)]}'
{"id":"openstack%2Fkeystone~681907","triplet_id":"openstack%2Fkeystone~stable%2Fqueens~I8f0f7a623a1741f461493d872849fae7ef3e8077","project":"openstack/keystone","branch":"stable/queens","hashtags":[],"change_id":"I8f0f7a623a1741f461493d872849fae7ef3e8077","subject":"Make system tokens work with domain-specific drivers","status":"MERGED","created":"2019-09-12 19:58:16.000000000","updated":"2019-10-24 01:33:30.000000000","submitted":"2019-10-24 01:31:12.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":4,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"681907-1571880672339-fe29816b","meta_rev_id":"2ce3defd0457bdfba5f22f177586c4d20fbeae72","_number":681907,"virtual_id_number":681907,"owner":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},{"value":0,"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2019-10-24 01:31:12.000000000","post_submit":true,"permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},"all":[{"value":2,"date":"2019-10-23 20:36:53.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},{"value":1,"date":"2019-10-23 20:31:01.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":2,"date":"2019-10-23 20:45:07.000000000","_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"all":[{"value":0,"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},{"value":0,"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":1,"date":"2019-10-23 20:45:07.000000000","_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2019-10-17 22:20:03.000000000","updated_by":{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},"reviewer":{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},"state":"REVIEWER"},{"updated":"2019-10-23 20:31:01.000000000","updated_by":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"reviewer":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"state":"REVIEWER"},{"updated":"2019-10-23 20:36:53.000000000","updated_by":{"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},"reviewer":{"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},"state":"REVIEWER"},{"updated":"2019-10-23 20:45:07.000000000","updated_by":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"reviewer":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"state":"REVIEWER"},{"updated":"2019-10-24 01:31:12.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"989685ecd1276b5fbe97cc2a1f620182465fff07","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2019-09-12 19:58:16.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"5b20199ba6b2191728e5fbf95b705995ad397b4b","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-09-13 05:10:43.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/88cdbb80f7804b2f936f1ae60c288e37 : SUCCESS in 7m 57s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/242bd2e5c6fc4ea7a1b2a031c8587914 : SUCCESS in 14m 59s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/a628f16f20ef47ab991bc27bdee6d1df : SUCCESS in 12m 48s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/4b28561690f5447ab77082351aeab753 : SUCCESS in 10m 06s\n- tempest-full https://zuul.opendev.org/t/openstack/build/62c3679427534cf09f68a68056208f1f : SUCCESS in 1h 33m 19s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/1afb842967f5403ea0373503906033fb : SUCCESS in 55m 01s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/365fdbb73dd949f096a55bd5e681cfc6 : SUCCESS in 1h 35m 33s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/370a8efb503c4793a713df5cb4148566 : SUCCESS in 11m 42s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/bdca0651a11d4f5995122f3026cd6311 : SUCCESS in 33m 17s\n- keystone-dsvm-functional-v3-only https://zuul.opendev.org/t/openstack/build/5154242093c64f30aedf058ec39afb0c : FAILURE in 25m 58s (non-voting)\n- keystone-dsvm-py35-functional-v3-only https://zuul.opendev.org/t/openstack/build/c743f346afd5494790601b4d8d1f3bb2 : FAILURE in 29m 38s (non-voting)\n- openstack-ansible-keystone-rolling-upgrade https://zuul.opendev.org/t/openstack/build/3d7f81b2619f430dbc9ae83f01b657fc : FAILURE in 2m 58s (non-voting)\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/33f4f452fa8b4da4ac1be9cd36593f17 : SUCCESS in 30m 17s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/9cdcdb44d68a45a29fdc4a0348baf10b : SUCCESS in 16m 03s\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/22d71642a5684c9391df8799d4948851 : FAILURE in 1h 07m 32s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"f5a5bdc6473762420c9ada9876de31cb4cf1e36f","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2019-09-13 13:58:08.000000000","message":"Patch Set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"6aa2f2ac5a0360f7389ceff918be920dda9e04ea","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-09-14 00:04:15.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/bbc74cef9d9b4e1f84ddb43168bdcd31 : SUCCESS in 10m 05s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/4fdf79e031974207a2b0482cea5a30d8 : SUCCESS in 18m 22s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/2ae2c3dee40b4d2e9d074ddd2a964467 : SUCCESS in 16m 19s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/dbebdd8d7ab548bc80b155fdff35d341 : SUCCESS in 9m 05s\n- tempest-full https://zuul.opendev.org/t/openstack/build/312684c615a5478aa5f6dcacfc056298 : SUCCESS in 1h 32m 58s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/8fff78466a8c443db7ec60f630f10ce2 : SUCCESS in 48m 18s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/bd8cdd8e6f12494b93fb83969a6f744e : SUCCESS in 1h 29m 46s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/65600e569e7c4784873e1a787c9ce4bf : SUCCESS in 13m 37s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/63c18256c45f46d2932f7d7d434915b8 : SUCCESS in 35m 01s\n- keystone-dsvm-functional-v3-only https://zuul.opendev.org/t/openstack/build/9d75f7e06b964a6b9f9f2f1139e12e9c : FAILURE in 30m 42s (non-voting)\n- keystone-dsvm-py35-functional-v3-only https://zuul.opendev.org/t/openstack/build/abaa831b4fa24322bd4d1a8fa59367ac : FAILURE in 32m 03s (non-voting)\n- openstack-ansible-keystone-rolling-upgrade https://zuul.opendev.org/t/openstack/build/3848a48f28c14e20a5b4faf100611f4e : FAILURE in 4m 05s (non-voting)\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/a7aaafc360d648419bfff71ce6102d44 : SUCCESS in 34m 24s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/98f1455e7107415a9bbfb1413820fd69 : SUCCESS in 16m 15s\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/e97bc354864d43748d9eb32af1bd5108 : SUCCESS in 1h 23m 23s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"2eb515f3c8143ade647961253feb426091722ec4","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2019-10-17 22:20:03.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"4094f7683d21957c15f49e98f1511e191626eeb0","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-10-17 23:55:05.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/98c28770349944fa80286d270436ef7a : SUCCESS in 8m 40s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/0e0ae1ccf3df42c3bd85033aef9b6db3 : FAILURE in 14m 44s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/652f753162bf4b49a59bf47e99a9c10b : FAILURE in 14m 54s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/9dbfbe626a1e41af85ffac066d13ded8 : SUCCESS in 8m 25s\n- tempest-full https://zuul.opendev.org/t/openstack/build/cc73aeae796144d1a7ee375f0cbe19ae : SUCCESS in 1h 33m 12s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/c3f0e7a698354c8d825d41c23f05ccf4 : SUCCESS in 50m 39s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/c344c02949d94351ba1fa1d0cdb9e773 : SUCCESS in 1h 15m 45s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/cc09e71b2da04fae8a751aab3ef33bee : SUCCESS in 19m 27s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/d67e1f48938847efa4389b4ccd9cc1f2 : SUCCESS in 31m 13s\n- keystone-dsvm-functional-v3-only https://zuul.opendev.org/t/openstack/build/02abf24299b347b9b4f2279c1b765e3e : FAILURE in 16m 52s (non-voting)\n- keystone-dsvm-py35-functional-v3-only https://zuul.opendev.org/t/openstack/build/585ca30365034f9891207b99a0211a30 : FAILURE in 26m 46s (non-voting)\n- openstack-ansible-keystone-rolling-upgrade https://zuul.opendev.org/t/openstack/build/e5e95654ba1248c597dba1681b5ea17f : FAILURE in 3m 31s (non-voting)\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/8062d9eeedb445e6b3f708dd0e88ef11 : SUCCESS in 29m 14s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/04d0d067e6fb4739aa4cd46e5335aefc : FAILURE in 13m 58s\n- legacy-tempest-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/f5a73ecd6ba143c98f4e9001f253a966 : SUCCESS in 1h 19m 52s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"844875fbe06f410b21dbe0e188ccf901f9c38615","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2019-10-18 15:46:49.000000000","message":"Patch Set 3:\n\nLooks like this cherry-pick needs some adjustment to make the tests work?","accounts_in_message":[],"_revision_number":3},{"id":"bdca091fbeca686477c7a5409d7bf452b4b5a497","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-22 18:47:04.000000000","message":"Patch Set 3:\n\nOK I guess need https://review.opendev.org/#/c/689586/ fixed in queens as well.","accounts_in_message":[],"_revision_number":3},{"id":"03569a4b6067130fb74fe02f9caeebbfd43db49a","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-22 18:47:57.000000000","message":"Patch Set 3: Workflow-1","accounts_in_message":[],"_revision_number":3},{"id":"f4394853c9616f9f981c2550abb5f0dae503a0c4","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-22 19:13:34.000000000","message":"Patch Set 4: Patch Set 3 was rebased","accounts_in_message":[],"_revision_number":4},{"id":"01f9b4c2c0779b72200860d696f89953df73a317","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-22 19:16:56.000000000","message":"Patch Set 4: Code-Review-1\n\n(1 comment)\n\nLet\u0027s re-cherry-pick this from the stable/rocky commit once that merges.","accounts_in_message":[],"_revision_number":4},{"id":"bb12316c7fe276c6c03eb43fc601002d8ad209a7","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2019-10-22 20:21:43.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"bd4299788e5e6bddf176fd48288a630199dacacf","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2019-10-22 20:22:49.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"1df0f6cbfec307cc10525d4ea282b3ce92a1fb6d","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-22 20:45:48.000000000","message":"Patch Set 5: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"02647a36c70dd09200623a8db26d371c1f3d8b83","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2019-10-22 21:12:27.000000000","message":"Uploaded patch set 6: Commit message was updated.","accounts_in_message":[],"_revision_number":6},{"id":"bbc1e76b3a7a8f0e95babfcd3a06ac4445e5f8bc","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2019-10-22 21:12:31.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"6d92c5393727da0dce7ffd4af751a27a9bfce785","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-22 21:51:16.000000000","message":"Patch Set 6: Code-Review+2\n\nOK this looks good to me now that the commit message is squared away and the stable/rocky backport is approved.","accounts_in_message":[],"_revision_number":6},{"id":"59cb0279b5e2cb35ea088712e71aa4620e41d625","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-22 21:51:47.000000000","message":"Patch Set 7: Patch Set 6 was rebased","accounts_in_message":[],"_revision_number":7},{"id":"0ee29ec054f52a5cdaaa072e47f843f9cee5c137","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-10-22 23:23:02.000000000","message":"Patch Set 7: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/3330c4e446dd43099edb2ba868e939c9 : SUCCESS in 10m 13s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/5e5ca406c0c843629b232006248902ab : FAILURE in 13m 11s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/7aa0192fffae4e328c9ae94fc4d0c9cd : FAILURE in 14m 12s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/9da4fc13817b432aace1ebd35baaa929 : SUCCESS in 8m 30s\n- tempest-full https://zuul.opendev.org/t/openstack/build/be542390aab540f8acf276f9da1fd3a2 : SUCCESS in 1h 29m 27s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/9ecd14d9d42744daafb2b27b46f17028 : SUCCESS in 53m 08s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/579b7582ef45436681ae7140c0678084 : SUCCESS in 1h 22m 22s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/95cc2e5124fe473085f8b02fc12c5caa : SUCCESS in 14m 41s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/9a2371d5d8b7410585a7469285bbea04 : SUCCESS in 43m 17s\n- keystone-dsvm-functional-v3-only https://zuul.opendev.org/t/openstack/build/e6d69565ea8a4602bdb584773152743e : FAILURE in 25m 45s (non-voting)\n- keystone-dsvm-py35-functional-v3-only https://zuul.opendev.org/t/openstack/build/9e527b5d0fca42e79da74810b42af774 : FAILURE in 29m 19s (non-voting)\n- openstack-ansible-keystone-rolling-upgrade https://zuul.opendev.org/t/openstack/build/7cb06f920696407f8658a8ed5d6ad39c : FAILURE in 6m 16s (non-voting)\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/69f4a9182d6640d9a0397b2c99f8cb67 : SUCCESS in 28m 02s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/b64580b042c24a82a9fed7fd7b5d4c8b : FAILURE in 30m 38s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/2ce02f16795e44d2982ad39493d37176 : SUCCESS in 42m 32s (non-voting)","accounts_in_message":[],"_revision_number":7},{"id":"ce9a7ff9e01b403abcfed1e502ace04eacb145ec","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2019-10-23 00:01:20.000000000","message":"Uploaded patch set 8.","accounts_in_message":[],"_revision_number":8},{"id":"c05ef3186aca7ac3b34f0a2dc31a04606fda95ce","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2019-10-23 00:01:42.000000000","message":"Patch Set 8:\n\nFixed the unit test to be pre-flask compatible","accounts_in_message":[],"_revision_number":8},{"id":"5bef2a74c0046e3f989422eb0ef02ff7b79f3f06","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-10-23 01:37:37.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5d866111095d417b9ede26e2a204ca39 : SUCCESS in 9m 03s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/465ccca506984eb5b5fc79c895496a13 : SUCCESS in 11m 51s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/68368c4d0d5742feb61c2367cd37e2eb : SUCCESS in 12m 46s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/64673bc9b8234cd48a011688240f4351 : SUCCESS in 7m 13s\n- tempest-full https://zuul.opendev.org/t/openstack/build/5fa7d2dc5ffd409aa90881f5505de507 : SUCCESS in 1h 30m 10s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/7cd7907f3a1e47eca4da6ade23999b14 : SUCCESS in 53m 51s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/d7d4579eb6e14f89897ff267dc7e4700 : SUCCESS in 1h 19m 17s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/7ac9cefa2e5c42648d4c670856997b35 : SUCCESS in 19m 30s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/bb940a91da7d47798ad5101823dc0a62 : SUCCESS in 28m 48s\n- keystone-dsvm-functional-v3-only https://zuul.opendev.org/t/openstack/build/12785e17564544b989c9ebcf457ea002 : FAILURE in 28m 52s (non-voting)\n- keystone-dsvm-py35-functional-v3-only https://zuul.opendev.org/t/openstack/build/51bd353d66e5492a8a759b1dd561db01 : FAILURE in 27m 48s (non-voting)\n- openstack-ansible-keystone-rolling-upgrade https://zuul.opendev.org/t/openstack/build/96f9da84de7142ea839c00702affc707 : FAILURE in 3m 06s (non-voting)\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/410045fdb9dd45beb8cde54ba2006cba : SUCCESS in 29m 05s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f8009dfcebeb4ae38968c571ce86ed0b : SUCCESS in 14m 30s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/46647b79af82444ba94e7fbfdbe4a3f1 : SUCCESS in 38m 30s (non-voting)","accounts_in_message":[],"_revision_number":8},{"id":"45bea6e049d2d0a91ae2386f2ca235690d17605b","author":{"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},"date":"2019-10-23 10:43:46.000000000","message":"Patch Set 8: Code-Review+1\n\nStill needed in stable/rocky.","accounts_in_message":[],"_revision_number":8},{"id":"0b595d9f8775380702b565199542821d8da54219","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2019-10-23 20:31:01.000000000","message":"Patch Set 8: Code-Review+1\n\nMerged in rocky","accounts_in_message":[],"_revision_number":8},{"id":"9fb5cf55d458b1c124850765f79b407b1586c977","author":{"_account_id":11904,"name":"Sean McGinnis","email":"sean.mcginnis@gmail.com","username":"SeanM"},"date":"2019-10-23 20:36:53.000000000","message":"Patch Set 8: Code-Review+2\n\nShould be good to go now.","accounts_in_message":[],"_revision_number":8},{"id":"5254addb5ae557e5cfc814ff19f4b64af78abc29","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2019-10-23 20:45:07.000000000","message":"Patch Set 8: Code-Review+2 Workflow+1\n\nlgtm","accounts_in_message":[],"_revision_number":8},{"id":"851fff19883897906e3f7c518ee25f71ceaceadd","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-10-23 20:45:34.000000000","message":"Patch Set 8: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":8},{"id":"e293a9cd10d76d12309542df20ed68ab40af2ae6","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-10-24 01:31:12.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":8},{"id":"696c0920de79568d3e26328e4a8e5746b7f35d66","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-10-24 01:31:12.000000000","message":"Patch Set 8: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/1bf7a43ebccd42568a6e35d04f531429 : SUCCESS in 9m 25s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/d84e7d8f97b34f15a33f9c9a53b95295 : SUCCESS in 11m 34s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/28fee0ab4c7b45648b4f2b32d34559fc : SUCCESS in 13m 31s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/1b3eed16a47940bba836b2e1769785e5 : SUCCESS in 7m 28s\n- tempest-full https://zuul.opendev.org/t/openstack/build/0e7749e1a5a6432b92f2137a6b5e30b1 : SUCCESS in 1h 21m 29s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/d06a5249c0624a489850f679c40c5272 : SUCCESS in 59m 28s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/97e9bff9f7484b7d8b81ab0a0b4ea424 : SUCCESS in 1h 23m 10s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/778001576f33494a99fbf461cf43697f : SUCCESS in 18m 55s\n- keystone-dsvm-functional https://zuul.opendev.org/t/openstack/build/60029e2d43cf41fa85985f2fbc8181ba : SUCCESS in 31m 20s","accounts_in_message":[],"_revision_number":8},{"id":"2ce3defd0457bdfba5f22f177586c4d20fbeae72","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-10-24 01:33:30.000000000","message":"Patch Set 8:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/8a8306f721c24adfb6398bbdf17ede74 : SUCCESS in 1m 04s","accounts_in_message":[],"_revision_number":8}],"current_revision_number":8,"current_revision":"65cb669e78521ad9012cba16f3071d741b8672c5","revisions":{"129ed134f87f8a928cc376a11101dd0a43df335e":{"kind":"REWORK","_number":1,"created":"2019-09-12 19:58:16.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/07/681907/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/1"}}},"commit":{"parents":[{"commit":"79ed42ee67915383242541329dd5aa186f087ff2","subject":"Fix python3 compatibility on LDAP search DN from id","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/79ed42ee67915383242541329dd5aa186f087ff2"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 19:57:41.000000000","tz":0},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not assocaited to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list uesrs or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n      keystone/tests/unit/test_v3_auth.py\n\nThis backport has conflicts with keystone/server/flask/common.py due\nto a massive refactor to get keystone off python-paste that started in\nRocky and spilled over into Stein. The change is functionally\nequivalent to the patch merged to Train but done in\nkeystone/common/controller.py instead of\nkeystone/server/flask/common.py. There was also some changes to the\ntest since it didn\u0027t have the flask test client available to call the\napplication with. Instead, we\u0027re using the old `self.get` utility\nmethods for functionally testing the API.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit b152d7e52caa817de0c42ed356dada07c7d0d370)\n(cherry picked from commit d62bbeef0bdb300d79e06d568db99a2bf936b4f5)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/129ed134f87f8a928cc376a11101dd0a43df335e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/129ed134f87f8a928cc376a11101dd0a43df335e"}]},"branch":"refs/heads/stable/queens"},"078a17fd37efb0433d51d2363ac35d22ebfcaef2":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2019-09-13 13:58:08.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/07/681907/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/2"}}},"commit":{"parents":[{"commit":"79ed42ee67915383242541329dd5aa186f087ff2","subject":"Fix python3 compatibility on LDAP search DN from id","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/79ed42ee67915383242541329dd5aa186f087ff2"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-13 13:58:06.000000000","tz":0},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not associated to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list users or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n      keystone/tests/unit/test_v3_auth.py\n\nThis backport has conflicts with keystone/server/flask/common.py due\nto a massive refactor to get keystone off python-paste that started in\nRocky and spilled over into Stein. The change is functionally\nequivalent to the patch merged to Train but done in\nkeystone/common/controller.py instead of\nkeystone/server/flask/common.py. There was also some changes to the\ntest since it didn\u0027t have the flask test client available to call the\napplication with. Instead, we\u0027re using the old `self.get` utility\nmethods for functionally testing the API.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit b152d7e52caa817de0c42ed356dada07c7d0d370)\n(cherry picked from commit d62bbeef0bdb300d79e06d568db99a2bf936b4f5)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/078a17fd37efb0433d51d2363ac35d22ebfcaef2"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/078a17fd37efb0433d51d2363ac35d22ebfcaef2"}]},"branch":"refs/heads/stable/queens"},"de5fed5597dd64e9646c03c5b6bae61926773105":{"kind":"REWORK","_number":3,"created":"2019-10-17 22:20:03.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/07/681907/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/3"}}},"commit":{"parents":[{"commit":"79ed42ee67915383242541329dd5aa186f087ff2","subject":"Fix python3 compatibility on LDAP search DN from id","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/79ed42ee67915383242541329dd5aa186f087ff2"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-10-17 22:19:23.000000000","tz":0},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not associated to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list users or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n      keystone/tests/unit/test_v3_auth.py\n\nThis backport has conflicts with keystone/server/flask/common.py due\nto a massive refactor to get keystone off python-paste that started in\nRocky and spilled over into Stein. The change is functionally\nequivalent to the patch merged to Train but done in\nkeystone/common/controller.py instead of\nkeystone/server/flask/common.py. There was also some changes to the\ntest since it didn\u0027t have the flask test client available to call the\napplication with. Instead, we\u0027re using the old `self.get` utility\nmethods for functionally testing the API.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit 8f43b9cab00c86a455b2a9700b434e98b2e9c2d8)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/de5fed5597dd64e9646c03c5b6bae61926773105"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/de5fed5597dd64e9646c03c5b6bae61926773105"}]},"branch":"refs/heads/stable/queens"},"9ca2c605b94506a7dfa411dd15cd61cc65f78045":{"kind":"TRIVIAL_REBASE","_number":4,"created":"2019-10-22 19:13:34.000000000","uploader":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"ref":"refs/changes/07/681907/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/4"}}},"commit":{"parents":[{"commit":"d57733f4e8849331935951e8a6c3f93d755fea3e","subject":"Add test case for expanding implied roles in system tokens","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d57733f4e8849331935951e8a6c3f93d755fea3e"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Matt Riedemann","email":"mriedem.os@gmail.com","date":"2019-10-22 19:13:34.000000000","tz":0},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not associated to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list users or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n      keystone/tests/unit/test_v3_auth.py\n\nThis backport has conflicts with keystone/server/flask/common.py due\nto a massive refactor to get keystone off python-paste that started in\nRocky and spilled over into Stein. The change is functionally\nequivalent to the patch merged to Train but done in\nkeystone/common/controller.py instead of\nkeystone/server/flask/common.py. There was also some changes to the\ntest since it didn\u0027t have the flask test client available to call the\napplication with. Instead, we\u0027re using the old `self.get` utility\nmethods for functionally testing the API.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit 8f43b9cab00c86a455b2a9700b434e98b2e9c2d8)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/9ca2c605b94506a7dfa411dd15cd61cc65f78045"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/9ca2c605b94506a7dfa411dd15cd61cc65f78045"}]},"branch":"refs/heads/stable/queens"},"2737e3ba3468fa3dd9b53dc24ea7cfd7948b132f":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":5,"created":"2019-10-22 20:21:43.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/07/681907/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/5"}}},"commit":{"parents":[{"commit":"a131622de4c0317fb6fa56fdc395539b35caf083","subject":"Merge \"Add retry for DBDeadlock in credential delete\" into stable/queens","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a131622de4c0317fb6fa56fdc395539b35caf083"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-10-22 20:21:17.000000000","tz":0},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not associated to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list users or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n\nThis backport has conflicts with keystone/server/flask/common.py due to\na massive refactor to get keystone off python-paste that started in\nRocky and spilled over into Stein. The change is functionally equivalent\nto the patch merged to Train but done in keystone/common/controller.py\ninstead of keystone/server/flask/common.py. There was also some changes\nto the test since it didn\u0027t have a utility method to obtain a\nsystem-scoped token.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit 8f43b9cab00c86a455b2a9700b434e98b2e9c2d8)\n(cherry picked from commit 417d2c0e6e6bef39f447681325ae5b0ba46b2e2c)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2737e3ba3468fa3dd9b53dc24ea7cfd7948b132f"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2737e3ba3468fa3dd9b53dc24ea7cfd7948b132f"}]},"branch":"refs/heads/stable/queens"},"83ccca3308fcfe6e9df3beba97f54c12e4e64374":{"kind":"NO_CODE_CHANGE","_number":6,"created":"2019-10-22 21:12:27.000000000","uploader":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"ref":"refs/changes/07/681907/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/6"}}},"commit":{"parents":[{"commit":"a131622de4c0317fb6fa56fdc395539b35caf083","subject":"Merge \"Add retry for DBDeadlock in credential delete\" into stable/queens","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a131622de4c0317fb6fa56fdc395539b35caf083"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-10-22 21:11:31.000000000","tz":0},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not associated to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list users or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n\nThis backport has conflicts with keystone/server/flask/common.py due to\nthe ``token_ref`` variable being renamed to ``token``. This conflict is\nresolved by continuing to use the old name, but the change is\nfunctionally equivalent to what was proposed to all other branches.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit 8f43b9cab00c86a455b2a9700b434e98b2e9c2d8)\n(cherry picked from commit 417d2c0e6e6bef39f447681325ae5b0ba46b2e2c)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/83ccca3308fcfe6e9df3beba97f54c12e4e64374"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/83ccca3308fcfe6e9df3beba97f54c12e4e64374"}]},"branch":"refs/heads/stable/queens"},"1449a33e7955284de4559f1a023369bdbbac0de0":{"kind":"TRIVIAL_REBASE","_number":7,"created":"2019-10-22 21:51:47.000000000","uploader":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"ref":"refs/changes/07/681907/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/7"}}},"commit":{"parents":[{"commit":"d57733f4e8849331935951e8a6c3f93d755fea3e","subject":"Add test case for expanding implied roles in system tokens","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d57733f4e8849331935951e8a6c3f93d755fea3e"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Matt Riedemann","email":"mriedem.os@gmail.com","date":"2019-10-22 21:51:47.000000000","tz":0},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not associated to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list users or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n\nThis backport has conflicts with keystone/server/flask/common.py due to\nthe ``token_ref`` variable being renamed to ``token``. This conflict is\nresolved by continuing to use the old name, but the change is\nfunctionally equivalent to what was proposed to all other branches.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit 8f43b9cab00c86a455b2a9700b434e98b2e9c2d8)\n(cherry picked from commit 417d2c0e6e6bef39f447681325ae5b0ba46b2e2c)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/1449a33e7955284de4559f1a023369bdbbac0de0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/1449a33e7955284de4559f1a023369bdbbac0de0"}]},"branch":"refs/heads/stable/queens"},"65cb669e78521ad9012cba16f3071d741b8672c5":{"kind":"REWORK","_number":8,"created":"2019-10-23 00:01:20.000000000","uploader":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"ref":"refs/changes/07/681907/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/07/681907/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/07/681907/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/07/681907/8"}}},"commit":{"parents":[{"commit":"d57733f4e8849331935951e8a6c3f93d755fea3e","subject":"Add test case for expanding implied roles in system tokens","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d57733f4e8849331935951e8a6c3f93d755fea3e"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2019-09-12 16:46:26.000000000","tz":0},"committer":{"name":"Colleen Murphy","email":"colleen.murphy@suse.de","date":"2019-10-22 23:56:09.000000000","tz":-420},"subject":"Make system tokens work with domain-specific drivers","message":"Make system tokens work with domain-specific drivers\n\nWhen calling certain group or user APIs, keystone logic would attempt\nto figure out the domain to scope responses to. This was specific to\nenabling domain-specific driver support, where each domain is backed\nby a different identity store. This functionality is turned off by\ndefault. Since system-scoped tokens are not associated to a domain\n(unlike project-scoped tokens or domain-scoped tokens), the logic to\ndetermine a domain from a system-scoped token was breaking and\nreturning an erroneous HTTP 401 Unauthorized when system users\nattempted to list users or groups.\n\nThis commit adds support for domain detection with system-scoped\ntokens.\n\nConflicts:\n      keystone/server/flask/common.py\n\nThis backport has conflicts with keystone/server/flask/common.py due to\nthe ``token_ref`` variable being renamed to ``token``. This conflict is\nresolved by continuing to use the old name, but the change is\nfunctionally equivalent to what was proposed to all other branches.\n\nThis backport modifies the unit test to use the pre-flask-compatible\nself.admin_request method instead of flask\u0027s test_client() context\nmanager.\n\nChange-Id: I8f0f7a623a1741f461493d872849fae7ef3e8077\nCloses-Bug: 1843609\n(cherry picked from commit 8f43b9cab00c86a455b2a9700b434e98b2e9c2d8)\n(cherry picked from commit 417d2c0e6e6bef39f447681325ae5b0ba46b2e2c)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/65cb669e78521ad9012cba16f3071d741b8672c5"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/65cb669e78521ad9012cba16f3071d741b8672c5"}]},"branch":"refs/heads/stable/queens"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
