)]}'
{"id":"openstack%2Fkeystone~1005069","triplet_id":"openstack%2Fkeystone~master~I520f24617c8ec16e2d007e13e3fff99944e71260","project":"openstack/keystone","branch":"master","attention_set":{},"removed_from_attention_set":{"7973":{"account":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"last_update":"2026-09-14 17:56:18.000000000","reason":"Change was submitted"},"7414":{"account":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"last_update":"2026-09-14 17:56:18.000000000","reason":"Change was submitted"},"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-09-14 17:56:18.000000000","reason":"Change was submitted"},"27900":{"account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"last_update":"2026-09-14 16:36:57.000000000","reason":"\u003cGERRIT_ACCOUNT_27900\u003e replied on the change","reason_account":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}}},"hashtags":[],"change_id":"I520f24617c8ec16e2d007e13e3fff99944e71260","subject":"feat: Register ec2credential as a marker auth method","status":"MERGED","created":"2026-09-10 15:22:55.000000000","updated":"2026-09-14 17:57:31.000000000","submitted":"2026-09-14 17:56:18.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":5,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1005069","meta_rev_id":"610d68a770e4ed991d2917c9d40222babe6d9ee2","_number":1005069,"virtual_id_number":1005069,"owner":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-09-14 17:56:18.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"all":[{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2026-09-14 16:36:57.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"all":[{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":1,"date":"2026-09-14 16:36:57.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"}],"reviewers":{"REVIEWER":[{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-10 15:58:45.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2026-09-10 16:59:46.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-09-11 10:46:31.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"state":"REVIEWER"},{"updated":"2026-09-11 10:46:31.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"state":"REVIEWER"},{"updated":"2026-09-11 10:46:31.000000000","updated_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"}],"messages":[{"id":"2fc821e6b28aa64a175f5b6b8507232eb00641e1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-09-10 15:22:55.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"132da45d67d7e994bd674b2b117dd77877114d96","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-10 15:58:45.000000000","message":"Patch Set 1:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/a767248b5dc64540a23b479b63921907\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/415acde2f8e04fd1868051885b509f7a : SUCCESS in 22m 41s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/919a06ff1a24428cb3a4a492b281062b : SUCCESS in 16m 26s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/6af20861724e4d8cb658853fcbd456e5 : SUCCESS in 33m 17s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"5413546e8e12fecd3d51ffac34e239827ff31bb6","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-10 16:59:46.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b3fd2075587f45309c363cb2c0467147\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/04327b41171b4cc2bc81f59eee1ea18f : SUCCESS in 3m 15s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/84b2c576ce074082aade59d080236250 : SUCCESS in 12m 46s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a5499a316f2f4f1ca7f359eedaeb1356 : SUCCESS in 5m 17s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/92bf7fb901e745198727b13abf3260bc : SUCCESS in 8m 14s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/6fa4415347464d60a3f217cfe82a633d : SUCCESS in 11m 28s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/cf9225272dab4ff78b6c23e3701e23ce : SUCCESS in 13m 32s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/155f7ebf74fd471e8b23557dd1f2c441 : SUCCESS in 13m 17s\n- requirements-check https://zuul.opendev.org/t/openstack/build/74dad95d028c477a9ceba25f4c8682b6 : SUCCESS in 5m 01s\n- grenade https://zuul.opendev.org/t/openstack/build/ab0ddc9f1a004cdeb557df8347d56c16 : SUCCESS in 35m 11s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/9a8448e260494cb8ba8f70b920fa18c7 : SUCCESS in 1h 33m 14s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3a571c7286c04212b6164fa6204929c9 : SUCCESS in 13m 07s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/c6604c0307de45249b5316762e303747 : FAILURE in 18m 41s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/0a6ab505cde04e14a0b2c078b2af3a6b : SUCCESS in 22m 49s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/519758fbbb4249d48203801d79f01af3 : FAILURE in 19m 29s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/e41b204151d84f368cebc3ae62df2173 : FAILURE in 25m 38s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/620bdfaed7d54f3d914e48c4217a0f44 : SUCCESS in 20m 34s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/5499af06865a41048d8ed6892dddb4f0 : SUCCESS in 25m 28s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/1afe2965b256490db8e4d03f4ac53091 : SUCCESS in 25m 12s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/8bc7a6c7f0d8461f8d772e4d47eb7907 : SUCCESS in 59m 04s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/f29b0093a3044ae786f8415b6ae0f139 : SUCCESS in 46m 11s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/373f33bc89ab4356bd71b4f0743cb999 : SUCCESS in 4m 00s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":1},{"id":"96410d3abeadfbe9bd96b81be154567a60b5e78f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-09-11 17:58:36.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"d3f6587eb9b502f5b8366bacb786fc4de4f7363d","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-11 18:30:37.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/0d656b2d02864f4a8c755f88d1818cba\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/8a9bb55f81cb4614807f5c7dd1b27874 : SUCCESS in 20m 30s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/69d06ce52baa4f9f907928b9aeb7aa46 : SUCCESS in 19m 10s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/7ab752b7c0a1437cbe2b58cf34106739 : SUCCESS in 29m 51s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"2cf610f4f48104922a59dcb3af9385015c091781","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-11 19:26:34.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b49defe585e446adbea985e46e469cb8\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/e902a73e853d45539d5c42a5bd885eed : SUCCESS in 2m 58s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/6975d7ed12ac4ce0b51c662bff19c052 : SUCCESS in 14m 42s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/ba177f3cd3424c409017eb8c6a34afb9 : SUCCESS in 3m 38s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/3aec06760f1d415a9e199d2af645406b : SUCCESS in 11m 18s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/09723245cb844a2c9de63686028c2122 : SUCCESS in 11m 08s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/aac1bc3d500044629f90e6823a4d2f43 : SUCCESS in 12m 44s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/13a4e14588084d3cad9cc51952b0482b : SUCCESS in 14m 02s\n- requirements-check https://zuul.opendev.org/t/openstack/build/bf0d128309b949f982e7cbb28fe689e2 : SUCCESS in 3m 20s\n- grenade https://zuul.opendev.org/t/openstack/build/42da4d553d3948c9bfb54dd47689c656 : SUCCESS in 53m 37s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/ef703f99e3c24a29b4a34f8bdb5eb7c3 : SUCCESS in 1h 25m 30s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/de35170f104047ea9fd81d6363017cbe : SUCCESS in 14m 25s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/738cc6c7b4904e9e8eea33e0f594b3ef : FAILURE in 8m 31s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/30a7a03730be4947bb11e262bc076a93 : SUCCESS in 50m 22s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/2669e4502a1a4921aec966cebe864f86 : FAILURE in 18m 43s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/ebb545f03183456d8b9736ad037d4308 : FAILURE in 13m 31s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/20370af1170f400e9c0bc60e054fb6db : SUCCESS in 47m 20s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/0ec32c662fa24061ba518f03daafdda3 : SUCCESS in 50m 13s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/b11561746c9747508dba2c8694a90b2d : SUCCESS in 38m 46s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/f8161d10d886487f948dfd9546592c12 : SUCCESS in 26m 50s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/3c34381d620f4c7b9c630b0c3044a5fe : SUCCESS in 32m 48s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/d7fd59cb2ebe4fd5bb57cbe9c6d6400e : SUCCESS in 4m 38s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":2},{"id":"4a7de1913f85f9d209307ffde4ba41dd42aacd65","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-14 11:22:01.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"9ab26ab229bd2197bba1c5952e0b835ee9b9586b","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-14 11:22:11.000000000","message":"Patch Set 2: Code-Review-1","accounts_in_message":[],"_revision_number":2},{"id":"de3f9cc76afd15a2ea1d70bc0f4204995cf538a0","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-14 11:23:15.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"a04511ebb529f0d441fbad7d1394e1f102a08a94","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-09-14 11:56:56.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":3},{"id":"4505790970ea19925446a58897e808b2f9af4d03","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-09-14 12:02:52.000000000","message":"Patch Set 3:\n\n(2 comments)","accounts_in_message":[],"_revision_number":3},{"id":"00c4c089a29425b1a1fe1e8582f1c84bb3a20774","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-09-14 12:15:58.000000000","message":"Patch Set 3: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":3},{"id":"8fab61b9d04b3c1a2faf75984f27ae84e0decf47","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 12:26:12.000000000","message":"Patch Set 3:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/0fd202cb71a344178798902bdb5e22cb\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/5a885e2838bf4a62b7a352ad743a623b : SUCCESS in 18m 34s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/90d90886551b43ea80a1b69e1041be39 : SUCCESS in 19m 00s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/290f88057a2144a9a67f8186a0ae6bab : SUCCESS in 27m 08s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"5285d1883e0dcd59f8cf6228847109daced84567","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-09-14 12:28:47.000000000","message":"Patch Set 3: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":3},{"id":"860fbd8c8406ffc356f2af849ff1d49b80cd748d","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-09-14 12:28:58.000000000","message":"Patch Set 3: -Workflow","accounts_in_message":[],"_revision_number":3},{"id":"4e00a00f10941548035823faeca9350ad1102975","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 13:45:32.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/c3c7691575b04cd9935b616ebac2637d\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/7e940f10737f4f969278681a71dfa0ee : SUCCESS in 3m 29s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/4e211cf48573463397a7fb33ba95ba37 : SUCCESS in 17m 26s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/9c56da59fb354cc387a67118197e59be : SUCCESS in 5m 14s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/253c48cd9910443d92c69b1cf0ce3fab : SUCCESS in 11m 26s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/1b4c3ba463264bd2abd7b7c4399334a7 : SUCCESS in 9m 41s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/815cc2be7d644dcf91b91240d08640fc : SUCCESS in 11m 09s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/9b03ae8239cd47c98761d5f7d2105f85 : SUCCESS in 14m 00s\n- requirements-check https://zuul.opendev.org/t/openstack/build/01f85bddb4f04584a0c3e0052ab0a7b8 : SUCCESS in 2m 59s\n- grenade https://zuul.opendev.org/t/openstack/build/cc755cfeca254b218e40f465e9e5679e : SUCCESS in 52m 11s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/9b1dc91dc6d5438ab2d6b056b70ab487 : SUCCESS in 1h 34m 13s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/171f0f93c156473faaa53600f10e8847 : FAILURE in 10m 16s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/7e1c4a3b9739459ba76d6e4133b17a69 : FAILURE in 8m 57s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/633d37d1e1a84cd9a1affcaa9b3be56a : SUCCESS in 52m 12s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/fccd845c7aa74d119515b979fc783b66 : FAILURE in 22m 07s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/49ea594643604d9e84160677f991b049 : FAILURE in 26m 19s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/9a5306edf405411cb663ca9ed87f4577 : SUCCESS in 54m 36s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/97fb6d15deb749be994a4e5a7c4e3ca4 : SUCCESS in 54m 58s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/7a23b781b0c2425083364106d783c324 : SUCCESS in 36m 03s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/8271732a73944eb195fa2391f0b34971 : SUCCESS in 42m 46s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/dd2574161f314edf8aa7cd29dab50cbd : SUCCESS in 43m 23s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/1164bd79ccc948dfa2c0c941394335db : SUCCESS in 7m 28s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":3},{"id":"84f250f06be14b0294405377d5f4791a9396d133","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-09-14 15:37:05.000000000","message":"Uploaded patch set 4.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified-1 (copy condition: \"NEVER\")\n* Workflow+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":4},{"id":"a35b0a6c52501d9aca04f243211d0398cd3ca8d5","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 16:09:07.000000000","message":"Patch Set 4:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2d207d80d67d4a1ca60f3234d6445ece\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/5533074e4a36472a9271db22c1a9de61 : SUCCESS in 19m 23s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/133cda91b4134dd182ca1d97bdf2e94b : SUCCESS in 20m 14s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/2327458b8023466090d05bf56a7d348b : SUCCESS in 30m 10s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"fe96a824b717c8b66bf82b6f2d73dec31e401ce0","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 16:33:33.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/0983f14079324243b583867b9bdcf33a\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/05e64e35f6884ac0866f5abd95acd3a5 : SUCCESS in 2m 10s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/98391b39c69a4ecfbdb48c6c96345f10 : SUCCESS in 11m 56s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/2e00db750f484f49aeea3e4dc3b030d0 : SUCCESS in 3m 47s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/b6f94065ad0648f692e21c0420d27ea1 : SUCCESS in 11m 39s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/cc730f885d8a48fb86a51fe8004c9582 : SUCCESS in 9m 05s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/338f88432ae84b8ab3a7f5c8f52484cd : SUCCESS in 14m 32s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/856298dfe68046099dc7b1099ccdf579 : SUCCESS in 14m 26s\n- requirements-check https://zuul.opendev.org/t/openstack/build/20a57ad6d8be4666867f5d0bc39ddb5f : SUCCESS in 3m 11s\n- grenade https://zuul.opendev.org/t/openstack/build/2755fc7f35d34fea8b0472ec29c41219 : SUCCESS in 53m 28s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/c3dda3df711a412f9741af412d5bcdbe : SUCCESS in 43m 31s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ffb71c755ba34830b8d864b78dcdac50 : SUCCESS in 14m 14s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/28bb1d599f9446c48bcf7f813320a8de : FAILURE in 18m 35s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/9e571f9505d34a32a0d740fd5fc65627 : SUCCESS in 49m 25s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/525360b9ad054070ae126d987d42b1f0 : FAILURE in 20m 52s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/824e58f09f994ecab1c929387e8ddb33 : FAILURE in 29m 16s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/e7183ea114244461af33ec7b4f25c48f : SUCCESS in 46m 51s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/e68184a9a08845dc818429aff3a3ddfe : SUCCESS in 22m 36s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/4791e6f5ecaf479ea6ffe55642fad247 : SUCCESS in 19m 29s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/230343eff18440dea9117f5d02ae67d6 : SUCCESS in 53m 59s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/485ff82976c94488a3e91f231bab8de7 : SUCCESS in 41m 02s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/4fc90af97f8b4f79ae26e97d6c1a3e6e : SUCCESS in 4m 07s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":4},{"id":"5e84928aeb047b0b52535a45a23f9b1ceae798db","author":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"date":"2026-09-14 16:36:57.000000000","message":"Patch Set 4: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"8ec04370e3c2484e05d0a1618ee3f6be01840970","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 16:37:46.000000000","message":"Patch Set 4: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":4},{"id":"4d6932f71b48abc45b0a70c60bfeb45fd52f2b64","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 17:56:18.000000000","message":"Patch Set 4: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/6a6470cbed50434c888edcd5410825d8\n\n- test-release-openstack https://zuul.opendev.org/t/openstack/build/b2d17d718d7b44a686797f7dd363ffa7 : SUCCESS in 4m 21s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/0927b863e05e4d448c36033691aec226 : SUCCESS in 5m 51s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/d830e98458d04b7ba2ab42bd10d01da6 : SUCCESS in 9m 37s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/f6c4b24cf7894e9d9469523fe7760bbd : SUCCESS in 6m 56s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ff44d5de3aab44d095712a61507bf672 : SUCCESS in 12m 34s\n- requirements-check https://zuul.opendev.org/t/openstack/build/999adcd2ae9e44b0abec54c3e9421f63 : SUCCESS in 2m 21s\n- grenade https://zuul.opendev.org/t/openstack/build/292ebc41ca3c4e9cb93b06afeff46c8f : SUCCESS in 30m 36s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/3d74ede552e8445ab8621fd86a113210 : SUCCESS in 1h 17m 31s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/03dfe54231a14ba19d2cc4cbb5caaa76 : SUCCESS in 12m 42s\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/c11ae3dfd7fb4ddeb437469e0d49c38d : SUCCESS in 22m 58s\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/b7b76d4fb4054a7db0347c839e3281d5 : SUCCESS in 51m 38s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/ef86ca7d386148238840a7211ebf2721 : SUCCESS in 1h 01m 34s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/6b4ea2e35f5046df87d9cd99662da7cb : SUCCESS in 42m 43s","accounts_in_message":[],"_revision_number":4},{"id":"d128b565e377e185017b1f7fc4756dbb5ad93e10","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 17:56:18.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":4},{"id":"610d68a770e4ed991d2917c9d40222babe6d9ee2","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-14 17:57:31.000000000","message":"Patch Set 4:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/83ca00f0add44245b6d390b250b68fdc\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/90354bf25fc745e8aa6e8249e8c7742b : SUCCESS in 1m 02s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/82b68984c2444ab2bcb7201aba799dc6 : SUCCESS in 51s","accounts_in_message":[],"_revision_number":4}],"current_revision_number":4,"current_revision":"0e2166742f7749d8f93200b4ccd995347912b4fa","revisions":{"b230bc793fa05158156d26a95a0a738aa5da5bd7":{"kind":"REWORK","_number":1,"created":"2026-09-10 15:22:55.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/69/1005069/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/1005069/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/1005069/1"}}},"commit":{"parents":[{"commit":"5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8","subject":"Merge \"Use common environment classifier\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-10 15:02:59.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-10 15:21:54.000000000","tz":120},"subject":"feat: Register ec2credential as a marker auth method","message":"feat: Register ec2credential as a marker auth method\n\nTokens minted from an EC2 or S3 credential exchange (POST /v3/ec2tokens\nor POST /v3/s3tokens) have always recorded the ec2credential auth\nmethod, which was never a registered auth method. The fernet token\nprovider encodes methods as a bitmask of [auth] methods, so the marker\nwas silently dropped on the token payload round-trip: on any validation\nthat re-read the payload (cache miss, different process) the token\nlooked like it had been issued with no auth methods at all, and the\nguard that rejects such tokens from authorizing requests in Keystone\ncould not recognize them. A stolen EC2 or S3 access/secret key pair\ncould therefore be exchanged for a token and used to authorize\nrequests in Keystone.\n\nRegister ec2credential as a deliberately non-functional auth method so\nthe marker has a bit in the fernet methods bitmask and survives the\nround-trip, and is recognized as delegated-credential derived by all of\nthe guards that reject such tokens (Keystone authorization, token\nre-scoping, trust, application credential, and OAuth1 management). The\nplugin can never authenticate: EC2 and S3 credentials must still be\nexchanged at their respective endpoints, and attempts to authenticate\nvia /v3/auth/tokens are rejected with 401.\n\nThe method is appended to the end of the default [auth] methods list\non purpose: the fernet method bitmask is positional, so appending\npreserves the bits of all existing methods and existing tokens\ncontinue to validate.\n\nWhile the method is removed from [auth] methods, POST /v3/ec2tokens\nand POST /v3/s3tokens refuse to issue tokens (HTTP 503): a token\nminted without the marker would not be recognized as\ndelegated-credential derived on a token payload round-trip, so the\nendpoints fail closed rather than re-opening the vulnerability.\nOperators pinning an explicit methods list must add the method after\nupgrading.\n\nAlso ensure ec2credential can never be reclassified as a primary auth\nmethod via [auth] additional_primary_auth_methods, which would\notherwise silently re-open the rescope path the guards block.\n\nThe notes in OSSA-2026-037 defer the EC2/S3 credential handling\nweakness to a separate advisory; this change is that fix.\n\nAssisted-by: Qwen-3.8\nChange-Id: I520f24617c8ec16e2d007e13e3fff99944e71260\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b230bc793fa05158156d26a95a0a738aa5da5bd7"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b230bc793fa05158156d26a95a0a738aa5da5bd7"}]},"branch":"refs/heads/master"},"26c5f5275eb1f35e634ff4bcec16b3bfc1b0f039":{"kind":"REWORK","_number":2,"created":"2026-09-11 17:58:36.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/69/1005069/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/1005069/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/1005069/2"}}},"commit":{"parents":[{"commit":"5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8","subject":"Merge \"Use common environment classifier\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-10 15:02:59.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-11 17:56:51.000000000","tz":120},"subject":"feat: Register ec2credential as a marker auth method","message":"feat: Register ec2credential as a marker auth method\n\nTokens minted from an EC2 or S3 credential exchange (POST /v3/ec2tokens\nor POST /v3/s3tokens) have always recorded the ec2credential auth\nmethod, which was never a registered auth method. The fernet token\nprovider encodes methods as a bitmask of [auth] methods, so the marker\nwas silently dropped on the token payload round-trip: on any validation\nthat re-read the payload (cache miss, different process) the token\nlooked like it had been issued with no auth methods at all, and the\nguard that rejects such tokens from authorizing requests in Keystone\ncould not recognize them. A stolen EC2 or S3 access/secret key pair\ncould therefore be exchanged for a token and used to authorize\nrequests in Keystone.\n\nRegister ec2credential as a deliberately non-functional auth method so\nthe marker has a bit in the fernet methods bitmask and survives the\nround-trip, and is recognized as delegated-credential derived by all of\nthe guards that reject such tokens (Keystone authorization, token\nre-scoping, trust, application credential, and OAuth1 management). The\nplugin can never authenticate: EC2 and S3 credentials must still be\nexchanged at their respective endpoints, and attempts to authenticate\nvia /v3/auth/tokens are rejected with 401.\n\nThe method is appended to the end of the default [auth] methods list\non purpose: the fernet method bitmask is positional, so appending\npreserves the bits of all existing methods and existing tokens\ncontinue to validate.\n\nWhile the method is removed from [auth] methods, POST /v3/ec2tokens\nand POST /v3/s3tokens refuse to issue tokens (HTTP 503): a token\nminted without the marker would not be recognized as\ndelegated-credential derived on a token payload round-trip, so the\nendpoints fail closed rather than re-opening the vulnerability.\nOperators pinning an explicit methods list must add the method after\nupgrading.\n\nAlso ensure ec2credential can never be reclassified as a primary auth\nmethod via [auth] additional_primary_auth_methods, which would\notherwise silently re-open the rescope path the guards block.\n\nThe notes in OSSA-2026-037 defer the EC2/S3 credential handling\nweakness to a separate advisory; this change is that fix.\n\nAssisted-by: Qwen-3.8\nChange-Id: I520f24617c8ec16e2d007e13e3fff99944e71260\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/26c5f5275eb1f35e634ff4bcec16b3bfc1b0f039"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/26c5f5275eb1f35e634ff4bcec16b3bfc1b0f039"}]},"branch":"refs/heads/master"},"01d2950788e59dc59c7eb841fa7f9253ef81e315":{"kind":"REWORK","_number":3,"created":"2026-09-14 11:56:56.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/69/1005069/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/1005069/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/1005069/3"}}},"commit":{"parents":[{"commit":"5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8","subject":"Merge \"Use common environment classifier\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-10 15:02:59.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-14 11:51:06.000000000","tz":120},"subject":"feat: Register ec2credential as a marker auth method","message":"feat: Register ec2credential as a marker auth method\n\nTokens minted from an EC2 or S3 credential exchange (POST /v3/ec2tokens\nor POST /v3/s3tokens) have always recorded the ec2credential auth\nmethod, which was never a registered auth method. The fernet token\nprovider encodes methods as a bitmask of [auth] methods, so the marker\nwas silently dropped on the token payload round-trip: on any validation\nthat re-read the payload (cache miss, different process) the token\nlooked like it had been issued with no auth methods at all, and the\nguard that rejects such tokens from authorizing requests in Keystone\ncould not recognize them. A stolen EC2 or S3 access/secret key pair\ncould therefore be exchanged for a token and used to authorize\nrequests in Keystone.\n\nRegister ec2credential as a deliberately non-functional auth method so\nthe marker has a bit in the fernet methods bitmask and survives the\nround-trip, and is recognized as delegated-credential derived by all of\nthe guards that reject such tokens (Keystone authorization, token\nre-scoping, trust, application credential, and OAuth1 management). The\nplugin can never authenticate: EC2 and S3 credentials must still be\nexchanged at their respective endpoints, and attempts to authenticate\nvia /v3/auth/tokens are rejected with 401.\n\nThe method is appended to the end of the default [auth] methods list\non purpose: the fernet method bitmask is positional, so appending\npreserves the bits of all existing methods and existing tokens\ncontinue to validate.\n\nWhile the method is removed from [auth] methods, POST /v3/ec2tokens\nand POST /v3/s3tokens refuse to issue tokens (HTTP 503): a token\nminted without the marker would not be recognized as\ndelegated-credential derived on a token payload round-trip, so the\nendpoints fail closed rather than re-opening the vulnerability.\nOperators pinning an explicit methods list must add the method after\nupgrading.\n\nAlso ensure ec2credential can never be reclassified as a primary auth\nmethod via [auth] additional_primary_auth_methods, which would\notherwise silently re-open the rescope path the guards block.\n\nThe notes in OSSA-2026-037 defer the EC2/S3 credential handling\nweakness to a separate advisory; this change is that fix.\n\nRelated-bug: #2153453\nAssisted-by: Qwen-3.8\nChange-Id: I520f24617c8ec16e2d007e13e3fff99944e71260\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/01d2950788e59dc59c7eb841fa7f9253ef81e315"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/01d2950788e59dc59c7eb841fa7f9253ef81e315"}]},"branch":"refs/heads/master"},"0e2166742f7749d8f93200b4ccd995347912b4fa":{"kind":"REWORK","_number":4,"created":"2026-09-14 15:37:05.000000000","uploader":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"},"ref":"refs/changes/69/1005069/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/1005069/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/1005069/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/1005069/4"}}},"commit":{"parents":[{"commit":"5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8","subject":"Merge \"Use common environment classifier\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5dfe76e36c3f91ee29065d8c5bce0b5b04ae73c8"}]}],"author":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-10 15:02:59.000000000","tz":120},"committer":{"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","date":"2026-09-14 14:27:23.000000000","tz":120},"subject":"feat: Register ec2credential as a marker auth method","message":"feat: Register ec2credential as a marker auth method\n\nTokens minted from an EC2 or S3 credential exchange (POST /v3/ec2tokens\nor POST /v3/s3tokens) have always recorded the ec2credential auth\nmethod, which was never a registered auth method. The fernet token\nprovider encodes methods as a bitmask of [auth] methods, so the marker\nwas silently dropped on the token payload round-trip: on any validation\nthat re-read the payload (cache miss, different process) the token\nlooked like it had been issued with no auth methods at all, and the\nguard that rejects such tokens from authorizing requests in Keystone\ncould not recognize them. A stolen EC2 or S3 access/secret key pair\ncould therefore be exchanged for a token and used to authorize\nrequests in Keystone.\n\nRegister ec2credential as a deliberately non-functional auth method so\nthe marker has a bit in the fernet methods bitmask and survives the\nround-trip, and is recognized as delegated-credential derived by all of\nthe guards that reject such tokens (Keystone authorization, token\nre-scoping, trust, application credential, and OAuth1 management). The\nplugin can never authenticate: EC2 and S3 credentials must still be\nexchanged at their respective endpoints, and attempts to authenticate\nvia /v3/auth/tokens are rejected with 401.\n\nThe method is appended to the end of the default [auth] methods list\non purpose: the fernet method bitmask is positional, so appending\npreserves the bits of all existing methods and existing tokens\ncontinue to validate.\n\nWhile the method is removed from [auth] methods, POST /v3/ec2tokens\nand POST /v3/s3tokens refuse to issue tokens (HTTP 503): a token\nminted without the marker would not be recognized as\ndelegated-credential derived on a token payload round-trip, so the\nendpoints fail closed rather than re-opening the vulnerability.\nOperators pinning an explicit methods list must add the method after\nupgrading.\n\nAlso ensure ec2credential can never be reclassified as a primary auth\nmethod via [auth] additional_primary_auth_methods, which would\notherwise silently re-open the rescope path the guards block.\n\nThe notes in OSSA-2026-037 defer the EC2/S3 credential handling\nweakness to a separate advisory; this change is that fix.\n\nRelated-bug: #2153453\nAssisted-by: Qwen-3.8\nChange-Id: I520f24617c8ec16e2d007e13e3fff99944e71260\nSigned-off-by: Artem Goncharov \u003cartem.goncharov@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/0e2166742f7749d8f93200b4ccd995347912b4fa"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/0e2166742f7749d8f93200b4ccd995347912b4fa"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":27900,"name":"Artem Goncharov","email":"artem.goncharov@gmail.com","username":"gtema"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
