)]}'
{"id":"openstack%2Fglance~981823","triplet_id":"openstack%2Fglance~master~I72db3ddc82fc7c6942363e2c7fb31f1660b3bda7","project":"openstack/glance","branch":"master","topic":"upstream-fix-set-acls-master","attention_set":{"32624":{"account":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"last_update":"2026-04-09 16:27:25.000000000","reason":"A robot voted negatively on a label"}},"removed_from_attention_set":{"37800":{"account":{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},"last_update":"2026-04-15 07:56:16.000000000","reason":"\u003cGERRIT_ACCOUNT_37800\u003e replied on the change","reason_account":{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"}}},"hashtags":[],"change_id":"I72db3ddc82fc7c6942363e2c7fb31f1660b3bda7","subject":"Fix set_acls when store metadata is missing","status":"NEW","created":"2026-03-23 18:40:21.000000000","updated":"2026-04-15 07:56:16.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":false,"submittable":false,"total_comment_count":3,"unresolved_comment_count":1,"has_review_started":true,"meta_rev_id":"b419668641f94aeac51089ea5351ce69a202c77b","_number":981823,"virtual_id_number":981823,"owner":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},{"tag":"autogenerated:zuul:check","value":-1,"date":"2026-04-14 21:56:50.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Top Priority / Holds Gate"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},{"_account_id":8122,"name":"Cyril Roelandt","email":"cyril@redhat.com","username":"cyril.roelandt.enovance"},{"_account_id":9303,"name":"Abhishek Kekane","email":"akekane@redhat.com","username":"abhishekkekane"}],"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-03-23 18:52:28.000000000","updated_by":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"reviewer":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"state":"CC"},{"updated":"2026-03-23 20:27:37.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2026-03-23 20:46:40.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-03-25 15:35:34.000000000","updated_by":{"_account_id":9303,"name":"Abhishek Kekane","email":"akekane@redhat.com","username":"abhishekkekane"},"reviewer":{"_account_id":9303,"name":"Abhishek Kekane","email":"akekane@redhat.com","username":"abhishekkekane"},"state":"CC"},{"updated":"2026-04-09 14:14:18.000000000","updated_by":{"_account_id":8122,"name":"Cyril Roelandt","email":"cyril@redhat.com","username":"cyril.roelandt.enovance"},"reviewer":{"_account_id":8122,"name":"Cyril Roelandt","email":"cyril@redhat.com","username":"cyril.roelandt.enovance"},"state":"CC"},{"updated":"2026-04-14 19:24:02.000000000","updated_by":{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},"reviewer":{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},"state":"REVIEWER"}],"messages":[{"id":"9ab9daa782ebd008b3ebda9144fcf63937c34be9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"date":"2026-03-23 18:40:21.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"05fb543d4746e0ef36fbd5379f6201ddbabfe719","author":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"date":"2026-03-23 18:43:19.000000000","message":"Patch Set 1:\n\nLogs showing the issue:\n\nDEBUG glance.location Store None is not available on this node, skipping _set_acls call.\n\nFull logs: https://paste.openstack.org/show/bio3nRxx7Ai4E6Gs8iv7/\n\nThis fix adds a fallback to derive the store from the URI when the store metadata is missing, ensuring Swift container ACLs are properly set when images are shared.","accounts_in_message":[],"_revision_number":1},{"id":"49f0eff4ead8c70d808b835e1452d41e3c933f0a","author":{"_account_id":4393,"name":"Dan Smith","email":"dms@danplanet.com","username":"danms"},"date":"2026-03-23 18:52:28.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"765e298a0d5e6b82a9244f75c61205467cae5d9a","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-03-23 20:27:37.000000000","message":"Patch Set 1:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/387116c657734fedb7024d4e1bf944be\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/aae256d669d640a698da8a05b3c876bc : SUCCESS in 5m 46s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/ec186329f2044e8f95fab994b4418a0d : SUCCESS in 6m 25s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/5e4d0e84f8af4e898404367418b14b05 : SUCCESS in 13m 08s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"b9a079b4b26f941cf77423bf04ad382e3e42ea8a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-03-23 20:46:40.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/d0321c657fa646caa7422de23aa372b5\n\n- grenade https://zuul.opendev.org/t/openstack/build/d5c0dc6112a8411b9625f9bd2477f1f2 : SUCCESS in 48m 44s\n- grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/f4d3525a75184d6e897cef75b8f4ca24 : SUCCESS in 1h 00m 23s\n- tempest-integrated-storage https://zuul.opendev.org/t/openstack/build/40ab882882e64f48acc947c1d79ae5ea : SUCCESS in 1h 46m 03s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/2e6a61f21887409db60c7032f313ee84 : SUCCESS in 59m 58s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5f921c8cb84f48fea03ee91bd4dab889 : SUCCESS in 3m 53s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/60ab7d56214a4973a7184cb0a6f4c0c5 : SUCCESS in 4m 50s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/5b152edce3224ca4a2bc08c57875afa8 : SUCCESS in 5m 28s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/8926aa60411941098db03dc86508dcde : SUCCESS in 7m 20s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/3123492ca8534037adb36cae462a5047 : SUCCESS in 5m 40s\n- openstack-tox-functional-py310 https://zuul.opendev.org/t/openstack/build/7be50195ac364f198a53822ea26a1eae : SUCCESS in 7m 34s\n- openstack-tox-functional-py313 https://zuul.opendev.org/t/openstack/build/29381fc472bf4d6289773977391212f3 : SUCCESS in 6m 36s\n- glance-ceph-thin-provisioning https://zuul.opendev.org/t/openstack/build/f8be171763fa441f8759ab28ab05733b : SUCCESS in 1h 50m 01s (non-voting)\n- tempest-integrated-storage-enforce-scope-new-defaults https://zuul.opendev.org/t/openstack/build/0c41b8ab8dfe47fb84693f93491347f1 : SUCCESS in 1h 54m 05s\n- tempest-integrated-storage-import https://zuul.opendev.org/t/openstack/build/ed850e8e605642ffad9143db088c2d5c : SUCCESS in 2h 04m 28s\n- glance-multistore-cinder-import https://zuul.opendev.org/t/openstack/build/16d94bb773904f0b959a9f76a04628c9 : FAILURE in 17m 18s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/ad8cfae5361b4cc4ad9656e56b4f0e2a : SUCCESS in 44m 23s\n- nova-ceph-multistore https://zuul.opendev.org/t/openstack/build/4056463296314d3199f848ab32e32878 : SUCCESS in 2h 01m 23s\n- glance-grenade-centralized-cache https://zuul.opendev.org/t/openstack/build/3c6c80f694a64b1bb2beb4e3d4641c23 : FAILURE in 8m 37s (non-voting)\n- glance-s3-multistore https://zuul.opendev.org/t/openstack/build/6e66eae4ad304daa8706519cb08c2798 : SUCCESS in 1h 59m 11s (non-voting)\n- glance-secure-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/17c3ab4150384379830ae625167645de : SUCCESS in 33m 36s","accounts_in_message":[],"_revision_number":1},{"id":"6fe526a80b2db7cc3c96348d4a0310e8f4ff7a2c","author":{"_account_id":9303,"name":"Abhishek Kekane","email":"akekane@redhat.com","username":"abhishekkekane"},"date":"2026-03-25 15:35:34.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"151d2753309f4596c4af2494a030f380b58e6455","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"date":"2026-03-26 03:55:46.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1\n","accounts_in_message":[],"_revision_number":2},{"id":"f0163d64989bc7bae3205d303c969e3dd520d29a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"date":"2026-03-26 04:10:37.000000000","message":"Uploaded patch set 3: Commit message was updated.","accounts_in_message":[],"_revision_number":3},{"id":"024d7c0bf6c0852acb57a748653a4c044aecb265","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-03-26 06:37:21.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/c54ab62b59e2443ea4fd443f4041027a\n\n- grenade https://zuul.opendev.org/t/openstack/build/83287fa14e204636bd6787aee2768ecc : SUCCESS in 50m 10s\n- grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/d65b7d3b189841688b911d31fc60988e : SUCCESS in 59m 14s\n- tempest-integrated-storage https://zuul.opendev.org/t/openstack/build/dcf1771ef0f34e9b855dcfdd49e5c040 : SUCCESS in 1h 20m 04s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/0edf201517f34a36a3f377a00b1edb7d : SUCCESS in 45m 39s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/c4f9362cb358454593eb8ad9b75c417d : SUCCESS in 4m 24s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/69c25e230fcf4db4b78615ebed614960 : FAILURE in 5m 58s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/853c6edcb29b462bbb47a0fc5abbdd78 : FAILURE in 2m 42s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/b81c23b572924a32a82dc9767e6d801d : FAILURE in 4m 11s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/93e3658597844fac9d38bd2970b7e9f9 : SUCCESS in 3m 52s\n- openstack-tox-functional-py310 https://zuul.opendev.org/t/openstack/build/3e07b43581294887a84cd92af513251d : SUCCESS in 6m 20s\n- openstack-tox-functional-py313 https://zuul.opendev.org/t/openstack/build/266874a5180043a3a9e1a0cc973a4b12 : SUCCESS in 6m 55s\n- glance-ceph-thin-provisioning https://zuul.opendev.org/t/openstack/build/2523f045a84d40cc9bde9c9ece490a29 : FAILURE in 14m 43s (non-voting)\n- tempest-integrated-storage-enforce-scope-new-defaults https://zuul.opendev.org/t/openstack/build/818ec6d618f24627a203a785e933b85c : SUCCESS in 1h 23m 27s\n- tempest-integrated-storage-import https://zuul.opendev.org/t/openstack/build/de424e8537d9495291230efe03a75b8a : SUCCESS in 1h 14m 19s\n- glance-multistore-cinder-import https://zuul.opendev.org/t/openstack/build/dc751f5239614dc48d1bed517bee7de8 : SUCCESS in 1h 17m 21s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/2a31bbaadcb746c8bf64b307a61071bd : SUCCESS in 44m 54s\n- nova-ceph-multistore https://zuul.opendev.org/t/openstack/build/2bc98f35982e4cb39e744deea57672f9 : SUCCESS in 2h 19m 52s\n- glance-grenade-centralized-cache https://zuul.opendev.org/t/openstack/build/0a7c14f7e26445b8b8eb7bda42bc492a : FAILURE in 14m 35s (non-voting)\n- glance-s3-multistore https://zuul.opendev.org/t/openstack/build/ba5d1d47ddeb418fa10d99b072735748 : SUCCESS in 1h 04m 14s (non-voting)\n- glance-secure-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/4e50beb2ece14e5f85a9a9d2857d92b5 : SUCCESS in 19m 02s","accounts_in_message":[],"_revision_number":3},{"id":"0aa5612813850e58ec92960e3fa471ea14362456","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"date":"2026-03-26 07:56:39.000000000","message":"Uploaded patch set 4.\n\nOutdated Votes:\n* Verified-1\n","accounts_in_message":[],"_revision_number":4},{"id":"7e268ad7ce54b7d7f3cd071be22857491d9237d5","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-03-26 09:45:10.000000000","message":"Patch Set 4:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/30c838036a8c428084dac5d72cb9be5f\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/7465aa7dbe2f477e9aaa5f576b10a919 : FAILURE in 6m 48s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/7a4b831be85c42feba258ccfd36e3ad4 : FAILURE in 7m 59s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/c59b440a981a4e5d817c1690b7aebf66 : FAILURE in 12m 38s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"217823500dbbadb310f673f23df46b70361b307a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-03-26 10:30:22.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/028bc997b1324679a6a2fc09da66c307\n\n- grenade https://zuul.opendev.org/t/openstack/build/46fa873a5ff24a60a0be749177e4c0a1 : SUCCESS in 34m 36s\n- grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/58d5d2d31c5046b8843f0ef398360820 : SUCCESS in 32m 32s\n- tempest-integrated-storage https://zuul.opendev.org/t/openstack/build/b260c6901ba146228f16fba2a6456c97 : SUCCESS in 1h 28m 02s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/11319a23801847bb8794b916b738fede : SUCCESS in 48m 14s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/10ee43e1e41f4654a2781df131631ca2 : SUCCESS in 4m 41s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/882a393ebbcc4b24baab30455f8ffee6 : FAILURE in 3m 10s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/a7d067739173406784c48db28b2ca408 : FAILURE in 4m 03s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/ab4ac296c07543499502a9420af270ad : FAILURE in 4m 45s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/5a73c10c109443b48a9c11dfca2e717f : SUCCESS in 5m 57s\n- openstack-tox-functional-py310 https://zuul.opendev.org/t/openstack/build/b5dc7963724c45559a96b31a7dfeab99 : SUCCESS in 4m 25s\n- openstack-tox-functional-py313 https://zuul.opendev.org/t/openstack/build/e9db2ba47d6e4a51bddb713948437e94 : SUCCESS in 6m 35s\n- glance-ceph-thin-provisioning https://zuul.opendev.org/t/openstack/build/9c6dfc4001d14c5e883e9e55d7e35ec8 : SUCCESS in 1h 51m 06s (non-voting)\n- tempest-integrated-storage-enforce-scope-new-defaults https://zuul.opendev.org/t/openstack/build/0f844590161e4ad4aa18514ec8f30682 : SUCCESS in 2h 02m 08s\n- tempest-integrated-storage-import https://zuul.opendev.org/t/openstack/build/a56e55d5bf094ca69069ac07a44c347b : SUCCESS in 1h 09m 39s\n- glance-multistore-cinder-import https://zuul.opendev.org/t/openstack/build/23047b7065a042a5b0b058117e3b7837 : SUCCESS in 2h 28m 12s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/d6b7e3c5a6f34da8a880ec858437a5dd : SUCCESS in 1h 14m 51s\n- nova-ceph-multistore https://zuul.opendev.org/t/openstack/build/2bff7bd11b8e4299b18805b6ad2641f1 : SUCCESS in 1h 03m 10s\n- glance-grenade-centralized-cache https://zuul.opendev.org/t/openstack/build/0a43af1373624f1188fb4a27116529cf : FAILURE in 7m 15s (non-voting)\n- glance-s3-multistore https://zuul.opendev.org/t/openstack/build/80f21b2e51c74893bdd0c65db0a049c6 : FAILURE in 55m 31s (non-voting)\n- glance-secure-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/68da61dec441469f86bf651553229883 : SUCCESS in 36m 47s","accounts_in_message":[],"_revision_number":4},{"id":"3310f55990be877b7ee11d5e7b24d3e91b2822a9","author":{"_account_id":8122,"name":"Cyril Roelandt","email":"cyril@redhat.com","username":"cyril.roelandt.enovance"},"date":"2026-04-09 14:14:18.000000000","message":"Patch Set 4:\n\nrecheck","accounts_in_message":[],"_revision_number":4},{"id":"41bdfe37885ba5c49b9938fd74c6b89228749d47","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-09 16:17:39.000000000","message":"Patch Set 4:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/fd706bedeb974eeb8dc72adb7a40aa38\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/a02b447a7f38419ca59d9b79aa09d006 : FAILURE in 5m 51s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/1230594271774a28a1e073d91da5a5c4 : FAILURE in 6m 44s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/0129bfa97637425fa35a1d78467163d2 : FAILURE in 10m 03s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"b7820b686befe43bffbb6715f8c1c519e23ece0e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-09 16:27:25.000000000","message":"Patch Set 4:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/d73b9128e12640d4a893e88e66f54be0\n\n- grenade https://zuul.opendev.org/t/openstack/build/6000a15119ba47848e32559d71e5bd38 : SUCCESS in 1h 04m 29s\n- grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/b4fef4f0010949e6b8b31c6fe7219345 : SUCCESS in 1h 08m 23s\n- tempest-integrated-storage https://zuul.opendev.org/t/openstack/build/ecd23f62dce543aab16d9d3a4b04afe2 : SUCCESS in 1h 53m 33s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/782d222547c34b14946362ce9d9d722c : SUCCESS in 1h 06m 42s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/c11b829fa74b400ab90cf2e1e48133fd : SUCCESS in 3m 42s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/937014def19144a893da8da35f6e030b : FAILURE in 5m 05s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/339619b952f34d50a0dc92bf33da2b45 : FAILURE in 4m 46s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/0ab6c5f64cbb4f87b53c0c99aeb77ddd : FAILURE in 10m 14s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a36e8de865c74da9810689c540b55e08 : SUCCESS in 6m 00s\n- openstack-tox-functional-py310 https://zuul.opendev.org/t/openstack/build/fa5a9a31cdcc4c549478c69b5cd889b6 : SUCCESS in 8m 48s\n- openstack-tox-functional-py313 https://zuul.opendev.org/t/openstack/build/87ce58a9d2794a80926e17cc4276f0c1 : SUCCESS in 6m 37s\n- glance-ceph-thin-provisioning https://zuul.opendev.org/t/openstack/build/e81a0d436ee54741a2ad8dcadd8b5c08 : SUCCESS in 1h 00m 11s (non-voting)\n- tempest-integrated-storage-enforce-scope-new-defaults https://zuul.opendev.org/t/openstack/build/8cd32dc3529f43658ca1911ece4b9d89 : SUCCESS in 2h 07m 07s\n- tempest-integrated-storage-import https://zuul.opendev.org/t/openstack/build/84737d99a5ee461ab048f23989b85d15 : FAILURE in 1h 50m 27s\n- glance-multistore-cinder-import https://zuul.opendev.org/t/openstack/build/da58e57420ab4d8f8bd04950b226cb36 : SUCCESS in 1h 54m 38s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/29340d74d1c2403197d2aff4e271e596 : SUCCESS in 55m 16s\n- nova-ceph-multistore https://zuul.opendev.org/t/openstack/build/f392f7c3154e4928878c1567e4394a75 : SUCCESS in 1h 49m 38s\n- glance-grenade-centralized-cache https://zuul.opendev.org/t/openstack/build/0c121998b63b447eabc5d5d4da693208 : FAILURE in 8m 46s (non-voting)\n- glance-s3-multistore https://zuul.opendev.org/t/openstack/build/6f1c1b98b14c49ac8c16592e264c6b1a : SUCCESS in 2h 02m 42s (non-voting)\n- glance-secure-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/9427cbe0b3244b7496775f4206b728cd : SUCCESS in 35m 15s","accounts_in_message":[],"_revision_number":4},{"id":"7dbe6248b394a6a7d135a55a1ed2b3b3407005f1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},"date":"2026-04-14 19:24:02.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"88d2f8454f330117c5c0ef5ce793cc05805b87db","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-14 21:56:50.000000000","message":"Patch Set 5: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/1ba642ac949c4904b28bffa69e0f9bbb\n\n- grenade https://zuul.opendev.org/t/openstack/build/cba20b74c24a4e708c36503b06a81ebf : SUCCESS in 30m 05s\n- grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/3781b8151f604e82a86e7b0197556d58 : SUCCESS in 53m 47s\n- tempest-integrated-storage https://zuul.opendev.org/t/openstack/build/7e24d1e637784df8a78d43bf165e4014 : SUCCESS in 1h 18m 53s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/f31e2f6c6dc7425fbe8acf0c7a167221 : SUCCESS in 32m 56s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/bbd349f6ba924128b1e898047592fff4 : SUCCESS in 2m 40s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/8dc8fdbd304e41edb3484509d3ef0b14 : FAILURE in 4m 42s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/d27ea58295c242c2b997babd46896d77 : FAILURE in 5m 54s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/7cb8102929964a59ac30da3eece393ae : FAILURE in 4m 57s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4a7db15322f0449cbb77da8e370e4fca : SUCCESS in 5m 39s\n- openstack-tox-functional-py310 https://zuul.opendev.org/t/openstack/build/7a797d942ad04e6ab68c57bd9b4d4abf : FAILURE in 4m 37s\n- openstack-tox-functional-py313 https://zuul.opendev.org/t/openstack/build/0afd02c8d7844a66b97681aac1d02172 : FAILURE in 5m 09s\n- glance-ceph-thin-provisioning https://zuul.opendev.org/t/openstack/build/f039cc0b292f4bc4bd08d692305502f2 : SUCCESS in 1h 09m 35s (non-voting)\n- tempest-integrated-storage-enforce-scope-new-defaults https://zuul.opendev.org/t/openstack/build/f585d9a7d2b54e618fee97e25cfadf2f : SUCCESS in 1h 03m 23s\n- tempest-integrated-storage-import https://zuul.opendev.org/t/openstack/build/b13c87bfa5604bc688ec18b6e7153a66 : SUCCESS in 1h 18m 39s\n- glance-multistore-cinder-import https://zuul.opendev.org/t/openstack/build/ae7393c379dc4574b42b2c79d20f630c : SUCCESS in 2h 27m 16s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/d50693a59ec848c9a36225aa676694e8 : SUCCESS in 28m 55s\n- nova-ceph-multistore https://zuul.opendev.org/t/openstack/build/f73c9cedd77d43b0b71cc63c497d7373 : FAILURE in 2h 19m 30s\n- glance-grenade-centralized-cache https://zuul.opendev.org/t/openstack/build/4e781ddea0b3462e85845b7527eabbd9 : FAILURE in 15m 22s (non-voting)\n- glance-s3-multistore https://zuul.opendev.org/t/openstack/build/5fd0cc4fc7ce416ca3bd6c2d8b875d36 : FAILURE in 1h 00m 01s (non-voting)\n- glance-secure-rbac-protection-functional https://zuul.opendev.org/t/openstack/build/41e0d8437b3f476a9ffaccce7aed0ce1 : SUCCESS in 19m 18s","accounts_in_message":[],"_revision_number":5},{"id":"66de8244d9eaedf810224754c29bd264ec6466d1","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-15 01:21:53.000000000","message":"Patch Set 5:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/611bb22cec9d4c55bda256bf08fb6223\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/171c318327974a478a2e554af71bb0ad : FAILURE in 5m 35s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/aad47f2a436847878754c8256b6b2f99 : FAILURE in 5m 25s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/8466cab3e24d4d3f8a0dc27a97fd2257 : FAILURE in 8m 37s (non-voting)","accounts_in_message":[],"_revision_number":5},{"id":"b419668641f94aeac51089ea5351ce69a202c77b","author":{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},"date":"2026-04-15 07:56:16.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5}],"current_revision_number":5,"current_revision":"410cb5c01fddbef8e2883178408135dbbe1d4fd5","revisions":{"fc4b7a12180aefdc047c9810756d0419bdc0026d":{"kind":"REWORK","_number":1,"created":"2026-03-23 18:40:21.000000000","uploader":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"ref":"refs/changes/23/981823/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance","ref":"refs/changes/23/981823/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance refs/changes/23/981823/1"}}},"commit":{"parents":[{"commit":"8c43caaefd8820e3e45b3c95b60bc6e1c668c55b","subject":"Fix SSRF vulnerabilities in image import API","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/8c43caaefd8820e3e45b3c95b60bc6e1c668c55b"}]}],"author":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-23 17:04:13.000000000","tz":330},"committer":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-23 18:26:58.000000000","tz":330},"subject":"Fix set_acls when store metadata is missing","message":"Fix set_acls when store metadata is missing\n\nWhen multi-store is enabled, the _set_acls() methods in ImageRepoProxy\nand ImageMemberRepoProxy require the \u0027store\u0027 key in location metadata.\nHowever, for images created before multi-store was enabled, or images\nthat haven\u0027t been retrieved via get() since multi-store was enabled,\nthis metadata may be missing (None).\n\nThis causes the ACL setting to be silently skipped with the log message:\n\u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\nThis issue was introduced in commit 2cf5df86a (\u0027Move lazy store update\nto locations layer\u0027) which moved the update_store_in_locations() call\nto the get() method, but did not add a fallback in _set_acls() for\ncases where the store metadata is missing.\n\nThis fix adds a fallback to derive the store identifier from the\nlocation URI using _get_store_id_from_uri() when the metadata is\nmissing, ensuring that Swift container ACLs are properly set when\nimages are shared.\n\nReproducer:\n1. Enable multi-store: enabled_backends \u003d swift:swift\n2. Have an image created bef2. Have an image created bef2. Have an image created bef2. Have an iloc2. Have an image created bef2. Have an image created bef2. Have an proj2. Have an image created bef2. Have an image created bef2. Have anode,2. Have an image created bef2. Have an image created bef2. Have a the image data from Swift\n\nChange-Id: I72db3ddc82fc7c6942363e2c7fb31f1660b3bda7\nSigned-off-by: rajivmucheli \u003crajiv.mucheli@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/fc4b7a12180aefdc047c9810756d0419bdc0026d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/fc4b7a12180aefdc047c9810756d0419bdc0026d"}]},"branch":"refs/heads/master"},"5b04dba1589b6fb5a16644d077b557a79bcb45cc":{"kind":"REWORK","_number":2,"created":"2026-03-26 03:55:46.000000000","uploader":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"ref":"refs/changes/23/981823/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance","ref":"refs/changes/23/981823/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance refs/changes/23/981823/2"}}},"commit":{"parents":[{"commit":"8c43caaefd8820e3e45b3c95b60bc6e1c668c55b","subject":"Fix SSRF vulnerabilities in image import API","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/8c43caaefd8820e3e45b3c95b60bc6e1c668c55b"}]}],"author":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-23 17:04:13.000000000","tz":330},"committer":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-26 03:55:32.000000000","tz":330},"subject":"Fix set_acls when store metadata is missing","message":"Fix set_acls when store metadata is missing\n\nWhen multi-store is enabled, the _set_acls() methods in ImageRepoProxy\nand ImageMemberRepoProxy require the \u0027store\u0027 key in location metadata.\nHowever, for images created before multi-store was enabled, or images\nthat haven\u0027t been retrieved via get() since multi-store was enabled,\nthis metadata may be missing (None).\n\nThis causes the ACL setting to be silently skipped with the log message:\n\u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\nThis issue was introduced in commit 2cf5df86a (\u0027Move lazy store update\nto locations layer\u0027) which moved the update_store_in_locations() call\nto the get() method, but did not add a fallback in _set_acls() for\ncases where the store metadata is missing.\n\nThis fix adds a fallback to derive the store identifier from the\nlocation URI using _get_store_id_from_uri() when the metadata is\nmissing, ensuring that Swift container ACLs are properly set when\nimages are shared.\n\nReproducer:\n1. Enable multi-store: enabled_backends \u003d swift:swift\n2. Have an image created bef2. Have an image created bef2. Have an image created bef2. Have an iloc2. Have an image created bef2. Have an image created bef2. Have an proj2. Have an image created bef2. Have an image created bef2. Have anode,2. Have an image created bef2. Have an image created bef2. Have a the image data from Swift\n\nChange-Id: I72db3ddc82fc7c6942363e2c7fb31f1660b3bda7\nSigned-off-by: rajivmucheli \u003crajiv.mucheli@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/5b04dba1589b6fb5a16644d077b557a79bcb45cc"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/5b04dba1589b6fb5a16644d077b557a79bcb45cc"}]},"branch":"refs/heads/master"},"d897b510491ecafafc0836b060922f2871600405":{"kind":"NO_CODE_CHANGE","_number":3,"created":"2026-03-26 04:10:37.000000000","uploader":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"ref":"refs/changes/23/981823/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance","ref":"refs/changes/23/981823/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance refs/changes/23/981823/3"}}},"commit":{"parents":[{"commit":"8c43caaefd8820e3e45b3c95b60bc6e1c668c55b","subject":"Fix SSRF vulnerabilities in image import API","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/8c43caaefd8820e3e45b3c95b60bc6e1c668c55b"}]}],"author":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-23 17:04:13.000000000","tz":330},"committer":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-26 04:10:23.000000000","tz":330},"subject":"Fix set_acls when store metadata is missing","message":"Fix set_acls when store metadata is missing\n\nWhen multi-store is enabled, the _set_acls() methods in ImageRepoProxy\nand ImageMemberRepoProxy require the \u0027store\u0027 key in location metadata.\nHowever, for images created before multi-store was enabled, or images\nthat haven\u0027t been retrieved via get() since multi-store was enabled,\nthis metadata may be missing (None).\n\nThis causes the ACL setting to be silently skipped with the log message:\n\u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\nThis issue was introduced in commit 2cf5df86a (\u0027Move lazy store update\nto locations layer\u0027) which moved the update_store_in_locations() call\nto the get() method, but did not add a fallback in _set_acls() for\ncases where the store metadata is missing.\n\nThis fix adds:\n1. A fallback in _set_acls() to derive the store identifier from the\n   location URI using _get_store_id_from_uri() when metadata is missing.\n2. Enhanced _get_store_id_from_uri() to handle Swift multi-tenant stores\n   where url_prefix matching fails due to malformed url_prefix format.\n   The fix adds scheme-based fallback for single Swift store configs\n   and host-based matching for multiple Swift store configurations.\n3. Uses conf_endpoint (set during configure()) instead of storage_url\n   which may be None for MultiTenantStore until _get_endpoint() is called.\n\nReproducer:\n1. Enable multi-store in glance-api.conf:\n   [DEFAULT]\n   enabled_backends \u003d swift:swift\n\n   [swift]\n   swift_store_container \u003d glance\n   swift_store_create_container_on_put \u003d true\n   swift_store_multi_tenant \u003d true\n\n2. Have an image created before multi-store was enabled (legacy image\n   without \u0027stores\u0027 property in metadata)\n\n3. Share the image with another project:\n   openstack image add project \u003cimage-id\u003e \u003cproject-id\u003e\n\n4. Check logs for the error:\n   \u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\n5. Verify the member cannot access the image data from Swift due to\n   missing container ACLs\n\nAfter fix:\n- The store is derived from the location URI\n- Swift container ACLs are properly set\n- The member can access the shared image\n\nChange-Id: I72db3ddc82fc7c6942363e2c7fb31f1660b3bda7\nSigned-off-by: rajivmucheli \u003crajiv.mucheli@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/d897b510491ecafafc0836b060922f2871600405"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/d897b510491ecafafc0836b060922f2871600405"}]},"branch":"refs/heads/master"},"7279b40f1db5a558d9168c8ea76d1b077ec6ca9e":{"kind":"REWORK","_number":4,"created":"2026-03-26 07:56:39.000000000","uploader":{"_account_id":32624,"name":"Rajiv Mucheli","email":"rajiv.mucheli@gmail.com","username":"rajivmucheli"},"ref":"refs/changes/23/981823/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance","ref":"refs/changes/23/981823/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance refs/changes/23/981823/4"}}},"commit":{"parents":[{"commit":"8c43caaefd8820e3e45b3c95b60bc6e1c668c55b","subject":"Fix SSRF vulnerabilities in image import API","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/8c43caaefd8820e3e45b3c95b60bc6e1c668c55b"}]}],"author":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-23 17:04:13.000000000","tz":330},"committer":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-26 07:56:30.000000000","tz":330},"subject":"Fix set_acls when store metadata is missing","message":"Fix set_acls when store metadata is missing\n\nWhen multi-store is enabled, the _set_acls() methods in ImageRepoProxy\nand ImageMemberRepoProxy require the \u0027store\u0027 key in location metadata.\nHowever, for images created before multi-store was enabled, or images\nthat haven\u0027t been retrieved via get() since multi-store was enabled,\nthis metadata may be missing (None).\n\nThis causes the ACL setting to be silently skipped with the log message:\n\u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\nThis issue was introduced in commit 2cf5df86a (\u0027Move lazy store update\nto locations layer\u0027) which moved the update_store_in_locations() call\nto the get() method, but did not add a fallback in _set_acls() for\ncases where the store metadata is missing.\n\nThis fix adds:\n1. A fallback in _set_acls() to derive the store identifier from the\n   location URI using _get_store_id_from_uri() when metadata is missing.\n2. Enhanced _get_store_id_from_uri() to handle Swift multi-tenant stores\n   where url_prefix matching fails due to malformed url_prefix format.\n   The fix adds scheme-based fallback for single Swift store configs\n   and host-based matching for multiple Swift store configurations.\n3. Uses conf_endpoint (set during configure()) instead of storage_url\n   which may be None for MultiTenantStore until _get_endpoint() is called.\n\nReproducer:\n1. Enable multi-store in glance-api.conf:\n   [DEFAULT]\n   enabled_backends \u003d swift:swift\n\n   [swift]\n   swift_store_container \u003d glance\n   swift_store_create_container_on_put \u003d true\n   swift_store_multi_tenant \u003d true\n\n2. Have an image created before multi-store was enabled (legacy image\n   without \u0027stores\u0027 property in metadata)\n\n3. Share the image with another project:\n   openstack image add project \u003cimage-id\u003e \u003cproject-id\u003e\n\n4. Check logs for the error:\n   \u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\n5. Verify the member cannot access the image data from Swift due to\n   missing container ACLs\n\nAfter fix:\n- The store is derived from the location URI\n- Swift container ACLs are properly set\n- The member can access the shared image\n\nChange-Id: I72db3ddc82fc7c6942363e2c7fb31f1660b3bda7\nSigned-off-by: rajivmucheli \u003crajiv.mucheli@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/7279b40f1db5a558d9168c8ea76d1b077ec6ca9e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/7279b40f1db5a558d9168c8ea76d1b077ec6ca9e"}]},"branch":"refs/heads/master"},"410cb5c01fddbef8e2883178408135dbbe1d4fd5":{"kind":"REWORK","_number":5,"created":"2026-04-14 19:24:02.000000000","uploader":{"_account_id":37800,"name":"Sebastian Krott","display_name":"Sebastian Krott","email":"sebastian.krott@sap.com","username":"sebkro_sap"},"ref":"refs/changes/23/981823/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance","ref":"refs/changes/23/981823/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance refs/changes/23/981823/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance refs/changes/23/981823/5"}}},"commit":{"parents":[{"commit":"8c43caaefd8820e3e45b3c95b60bc6e1c668c55b","subject":"Fix SSRF vulnerabilities in image import API","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/8c43caaefd8820e3e45b3c95b60bc6e1c668c55b"}]}],"author":{"name":"rajivmucheli","email":"rajiv.mucheli@gmail.com","date":"2026-03-23 17:04:13.000000000","tz":330},"committer":{"name":"Sebastian Krott","email":"sebastian.krott@sap.com","date":"2026-04-14 19:24:00.000000000","tz":120},"subject":"Fix set_acls when store metadata is missing","message":"Fix set_acls when store metadata is missing\n\nWhen multi-store is enabled, the _set_acls() methods in ImageRepoProxy\nand ImageMemberRepoProxy require the \u0027store\u0027 key in location metadata.\nHowever, for images created before multi-store was enabled, or images\nthat haven\u0027t been retrieved via get() since multi-store was enabled,\nthis metadata may be missing (None).\n\nThis causes the ACL setting to be silently skipped with the log message:\n\u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\nThis issue was introduced in commit 2cf5df86a (\u0027Move lazy store update\nto locations layer\u0027) which moved the update_store_in_locations() call\nto the get() method, but did not add a fallback in _set_acls() for\ncases where the store metadata is missing.\n\nAdditionally, `_get_store_id_from_uri()` matched image location URIs to\nstores via `url_prefix`. For Swift multi-tenant stores, `url_prefix` may\nbe unavailable and does not include the URL\u0027s `container` segment.\n\nThis fix\n- adds a fallback in _set_acls() to derive the store identifier\n  from the location URI using _get_store_id_from_uri() when metadata is\n  missing.\n- adjusts `_get_store_id_from_uri` to use Glance Store\u0027s new\n  `matches_uri` function which implements custom matching for the Swift\n  multi-tenant stores and the current prefix matching for all other\n  stores. Since the matching for the Swift multi-tenant store is\n  best-effort and not precise, we do not break on the first match but\n  check all stores to ensure that exactly one store matches.\n\nReproducer:\n1. Enable multi-store in glance-api.conf:\n   [DEFAULT]\n   enabled_backends \u003d swift:swift\n\n   [swift]\n   swift_store_container \u003d glance\n   swift_store_create_container_on_put \u003d true\n   swift_store_multi_tenant \u003d true\n\n2. Have an image created before multi-store was enabled (legacy image\n   without \u0027stores\u0027 property in metadata)\n\n3. Share the image with another project:\n   openstack image add project \u003cimage-id\u003e \u003cproject-id\u003e\n\n4. Check logs for the error:\n   \u0027Store None is not available on this node, skipping _set_acls call.\u0027\n\n5. Verify the member cannot access the image data from Swift due to\n   missing container ACLs\n\nAfter fix:\n- The store is derived from the location URI\n- Swift container ACLs are properly set\n- The member can access the shared image\n\nChange-Id: I72db3ddc82fc7c6942363e2c7fb31f1660b3bda7\nRelated-Bug: #2148337\nDepends-On: https://review.opendev.org/c/openstack/glance_store/+/984614\nSigned-off-by: rajivmucheli \u003crajiv.mucheli@gmail.com\u003e\nSigned-off-by: Sebastian Krott \u003csebastian.krott@sap.com\u003e\nCo-authored-by: Sebastian Krott \u003csebastian.krott@sap.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/410cb5c01fddbef8e2883178408135dbbe1d4fd5"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance/commit/410cb5c01fddbef8e2883178408135dbbe1d4fd5"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"},{"label":"Review-Priority","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Review-Priority","description":"Review priority","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"-label:Review-Priority\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":[],"failing_atoms":["label:Review-Priority\u003dMIN"],"atom_explanations":{"label:Review-Priority\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
