)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"change_message_id":"cb05bc806718d399bba0320ac944ecc50d6d5af2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"e762985a_0f4ccfb8","updated":"2026-09-23 10:16:39.000000000","message":"Left a suggestion, thanks for working on this fix","commit_id":"ab3d9e64cd23c4c678500341d0e3d8d8b9853afd"}],"designate/mdns/handler.py":[{"author":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"change_message_id":"cb05bc806718d399bba0320ac944ecc50d6d5af2","unresolved":true,"context_lines":[{"line_number":212,"context_line":"            # a name-only lookup restricted to catalog zones before"},{"line_number":213,"context_line":"            # giving up."},{"line_number":214,"context_line":"            try:"},{"line_number":215,"context_line":"                zone \u003d self.storage.find_zone("},{"line_number":216,"context_line":"                    context,"},{"line_number":217,"context_line":"                    {\u0027name\u0027: name, \u0027type\u0027: constants.ZONE_CATALOG}"},{"line_number":218,"context_line":"                )"}],"source_content_type":"text/x-python","patch_set":3,"id":"4c5b103f_50e5de6e","line":215,"range":{"start_line":215,"start_character":16,"end_line":215,"end_character":46},"updated":"2026-09-23 10:16:39.000000000","message":"This fallback drops the pool or zone ID derived from the request’s TSIG key. If a client signs an AXFR request with a valid key for another pool or zone, the scoped lookup fails, but this lookup can return the requested catalog zone and its member list—even with query_enforce_tsig\u003dTrue. Could we limit the fallback to unsigned requests and keep refusing signed requests whose scoped lookup fails? A test with an unrelated valid TSIG key would cover this case.\n\nE.g.\n```python\n          except exceptions.ZoneNotFound:\n              # A TSIG key scopes the request to its pool or zone. Do not\n              # search other pools when that scoped lookup fails.\n              if request.environ.get(\u0027tsigkey\u0027) is not None:\n                  LOG.warning(\u0027ZoneNotFound while handling axfr request. \u0027\n                              \u0027Question was %(qr)s\u0027, {\u0027qr\u0027: q_rrset})\n  \n                  yield self._handle_query_error(request, dns.rcode.REFUSED)\n                  return\n  \n              # Catalog zone FQDNs are globally unique and are not tied to\n```\nWhat do you think?","commit_id":"ab3d9e64cd23c4c678500341d0e3d8d8b9853afd"},{"author":{"_account_id":20178,"name":"Tore Anderson","email":"tore@fud.no","username":"tore"},"change_message_id":"3da7f0b3a9052c8f17f0d486deef7bd43983c39b","unresolved":false,"context_lines":[{"line_number":212,"context_line":"            # a name-only lookup restricted to catalog zones before"},{"line_number":213,"context_line":"            # giving up."},{"line_number":214,"context_line":"            try:"},{"line_number":215,"context_line":"                zone \u003d self.storage.find_zone("},{"line_number":216,"context_line":"                    context,"},{"line_number":217,"context_line":"                    {\u0027name\u0027: name, \u0027type\u0027: constants.ZONE_CATALOG}"},{"line_number":218,"context_line":"                )"}],"source_content_type":"text/x-python","patch_set":3,"id":"fe38f389_ad310b77","line":215,"range":{"start_line":215,"start_character":16,"end_line":215,"end_character":46},"in_reply_to":"4901d6f8_afd78b37","updated":"2026-09-24 10:26:23.000000000","message":"Done","commit_id":"ab3d9e64cd23c4c678500341d0e3d8d8b9853afd"},{"author":{"_account_id":20178,"name":"Tore Anderson","email":"tore@fud.no","username":"tore"},"change_message_id":"97075123de599af35750308ff496c7f2c5572c9d","unresolved":true,"context_lines":[{"line_number":212,"context_line":"            # a name-only lookup restricted to catalog zones before"},{"line_number":213,"context_line":"            # giving up."},{"line_number":214,"context_line":"            try:"},{"line_number":215,"context_line":"                zone \u003d self.storage.find_zone("},{"line_number":216,"context_line":"                    context,"},{"line_number":217,"context_line":"                    {\u0027name\u0027: name, \u0027type\u0027: constants.ZONE_CATALOG}"},{"line_number":218,"context_line":"                )"}],"source_content_type":"text/x-python","patch_set":3,"id":"7aa2a03a_59754931","line":215,"range":{"start_line":215,"start_character":16,"end_line":215,"end_character":46},"in_reply_to":"4c5b103f_50e5de6e","updated":"2026-09-23 10:21:56.000000000","message":"Thanks for the review! This makes sense to me, yes. I\u0027ll push an updated version soon.","commit_id":"ab3d9e64cd23c4c678500341d0e3d8d8b9853afd"},{"author":{"_account_id":20178,"name":"Tore Anderson","email":"tore@fud.no","username":"tore"},"change_message_id":"7a91d98bc78de935dcf175140802a8cf4d46be7a","unresolved":true,"context_lines":[{"line_number":212,"context_line":"            # a name-only lookup restricted to catalog zones before"},{"line_number":213,"context_line":"            # giving up."},{"line_number":214,"context_line":"            try:"},{"line_number":215,"context_line":"                zone \u003d self.storage.find_zone("},{"line_number":216,"context_line":"                    context,"},{"line_number":217,"context_line":"                    {\u0027name\u0027: name, \u0027type\u0027: constants.ZONE_CATALOG}"},{"line_number":218,"context_line":"                )"}],"source_content_type":"text/x-python","patch_set":3,"id":"e97d9ae8_1e64ee48","line":215,"range":{"start_line":215,"start_character":16,"end_line":215,"end_character":46},"in_reply_to":"7aa2a03a_59754931","updated":"2026-09-24 06:24:02.000000000","message":"Hi @oschwart@redhat.com, and thanks again for your feedback. It is appropriate and correct, but caused me to take a step back and rethink whether or not this change is appropriate in the light of change https://review.opendev.org/c/openstack/designate/+/971659.\n\nWhile that change strictly speaking concerns itself with regular zones and not catalog zones, the overall effect is bigger - namely preventing all non-default pools from being used without TSIGs. While this change would make the catalog zone work without TSIG, this is a meaningless exercise - the regular zones advertised within the catalog zone cannot be transferred by the downstream anyway, so the setup remains defective overall, and the only way to fix it is to add TSIGs to the non-default pool - at which point this change is not needed.\n\nThe documentation introduced by https://review.opendev.org/c/openstack/designate/+/971659 spells it out in no uncertain terms: «Non-default pools require TSIG (Transaction Signature) keys for zone transfers to function correctly. Without TSIG keys, zones in non-default pools will fail to synchronize with backend nameservers»\n\nFor this reason I think this change is now pointless, and I suggest simply abandoning it and closing https://bugs.launchpad.net/designate/+bug/2160221 as invalid following the merge of https://review.opendev.org/c/openstack/designate/+/971659.\n\nDo you agree?","commit_id":"ab3d9e64cd23c4c678500341d0e3d8d8b9853afd"},{"author":{"_account_id":31664,"name":"Omer Schwartz","email":"oschwart@redhat.com","username":"oschwart"},"change_message_id":"857392ef7ed268a6d1116d5df1d793b3401442a2","unresolved":true,"context_lines":[{"line_number":212,"context_line":"            # a name-only lookup restricted to catalog zones before"},{"line_number":213,"context_line":"            # giving up."},{"line_number":214,"context_line":"            try:"},{"line_number":215,"context_line":"                zone \u003d self.storage.find_zone("},{"line_number":216,"context_line":"                    context,"},{"line_number":217,"context_line":"                    {\u0027name\u0027: name, \u0027type\u0027: constants.ZONE_CATALOG}"},{"line_number":218,"context_line":"                )"}],"source_content_type":"text/x-python","patch_set":3,"id":"4901d6f8_afd78b37","line":215,"range":{"start_line":215,"start_character":16,"end_line":215,"end_character":46},"in_reply_to":"e97d9ae8_1e64ee48","updated":"2026-09-24 10:20:01.000000000","message":"Yeah ok, I think we can close it. If anyone\u0027s interested in discussing about it in the future, we could always do it in the bug or open a new LP","commit_id":"ab3d9e64cd23c4c678500341d0e3d8d8b9853afd"}]}
