)]}'
{"id":"openstack%2Fkeystone~677239","triplet_id":"openstack%2Fkeystone~master~Id00db3f303f45daf0e25be1f1bcf6a8834cb3ea7","project":"openstack/keystone","branch":"master","topic":"bug/1840647","hashtags":[],"change_id":"Id00db3f303f45daf0e25be1f1bcf6a8834cb3ea7","subject":"Fix caching behavior","status":"ABANDONED","created":"2019-08-19 15:46:27.000000000","updated":"2020-03-17 20:31:54.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"5f3ada49553b6d5ac2f1fa9e06f492b8b6fb5180","_number":677239,"virtual_id_number":677239,"owner":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"date":"2019-09-26 12:43:15.000000000","_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":13063,"name":"WEI CHEN","email":"dave.jungler@gmail.com","username":"wei.d.chen"},{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":-1,"date":"2019-08-26 11:01:13.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":15054,"name":"wangxiyuan","email":"wangxiyuan1007@gmail.com","username":"wangxiyuan"},{"_account_id":11022,"name":"Rodrigo Duarte Sousa","email":"rodrigodsousa@gmail.com","username":"rodrigods"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":13063,"name":"WEI CHEN","email":"dave.jungler@gmail.com","username":"wei.d.chen"},{"value":0,"date":"2020-01-30 09:14:48.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":15054,"name":"wangxiyuan","email":"wangxiyuan1007@gmail.com","username":"wangxiyuan"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":11022,"name":"Rodrigo Duarte Sousa","email":"rodrigodsousa@gmail.com","username":"rodrigods"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"value":0,"date":"2019-09-11 11:06:16.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"permitted_voting_range":{"min":-1,"max":0},"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},{"date":"2019-09-11 11:06:16.000000000","_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"date":"2019-09-11 11:06:16.000000000","_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"date":"2019-09-11 11:06:16.000000000","_account_id":13063,"name":"WEI CHEN","email":"dave.jungler@gmail.com","username":"wei.d.chen"},{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},{"date":"2019-09-26 15:24:08.000000000","_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"date":"2019-09-11 11:06:16.000000000","_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"date":"2019-09-11 11:06:16.000000000","_account_id":15054,"name":"wangxiyuan","email":"wangxiyuan1007@gmail.com","username":"wangxiyuan"},{"date":"2019-09-11 11:06:16.000000000","_account_id":11022,"name":"Rodrigo Duarte Sousa","email":"rodrigodsousa@gmail.com","username":"rodrigods"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},{"_account_id":11022,"name":"Rodrigo Duarte Sousa","email":"rodrigodsousa@gmail.com","username":"rodrigods"},{"_account_id":13063,"name":"WEI CHEN","email":"dave.jungler@gmail.com","username":"wei.d.chen"},{"_account_id":15054,"name":"wangxiyuan","email":"wangxiyuan1007@gmail.com","username":"wangxiyuan"},{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2019-08-26 11:01:13.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2019-09-11 11:06:16.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"state":"REVIEWER"},{"updated":"2019-09-11 11:06:16.000000000","updated_by":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"reviewer":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"state":"REVIEWER"},{"updated":"2019-09-11 11:06:16.000000000","updated_by":{"_account_id":11022,"name":"Rodrigo Duarte Sousa","email":"rodrigodsousa@gmail.com","username":"rodrigods"},"reviewer":{"_account_id":11022,"name":"Rodrigo Duarte Sousa","email":"rodrigodsousa@gmail.com","username":"rodrigods"},"state":"REVIEWER"},{"updated":"2019-09-11 11:06:16.000000000","updated_by":{"_account_id":13063,"name":"WEI CHEN","email":"dave.jungler@gmail.com","username":"wei.d.chen"},"reviewer":{"_account_id":13063,"name":"WEI CHEN","email":"dave.jungler@gmail.com","username":"wei.d.chen"},"state":"REVIEWER"},{"updated":"2019-09-11 11:06:16.000000000","updated_by":{"_account_id":15054,"name":"wangxiyuan","email":"wangxiyuan1007@gmail.com","username":"wangxiyuan"},"reviewer":{"_account_id":15054,"name":"wangxiyuan","email":"wangxiyuan1007@gmail.com","username":"wangxiyuan"},"state":"REVIEWER"},{"updated":"2019-09-11 11:06:16.000000000","updated_by":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"reviewer":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"state":"REVIEWER"},{"updated":"2019-09-11 11:06:16.000000000","updated_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"reviewer":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"state":"REVIEWER"},{"updated":"2019-09-26 15:24:08.000000000","updated_by":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"reviewer":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"state":"REVIEWER"},{"updated":"2020-01-30 09:14:48.000000000","updated_by":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"reviewer":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"state":"REVIEWER"}],"messages":[{"id":"bfceb7a6d6e7aa2ba1dbb484c024b8b832d7a478","author":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"date":"2019-08-19 15:46:27.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"12e2123fa3dca09c4739eee9b8efa15de7b7db1a","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-08-19 18:15:44.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/452e9ec83a19429f91b90573f8d1b0cb : SUCCESS in 32m 47s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/2d68ec7f4b2043e483079de8421f3149 : SUCCESS in 41m 18s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/88bde37c5b5441dcbbd121598756ae55 : FAILURE in 5m 46s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/3616ecb7af984b26ac8efb9b29b42f14 : SUCCESS in 40m 41s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/cb22e14c045a469880e686955711d5a8 : SUCCESS in 27m 11s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/44fb79f750e3474eb3bb9796e438787b : SUCCESS in 28m 49s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c2e6c154fa9249d796a2494cc11eda0c : SUCCESS in 9m 03s\n- tempest-full https://zuul.opendev.org/t/openstack/build/4d05a7733e4944f59c10c26640c21992 : SUCCESS in 1h 37m 35s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/6962c86da3ab4e5c9d3e68ff0a181538 : SUCCESS in 58m 38s\n- grenade-py3 https://zuul.opendev.org/t/openstack/build/8a913ab7d43545b7a2544221c79ee8ba : SUCCESS in 1h 04m 58s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/6b565a12948741c3a75667a0bb39ad8b : SUCCESS in 1h 30m 39s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/8f2870cc845140c88a5d005ed01c5863 : SUCCESS in 40m 34s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/cbb24d6fcded4f0eb7b936da3c8982bd : SUCCESS in 40m 05s\n- keystone-dsvm-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/3eb0b6253e5c4f619c0db8513713ec0b : SUCCESS in 43m 05s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/d15fcab77abb46bf8fbe783f6e69cd41 : SUCCESS in 41m 05s (non-voting)\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/571d78020bde40668e0edefa5db2df0a : SUCCESS in 18m 07s (non-voting)\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/e7c15c8b53254ae99a85811af3120f36 : SUCCESS in 1h 51m 07s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/f57beb2afad841f88e6c73479dc85afa : SUCCESS in 1h 06m 32s","accounts_in_message":[],"_revision_number":1},{"id":"a52d447c22c8200f0d96d8696bd2adf731bb7dcb","author":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"date":"2019-08-19 18:24:46.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"726cbe6dcf763e1e7e30bf7c8677a284425e6089","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-08-19 19:47:00.000000000","message":"Patch Set 2: Code-Review-2\n\nThere should NEVER be a cached response of the decrypted data. If you are running into an issue where the data is being passed through decrypt it means we are caching unencrypted data.\n\nPlease see my comments on https://review.opendev.org/#/c/676991 . I am marking this as a -2. Please update 676991 instead of creating a new review. You can amend (git --amend) your previous change and push it, it will instead of creating a new review, update the previous one, see https://docs.openstack.org/contributors/code-and-documentation/using-gerrit.html#pushing-a-change for more information.","accounts_in_message":[],"_revision_number":2},{"id":"2e71fd6b0329ddbb7a99d0f935ba5d43c6a7a14c","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-08-19 19:47:16.000000000","message":"Patch Set 2:\n\nYou can use the git commit --amend for the commit message as well.","accounts_in_message":[],"_revision_number":2},{"id":"2a1e726d7b7719bd71daf893447277f5cb19e1c4","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-08-19 21:52:57.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/2200aeaceae24a8c84962ed7ffff4ca2 : SUCCESS in 39m 40s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/8a47fdb0aee74f5fa0638ff604db4c34 : SUCCESS in 30m 59s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e921549de03a4935b979bd26831ee109 : SUCCESS in 5m 30s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/615205cd05c64be8bc58c1f1345f3cd0 : SUCCESS in 30m 40s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/7bcaf6e446f9407db970aa90e4a76b78 : SUCCESS in 26m 35s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/2e54622e86b84052a8f032a6ed882bf5 : SUCCESS in 28m 37s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/895b3ed6c71444569ceb9c40709096e6 : SUCCESS in 11m 28s\n- tempest-full https://zuul.opendev.org/t/openstack/build/9006ad4c8da1442fbaf96b28fa7b7c77 : SUCCESS in 1h 47m 35s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/5636a1681e5e43a8a390665d290c9c7d : SUCCESS in 1h 14m 00s\n- grenade-py3 https://zuul.opendev.org/t/openstack/build/2976bbf90f684ec8adf0879d0fa3963b : SUCCESS in 1h 13m 19s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/8bc7c309c0d04ee880ea6717dd34a8a7 : SUCCESS in 1h 21m 17s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/b8ec7adfdfbb4234853993166feb9993 : SUCCESS in 31m 51s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/04092d3554bb44c9873fc8ff2cc82c55 : SUCCESS in 34m 20s\n- keystone-dsvm-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/356be9d7a13e4d828044ae8d32c66d6c : SUCCESS in 34m 31s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/f7e81ca2fced4ca88478061c744ae193 : SUCCESS in 40m 10s (non-voting)\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/429cebce243c4567a242d342723a5e74 : SUCCESS in 26m 07s (non-voting)\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/a1152f545acd414c815ff2be1a64519e : SUCCESS in 1h 30m 47s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/a23b312e774145d3855d5f3ef92385dc : SUCCESS in 1h 06m 14s","accounts_in_message":[],"_revision_number":2},{"id":"14f1f3749740e57c22096787c6a7f44e4465e912","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-20 09:12:34.000000000","message":"Patch Set 2:\n\nHi Morgan, I think that two previous can be abandoned - this one incorporates all required changes and has UT green.","accounts_in_message":[],"_revision_number":2},{"id":"924589f65d2648a8eae0d7b4f649ffe1813cf590","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-20 10:22:12.000000000","message":"Patch Set 2: Code-Review+1\n\n@Morgan - here we have dependent review that passed https://review.opendev.org/#/c/676894/","accounts_in_message":[],"_revision_number":2},{"id":"f6d7b57e6b7070d8007772a9de6acb096080943b","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-08-23 16:17:08.000000000","message":"Patch Set 2:\n\nAs stated in my email here is an outline of the -2 and what needs to be fixed for this to merge:\n\n1) This -2 was because there was a previous review that could have solved the problem with a -1 and comments on it (Actionable commentS). The -2 here was to encourage continued use of the previous review and avoid the appearance that a new review was spun up to avoid the -1 and comments\n\n2) To remove the -2 (now) and move beyond a -1, the core issue is that we are potentially caching unencrypted data (which by policy must support being encrypted at rest and the cache is in many cases considered data \"at rest\"). The fix, instead of a copy is to ensure that we never cache unencrypted data and only pass through the decrypt method once.\n\nIn short, this fix cannot land as is, it breaks potential security considerations around the credentials and cache. I\u0027ll walk back the -2 once the code can show there is no potential caching of decrypted credentials.","accounts_in_message":[],"_revision_number":2},{"id":"ec01c1005860eb498990ac183b31f1637c8ce912","author":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"date":"2019-08-23 18:35:40.000000000","message":"Patch Set 2:\n\nI think there is misunderstanding.\n\n\nThe credentials are already stored in cache in plain text after the first decryption: I elaborate on this on LaunchPad (with logs). This happens because the actual cached object in memory gets modified during decryption. This fix actually makes them to be stored only in ecrypted way by working with the copy of the cached object instead. This way the credentials are always encrypted and not modified in cache and they get decrypted at runtime if needed, encorporating your comments.\n\n\n\nThe simpified version of algorithm before the fix is like that:\n1. The credentials are retrieved from the database by backend and the result is cached\n2. Credentials get decrypted: they are modified IN-PLACE by _decrypt_credential \u003d\u003e the actual cached object in memory gets changed so now the PLAIN TEXT is cached\n3. During the second and subsequent calls the cached database response is used BUT the actual object in memory was modified in-place on step 2\n4. The attempt of re-decryption of cached plain text is happening and the _decrypt_credential fails with Key Error\n\n\nThe fix just changes step 2, now the sequence of actions looks like this:\n1. The credentials are retrieved from the database by backend and the result is cached\n2. Credentials get decrypted: the COPY of credentials is modified and returned by _decrypt_credential \u003d\u003e the actual cached object in memory does NOT get changed\n3. During the second and subsequent calls the cached database response is used\n4. The cached encrypted credential gets decrypted fine, no fails\n\n\nSo, the problem is due to in-place manipulation on the credential dictionary object. Changing the _decrypt_credential method to work on the copy of the object solves it (and is also in line with how _encrypt_credential work). Now the actual cached encrypted credentials are not edited in any way after caching and now no caching of plain text data is happening which I guess is what we all want.\nSo, the fix does just exactly what you mentioned in your comments. It ensures no plain text credentials are cached, instead each time they are decrypted at runtime from the cached encrypted version.","accounts_in_message":[],"_revision_number":2},{"id":"bac8f824c3124ca504332cc7f2172252e6e87b8a","author":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"date":"2019-08-26 09:05:38.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"c5548819d709449568d1f76f061462d32f42e189","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-26 09:10:24.000000000","message":"Patch Set 3: Code-Review+1","accounts_in_message":[],"_revision_number":3},{"id":"ded547c951bb67a5c775b9ef231f6c8245a381f5","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-08-26 11:01:13.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/b34e69b90f7e451ca573780bdc80fe45 : TIMED_OUT in 51m 47s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/8e7a741613354edea0b346bbf51863dc : TIMED_OUT in 41m 50s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/9d11ddf5f9254a2e9ea6c05b63678724 : SUCCESS in 9m 01s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/ae80e3e7370b4f32a31c621cb08e9dbe : TIMED_OUT in 41m 49s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/6a15e63a911a4fa9a5e58ca2936ec555 : TIMED_OUT in 41m 45s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/c5081ca0cf1345969d6661ed253d4f3f : SUCCESS in 37m 36s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/fe7424b520784e1eadc3aa45fa7767d8 : SUCCESS in 11m 56s\n- tempest-full https://zuul.opendev.org/t/openstack/build/aa2b3477d1d646c69ecff1edbe7366b2 : SUCCESS in 1h 54m 01s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/0a0539c4c1204752b3240f9fa28a343d : SUCCESS in 1h 04m 49s\n- grenade-py3 https://zuul.opendev.org/t/openstack/build/6871977c118047619c6efff7cebba6d5 : SUCCESS in 1h 02m 53s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/ec14140bce5f47df89f534967c59b6d0 : SUCCESS in 1h 35m 07s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/6ab8293db17f4846a6be718318994a9d : SUCCESS in 13m 28s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/1b7aa186f6e54cba816930ede6c649cf : SUCCESS in 36m 28s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/37efffa2f5bc4ef5997896611a43c723 : SUCCESS in 35m 32s\n- keystone-dsvm-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/3fd4a255ec2f4bdfa844685067e424bf : RETRY_LIMIT in 3m 32s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/343e201a23b84cdd97b4f5b9c037a928 : RETRY_LIMIT in 5m 27s (non-voting)\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/2ff0216deb38471babd897c7f4e8d2f0 : SUCCESS in 20m 17s (non-voting)\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/fdc4508e8860450890e05e412fe68e56 : SUCCESS in 1h 25m 27s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/e30a4a70c3e54e359804c338527f0cd8 : SUCCESS in 1h 31m 26s","accounts_in_message":[],"_revision_number":3},{"id":"1c244965053fc601bfc75e37d3c69e66e4922d8f","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-26 11:48:20.000000000","message":"Patch Set 3:\n\nrecheck","accounts_in_message":[],"_revision_number":3},{"id":"76f4dbbb4c19b4c2662b019a8126da54026678b4","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-08-26 13:35:38.000000000","message":"Patch Set 3:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/14a2059da6d544ab8043c4ba7f67e46d : SUCCESS in 38m 23s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/a16a099c0ebd4a51b2241e89971271ec : TIMED_OUT in 41m 34s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e6539026425e4268aeeb32bf76eaacd0 : SUCCESS in 6m 25s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/4ebc90a178b74d50b66b1e4b2e3c50d4 : SUCCESS in 29m 17s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/5bb3821abcf3433c9d608bf1488ae244 : SUCCESS in 33m 01s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/f5fcc60642a146379c0828181ad80c73 : SUCCESS in 37m 25s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/6f6ecbe4e9bb456082b5328d03af6f68 : SUCCESS in 12m 47s\n- tempest-full https://zuul.opendev.org/t/openstack/build/61daa3f9102e416aa68f135cfeaf1a36 : SUCCESS in 1h 24m 55s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/b4754dfbab9448c5bff93975d005bff6 : SUCCESS in 1h 01m 32s\n- grenade-py3 https://zuul.opendev.org/t/openstack/build/754c95327d3842f2a92b9e1b94776322 : SUCCESS in 1h 01m 43s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/cbccc889c7374231bb3ffd9e7b89b863 : SUCCESS in 1h 33m 15s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/2e6dcad819c54db5a48ea2e7328b6f95 : SUCCESS in 11m 24s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/1a05e6514e114c7a94793d1093feb4b9 : SUCCESS in 31m 46s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/c9212e249df240c287d58b073132b38c : SUCCESS in 30m 27s\n- keystone-dsvm-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/defde404691f48f48e83871191fc3580 : RETRY_LIMIT in 4m 00s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/c6d260e46ac64679985ef7532ac78c01 : RETRY_LIMIT in 4m 05s (non-voting)\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/50c340f1b14b40bca43735538f44d516 : SUCCESS in 15m 27s (non-voting)\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/b1151e98b4b1455391ac7a31f465605b : SUCCESS in 1h 31m 20s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/ed536fbc639f4252bd9967606433180c : SUCCESS in 1h 02m 16s","accounts_in_message":[],"_revision_number":3},{"id":"688d5d21579b50f7611adb5fee89051d427d75a8","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-26 13:53:19.000000000","message":"Patch Set 3:\n\nrecheck","accounts_in_message":[],"_revision_number":3},{"id":"56ff1ad671500e850b0992752d16380125457699","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-08-26 17:09:21.000000000","message":"Patch Set 3:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f0b62b336fe04f9ea84880246354fc28 : SUCCESS in 42m 36s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/113704fb721b4c18b6af58121a20318e : TIMED_OUT in 41m 31s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/cd9cfcc54a1240e389e6c95a5a78cd0e : SUCCESS in 6m 46s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/717341151cca433d9cde9602b2e96fb7 : SUCCESS in 37m 10s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/3021f3e9785043a9ab3c2a298d9d63bc : SUCCESS in 29m 31s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/ccc1e805da3342b8b350026e929ce4b5 : SUCCESS in 31m 02s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/abb5bb2975b446b780efddfa7d9ad7c0 : SUCCESS in 12m 07s\n- tempest-full https://zuul.opendev.org/t/openstack/build/2ce983ccb1e7423e8569ee2801082fb1 : SUCCESS in 1h 36m 40s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/2555906727c14f7eaee7cffbe8bc8594 : SUCCESS in 1h 10m 37s\n- grenade-py3 https://zuul.opendev.org/t/openstack/build/ea39bf8149304ddda715aa250aec354b : SUCCESS in 1h 10m 47s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/440836a8f1a1415ebe6dd1a0dd540e8e : SUCCESS in 1h 50m 06s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/eef1510ade774a94a0100088c735075b : SUCCESS in 14m 54s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/3afae311732343879aa90e0d2e9aabc7 : SUCCESS in 34m 44s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/7534ebe9911942a794a4b176a5177295 : SUCCESS in 34m 55s\n- keystone-dsvm-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/c4eb761e4ab84bcd9564e94996a6f9c7 : RETRY_LIMIT in 5m 34s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/9d29db8f042047d582a744c405f894c9 : RETRY_LIMIT in 3m 34s (non-voting)\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/8e87800cc1d348e3a6ebf81a10d1984a : SUCCESS in 21m 31s (non-voting)\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/b556f2794b7f4b55a80b20550992b2eb : SUCCESS in 1h 45m 41s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/ae1c51a9f2914666a8d8ee0e393225ad : SUCCESS in 1h 08m 05s","accounts_in_message":[],"_revision_number":3},{"id":"31ae35028a1702960f65190c4e043af426817bff","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-08-26 17:09:41.000000000","message":"Patch Set 3:\n\nCorrect. The previous fix was intended to avoid caching plain text credentials. This bug is fixed by addressing the core issue, plain text credentials are being cached. \n\nFix the issue with caching plain text credentials, cached data should always be passed through the decrypt function. The issue here is that we are caching incorrect information.","accounts_in_message":[],"_revision_number":3},{"id":"01314511a7a3854c32177c04f60c2750e8c87f9c","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-08-26 17:14:36.000000000","message":"Patch Set 3:\n\nIf you are using in-memory (dict-based) cache and this is the genesis of the bug, this is simply a \"wont fix\", and we are pretty deep into the weeds; dict (in-memory backend) should never be used. Even in devstack we use a proper memcache server. The way the caching code is intended to work is as follows:\n\nThread Local cache is intended to be msgpacked, and deserialized as needed. This ensures there is no in-place code changes (we are inherently working with copies). External cache (memcache) is not within the keystone process and cannot be modified directly only with a set/multiset/etc.\n\nIf the issue is that we have plain-text cached data in the thread-local cache or the external memcache, the fix is to ensure we never cache plain-text data. On render (to json) from the API decrypt is intended to be called.","accounts_in_message":[],"_revision_number":3},{"id":"70081d21917f7cbd2c351daf1373391dd3d271fc","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-08-26 18:16:44.000000000","message":"Patch Set 3:\n\nI\u0027m digging more into the code to try and see what is going on here. I was following the code and there is no case we should be modifying in memory.\n\nCan you provide more information about the setup so that we can explicitly correct the problem (e.g. in-memory cache and documentation if needed). We need to be extra sure we\u0027re NEVER caching the plain-text version.","accounts_in_message":[],"_revision_number":3},{"id":"e5c99ed73b41bbaff0422afa9ba199d1b8f8e5ec","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-26 18:39:50.000000000","message":"Patch Set 3:\n\n\u003e I\u0027m digging more into the code to try and see what is going on\n \u003e here. I was following the code and there is no case we should be\n \u003e modifying in memory.\n \u003e \n \u003e Can you provide more information about the setup so that we can\n \u003e explicitly correct the problem (e.g. in-memory cache and\n \u003e documentation if needed). We need to be extra sure we\u0027re NEVER\n \u003e caching the plain-text version.\n\nHi Morgan,\nThis is an ordinary devstack (keystone, nova, cinder, glance, neutron) + ec2-api plugin.\nIn patchset #1 problem was observed - https://review.opendev.org/#/c/676894/ (in functional job logs).\n\nthe first test just calls \u0027aws ec2 describe-images\u0027 several times.\n\n- this call goes to ec2-api plugin with signature (signed by botocore library from AWS)\n- ec2-api plugin takes creds (access_key and check sum) from request and passes them to keystone to check.\n- keystone check creds. it returns OK from first request and then it returns error from next requests.\n\nsecond patchset of that review has dependency to this one and passed well.","accounts_in_message":[],"_revision_number":3},{"id":"cd563a3c4d559d190f9fe50c1b09484b57d13123","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-29 16:29:46.000000000","message":"Patch Set 3:\n\nHi @Morgan,\nHave you had a chance to look into this again?\nWas my answer clear enough  or I need to provide more details?","accounts_in_message":[],"_revision_number":3},{"id":"d7347c8205080c664d269d972187aa033295f126","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-08-29 16:33:42.000000000","message":"Patch Set 3:\n\nYes, it\u0027s clear enough. I\u0027m working through the code to identify how we\u0027re caching plain-text. Again, the solution is not to cache plain-text ever. Not to do the copy.","accounts_in_message":[],"_revision_number":3},{"id":"20a766fc3d873edd07612c0dd5cdff45895c9b57","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-08-29 16:37:22.000000000","message":"Patch Set 3:\n\nThank you Morgan. Please let me know if you\u0027ll need some info/help for this bug.","accounts_in_message":[],"_revision_number":3},{"id":"1887d5d6e3cb1a0439f40e5331e848527d6a703f","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-09-05 14:33:51.000000000","message":"Patch Set 3:\n\nHi Morgan,\nMay I ask you about news on this?","accounts_in_message":[],"_revision_number":3},{"id":"f340124c76ac889256f1ae9a8ec9b4fae86df812","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-09-09 18:28:27.000000000","message":"Patch Set 3: Code-Review-1\n\ndowngrading to a -1, specifically so that someone can continue the work without needing me to remove a -2. I\u0027m having a hard time figuring out where the plain-text cache is happening.\n\nI expect this to continue to take more time.","accounts_in_message":[],"_revision_number":3},{"id":"ec80a4ea48f193f8b1ed18d2a10c075d698e89df","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-09-13 08:52:09.000000000","message":"Patch Set 3:\n\nHi guys,\nIs it possible to spend some time on this? Otherwise EC2 functionality will be broken in next release.","accounts_in_message":[],"_revision_number":3},{"id":"0e27501de08fb7c66d75a4abadd3fc241356cdfb","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2019-09-13 22:32:35.000000000","message":"Patch Set 3:\n\nI am unable to reproduce the problem in devstack. See\n\nhttps://bugs.launchpad.net/keystone/+bug/1840647/comments/3\n\nCan you please share your configuration and steps to reproduce the problem?","accounts_in_message":[],"_revision_number":3},{"id":"71a24e8beed7ecf01671f953ecbbd6660cb90ff5","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-09-25 16:53:43.000000000","message":"Patch Set 3:\n\nguys, functionality  of ec2-api will be useless with out this pathset. can you please review this?\ncan you let us know how we can help?","accounts_in_message":[],"_revision_number":3},{"id":"b02687a00724c1020556bd702dd684b6d13361dd","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2019-09-25 17:25:54.000000000","message":"Patch Set 3:\n\n\u003e guys, functionality  of ec2-api will be useless with out this\n \u003e pathset. can you please review this?\n \u003e can you let us know how we can help?\n\nCan you please let us know how to reproduce this problem in devstack?\nAnd have some unit/functional tests to guard your fix?","accounts_in_message":[],"_revision_number":3},{"id":"4274b610b7365f8a15eb9ff101a29db88666748a","author":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"date":"2019-09-25 22:33:07.000000000","message":"Patch Set 3:\n\n\u003e \u003e guys, functionality  of ec2-api will be useless with out this\n \u003e \u003e pathset. can you please review this?\n \u003e \u003e can you let us know how we can help?\n \u003e \n \u003e Can you please let us know how to reproduce this problem in\n \u003e devstack?\n \u003e And have some unit/functional tests to guard your fix?\n\nCopying my reply from launchpad:\n\nI was testing with describe-images and other commands seen in functional\ntests in particular, not sure how \u0027credentials list\u0027 works. Please see this\nhttps://review.opendev.org/#/c/676894\nYou could execute the \u0027create_config\u0027 script from this change and you\nsholud see the same failure as in Zuul logs for this job. It uses aws-cli\nbut the partucular client does not matter - the functional tests use boto\nlibrary and also fail.\n\nсб, 14 сент. 2019, 1:41 Guang Yee \u003c1840647@bugs.launchpad.net\u003e:","accounts_in_message":[],"_revision_number":3},{"id":"330a0dfcd8f8fd4d70249cd7943e6ba5d2c095df","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2019-09-25 22:55:13.000000000","message":"Patch Set 3:\n\n\u003e \u003e \u003e guys, functionality  of ec2-api will be useless with out this\n \u003e \u003e \u003e pathset. can you please review this?\n \u003e \u003e \u003e can you let us know how we can help?\n \u003e \u003e\n \u003e \u003e Can you please let us know how to reproduce this problem in\n \u003e \u003e devstack?\n \u003e \u003e And have some unit/functional tests to guard your fix?\n \u003e \n \u003e Copying my reply from launchpad:\n \u003e \n \u003e I was testing with describe-images and other commands seen in\n \u003e functional\n \u003e tests in particular, not sure how \u0027credentials list\u0027 works. Please\n \u003e see this\n \u003e https://review.opendev.org/#/c/676894\n \u003e You could execute the \u0027create_config\u0027 script from this change and\n \u003e you\n \u003e sholud see the same failure as in Zuul logs for this job. It uses\n \u003e aws-cli\n \u003e but the partucular client does not matter - the functional tests\n \u003e use boto\n \u003e library and also fail.\n \u003e \n \u003e сб, 14 сент. 2019, 1:41 Guang Yee \u003c1840647@bugs.launchpad.net\u003e:\n\nI did inspect the Keystone API access logs from https://review.opendev.org/#/c/676894 and I don\u0027t see any evidence of Keystone ec2token or credential API calls.\n\nhttps://4d7bdee1bcd63b36fcfd-ff49463e30b903e99104e49c0188b366.ssl.cf2.rackcdn.com/676894/3/check/ec2-api-functional-neutron/b4aad4c/logs/apache/access.txt.gz\n\nI am not convinced the failure you are experiencing is related to Keystone at this point.","accounts_in_message":[],"_revision_number":3},{"id":"e453eb99cb6bd87a7e119dd90c8fa7295cc11a05","author":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"date":"2019-09-26 12:43:15.000000000","message":"Patch Set 3:\n\n\u003e \u003e \u003e \u003e guys, functionality  of ec2-api will be useless with out this\n \u003e \u003e \u003e \u003e pathset. can you please review this?\n \u003e \u003e \u003e \u003e can you let us know how we can help?\n \u003e \u003e \u003e\n \u003e \u003e \u003e Can you please let us know how to reproduce this problem in\n \u003e \u003e \u003e devstack?\n \u003e \u003e \u003e And have some unit/functional tests to guard your fix?\n \u003e \u003e\n \u003e \u003e Copying my reply from launchpad:\n \u003e \u003e\n \u003e \u003e I was testing with describe-images and other commands seen in\n \u003e \u003e functional\n \u003e \u003e tests in particular, not sure how \u0027credentials list\u0027 works.\n \u003e Please\n \u003e \u003e see this\n \u003e \u003e https://review.opendev.org/#/c/676894\n \u003e \u003e You could execute the \u0027create_config\u0027 script from this change and\n \u003e \u003e you\n \u003e \u003e sholud see the same failure as in Zuul logs for this job. It uses\n \u003e \u003e aws-cli\n \u003e \u003e but the partucular client does not matter - the functional tests\n \u003e \u003e use boto\n \u003e \u003e library and also fail.\n \u003e \u003e\n \u003e \u003e сб, 14 сент. 2019, 1:41 Guang Yee \u003c1840647@bugs.launchpad.net\u003e:\n \u003e \n \u003e I did inspect the Keystone API access logs from https://review.opendev.org/#/c/676894\n \u003e and I don\u0027t see any evidence of Keystone ec2token or credential API\n \u003e calls.\n \u003e \n \u003e https://4d7bdee1bcd63b36fcfd-ff49463e30b903e99104e49c0188b366.ssl.cf2.rackcdn.com/676894/3/check/ec2-api-functional-neutron/b4aad4c/logs/apache/access.txt.gz\n \u003e \n \u003e I am not convinced the failure you are experiencing is related to\n \u003e Keystone at this point.\n\nPlease take a look at the logs here https://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_d9c/680481/1/check/ec2-api-functional-neutron/d9c3627/logs/\nThese logs are from the change that basically just turns the tests back on (without any fixes or preliminary checks). I see some keystone-related 500 errors in logs and also the same traceback as the one I posted on Launchpad.","accounts_in_message":[],"_revision_number":3},{"id":"853fffbfb7c16426918774bb189e74b4c82c91aa","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2019-09-26 15:24:08.000000000","message":"Patch Set 3:\n\n\u003e \u003e \u003e \u003e \u003e guys, functionality  of ec2-api will be useless with out\n \u003e this\n \u003e \u003e \u003e \u003e \u003e pathset. can you please review this?\n \u003e \u003e \u003e \u003e \u003e can you let us know how we can help?\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e Can you please let us know how to reproduce this problem in\n \u003e \u003e \u003e \u003e devstack?\n \u003e \u003e \u003e \u003e And have some unit/functional tests to guard your fix?\n \u003e \u003e \u003e\n \u003e \u003e \u003e Copying my reply from launchpad:\n \u003e \u003e \u003e\n \u003e \u003e \u003e I was testing with describe-images and other commands seen in\n \u003e \u003e \u003e functional\n \u003e \u003e \u003e tests in particular, not sure how \u0027credentials list\u0027 works.\n \u003e \u003e Please\n \u003e \u003e \u003e see this\n \u003e \u003e \u003e https://review.opendev.org/#/c/676894\n \u003e \u003e \u003e You could execute the \u0027create_config\u0027 script from this change\n \u003e and\n \u003e \u003e \u003e you\n \u003e \u003e \u003e sholud see the same failure as in Zuul logs for this job. It\n \u003e uses\n \u003e \u003e \u003e aws-cli\n \u003e \u003e \u003e but the partucular client does not matter - the functional\n \u003e tests\n \u003e \u003e \u003e use boto\n \u003e \u003e \u003e library and also fail.\n \u003e \u003e \u003e\n \u003e \u003e \u003e сб, 14 сент. 2019, 1:41 Guang Yee \u003c1840647@bugs.launchpad.net\u003e:\n \u003e \u003e\n \u003e \u003e I did inspect the Keystone API access logs from https://review.opendev.org/#/c/676894\n \u003e \u003e and I don\u0027t see any evidence of Keystone ec2token or credential\n \u003e API\n \u003e \u003e calls.\n \u003e \u003e\n \u003e \u003e https://4d7bdee1bcd63b36fcfd-ff49463e30b903e99104e49c0188b366.ssl.cf2.rackcdn.com/676894/3/check/ec2-api-functional-neutron/b4aad4c/logs/apache/access.txt.gz\n \u003e \u003e\n \u003e \u003e I am not convinced the failure you are experiencing is related to\n \u003e \u003e Keystone at this point.\n \u003e \n \u003e Please take a look at the logs here https://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_d9c/680481/1/check/ec2-api-functional-neutron/d9c3627/logs/\n \u003e These logs are from the change that basically just turns the tests\n \u003e back on (without any fixes or preliminary checks). I see some\n \u003e keystone-related 500 errors in logs and also the same traceback as\n \u003e the one I posted on Launchpad.\n\n \u003e \u003e \u003e \u003e \u003e guys, functionality  of ec2-api will be useless with out\n \u003e this\n \u003e \u003e \u003e \u003e \u003e pathset. can you please review this?\n \u003e \u003e \u003e \u003e \u003e can you let us know how we can help?\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e Can you please let us know how to reproduce this problem in\n \u003e \u003e \u003e \u003e devstack?\n \u003e \u003e \u003e \u003e And have some unit/functional tests to guard your fix?\n \u003e \u003e \u003e\n \u003e \u003e \u003e Copying my reply from launchpad:\n \u003e \u003e \u003e\n \u003e \u003e \u003e I was testing with describe-images and other commands seen in\n \u003e \u003e \u003e functional\n \u003e \u003e \u003e tests in particular, not sure how \u0027credentials list\u0027 works.\n \u003e \u003e Please\n \u003e \u003e \u003e see this\n \u003e \u003e \u003e https://review.opendev.org/#/c/676894\n \u003e \u003e \u003e You could execute the \u0027create_config\u0027 script from this change\n \u003e and\n \u003e \u003e \u003e you\n \u003e \u003e \u003e sholud see the same failure as in Zuul logs for this job. It\n \u003e uses\n \u003e \u003e \u003e aws-cli\n \u003e \u003e \u003e but the partucular client does not matter - the functional\n \u003e tests\n \u003e \u003e \u003e use boto\n \u003e \u003e \u003e library and also fail.\n \u003e \u003e \u003e\n \u003e \u003e \u003e сб, 14 сент. 2019, 1:41 Guang Yee \u003c1840647@bugs.launchpad.net\u003e:\n \u003e \u003e\n \u003e \u003e I did inspect the Keystone API access logs from https://review.opendev.org/#/c/676894\n \u003e \u003e and I don\u0027t see any evidence of Keystone ec2token or credential\n \u003e API\n \u003e \u003e calls.\n \u003e \u003e\n \u003e \u003e https://4d7bdee1bcd63b36fcfd-ff49463e30b903e99104e49c0188b366.ssl.cf2.rackcdn.com/676894/3/check/ec2-api-functional-neutron/b4aad4c/logs/apache/access.txt.gz\n \u003e \u003e\n \u003e \u003e I am not convinced the failure you are experiencing is related to\n \u003e \u003e Keystone at this point.\n \u003e \n \u003e Please take a look at the logs here https://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_d9c/680481/1/check/ec2-api-functional-neutron/d9c3627/logs/\n \u003e These logs are from the change that basically just turns the tests\n \u003e back on (without any fixes or preliminary checks). I see some\n \u003e keystone-related 500 errors in logs and also the same traceback as\n \u003e the one I posted on Launchpad.\n\nWhere are these logs coming from? I don\u0027t see them here https://review.opendev.org/#/c/676894.","accounts_in_message":[],"_revision_number":3},{"id":"5501c0c80daa331036b04702865b177ba2be49fd","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-09-26 16:23:16.000000000","message":"Patch Set 3:\n\n\u003e \u003e \u003e \u003e \u003e \u003e guys, functionality  of ec2-api will be useless with out\n \u003e \u003e this\n \u003e \u003e \u003e \u003e \u003e \u003e pathset. can you please review this?\n \u003e \u003e \u003e \u003e \u003e \u003e can you let us know how we can help?\n \u003e \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e \u003e Can you please let us know how to reproduce this problem in\n \u003e \u003e \u003e \u003e \u003e devstack?\n \u003e \u003e \u003e \u003e \u003e And have some unit/functional tests to guard your fix?\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e Copying my reply from launchpad:\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e I was testing with describe-images and other commands seen in\n \u003e \u003e \u003e \u003e functional\n \u003e \u003e \u003e \u003e tests in particular, not sure how \u0027credentials list\u0027 works.\n \u003e \u003e \u003e Please\n \u003e \u003e \u003e \u003e see this\n \u003e \u003e \u003e \u003e https://review.opendev.org/#/c/676894\n \u003e \u003e \u003e \u003e You could execute the \u0027create_config\u0027 script from this change\n \u003e \u003e and\n \u003e \u003e \u003e \u003e you\n \u003e \u003e \u003e \u003e sholud see the same failure as in Zuul logs for this job. It\n \u003e \u003e uses\n \u003e \u003e \u003e \u003e aws-cli\n \u003e \u003e \u003e \u003e but the partucular client does not matter - the functional\n \u003e \u003e tests\n \u003e \u003e \u003e \u003e use boto\n \u003e \u003e \u003e \u003e library and also fail.\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e сб, 14 сент. 2019, 1:41 Guang Yee \u003c1840647@bugs.launchpad.net\u003e:\n \u003e \u003e \u003e\n \u003e \u003e \u003e I did inspect the Keystone API access logs from\n \u003e https://review.opendev.org/#/c/676894\n \u003e \u003e \u003e and I don\u0027t see any evidence of Keystone ec2token or credential\n \u003e \u003e API\n \u003e \u003e \u003e calls.\n \u003e \u003e \u003e\n \u003e \u003e \u003e https://4d7bdee1bcd63b36fcfd-ff49463e30b903e99104e49c0188b366.ssl.cf2.rackcdn.com/676894/3/check/ec2-api-functional-neutron/b4aad4c/logs/apache/access.txt.gz\n \u003e \u003e \u003e\n \u003e \u003e \u003e I am not convinced the failure you are experiencing is related\n \u003e to\n \u003e \u003e \u003e Keystone at this point.\n \u003e \u003e\n \u003e \u003e Please take a look at the logs here https://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_d9c/680481/1/check/ec2-api-functional-neutron/d9c3627/logs/\n \u003e \u003e These logs are from the change that basically just turns the\n \u003e tests\n \u003e \u003e back on (without any fixes or preliminary checks). I see some\n \u003e \u003e keystone-related 500 errors in logs and also the same traceback\n \u003e as\n \u003e \u003e the one I posted on Launchpad.\n \u003e \n \u003e \u003e \u003e \u003e \u003e \u003e guys, functionality  of ec2-api will be useless with out\n \u003e \u003e this\n \u003e \u003e \u003e \u003e \u003e \u003e pathset. can you please review this?\n \u003e \u003e \u003e \u003e \u003e \u003e can you let us know how we can help?\n \u003e \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e \u003e Can you please let us know how to reproduce this problem in\n \u003e \u003e \u003e \u003e \u003e devstack?\n \u003e \u003e \u003e \u003e \u003e And have some unit/functional tests to guard your fix?\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e Copying my reply from launchpad:\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e I was testing with describe-images and other commands seen in\n \u003e \u003e \u003e \u003e functional\n \u003e \u003e \u003e \u003e tests in particular, not sure how \u0027credentials list\u0027 works.\n \u003e \u003e \u003e Please\n \u003e \u003e \u003e \u003e see this\n \u003e \u003e \u003e \u003e https://review.opendev.org/#/c/676894\n \u003e \u003e \u003e \u003e You could execute the \u0027create_config\u0027 script from this change\n \u003e \u003e and\n \u003e \u003e \u003e \u003e you\n \u003e \u003e \u003e \u003e sholud see the same failure as in Zuul logs for this job. It\n \u003e \u003e uses\n \u003e \u003e \u003e \u003e aws-cli\n \u003e \u003e \u003e \u003e but the partucular client does not matter - the functional\n \u003e \u003e tests\n \u003e \u003e \u003e \u003e use boto\n \u003e \u003e \u003e \u003e library and also fail.\n \u003e \u003e \u003e \u003e\n \u003e \u003e \u003e \u003e сб, 14 сент. 2019, 1:41 Guang Yee \u003c1840647@bugs.launchpad.net\u003e:\n \u003e \u003e \u003e\n \u003e \u003e \u003e I did inspect the Keystone API access logs from\n \u003e https://review.opendev.org/#/c/676894\n \u003e \u003e \u003e and I don\u0027t see any evidence of Keystone ec2token or credential\n \u003e \u003e API\n \u003e \u003e \u003e calls.\n \u003e \u003e \u003e\n \u003e \u003e \u003e https://4d7bdee1bcd63b36fcfd-ff49463e30b903e99104e49c0188b366.ssl.cf2.rackcdn.com/676894/3/check/ec2-api-functional-neutron/b4aad4c/logs/apache/access.txt.gz\n \u003e \u003e \u003e\n \u003e \u003e \u003e I am not convinced the failure you are experiencing is related\n \u003e to\n \u003e \u003e \u003e Keystone at this point.\n \u003e \u003e\n \u003e \u003e Please take a look at the logs here https://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_d9c/680481/1/check/ec2-api-functional-neutron/d9c3627/logs/\n \u003e \u003e These logs are from the change that basically just turns the\n \u003e tests\n \u003e \u003e back on (without any fixes or preliminary checks). I see some\n \u003e \u003e keystone-related 500 errors in logs and also the same traceback\n \u003e as\n \u003e \u003e the one I posted on Launchpad.\n \u003e \n \u003e Where are these logs coming from? I don\u0027t see them here\n \u003e https://review.opendev.org/#/c/676894.\n\nplease look here https://review.opendev.org/#/c/680481/","accounts_in_message":[],"_revision_number":3},{"id":"722820c8997af11cf18a94c390970b07e6813b7f","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2019-09-26 17:54:43.000000000","message":"Patch Set 3: Code-Review-2\n\nAs shown here:\n\nhttps://storage.gra1.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_d9c/680481/1/check/ec2-api-functional-neutron/d9c3627/logs/etc/keystone/keystone.conf.txt.gz\n\nYou are using \u0027backend \u003d oslo_cache.dict\u0027 this is no way is representative of any configuration that should be run in production. The dict backend will have odd edge cases and potential problems such as mutability of the cached data. The data is housed in-memory within the process.\n\nUse memcached.\n\nThis is not a bug.","accounts_in_message":[],"_revision_number":3},{"id":"2c64ecad3286152dbe819aaab1c688a7ef2a79dd","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2019-10-07 07:48:08.000000000","message":"Removed Code-Review+1 by Andrey Pavlov \u003candrey.mp@gmail.com\u003e\n","accounts_in_message":[],"_revision_number":3},{"id":"60ff26e7f4803a4e05cf4b64844f0358a1272862","author":{"_account_id":2903,"name":"Morgan Fainberg","email":"morgan.fainberg@gmail.com","username":"mdrnstm"},"date":"2020-01-28 17:16:24.000000000","message":"Removed reviewer Morgan Fainberg with the following votes:\n\n* Code-Review-2 by Morgan Fainberg \u003cmorgan.fainberg@gmail.com\u003e\n","accounts_in_message":[],"_revision_number":3},{"id":"3d1e69a557402a158c1d221439306fcc4f6286a0","author":{"_account_id":10234,"name":"Andrey Pavlov","email":"andrey.mp@gmail.com","username":"andrey-mp"},"date":"2020-01-30 09:14:48.000000000","message":"Patch Set 3:\n\nplease abandon this.","accounts_in_message":[],"_revision_number":3},{"id":"2e43a55850230809f9beec4cab132b1d1ca11730","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-03-17 20:31:54.000000000","message":"Abandoned\n\nAbandoning as requested.","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"4ec55aec91692e533be704217b75546273ab10bc","revisions":{"40f3d3700beb3e120f60ff57f2918866fe5e94f3":{"kind":"REWORK","_number":1,"created":"2019-08-19 15:46:27.000000000","uploader":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"ref":"refs/changes/39/677239/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/39/677239/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/39/677239/1"}}},"commit":{"parents":[{"commit":"7aa97f1712f6dcb1981f293b3e1eb2e74b084515","subject":"Merge \"Add protection tests for trusts API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7aa97f1712f6dcb1981f293b3e1eb2e74b084515"}]}],"author":{"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","date":"2019-08-19 15:35:47.000000000","tz":180},"committer":{"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","date":"2019-08-19 15:35:47.000000000","tz":180},"subject":"Fix caching behavior","message":"Fix caching behavior\n\nThis fixes inproper caching particulary affecting EC2 API\n(see the attached bug) by changing the _decrypt_credential method to modify\nthe copy of the credential instead of previous in-place modification.\nThis allow for proper caching of the returned value and fixes EC2 API.\nChanges in other methods are needed to support the new \u0027not-in-place\u0027 modification.\n\nChange-Id: Id00db3f303f45daf0e25be1f1bcf6a8834cb3ea7\nCloses-Bug:#1840647\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/40f3d3700beb3e120f60ff57f2918866fe5e94f3"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/40f3d3700beb3e120f60ff57f2918866fe5e94f3"}]},"branch":"refs/heads/master"},"3f7dda585ebf73144116ddfee4546df5289d377b":{"kind":"REWORK","_number":2,"created":"2019-08-19 18:24:46.000000000","uploader":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"ref":"refs/changes/39/677239/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/39/677239/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/39/677239/2"}}},"commit":{"parents":[{"commit":"7aa97f1712f6dcb1981f293b3e1eb2e74b084515","subject":"Merge \"Add protection tests for trusts API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7aa97f1712f6dcb1981f293b3e1eb2e74b084515"}]}],"author":{"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","date":"2019-08-19 15:35:47.000000000","tz":180},"committer":{"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","date":"2019-08-19 18:23:57.000000000","tz":180},"subject":"Fix caching behavior","message":"Fix caching behavior\n\nThis fixes inproper caching particulary affecting EC2 API\n(see the attached bug) by changing the _decrypt_credential method to modify\nthe copy of the credential instead of previous in-place modification.\nThis allow for proper caching of the returned value and fixes EC2 API.\nChanges in other methods are needed to support the new \u0027not-in-place\u0027 modification.\n\nChange-Id: Id00db3f303f45daf0e25be1f1bcf6a8834cb3ea7\nCloses-Bug:#1840647\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/3f7dda585ebf73144116ddfee4546df5289d377b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/3f7dda585ebf73144116ddfee4546df5289d377b"}]},"branch":"refs/heads/master"},"4ec55aec91692e533be704217b75546273ab10bc":{"kind":"REWORK","_number":3,"created":"2019-08-26 09:05:38.000000000","uploader":{"_account_id":30834,"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","username":"nikitakalyanov"},"ref":"refs/changes/39/677239/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/39/677239/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/39/677239/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/39/677239/3"}}},"commit":{"parents":[{"commit":"7aa97f1712f6dcb1981f293b3e1eb2e74b084515","subject":"Merge \"Add protection tests for trusts API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7aa97f1712f6dcb1981f293b3e1eb2e74b084515"}]}],"author":{"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","date":"2019-08-19 15:35:47.000000000","tz":180},"committer":{"name":"Nikita Kalyanov","email":"nikitakalyanov@gmail.com","date":"2019-08-26 09:03:53.000000000","tz":180},"subject":"Fix caching behavior","message":"Fix caching behavior\n\nThis fixes inproper caching particulary affecting EC2 API\n(see the attached bug) by changing the _decrypt_credential method to modify\nthe copy of the credential instead of previous in-place modification.\nThis allow for proper caching of the returned value and fixes EC2 API.\nChanges in other methods are needed to support the new \u0027not-in-place\u0027 modification.\n\nChange-Id: Id00db3f303f45daf0e25be1f1bcf6a8834cb3ea7\nCloses-Bug:#1840647\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/4ec55aec91692e533be704217b75546273ab10bc"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/4ec55aec91692e533be704217b75546273ab10bc"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
