)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"fc4d1b9643a1015301951093f812d0bfd6f91ec8","unresolved":true,"context_lines":[{"line_number":8,"context_line":""},{"line_number":9,"context_line":"In recent discussions of disallowing steps, it occured"},{"line_number":10,"context_line":"to me that operators might want to instead effectively"},{"line_number":11,"context_line":"say \"admin, your allowed to do this, but not manager\"."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"Where this is different and difficult is becasue the"},{"line_number":14,"context_line":"same basic endpoint may be acceptable for a member to"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"f291034d_f846ce20","line":11,"updated":"2026-07-07 17:21:34.000000000","message":"your -\u003e you\u0027re","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"fc4d1b9643a1015301951093f812d0bfd6f91ec8","unresolved":true,"context_lines":[{"line_number":10,"context_line":"to me that operators might want to instead effectively"},{"line_number":11,"context_line":"say \"admin, your allowed to do this, but not manager\"."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"Where this is different and difficult is becasue the"},{"line_number":14,"context_line":"same basic endpoint may be acceptable for a member to"},{"line_number":15,"context_line":"post to, which meant we really needed to permit operators"},{"line_number":16,"context_line":"to be able to define custom RBAC rules which is then applied"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"a524882e_0b68c3fd","line":13,"updated":"2026-07-07 17:21:34.000000000","message":"sp: because","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"3eed2f3cbd3299bbdb318235bb1784d802ca8fcf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"ae79bbe6_55753bb2","updated":"2026-07-07 19:44:07.000000000","message":"\"As a project scoped user creating a project scoped runbook, The step RBAC policy should apply *then* before being stored in ironic.\"\n\nFurthermore, step validation *WAY* later down int eh flow needs to be trusted if it comes from a runbook or deploy template, because a runbook can/is admin-approved or is specifically project scoped.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"fc4d1b9643a1015301951093f812d0bfd6f91ec8","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"07374433_69c4addd","updated":"2026-07-07 17:21:34.000000000","message":"GR-OSS team review\n\nI forsee a security issue with this change: we do not apply any of these restrictions (including allow_*_step in config, AFAICT) when creating or modifying runbooks or deploy_templates. This may act as a way to circumvent our policy checks.\n\nGiven part of the goal of runbooks is to allow operators to bundle \"dangerous steps\", it seems like we may want to add a check to disallow a project-owned runbook from having any steps that require admin-only to run? I\u0027m not 100% sure as to the solution though, because the RBAC intersection of runbooks-that-can-be-changed-to-admin and step-only-allowed-for-admin is pretty difficult to navigate.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"71ff90daedc0c9f504ef775521b46bf22676ecac","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"377d809c_13962b7d","updated":"2026-07-07 19:40:59.000000000","message":"Okay, discussed with Jay.\n\nWe likely need to do filtering on the API side on *submission*/post.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"6cc5167831acd548626c4cc92c5cf322e1733d9e","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"43ec2e27_6ad7c834","in_reply_to":"07374433_69c4addd","updated":"2026-07-07 18:06:50.000000000","message":"So that happens in _validate_user_steps which is after the deploy_template hydration, and similary for runbooks as they are hydrated super early before the conductor and passed in.\n\nI think the intersection could also be that if you want to, you can do a custom policy to go beyond the default.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"9e41044ce0317b80edd2daa8bcef5cd8db298245","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":3,"id":"9e133862_a03e068d","updated":"2026-08-06 16:50:03.000000000","message":"Mainly want to know if node.py is a style comment or a behavior comment, and if it\u0027s important that it happen later we should put a comment inline about the ordering.","commit_id":"87af79a181eb69f1ad05ba6394f702368b0ff88e"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"f55bae930e24aa2bc9bbada3cec8d63274b39e66","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"c9f47834_f478fd42","updated":"2026-08-10 13:05:22.000000000","message":"recheck sdk storage test job race condition","commit_id":"98e02afea9dc15f62f4bbea6d7ff2ab6ff2e11d9"}],"doc/source/admin/steps.rst":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":250,"context_line":"  modifies a runbook, step-level policies are checked against"},{"line_number":251,"context_line":"  the requester\u0027s credentials. Since no specific node is"},{"line_number":252,"context_line":"  involved at creation time, policy rules that reference"},{"line_number":253,"context_line":"  ``node.owner`` or ``node.lessee`` cannot be evaluated here;"},{"line_number":254,"context_line":"  only role-based rules (e.g. ``role:admin``) are enforced."},{"line_number":255,"context_line":""},{"line_number":256,"context_line":"* **Project-scoped runbook execution** -- When a runbook owned"}],"source_content_type":"text/x-rst","patch_set":2,"id":"1b1880cd_87b0f0b0","line":253,"updated":"2026-07-20 17:06:05.000000000","message":"Please specify what happens when such rules exist: are they ignore or does the verification fail?","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"d5f77bef91f8795092fc22a8c18ab047571b64a6","unresolved":true,"context_lines":[{"line_number":202,"context_line":""},{"line_number":203,"context_line":"Cleaning operation step invocations have the same"},{"line_number":204,"context_line":"basic parameter in the form of"},{"line_number":205,"context_line":":oslo.config:option:`api.disallow_clean_steps`."},{"line_number":206,"context_line":""},{"line_number":207,"context_line":".. note::"},{"line_number":208,"context_line":"   These configurations are enforced in both the API and Conductor"}],"source_content_type":"text/x-rst","patch_set":4,"id":"b87e236f_1d88badb","line":205,"updated":"2026-08-13 11:16:54.000000000","message":"nit: a bit too verbose to my test, I think it would be better to have an example and 3 :oslo.config: links","commit_id":"98e02afea9dc15f62f4bbea6d7ff2ab6ff2e11d9"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"d5f77bef91f8795092fc22a8c18ab047571b64a6","unresolved":true,"context_lines":[{"line_number":235,"context_line":"Rules can also reference node ownership for fine-grained control::"},{"line_number":236,"context_line":""},{"line_number":237,"context_line":"  baremetal:step:execute:bios.apply_configuration: \"role:admin and project_id:%(node.owner)s\""},{"line_number":238,"context_line":""},{"line_number":239,"context_line":"Enforcement points"},{"line_number":240,"context_line":"~~~~~~~~~~~~~~~~~~"},{"line_number":241,"context_line":""}],"source_content_type":"text/x-rst","patch_set":4,"id":"0f2c0f84_54ca075c","line":238,"updated":"2026-08-13 11:16:54.000000000","message":"I think it\u0027s useful to mention that these rules do **not** enable servicing/cleaning if disabled by the catch-all rules like `\u0027baremetal:node:set_provision_state:service_steps`.\n\nA reader could assume that they can opt into only one specific step, which is not the case.","commit_id":"98e02afea9dc15f62f4bbea6d7ff2ab6ff2e11d9"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"d5f77bef91f8795092fc22a8c18ab047571b64a6","unresolved":true,"context_lines":[{"line_number":239,"context_line":"Enforcement points"},{"line_number":240,"context_line":"~~~~~~~~~~~~~~~~~~"},{"line_number":241,"context_line":""},{"line_number":242,"context_line":"Step-level RBAC policies are enforced in the following locations:"},{"line_number":243,"context_line":""},{"line_number":244,"context_line":"* **Direct step requests** -- When a user provides steps directly"},{"line_number":245,"context_line":"  via the API (deploy, clean, or service), the policy is checked"}],"source_content_type":"text/x-rst","patch_set":4,"id":"b40a5571_8037c001","line":242,"updated":"2026-08-13 11:16:54.000000000","message":"nit: needs rephrasing: at least one of the locations is where RBAC policies are **not** enforced","commit_id":"98e02afea9dc15f62f4bbea6d7ff2ab6ff2e11d9"}],"ironic/api/controllers/v1/node.py":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"9e41044ce0317b80edd2daa8bcef5cd8db298245","unresolved":true,"context_lines":[{"line_number":1355,"context_line":"                + (service_steps or [])"},{"line_number":1356,"context_line":"            conductor_steps.validate_user_steps_policy("},{"line_number":1357,"context_line":"                api.request.context, all_steps,"},{"line_number":1358,"context_line":"                node\u003drpc_node)"},{"line_number":1359,"context_line":""},{"line_number":1360,"context_line":"        self._do_provision_action(rpc_node, target, configdrive, clean_steps,"},{"line_number":1361,"context_line":"                                  deploy_steps, rescue_password,"}],"source_content_type":"text/x-python","patch_set":3,"id":"5f414e91_a9bbd8da","line":1358,"updated":"2026-08-06 16:50:03.000000000","message":"Why isn\u0027t this at line 1252?","commit_id":"87af79a181eb69f1ad05ba6394f702368b0ff88e"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"e9cc946eec8e1420500be680b3fefb12dde16053","unresolved":true,"context_lines":[{"line_number":1355,"context_line":"                + (service_steps or [])"},{"line_number":1356,"context_line":"            conductor_steps.validate_user_steps_policy("},{"line_number":1357,"context_line":"                api.request.context, all_steps,"},{"line_number":1358,"context_line":"                node\u003drpc_node)"},{"line_number":1359,"context_line":""},{"line_number":1360,"context_line":"        self._do_provision_action(rpc_node, target, configdrive, clean_steps,"},{"line_number":1361,"context_line":"                                  deploy_steps, rescue_password,"}],"source_content_type":"text/x-python","patch_set":3,"id":"29aea798_587ea2fa","line":1358,"in_reply_to":"5f414e91_a9bbd8da","updated":"2026-08-06 17:53:42.000000000","message":"So, we should be doing it *after* the \ncan these be invoked\" verb wise checks, not before. Before would be super weird to validate and reject before the API version check.","commit_id":"87af79a181eb69f1ad05ba6394f702368b0ff88e"}],"ironic/api/controllers/v1/runbook.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":543,"context_line":""},{"line_number":544,"context_line":"        # If steps were modified, re-validate step-level RBAC"},{"line_number":545,"context_line":"        # policies against the requester\u0027s credentials."},{"line_number":546,"context_line":"        steps_changed \u003d any(p[\u0027path\u0027].startswith(\u0027/steps\u0027)"},{"line_number":547,"context_line":"                            for p in patch)"},{"line_number":548,"context_line":"        if steps_changed:"},{"line_number":549,"context_line":"            conductor_steps.validate_user_steps_policy("}],"source_content_type":"text/x-python","patch_set":2,"id":"008f076e_1fd498c1","line":546,"updated":"2026-07-20 17:06:05.000000000","message":"nit: it\u0027s more future-proof to check for strict equality of \u0027/steps` or startswith \u0027/steps/\u0027","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"}],"ironic/conductor/manager.py":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"fc4d1b9643a1015301951093f812d0bfd6f91ec8","unresolved":true,"context_lines":[{"line_number":953,"context_line":"                # steps by RBAC model, then this is the point"},{"line_number":954,"context_line":"                # where the check occurs."},{"line_number":955,"context_line":"                conductor_steps.validate_user_steps_policy("},{"line_number":956,"context_line":"                     task, deploy_steps)"},{"line_number":957,"context_line":""},{"line_number":958,"context_line":"            deployments.start_deploy(task, self, configdrive, event\u003devent,"},{"line_number":959,"context_line":"                                     deploy_steps\u003ddeploy_steps)"}],"source_content_type":"text/x-python","patch_set":1,"id":"b4298f67_235140ed","line":956,"updated":"2026-07-07 17:21:34.000000000","message":"Just making a note: I checked, deploy_steps here are ONLY ones passed explicitly from API; deploy template steps are added afterwards. We should make sure the documentation calls out that the steps are only limited when called directly (but not via deploy_templates or runbooks).\n\nThis may lead to an ability to workaround this if someone can create+execute runbooks.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"6cc5167831acd548626c4cc92c5cf322e1733d9e","unresolved":true,"context_lines":[{"line_number":953,"context_line":"                # steps by RBAC model, then this is the point"},{"line_number":954,"context_line":"                # where the check occurs."},{"line_number":955,"context_line":"                conductor_steps.validate_user_steps_policy("},{"line_number":956,"context_line":"                     task, deploy_steps)"},{"line_number":957,"context_line":""},{"line_number":958,"context_line":"            deployments.start_deploy(task, self, configdrive, event\u003devent,"},{"line_number":959,"context_line":"                                     deploy_steps\u003ddeploy_steps)"}],"source_content_type":"text/x-python","patch_set":1,"id":"00f7880c_733452ca","line":956,"in_reply_to":"b4298f67_235140ed","updated":"2026-07-07 18:06:50.000000000","message":"As I read the code, a validation helper which ultimately invokes _validate_user_steps still gets invoked *after* hydrating steps from the deploy templates.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"9ac760e943b2988cfa9ea3c199b49fd0f0289705","unresolved":true,"context_lines":[{"line_number":1386,"context_line":"            # rights, but if an operator wanted to lockout specific"},{"line_number":1387,"context_line":"            # steps by RBAC model, then this is the point"},{"line_number":1388,"context_line":"            # where the check occurs."},{"line_number":1389,"context_line":"            conductor_steps.validate_user_steps_policy("},{"line_number":1390,"context_line":"                task, clean_steps)"},{"line_number":1391,"context_line":""},{"line_number":1392,"context_line":"            try:"}],"source_content_type":"text/x-python","patch_set":1,"id":"8ecfe175_3d599a2d","line":1389,"updated":"2026-07-07 19:50:14.000000000","message":"This and the other case likely needs to be moved into the API. The risk is an initial RBAC check is done on the servicing/cleaning runbook step invocation as a set of authorized steps which an admin has explicitly said is OKAY.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"9e41044ce0317b80edd2daa8bcef5cd8db298245","unresolved":true,"context_lines":[{"line_number":946,"context_line":"            if deploy_steps:"},{"line_number":947,"context_line":"                conductor_steps.check_disallowed_steps("},{"line_number":948,"context_line":"                    deploy_steps, \u0027deploy\u0027, raise_on_disallowed\u003dTrue)"},{"line_number":949,"context_line":""},{"line_number":950,"context_line":"            deployments.start_deploy(task, self, configdrive, event\u003devent,"},{"line_number":951,"context_line":"                                     deploy_steps\u003ddeploy_steps)"},{"line_number":952,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"ea7a413e_39c706a8","line":949,"updated":"2026-08-06 16:50:03.000000000","message":"whitespace change intentional?","commit_id":"87af79a181eb69f1ad05ba6394f702368b0ff88e"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"e9cc946eec8e1420500be680b3fefb12dde16053","unresolved":false,"context_lines":[{"line_number":946,"context_line":"            if deploy_steps:"},{"line_number":947,"context_line":"                conductor_steps.check_disallowed_steps("},{"line_number":948,"context_line":"                    deploy_steps, \u0027deploy\u0027, raise_on_disallowed\u003dTrue)"},{"line_number":949,"context_line":""},{"line_number":950,"context_line":"            deployments.start_deploy(task, self, configdrive, event\u003devent,"},{"line_number":951,"context_line":"                                     deploy_steps\u003ddeploy_steps)"},{"line_number":952,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"ee2535d5_2ce5837e","line":949,"in_reply_to":"ea7a413e_39c706a8","updated":"2026-08-06 17:53:42.000000000","message":"nope, removing. Thanks!","commit_id":"87af79a181eb69f1ad05ba6394f702368b0ff88e"}],"ironic/conductor/steps.py":[{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"9ac760e943b2988cfa9ea3c199b49fd0f0289705","unresolved":true,"context_lines":[{"line_number":894,"context_line":"                errors.append(error)"},{"line_number":895,"context_line":"            continue"},{"line_number":896,"context_line":""},{"line_number":897,"context_line":"        rbac_error \u003d _check_step_policy(task, user_step)"},{"line_number":898,"context_line":"        if rbac_error:"},{"line_number":899,"context_line":"            errors.append(rbac_error)"},{"line_number":900,"context_line":"            result.append(user_step)"},{"line_number":901,"context_line":"            continue"},{"line_number":902,"context_line":""},{"line_number":903,"context_line":"        step_errors \u003d _validate_user_step(task, user_step, driver_step,"},{"line_number":904,"context_line":"                                          step_type, disable_ramdisk)"},{"line_number":905,"context_line":"        errors.extend(step_errors)"}],"source_content_type":"text/x-python","patch_set":1,"id":"f7d5ab11_7026e4f1","line":902,"range":{"start_line":897,"start_character":0,"end_line":902,"end_character":0},"updated":"2026-07-07 19:50:14.000000000","message":"Per discussion with Jay, this is simply too late in the process.","commit_id":"7a28d4fdfeeeb475ad78600fba85f4c243f10e4a"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":797,"context_line":"    :raises: InvalidParameterValue if any step fails its policy"},{"line_number":798,"context_line":"        check."},{"line_number":799,"context_line":"    \"\"\""},{"line_number":800,"context_line":"    if not isinstance(user_steps, list):"},{"line_number":801,"context_line":"        return"},{"line_number":802,"context_line":"    errors \u003d []"},{"line_number":803,"context_line":"    for step in user_steps:"}],"source_content_type":"text/x-python","patch_set":2,"id":"32305032_f973f97b","line":800,"updated":"2026-07-20 17:06:05.000000000","message":"This is odd, what else can it be? Did you mean `if user_steps is None`?","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"5a73fb76dc51177d314e9c4d99a42cdf129d40ac","unresolved":true,"context_lines":[{"line_number":797,"context_line":"    :raises: InvalidParameterValue if any step fails its policy"},{"line_number":798,"context_line":"        check."},{"line_number":799,"context_line":"    \"\"\""},{"line_number":800,"context_line":"    if not isinstance(user_steps, list):"},{"line_number":801,"context_line":"        return"},{"line_number":802,"context_line":"    errors \u003d []"},{"line_number":803,"context_line":"    for step in user_steps:"}],"source_content_type":"text/x-python","patch_set":2,"id":"41383cd3_3c12e6d3","line":800,"in_reply_to":"32305032_f973f97b","updated":"2026-08-03 20:50:25.000000000","message":"I think this is largely claude being overly guard-rail safe. I think if the list is none then we should just return, or to be more precise \"if not user_steps\", then \"return\"","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":801,"context_line":"        return"},{"line_number":802,"context_line":"    errors \u003d []"},{"line_number":803,"context_line":"    for step in user_steps:"},{"line_number":804,"context_line":"        if not isinstance(step, dict):"},{"line_number":805,"context_line":"            continue"},{"line_number":806,"context_line":"        error \u003d _check_step_policy(context, step, node\u003dnode)"},{"line_number":807,"context_line":"        if error:"}],"source_content_type":"text/x-python","patch_set":2,"id":"fc58b758_6ce31c5d","line":804,"updated":"2026-07-20 17:06:05.000000000","message":"Similar question here.","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"5a73fb76dc51177d314e9c4d99a42cdf129d40ac","unresolved":true,"context_lines":[{"line_number":801,"context_line":"        return"},{"line_number":802,"context_line":"    errors \u003d []"},{"line_number":803,"context_line":"    for step in user_steps:"},{"line_number":804,"context_line":"        if not isinstance(step, dict):"},{"line_number":805,"context_line":"            continue"},{"line_number":806,"context_line":"        error \u003d _check_step_policy(context, step, node\u003dnode)"},{"line_number":807,"context_line":"        if error:"}],"source_content_type":"text/x-python","patch_set":2,"id":"f4d397fb_7f9d545a","line":804,"in_reply_to":"fc58b758_6ce31c5d","updated":"2026-08-03 20:50:25.000000000","message":"Same, It is a list of dicts, so this is just trying to advance guard that we have data which we can act upon, except that should already be validated via schema validation.","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":807,"context_line":"        if error:"},{"line_number":808,"context_line":"            errors.append(error)"},{"line_number":809,"context_line":"    if errors:"},{"line_number":810,"context_line":"        raise exception.InvalidParameterValue("},{"line_number":811,"context_line":"            err\u003d\u0027; \u0027.join(errors))"},{"line_number":812,"context_line":""},{"line_number":813,"context_line":""}],"source_content_type":"text/x-python","patch_set":2,"id":"192e1099_b221f4ab","line":810,"updated":"2026-07-20 17:06:05.000000000","message":"Are you sure you want HTTP 400 here? It seems to be a perfect case of 403 to me.","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"5a73fb76dc51177d314e9c4d99a42cdf129d40ac","unresolved":true,"context_lines":[{"line_number":807,"context_line":"        if error:"},{"line_number":808,"context_line":"            errors.append(error)"},{"line_number":809,"context_line":"    if errors:"},{"line_number":810,"context_line":"        raise exception.InvalidParameterValue("},{"line_number":811,"context_line":"            err\u003d\u0027; \u0027.join(errors))"},{"line_number":812,"context_line":""},{"line_number":813,"context_line":""}],"source_content_type":"text/x-python","patch_set":2,"id":"c2a3769b_c888064b","line":810,"in_reply_to":"192e1099_b221f4ab","updated":"2026-08-03 20:50:25.000000000","message":"Yeah, 403 is actually more valid here because it would be an RBAC issue.","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"}],"ironic/tests/unit/conductor/test_manager.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":2221,"context_line":"            deploy_steps\u003ddeploy_steps)"},{"line_number":2222,"context_line":""},{"line_number":2223,"context_line":""},{"line_number":2224,"context_line":""},{"line_number":2225,"context_line":"@mgr_utils.mock_record_keepalive"},{"line_number":2226,"context_line":"class ContinueNodeDeployTestCase(mgr_utils.ServiceSetUpMixin,"},{"line_number":2227,"context_line":"                                 db_base.DbTestCase):"}],"source_content_type":"text/x-python","patch_set":2,"id":"c43c8ed0_95e89f7c","line":2224,"updated":"2026-07-20 17:06:05.000000000","message":"This is unrelated and should actually cause a linting failure (if it was not broken)","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"}],"ironic/tests/unit/conductor/test_steps.py":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"from oslo_config import cfg"},{"line_number":16,"context_line":"from oslo_utils import uuidutils"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"from oslo_policy import policy as oslo_policy"},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"from ironic.common import exception"}],"source_content_type":"text/x-python","patch_set":2,"id":"1f8ba9a3_25efa737","line":17,"updated":"2026-07-20 17:06:05.000000000","message":"Redundant space (should have been picked by the linter, but it\u0027s broken)","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"9eea3995ae1a5370cb3621233c5ef9ea04656df5","unresolved":true,"context_lines":[{"line_number":15,"context_line":"from oslo_config import cfg"},{"line_number":16,"context_line":"from oslo_utils import uuidutils"},{"line_number":17,"context_line":""},{"line_number":18,"context_line":"from oslo_policy import policy as oslo_policy"},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"from ironic.common import exception"},{"line_number":21,"context_line":"from ironic.common import policy"}],"source_content_type":"text/x-python","patch_set":2,"id":"ec978cde_f2f454a1","line":18,"updated":"2026-07-20 17:06:05.000000000","message":"Has to be before oslo_utils","commit_id":"8a956f8d97cccd45517dc3e8be4940ece6cb8ed4"},{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"d5f77bef91f8795092fc22a8c18ab047571b64a6","unresolved":true,"context_lines":[{"line_number":1841,"context_line":"        rule_name \u003d (\u0027baremetal:step:execute:%s.%s\u0027"},{"line_number":1842,"context_line":"                     % (interface, step))"},{"line_number":1843,"context_line":"        rule \u003d oslo_policy.RuleDefault(rule_name, check_str)"},{"line_number":1844,"context_line":"        enforcer \u003d policy.get_enforcer()"},{"line_number":1845,"context_line":"        enforcer.register_default(rule)"},{"line_number":1846,"context_line":"        enforcer.load_rules()"},{"line_number":1847,"context_line":"        return rule_name"}],"source_content_type":"text/x-python","patch_set":4,"id":"973e4562_3683a674","line":1844,"updated":"2026-08-13 11:16:54.000000000","message":"I hope we clean up the enforcer between test runs","commit_id":"98e02afea9dc15f62f4bbea6d7ff2ab6ff2e11d9"}],"releasenotes/notes/per-step-rbac-policy-7c78088cb2104fac.yaml":[{"author":{"_account_id":10239,"name":"Dmitry Tantsur","email":"dtantsur@protonmail.com","username":"dtantsur"},"change_message_id":"d5f77bef91f8795092fc22a8c18ab047571b64a6","unresolved":true,"context_lines":[{"line_number":32,"context_line":"      at execution time, step policies are re-checked with full"},{"line_number":33,"context_line":"      node context."},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"    * Admin-approved runbooks (system-scoped or public) and"},{"line_number":36,"context_line":"      deploy templates (which require system administrator"},{"line_number":37,"context_line":"      privileges to create) are trusted at execution time and"},{"line_number":38,"context_line":"      their steps are not re-checked."}],"source_content_type":"text/x-yaml","patch_set":4,"id":"ff63e3bb_440b9ccc","line":35,"updated":"2026-08-13 11:16:54.000000000","message":"Same comment as on the docs","commit_id":"98e02afea9dc15f62f4bbea6d7ff2ab6ff2e11d9"}]}
