)]}'
{"id":"openstack%2Fkeystone~985969","triplet_id":"openstack%2Fkeystone~master~I3d72b789552522ff34b5291143c49fea6f154343","project":"openstack/keystone","branch":"master","attention_set":{},"removed_from_attention_set":{"36082":{"account":{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},"last_update":"2026-09-02 08:47:01.000000000","reason":"Change was marked work in progress"},"7973":{"account":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"last_update":"2026-09-02 08:47:01.000000000","reason":"Change was marked work in progress"},"14250":{"account":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"last_update":"2026-09-02 08:47:01.000000000","reason":"Change was marked work in progress"},"36012":{"account":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"last_update":"2026-09-02 08:47:01.000000000","reason":"Change was marked work in progress"}},"hashtags":[],"change_id":"I3d72b789552522ff34b5291143c49fea6f154343","subject":"Fix: TOTP authentication lockout risk in Keystone","status":"NEW","created":"2026-04-23 14:49:48.000000000","updated":"2026-09-02 08:47:01.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":12,"unresolved_comment_count":4,"work_in_progress":true,"has_review_started":true,"meta_rev_id":"3d7ba98ef575a58f695087fa9c1523cdc4f27a5e","_number":985969,"virtual_id_number":985969,"owner":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"tag":"autogenerated:zuul:check","value":-1,"date":"2026-09-01 11:06:04.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-04-23 15:49:54.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-08-24 17:14:26.000000000","updated_by":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"reviewer":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"state":"REVIEWER"},{"updated":"2026-08-26 17:45:18.000000000","updated_by":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"reviewer":{"_account_id":7973,"name":"Douglas Mendizábal","email":"dmendiza@redhat.com","username":"dougmendizabal"},"state":"REVIEWER"},{"updated":"2026-08-29 16:20:40.000000000","updated_by":{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},"reviewer":{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},"state":"REVIEWER"}],"messages":[{"id":"691c7a3bad059e9252dd3a60f5aad39fd0b96678","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-04-23 14:49:48.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"ba30777b100c54294594c137b76295abf8a549f1","tag":"autogenerated:gerrit:setWorkInProgress","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-04-23 14:50:23.000000000","message":"Set Work In Progress","accounts_in_message":[],"_revision_number":1},{"id":"1169c519bac1e207ad5962f44ca8262f9b902242","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-23 15:49:54.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/c731d83fd9814f1e91f023ba0738f01f\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/bce6a58710b141ad8b8a00a8f8b3f966 : FAILURE in 11m 52s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/fb3cdf532bc24170a6e655f1c9c303ac : FAILURE in 3m 17s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/70ee02ce789048278acdb042c86a1165 : FAILURE in 9m 00s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/3465a0e2d47b460780740fbc56810546 : FAILURE in 7m 46s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/fce8b776fc0246208b0b41d5e92e23c9 : FAILURE in 13m 59s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/d4dadb2f1c0d4de6bf4cadbaa78aa553 : SUCCESS in 7m 21s\n- grenade https://zuul.opendev.org/t/openstack/build/8b8c167a0775459481c8d65149bab156 : SUCCESS in 31m 37s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/a0f75a01c5b84a31b2dddf66351f9d48 : SUCCESS in 57m 30s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/85eb2f9416d441cfa9ee829ee77ebd1c : SUCCESS in 9m 51s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/760c9943595c4819961ed67ad7556fb7 : SUCCESS in 14m 59s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/9a934f9b24ae4df78eb421c0d961858f : FAILURE in 9m 06s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/9a3d83fa76ac47cba6af7d2489f87ad2 : FAILURE in 25m 38s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/40979519b49c4563a0c1a847a8767074 : SUCCESS in 29m 42s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/088731ff07114ac39dcca96a2660bfdc : SUCCESS in 18m 56s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/b524594cb79149f1b32b4b177cd81379 : SUCCESS in 36m 27s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/f904aaa014ea44d58f75cb7ee990bc79 : SUCCESS in 30m 54s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/950ad982cea441588ee5819e95062654 : FAILURE in 20m 20s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/3612ee107e6f4ac1a40f480abe90300c : SUCCESS in 3m 33s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"579bc4b9caef3a033a06a386463d775f1c9309ef","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-23 15:52:08.000000000","message":"Patch Set 1:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/774d1e978f82465e8f932b2787ce5397\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/7e2e50708ba84cdf8c4f52e182392a58 : FAILURE in 17m 50s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/a8f4fae551314d0ea9896f498786c964 : FAILURE in 15m 51s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/349965bee0a44f6eba821b157d2fefc5 : FAILURE in 20m 32s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"a35b9a8d0772ce0823f30d97d865456fd86b793d","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-04-24 06:43:36.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"16b5825969adfe409f42f70e30141bb416b86094","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-24 07:30:30.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/59de797cb07f4846b847c15e47c09510\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/45db6467555f4987ae732339afd5754d : FAILURE in 22m 22s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/84294f1849da4441b9eed89b6bcd66cc : FAILURE in 20m 26s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/d60800318f07450cb17e99d0382a3c22 : FAILURE in 25m 53s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"509618bbfb82f9065d993cf8f6594652a5a1344d","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-24 08:27:09.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/033ea17c3361472b82d54eccd75d603c\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/988cf14b533a4d9e940fae7c504dcb04 : FAILURE in 18m 05s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/89a26932a98b4a808a443de2c2311353 : SUCCESS in 6m 37s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/7ee2fc4e14274bd1a65a5f8dbe0612f1 : FAILURE in 11m 01s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/dd145fe2c9884120944b48acee944ea6 : FAILURE in 6m 30s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/d951f4e843af45b9aee76dba6a8a31b9 : FAILURE in 15m 17s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/ae93a04867c046eabb160151ee1daccc : SUCCESS in 13m 52s\n- grenade https://zuul.opendev.org/t/openstack/build/ef395c939b4440af88728f4332154684 : SUCCESS in 52m 58s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/def837bbaeb14a88ad4a0a3a5f08416f : SUCCESS in 1h 41m 22s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/e8fb30593ace43a2a11c6041246be4d7 : SUCCESS in 11m 59s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/195e2412d6dd476d85f707a2fb32b1aa : SUCCESS in 9m 36s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/897e7e28706e411c9d3a2d0d2f6cb7ad : SUCCESS in 15m 10s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/74571b18a85b4f99b311215b5663e544 : FAILURE in 15m 48s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/87f153eeee6c48b685e94216926e7143 : FAILURE in 19m 49s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/b6a71d8eb8e147e38f88fef080e9307e : SUCCESS in 30m 00s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/38f14609165b4c32991b9d8a5cd32efd : SUCCESS in 15m 55s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/50c8167d0bd74aa9a46d0ef97345e318 : SUCCESS in 32m 41s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/22e950eaf9d543cf9a40bff965857b52 : SUCCESS in 34m 31s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/0eca035f62af4027be6f89b9a26ce541 : FAILURE in 21m 00s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/d989f902d88740128f1dfc2d06d22f61 : SUCCESS in 4m 13s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"6e3752bbb11a0751bc655b5cb7df5ce5ed05a84b","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-04-24 12:02:51.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":3},{"id":"2dcba020ac72216f97ce40a0b6c701ef2c1c803c","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-24 14:03:25.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/9212c4874b0f48259550091d41f1db17\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/32bc1663902b481484cb8a0b376ffbd9 : FAILURE in 16m 58s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/4626ffc3fec842ed966997e170198ec7 : SUCCESS in 5m 12s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/218fb9b0d5b64e148f2affac65b26897 : FAILURE in 10m 57s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/1077e498f50649a281788c3f4da903d7 : FAILURE in 11m 22s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/8c983eb78f3147768ea66d48b22ebef4 : FAILURE in 15m 29s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/2dddca84fdf7458cbf140b63c5bf1e72 : SUCCESS in 14m 03s\n- grenade https://zuul.opendev.org/t/openstack/build/46cc922027d04bfab8f841a908156677 : SUCCESS in 1h 14m 31s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/7de8d9abac4d4558bfbe0019b06b13e1 : SUCCESS in 1h 56m 01s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/a5e63897134e4f7dbded8c89cb476293 : SUCCESS in 12m 03s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/1ad201dc496e4531adb6ad60f61c78b2 : SUCCESS in 20m 18s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/3fda4212f33c4c82a36cb985f23153cd : SUCCESS in 33m 00s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/83223c9f794e4ce59122394134533910 : FAILURE in 21m 45s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/1b647ca3c1fa42e0928db8b424b80027 : FAILURE in 26m 21s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/17fcec44b15c415991703c8a4c5cf270 : SUCCESS in 33m 28s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/72d9e7d53b9940828ac084b5b8d45cd4 : SUCCESS in 33m 31s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/1cd20476ac914a43803a9312217208e0 : SUCCESS in 36m 36s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/1a45546c92dd4fac8348a8cef9142d5c : SUCCESS in 51m 11s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/66e93792e89e46a196f756c3ec2fb9da : FAILURE in 39m 17s (non-voting)\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/62c7b05efaf64e4aba7c52ba35e8c412 : SUCCESS in 6m 41s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"887cbf2011dd3150ea096048351cfd4730d52b5d","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-04-24 16:23:39.000000000","message":"Patch Set 3:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/9b1b6f1c5b3b40c1bed3387ba6edc958\n\n- openstack-tox-py310-arm64 https://zuul.opendev.org/t/openstack/build/cc47734666454bbea4ec5e7d302a5365 : FAILURE in 15m 29s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/141a02493e9343768b49a19cbe5af51e : FAILURE in 16m 11s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/2cccda0800ae477db2f5b18af1aa68a8 : FAILURE in 22m 32s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"0118fb55fa3453e4c55c23dc09057c97df91d4dc","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-03 08:32:25.000000000","message":"Uploaded patch set 4: New patch set was added with same tree, parent tree, and commit message as Patch Set 3.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":4},{"id":"c0467ba03c4b7cea13de5e9d9ddfe1a0da02951e","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-03 08:33:57.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.","accounts_in_message":[],"_revision_number":5},{"id":"b65222412979eaabd4ca2b68ae4dda42256d3c9e","tag":"autogenerated:gerrit:newWipPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-03 08:36:24.000000000","message":"Uploaded patch set 6: New patch set was added with same tree, parent tree, and commit message as Patch Set 5.","accounts_in_message":[],"_revision_number":6},{"id":"d3dac0272a414fada404ce9565a126ec431dd375","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 09:08:44.000000000","message":"Patch Set 6:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/fd7e511a8d42464bb036a581e0ee3233\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/a0b84b71047b489c84fc9769c03240c0 : FAILURE in 22m 41s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/767eec51cb41412687578f2076d7ac67 : FAILURE in 20m 39s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/4edd6fcfae9f481581a21e8b5f9330cc : FAILURE in 30m 06s (non-voting)","accounts_in_message":[],"_revision_number":6},{"id":"96ecc4071315882674660b227d25315f3fa6c51c","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-03 09:46:53.000000000","message":"Patch Set 6:\n\n(1 comment)\n\nThis change is ready for review.","accounts_in_message":[],"_revision_number":6},{"id":"51a0259be4aa33d3de7f473a8c7891bc99f36b24","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 10:09:56.000000000","message":"Patch Set 6: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/f40d79fd4c4b4cffbb48bfa6ce870edf\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f53eb8e2aaa24ae097aea96ba8fb4d3a : FAILURE in 15m 56s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5204e613eb8441af9ef4a246bde149c6 : SUCCESS in 5m 17s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/74aec6d4d00e4affbeb59587e4d4cfb5 : FAILURE in 11m 12s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/2efbb0836bed43c7b52bd8ce9941a290 : FAILURE in 11m 06s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/b2b7b0a164fd47c6ab35e69f456cb6fe : FAILURE in 16m 54s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/762fe11bb22147a6b8d88cd1b181f1f6 : SUCCESS in 14m 25s\n- grenade https://zuul.opendev.org/t/openstack/build/6a4844215d514bae971441f7055782d1 : SUCCESS in 1h 03m 47s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/48801d112a2242fdae47e43771abd14a : SUCCESS in 1h 32m 15s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/52039fb0314b40ac8626a8377fe9fa65 : SUCCESS in 13m 14s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/e747fc72f5da4433abd3050d8400f9d5 : SUCCESS in 18m 05s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/ca2b3425d0aa4f99b703089c5fd56650 : SUCCESS in 48m 01s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/9523337c446d4a1f8ad78f4ecdd2fcc6 : FAILURE in 19m 02s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/424e910a9a0947b18b0d3a6e8f7a702f : FAILURE in 26m 34s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/d202f6b6057a42719b6ccccff556005c : SUCCESS in 50m 15s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/1f774194613044958b32aeddb42a1732 : SUCCESS in 48m 49s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/51b0c9cf644443d99fc45e16751717c8 : SUCCESS in 39m 13s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/ffd0237c25e8435da9eda60756adfc29 : SUCCESS in 55m 21s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/f91ecedd413d493f94e7c11f4c8e4535 : SUCCESS in 30m 22s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/5af89340bc0647b7bc56f49446e59327 : SUCCESS in 6m 50s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":6},{"id":"cda5552c2d9a44a1a59c78d516ab33b782693cfd","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 10:28:01.000000000","message":"Patch Set 6:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/e0bb938e37394d7d843a1045fcba9f0d\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/001795ac627041668f94d32947271141 : FAILURE in 26m 14s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/296a1eb6dc4045d6a6d0299b2cf5572a : FAILURE in 25m 12s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/3970851597f34397b849e10c57ee5696 : FAILURE in 39m 14s (non-voting)","accounts_in_message":[],"_revision_number":6},{"id":"122b0625d31b15f99abdb704a020d16669939b1a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-03 14:06:56.000000000","message":"Uploaded patch set 7.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":7},{"id":"29f2723fdb3842ea6f5c1a696c68fed391cd0a7e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 15:42:52.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/8ac23ee7c0d749d092360b87e0a2890f\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/7708e165c7e24a299bc4678ef2a52e0e : SUCCESS in 14m 59s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/cd0c9a6c4e7d47419c62e8c1c251a1e6 : SUCCESS in 5m 06s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/25c153b5da9c46389779005327fc2bb1 : SUCCESS in 13m 04s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/31b79cad132c4f5484978050dce07392 : SUCCESS in 9m 20s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/930d0c506c3f48da974194cd44f08dc2 : SUCCESS in 14m 48s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/bc7460f247724003a1782c0e8dc92864 : SUCCESS in 12m 58s\n- grenade https://zuul.opendev.org/t/openstack/build/b15eee35d6fe4c07a55401b6ed1be7ae : SUCCESS in 37m 50s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/aa933e6140ac490e8669f4ee59b16486 : SUCCESS in 1h 30m 00s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3eb1bbe45651439f86bb05a0aa10d24e : SUCCESS in 12m 50s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/99386f1135c046c69ce63e6351cbbe43 : SUCCESS in 10m 58s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/5f501889b566443593a32896ed3855d0 : SUCCESS in 28m 11s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/34f9b8f173624d81a0701a48a866b47d : FAILURE in 12m 51s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/74e6e747c1f84b3798eadb1d8c9507b4 : FAILURE in 16m 45s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/f33a29f2f7dd4df5a527a817d2e12a55 : SUCCESS in 46m 01s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/9547f216b3f648638a620d4b51aa1864 : SUCCESS in 32m 20s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/3a81dce5124040c29a9288045172379e : SUCCESS in 33m 04s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/246252449e27412d8586969cc4da25ce : SUCCESS in 32m 48s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/21380ee542c341d0a949cb46d40f15ca : SUCCESS in 24m 08s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/6aaeaafd9dc4479396514f771d7c3bf6 : SUCCESS in 7m 06s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":7},{"id":"e4424e054da3d66fcb7a279005a7ec7f11627668","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-03 16:13:44.000000000","message":"Patch Set 7:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/b1999e015ef74cd295d49b4609a7f0ee\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/079517eee9c849d097deea96feafc35d : SUCCESS in 40m 16s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/7a74f1fa6c9447a6a50f30ea0d3aa4f1 : SUCCESS in 36m 50s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/8cfc97b02f644b70880dbc3d786af8da : FAILURE in 50m 56s (non-voting)","accounts_in_message":[],"_revision_number":7},{"id":"1dd1b4909a1b411fb4b3bb4b16ca39ce74b1f753","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-08-26 19:39:36.000000000","message":"Patch Set 7:\n\n(5 comments)","accounts_in_message":[],"_revision_number":7},{"id":"e315bbb3b930c3954a51105839c3da3bff85319b","author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"date":"2026-08-26 19:40:14.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"8d65abc8cadb96d120fef0944b6c05b8694f72f3","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-28 09:25:07.000000000","message":"Patch Set 7:\n\n(2 comments)","accounts_in_message":[],"_revision_number":7},{"id":"d1134ed1023ffc1ea5ca3ad41ae6cd80e8456dcd","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-28 12:15:17.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"a59b7bfe6e447e43049cecd91f3723158e3f095d","author":{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},"date":"2026-08-29 16:20:40.000000000","message":"Patch Set 7: Code-Review-1\n\nThe lockout this addresses is real, but I think the two guards are too broad as\nwritten, and one of them conflicts with the horizon companion change.\n\n1. Conflict with horizon change 977939\n\nThe MFA panel proposed in https://review.opendev.org/c/openstack/horizon/+/977939\ndisables MFA in this order, in settings/mfa/forms.py handle():\n\n    if data.get(\"credential_action\") \u003d\u003d \"delete\":\n        for cred in credentials:\n            api.keystone.credential_delete(request, cred.id)\n    api.keystone.user_update_own_options(\n        request,\n        multi_factor_auth_enabled\u003dFalse,\n        multi_factor_auth_rules\u003d[],\n    )\n\nCredentials are deleted while the rules still contain totp, so with this change\nthe first credential_delete raises Forbidden, the whole handler falls into its\nexcept branch and the user cannot disable MFA at all through that path. The\nhorizon side would need to clear the options before deleting the credentials.\n\n2. delete_credential blocks every TOTP credential, not just the last one\n\nThe check raises as soon as totp appears in the rules, without looking at how\nmany TOTP credentials the user has. Rotating an authenticator, which is the\nnormal \"I changed phone\" workflow, means enrolling a new credential and deleting\nthe old one, and that becomes impossible: the only way out is to drop totp from\nthe rules, delete, then put the rules back, leaving a window with MFA off. That\nseems worse than the situation being fixed.\n\nCounting the user\u0027s remaining active TOTP credentials and refusing only the last\none would keep the lockout protection without blocking rotation. It would also\ngive the tests a natural extra case, since the two added tests only cover the\nsingle-credential path today.\n\n3. multi_factor_auth_enabled is not taken into account\n\ncheck_auth_methods_against_rules() in keystone/auth/core.py returns early when\nthe option is false:\n\n    if not rules or not mfa_rules_enabled:\n        return True\n\nSo a user who has totp in their rules but multi_factor_auth_enabled explicitly\nset to false is not subject to MFA at login, yet this change still refuses to\ndelete their credential. The option defaults to True when unset, so the guard\nonly needs to skip when it is explicitly false.\n\n4. Inconsistent rule parsing between the two hunks\n\ncredential/core.py filters with \"if isinstance(rule, list)\", identity/core.py\ndoes not:\n\n    any(\u0027totp\u0027 in rule for rule in mfa_rules)\n\nOn a malformed rule stored as a string, that becomes a substring match rather\nthan a membership test. Worth aligning the two.\n\n5. One thing that is fine\n\ndelete_credentials_for_user() goes straight to the driver rather than through\ndelete_credential(), so deleting a user is not affected by the new guard.\n\nIt would also help to say in the release note how an operator recovers a user\nwhose device is lost, since the stale credential can no longer be removed until\ntotp is taken out of the rules first.","accounts_in_message":[],"_revision_number":7},{"id":"afff8cc40d1de2fa027d5a20032a75fe6883f795","tag":"autogenerated:gerrit:setWorkInProgress","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-29 16:36:18.000000000","message":"Set Work In Progress","accounts_in_message":[],"_revision_number":7},{"id":"6857ce24613b642da7daa6cd7a7ddb3022e3c62e","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-31 07:52:07.000000000","message":"Patch Set 7:\n\n(1 comment)\n\nThis change is ready for review.","accounts_in_message":[],"_revision_number":7},{"id":"c5c9df4c003fe57b4f2a30814c5f7c7209e94006","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-31 08:44:53.000000000","message":"Patch Set 7:\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"3fcbc741bac67c3f57b7f9d7a0211d73e2086107","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-31 13:27:17.000000000","message":"Uploaded patch set 8.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":8},{"id":"c0f351576b423bf97e171401d22e192d93598c7b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-08-31 14:21:26.000000000","message":"Uploaded patch set 9.","accounts_in_message":[],"_revision_number":9},{"id":"784e155c97a5bb5755489c4da4e48cdb0a5dc0c3","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-31 15:10:05.000000000","message":"Patch Set 9:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/78ce30bbdaa545bd92429a7a58bf3aa1\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/787f34c4a8374e3eb287f7b5416c8e27 : SUCCESS in 22m 48s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/1007a9c54adb48c58e4882ffd208ca1b : SUCCESS in 17m 28s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/b6530a03d1e14097ad48101899619254 : SUCCESS in 41m 07s (non-voting)","accounts_in_message":[],"_revision_number":9},{"id":"9531a395ce1a57bd20a09be8c4af45462be261f0","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-31 15:53:18.000000000","message":"Patch Set 9: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/3a438a2643314702b7c8bfc19d46eae5\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/134d513725434487a53969835752cfc2 : SUCCESS in 18m 08s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e108c79df64940edb4cfe2d3298d3868 : SUCCESS in 7m 42s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/928ae46bee9340c299f223744f8b65a1 : SUCCESS in 11m 56s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/1ca6ded47977442cbcf32c7c08390cf6 : SUCCESS in 7m 33s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/4d5489ca22134fc596403efc564732d9 : SUCCESS in 12m 37s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/814660ef673646ceb567397ffdc6d773 : SUCCESS in 11m 40s\n- grenade https://zuul.opendev.org/t/openstack/build/a92f3a9d06804e3591d3b477ee9843d4 : SUCCESS in 53m 09s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/4c054436b7aa4adcbfcd957321452b80 : SUCCESS in 1h 28m 51s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/81e02e04ada74c8292f04dd59df94bac : SUCCESS in 6m 09s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/9dedf11ecf354fc990c1289e3024ce68 : SUCCESS in 19m 53s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/8b3f54f0976940a9b3706dc29cae72ef : SUCCESS in 33m 54s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/69dd86bf46dd46b6b13891bb20ec4296 : FAILURE in 10m 29s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/859dde0252a6416a9e1556fa218cc537 : FAILURE in 27m 43s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/1ebf1cce21de48518d8c871f966c0d76 : SUCCESS in 41m 57s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/95fcadff654d4732813a594288f0f011 : SUCCESS in 1h 03m 17s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/e9fdc230c3ee44809d33cffd651d7512 : SUCCESS in 25m 47s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/63bb234279c94b14b4c5d29c891e11c9 : SUCCESS in 45m 38s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/5a24077983964fc584f705a766858ab4 : SUCCESS in 48m 07s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/39c225a048ec402e9e7860951a1a3fe9 : SUCCESS in 8m 34s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":9},{"id":"9bdde1a99c41d94d6e20c2f9d951dba3667e0831","author":{"_account_id":36082,"name":"Kevin Allioli","display_name":"Kevin Allioli","email":"kevin@stackops.ch","username":"kallioli"},"date":"2026-08-31 18:49:58.000000000","message":"Patch Set 9: Code-Review-1\n\nThis reads much better than patch set 7, and the admin doc warning is the\nright call: it says plainly that a user without a credential can authenticate\nwith a password alone. That was my main worry with the earlier idea and it is\nnow stated where operators will find it, so I have nothing left to ask there.\nThe X-Auth-Warning header is yours and keystone-core\u0027s call, I would only note\nthat adding a header to the Identity API probably wants an api-ref entry to go\nwith it.\n\nOne thing does need fixing. The NOTE above the new block promises two guards\nthat the code does not implement:\n\n    # ... if the rule requires totp AND the user submitted totp as an\n    # auth method but has no TOTP credentials registered ...\n    # Only strip when other valid methods remain in the rule so that a\n    # totp-only rule is not silently bypassed.\n\nNeither holds. `auth_methods` is never consulted, and the strip is\nunconditional, so a totp-only rule is bypassed:\n\n    rules \u003d [[\u0027totp\u0027]], no credential, user presents password\n\n    r_set \u003d {\u0027totp\u0027} -\u003e stripped -\u003e set()\n    `if r_set:` is False, so has_valid_auth_methods stays False\n    no rule matches, the final else returns True\n\nThe rule becomes entirely inert. That is worse than the [\u0027password\u0027, \u0027totp\u0027]\ncase, where at least the password is still required, and it is exactly what\nthe comment says it is preventing.\n\nSo either the comment describes the intended behaviour and the code is missing\nit, in which case something like\n\n    remaining \u003d r_set - {\u0027totp\u0027}\n    if remaining:\n        r_set \u003d remaining\n        ...warn...\n\nor the bypass is deliberate, matching the doc, and the comment needs to stop\nclaiming otherwise. A reader trusting that comment would conclude totp-only\nrules are safe.\n\nOne smaller point: list_credentials_for_user() runs on every authentication\nwhose rules mention totp, including the ones about to succeed. Doing the\nlookup only after `set(auth_methods).issuperset(r_set)` has failed keeps the\nnormal path free of the extra query, since a user who did present totp has a\ncredential.","accounts_in_message":[],"_revision_number":9},{"id":"60786ca396a55e9616817143a84f43745409622e","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-09-01 09:41:50.000000000","message":"Uploaded patch set 10.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:TRIVIAL_REBASE OR is:MIN\")\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":10},{"id":"fd9360819c06bb1ab2e117a281d33ddb8b3e87a5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-09-01 09:50:10.000000000","message":"Uploaded patch set 11.","accounts_in_message":[],"_revision_number":11},{"id":"d1f3398adfb6dc5a987fddd865cd2055d13cd281","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-01 10:48:27.000000000","message":"Patch Set 11:\n\nBuild succeeded (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/feccada725664b3eabe550a43f1a1c13\n\n- openstack-tox-py311-arm64 https://zuul.opendev.org/t/openstack/build/feb94d5471d44db0b1687ec376a88d55 : FAILURE in 15m 23s (non-voting)\n- openstack-tox-py313-arm64 https://zuul.opendev.org/t/openstack/build/2257904811e7447e86f294d23c764b78 : FAILURE in 15m 58s (non-voting)\n- openstack-tox-py314-arm64 https://zuul.opendev.org/t/openstack/build/9ecde4b44fe343a2b1c5c674716a462f : FAILURE in 38m 38s (non-voting)","accounts_in_message":[],"_revision_number":11},{"id":"7f3b704ccc86200afb64b5fca2edd3e0c887b153","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-09-01 11:06:04.000000000","message":"Patch Set 11: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/85e8049da276475e8db6cc2ae07e4b06\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/8314a6630df54c46a8d04a59c5752ace : FAILURE in 18m 05s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/8a3408e3ce274936a1acad59199794d7 : SUCCESS in 6m 08s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/7217833301704305aaff432caae24020 : FAILURE in 11m 30s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/bc02a877ed9e4b0b86fb19d58e6eea8f : FAILURE in 7m 20s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/d3a0464c9c23451885bec73e95966265 : FAILURE in 16m 22s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/dc2f0c6e6d9b4f8d89f976a65846b777 : SUCCESS in 13m 07s\n- grenade https://zuul.opendev.org/t/openstack/build/e417cdfc47004457bbfca18bf673cfb7 : SUCCESS in 1h 08m 11s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/52886351db9546a4b86814775c39c7fe : SUCCESS in 1h 09m 40s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/ccd8e90c1e57460197ccf5ec27c8f971 : SUCCESS in 9m 49s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/ef9f1b1f477343b6ac65103f829c22a4 : SUCCESS in 11m 01s (non-voting)\n- keystone-tempest https://zuul.opendev.org/t/openstack/build/50d93d3095d940edb8c48a9faf24811a : SUCCESS in 57m 59s\n- keystone-tempest-fips https://zuul.opendev.org/t/openstack/build/3f5070b7d2bf4dfcbcc04173206497fd : FAILURE in 11m 33s (non-voting)\n- keystone-tempest-federation https://zuul.opendev.org/t/openstack/build/bbac49fc3a0348e490004fc0a5cf3b5d : FAILURE in 26m 25s (non-voting)\n- keystone-tempest-federation-k2k https://zuul.opendev.org/t/openstack/build/c9df88f668954c9eadab00f2fe0d2dc4 : SUCCESS in 39m 05s\n- keystone-tempest-oidc-federation https://zuul.opendev.org/t/openstack/build/27ba20ca8d9a4a2393e3e6a684c31b75 : SUCCESS in 48m 14s\n- keystone-tempest-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/a65594baeba248ed8f11c57156da43c7 : SUCCESS in 22m 19s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/44b83630ef1b42748b594a086db41d92 : SUCCESS in 28m 20s\n- keystone-protection-functional https://zuul.opendev.org/t/openstack/build/1957fe27906541bb8440bfa5101c158b : SUCCESS in 43m 03s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/54ad01e5b7904aefb342b55c8946b1de : SUCCESS in 7m 47s (non-voting)\n\nWarning:\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/cleanup.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.\n  File .ssh/known_hosts.old found in build home directory during playbook opendev.org/opendev/base-jobs/playbooks/base/post-logs.yaml for job keystone-tempest-fips.  Add to preserve-home-paths if safe, or otherwise remove.","accounts_in_message":[],"_revision_number":11},{"id":"3d7ba98ef575a58f695087fa9c1523cdc4f27a5e","tag":"autogenerated:gerrit:setWorkInProgress","author":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"date":"2026-09-02 08:47:01.000000000","message":"Set Work In Progress","accounts_in_message":[],"_revision_number":11}],"current_revision_number":11,"current_revision":"b118ac2a7a1fa5645911a45a56308948be092355","revisions":{"34ecdde13147e35cbc5d9fa5f130db534b5ade24":{"kind":"REWORK","_number":1,"created":"2026-04-23 14:49:48.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/1"}}},"commit":{"parents":[{"commit":"b6fd80996b882890a51f3e2aab41d952d7ff68ae","subject":"Enforce app cred project boundary on EC2 credential paths","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b6fd80996b882890a51f3e2aab41d952d7ff68ae"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:49:13.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, I prevent the user from deleting a credential if TOTP is\nenabled. And I prevent TOTP from being enabled if a TOTP credential is not\nactive.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/34ecdde13147e35cbc5d9fa5f130db534b5ade24"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/34ecdde13147e35cbc5d9fa5f130db534b5ade24"}]},"branch":"refs/heads/master"},"0a1d75340eaacc77012306e446413340a7b7bc05":{"kind":"REWORK","_number":2,"created":"2026-04-24 06:43:36.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/2"}}},"commit":{"parents":[{"commit":"b6fd80996b882890a51f3e2aab41d952d7ff68ae","subject":"Enforce app cred project boundary on EC2 credential paths","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b6fd80996b882890a51f3e2aab41d952d7ff68ae"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-24 06:43:17.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, I prevent the user from deleting a credential if TOTP is\nenabled. And I prevent TOTP from being enabled if a TOTP credential is not\nactive.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/0a1d75340eaacc77012306e446413340a7b7bc05"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/0a1d75340eaacc77012306e446413340a7b7bc05"}]},"branch":"refs/heads/master"},"a51a7ab43cbd577d3c3737ab680a0134b0e7ce98":{"kind":"REWORK","_number":3,"created":"2026-04-24 12:02:51.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/3"}}},"commit":{"parents":[{"commit":"2230026f77a8ed50493d2d58be9120910ceb2089","subject":"Merge \"Fix keystone scope flag in tempest.conf\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2230026f77a8ed50493d2d58be9120910ceb2089"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-24 12:02:41.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, I prevent the user from deleting a credential if TOTP is\nenabled. And I prevent TOTP from being enabled if a TOTP credential is not\nactive.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a51a7ab43cbd577d3c3737ab680a0134b0e7ce98"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a51a7ab43cbd577d3c3737ab680a0134b0e7ce98"}]},"branch":"refs/heads/master"},"be53b5ceebd71a89b195376565e6109a7961e7af":{"kind":"NO_CHANGE","_number":4,"created":"2026-08-03 08:32:25.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/4"}}},"commit":{"parents":[{"commit":"2230026f77a8ed50493d2d58be9120910ceb2089","subject":"Merge \"Fix keystone scope flag in tempest.conf\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/2230026f77a8ed50493d2d58be9120910ceb2089"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-08-03 08:31:58.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, I prevent the user from deleting a credential if TOTP is\nenabled. And I prevent TOTP from being enabled if a TOTP credential is not\nactive.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/be53b5ceebd71a89b195376565e6109a7961e7af"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/be53b5ceebd71a89b195376565e6109a7961e7af"}]},"branch":"refs/heads/master"},"29de552ea3a430fde7d72c45edc522a9e6eb0baa":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-08-03 08:33:57.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/5"}}},"commit":{"parents":[{"commit":"30ef2ffa65a3486ef882f00538e20f2253c57d4c","subject":"Merge \"Make JWT token signing algorithm configurable\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/30ef2ffa65a3486ef882f00538e20f2253c57d4c"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-08-03 08:33:30.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, I prevent the user from deleting a credential if TOTP is\nenabled. And I prevent TOTP from being enabled if a TOTP credential is not\nactive.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/29de552ea3a430fde7d72c45edc522a9e6eb0baa"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/29de552ea3a430fde7d72c45edc522a9e6eb0baa"}]},"branch":"refs/heads/master"},"b6453c7505800fd59942d59c3dc19f79003081cd":{"kind":"NO_CHANGE","_number":6,"created":"2026-08-03 08:36:24.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/6"}}},"commit":{"parents":[{"commit":"30ef2ffa65a3486ef882f00538e20f2253c57d4c","subject":"Merge \"Make JWT token signing algorithm configurable\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/30ef2ffa65a3486ef882f00538e20f2253c57d4c"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-08-03 08:36:03.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, I prevent the user from deleting a credential if TOTP is\nenabled. And I prevent TOTP from being enabled if a TOTP credential is not\nactive.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b6453c7505800fd59942d59c3dc19f79003081cd"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b6453c7505800fd59942d59c3dc19f79003081cd"}]},"branch":"refs/heads/master"},"c3622da3e0927946e7c176ce5ded80f323e2dfc8":{"kind":"REWORK","_number":7,"created":"2026-08-03 14:06:56.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/7"}}},"commit":{"parents":[{"commit":"30ef2ffa65a3486ef882f00538e20f2253c57d4c","subject":"Merge \"Make JWT token signing algorithm configurable\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/30ef2ffa65a3486ef882f00538e20f2253c57d4c"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-08-03 14:05:40.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, I prevent the user from deleting a credential if TOTP is\nenabled. And I prevent TOTP from being enabled if a TOTP credential is not\nactive.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c3622da3e0927946e7c176ce5ded80f323e2dfc8"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/c3622da3e0927946e7c176ce5ded80f323e2dfc8"}]},"branch":"refs/heads/master"},"43aa036b42ece3e377757412902eb56bf9da2934":{"kind":"REWORK","_number":8,"created":"2026-08-31 13:27:17.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/8"}}},"commit":{"parents":[{"commit":"16afc813b7e6de727d8a91e065d7824b06e32925","subject":"Merge \"Abandon server-side paged search cursor when sizelimit is reached\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/16afc813b7e6de727d8a91e065d7824b06e32925"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-08-31 13:26:51.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, when evaluating MFA rules, if a rule requires ``totp``\nbut the user has no TOTP credential registered, the ``totp``\nrequirement is silently dropped from that rule at evaluation time.\nThis allows the remaining methods (e.g. ``password``) to satisfy\nauthentication and prevents lockout. A warning is returned via the\n``X-Auth-Warning`` response header to advise the user to register a\nTOTP credential.\n\nThe ``check_auth_methods_against_rules`` method now returns a\n``(passed, warnings)`` tuple instead of a plain boolean.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/43aa036b42ece3e377757412902eb56bf9da2934"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/43aa036b42ece3e377757412902eb56bf9da2934"}]},"branch":"refs/heads/master"},"d188491860226539b593eedfb17c01b01648dcf1":{"kind":"REWORK","_number":9,"created":"2026-08-31 14:21:26.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/9","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/9","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/9"}}},"commit":{"parents":[{"commit":"16afc813b7e6de727d8a91e065d7824b06e32925","subject":"Merge \"Abandon server-side paged search cursor when sizelimit is reached\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/16afc813b7e6de727d8a91e065d7824b06e32925"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-08-31 14:21:05.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, when evaluating MFA rules, if a rule requires ``totp``\nbut the user has no TOTP credential registered, the ``totp``\nrequirement is silently dropped from that rule at evaluation time.\nThis allows the remaining methods (e.g. ``password``) to satisfy\nauthentication and prevents lockout. A warning is returned via the\n``X-Auth-Warning`` response header to advise the user to register a\nTOTP credential.\n\nThe ``check_auth_methods_against_rules`` method now returns a\n``(passed, warnings)`` tuple instead of a plain boolean.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d188491860226539b593eedfb17c01b01648dcf1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/d188491860226539b593eedfb17c01b01648dcf1"}]},"branch":"refs/heads/master"},"747d3e17dfe95e9b9ea159f572a1bd66215fd2c2":{"kind":"REWORK","_number":10,"created":"2026-09-01 09:41:50.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/10","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/10","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/10"}}},"commit":{"parents":[{"commit":"16afc813b7e6de727d8a91e065d7824b06e32925","subject":"Merge \"Abandon server-side paged search cursor when sizelimit is reached\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/16afc813b7e6de727d8a91e065d7824b06e32925"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-09-01 09:36:56.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, when evaluating MFA rules, if a rule requires ``totp``\nbut the user has no TOTP credential registered, the ``totp``\nrequirement is silently dropped from that rule at evaluation time.\nThis allows the remaining methods (e.g. ``password``) to satisfy\nauthentication and prevents lockout. A warning is returned via the\n``X-Auth-Warning`` response header to advise the user to register a\nTOTP credential.\n\nThe ``check_auth_methods_against_rules`` method now returns a\n``(passed, warnings)`` tuple instead of a plain boolean.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/747d3e17dfe95e9b9ea159f572a1bd66215fd2c2"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/747d3e17dfe95e9b9ea159f572a1bd66215fd2c2"}]},"branch":"refs/heads/master"},"b118ac2a7a1fa5645911a45a56308948be092355":{"kind":"REWORK","_number":11,"created":"2026-09-01 09:50:10.000000000","uploader":{"_account_id":36012,"name":"Benjamin Lasseye","display_name":"Benjamin Lasseye","email":"blasseye@ikmail.com","username":"blasseye"},"ref":"refs/changes/69/985969/11","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/69/985969/11","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/69/985969/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/69/985969/11"}}},"commit":{"parents":[{"commit":"16afc813b7e6de727d8a91e065d7824b06e32925","subject":"Merge \"Abandon server-side paged search cursor when sizelimit is reached\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/16afc813b7e6de727d8a91e065d7824b06e32925"}]}],"author":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-04-23 14:35:03.000000000","tz":120},"committer":{"name":"blasseye","email":"blasseye@ikmail.com","date":"2026-09-01 09:49:40.000000000","tz":120},"subject":"Fix: TOTP authentication lockout risk in Keystone","message":"Fix: TOTP authentication lockout risk in Keystone\n\nEnabling TOTP authentication in Keystone without users already having TOTP\ncredentials can result in authentication being completely blocked.\nFurthermore, if a user (or an administrator) deletes an existing TOTP\ncredential while TOTP is enforced as a mandatory authentication method,\nthe user is immediately locked out, as they can no longer meet the\nauthentication requirements or re-register a new credential.\n\nWith this fix, when evaluating MFA rules, if a rule requires ``totp``\nbut the user has no TOTP credential registered, the ``totp``\nrequirement is silently dropped from that rule at evaluation time.\nThis allows the remaining methods (e.g. ``password``) to satisfy\nauthentication and prevents lockout. A warning is returned via the\n``X-Auth-Warning`` response header to advise the user to register a\nTOTP credential.\n\nThe ``check_auth_methods_against_rules`` method now returns a\n``(passed, warnings)`` tuple instead of a plain boolean.\n\nCloses-Bug: #2150088\nChange-Id: I3d72b789552522ff34b5291143c49fea6f154343\nSigned-off-by: blasseye \u003cblasseye@ikmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b118ac2a7a1fa5645911a45a56308948be092355"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/b118ac2a7a1fa5645911a45a56308948be092355"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
