)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"2583cdd0e3ce2be755f03e3c14561643d135d4b1","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"f1ea9c79_cf2a6fb0","updated":"2026-05-06 17:23:23.000000000","message":"This may need to be re-worked in light of https://bugs.launchpad.net/ironic-python-agent/+bug/2148310/comments/10 This initial patch was written prior to that comment. Leaving up for now since it\u0027s a pretty small patch as it stands and should only take a few minutes for an initial review.","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"dda0bfabf96def05530c7a894e5e08643f42e6d0","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"bf74352c_86e21c84","in_reply_to":"abb4053a_2f3ff832","updated":"2026-05-07 11:57:20.000000000","message":"Yes, this (missed this comment)","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"478b54bc48f3e18d8555d53130e67eee7310878f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"533b5b15_c227d34f","in_reply_to":"bf74352c_86e21c84","updated":"2026-06-01 18:00:00.000000000","message":"Done","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"893b2d182754833ee8b4e50ff91045554753f4a1","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"abb4053a_2f3ff832","in_reply_to":"f1ea9c79_cf2a6fb0","updated":"2026-05-06 18:54:18.000000000","message":"This could work, but it does block out users who have an image with UEFI loader artifacts. In such a case, I\u0027d wire this in very close to the issue and not at the front end of prepare_image. In otherwords, in install_bootloader.","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"0e5faeb311fc6dcddf17d3c857634914bea08798","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"dd7d57e3_e48014b1","updated":"2026-05-20 17:33:47.000000000","message":"release note","commit_id":"0166df6a9036ada6add0d67f513eee92f38606dd"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"478b54bc48f3e18d8555d53130e67eee7310878f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"457bc0f7_df642c17","in_reply_to":"dd7d57e3_e48014b1","updated":"2026-06-01 18:00:00.000000000","message":"Acknowledged","commit_id":"0166df6a9036ada6add0d67f513eee92f38606dd"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"3595c74e7c38353f382038a9f0f382bd9c116f84","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"f591c884_0d26b6d0","updated":"2026-06-01 16:35:24.000000000","message":"I think I\u0027ve addressed everything brought up so far.","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"2bf73985307fe043dfe70ed75e1951268d5d77b8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"45a6c67b_5822e55b","updated":"2026-06-01 11:13:03.000000000","message":"Some comments + needs a release note.","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"abca80b16fdcfa8bbf1cf1066ba8d6c384c5f1df","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"86469ffd_7f82f38c","updated":"2026-06-01 17:18:24.000000000","message":"LGTM aside from indicated issue","commit_id":"72daa017efcc023269d22c82e1dc1f0a39032a0e"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"a6f2e0d5c9f41915cf83618635aeb5d36fc51d72","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":6,"id":"63dfb5de_f6a08042","updated":"2026-06-02 18:59:09.000000000","message":"recheck dep merged","commit_id":"6cd463a657edcddf7b79416ac69bdef5b6f30099"}],"ironic_python_agent/config.py":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"3ffae0059e98bacc8afd80ed9d904ca4ef55020c","unresolved":true,"context_lines":[{"line_number":439,"context_line":"                     \u0027because the bootc command inside of the ramdisk \u0027"},{"line_number":440,"context_line":"                     \u0027comes from the supplied image to be deployed.\u0027),"},{"line_number":441,"context_line":"    cfg.BoolOpt(\u0027enable_partition_images\u0027,"},{"line_number":442,"context_line":"                default\u003dFalse,"},{"line_number":443,"context_line":"                help\u003d\u0027Enables the \"partition\" image type. Disabled by default \u0027"},{"line_number":444,"context_line":"                     \u0027due to security risks.\u0027),"},{"line_number":445,"context_line":"]"}],"source_content_type":"text/x-python","patch_set":1,"id":"f84652cf_6d12b4b6","line":442,"updated":"2026-05-06 18:59:19.000000000","message":"Should we make this enablable via kernel command line or conductor? It seems like asking anyone using existing partition image support to build a custom IPA might be too heavy, but obviously there\u0027s added security risk to having it remotely toggled.","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"3595c74e7c38353f382038a9f0f382bd9c116f84","unresolved":false,"context_lines":[{"line_number":439,"context_line":"                     \u0027because the bootc command inside of the ramdisk \u0027"},{"line_number":440,"context_line":"                     \u0027comes from the supplied image to be deployed.\u0027),"},{"line_number":441,"context_line":"    cfg.BoolOpt(\u0027enable_partition_images\u0027,"},{"line_number":442,"context_line":"                default\u003dFalse,"},{"line_number":443,"context_line":"                help\u003d\u0027Enables the \"partition\" image type. Disabled by default \u0027"},{"line_number":444,"context_line":"                     \u0027due to security risks.\u0027),"},{"line_number":445,"context_line":"]"}],"source_content_type":"text/x-python","patch_set":1,"id":"ff50006b_be545d36","line":442,"in_reply_to":"f84652cf_6d12b4b6","updated":"2026-06-01 16:35:24.000000000","message":"This change plumbs it: https://review.opendev.org/c/openstack/ironic/+/990724","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"abca80b16fdcfa8bbf1cf1066ba8d6c384c5f1df","unresolved":true,"context_lines":[{"line_number":439,"context_line":"                     \u0027because the bootc command inside of the ramdisk \u0027"},{"line_number":440,"context_line":"                     \u0027comes from the supplied image to be deployed.\u0027),"},{"line_number":441,"context_line":"    cfg.BoolOpt(\u0027enable_bios_bootloader_install\u0027,"},{"line_number":442,"context_line":"                default\u003dFalse,"},{"line_number":443,"context_line":"                help\u003d\u0027Enables support for partition images which require a \u0027"},{"line_number":444,"context_line":"                     \u0027legacy bootloader -- and a call to ``grub-install``. \u0027"},{"line_number":445,"context_line":"                     \u0027Generally, this should remain disabled for maximum \u0027"}],"source_content_type":"text/x-python","patch_set":5,"id":"70b5e042_2e37b2dd","line":442,"updated":"2026-06-01 17:18:24.000000000","message":"I hate to be annoying; but we either have to land the Ironic side change first, or do a default-config-juggle to avoid a weird period of breakage.\n\nWe have two choices:\n\n(Option 1)\n- Add the conductor side config and code to wire it through first (older IPAs will ignore the added payload)\n- THEN merge this (so operators relying on this functionality and upgrading IPA/Ironic in lock-step will be able to flip the conductor config\n\n(Option 2)\n- Change this to default: True\n- Add the ironic-conductor change plumbing through the Ironic default (False, I assume)\n- Change this default to False in a later change\n\n\nEssentially, IMO, we want to avoid a case where someone using latest IPA + latest Ironic would have enable_bios_bootloader_install\u003dFalse with no Ironic-side way to workaround it.","commit_id":"72daa017efcc023269d22c82e1dc1f0a39032a0e"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"c90478b2987c4d91be93b2bb682c2404c4f1b137","unresolved":true,"context_lines":[{"line_number":439,"context_line":"                     \u0027because the bootc command inside of the ramdisk \u0027"},{"line_number":440,"context_line":"                     \u0027comes from the supplied image to be deployed.\u0027),"},{"line_number":441,"context_line":"    cfg.BoolOpt(\u0027enable_bios_bootloader_install\u0027,"},{"line_number":442,"context_line":"                default\u003dFalse,"},{"line_number":443,"context_line":"                help\u003d\u0027Enables support for partition images which require a \u0027"},{"line_number":444,"context_line":"                     \u0027legacy bootloader -- and a call to ``grub-install``. \u0027"},{"line_number":445,"context_line":"                     \u0027Generally, this should remain disabled for maximum \u0027"}],"source_content_type":"text/x-python","patch_set":5,"id":"4e1d102c_396d826e","line":442,"in_reply_to":"3badd2fd_871d14e3","updated":"2026-06-01 21:20:40.000000000","message":"Ideally speaking, we can land independently but given this is a security fix, we just need to get it landed.","commit_id":"72daa017efcc023269d22c82e1dc1f0a39032a0e"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"478b54bc48f3e18d8555d53130e67eee7310878f","unresolved":true,"context_lines":[{"line_number":439,"context_line":"                     \u0027because the bootc command inside of the ramdisk \u0027"},{"line_number":440,"context_line":"                     \u0027comes from the supplied image to be deployed.\u0027),"},{"line_number":441,"context_line":"    cfg.BoolOpt(\u0027enable_bios_bootloader_install\u0027,"},{"line_number":442,"context_line":"                default\u003dFalse,"},{"line_number":443,"context_line":"                help\u003d\u0027Enables support for partition images which require a \u0027"},{"line_number":444,"context_line":"                     \u0027legacy bootloader -- and a call to ``grub-install``. \u0027"},{"line_number":445,"context_line":"                     \u0027Generally, this should remain disabled for maximum \u0027"}],"source_content_type":"text/x-python","patch_set":5,"id":"3badd2fd_871d14e3","line":442,"in_reply_to":"70b5e042_2e37b2dd","updated":"2026-06-01 18:00:00.000000000","message":"I\u0027m happy to land the conductor side first since that sounds easiest to me.","commit_id":"72daa017efcc023269d22c82e1dc1f0a39032a0e"}],"ironic_python_agent/extensions/image.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"2bf73985307fe043dfe70ed75e1951268d5d77b8","unresolved":true,"context_lines":[{"line_number":741,"context_line":"            msg \u003d (\"Install of legacy BIOS bootloaders disabled by \""},{"line_number":742,"context_line":"                   \"CONF.enable_bios_bootloader_install as part of \""},{"line_number":743,"context_line":"                   \"CVE-2026-43003 mitigation.\")"},{"line_number":744,"context_line":"            LOG.warning(msg)"},{"line_number":745,"context_line":"            if not ignore_failure:"},{"line_number":746,"context_line":"                raise errors.InvalidImage(details\u003dmsg)"}],"source_content_type":"text/x-python","patch_set":3,"id":"4b4f178b_fc362ec2","line":744,"updated":"2026-06-01 11:13:03.000000000","message":"s/warning/error/","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"3595c74e7c38353f382038a9f0f382bd9c116f84","unresolved":false,"context_lines":[{"line_number":741,"context_line":"            msg \u003d (\"Install of legacy BIOS bootloaders disabled by \""},{"line_number":742,"context_line":"                   \"CONF.enable_bios_bootloader_install as part of \""},{"line_number":743,"context_line":"                   \"CVE-2026-43003 mitigation.\")"},{"line_number":744,"context_line":"            LOG.warning(msg)"},{"line_number":745,"context_line":"            if not ignore_failure:"},{"line_number":746,"context_line":"                raise errors.InvalidImage(details\u003dmsg)"}],"source_content_type":"text/x-python","patch_set":3,"id":"11f39d57_4aa6b081","line":744,"in_reply_to":"4b4f178b_fc362ec2","updated":"2026-06-01 16:35:24.000000000","message":"Done","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"}],"ironic_python_agent/extensions/standby.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"b598c4521637e1dc2177fb18ce6cdd42509e457c","unresolved":true,"context_lines":[{"line_number":1011,"context_line":"        \"\"\""},{"line_number":1012,"context_line":"        LOG.debug(\u0027Preparing image %s\u0027, image_info[\u0027id\u0027])"},{"line_number":1013,"context_line":""},{"line_number":1014,"context_line":"        if not CONF.enable_partition_images \\"},{"line_number":1015,"context_line":"           and image_info.get(\u0027image_type\u0027) \u003d\u003d \u0027partition\u0027:"},{"line_number":1016,"context_line":"            LOG.info(\u0027Partition images are disabled, refusing to prepare \u0027"},{"line_number":1017,"context_line":"                     \u0027image %s\u0027, image_info[\u0027id\u0027])"}],"source_content_type":"text/x-python","patch_set":1,"id":"a378bb70_4524a79e","line":1014,"updated":"2026-05-07 11:55:45.000000000","message":"Please don\u0027t disable all partition images, it has too high of an impact. As discussed on the bug, we only need to disable running grub by default.","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"3595c74e7c38353f382038a9f0f382bd9c116f84","unresolved":false,"context_lines":[{"line_number":1011,"context_line":"        \"\"\""},{"line_number":1012,"context_line":"        LOG.debug(\u0027Preparing image %s\u0027, image_info[\u0027id\u0027])"},{"line_number":1013,"context_line":""},{"line_number":1014,"context_line":"        if not CONF.enable_partition_images \\"},{"line_number":1015,"context_line":"           and image_info.get(\u0027image_type\u0027) \u003d\u003d \u0027partition\u0027:"},{"line_number":1016,"context_line":"            LOG.info(\u0027Partition images are disabled, refusing to prepare \u0027"},{"line_number":1017,"context_line":"                     \u0027image %s\u0027, image_info[\u0027id\u0027])"}],"source_content_type":"text/x-python","patch_set":1,"id":"f87572d4_cb7f7aee","line":1014,"in_reply_to":"a378bb70_4524a79e","updated":"2026-06-01 16:35:24.000000000","message":"Done","commit_id":"51932a8b10aba90447082d4b00344eaba8c6e3bd"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"2bf73985307fe043dfe70ed75e1951268d5d77b8","unresolved":true,"context_lines":[{"line_number":1007,"context_line":"        :raises: ImageWriteError if writing the image fails."},{"line_number":1008,"context_line":"        :raises: InstanceDeployFailure if failed to create config drive."},{"line_number":1009,"context_line":"             large to store on the given device."},{"line_number":1010,"context_line":"        :raises: InvalidImageType if the image type is invalid or disabled."},{"line_number":1011,"context_line":"        \"\"\""},{"line_number":1012,"context_line":"        LOG.debug(\u0027Preparing image %s\u0027, image_info[\u0027id\u0027])"},{"line_number":1013,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"d0df2f24_10788f0b","line":1010,"updated":"2026-06-01 11:13:03.000000000","message":"This seems unrelated to me, even if technically correct","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"3595c74e7c38353f382038a9f0f382bd9c116f84","unresolved":false,"context_lines":[{"line_number":1007,"context_line":"        :raises: ImageWriteError if writing the image fails."},{"line_number":1008,"context_line":"        :raises: InstanceDeployFailure if failed to create config drive."},{"line_number":1009,"context_line":"             large to store on the given device."},{"line_number":1010,"context_line":"        :raises: InvalidImageType if the image type is invalid or disabled."},{"line_number":1011,"context_line":"        \"\"\""},{"line_number":1012,"context_line":"        LOG.debug(\u0027Preparing image %s\u0027, image_info[\u0027id\u0027])"},{"line_number":1013,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"ac04fe65_a8894d0f","line":1010,"in_reply_to":"d0df2f24_10788f0b","updated":"2026-06-01 16:35:24.000000000","message":"Done","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"}],"ironic_python_agent/tests/unit/extensions/test_image.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"2bf73985307fe043dfe70ed75e1951268d5d77b8","unresolved":true,"context_lines":[{"line_number":56,"context_line":"    @mock.patch.object(image, \u0027_install_grub2\u0027, autospec\u003dTrue)"},{"line_number":57,"context_line":"    def test__install_bootloader_bios(self, mock_grub2,"},{"line_number":58,"context_line":"                                      mock_execute, mock_dispatch):"},{"line_number":59,"context_line":"        self.config(enable_bios_bootloader_install\u003dTrue)"},{"line_number":60,"context_line":"        mock_dispatch.side_effect \u003d ["},{"line_number":61,"context_line":"            self.fake_dev, hardware.BootInfo(current_boot_mode\u003d\u0027bios\u0027)"},{"line_number":62,"context_line":"        ]"}],"source_content_type":"text/x-python","patch_set":3,"id":"0f5972bd_a41cd42c","line":59,"updated":"2026-06-01 11:13:03.000000000","message":"nit: move to setUp","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"3595c74e7c38353f382038a9f0f382bd9c116f84","unresolved":false,"context_lines":[{"line_number":56,"context_line":"    @mock.patch.object(image, \u0027_install_grub2\u0027, autospec\u003dTrue)"},{"line_number":57,"context_line":"    def test__install_bootloader_bios(self, mock_grub2,"},{"line_number":58,"context_line":"                                      mock_execute, mock_dispatch):"},{"line_number":59,"context_line":"        self.config(enable_bios_bootloader_install\u003dTrue)"},{"line_number":60,"context_line":"        mock_dispatch.side_effect \u003d ["},{"line_number":61,"context_line":"            self.fake_dev, hardware.BootInfo(current_boot_mode\u003d\u0027bios\u0027)"},{"line_number":62,"context_line":"        ]"}],"source_content_type":"text/x-python","patch_set":3,"id":"24c48c37_87acc5ee","line":59,"in_reply_to":"0f5972bd_a41cd42c","updated":"2026-06-01 16:35:24.000000000","message":"Done","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"2bf73985307fe043dfe70ed75e1951268d5d77b8","unresolved":true,"context_lines":[{"line_number":73,"context_line":"        )"},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"    @mock.patch.object(image, \u0027_install_grub2\u0027, autospec\u003dTrue)"},{"line_number":76,"context_line":"    def test__install_bootloader_bios_disabled(self, mock_grub2,"},{"line_number":77,"context_line":"                                               mock_execute, mock_dispatch):"},{"line_number":78,"context_line":"        self.config(enable_bios_bootloader_install\u003dFalse)"},{"line_number":79,"context_line":"        mock_dispatch.side_effect \u003d ["}],"source_content_type":"text/x-python","patch_set":3,"id":"0346929c_054fb966","line":76,"updated":"2026-06-01 11:13:03.000000000","message":"Let\u0027s add a test for behavior with ignore_errors\u003dFalse","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"},{"author":{"_account_id":14228,"name":"Clif Houck","email":"me@clifhouck.com","username":"clif_h"},"change_message_id":"3595c74e7c38353f382038a9f0f382bd9c116f84","unresolved":false,"context_lines":[{"line_number":73,"context_line":"        )"},{"line_number":74,"context_line":""},{"line_number":75,"context_line":"    @mock.patch.object(image, \u0027_install_grub2\u0027, autospec\u003dTrue)"},{"line_number":76,"context_line":"    def test__install_bootloader_bios_disabled(self, mock_grub2,"},{"line_number":77,"context_line":"                                               mock_execute, mock_dispatch):"},{"line_number":78,"context_line":"        self.config(enable_bios_bootloader_install\u003dFalse)"},{"line_number":79,"context_line":"        mock_dispatch.side_effect \u003d ["}],"source_content_type":"text/x-python","patch_set":3,"id":"cfbc5080_0a911529","line":76,"in_reply_to":"0346929c_054fb966","updated":"2026-06-01 16:35:24.000000000","message":"Done","commit_id":"79b0b7731739e04a014bcffdb6825f3ad35010ee"}]}
