)]}'
{"id":"openstack%2Fglance-tempest-plugin~779059","triplet_id":"openstack%2Fglance-tempest-plugin~master~I98bdae73e752ba3641689cfc81d52e6d5d2674ee","project":"openstack/glance-tempest-plugin","branch":"master","topic":"secure-rbac","hashtags":[],"change_id":"I98bdae73e752ba3641689cfc81d52e6d5d2674ee","subject":"Reuse project credentials from tempest for tenancy checks","status":"ABANDONED","created":"2021-03-05 22:32:51.000000000","updated":"2025-04-14 14:06:51.000000000","total_comment_count":6,"unresolved_comment_count":3,"has_review_started":true,"meta_rev_id":"e8604e2a8840eddd9d711065f8d11c779b299e6e","_number":779059,"virtual_id_number":779059,"owner":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2021-03-05 23:52:54.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Gate Blocker Fix / Urgent Change"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"}],"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-03-05 23:01:01.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-03-09 23:32:05.000000000","updated_by":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"reviewer":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"state":"CC"}],"messages":[{"id":"bddae769d73f36be08930fa07a1efd60428ca325","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-03-05 22:32:51.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"53a77c81dfd3469284a4f5cc1da0e8f3a0b7289b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-03-05 22:38:05.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"428e437679065844e3788862a4b7af590b6c50fc","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-05 23:01:01.000000000","message":"Patch Set 2: Verified-1\n\n(2 comments)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/4e17eeea8e854e49a108da1d154cdc4c : FAILURE in 4m 23s\n- glance-secure-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/fe1dc531a496427898a59fd0ed1e3ebc : FAILURE in 13m 06s (non-voting)\n- glance-legacy-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/34135dd9b4b4449487889da62ab88167 : FAILURE in 16m 23s","accounts_in_message":[],"_revision_number":2},{"id":"20e71cf9a3c7ea21579c55b23e70fe4353516394","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-03-05 23:04:20.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"ba6dba1caa1e7d8d37b1da4729629b4756eaf40b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-05 23:52:54.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/04afd9bb172e4603aef0c86580b57146 : SUCCESS in 4m 20s\n- glance-secure-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/0c6caa33b92649bbb32d886d9cd5d767 : FAILURE in 41m 24s (non-voting)\n- glance-legacy-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/20e12ee07e3147519f4a854ff6bf0f4a : SUCCESS in 42m 13s","accounts_in_message":[],"_revision_number":3},{"id":"2f21f1a416059c7f929adea9773bc7d51d4d1c7e","author":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"date":"2021-03-09 23:32:05.000000000","message":"Patch Set 3:\n\n(2 comments)\n\nSeems like a good plan, I just have a question about some of the client-\u003emember stuff which doesn\u0027t seem quite right.","accounts_in_message":[],"_revision_number":3},{"id":"543d834cc050eefa201a488342c59f08ccab0945","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-03-10 02:14:31.000000000","message":"Patch Set 3:\n\n(2 comments)\n\nYeah - I\u0027m struggling with finding a way to name these clients in a way that doesn\u0027t muddy the water of complex authorization tests.","accounts_in_message":[],"_revision_number":3},{"id":"2e2020051ef5d0324de02c527387d193a9c06b2b","author":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"date":"2021-03-10 02:21:23.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"6b442a5cde1350445c4fd55886210476e68e5a59","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-03-10 16:34:35.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"e8604e2a8840eddd9d711065f8d11c779b299e6e","tag":"autogenerated:gerrit:abandon","author":{"_account_id":8122,"name":"Cyril Roelandt","email":"cyril@redhat.com","username":"cyril.roelandt.enovance"},"date":"2025-04-14 14:06:51.000000000","message":"Abandoned\n\nDuring PTG, we decided we could abandon this: \"We can drop patch as we already test  with os_project_alt_member\"","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"609c963e90c943dedc0f20348de82c6e37eb0c5c","revisions":{"535fa6d7dfb2bb32fc91f8a1e29c5b171b6aa61c":{"kind":"REWORK","_number":1,"created":"2021-03-05 22:32:51.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/59/779059/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-tempest-plugin","ref":"refs/changes/59/779059/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/1"}}},"commit":{"parents":[{"commit":"aec88f1ff59b90ee8fb3fc38cf1ea492934a209a","subject":"Add tests for image membership, deactivation, and reactivation","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/aec88f1ff59b90ee8fb3fc38cf1ea492934a209a"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-03-05 22:27:21.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-03-05 22:27:21.000000000","tz":0},"subject":"Reuse project credentials from tempest for tenancy checks","message":"Reuse project credentials from tempest for tenancy checks\n\nPreviously, we used a utility method to setup a new user with\nauthorization on a separate project. This is useful for testing tenancy\nand that regular users can\u0027t fish information or resources out ot\nprojects they don\u0027t have any authorization on.\n\nA recent change in tempest added another set of users that are hooked\ninto dynamic credentials, specifically for the purpose of checking\ntenancy [0].\n\nThis commit replaces some of the home-grown user setup with user\ncredentials available to us from tempest. This helps reduce\ninconsistencies in the tests and should help make things more readable\nin the long term as it becomes a more widely adopted convention.\n\n[0] https://review.opendev.org/c/openstack/tempest/+/773177\n\nChange-Id: I98bdae73e752ba3641689cfc81d52e6d5d2674ee\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/535fa6d7dfb2bb32fc91f8a1e29c5b171b6aa61c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/535fa6d7dfb2bb32fc91f8a1e29c5b171b6aa61c"}]},"branch":"refs/heads/master"},"6dc9fe18206d99864fcf78803d1ea3853db69b8b":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2021-03-05 22:38:05.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/59/779059/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-tempest-plugin","ref":"refs/changes/59/779059/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/2"}}},"commit":{"parents":[{"commit":"aec88f1ff59b90ee8fb3fc38cf1ea492934a209a","subject":"Add tests for image membership, deactivation, and reactivation","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/aec88f1ff59b90ee8fb3fc38cf1ea492934a209a"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-03-05 22:27:21.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-03-05 22:35:36.000000000","tz":0},"subject":"Reuse project credentials from tempest for tenancy checks","message":"Reuse project credentials from tempest for tenancy checks\n\nPreviously, we used a utility method to setup a new user with\nauthorization on a separate project. This is useful for testing tenancy\nand that regular users can\u0027t fish information or resources out of\nprojects they don\u0027t have any authorization on.\n\nA recent change in tempest added another set of users that are hooked\ninto dynamic credentials, specifically for the purpose of checking\ntenancy [0].\n\nThis commit replaces some of the home-grown user setup with user\ncredentials available to us from tempest. This helps reduce\ninconsistencies in the tests and should help make things more readable\nin the long term as it becomes a more widely adopted convention.\n\n[0] https://review.opendev.org/c/openstack/tempest/+/773177\n\nChange-Id: I98bdae73e752ba3641689cfc81d52e6d5d2674ee\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/6dc9fe18206d99864fcf78803d1ea3853db69b8b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/6dc9fe18206d99864fcf78803d1ea3853db69b8b"}]},"branch":"refs/heads/master"},"609c963e90c943dedc0f20348de82c6e37eb0c5c":{"kind":"REWORK","_number":3,"created":"2021-03-05 23:04:20.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/59/779059/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-tempest-plugin","ref":"refs/changes/59/779059/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-tempest-plugin refs/changes/59/779059/3"}}},"commit":{"parents":[{"commit":"aec88f1ff59b90ee8fb3fc38cf1ea492934a209a","subject":"Add tests for image membership, deactivation, and reactivation","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/aec88f1ff59b90ee8fb3fc38cf1ea492934a209a"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-03-05 22:27:21.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2021-03-05 23:02:13.000000000","tz":0},"subject":"Reuse project credentials from tempest for tenancy checks","message":"Reuse project credentials from tempest for tenancy checks\n\nPreviously, we used a utility method to setup a new user with\nauthorization on a separate project. This is useful for testing tenancy\nand that regular users can\u0027t fish information or resources out of\nprojects they don\u0027t have any authorization on.\n\nA recent change in tempest added another set of users that are hooked\ninto dynamic credentials, specifically for the purpose of checking\ntenancy [0].\n\nThis commit replaces some of the home-grown user setup with user\ncredentials available to us from tempest. This helps reduce\ninconsistencies in the tests and should help make things more readable\nin the long term as it becomes a more widely adopted convention.\n\n[0] https://review.opendev.org/c/openstack/tempest/+/773177\n\nChange-Id: I98bdae73e752ba3641689cfc81d52e6d5d2674ee\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/609c963e90c943dedc0f20348de82c6e37eb0c5c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-tempest-plugin/commit/609c963e90c943dedc0f20348de82c6e37eb0c5c"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Review-Priority","description":"Review priority","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"-label:Review-Priority\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":[],"failing_atoms":["label:Review-Priority\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
