)]}'
{"id":"openstack%2Fkeystone~755735","triplet_id":"openstack%2Fkeystone~stable%2Fussuri~Ia45a45ff852d0d4e3a713dae07a46d4ff8d370f3","project":"openstack/keystone","branch":"stable/ussuri","hashtags":[],"change_id":"Ia45a45ff852d0d4e3a713dae07a46d4ff8d370f3","subject":"Implement more robust connection handling for asynchronous LDAP calls","status":"MERGED","created":"2020-10-02 09:22:10.000000000","updated":"2020-10-21 23:34:56.000000000","submitted":"2020-10-21 23:32:43.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"755735-1603323163615-4cccc635","meta_rev_id":"d8b1ac2b8d5f0a3bcd592cf993d9add3daddee1b","_number":755735,"virtual_id_number":755735,"owner":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"date":"2020-10-18 14:55:40.000000000","_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},{"value":0,"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2020-10-21 23:32:28.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"recommended":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"all":[{"value":1,"date":"2020-10-19 14:48:06.000000000","permitted_voting_range":{"min":1,"max":2},"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},{"value":2,"date":"2020-10-19 14:37:10.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"all":[{"value":0,"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"value":0,"date":"2020-10-02 09:22:10.000000000","_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},{"value":1,"date":"2020-10-21 21:39:27.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"date":"2020-10-18 14:49:05.000000000","_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2020-10-02 09:22:10.000000000","updated_by":{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},"reviewer":{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},"state":"REVIEWER"},{"updated":"2020-10-18 14:49:05.000000000","updated_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"reviewer":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"state":"REVIEWER"},{"updated":"2020-10-19 14:48:06.000000000","updated_by":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"reviewer":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"state":"REVIEWER"},{"updated":"2020-10-21 21:39:27.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"state":"REVIEWER"},{"updated":"2020-10-21 23:32:28.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"d6b4dd804dad8fb4c878384dd257747f0f96f148","author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"date":"2020-10-02 09:22:10.000000000","message":"Patch Set 1: Cherry Picked from branch stable/victoria.","accounts_in_message":[],"_revision_number":1},{"id":"32fd154e945accd79962be91c528afb1ca21a401","author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"date":"2020-10-02 09:22:22.000000000","message":"Patch Set 1: Cherry Picked\n\nThis patchset was cherry picked to branch stable/train as commit 36b49fb4f1a0c69efffe6425701c5a942833be40","accounts_in_message":[],"_revision_number":1},{"id":"6b5655a3bdc3440a631b2a247986f4b823a095c7","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-02 16:20:47.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/82c4a238bb014cc898839a0963cdd3df : SUCCESS in 15m 16s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/66b4b2abf8aa431a8ea77e16617b806c : FAILURE in 12m 45s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/8e44dea02fd14670b3cb127013806454 : SUCCESS in 6m 38s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/91cfcc7cc7004b82b28e5c7469fca19a : SUCCESS in 18m 44s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/14756e3a367941ef954ba001278f23d9 : SUCCESS in 24m 31s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c078f1f5b9544878af0cf135c5c3aec4 : SUCCESS in 14m 03s\n- grenade https://zuul.opendev.org/t/openstack/build/c262513691834982a4a0fd777f24fe3d : SUCCESS in 1h 10m 01s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/ba680f639074412ca75419fd58bc922e : SUCCESS in 1h 32m 45s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ac3623b9503c48118929ab4757e32e6a : SUCCESS in 8m 09s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/ae9edbae2fe24bad881df7b297007421 : SUCCESS in 32m 06s\n- keystone-dsvm-py3-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/85986223e49c4335a4655843839cba54 : FAILURE in 8m 06s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15-k2k https://zuul.opendev.org/t/openstack/build/1e6d6cb1f443491897924ce2303ac2cf : FAILURE in 7m 15s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/39bc089679e34ec099247c9388f17aaf : FAILURE in 12m 38s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/180fbfc5b17242eea4fbfe1e5a3ef0da : SUCCESS in 37m 21s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/84f5af29a75d499c96814c8de33f23f6 : SUCCESS in 52m 16s\n- keystone-tox-protection https://zuul.opendev.org/t/openstack/build/626feb8932c745de8a0eb762c4695f8c : SUCCESS in 34m 14s","accounts_in_message":[],"_revision_number":1},{"id":"230ab156a1f537811eb258e2ef250dace9c5d00a","author":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"date":"2020-10-18 14:55:40.000000000","message":"Patch Set 1:\n\nrecheck","accounts_in_message":[],"_revision_number":1},{"id":"9158bd177cab65a27431cbdd59e5b8a2546d9592","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-18 16:27:08.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/011e725000b24080be1a77ee8fc0e164 : SUCCESS in 16m 28s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/082d6a1430544a22aa89c50128bdc7ad : SUCCESS in 17m 23s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/878b64c391794c4b8b061b07540925af : SUCCESS in 7m 05s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/e1e207b3c8ee4ce2aff3390a62b92ed6 : SUCCESS in 20m 01s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/49ccc16b60ff4c15b03ee97a57ffdc88 : SUCCESS in 15m 07s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/dbcb913c18634270856bf09262c2e254 : SUCCESS in 14m 10s\n- grenade https://zuul.opendev.org/t/openstack/build/221f783aa5474d5b833947ba5b68d17f : SUCCESS in 1h 03m 44s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/fdd9057e89ac494da82d120fc9e89758 : SUCCESS in 1h 29m 31s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/a47b5c96897e453fb7e7b8c3c27e3c95 : SUCCESS in 7m 57s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/73a4a7e1011b4c8182e7f378bf1965ce : SUCCESS in 26m 40s\n- keystone-dsvm-py3-functional-federation-opensuse15 https://zuul.opendev.org/t/openstack/build/b63a9eeb1a384944b7ffd25bee8bdc40 : FAILURE in 29m 13s (non-voting)\n- keystone-dsvm-py3-functional-federation-opensuse15-k2k https://zuul.opendev.org/t/openstack/build/d1b4f9b5cd694947a8a315ec2346d3bf : SUCCESS in 27m 46s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/67a9cf5bd52c4555abe5bfb83dd997af : FAILURE in 11m 23s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/c0e478a72d8f4672aa38871fe2e30195 : SUCCESS in 34m 33s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/f622c12353d340589b476f2ef4263483 : SUCCESS in 49m 03s\n- keystone-tox-protection https://zuul.opendev.org/t/openstack/build/4107057a0ba74311830f53a2495a05c6 : SUCCESS in 34m 07s","accounts_in_message":[],"_revision_number":1},{"id":"4e8e418e3c1c9c59a71785e9468974737e302bfe","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-10-19 14:37:10.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"3d4859c917d48de1f91782a1b8ba4a471d818e06","author":{"_account_id":16465,"name":"Kristi Nikolla","email":"knikolla@bu.edu","username":"knikolla"},"date":"2020-10-19 14:48:06.000000000","message":"Patch Set 1: Code-Review+1","accounts_in_message":[],"_revision_number":1},{"id":"8c4240ef062280634cec1df310f30f63783d2373","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2020-10-21 21:39:27.000000000","message":"Patch Set 1: Workflow+1","accounts_in_message":[],"_revision_number":1},{"id":"522e81d90697dddfc9e2cef17c863dd7ef41315b","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 21:39:47.000000000","message":"Patch Set 1: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":1},{"id":"daba7a7873f9a3c51c5a97fee42357f4fe006934","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 23:32:28.000000000","message":"Patch Set 1: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/86ccc943586e46b096ce3182f3e86b4d : SUCCESS in 17m 36s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/39f781f635b34e39a51787969a3a160e : SUCCESS in 9m 56s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/b240b99a5adf43a8be674745c21a7698 : SUCCESS in 14m 35s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/6832c71415e64cff99c14429c0091297 : SUCCESS in 15m 54s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/b7828678be1040a790438d43d63706af : SUCCESS in 15m 48s\n- grenade https://zuul.opendev.org/t/openstack/build/19e427d3f1004b708e381ec48dcbf6ca : SUCCESS in 1h 15m 07s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/6f92868ab00940f8a4de5bdd380c9beb : SUCCESS in 1h 17m 19s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/da8202a7a75c431b9f5051766ef8da36 : SUCCESS in 10m 46s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/a4a34f89963a46a69bc688b9fc8fb715 : SUCCESS in 39m 13s\n- keystone-dsvm-py3-functional-federation-opensuse15-k2k https://zuul.opendev.org/t/openstack/build/5a47ee36161e49c287dae6a28cbefc6c : SUCCESS in 39m 57s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/778314c3e857416392402428d3400d7d : SUCCESS in 51m 29s\n- keystone-tox-protection https://zuul.opendev.org/t/openstack/build/43616a66cd644aa8af6d204866a47d51 : SUCCESS in 44m 27s","accounts_in_message":[],"_revision_number":1},{"id":"9d51ab52fb809c4b59edc49f72fc4b8720ff9c85","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 23:32:43.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":1},{"id":"d8b1ac2b8d5f0a3bcd592cf993d9add3daddee1b","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2020-10-21 23:34:56.000000000","message":"Patch Set 1:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e067f46e7f1a4c33ac4c2dff56aaa3ac : SUCCESS in 1m 20s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/f8f0191af30a4ed087805762d8f17203 : SUCCESS in 57s","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"35c7406bffdd71cf63c65b8628f4eafa28baaac7","revisions":{"35c7406bffdd71cf63c65b8628f4eafa28baaac7":{"kind":"REWORK","_number":1,"created":"2020-10-02 09:22:10.000000000","uploader":{"_account_id":27954,"name":"Moisés Guimarães de Medeiros","email":"guimaraes@pm.me","username":"moguimar"},"ref":"refs/changes/35/755735/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/35/755735/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/35/755735/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/35/755735/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/35/755735/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/35/755735/1"}}},"commit":{"parents":[{"commit":"d5870f69c12c034dd97b164345e85e6259ee7abe","subject":"Properly handle octet (byte) strings when converting LDAP responses","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d5870f69c12c034dd97b164345e85e6259ee7abe"}]}],"author":{"name":"Lance Bragstad","email":"lbragstad@gmail.com","date":"2020-09-29 15:20:13.000000000","tz":-300},"committer":{"name":"Moisés Guimarães","email":"moguimar@redhat.com","date":"2020-10-02 09:22:10.000000000","tz":0},"subject":"Implement more robust connection handling for asynchronous LDAP calls","message":"Implement more robust connection handling for asynchronous LDAP calls\n\nKeystone\u0027s paging implementation contains a memory leak. The issue is\nnoticeable if you integrate keystone with an LDAP server that supports\npaging and set `keystone.conf [ldap] page_size` to a low integer\n(e.g., 5).\n\nKeystone\u0027s LDAP backend uses `python-ldap` to interact with LDAP\nservers. For paged requests, it uses `search_ext()`, which is an\nasynchronous API [0]. The server responds with a message ID, which the\nclient uses to retrieve all data for the request. In keystone\u0027s case,\nthe `search_ext()` method is invoked with a page control that tells\nthe server to deliver responses in increments according to the page\nsize configured with `keystone.conf [ldap] page_size`. So long as the\nclient has the original connection used to fetch the message ID, it\ncan request the rest of the information associated to the request.\n\nKeystone\u0027s paging implementation loops continuously for paged\nrequests. It takes the message ID it gets from `search_ext()` and\ncalls `result3()`, asking the server for the data associated with that\nspecific message. Keystone continues to do this until the server sends\nan indicator that it has no more data relevant to the query (via a\ncookie). The `search_ext()` and `result3()` methods must use the same\nLDAP connection.\n\nGiven the above information, keystone uses context managers to provide\nconnections. This is relevant when deploying connection pools, where\ncertain connections are re-used from a pool. Keystone relies on Python\ncontext managers to handle connections, which is pretty typical\nuse-case for context managers. Connection managers allow us to do the\nfollowing (assuming pseudocode):\n\n  with self.get_connection as conn:\n      response \u003d conn.search_s()\n      return format(response)\n\nThe above snippet assumes the `get_connection` method provides a\nconnection object and a callable that implements `search_s`. Upon\nexiting the `with` statement, the connection is disconnected, or put\nback into the pool, or whatever the implementation of the context\nmanager decides to do. Most connections in the LDAP backend are\nhandled in this fashion.\n\nUnfortunately, the LDAP driver is somewhat oblivious to paging, it\u0027s\ncontrol implementation, or the fact that it uses an asynchronous API.\nInstead, the driver leaves it up to the handler objects it uses for\nconnections to determine if the request should be controlled via\npaging. This is an anti-pattern since the backend establishes the\nconnection for the request but doesn\u0027t ensure that connection is\nsafely handled for asynchronous APIs.\n\nThis forces the `search_ext()` and `result3()` implementations in the\nPooledLDAPHandler to know how to handle connections and context\nmanagers, since it needs to ensure the same connection is used for\npaged requests. The current code tried to clean up the context\nmanager responsible for connections after the results are collected\nfrom the server using the message ID. I believe it does this because\nit needs to get a new connection for each message in the paged\nresults, even though it already operates from within a connection\nestablished via a context manager and the PooledLDAPHandler almost\nalways returns the same connection object from the pool. The code\ntries to use a weak reference to create a callback that tears down the\ncontext manager when nothing else references it. At a high-level, the\nidea is similar to the following pseudocode:\n\n  with self.get_connection as conn:\n      while True:\n\tldap_data \u003d []\n\tcontext_manager \u003d self.get_connection()\n\tconnection \u003d context_manager.__enter__()\n\tmessage_id \u003d connection.search_ext()\n\tresults \u003d connection.result3(message_id)\n\tldap_data.append(results)\n\tcontext_manager.__exit__()\n\nI wasn\u0027t able to see the callback get invoked or work as described in\ncomments, resulting in memory bloat, especially with low page sizes\nwhich results in more requests. A weak reference invokes the callback\nwhen the weak reference is called, but there are no other references\nto the original object [1]. In our case, I don\u0027t think we invoke that\npath because we don\u0027t actually do anything with the weak reference. We\nassume it\u0027s going to run the callback when the object is garbage\ncollected.\n\nThis commit attempts to address this issue by using the concept of a\nfinalizer [2], which was designed for similar cases. It also attempts\nto hide the cleanup implementation in the AsynchronousMessage object,\nso that callers don\u0027t have to worry about making sure they invoke the\nfinalizer.\n\nAn alternative approach would be to push more of the paging logic and\nimplementation up into the LDAP driver. This would make it easier to\nput the entire asynchronous API flow for paging into a `with`\nstatement and relying on the normal behavior of context managers to\nclean up accordingly. This approach would remove the manual cleanup\ninvocation, regardless of using weak references or finalizer objects.\nHowever, this approach would likely require a non-trivial amount of\ndesign work to refactor the entire LDAP backend. The LDAP backend has\nother issues that would complicate the re-design process:\n\n  - Handlers and connection are generalized to mean the same thing\n  - Method names don\u0027t follow a convention\n  - Domain-specific language from python-ldap bleeds into keystone\u0027s\n    implementation (e.g., get_all, _ldap_get_all, add_member) at\n    different points in the backend (e.g., UserApi (BaseLdap), GroupApi\n    (BaseLdap), KeystoneLDAPHandler, PooledLDAPHandler,\n    PythonLDAPHandler)\n  - Backend contains dead code from when keystone supported writeable\n    LDAP backends\n  - Responsibility for connections and connection handling is spread\n    across objects (BaseLdap, LDAPHandler)\n  - Handlers will invoke methods differently based on configuration at\n    runtime, which is a sign that the relationship between the driver,\n    handlers, and connection objects isn\u0027t truely polymorphic\n\nWhile keeping the logic for properly handling context managers and\nconnections in the Handlers might not be ideal, it is a relatively\nminimal fix in comparison to a re-design or backend refactor. These\nissues can be considered during a refactor of the LDAP backend if or\nwhen the community decides to re-design the LDAP backend.\n\n[0] https://www.python-ldap.org/en/python-ldap-3.3.0/reference/ldap.html#ldap.LDAPObject.search_ext\n[1] https://docs.python.org/3/library/weakref.html#weakref.ref\n[2] https://docs.python.org/3/library/weakref.html#finalizer-objects\n\nCloses-Bug: 1896125\nChange-Id: Ia45a45ff852d0d4e3a713dae07a46d4ff8d370f3\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/35c7406bffdd71cf63c65b8628f4eafa28baaac7"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/35c7406bffdd71cf63c65b8628f4eafa28baaac7"}]},"branch":"refs/heads/stable/ussuri"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
