)]}'
{"id":"openstack%2Fkeystone~726046","triplet_id":"openstack%2Fkeystone~stable%2Fpike~I39d0d705839fbe31ac518ac9a82959e108cb7c1d","project":"openstack/keystone","branch":"stable/pike","topic":"bug/1872733","hashtags":[],"change_id":"I39d0d705839fbe31ac518ac9a82959e108cb7c1d","subject":"Fix security issues with EC2 credentials","status":"MERGED","created":"2020-05-07 06:32:40.000000000","updated":"2020-06-04 20:14:22.000000000","submitted":"2020-06-04 20:12:40.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":10,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"726046-1591301561283-0bd3b327","meta_rev_id":"1fb985e3cb45d87013c4055179cb024a2acdc61c","_number":726046,"virtual_id_number":726046,"owner":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"value":0,"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":16310,"name":"Flávio","email":"framalho@suse.com","username":"flaviosr"},{"value":0,"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2020-06-04 20:12:40.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"all":[{"value":2,"date":"2020-06-03 19:39:54.000000000","_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"value":2,"date":"2020-06-04 18:10:03.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":16310,"name":"Flávio","email":"framalho@suse.com","username":"flaviosr"},{"value":0,"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"all":[{"value":0,"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"value":0,"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"value":1,"date":"2020-06-04 18:09:59.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":16310,"name":"Flávio","email":"framalho@suse.com","username":"flaviosr"},{"value":0,"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},{"_account_id":16310,"name":"Flávio","email":"framalho@suse.com","username":"flaviosr"},{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2020-05-07 06:37:43.000000000","updated_by":{"_account_id":16310,"name":"Flávio","email":"framalho@suse.com","username":"flaviosr"},"reviewer":{"_account_id":16310,"name":"Flávio","email":"framalho@suse.com","username":"flaviosr"},"state":"REVIEWER"},{"updated":"2020-05-07 06:40:41.000000000","updated_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"reviewer":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"state":"REVIEWER"},{"updated":"2020-05-08 14:00:45.000000000","updated_by":{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},"reviewer":{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},"state":"REVIEWER"},{"updated":"2020-05-29 15:23:16.000000000","updated_by":{"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},"reviewer":{"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},"state":"REVIEWER"},{"updated":"2020-06-03 19:39:54.000000000","updated_by":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"reviewer":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"state":"REVIEWER"},{"updated":"2020-06-04 18:09:59.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"state":"REVIEWER"},{"updated":"2020-06-04 20:12:40.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"f7acb2f23dbf79a61bea132dc43153fa6d999646","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-07 06:32:40.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"d179403d93f83a11ca50cdcaee6187d4a9ad10c5","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-07 06:37:26.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"5ab95df1f8ff416edde1e7901990398ad5b1a437","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-07 08:41:06.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/d508273b5c4c47b19186ca5a78f2d3de : SUCCESS in 7m 04s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/686d4bd2b2cb489bb496cef7ce918a11 : SUCCESS in 12m 42s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/53de986f2dcd44c6bf79b2e20758a293 : SUCCESS in 21m 02s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/d0f07dc080fb494591e3999ad3eef8de : SUCCESS in 10m 26s\n- tempest-full https://zuul.opendev.org/t/openstack/build/b7c92163920f4a2da21e4641454c19d1 : FAILURE in 1h 27m 53s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/5221ae6de85e403482f2863ad79f3fe5 : FAILURE in 35m 30s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/2f525a3d90fe40cd9e9126c5d2cc4d6a : SUCCESS in 20m 50s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/d70717b61e034f33bd841ad52108061a : FAILURE in 28m 48s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/de8e290bd04e4ecc9e3151ad6224fb2c : SUCCESS in 16m 44s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/914409b234244a3d9dee3dd3c4b6a7ff : FAILURE in 39m 50s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"6012a4785ac700ca0c82bbd026ad6ed628206a5c","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-07 16:49:47.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"381645860506ea905983e65b4d6a62fe184967be","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-07 18:25:53.000000000","message":"Patch Set 3: Verified-1\n\n(3 comments)\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/b85723ea52f24fd9be624e8f5f8a285f : FAILURE in 12m 05s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/d42bad98cbae4323a9a05e81db8bdc57 : FAILURE in 20m 12s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/281a467f9848466f994fb32a31848d21 : FAILURE in 23m 00s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/a876e8b4f61f4dc5b68ab082f492ef52 : SUCCESS in 15m 10s\n- tempest-full https://zuul.opendev.org/t/openstack/build/d4261b4bd66945c1b18b9f8d010baa45 : FAILURE in 1h 16m 47s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/14ddb194cbab4951a2d402363fc36029 : FAILURE in 33m 08s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/a6935606e4dd451abefa11d032129285 : SUCCESS in 23m 18s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/12506c7b95e549589619c9df6eaa18ec : FAILURE in 34m 23s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/2d7d588cb9e24254adde1c85257f46fe : FAILURE in 14m 38s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/16d818d7bca84adebb6cd390ae58b23d : FAILURE in 47m 16s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"93fee7a0a92c5cab8d46b54dcaeaae80fedc030d","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-07 18:46:06.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"5228b00d7a61b72ca800100ba29fe2a00d2e5300","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-07 20:16:03.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/75f3da4e18234edcb1f0b309f8526c3a : SUCCESS in 7m 37s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/03a6f9bccbb64ce3bda0b0efef8d8f68 : SUCCESS in 19m 33s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/2429a40b767a4fd283472645bd76f243 : TIMED_OUT in 41m 16s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/e66f31e9ba034ef7a9abcf0fef433f2c : SUCCESS in 9m 44s\n- tempest-full https://zuul.opendev.org/t/openstack/build/8b7acd5f5a72444a9c4d0c1b624c3956 : FAILURE in 1h 27m 52s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/3bd30d9255904dfba706048b691beaae : FAILURE in 40m 32s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/de2482cbbfae4172bc0a7b4894f31b36 : SUCCESS in 18m 38s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/a82ebae3b2ac4003a6b119659534436d : FAILURE in 38m 51s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/ebac20266f2e4b34bf4dc3ee04661897 : SUCCESS in 47m 35s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/0f28dd2d4e0544388763d47837b55793 : SUCCESS in 50m 40s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"38a4817f0cd71c8dee6e269fb03471ea480703a4","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-07 20:56:23.000000000","message":"Patch Set 4:\n\nrecheck","accounts_in_message":[],"_revision_number":4},{"id":"62277952d6cf61a37edf32a4f305eb4f6c2ac03a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-07 22:21:54.000000000","message":"Patch Set 4:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/418936cb4292427187ca8be6981ef747 : SUCCESS in 7m 54s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/77eecdcc9fc04386884340b8d8281006 : SUCCESS in 21m 44s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/1cb1f73919a04329a4143d57c8ad1ac4 : SUCCESS in 16m 06s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/d282197ef8a440c88de6d487dff5dbd2 : SUCCESS in 8m 59s\n- tempest-full https://zuul.opendev.org/t/openstack/build/4fe69fe57d8a4a7bae1d824d3d76b71b : FAILURE in 1h 18m 02s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/16cafa708b0b4170969a34d2b37f865e : FAILURE in 31m 42s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/4bdb739380c64fe3aa74e3f09c3b4755 : SUCCESS in 17m 21s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/03d5e4a8fb704471adff51964958ec62 : FAILURE in 30m 50s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/e402ad510f5c4e35bd4a07fee6884485 : SUCCESS in 14m 16s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/9ac7d66b87f746eb9540af6fc9bd7836 : SUCCESS in 37m 26s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"444aec87402ba8f0d5d1de4cc23b6254f7613de4","author":{"_account_id":8866,"name":"Raildo Mascena de Sousa Filho","email":"rmascena@redhat.com","username":"raildo"},"date":"2020-05-08 14:00:45.000000000","message":"Patch Set 4:\n\nrecheck","accounts_in_message":[],"_revision_number":4},{"id":"9603100d1d62fac87eff047ee56258d5a82bcc21","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-05-08 15:03:10.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"7957076b945fd57caf138115ae0f9a331670b470","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-08 15:40:20.000000000","message":"Patch Set 4:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/3af9743081bc4abab90bf5b98895253f : SUCCESS in 10m 05s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/6ac660a1ecb6446c9c7a41e4668e202c : SUCCESS in 18m 31s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/4923ea08ac5046b7b3a77163f136c39c : SUCCESS in 19m 36s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/2cef943b9876431797dca87be703eb28 : SUCCESS in 9m 13s\n- tempest-full https://zuul.opendev.org/t/openstack/build/d4d53a16c9b94c11b0fcaaabb4f150b3 : SUCCESS in 1h 34m 09s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/8c98eb4e50934d119686a476e2247f6a : FAILURE in 32m 30s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/c690e7ba83724b69874bcccf3c4ccd78 : SUCCESS in 20m 36s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/c71823b5ef724dba8133c204dd05e551 : FAILURE in 28m 10s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/395f17ccf3024efc8028b1a40963e853 : SUCCESS in 20m 04s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/7290a0e629bc4f4b862f676ec67182cd : SUCCESS in 38m 08s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"e9e4232bb2fe1e4db28e151f5dd44e77e5dc2575","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-08 17:08:26.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"7ad083c39a09090f156b948288237c88286f7bd7","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-08 17:09:47.000000000","message":"Patch Set 5: Commit message was updated.","accounts_in_message":[],"_revision_number":5},{"id":"7ecac34fecd8de943a1519bc66e7f4526056bb16","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-08 18:48:59.000000000","message":"Patch Set 5: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/38813306d5514bc180ba698bfdcb7a52 : SUCCESS in 6m 53s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/c0e681d28e7045aab270e650329eb615 : SUCCESS in 17m 10s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/25d1fc77339e4fc8a963dceb5bc03887 : SUCCESS in 19m 34s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/922abe51745943e4864950985b609097 : SUCCESS in 9m 46s\n- tempest-full https://zuul.opendev.org/t/openstack/build/f6cc92360ef3449fa6cb745d8816925d : SUCCESS in 1h 37m 59s\n- neutron-grenade https://zuul.opendev.org/t/openstack/build/6746fa8518d34bc5a18a1005e85dc54a : FAILURE in 31m 54s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d52d92df615e4b56bfda2cc26c4dd03b : SUCCESS in 17m 07s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/ae6e855e1db54a7b98145757e4ed12e4 : FAILURE in 25m 23s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/7713f2ceac75478383857f8cc9199bbe : SUCCESS in 16m 19s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/b74a8f2133504326933db182665099ac : SUCCESS in 34m 13s (non-voting)","accounts_in_message":[],"_revision_number":5},{"id":"b0c5652cb9a382bc16feac39c520b3f15b70472e","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2020-05-26 18:59:36.000000000","message":"Patch Set 5:\n\nrecheck","accounts_in_message":[],"_revision_number":5},{"id":"f29045876f904586a7c22a6a713795f9e46ed291","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-26 20:56:08.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/1c37ca0fa11443c786d02fae20f0586b : SUCCESS in 6m 29s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/37ad3a637c5b476ab501ed13254c2bcd : SUCCESS in 13m 31s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/062ac8f8beb54cbfa64018dc9c25ff5b : SUCCESS in 14m 58s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/c0999d032c60481986dc0e323684e556 : SUCCESS in 10m 00s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3bb1716da5b94fdab5aaced3d94bba35 : SUCCESS in 7m 32s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/0ff0b2b07d434964bfb345643f8e5f0b : FAILURE in 32m 07s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/50f89f3629af4617a53231e3224dafc7 : SUCCESS in 15m 11s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/e283a0126af34d22bd901b709e81fce5 : SUCCESS in 42m 38s (non-voting)\n- tempest-full https://zuul.opendev.org/t/openstack/build/c36c39eaab0f4998b579f1e93335481c : SUCCESS in 1h 50m 19s","accounts_in_message":[],"_revision_number":5},{"id":"f8cea606006192257fd8ff461e9e62dfb14a77d7","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2020-05-26 21:05:53.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"4472ee9cabd1e49a266963bd07ab8c456de2f72c","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-28 16:51:31.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"50ca076c3292550e085827c15de57aa3729a6438","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-05-28 17:03:08.000000000","message":"Uploaded patch set 6.","accounts_in_message":[],"_revision_number":6},{"id":"3fed2057939fd96743c23ca99b6aea180cd949cc","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-05-28 18:57:23.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e3d7921b529e46258c1ad9355d723437 : SUCCESS in 6m 38s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/33eb1077eaff4472a26ec7417a0b94fe : SUCCESS in 10m 50s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/f34add023c6445f3ab649326eba66733 : SUCCESS in 17m 48s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/0326e1b794894e4c99495c4952963ece : SUCCESS in 9m 09s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/46ad2149f4af4153bf6fbaa56d4a1db9 : SUCCESS in 9m 57s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/6a00f310e43f41b095e71d225692276e : FAILURE in 28m 15s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f74f42b879f7420a831be8792afe2625 : SUCCESS in 15m 16s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/64d34a38d9114837b46dd6b3ad804c5d : SUCCESS in 43m 56s (non-voting)\n- tempest-full https://zuul.opendev.org/t/openstack/build/3e019f4398814f598d8780f43084a561 : SUCCESS in 1h 45m 31s","accounts_in_message":[],"_revision_number":6},{"id":"21bf55aba3582840c226472b2405425b0fb7d9bd","author":{"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},"date":"2020-05-29 15:23:16.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"5b6fdb7457bed2f90fcb250302261fa52d7fb086","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2020-06-02 15:00:37.000000000","message":"Patch Set 6: Code-Review+2","accounts_in_message":[],"_revision_number":6},{"id":"b5fc707ad393cf0f09a8903cebabc4ad15f0c3a9","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-06-02 15:47:58.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"6d325ad1eab8785bb2b9d4a7db2d6e378824cf6d","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-06-02 16:28:13.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"3e780bbb724c4290974a3d83e7fa4a2ee5469c66","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2020-06-02 16:54:02.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"acb5fe34e9d4e59b417f1df5fa18d20e78b3f58d","author":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"date":"2020-06-03 16:54:02.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"b53f0fbdd6dd08ac54f03ef253446d84646b22cf","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-06-03 18:30:22.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/2324d1d9e1564f7082c57a370f63506a : SUCCESS in 5m 59s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/9337809bcbce48729efe753f9b478695 : SUCCESS in 11m 42s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/9906f2dcf0d842ef8793cf109a1a767d : SUCCESS in 12m 18s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/97b152cc434d4fb39cd71bdf0990c833 : SUCCESS in 7m 30s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/509855089a6e43b19ce1e745f07ef77d : SUCCESS in 6m 50s\n- legacy-keystoneclient-dsvm-functional https://zuul.opendev.org/t/openstack/build/2778d98ecd1f40d5a3e86bef327a9981 : FAILURE in 27m 06s (non-voting)\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/e733549725f1468a857498e6ab47ee36 : SUCCESS in 26m 32s\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/9d13d43809a44b418730d41fdda2ab64 : SUCCESS in 42m 25s (non-voting)\n- tempest-full https://zuul.opendev.org/t/openstack/build/6de1d53820cd471ba51b7871efe4126f : SUCCESS in 1h 31m 07s","accounts_in_message":[],"_revision_number":7},{"id":"155383b139ffc94f06f9b78b671fc969ff7e2ec1","author":{"_account_id":8482,"name":"Colleen Murphy","email":"colleen@gazlene.net","username":"krinkle"},"date":"2020-06-03 19:39:54.000000000","message":"Patch Set 7: Code-Review+2","accounts_in_message":[],"_revision_number":7},{"id":"2ef177bb8e03a7b1dce2aaf837b394c580bc8349","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-06-04 18:09:59.000000000","message":"Patch Set 7: Workflow+1","accounts_in_message":[],"_revision_number":7},{"id":"e082c14a239bd2944c596a19a06cc4f1ed244be6","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-06-04 18:10:03.000000000","message":"Patch Set 7: Code-Review+2","accounts_in_message":[],"_revision_number":7},{"id":"eb5247391c316ffa42e82eaeaee6843c25c575d0","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-06-04 18:10:15.000000000","message":"Patch Set 7: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":7},{"id":"763e1a0cd53ba67f0508d89bc83531bfcfe5be58","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-06-04 20:12:40.000000000","message":"Patch Set 7: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/d88652e68e7748c18e65569f43c0910e : SUCCESS in 6m 55s\n- openstack-tox-py27 https://zuul.opendev.org/t/openstack/build/78f29e32609a4e8fb68ec7bdcb7abad0 : SUCCESS in 17m 00s\n- openstack-tox-py35 https://zuul.opendev.org/t/openstack/build/3e420eed0e7f4ab8acb37db20c54921d : SUCCESS in 13m 35s\n- build-openstack-sphinx-docs https://zuul.opendev.org/t/openstack/build/25be8e1b8e6442bfb5469bb6e71a6eb0 : SUCCESS in 8m 43s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d0251a3bfb21489fa95f52f332390a34 : SUCCESS in 8m 03s\n- tempest-full https://zuul.opendev.org/t/openstack/build/74c0e98f5f7e47b6a936ed08d467b090 : SUCCESS in 1h 37m 38s","accounts_in_message":[],"_revision_number":7},{"id":"7237157f9a87c1b3a6d2879d5c909ac98f41bf4b","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-06-04 20:12:41.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":7},{"id":"a24997ad2961e7dd7bdadbb7ee9b7a675e8b086f","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-06-04 20:14:22.000000000","message":"Patch Set 7:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/4f898c340e294453b8942c499f146169 : SUCCESS in 1m 21s","accounts_in_message":[],"_revision_number":7}],"current_revision_number":7,"current_revision":"a405e4b71d7de31e81a01f07e02f189650eb66fe","revisions":{"a5a27fd3281ede0d25ec5718d9c6cfdd9ff8f2c9":{"kind":"REWORK","_number":1,"created":"2020-05-07 06:32:40.000000000","uploader":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"ref":"refs/changes/46/726046/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/46/726046/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/46/726046/1"}}},"commit":{"parents":[{"commit":"5ba1b6ace597e9ce5fd25edac874c73abfabf743","subject":"Import LDAP job into project","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5ba1b6ace597e9ce5fd25edac874c73abfabf743"}]}],"author":{"name":"Colleen Murphy","email":"colleen.murphy@suse.com","date":"2020-04-14 23:47:44.000000000","tz":-420},"committer":{"name":"Guang Yee","email":"guang.yee@suse.com","date":"2020-05-07 06:32:39.000000000","tz":-420},"subject":"Fix security issues with EC2 credentials","message":"Fix security issues with EC2 credentials\n\nThis change addresses several issues in the creation and use of EC2/S3\ncredentials with keystone tokens.\n\n1. Disable altering credential owner attributes or metadata\n\nWithout this patch, an authenticated user can create an EC2 credential\nfor themself for a project they have a role on, then update the\ncredential to target a user and project completely unrelated to them. In\nthe worst case, this could be the admin user and a project the admin\nuser has a role assignment on. A token granted for an altered credential\nlike this would allow the user to masquerade as the victim user. This\npatch ensures that when updating a credential, the new form of the\ncredential is one the acting user has access to: if the system admin\nuser is changing the credential, the new user ID or project ID could be\nanything, but regular users may only change the credential to be one\nthat they still own.\n\nRelatedly, when a user uses an application credential or a trust to\ncreate an EC2 credential, keystone automatically adds the trust ID or\napplication credential ID as metadata in the EC2 access blob so that it\nknows how the token can be scoped when it is used. Without this patch, a\nuser who has created a credential in this way can update the access blob\nto remove or alter this metadata and escalate their privileges to be\nfully authorized for the trustor\u0027s, application credential creator\u0027s, or\nOAuth1 access token authorizor\u0027s privileges on the project. This patch\nfixes the issue by simply disallowing updates to keystone-controlled\nmetadata in the credential.\n\n2. Respect token roles when creating EC2 credentials\n\nWithout this patch, a trustee, an application credential user, or an\nOAuth1 access token holder could create an EC2 credential or an\napplication credential using any roles the trustor, application\ncredential creator, or access token authorizor had on the project,\nregardless of whether the creator had delegated only a limited subset of\nroles. This was because the trust_id attribute of the EC2 access blob\nwas ignored, and no metadata for the application credential or access\ntoken was recorded either. This change ensures that the access\ndelegation resource is recorded in the metadata of the EC2 credential\nwhen created and passed to the token provider when used for\nauthentication so that the token provider can look up the correct roles\nfor the request.\n\nConflicts (six removal in  e2d83ae9, pep8 fixes in e2d83ae9):\n      keystone/api/credentials.py\n      keystone/tests/unit/test_v3_application_credential.py\n      keystone/tests/unit/test_v3_credential.py\n\nConflicts due to flask reorg:\n\tkeystone/api/_shared/EC2_S3_Resource.py\n\tkeystone/api/credentials.py\n\tkeystone/api/users.py\n\tkeystone/tests/unit/test_v3_credential.py\n\nMoved the test_update_credential_non_owner unit test to\nCredentialSelfServiceTestCase since in this branch the default policies\nare not affected by #1872733.\n\nNOTE: the application credential functional changes, along with its\ntests were removed from the stable/pike backport as stable/pike does not\nsupport application credentials.\n\nChange-Id: I39d0d705839fbe31ac518ac9a82959e108cb7c1d\nCloses-bug: #1872733\nCloses-bug: #1872755\nCloses-bug: #1872735\n(cherry picked from commit 37e9907a176dad6843819b1bec4946c3aecc4548)\n(cherry picked from commit 2f2736ebb267c757ad77fcf25ee0aaeefab2a09d)\n(cherry picked from commit 27caafe3daa552663719954f2cd6713dd4493178)\n(cherry picked from commit bfba75fc3c5c8f119f74dbf31347e008824a2134)\n(cherry picked from commit 53d1ccb8a1bdbb5aa0efaacf9739b1a6f436e191)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a5a27fd3281ede0d25ec5718d9c6cfdd9ff8f2c9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a5a27fd3281ede0d25ec5718d9c6cfdd9ff8f2c9"}]},"branch":"refs/heads/stable/pike"},"ed92ec6f8c8d59ceeab1b4fc70c92d57ca4c6d92":{"kind":"REWORK","_number":2,"created":"2020-05-07 06:37:26.000000000","uploader":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"ref":"refs/changes/46/726046/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/46/726046/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/46/726046/2"}}},"commit":{"parents":[{"commit":"5ba1b6ace597e9ce5fd25edac874c73abfabf743","subject":"Import LDAP job into project","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5ba1b6ace597e9ce5fd25edac874c73abfabf743"}]}],"author":{"name":"Colleen Murphy","email":"colleen.murphy@suse.com","date":"2020-04-14 23:47:44.000000000","tz":-420},"committer":{"name":"Guang Yee","email":"guang.yee@suse.com","date":"2020-05-07 06:37:25.000000000","tz":-420},"subject":"Fix security issues with EC2 credentials","message":"Fix security issues with EC2 credentials\n\nThis change addresses several issues in the creation and use of EC2/S3\ncredentials with keystone tokens.\n\n1. Disable altering credential owner attributes or metadata\n\nWithout this patch, an authenticated user can create an EC2 credential\nfor themself for a project they have a role on, then update the\ncredential to target a user and project completely unrelated to them. In\nthe worst case, this could be the admin user and a project the admin\nuser has a role assignment on. A token granted for an altered credential\nlike this would allow the user to masquerade as the victim user. This\npatch ensures that when updating a credential, the new form of the\ncredential is one the acting user has access to: if the system admin\nuser is changing the credential, the new user ID or project ID could be\nanything, but regular users may only change the credential to be one\nthat they still own.\n\nRelatedly, when a user uses an application credential or a trust to\ncreate an EC2 credential, keystone automatically adds the trust ID or\napplication credential ID as metadata in the EC2 access blob so that it\nknows how the token can be scoped when it is used. Without this patch, a\nuser who has created a credential in this way can update the access blob\nto remove or alter this metadata and escalate their privileges to be\nfully authorized for the trustor\u0027s, application credential creator\u0027s, or\nOAuth1 access token authorizor\u0027s privileges on the project. This patch\nfixes the issue by simply disallowing updates to keystone-controlled\nmetadata in the credential.\n\n2. Respect token roles when creating EC2 credentials\n\nWithout this patch, a trustee, an application credential user, or an\nOAuth1 access token holder could create an EC2 credential or an\napplication credential using any roles the trustor, application\ncredential creator, or access token authorizor had on the project,\nregardless of whether the creator had delegated only a limited subset of\nroles. This was because the trust_id attribute of the EC2 access blob\nwas ignored, and no metadata for the application credential or access\ntoken was recorded either. This change ensures that the access\ndelegation resource is recorded in the metadata of the EC2 credential\nwhen created and passed to the token provider when used for\nauthentication so that the token provider can look up the correct roles\nfor the request.\n\nConflicts (six removal in  e2d83ae9, pep8 fixes in e2d83ae9):\n      keystone/api/credentials.py\n      keystone/tests/unit/test_v3_application_credential.py\n      keystone/tests/unit/test_v3_credential.py\n\nConflicts due to flask reorg:\n\tkeystone/api/_shared/EC2_S3_Resource.py\n\tkeystone/api/credentials.py\n\tkeystone/api/users.py\n\tkeystone/tests/unit/test_v3_credential.py\n\nMoved the test_update_credential_non_owner unit test to\nCredentialSelfServiceTestCase since in this branch the default policies\nare not affected by #1872733.\n\nNOTE: the application credential functional changes, along with its\ntests were removed from the stable/pike backport as stable/pike does not\nsupport application credentials.\n\nChange-Id: I39d0d705839fbe31ac518ac9a82959e108cb7c1d\nCloses-bug: #1872733\nCloses-bug: #1872755\nCloses-bug: #1872735\n(cherry picked from commit 37e9907a176dad6843819b1bec4946c3aecc4548)\n(cherry picked from commit 2f2736ebb267c757ad77fcf25ee0aaeefab2a09d)\n(cherry picked from commit 27caafe3daa552663719954f2cd6713dd4493178)\n(cherry picked from commit bfba75fc3c5c8f119f74dbf31347e008824a2134)\n(cherry picked from commit 53d1ccb8a1bdbb5aa0efaacf9739b1a6f436e191)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/ed92ec6f8c8d59ceeab1b4fc70c92d57ca4c6d92"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/ed92ec6f8c8d59ceeab1b4fc70c92d57ca4c6d92"}]},"branch":"refs/heads/stable/pike"},"5d8df6694d4d6752dbe5a95111d774cdd169890e":{"kind":"REWORK","_number":3,"created":"2020-05-07 16:49:47.000000000","uploader":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"ref":"refs/changes/46/726046/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/46/726046/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/46/726046/3"}}},"commit":{"parents":[{"commit":"5ba1b6ace597e9ce5fd25edac874c73abfabf743","subject":"Import LDAP job into project","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5ba1b6ace597e9ce5fd25edac874c73abfabf743"}]}],"author":{"name":"Colleen Murphy","email":"colleen.murphy@suse.com","date":"2020-04-14 23:47:44.000000000","tz":-420},"committer":{"name":"Guang Yee","email":"guang.yee@suse.com","date":"2020-05-07 16:49:31.000000000","tz":-420},"subject":"Fix security issues with EC2 credentials","message":"Fix security issues with EC2 credentials\n\nThis change addresses several issues in the creation and use of EC2/S3\ncredentials with keystone tokens.\n\n1. Disable altering credential owner attributes or metadata\n\nWithout this patch, an authenticated user can create an EC2 credential\nfor themself for a project they have a role on, then update the\ncredential to target a user and project completely unrelated to them. In\nthe worst case, this could be the admin user and a project the admin\nuser has a role assignment on. A token granted for an altered credential\nlike this would allow the user to masquerade as the victim user. This\npatch ensures that when updating a credential, the new form of the\ncredential is one the acting user has access to: if the system admin\nuser is changing the credential, the new user ID or project ID could be\nanything, but regular users may only change the credential to be one\nthat they still own.\n\nRelatedly, when a user uses an application credential or a trust to\ncreate an EC2 credential, keystone automatically adds the trust ID or\napplication credential ID as metadata in the EC2 access blob so that it\nknows how the token can be scoped when it is used. Without this patch, a\nuser who has created a credential in this way can update the access blob\nto remove or alter this metadata and escalate their privileges to be\nfully authorized for the trustor\u0027s, application credential creator\u0027s, or\nOAuth1 access token authorizor\u0027s privileges on the project. This patch\nfixes the issue by simply disallowing updates to keystone-controlled\nmetadata in the credential.\n\n2. Respect token roles when creating EC2 credentials\n\nWithout this patch, a trustee, an application credential user, or an\nOAuth1 access token holder could create an EC2 credential or an\napplication credential using any roles the trustor, application\ncredential creator, or access token authorizor had on the project,\nregardless of whether the creator had delegated only a limited subset of\nroles. This was because the trust_id attribute of the EC2 access blob\nwas ignored, and no metadata for the application credential or access\ntoken was recorded either. This change ensures that the access\ndelegation resource is recorded in the metadata of the EC2 credential\nwhen created and passed to the token provider when used for\nauthentication so that the token provider can look up the correct roles\nfor the request.\n\nConflicts (six removal in  e2d83ae9, pep8 fixes in e2d83ae9):\n      keystone/api/credentials.py\n      keystone/tests/unit/test_v3_application_credential.py\n      keystone/tests/unit/test_v3_credential.py\n\nConflicts due to flask reorg:\n\tkeystone/api/_shared/EC2_S3_Resource.py\n\tkeystone/api/credentials.py\n\tkeystone/api/users.py\n\tkeystone/tests/unit/test_v3_credential.py\n\nMoved the test_update_credential_non_owner unit test to\nCredentialSelfServiceTestCase since in this branch the default policies\nare not affected by #1872733.\n\nNOTE: the application credential functional changes, along with its\ntests were removed from the stable/pike backport as stable/pike does not\nsupport application credentials.\n\nChange-Id: I39d0d705839fbe31ac518ac9a82959e108cb7c1d\nCloses-bug: #1872733\nCloses-bug: #1872755\nCloses-bug: #1872735\n(cherry picked from commit 37e9907a176dad6843819b1bec4946c3aecc4548)\n(cherry picked from commit 2f2736ebb267c757ad77fcf25ee0aaeefab2a09d)\n(cherry picked from commit 27caafe3daa552663719954f2cd6713dd4493178)\n(cherry picked from commit bfba75fc3c5c8f119f74dbf31347e008824a2134)\n(cherry picked from commit 53d1ccb8a1bdbb5aa0efaacf9739b1a6f436e191)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5d8df6694d4d6752dbe5a95111d774cdd169890e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5d8df6694d4d6752dbe5a95111d774cdd169890e"}]},"branch":"refs/heads/stable/pike"},"64c9d15ee49561c4fd2fa47af5e66105d5d1a80b":{"kind":"REWORK","_number":4,"created":"2020-05-07 18:46:06.000000000","uploader":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"ref":"refs/changes/46/726046/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/46/726046/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/46/726046/4"}}},"commit":{"parents":[{"commit":"5ba1b6ace597e9ce5fd25edac874c73abfabf743","subject":"Import LDAP job into project","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5ba1b6ace597e9ce5fd25edac874c73abfabf743"}]}],"author":{"name":"Colleen Murphy","email":"colleen.murphy@suse.com","date":"2020-04-14 23:47:44.000000000","tz":-420},"committer":{"name":"Guang Yee","email":"guang.yee@suse.com","date":"2020-05-07 18:45:59.000000000","tz":-420},"subject":"Fix security issues with EC2 credentials","message":"Fix security issues with EC2 credentials\n\nThis change addresses several issues in the creation and use of EC2/S3\ncredentials with keystone tokens.\n\n1. Disable altering credential owner attributes or metadata\n\nWithout this patch, an authenticated user can create an EC2 credential\nfor themself for a project they have a role on, then update the\ncredential to target a user and project completely unrelated to them. In\nthe worst case, this could be the admin user and a project the admin\nuser has a role assignment on. A token granted for an altered credential\nlike this would allow the user to masquerade as the victim user. This\npatch ensures that when updating a credential, the new form of the\ncredential is one the acting user has access to: if the system admin\nuser is changing the credential, the new user ID or project ID could be\nanything, but regular users may only change the credential to be one\nthat they still own.\n\nRelatedly, when a user uses an application credential or a trust to\ncreate an EC2 credential, keystone automatically adds the trust ID or\napplication credential ID as metadata in the EC2 access blob so that it\nknows how the token can be scoped when it is used. Without this patch, a\nuser who has created a credential in this way can update the access blob\nto remove or alter this metadata and escalate their privileges to be\nfully authorized for the trustor\u0027s, application credential creator\u0027s, or\nOAuth1 access token authorizor\u0027s privileges on the project. This patch\nfixes the issue by simply disallowing updates to keystone-controlled\nmetadata in the credential.\n\n2. Respect token roles when creating EC2 credentials\n\nWithout this patch, a trustee, an application credential user, or an\nOAuth1 access token holder could create an EC2 credential or an\napplication credential using any roles the trustor, application\ncredential creator, or access token authorizor had on the project,\nregardless of whether the creator had delegated only a limited subset of\nroles. This was because the trust_id attribute of the EC2 access blob\nwas ignored, and no metadata for the application credential or access\ntoken was recorded either. This change ensures that the access\ndelegation resource is recorded in the metadata of the EC2 credential\nwhen created and passed to the token provider when used for\nauthentication so that the token provider can look up the correct roles\nfor the request.\n\nConflicts (six removal in  e2d83ae9, pep8 fixes in e2d83ae9):\n      keystone/api/credentials.py\n      keystone/tests/unit/test_v3_application_credential.py\n      keystone/tests/unit/test_v3_credential.py\n\nConflicts due to flask reorg:\n\tkeystone/api/_shared/EC2_S3_Resource.py\n\tkeystone/api/credentials.py\n\tkeystone/api/users.py\n\tkeystone/tests/unit/test_v3_credential.py\n\nMoved the test_update_credential_non_owner unit test to\nCredentialSelfServiceTestCase since in this branch the default policies\nare not affected by #1872733.\n\nNOTE: the application credential functional changes, along with its\ntests were removed from the stable/pike backport as stable/pike does not\nsupport application credentials.\n\nChange-Id: I39d0d705839fbe31ac518ac9a82959e108cb7c1d\nCloses-bug: #1872733\nCloses-bug: #1872755\nCloses-bug: #1872735\n(cherry picked from commit 37e9907a176dad6843819b1bec4946c3aecc4548)\n(cherry picked from commit 2f2736ebb267c757ad77fcf25ee0aaeefab2a09d)\n(cherry picked from commit 27caafe3daa552663719954f2cd6713dd4493178)\n(cherry picked from commit bfba75fc3c5c8f119f74dbf31347e008824a2134)\n(cherry picked from commit 53d1ccb8a1bdbb5aa0efaacf9739b1a6f436e191)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/64c9d15ee49561c4fd2fa47af5e66105d5d1a80b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/64c9d15ee49561c4fd2fa47af5e66105d5d1a80b"}]},"branch":"refs/heads/stable/pike"},"20ad559e05dda18b1fb01bb331b644fa6d6faaee":{"kind":"NO_CODE_CHANGE","_number":5,"created":"2020-05-08 17:09:47.000000000","uploader":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"ref":"refs/changes/46/726046/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/46/726046/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/46/726046/5"}}},"commit":{"parents":[{"commit":"5ba1b6ace597e9ce5fd25edac874c73abfabf743","subject":"Import LDAP job into project","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5ba1b6ace597e9ce5fd25edac874c73abfabf743"}]}],"author":{"name":"Colleen Murphy","email":"colleen.murphy@suse.com","date":"2020-04-14 23:47:44.000000000","tz":-420},"committer":{"name":"guang-yee","email":"gyee@suse.com","date":"2020-05-08 17:09:40.000000000","tz":0},"subject":"Fix security issues with EC2 credentials","message":"Fix security issues with EC2 credentials\n\nThis change addresses several issues in the creation and use of EC2/S3\ncredentials with keystone tokens.\n\n1. Disable altering credential owner attributes or metadata\n\nWithout this patch, an authenticated user can create an EC2 credential\nfor themself for a project they have a role on, then update the\ncredential to target a user and project completely unrelated to them. In\nthe worst case, this could be the admin user and a project the admin\nuser has a role assignment on. A token granted for an altered credential\nlike this would allow the user to masquerade as the victim user. This\npatch ensures that when updating a credential, the new form of the\ncredential is one the acting user has access to: if the system admin\nuser is changing the credential, the new user ID or project ID could be\nanything, but regular users may only change the credential to be one\nthat they still own.\n\nRelatedly, when a user uses an application credential or a trust to\ncreate an EC2 credential, keystone automatically adds the trust ID or\napplication credential ID as metadata in the EC2 access blob so that it\nknows how the token can be scoped when it is used. Without this patch, a\nuser who has created a credential in this way can update the access blob\nto remove or alter this metadata and escalate their privileges to be\nfully authorized for the trustor\u0027s, application credential creator\u0027s, or\nOAuth1 access token authorizor\u0027s privileges on the project. This patch\nfixes the issue by simply disallowing updates to keystone-controlled\nmetadata in the credential.\n\n2. Respect token roles when creating EC2 credentials\n\nWithout this patch, a trustee, an application credential user, or an\nOAuth1 access token holder could create an EC2 credential or an\napplication credential using any roles the trustor, application\ncredential creator, or access token authorizor had on the project,\nregardless of whether the creator had delegated only a limited subset of\nroles. This was because the trust_id attribute of the EC2 access blob\nwas ignored, and no metadata for the application credential or access\ntoken was recorded either. This change ensures that the access\ndelegation resource is recorded in the metadata of the EC2 credential\nwhen created and passed to the token provider when used for\nauthentication so that the token provider can look up the correct roles\nfor the request.\n\nConflicts (six removal in  e2d83ae9, pep8 fixes in e2d83ae9):\n      keystone/api/credentials.py\n      keystone/tests/unit/test_v3_application_credential.py\n      keystone/tests/unit/test_v3_credential.py\n\nConflicts due to flask reorg:\n\tkeystone/api/_shared/EC2_S3_Resource.py\n\tkeystone/api/credentials.py\n\tkeystone/api/users.py\n\tkeystone/tests/unit/test_v3_credential.py\n\nMoved the test_update_credential_non_owner unit test to\nCredentialSelfServiceTestCase since in this branch the default policies\nare not affected by #1872733.\n\nNOTE: the application credential functional changes, along with its\ntests were removed from the stable/pike backport as stable/pike does not\nsupport application credentials.\n\nChange-Id: I39d0d705839fbe31ac518ac9a82959e108cb7c1d\nCloses-bug: #1872733\nCloses-bug: #1872755\nCloses-bug: #1872735\n(cherry picked from commit 37e9907a176dad6843819b1bec4946c3aecc4548)\n(cherry picked from commit 2f2736ebb267c757ad77fcf25ee0aaeefab2a09d)\n(cherry picked from commit 27caafe3daa552663719954f2cd6713dd4493178)\n(cherry picked from commit bfba75fc3c5c8f119f74dbf31347e008824a2134)\n(cherry picked from commit 53d1ccb8a1bdbb5aa0efaacf9739b1a6f436e191)\n(cherry picked from commit 6db1bb09a048dfb7f337484698a9a19fdbbe9546)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/20ad559e05dda18b1fb01bb331b644fa6d6faaee"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/20ad559e05dda18b1fb01bb331b644fa6d6faaee"}]},"branch":"refs/heads/stable/pike"},"bc165157ebed5b5c60dafb7eca343b21156f006e":{"kind":"REWORK","_number":6,"created":"2020-05-28 17:03:08.000000000","uploader":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"ref":"refs/changes/46/726046/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/46/726046/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/46/726046/6"}}},"commit":{"parents":[{"commit":"5ba1b6ace597e9ce5fd25edac874c73abfabf743","subject":"Import LDAP job into project","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5ba1b6ace597e9ce5fd25edac874c73abfabf743"}]}],"author":{"name":"Colleen Murphy","email":"colleen.murphy@suse.com","date":"2020-04-14 23:47:44.000000000","tz":-420},"committer":{"name":"Guang Yee","email":"guang.yee@suse.com","date":"2020-05-28 17:02:59.000000000","tz":-420},"subject":"Fix security issues with EC2 credentials","message":"Fix security issues with EC2 credentials\n\nThis change addresses several issues in the creation and use of EC2/S3\ncredentials with keystone tokens.\n\n1. Disable altering credential owner attributes or metadata\n\nWithout this patch, an authenticated user can create an EC2 credential\nfor themself for a project they have a role on, then update the\ncredential to target a user and project completely unrelated to them. In\nthe worst case, this could be the admin user and a project the admin\nuser has a role assignment on. A token granted for an altered credential\nlike this would allow the user to masquerade as the victim user. This\npatch ensures that when updating a credential, the new form of the\ncredential is one the acting user has access to: if the system admin\nuser is changing the credential, the new user ID or project ID could be\nanything, but regular users may only change the credential to be one\nthat they still own.\n\nRelatedly, when a user uses an application credential or a trust to\ncreate an EC2 credential, keystone automatically adds the trust ID or\napplication credential ID as metadata in the EC2 access blob so that it\nknows how the token can be scoped when it is used. Without this patch, a\nuser who has created a credential in this way can update the access blob\nto remove or alter this metadata and escalate their privileges to be\nfully authorized for the trustor\u0027s, application credential creator\u0027s, or\nOAuth1 access token authorizor\u0027s privileges on the project. This patch\nfixes the issue by simply disallowing updates to keystone-controlled\nmetadata in the credential.\n\n2. Respect token roles when creating EC2 credentials\n\nWithout this patch, a trustee, an application credential user, or an\nOAuth1 access token holder could create an EC2 credential or an\napplication credential using any roles the trustor, application\ncredential creator, or access token authorizor had on the project,\nregardless of whether the creator had delegated only a limited subset of\nroles. This was because the trust_id attribute of the EC2 access blob\nwas ignored, and no metadata for the application credential or access\ntoken was recorded either. This change ensures that the access\ndelegation resource is recorded in the metadata of the EC2 credential\nwhen created and passed to the token provider when used for\nauthentication so that the token provider can look up the correct roles\nfor the request.\n\nConflicts (six removal in  e2d83ae9, pep8 fixes in e2d83ae9):\n      keystone/api/credentials.py\n      keystone/tests/unit/test_v3_application_credential.py\n      keystone/tests/unit/test_v3_credential.py\n\nConflicts due to flask reorg:\n\tkeystone/api/_shared/EC2_S3_Resource.py\n\tkeystone/api/credentials.py\n\tkeystone/api/users.py\n\tkeystone/tests/unit/test_v3_credential.py\n\nMoved the test_update_credential_non_owner unit test to\nCredentialSelfServiceTestCase since in this branch the default policies\nare not affected by #1872733.\n\nNOTE: the application credential functional changes, along with its\ntests were removed from the stable/pike backport as stable/pike does not\nsupport application credentials.\n\nChange-Id: I39d0d705839fbe31ac518ac9a82959e108cb7c1d\nCloses-bug: #1872733\nCloses-bug: #1872755\nCloses-bug: #1872735\n(cherry picked from commit 37e9907a176dad6843819b1bec4946c3aecc4548)\n(cherry picked from commit 2f2736ebb267c757ad77fcf25ee0aaeefab2a09d)\n(cherry picked from commit 27caafe3daa552663719954f2cd6713dd4493178)\n(cherry picked from commit bfba75fc3c5c8f119f74dbf31347e008824a2134)\n(cherry picked from commit 53d1ccb8a1bdbb5aa0efaacf9739b1a6f436e191)\n(cherry picked from commit 6db1bb09a048dfb7f337484698a9a19fdbbe9546)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/bc165157ebed5b5c60dafb7eca343b21156f006e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/bc165157ebed5b5c60dafb7eca343b21156f006e"}]},"branch":"refs/heads/stable/pike"},"a405e4b71d7de31e81a01f07e02f189650eb66fe":{"kind":"REWORK","_number":7,"created":"2020-06-03 16:54:02.000000000","uploader":{"_account_id":1916,"name":"Guang Yee","email":"gyee@suse.com","username":"guang-yee"},"ref":"refs/changes/46/726046/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/46/726046/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/46/726046/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/46/726046/7"}}},"commit":{"parents":[{"commit":"7f90daa99927db361280deb7e8e837b18c74ad8b","subject":"Merge \"Check timestamp of signed EC2 token request\" into stable/pike","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7f90daa99927db361280deb7e8e837b18c74ad8b"}]}],"author":{"name":"Colleen Murphy","email":"colleen.murphy@suse.com","date":"2020-04-14 23:47:44.000000000","tz":-420},"committer":{"name":"Guang Yee","email":"guang.yee@suse.com","date":"2020-06-03 16:54:00.000000000","tz":-420},"subject":"Fix security issues with EC2 credentials","message":"Fix security issues with EC2 credentials\n\nThis change addresses several issues in the creation and use of EC2/S3\ncredentials with keystone tokens.\n\n1. Disable altering credential owner attributes or metadata\n\nWithout this patch, an authenticated user can create an EC2 credential\nfor themself for a project they have a role on, then update the\ncredential to target a user and project completely unrelated to them. In\nthe worst case, this could be the admin user and a project the admin\nuser has a role assignment on. A token granted for an altered credential\nlike this would allow the user to masquerade as the victim user. This\npatch ensures that when updating a credential, the new form of the\ncredential is one the acting user has access to: if the system admin\nuser is changing the credential, the new user ID or project ID could be\nanything, but regular users may only change the credential to be one\nthat they still own.\n\nRelatedly, when a user uses an application credential or a trust to\ncreate an EC2 credential, keystone automatically adds the trust ID or\napplication credential ID as metadata in the EC2 access blob so that it\nknows how the token can be scoped when it is used. Without this patch, a\nuser who has created a credential in this way can update the access blob\nto remove or alter this metadata and escalate their privileges to be\nfully authorized for the trustor\u0027s, application credential creator\u0027s, or\nOAuth1 access token authorizor\u0027s privileges on the project. This patch\nfixes the issue by simply disallowing updates to keystone-controlled\nmetadata in the credential.\n\n2. Respect token roles when creating EC2 credentials\n\nWithout this patch, a trustee, an application credential user, or an\nOAuth1 access token holder could create an EC2 credential or an\napplication credential using any roles the trustor, application\ncredential creator, or access token authorizor had on the project,\nregardless of whether the creator had delegated only a limited subset of\nroles. This was because the trust_id attribute of the EC2 access blob\nwas ignored, and no metadata for the application credential or access\ntoken was recorded either. This change ensures that the access\ndelegation resource is recorded in the metadata of the EC2 credential\nwhen created and passed to the token provider when used for\nauthentication so that the token provider can look up the correct roles\nfor the request.\n\nConflicts (six removal in  e2d83ae9, pep8 fixes in e2d83ae9):\n      keystone/api/credentials.py\n      keystone/tests/unit/test_v3_application_credential.py\n      keystone/tests/unit/test_v3_credential.py\n\nConflicts due to flask reorg:\n\tkeystone/api/_shared/EC2_S3_Resource.py\n\tkeystone/api/credentials.py\n\tkeystone/api/users.py\n\tkeystone/tests/unit/test_v3_credential.py\n\nMoved the test_update_credential_non_owner unit test to\nCredentialSelfServiceTestCase since in this branch the default policies\nare not affected by #1872733.\n\nNOTE: the application credential functional changes, along with its\ntests were removed from the stable/pike backport as stable/pike does not\nsupport application credentials.\n\nChange-Id: I39d0d705839fbe31ac518ac9a82959e108cb7c1d\nCloses-bug: #1872733\nCloses-bug: #1872755\nCloses-bug: #1872735\n(cherry picked from commit 37e9907a176dad6843819b1bec4946c3aecc4548)\n(cherry picked from commit 2f2736ebb267c757ad77fcf25ee0aaeefab2a09d)\n(cherry picked from commit 27caafe3daa552663719954f2cd6713dd4493178)\n(cherry picked from commit bfba75fc3c5c8f119f74dbf31347e008824a2134)\n(cherry picked from commit 53d1ccb8a1bdbb5aa0efaacf9739b1a6f436e191)\n(cherry picked from commit 6db1bb09a048dfb7f337484698a9a19fdbbe9546)\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a405e4b71d7de31e81a01f07e02f189650eb66fe"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a405e4b71d7de31e81a01f07e02f189650eb66fe"}]},"branch":"refs/heads/stable/pike"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
