)]}'
{"id":"openstack%2Fkeystone~976998","triplet_id":"openstack%2Fkeystone~master~I0f5f001c9ecf1aeb32523027da5906d9efb7a26b","project":"openstack/keystone","branch":"master","attention_set":{"7556":{"account":{"_account_id":7556,"name":"Zuul (dev)","email":"zuul-dev@openstack.org","username":"zuul-dev"},"last_update":"2026-02-16 17:22:20.000000000","reason":"\u003cGERRIT_ACCOUNT_34391\u003e replied on the change","reason_account":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"}},"34391":{"account":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"last_update":"2026-02-17 23:04:24.000000000","reason":"A robot voted negatively on a label"},"9816":{"account":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"last_update":"2026-02-17 21:39:08.000000000","reason":"Vote got outdated and was removed: Code-Review-1"}},"removed_from_attention_set":{},"hashtags":[],"change_id":"I0f5f001c9ecf1aeb32523027da5906d9efb7a26b","subject":"trust: remove duplicate trustor identity validation from v3 API","status":"NEW","created":"2026-02-16 16:20:33.000000000","updated":"2026-02-17 23:04:24.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":13,"unresolved_comment_count":1,"has_review_started":true,"meta_rev_id":"d3b7daa314b72cc7f80da63730fcda7b2dbbda6f","_number":976998,"virtual_id_number":976998,"owner":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":7556,"name":"Zuul (dev)","email":"zuul-dev@openstack.org","username":"zuul-dev"},{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},{"tag":"autogenerated:zuul:check","value":-1,"date":"2026-02-17 23:04:24.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":7556,"name":"Zuul (dev)","email":"zuul-dev@openstack.org","username":"zuul-dev"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":7556,"name":"Zuul (dev)","email":"zuul-dev@openstack.org","username":"zuul-dev"},{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7556,"name":"Zuul (dev)","email":"zuul-dev@openstack.org","username":"zuul-dev"},{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-02-16 17:22:20.000000000","updated_by":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"reviewer":{"_account_id":7556,"name":"Zuul (dev)","email":"zuul-dev@openstack.org","username":"zuul-dev"},"state":"REVIEWER"},{"updated":"2026-02-16 17:33:29.000000000","updated_by":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"reviewer":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"state":"REVIEWER"},{"updated":"2026-02-16 18:00:11.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"4aff9b42ce17aeb94486e3abb41977c673e38d8e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-16 16:20:33.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"c44cb821a8ae6f0ffbcc10a1ca2f82e0134bf649","author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"date":"2026-02-16 17:33:29.000000000","message":"Patch Set 1: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":1},{"id":"950eb8f38217051a4093e39feb3b62e429431f60","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-16 18:00:11.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/3cbf6bad6b1340b18d98d970b6168a50\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/7ab1a20e189142488b351e552e3cfdb5 : FAILURE in 14m 41s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/8ec99aec50b14ac79815e514ff97aaf4 : FAILURE in 4m 56s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/ed4d7e848a1c4cc9a4e5d0386ac5806c : FAILURE in 7m 30s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/16cad624de2b4c958de6dfc7b6adbf79 : FAILURE in 10m 10s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/bb43968d2ae54a28bd8211078db49772 : SUCCESS in 14m 01s\n- grenade https://zuul.opendev.org/t/openstack/build/68b401ebf9944c59907686873318559f : SUCCESS in 1h 00m 46s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/77a0647112864f409af1ac875cb52c61 : SUCCESS in 1h 38m 41s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d4855f2917854e7f931b3fed62c95b14 : SUCCESS in 9m 22s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/09181e4e2a4143f5b36138c54fd82ce3 : SUCCESS in 20m 14s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/97dae7c8db0248f5887b0f6a9ca13084 : SUCCESS in 30m 09s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/85548bede77b483e9c3c987027103511 : FAILURE in 22m 18s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/da9876ee0f7045928f5c81ff0d54593f : FAILURE in 15m 44s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/f992d447e2fb484fba24c150c6aa32ca : SUCCESS in 18m 30s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/fe60c0e169c043d49ed9c488e5f92501 : SUCCESS in 21m 26s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/328b21caf49b46f799d7d24486ecdafe : SUCCESS in 38m 44s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/805a5d4b250149e1a14891e7f80b9893 : SUCCESS in 1h 08m 11s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/46697a36ddfe440398b71fe2197263fa : FAILURE in 31m 34s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/3ad3afcb5f524aabb60e1ec9a499b30e : SUCCESS in 6m 40s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"068d53241e47143938df255e9584a0383e9350be","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-16 18:34:57.000000000","message":"Uploaded patch set 2: Commit message was updated.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified-1\n","accounts_in_message":[],"_revision_number":2},{"id":"3751d579fa3b50cc6ea4d695b052e0fa3171a5f2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-16 18:36:16.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"309b1fa6122ee4b37a547567401b93014a1c437a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-16 18:37:03.000000000","message":"Patch Set 4: Commit message was updated.","accounts_in_message":[],"_revision_number":4},{"id":"17df8881bc694746acec5f6f61755e0ed579374e","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-16 18:38:14.000000000","message":"Patch Set 4:\n\n(2 comments)","accounts_in_message":[],"_revision_number":4},{"id":"df7afe6ecdafe98ab92e4f6c5356ef1e847bdc1d","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-16 20:12:52.000000000","message":"Patch Set 4:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/522f180f1e4842d98f28df019b9be824\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/001a2755f73b41c0a61f4bb8479afe82 : FAILURE in 27m 21s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/68062683af064877951157c588fbf4a9 : FAILURE in 18m 31s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/f13c5de609d14a639ab62caf1009a312 : RETRY_LIMIT in 5m 18s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"1b328dd7dc7dd4a35293442d02134024e5a0fde7","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-16 20:29:18.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/b37f2d4480a84c67a54ed3934a60ff08\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/88613590bd6e4558a1050cedcd594357 : FAILURE in 17m 10s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a9b9dcda43a349e59251ea59c1b854fe : FAILURE in 4m 58s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/638c567cb34941b9a79ebb6c664916e9 : FAILURE in 11m 32s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/3b4533abfa3245f4b8fa5d8a91b76a35 : FAILURE in 11m 06s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/3b1365432f5347f7ba56ffe2b15e1a88 : SUCCESS in 13m 01s\n- grenade https://zuul.opendev.org/t/openstack/build/42e7d0ee7230490a977f72af9f6c4627 : SUCCESS in 58m 47s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/b29c58acdd6d45f3820c9a56d46d3a1c : SUCCESS in 1h 45m 33s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/37f85abade9346b88a46385d9905fcd8 : SUCCESS in 10m 07s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/19aeeb485494438db57b6b8f31ffd978 : SUCCESS in 29m 57s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/eb68e3664ab64941be86ec68a19da28c : FAILURE in 22m 38s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/97b2380355314849b8da0ec8bc02df23 : FAILURE in 26m 29s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/c845178904e54762aa7ccf1ba8f01c80 : SUCCESS in 28m 15s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/5ff51809f2ce4ff4bb08ccad024110ae : SUCCESS in 33m 26s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/0223b6a2bcd2498395f523bbea10e93d : SUCCESS in 18m 17s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/841c356a3db14f25a317a060e70def68 : SUCCESS in 57m 56s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/d5c73e051a6b42f1b6b2ca54deadec0d : FAILURE in 38m 39s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/dd5308fc738e4ebda1ba5af225a37186 : SUCCESS in 8m 43s (non-voting)","accounts_in_message":[],"_revision_number":4},{"id":"ea7ef8b3ac7fb24e1634d8e48971c6fd4e3165a1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 11:23:40.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Verified-1\n","accounts_in_message":[],"_revision_number":5},{"id":"b28039619cd5e013bad99397ad1ad7726778a25d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 11:25:46.000000000","message":"Uploaded patch set 6: Commit message was updated.","accounts_in_message":[],"_revision_number":6},{"id":"d3842efdfadd9194026050113437ac84efe98f6b","author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"date":"2026-02-17 12:01:59.000000000","message":"Patch Set 6: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"5587fffe02ca17faa715fbc57dc4b7595ef26ba2","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-17 12:49:34.000000000","message":"Patch Set 6:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/81c3380249574062beb2c54d18c2e50a\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/a63510f0047f4741b2c152d68ec8f6ce : SUCCESS in 41m 54s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/2df177749fa542fd828040558d60db41 : SUCCESS in 45m 55s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/c0acefd5ef59480e887acda59a10fcfc : RETRY_LIMIT in 7m 52s (non-voting)","accounts_in_message":[],"_revision_number":6},{"id":"5e9bcf7a8f9a98a9b87e590be49bdc27b805f092","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-17 13:20:11.000000000","message":"Patch Set 6: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/f89921734d4f48eeb8d66400cec9af5c\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/12eeb2a0e9694a28ab6a976246824d72 : SUCCESS in 13m 07s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/ff6514b536614ab3909067c9f86b861e : FAILURE in 4m 57s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/103df83c9b7b4b8ebbe7da05e0cb5c72 : SUCCESS in 11m 56s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/72d84cd343d94c0b9ab99b21911a2bc7 : SUCCESS in 9m 08s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/2037c346454d4ffeb0584e2da4fb2fac : SUCCESS in 12m 54s\n- grenade https://zuul.opendev.org/t/openstack/build/398c30f230fc47118142fe93175b0a34 : SUCCESS in 50m 52s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/d767778f560643339ad1efdb833ebc4e : SUCCESS in 1h 50m 04s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/7735314468184628b27617a423b7b4cc : SUCCESS in 18m 07s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/c8aa738ef07f4f16a70eb46f32f7bce1 : SUCCESS in 32m 41s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/d022ec057cbd43cc80bedef834e3b96b : FAILURE in 20m 53s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/1460dbc2ddc84b3695a8d0380e02b361 : FAILURE in 6m 26s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/787e26fd1b8540228012fdd095eb9859 : FAILURE in 8m 33s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/d762c2daa1b04253ae60a1f596f2ded4 : SUCCESS in 32m 41s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/7b46e8f3199b403788b58b3c8cf0904e : SUCCESS in 25m 50s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/c8ccb920dcec40babf9d07fd08257dfa : SUCCESS in 36m 08s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/a32fab9acd8a437898f518a8ec641f0f : FAILURE in 37m 54s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/a4205ec0f7c649d0b01101f5bdf920e1 : SUCCESS in 6m 11s (non-voting)","accounts_in_message":[],"_revision_number":6},{"id":"87f793c1f785947275a05ea01e94d2cc0b0e0165","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 13:55:07.000000000","message":"Uploaded patch set 7.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified-1\n","accounts_in_message":[],"_revision_number":7},{"id":"8628d109a95875dc6a1512017a9b20c35d9a2e7e","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 14:02:15.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"14b57c33e822fac10414310e75bc98474df46e73","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 14:06:57.000000000","message":"Uploaded patch set 8: Commit message was updated.","accounts_in_message":[],"_revision_number":8},{"id":"a6ee4bd47fed537ed008549b78d71a66b43ffd01","author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"date":"2026-02-17 14:26:56.000000000","message":"Patch Set 8: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"9ac3702316fa46ebb27ed1f6101e44977dcbaf67","author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"date":"2026-02-17 14:30:09.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"a0677820b76913e022a8163ce0a28fafd8a6c86a","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 14:45:23.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"c3a53418ea941e8e9621cb98c0b3ace97578a0b7","author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"date":"2026-02-17 14:50:52.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"f5a17254d4e230cee57780bd3fae389e586a7709","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 15:06:57.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"be05d8dff267cc4e0c01bc3d89744965df6dde4a","author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"date":"2026-02-17 15:42:12.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"f9ec563787ea16865b5ca082df3ed78dd1ac799e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-17 16:06:32.000000000","message":"Patch Set 8: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/c552e48040d54447ace449e24396d752\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/024bad0f53b048448297d8375fa90e19 : SUCCESS in 17m 01s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/2aef5a5796c74f9eafc11e26b276045e : SUCCESS in 5m 39s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/ce74797d935d4087b9dc031592234301 : SUCCESS in 10m 09s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/8195fb7815a94ff5a885a52eb4082fb2 : SUCCESS in 10m 25s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8e2957ffc79849218376d154919a49ee : SUCCESS in 13m 05s\n- grenade https://zuul.opendev.org/t/openstack/build/0dc193dfcdb347bfac5eb422c6ef2aed : SUCCESS in 1h 06m 33s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/9b60e13ea94342a7b7b3f926af096f2f : SUCCESS in 1h 45m 20s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/011d580f5dbe4f36be0f45268fd4a9e9 : SUCCESS in 10m 37s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/2584e3102a814fc7a839fed30324763b : SUCCESS in 27m 02s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/cffdad4283304bdb98b3b7626bda6936 : FAILURE in 21m 12s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/29d2b25b5d384519865da323f68469e9 : FAILURE in 11m 31s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/94a9f30dde4d47b69d50e79143167439 : FAILURE in 4m 29s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/2f39b8bc8aa4487baba63d0446e40c00 : SUCCESS in 31m 40s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/d2982aef2fb84f96b2e6b65116b767e1 : SUCCESS in 21m 42s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/31553d68090b4fee9d235a3be2d130d4 : SUCCESS in 47m 34s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/eaf8d6f4aeb64900bee3d626906d415a : FAILURE in 48m 06s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/4e37cc538ebf4fb392770d0884a4ef0f : SUCCESS in 6m 31s (non-voting)","accounts_in_message":[],"_revision_number":8},{"id":"8efe7210b320ee5b6f625c6a55784b9a4ef81d64","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-17 17:13:37.000000000","message":"Patch Set 8:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/04f6d42bcb864fefa1ed11dd378f43ca\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/7c8df353a83e4ecb8dc9ef12f032a61a : SUCCESS in 23m 16s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/3a4c00f59e094490a1883515e1c01ce6 : SUCCESS in 19m 45s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/a6b0138fd535436780393848bc5010cd : RETRY_LIMIT in 4m 32s (non-voting)","accounts_in_message":[],"_revision_number":8},{"id":"d8e49be41c8f2bf9bfc302e4dee2ece54c61008e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 21:39:08.000000000","message":"Uploaded patch set 9.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified-1\n","accounts_in_message":[],"_revision_number":9},{"id":"02ca5325050324da4c7b2d47b5f1106d0602c4a3","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 21:58:15.000000000","message":"Uploaded patch set 10.","accounts_in_message":[],"_revision_number":10},{"id":"eaab52047b5c7a9e85e40a6d86dd18d81beb3eb0","author":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"date":"2026-02-17 22:00:23.000000000","message":"Patch Set 9:\n\n(1 comment)","accounts_in_message":[],"_revision_number":9},{"id":"f7d7bce2ca72451f1b0d2b09c8ecf1babab87c1e","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-17 22:16:59.000000000","message":"Patch Set 10:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/70f2666f4ffc45dc95fa37233ec51df9\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/8f49a781ad974294ae7cce287d8a6506 : SUCCESS in 14m 59s (non-voting)\n- openstack-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/de45a10972af4b09b22a6300b655aa2d : SUCCESS in 17m 11s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/6adc7654225d4609956d42309ea49c79 : RETRY_LIMIT in 3m 49s (non-voting)","accounts_in_message":[],"_revision_number":10},{"id":"d3b7daa314b72cc7f80da63730fcda7b2dbbda6f","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-02-17 23:04:24.000000000","message":"Patch Set 10: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/d027b56532054cf895ee385fb556e2b6\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/14c35267b04643a7bf7bdc3804c6a2ad : SUCCESS in 18m 49s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/337e338c7065435191d17f2e78987114 : SUCCESS in 3m 10s\n- openstack-tox-py310 https://zuul.opendev.org/t/openstack/build/474f430e62294ee3b97524c62a9911a4 : SUCCESS in 11m 04s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/07cffd78723d4ebf9418324935134676 : SUCCESS in 8m 57s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/43515e662c4843f8b80b2605bc9ae1b5 : SUCCESS in 7m 00s\n- grenade https://zuul.opendev.org/t/openstack/build/0a132f49a2114687a0a420c997fc62d2 : SUCCESS in 59m 42s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/5712be772e4e4219b30a6d8dffc6bc7f : SUCCESS in 1h 05m 09s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3e6f99041b88436bbf501be1cc2537f2 : SUCCESS in 16m 04s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/be62b0b3ec58444f9eabfb082aa277f5 : SUCCESS in 18m 19s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/b80a4ba8a9d34a99bf3293d4c93b7810 : SUCCESS in 21m 44s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/f876c1c3568443b89c0e84bcef6955a8 : FAILURE in 11m 14s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/e2bdacaa1d464b14a9c07ac937a9713a : FAILURE in 4m 17s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/711fff0cbfb346fb92e9d4159d2e5bea : FAILURE in 10m 47s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/eead2620e6d441e7889c25ce24c86633 : SUCCESS in 32m 45s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/12005404f0c14c7e95b2d9d33a632fd6 : SUCCESS in 38m 55s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/0e2aa4a90df747079e8c4931570f58f9 : SUCCESS in 57m 23s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/46abb6c48098483b872fc2e015e6f771 : FAILURE in 41m 21s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/6918163349be409980d4b2f9a4ac4a42 : SUCCESS in 8m 46s (non-voting)","accounts_in_message":[],"_revision_number":10}],"current_revision_number":10,"current_revision":"148379768d0f41c5cc611b421cd7d28434a6d343","revisions":{"5d1590783f596b6e0a20addd0ed29706ea1dbc46":{"kind":"REWORK","_number":1,"created":"2026-02-16 16:20:33.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/1"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"subject":"Moved the validation ensuring the authenticated user matches the trustor during trust creation from the API layer to the Trust SQL driver.","message":"Moved the validation ensuring the authenticated user matches the trustor during trust creation from the API layer to the Trust SQL driver.\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5d1590783f596b6e0a20addd0ed29706ea1dbc46"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/5d1590783f596b6e0a20addd0ed29706ea1dbc46"}]},"branch":"refs/heads/master"},"6854766c33c5e7ed879d00ee199bd2783318e501":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2026-02-16 18:34:57.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/2"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 18:34:22.000000000","tz":60},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe trust creation guard that requires the authenticated user to match\nthe trustor was implemented in the v3 API controller. That made this rule\nentrypoint-specific instead of a backend invariant.\n\nMove this validation into the Trust SQL driver and invoke it from\ncreate_trust() before the database write. The API layer no longer carries\na duplicate pre-check.\n\nKeeping this check in the backend is required for backend substitutability:\noperators can override the Trust backend through Stevedore and still get the\nsame trustor validation behavior. With the earlier API-layer logic, that\nvalidation path was tied to one entrypoint and was not cleanly portable across\nbackend implementations.\n\nBehavior is unchanged for API callers: trust creation still fails with\nForbiddenAction when the authenticated user differs from\ntrustor_user_id. This change only improves layering and centralizes the\nauthorization check in the backend.\n\nKnown limitation: when no request context is available, this specific\nidentity check is not applied by the backend.\n\nTest Plan:\n- Not run (commit-message-only follow-up).\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/6854766c33c5e7ed879d00ee199bd2783318e501"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/6854766c33c5e7ed879d00ee199bd2783318e501"}]},"branch":"refs/heads/master"},"9403ab0d47d2111e312012ae458c368cc6fe138a":{"kind":"REWORK","_number":3,"created":"2026-02-16 18:36:16.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/3"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 18:36:02.000000000","tz":60},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe trust creation guard that requires the authenticated user to match\nthe trustor was implemented in the v3 API controller. That made this rule\nentrypoint-specific instead of a backend invariant.\n\nMove this validation into the Trust SQL driver and invoke it from\ncreate_trust() before the database write. The API layer no longer carries\na duplicate pre-check.\n\nKeeping this check in the backend is required for backend substitutability:\noperators can override the Trust backend through Stevedore and still get the\nsame trustor validation behavior. With the earlier API-layer logic, that\nvalidation path was tied to one entrypoint and was not cleanly portable across\nbackend implementations.\n\nBehavior is unchanged for API callers: trust creation still fails with\nForbiddenAction when the authenticated user differs from\ntrustor_user_id. This change only improves layering and centralizes the\nauthorization check in the backend.\n\nKnown limitation: when no request context is available, this specific\nidentity check is not applied by the backend.\n\nTest Plan:\n- Not run (commit-message-only follow-up).\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/9403ab0d47d2111e312012ae458c368cc6fe138a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/9403ab0d47d2111e312012ae458c368cc6fe138a"}]},"branch":"refs/heads/master"},"b8cda9fdcd43db64305c02248a10fa407f6413e1":{"kind":"NO_CODE_CHANGE","_number":4,"created":"2026-02-16 18:37:03.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/4"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 18:37:03.000000000","tz":0},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe trust creation guard that requires the authenticated user to match\nthe trustor was implemented in the v3 API controller. That made this rule\nentrypoint-specific instead of a backend invariant.\n\nMove this validation into the Trust SQL driver and invoke it from\ncreate_trust() before the database write. The API layer no longer carries\na duplicate pre-check.\n\nKeeping this check in the backend is required for backend substitutability:\noperators can override the Trust backend through Stevedore and still get the\nsame trustor validation behavior. With the earlier API-layer logic, that\nvalidation path was tied to one entrypoint and was not cleanly portable across\nbackend implementations.\n\nBehavior is unchanged for API callers: trust creation still fails with\nForbiddenAction when the authenticated user differs from\ntrustor_user_id. This change only improves layering and centralizes the\nauthorization check in the backend.\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b8cda9fdcd43db64305c02248a10fa407f6413e1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b8cda9fdcd43db64305c02248a10fa407f6413e1"}]},"branch":"refs/heads/master","description":"Edit commit message"},"b024628e6a94f80da59d03c166405271428cfed6":{"kind":"REWORK","_number":5,"created":"2026-02-17 11:23:40.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/5"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-17 11:23:34.000000000","tz":60},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe trust creation guard that requires the authenticated user to match\nthe trustor was implemented in the v3 API controller. That made this rule\nentrypoint-specific instead of a backend invariant.\n\nMove this validation into the Trust SQL driver and invoke it from\ncreate_trust() before the database write. The API layer no longer carries\na duplicate pre-check.\n\nKeeping this check in the backend is required for backend substitutability:\noperators can override the Trust backend through Stevedore and still get the\nsame trustor validation behavior. With the earlier API-layer logic, that\nvalidation path was tied to one entrypoint and was not cleanly portable across\nbackend implementations.\n\nBehavior is unchanged for API callers: trust creation still fails with\nForbiddenAction when the authenticated user differs from\ntrustor_user_id. This change only improves layering and centralizes the\nauthorization check in the backend.\n\nKnown limitation: when no request context is available, this specific\nidentity check is not applied by the backend.\n\nTest Plan:\n- Not run (commit-message-only follow-up).\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b024628e6a94f80da59d03c166405271428cfed6"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b024628e6a94f80da59d03c166405271428cfed6"}]},"branch":"refs/heads/master"},"49818b202cc34b1ec6d919cd048cfdd2790913c9":{"kind":"NO_CODE_CHANGE","_number":6,"created":"2026-02-17 11:25:46.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/6"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-17 11:25:41.000000000","tz":60},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe trust creation guard that requires the authenticated user to match\nthe trustor was implemented in the v3 API controller. That made this rule\nentrypoint-specific instead of a backend invariant.\n\nMove this validation into the Trust SQL driver and invoke it from\ncreate_trust() before the database write. The API layer no longer carries\na duplicate pre-check.\n\nKeeping this check in the backend is required for backend substitutability:\noperators can override the Trust backend through Stevedore and still get the\nsame trustor validation behavior. With the earlier API-layer logic, that\nvalidation path was tied to one entrypoint and was not cleanly portable across\nbackend implementations.\n\nBehavior is unchanged for API callers: trust creation still fails with\nForbiddenAction when the authenticated user differs from\ntrustor_user_id. This change only improves layering and centralizes the\nauthorization check in the backend.\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/49818b202cc34b1ec6d919cd048cfdd2790913c9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/49818b202cc34b1ec6d919cd048cfdd2790913c9"}]},"branch":"refs/heads/master"},"b5486bf34009db53e146757f5ddb33db8567e847":{"kind":"REWORK","_number":7,"created":"2026-02-17 13:55:07.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/7"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-17 13:55:04.000000000","tz":60},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe trust creation guard that requires the authenticated user to match\nthe trustor was implemented in the v3 API controller. That made this rule\nentrypoint-specific instead of a backend invariant.\n\nMove this validation into the Trust SQL driver and invoke it from\ncreate_trust() before the database write. The API layer no longer carries\na duplicate pre-check.\n\nKeeping this check in the backend is required for backend substitutability:\noperators can override the Trust backend through Stevedore and still get the\nsame trustor validation behavior. With the earlier API-layer logic, that\nvalidation path was tied to one entrypoint and was not cleanly portable across\nbackend implementations.\n\nBehavior is unchanged for API callers: trust creation still fails with\nForbiddenAction when the authenticated user differs from\ntrustor_user_id. This change only improves layering and centralizes the\nauthorization check in the backend.\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b5486bf34009db53e146757f5ddb33db8567e847"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b5486bf34009db53e146757f5ddb33db8567e847"}]},"branch":"refs/heads/master"},"8da61709886e9b0c553969582652e422f6e2204b":{"kind":"NO_CODE_CHANGE","_number":8,"created":"2026-02-17 14:06:57.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/8"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-17 14:06:54.000000000","tz":60},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe check that requires the authenticated user to match the trustor was\npreviously done in the v3 API controller, which tied the validation to a\nspecific entrypoint.\n\nMove this validation into the Trust SQL driver and call it from\ncreate_trust() before writing to the database. The API layer no longer\nduplicates this check.\n\nValidation for Trust operations should live in Trust backends so Keystone\noperators can override or disable it by providing a custom backend. This\nkeeps behavior consistent across entrypoints and preserves backend\nsubstitutability.\n\nBehavior for API callers is unchanged: trust creation still fails with\nForbiddenAction when the authenticated user differs from trustor_user_id.\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/8da61709886e9b0c553969582652e422f6e2204b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/8da61709886e9b0c553969582652e422f6e2204b"}]},"branch":"refs/heads/master"},"1b416e65b16e2bc4c8332c16ff08e5fabf0d7b7d":{"kind":"REWORK","_number":9,"created":"2026-02-17 21:39:08.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/9","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/9","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/9"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-17 21:39:02.000000000","tz":60},"subject":"trust: enforce trustor identity check in SQL backend","message":"trust: enforce trustor identity check in SQL backend\n\nThe check that requires the authenticated user to match the trustor was\npreviously done in the v3 API controller, which tied the validation to a\nspecific entrypoint.\n\nMove this validation into the Trust SQL driver and call it from\ncreate_trust() before writing to the database. The API layer no longer\nduplicates this check.\n\nValidation for Trust operations should live in Trust backends so Keystone\noperators can override or disable it by providing a custom backend. This\nkeeps behavior consistent across entrypoints and preserves backend\nsubstitutability.\n\nBehavior for API callers is unchanged: trust creation still fails with\nForbiddenAction when the authenticated user differs from trustor_user_id.\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/1b416e65b16e2bc4c8332c16ff08e5fabf0d7b7d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/1b416e65b16e2bc4c8332c16ff08e5fabf0d7b7d"}]},"branch":"refs/heads/master"},"148379768d0f41c5cc611b421cd7d28434a6d343":{"kind":"REWORK","_number":10,"created":"2026-02-17 21:58:15.000000000","uploader":{"_account_id":34391,"name":"Bram Kranendonk","display_name":"bkranendonk","email":"bram.kranendonk@team.blue","username":"bkranendonk"},"ref":"refs/changes/98/976998/10","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/98/976998/10","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/98/976998/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/98/976998/10"}}},"commit":{"parents":[{"commit":"7b5702f994139140ce195acbe15598dfcf4c8b98","subject":"Merge \"Replace deprecated warn method\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/7b5702f994139140ce195acbe15598dfcf4c8b98"}]}],"author":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-16 16:20:26.000000000","tz":60},"committer":{"name":"Bram Kranendonk","email":"bram.kranendonk@nl.team.blue","date":"2026-02-17 21:58:07.000000000","tz":60},"subject":"trust: remove duplicate trustor identity validation from v3 API","message":"trust: remove duplicate trustor identity validation from v3 API\n\nDrop the trust creation check in `keystone/api/trusts.py` that required\nthe authenticated user to match `trustor_user_id`.\n\nThat validation is already enforced in the Trust backend path, so keeping\nit in the v3 controller duplicates policy logic and ties behavior to a\nsingle API entrypoint. Removing the API-layer check keeps trust validation\nbackend-centric purely an Oslo policy and making the behaviour adjustable by an operator.\n\nUser-visible behavior is unchanged: trust creation still raises\n`ForbiddenAction` when the authenticated user differs from the trustor.\n\nChange-Id: I0f5f001c9ecf1aeb32523027da5906d9efb7a26b\nSigned-off-by: Bram Kranendonk \u003cbram.kranendonk@nl.team.blue\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/148379768d0f41c5cc611b421cd7d28434a6d343"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/148379768d0f41c5cc611b421cd7d28434a6d343"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
