)]}'
{"id":"openstack%2Fglance~958810","triplet_id":"openstack%2Fglance~master~I0ccc9742c4a1fb7cad05dbde2be92fae95e8c7e7","project":"openstack/glance","branch":"master","attention_set":{},"removed_from_attention_set":{"11604":{"account":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"last_update":"2025-08-28 20:23:36.000000000","reason":"Change was abandoned"}},"hashtags":[],"change_id":"I0ccc9742c4a1fb7cad05dbde2be92fae95e8c7e7","subject":"Fix glance service policy rule","status":"ABANDONED","created":"2025-08-28 20:21:26.000000000","updated":"2025-08-28 20:23:36.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"628d06f6312c7aed91ec7b858ca8becba996784a","_number":958810,"virtual_id_number":958810,"owner":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"actions":{},"labels":{"Verified":{"all":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Top Priority / Holds Gate"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2025-08-28 20:21:26.000000000","updated_by":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"reviewer":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"state":"REVIEWER"}],"messages":[{"id":"6398465d1b9c00ad6df9617a98db668eadd0d4cb","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"date":"2025-08-28 20:21:26.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"628d06f6312c7aed91ec7b858ca8becba996784a","tag":"autogenerated:gerrit:abandon","author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"date":"2025-08-28 20:23:36.000000000","message":"Abandoned\n\nhttps://review.opendev.org/c/openstack/glance/+/958715","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"bb893b35504b8edbfdcd01d90f6dfcf6ec8045ca","revisions":{"bb893b35504b8edbfdcd01d90f6dfcf6ec8045ca":{"kind":"REWORK","_number":1,"created":"2025-08-28 20:21:26.000000000","uploader":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"ref":"refs/changes/10/958810/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance","ref":"refs/changes/10/958810/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance refs/changes/10/958810/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance refs/changes/10/958810/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance refs/changes/10/958810/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance refs/changes/10/958810/1"}}},"commit":{"parents":[{"commit":"6c33a667a9f5ddce07b6131f4a5cb7460a4bdf17","subject":"Merge \"Replaced usage outdate egrep to grep\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/6c33a667a9f5ddce07b6131f4a5cb7460a4bdf17"}]}],"author":{"name":"Ghanshyam Maan","email":"gmaan@ghanshyammann.com","date":"2025-08-28 03:19:27.000000000","tz":0},"committer":{"name":"Ghanshyam Maan","email":"gmaan@ghanshyammann.com","date":"2025-08-28 20:16:31.000000000","tz":0},"subject":"Fix glance service policy rule","message":"Fix glance service policy rule\n\nGlance service APIs are default to \u0027service_roles: service\u0027\n\n- https://github.com/openstack/glance/blob/6c33a667a9f5ddce07b6131f4a5cb7460a4bdf17/glance/policies/base.py#L116\n\nThe issue here is the service token, which is sent from the\nservice for the user token expiry case but glance uses that\nservice token (keystonemiddleware sets the service token roles\nin Requestcontext in \u0027service_roles\u0027 field) for RBAC, which\nis not correct.\n\nThe OpenStack services communicate with each other by\npassing the user token and service token wrapped in\nkeystoneauth\u0027s ServiceTokenAuthWrapper. The only purpose\nof passing the service token is for long-running\noperations and in case the user token gets expired.\n\nFor RBAC, we need to check if a user token has the \u0027service\u0027\nrole or not. Service needs to load the configured user auth\nplugin (where the user should have the \u0027service\u0027 role) from\nkeystoneauth and pass that to the other services (for example,\ncinder change depends-on) and glance will use that user role\nto verify the policy permission. To fix that, we need to make\nthe service APIs default to ``role:service`` and not\n`service_role`:`service`.\n\nThis commit does one more change. Cinder does not have the\nway to configure the glance service user, we are adding the\nnew config in this release. For backward compatibility,\nwe need to allow admin access in service policy rule. In\nfuture release (after one SLURP release), we cna remove\nthe admin access.\n\nDepends-On: https://review.opendev.org/c/openstack/devstack/+/958718\nDepends-On: https://review.opendev.org/c/openstack/cinder/+/958716\n\nCloses-Bug: #2121622\n\nChange-Id: I50909e6bdb3227ca99b7eba642546da791f9552a\n\nCo-Authored-By: : Sean Mooney \u003cwork@seanmooney.info\u003e\nChange-Id: I0ccc9742c4a1fb7cad05dbde2be92fae95e8c7e7\nSigned-off-by: Sean Mooney \u003cwork@seanmooney.info\u003e\nSigned-off-by: Ghanshyam Maan \u003cgmaan@ghanshyammann.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/bb893b35504b8edbfdcd01d90f6dfcf6ec8045ca"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/bb893b35504b8edbfdcd01d90f6dfcf6ec8045ca"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{}}},{"name":"Review-Priority","description":"Review priority","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"-label:Review-Priority\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":[],"failing_atoms":["label:Review-Priority\u003dMIN"],"atom_explanations":{}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{}}}]}
