author":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"date":"2026-08-18 16:47:51.000000000","message":"Patch Set 1: Code-Review+2 Review-Priority+1 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"4a075301164adeb14097bc75ea63d8e027777094","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-18 16:48:49.000000000","message":"Patch Set 1: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":1},{"id":"25fddff528fa38301d925418fc06795a544f01e1","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-18 18:19:00.000000000","message":"Patch Set 1: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/dc6124014ead46f8b317adca0f6896d0\n\n- designate-grenade-pdns4 https://zuul.opendev.org/t/openstack/build/e7204bf8823148738ab0e7bd3d9da003 : SUCCESS in 1h 18m 50s\n- designate-grenade-bind9 https://zuul.opendev.org/t/openstack/build/5903af73bce743a2b6a2710211f20b7a : SUCCESS in 1h 18m 52s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/b506801482f8401992c47afd51d1d55b : SUCCESS in 3m 11s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/f2d3f562e70c4e85bdc01409f8095b0b : SUCCESS in 6m 01s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/bcbfd35effbc47aab330d44b7e4f8c94 : SUCCESS in 6m 01s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/3c78368122c54e4c9d0f390c501a0395 : SUCCESS in 8m 26s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/72e6c2d5e6a74e4781b5a479e79a0974 : SUCCESS in 5m 01s\n- neutron-tempest-plugin-designate-scenario https://zuul.opendev.org/t/openstack/build/a3b309ccd8dd4ac681cffb68fd6d337d : SUCCESS in 31m 02s","accounts_in_message":[],"_revision_number":1},{"id":"3de5a7db8a8f0e96c3613d42c103987869981018","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-18 18:19:01.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":1},{"id":"0fc1fb7ffb7d33fa6194130a4330449d22ead66e","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-18 18:20:04.000000000","message":"Patch Set 1:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/37acc6d3e7324b7e8f0b2831c366dec3\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/62565eb2f2d74338bfb17da87804a85b : SUCCESS in 53s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/bb0a6c729d0c4bbc82a9506d9a10ecb1 : SUCCESS in 51s","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"985b488885d69a0d271605ecf8a2cbeaf582188c","revisions":{"985b488885d69a0d271605ecf8a2cbeaf582188c":{"kind":"REWORK","_number":1,"created":"2026-08-17 11:00:19.000000000","uploader":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"ref":"refs/changes/14/1001114/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/designate","ref":"refs/changes/14/1001114/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/designate refs/changes/14/1001114/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/designate refs/changes/14/1001114/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/designate refs/changes/14/1001114/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/designate refs/changes/14/1001114/1"}}},"commit":{"parents":[{"commit":"2ee5e4a00bc632283a4b5c5da1a94d8f184d1272","subject":"Fix cross-tenant/cross-pool zone ownership bypass","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/designate/commit/2ee5e4a00bc632283a4b5c5da1a94d8f184d1272"}]}],"author":{"name":"Omer","email":"oschwart@redhat.com","date":"2026-07-31 09:05:50.000000000","tz":120},"committer":{"name":"Omer","email":"oschwart@redhat.com","date":"2026-08-17 11:00:11.000000000","tz":120},"subject":"Fix newline validation gap in TXT/SPF/NAPTR causing AXFR DoS","message":"Fix newline validation gap in TXT/SPF/NAPTR causing AXFR DoS\n\nTXT and SPF record validation never rejected a literal newline\ncharacter in the value, and NAPTR\u0027s flags/service/regexp field\nregexes were anchored with a trailing $, which (without\nre.MULTILINE) matches immediately before a trailing newline\nrather than strictly at the end of the string. A value crafted\neither way passed designate\u0027s validation but later broke\ndnspython\u0027s tokenizer with \"newline in quoted string\" when\nmdns/handler.py rendered it during AXFR.\n\nmdns/handler.py\u0027s dns.rrset.from_text_list() call had no\nexception handling, so that parse failure raised unhandled during\nAXFR rendering and aborted the entire zone transfer. Since any\nproject with recordset-create permission on a zone -- including a\nproject a PRIMARY zone has been shared with -- could create such\na value, this let one project\u0027s malformed recordset permanently\nblock publication of every other recordset in the same zone,\nincluding recordsets belonging to other projects.\n\nReject literal newlines in TXT and SPF validation, and anchor the\nNAPTR field regexes with \\Z instead of $. As defense in depth,\nmdns/handler.py now catches a parse failure and skips just the\noffending recordset (with an error log identifying it) both while\nrendering an AXFR response and while answering a direct record\nquery, instead of aborting the whole response.\n\nCloses-Bug: #2162105\nGenerated-By: Claude Code 5 Sonnet\nChange-Id: Id39956b744023a591fcd2c4098a9e29fcd9cfdf8\nSigned-off-by: Omer \u003coschwart@redhat.com\u003e\n(cherry picked from commit 2b70b1c85c30d0fc5cd4e44aedcf0da7250a9d47)\n(cherry picked from commit 02475bc17b65226dacc30716b5dad069f9d14315)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/designate/commit/985b488885d69a0d271605ecf8a2cbeaf582188c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/designate/commit/985b488885d69a0d271605ecf8a2cbeaf582188c"}]},"branch":"refs/heads/stable/2025.2"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"}},{"label":"Review-Priority","status":"MAY","applied_by":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Review-Priority","description":"Review priority","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"-label:Review-Priority\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":[],"failing_atoms":["label:Review-Priority\u003dMIN"],"atom_explanations":{"label:Review-Priority\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
