)]}'
{"id":"openstack%2Fkeystone~755734","triplet_id":"openstack%2Fkeystone~stable%2Fvictoria~Ia45a45ff852d0d4e3a713dae07a46d4ff8d370f3","project":"openstack/keystone","branch":"stable/victoria","hashtags":[],"change_id":"Ia45a45ff852d0d4e3a713dae07a46d4ff8d370f3","subject":"Implement more robust connection handling for asynchronous LDAP calls","status":"MERGED","created":"2020-10-02 09:21:43.000000000","updated":"2020-10-21 19:10:24.000000000","submitted":"2020-10-21 19:07:51.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"755734-1603307271536-d4ae1b61","meta_rev_id":"4d2906bd7f2bb9ed7401f7eb74b65d2443d7976b","_number":755734,"virtual_id_number":755734,"owner":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"date":"2020-10-21 14:00:57.000000000","_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},{"value":0,"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2020-10-21 19:07:51.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"recommended":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"all":[{"value":1,"date":"2020-10-19 14:47:33.000000000","permitted_voting_range":{"min":1,"max":2},"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},{"value":2,"date":"2020-10-19 14:37:00.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"all":[{"value":0,"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"date":"2020-10-02 09:21:43.000000000","_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},{"value":1,"date":"2020-10-19 15:36:56.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"date":"2020-10-18 14:48:21.000000000","_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2020-10-02 09:21:43.000000000","updated_by":{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},"reviewer":{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},"state":"REVIEWER"},{"updated":"2020-10-18 14:48:21.000000000","updated_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"reviewer":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"state":"REVIEWER"},{"updated":"2020-10-19 14:47:33.000000000","updated_by":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"reviewer":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"state":"REVIEWER"},{"updated":"2020-10-19 15:36:56.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"state":"REVIEWER"},{"updated":"2020-10-21 19:07:51.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"32589c78f8347473ba1263a3745914f6337f19e0","author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"date":"2020-10-02 09:21:43.000000000","message":"Patch Set 1: Cherry Picked from branch master.","accounts_in_message":[],"_revision_number":1},{"id":"f10f7a88cd69a4735a08dcea0d399b3083bf5a0d","author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"date":"2020-10-02 09:22:10.000000000","message":"Patch Set 1: Cherry Picked\n\nThis patchset was cherry picked to branch stable/ussuri as commit 35c7406bffdd71cf63c65b8628f4eafa28baaac7","accounts_in_message":[],"_revision_number":1},{"id":"14383f51fd5540c2b877fd74820a47bc4aab4dea","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-02 15:43:26.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/0128e07b15924018955dbd0c4201c69f : SUCCESS in 17m 15s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/4a15d4aaa07545a4882751611d146ae2 : SUCCESS in 12m 13s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/416f2c2154914c70af6eaacad42d1cc0 : SUCCESS in 6m 02s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/0c170283afcc499cb37b11dceb0a3a6a : SUCCESS in 12m 27s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/ab7de331442543229d785c7effb76c81 : SUCCESS in 13m 15s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/be50400b5ef74c4abc384879653c36a8 : SUCCESS in 14m 05s\n- grenade https://zuul.opendev.org/t/openstack/build/663ff30ba2a74ab6a8dcdef1f8ffd465 : SUCCESS in 1h 01m 35s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/3e9373ea4744425db035cd5b47b99c54 : SUCCESS in 1h 18m 19s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/02fe004288604a12b1e08cba4c575db3 : SUCCESS in 7m 46s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/862e7d2d2869494e8faff2bc4a00a2bb : SUCCESS in 33m 00s\n- keystone-dsvm-py3-functional-federation-ubuntu-focal https://zuul.opendev.org/t/openstack/build/396b190c6f9c4d049381da248751152d : SUCCESS in 31m 05s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-focal-k2k https://zuul.opendev.org/t/openstack/build/3e13fd7a0e7a49afb64e5a7f7ffa611f : SUCCESS in 33m 43s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/d4584a1bddd946009e2acb0b0b88f7e5 : SUCCESS in 15m 43s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/191cac274d264e9092a8f56b15969e19 : FAILURE in 12m 04s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/dc7d05b374cc4135b083aedee020fc50 : SUCCESS in 1h 12m 35s\n- keystone-tox-protection https://zuul.opendev.org/t/openstack/build/cdfd7077f9894d399762b6344e96ad05 : SUCCESS in 37m 05s","accounts_in_message":[],"_revision_number":1},{"id":"b2d8dafcd5737218898c80d8bddf74399f1fe7af","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-10-19 14:37:00.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"6342704a6de0cfb03e2013803965e40eb482abb8","author":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"date":"2020-10-19 14:47:33.000000000","message":"Patch Set 1: Code-Review+1","accounts_in_message":[],"_revision_number":1},{"id":"fe0c09f8494070edfb59b0b40ded94d3c59cd64c","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-10-19 15:36:56.000000000","message":"Patch Set 1: Workflow+1","accounts_in_message":[],"_revision_number":1},{"id":"41ee0adce7262bcae0e0a80fcf11b61c692ebcef","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-19 15:37:48.000000000","message":"Patch Set 1: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":1},{"id":"097a039ac421e1d66c592612eb7474159136fb71","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-19 17:19:41.000000000","message":"Patch Set 1: Verified-2\n\nBuild failed (gate pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/28da8c1a95724720871ea141bc8ab1a8 : SUCCESS in 15m 46s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/c3c0a7a5dbfa4d898047e9124986fbb4 : SUCCESS in 12m 11s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/576cce0ac44d40ad8d2a503ea0616567 : SUCCESS in 20m 02s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/5f2dd12a3e4e4a428827f63bb1192310 : SUCCESS in 20m 00s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ad3ade6a35524d0b82aa3fac0825f1cf : SUCCESS in 17m 47s\n- grenade https://zuul.opendev.org/t/openstack/build/7ab3e431012942c49abfebd94af62d8b : SUCCESS in 1h 11m 43s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/d23ba5fc6c1043f48bcf038587e584aa : SUCCESS in 1h 34m 26s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/13dc83c9beea41e2b0bc64ef6861e59b : SUCCESS in 13m 13s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/dfb45e26afaf4062b2da1609f736849a : SUCCESS in 40m 02s\n- keystone-dsvm-py3-functional-federation-ubuntu-focal-k2k https://zuul.opendev.org/t/openstack/build/ab0f8c9933654972b7c31fecdc0b8714 : SUCCESS in 37m 26s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/11d1f2cf0f2f408ba9e100df45effda4 : SUCCESS in 1h 00m 23s\n- keystone-tox-protection https://zuul.opendev.org/t/openstack/build/e8377255263c479793b4a4ef683c793d : RETRY_LIMIT in 22m 27s","accounts_in_message":[],"_revision_number":1},{"id":"8bb61aab7ea0ee777b6c3c06fdce700cdd410e07","author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"date":"2020-10-21 14:00:57.000000000","message":"Patch Set 1:\n\nrecheck","accounts_in_message":[],"_revision_number":1},{"id":"8256bfc994d66ec2ef5ee51374741a3f41e22305","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 15:43:52.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/db73dda6a4ff4066951f91036d45fec9 : SUCCESS in 18m 24s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/188dc8839a2f490585a288398c026c49 : SUCCESS in 13m 10s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/edb0496244d04f19b28fae3d18ec6693 : SUCCESS in 7m 55s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/a3453afda4a0481092506e29cdaff6f4 : SUCCESS in 14m 36s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/5388c72f9cde42fcb430b09c28cccfe1 : SUCCESS in 16m 11s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d5bbf312a312469180c65bba795d92f9 : SUCCESS in 15m 06s\n- grenade https://zuul.opendev.org/t/openstack/build/39919394e7804dd69b4776c13b28ddd2 : SUCCESS in 54m 42s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/eb202ea327524199b77667d0040d7dab : SUCCESS in 1h 35m 00s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/f8e516b7d2a1450eb9017899359c6099 : SUCCESS in 9m 17s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/1ebe96b3787e498c97d1dcd6ab5021ea : SUCCESS in 38m 15s\n- keystone-dsvm-py3-functional-federation-ubuntu-focal https://zuul.opendev.org/t/openstack/build/42d7baaefb3c416cb31ba34a77126828 : FAILURE in 42m 58s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-focal-k2k https://zuul.opendev.org/t/openstack/build/2039de3ebffb4ec2bde9d2e004a72429 : SUCCESS in 34m 32s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/f71c6be4fff7400bb149a9cf0ec6738a : SUCCESS in 30m 33s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/1576692812ae47e9839890923c345752 : FAILURE in 17m 29s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/dd5ea6d40295482084c3f9d5f59e2103 : SUCCESS in 1h 12m 10s\n- keystone-tox-protection https://zuul.opendev.org/t/openstack/build/304606104f1d472d9f76dbc1795edcfa : SUCCESS in 38m 58s","accounts_in_message":[],"_revision_number":1},{"id":"8c196cd48ae78adb473c23dd8149eb0b126e4145","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 15:44:27.000000000","message":"Patch Set 1: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":1},{"id":"798068c642454136c50f10f000110259830cce5e","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 19:07:51.000000000","message":"Patch Set 1: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/717b66e88e5b490ab69051e742b39552 : SUCCESS in 15m 28s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/34d65a385c884e0894e9e58124606145 : SUCCESS in 9m 01s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/0b9705af649c4ad79991547f42411c69 : SUCCESS in 16m 17s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/e2e87d12edc946499a154f50dcee6006 : SUCCESS in 16m 14s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/7755f43e1e124992bf13faae348d722d : SUCCESS in 16m 28s\n- grenade https://zuul.opendev.org/t/openstack/build/582fc9e892944bebb6d6c9c9fa24725a : SUCCESS in 1h 03m 14s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/4b9fee3bdf0a4922bf2056f2e4f5205d : SUCCESS in 1h 21m 13s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/cf5d008f6a1f442088597ff602c43922 : SUCCESS in 10m 34s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/e1821ffdff4548b590ec0b39ed37bb57 : SUCCESS in 30m 32s\n- keystone-dsvm-py3-functional-federation-ubuntu-focal-k2k https://zuul.opendev.org/t/openstack/build/bd444370332d484ca8381cdfdf28061f : SUCCESS in 33m 37s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/b325c72147514540b54bec0215b67e2f : SUCCESS in 1h 00m 38s\n- keystone-tox-protection https://zuul.opendev.org/t/openstack/build/90ddc91d06f148ce9ed778e55aa11d3c : SUCCESS in 39m 19s","accounts_in_message":[],"_revision_number":1},{"id":"0e2808eea51bd9aac6e4ec4865b112977729705f","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 19:07:51.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":1},{"id":"4d2906bd7f2bb9ed7401f7eb74b65d2443d7976b","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 19:10:24.000000000","message":"Patch Set 1:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/a9b78b2a12844a27a9b57279fbf9fd12 : SUCCESS in 2m 00s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/76e9d682833d4d588a5fb51b9f3795a5 : SUCCESS in 59s","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"a26a40d441e7f211fd68e0c1b9c779d965c19dea","revisions":{"a26a40d441e7f211fd68e0c1b9c779d965c19dea":{"kind":"REWORK","_number":1,"created":"2020-10-02 09:21:43.000000000","uploader":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"ref":"refs/changes/34/755734/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/34/755734/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/34/755734/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/34/755734/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/34/755734/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/34/755734/1"}}},"commit":{"parents":[{"commit":"db25e505a30b10ed8a2a66c4674e20130dd5d5e0","subject":"[goal] Migrate testing to ubuntu focal","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/db25e505a30b10ed8a2a66c4674e20130dd5d5e0"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2020-09-29 15:20:13.000000000","tz":-300},"committer":{"name":"Moisés Guimarães","email":"moguimar@redhat.com","date":"2020-10-02 09:21:43.000000000","tz":0},"subject":"Implement more robust connection handling for asynchronous LDAP calls","message":"Implement more robust connection handling for asynchronous LDAP calls\n\nKeystone\u0027s paging implementation contains a memory leak. The issue is\nnoticeable if you integrate keystone with an LDAP server that supports\npaging and set `keystone.conf [ldap] page_size` to a low integer\n(e.g., 5).\n\nKeystone\u0027s LDAP backend uses `python-ldap` to interact with LDAP\nservers. For paged requests, it uses `search_ext()`, which is an\nasynchronous API [0]. The server responds with a message ID, which the\nclient uses to retrieve all data for the request. In keystone\u0027s case,\nthe `search_ext()` method is invoked with a page control that tells\nthe server to deliver responses in increments according to the page\nsize configured with `keystone.conf [ldap] page_size`. So long as the\nclient has the original connection used to fetch the message ID, it\ncan request the rest of the information associated to the request.\n\nKeystone\u0027s paging implementation loops continuously for paged\nrequests. It takes the message ID it gets from `search_ext()` and\ncalls `result3()`, asking the server for the data associated with that\nspecific message. Keystone continues to do this until the server sends\nan indicator that it has no more data relevant to the query (via a\ncookie). The `search_ext()` and `result3()` methods must use the same\nLDAP connection.\n\nGiven the above information, keystone uses context managers to provide\nconnections. This is relevant when deploying connection pools, where\ncertain connections are re-used from a pool. Keystone relies on Python\ncontext managers to handle connections, which is pretty typical\nuse-case for context managers. Connection managers allow us to do the\nfollowing (assuming pseudocode):\n\n  with self.get_connection as conn:\n      response \u003d conn.search_s()\n      return format(response)\n\nThe above snippet assumes the `get_connection` method provides a\nconnection object and a callable that implements `search_s`. Upon\nexiting the `with` statement, the connection is disconnected, or put\nback into the pool, or whatever the implementation of the context\nmanager decides to do. Most connections in the LDAP backend are\nhandled in this fashion.\n\nUnfortunately, the LDAP driver is somewhat oblivious to paging, it\u0027s\ncontrol implementation, or the fact that it uses an asynchronous API.\nInstead, the driver leaves it up to the handler objects it uses for\nconnections to determine if the request should be controlled via\npaging. This is an anti-pattern since the backend establishes the\nconnection for the request but doesn\u0027t ensure that connection is\nsafely handled for asynchronous APIs.\n\nThis forces the `search_ext()` and `result3()` implementations in the\nPooledLDAPHandler to know how to handle connections and context\nmanagers, since it needs to ensure the same connection is used for\npaged requests. The current code tried to clean up the context\nmanager responsible for connections after the results are collected\nfrom the server using the message ID. I believe it does this because\nit needs to get a new connection for each message in the paged\nresults, even though it already operates from within a connection\nestablished via a context manager and the PooledLDAPHandler almost\nalways returns the same connection object from the pool. The code\ntries to use a weak reference to create a callback that tears down the\ncontext manager when nothing else references it. At a high-level, the\nidea is similar to the following pseudocode:\n\n  with self.get_connection as conn:\n      while True:\n\tldap_data \u003d []\n\tcontext_manager \u003d self.get_connection()\n\tconnection \u003d context_manager.__enter__()\n\tmessage_id \u003d connection.search_ext()\n\tresults \u003d connection.result3(message_id)\n\tldap_data.append(results)\n\tcontext_manager.__exit__()\n\nI wasn\u0027t able to see the callback get invoked or work as described in\ncomments, resulting in memory bloat, especially with low page sizes\nwhich results in more requests. A weak reference invokes the callback\nwhen the weak reference is called, but there are no other references\nto the original object [1]. In our case, I don\u0027t think we invoke that\npath because we don\u0027t actually do anything with the weak reference. We\nassume it\u0027s going to run the callback when the object is garbage\ncollected.\n\nThis commit attempts to address this issue by using the concept of a\nfinalizer [2], which was designed for similar cases. It also attempts\nto hide the cleanup implementation in the AsynchronousMessage object,\nso that callers don\u0027t have to worry about making sure they invoke the\nfinalizer.\n\nAn alternative approach would be to push more of the paging logic and\nimplementation up into the LDAP driver. This would make it easier to\nput the entire asynchronous API flow for paging into a `with`\nstatement and relying on the normal behavior of context managers to\nclean up accordingly. This approach would remove the manual cleanup\ninvocation, regardless of using weak references or finalizer objects.\nHowever, this approach would likely require a non-trivial amount of\ndesign work to refactor the entire LDAP backend. The LDAP backend has\nother issues that would complicate the re-design process:\n\n  - Handlers and connection are generalized to mean the same thing\n  - Method names don\u0027t follow a convention\n  - Domain-specific language from python-ldap bleeds into keystone\u0027s\n    implementation (e.g., get_all, _ldap_get_all, add_member) at\n    different points in the backend (e.g., UserApi (BaseLdap), GroupApi\n    (BaseLdap), KeystoneLDAPHandler, PooledLDAPHandler,\n    PythonLDAPHandler)\n  - Backend contains dead code from when keystone supported writeable\n    LDAP backends\n  - Responsibility for connections and connection handling is spread\n    across objects (BaseLdap, LDAPHandler)\n  - Handlers will invoke methods differently based on configuration at\n    runtime, which is a sign that the relationship between the driver,\n    handlers, and connection objects isn\u0027t truely polymorphic\n\nWhile keeping the logic for properly handling context managers and\nconnections in the Handlers might not be ideal, it is a relatively\nminimal fix in comparison to a re-design or backend refactor. These\nissues can be considered during a refactor of the LDAP backend if or\nwhen the community decides to re-design the LDAP backend.\n\n[0] https://www.python-ldap.org/en/python-ldap-3.3.0/reference/ldap.html#ldap.LDAPObject.search_ext\n[1] https://docs.python.org/3/library/weakref.html#weakref.ref\n[2] https://docs.python.org/3/library/weakref.html#finalizer-objects\n\nCloses-Bug: 1896125\nChange-Id: Ia45a45ff852d0d4e3a713dae07a46d4ff8d370f3\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a26a40d441e7f211fd68e0c1b9c779d965c19dea"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a26a40d441e7f211fd68e0c1b9c779d965c19dea"}]},"branch":"refs/heads/stable/victoria"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
