)]}'
{"id":"openstack%2Fkeystone~989203","triplet_id":"openstack%2Fkeystone~stable%2F2025.1~I238870bb859928b7152f62dec54c51c0c1d2819b","project":"openstack/keystone","branch":"stable/2025.1","attention_set":{},"removed_from_attention_set":{"7414":{"account":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"last_update":"2026-05-20 01:24:10.000000000","reason":"\u003cGERRIT_ACCOUNT_7414\u003e replied on the change","reason_account":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}},"37598":{"account":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"last_update":"2026-05-20 03:11:31.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"I238870bb859928b7152f62dec54c51c0c1d2819b","subject":"Use branch constraints for tempest venv on stable/2025.1","status":"MERGED","created":"2026-05-19 18:58:18.000000000","updated":"2026-05-20 03:14:50.000000000","submitted":"2026-05-20 03:11:31.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":3,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"989203","meta_rev_id":"44f3bcb34bdfd32e624bfa57acff706fe022fcfb","_number":989203,"virtual_id_number":989203,"owner":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-05-20 03:11:31.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":2,"date":"2026-05-20 01:24:10.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"all":[{"value":1,"date":"2026-05-20 01:24:10.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"CC":[{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-05-19 20:12:03.000000000","updated_by":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"reviewer":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"state":"CC"},{"updated":"2026-05-19 21:52:14.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"a2262bf64151f839017b4742941d1116210e6ba7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-19 18:58:18.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"d9e6bb7ff5c5018cb970ad51c094b1c4465fa672","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-19 19:01:49.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"3f6720575abede98a0b5cccadcdd98d0f28b06d8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-19 19:31:42.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"685e9f3c8d0a12bdab5926ce290f5c9481435a38","author":{"_account_id":37598,"name":"Ivan Anfimov","display_name":"Ivan Anfimov","email":"lazekteam@gmail.com","username":"anfimovir"},"date":"2026-05-19 20:12:03.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"629d22aa7f1677392cee741cd606f0c11d184890","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-19 20:43:44.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"3f427e87e1bb2711fde42ea3d0c32a4fba5041f3","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-19 21:25:10.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"72b15672da5009ae50c742d088c57fc71a603b2b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-19 21:52:14.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/25e30d2b75214dab9155e0390b80edae\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/a424635b550545a09d24082dbb985194 : SUCCESS in 18m 48s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/37ca8671b18c43459df57b17a78ee69a : SUCCESS in 6m 17s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/76e5870ea1b041e293a46cd7abb6bc7c : SUCCESS in 11m 46s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/0a104499475a48859e2aa194acdf776a : SUCCESS in 12m 18s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/f8630b77405d47a5a4f31ff0ace6b69b : SUCCESS in 16m 38s\n- grenade https://zuul.opendev.org/t/openstack/build/d844ad542d53449298791d478d3aadbe : SUCCESS in 1h 00m 58s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/f7c4ced6ed71405693e4553e311c05f9 : SUCCESS in 59m 58s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/2cb9bfa372104c9581f6863d7ed0b1a2 : SUCCESS in 6m 56s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/1f81f56a98d147fb8688a937fdaa1b3b : SUCCESS in 31m 53s\n- keystone-dsvm-py3-functional-fips https://zuul.opendev.org/t/openstack/build/a7789e694fbb4c2b98f9587a8a29033d : FAILURE in 36m 51s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy https://zuul.opendev.org/t/openstack/build/d0c9612a844440c9b03a84ed82713d9d : FAILURE in 23m 59s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy-k2k https://zuul.opendev.org/t/openstack/build/fa57508d413943d492de09f9eb1db303 : FAILURE in 13m 25s\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/04eecddbb7f1422e927e17274a26c0bd : SUCCESS in 16m 23s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/8ec12c4ecfb0456c804345b6cf3dd90f : SUCCESS in 34m 34s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/8cbb08626ceb4fbe9637b822a349d475 : SUCCESS in 55m 49s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/3910ed5386fc4ab9b787c402f4e61305 : FAILURE in 5m 57s (non-voting)\n- keystone-dsvm-functional-oidc-federation https://zuul.opendev.org/t/openstack/build/848bbb67c07d4fdcb2b27c455ad3b9c7 : FAILURE in 31m 51s","accounts_in_message":[],"_revision_number":4},{"id":"3a741feb7abb4ea2a0b37ebbcdf68af056cb7f9d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-19 23:37:30.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"77678d2223da693a756d4b01a13fc52f9b6d7374","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-20 01:20:12.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/ff8eebd8e0974fcabab52bbd293b22a3\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/910237f65de44c61898368b5547c9158 : SUCCESS in 18m 00s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/da219021a1fc419f8d42855a69852939 : SUCCESS in 3m 54s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/8c681157e9b04b198404954cc7a37caa : SUCCESS in 11m 06s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/a04374c523f3415aa2111f8e69859a9b : SUCCESS in 8m 42s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e80a0d3dfe464abcb67375571d036fec : SUCCESS in 14m 24s\n- grenade https://zuul.opendev.org/t/openstack/build/8931d49960df4d098690fbfdbb1f11ea : SUCCESS in 1h 06m 47s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/4f45d38c1b004bd09a2995ee16e991fc : SUCCESS in 1h 41m 19s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/dec3a7c420524499b2f3ce0aa5724d4c : SUCCESS in 12m 18s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/c7d87fe42b204c0187a23180dae05038 : SUCCESS in 35m 02s\n- keystone-dsvm-py3-functional-fips https://zuul.opendev.org/t/openstack/build/7f6a1458cf424bd7bb6e49955b2993d7 : FAILURE in 38m 51s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy https://zuul.opendev.org/t/openstack/build/17a8e4c8ec9647dba39269bda61942b3 : FAILURE in 17m 06s (non-voting)\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy-k2k https://zuul.opendev.org/t/openstack/build/e9b9f88bfec44f12bbf2f1206858e750 : FAILURE in 28m 39s (non-voting)\n- keystoneclient-devstack-functional https://zuul.opendev.org/t/openstack/build/203b7f9b99684079b9649c7fa2bd1d7e : SUCCESS in 15m 28s (non-voting)\n- keystone-dsvm-ldap-domain-specific-driver https://zuul.opendev.org/t/openstack/build/f740b39eaf8f4fe28efdf5d29db1ad7e : SUCCESS in 39m 15s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/0d8049db70664a8ab8cc1407ffa65962 : SUCCESS in 46m 39s\n- codegenerator-openapi-identity-tips-with-api-ref https://zuul.opendev.org/t/openstack/build/328fe3fe999947a7b4843f12d7213286 : FAILURE in 3m 39s (non-voting)\n- keystone-dsvm-functional-oidc-federation https://zuul.opendev.org/t/openstack/build/cc50b7942434402d9ea08a4b5dbd9e36 : FAILURE in 30m 50s (non-voting)","accounts_in_message":[],"_revision_number":5},{"id":"2e9b77b8d1013513674631f1ceee21fdc66ec313","author":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"date":"2026-05-20 01:24:10.000000000","message":"Patch Set 5: Code-Review+2 Workflow+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"7f4e9ad707aad775c4ffc74de905de42589377eb","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-20 01:25:04.000000000","message":"Patch Set 5: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":5},{"id":"93d1c7693ac53d86257453677ac7945650a72bfa","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-20 03:11:31.000000000","message":"Patch Set 5: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/08546df2c74e4b5fb0278cad883cd852\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a9d7b3ed5ed6439d9a1e12300bc7e7e5 : SUCCESS in 7m 05s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/894d66d7d4f54df3919822bbe3b8853a : SUCCESS in 13m 06s\n- openstack-tox-py312 https://zuul.opendev.org/t/openstack/build/3d021b9713154ae0bc9841dcb492c5fd : SUCCESS in 8m 47s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/64d82aa1bb5142dc83c7be5e790c847f : SUCCESS in 11m 56s\n- grenade https://zuul.opendev.org/t/openstack/build/19faee54f5b84216995a1d54baf09093 : SUCCESS in 33m 25s\n- tempest-full-py3 https://zuul.opendev.org/t/openstack/build/21e2de57d5ed417cb8d8c3266e85bfb8 : SUCCESS in 1h 44m 13s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/75187a97ee6c4112a428ae91bb10717c : SUCCESS in 12m 35s\n- keystone-dsvm-py3-functional https://zuul.opendev.org/t/openstack/build/fd7566b6a43a4cb78bf932b7367ef52a : SUCCESS in 31m 16s\n- keystone-dsvm-py3-functional-federation-ubuntu-jammy-k2k https://zuul.opendev.org/t/openstack/build/0aa0e88f5ccb420ea94c630a3afe1bf9 : FAILURE in 27m 46s (non-voting)\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/0afb23b63adc456c96d232f256bf396e : SUCCESS in 35m 13s","accounts_in_message":[],"_revision_number":5},{"id":"a971d88705c102c3d1be33a8cd3de29bcedb401e","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-20 03:11:31.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":5},{"id":"44f3bcb34bdfd32e624bfa57acff706fe022fcfb","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-05-20 03:14:50.000000000","message":"Patch Set 5:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/5bb5de338b134be6a1a82463234cf274\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/0fb00b6a04e641e69fee9f721b599a77 : SUCCESS in 1m 04s","accounts_in_message":[],"_revision_number":5}],"current_revision_number":5,"current_revision":"52c167fb2504bc9963d17248c4c506140e035757","revisions":{"bd60b52bad9f284517b5df1fdad98f04b9cb9a35":{"kind":"REWORK","_number":1,"created":"2026-05-19 18:58:18.000000000","uploader":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"ref":"refs/changes/03/989203/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/03/989203/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/03/989203/1"}}},"commit":{"parents":[{"commit":"33744fef63a618e074af4915f03427a054ac4bc8","subject":"Block app cred tokens from authorizing OAuth1 requests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/33744fef63a618e074af4915f03427a054ac4bc8"}]}],"author":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 18:43:56.000000000","tz":-300},"committer":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 18:43:56.000000000","tz":-300},"subject":"Use branch constraints for tempest venv on stable/2025.1","message":"Use branch constraints for tempest venv on stable/2025.1\n\nThe stable/2025.1 gate is completely broken for all Keystone changes.\nThe grenade, grenade-skip-level, k2k federation, and other devstack-\nbased jobs fail during configure_tempest because tox creates a \u0027venv\u0027\nenvironment using master\u0027s upper-constraints.txt, which pins\nSphinx\u003d\u003d\u003d9.0.4. This conflicts with tempest\u0027s doc/requirements.txt\n(sphinx\u003e\u003d2.0.0,!\u003d2.1.0), producing a ResolutionImpossible error from\npip. No Keystone code executes before the failure.\n\nFix this by setting TEMPEST_VENV_UPPER_CONSTRAINTS to the branch-\nspecific constraints file from the locally cloned requirements repo.\nDevStack already supports this: when the variable is set to a file\npath (not \"master\"), set_tempest_venv_constraints in lib/tempest\nreads the file and exports UPPER_CONSTRAINTS_FILE pointing to it.\nThe cloned requirements repo on each branch has a compatible Sphinx\npin, eliminating the resolution conflict.\n\nFor grenade jobs, the variable is set via grenade_devstack_localrc\n(shared) so it applies to both old-side and new-side devstack. On\nthe old side (stable/2024.2), $DEST expands to /opt/stack/old and\nthe requirements repo is cloned from stable/2024.2. On the new side,\n$DEST is /opt/stack/new with stable/2025.1 constraints. Both have\nSphinx pins compatible with their respective tempest versions.\n\nThis is a standalone CI configuration change, separate from change\n988237 (the EC2 credential policy fix that was blocked by this gate\nfailure).\n\nAssisted-by: Claude Code (Opus 4.6)\nChange-Id: I238870bb859928b7152f62dec54c51c0c1d2819b\nSigned-off-by: Dave Wilde \u003cdwilde@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/bd60b52bad9f284517b5df1fdad98f04b9cb9a35"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/bd60b52bad9f284517b5df1fdad98f04b9cb9a35"}]},"branch":"refs/heads/stable/2025.1"},"63e981d2b9c1b68d937082a56d63da88b706f3a9":{"kind":"REWORK","_number":2,"created":"2026-05-19 19:01:49.000000000","uploader":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"ref":"refs/changes/03/989203/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/03/989203/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/03/989203/2"}}},"commit":{"parents":[{"commit":"33744fef63a618e074af4915f03427a054ac4bc8","subject":"Block app cred tokens from authorizing OAuth1 requests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/33744fef63a618e074af4915f03427a054ac4bc8"}]}],"author":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 18:43:56.000000000","tz":-300},"committer":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 19:01:42.000000000","tz":-300},"subject":"Use branch constraints for tempest venv on stable/2025.1","message":"Use branch constraints for tempest venv on stable/2025.1\n\nThe stable/2025.1 gate is completely broken for all Keystone changes.\nThe grenade, grenade-skip-level, k2k federation, and other devstack-\nbased jobs fail during configure_tempest because tox creates a \u0027venv\u0027\nenvironment using master\u0027s upper-constraints.txt, which pins\nSphinx\u003d\u003d\u003d9.0.4. This conflicts with tempest\u0027s doc/requirements.txt\n(sphinx\u003e\u003d2.0.0,!\u003d2.1.0), producing a ResolutionImpossible error from\npip. No Keystone code executes before the failure.\n\nFix this by setting TEMPEST_VENV_UPPER_CONSTRAINTS to the branch-\nspecific constraints file from the locally cloned requirements repo.\nDevStack already supports this: when the variable is set to a file\npath (not \"master\"), set_tempest_venv_constraints in lib/tempest\nreads the file and exports UPPER_CONSTRAINTS_FILE pointing to it.\nThe cloned requirements repo on each branch has a compatible Sphinx\npin, eliminating the resolution conflict.\n\nFor grenade jobs, the variable is set via grenade_devstack_localrc\n(shared) so it applies to both old-side and new-side devstack. On\nthe old side (stable/2024.2), $DEST expands to /opt/stack/old and\nthe requirements repo is cloned from stable/2024.2. On the new side,\n$DEST is /opt/stack/new with stable/2025.1 constraints. Both have\nSphinx pins compatible with their respective tempest versions.\n\nThis is a standalone CI configuration change, separate from change\n988237 (the EC2 credential policy fix that was blocked by this gate\nfailure).\n\nAssisted-by: Claude Code (Opus 4.6)\nChange-Id: I238870bb859928b7152f62dec54c51c0c1d2819b\nSigned-off-by: Dave Wilde \u003cdwilde@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/63e981d2b9c1b68d937082a56d63da88b706f3a9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/63e981d2b9c1b68d937082a56d63da88b706f3a9"}]},"branch":"refs/heads/stable/2025.1"},"02b1057050d3168025c4e83a62e2bea8384d2362":{"kind":"REWORK","_number":3,"created":"2026-05-19 19:31:42.000000000","uploader":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"ref":"refs/changes/03/989203/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/03/989203/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/03/989203/3"}}},"commit":{"parents":[{"commit":"33744fef63a618e074af4915f03427a054ac4bc8","subject":"Block app cred tokens from authorizing OAuth1 requests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/33744fef63a618e074af4915f03427a054ac4bc8"}]}],"author":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 18:43:56.000000000","tz":-300},"committer":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 19:31:34.000000000","tz":-300},"subject":"Use branch constraints for tempest venv on stable/2025.1","message":"Use branch constraints for tempest venv on stable/2025.1\n\nThe stable/2025.1 gate is completely broken for all Keystone changes.\nThe grenade, grenade-skip-level, k2k federation, and other devstack-\nbased jobs fail during configure_tempest because tox creates a \u0027venv\u0027\nenvironment using master\u0027s upper-constraints.txt, which pins\nSphinx\u003d\u003d\u003d9.0.4. This conflicts with tempest\u0027s doc/requirements.txt\n(sphinx\u003e\u003d2.0.0,!\u003d2.1.0), producing a ResolutionImpossible error from\npip. No Keystone code executes before the failure.\n\nFix this by setting TEMPEST_VENV_UPPER_CONSTRAINTS to the branch-\nspecific constraints file from the locally cloned requirements repo.\nDevStack already supports this: when the variable is set to a file\npath (not \"master\"), set_tempest_venv_constraints in lib/tempest\nreads the file and exports UPPER_CONSTRAINTS_FILE pointing to it.\nThe cloned requirements repo on each branch has a compatible Sphinx\npin, eliminating the resolution conflict.\n\nFor grenade jobs, the variable is set via grenade_devstack_localrc\n(shared) so it applies to both old-side and new-side devstack. On\nthe old side (stable/2024.2), $DEST expands to /opt/stack/old and\nthe requirements repo is cloned from stable/2024.2. On the new side,\n$DEST is /opt/stack/new with stable/2025.1 constraints. Both have\nSphinx pins compatible with their respective tempest versions.\n\nThis is a standalone CI configuration change, separate from change\n988237 (the EC2 credential policy fix that was blocked by this gate\nfailure).\n\nAssisted-by: Claude Code (Opus 4.6)\nChange-Id: I238870bb859928b7152f62dec54c51c0c1d2819b\nSigned-off-by: Dave Wilde \u003cdwilde@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/02b1057050d3168025c4e83a62e2bea8384d2362"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/02b1057050d3168025c4e83a62e2bea8384d2362"}]},"branch":"refs/heads/stable/2025.1"},"a38c49e47955bc2ecf51b54613dbc866b0bdc78e":{"kind":"REWORK","_number":4,"created":"2026-05-19 20:43:44.000000000","uploader":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"ref":"refs/changes/03/989203/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/03/989203/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/03/989203/4"}}},"commit":{"parents":[{"commit":"33744fef63a618e074af4915f03427a054ac4bc8","subject":"Block app cred tokens from authorizing OAuth1 requests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/33744fef63a618e074af4915f03427a054ac4bc8"}]}],"author":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 18:43:56.000000000","tz":-300},"committer":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 20:43:36.000000000","tz":-300},"subject":"Use branch constraints for tempest venv on stable/2025.1","message":"Use branch constraints for tempest venv on stable/2025.1\n\nThe stable/2025.1 gate is completely broken for all Keystone changes.\nThe grenade, grenade-skip-level, k2k federation, and other devstack-\nbased jobs fail during configure_tempest because tox creates a \u0027venv\u0027\nenvironment using master\u0027s upper-constraints.txt, which pins\nSphinx\u003d\u003d\u003d9.0.4. This conflicts with tempest\u0027s doc/requirements.txt\n(sphinx\u003e\u003d2.0.0,!\u003d2.1.0), producing a ResolutionImpossible error from\npip. No Keystone code executes before the failure.\n\nFix this by setting TEMPEST_VENV_UPPER_CONSTRAINTS to the branch-\nspecific constraints file from the locally cloned requirements repo.\nDevStack already supports this: when the variable is set to a file\npath (not \"master\"), set_tempest_venv_constraints in lib/tempest\nreads the file and exports UPPER_CONSTRAINTS_FILE pointing to it.\nThe cloned requirements repo on each branch has a compatible Sphinx\npin, eliminating the resolution conflict.\n\nFor grenade jobs, the variable is set via grenade_devstack_localrc\n(shared) so it applies to both old-side and new-side devstack. On\nthe old side (stable/2024.2), $DEST expands to /opt/stack/old and\nthe requirements repo is cloned from stable/2024.2. On the new side,\n$DEST is /opt/stack/new with stable/2025.1 constraints. Both have\nSphinx pins compatible with their respective tempest versions.\n\nThis is a standalone CI configuration change, separate from change\n988237 (the EC2 credential policy fix that was blocked by this gate\nfailure).\n\nAssisted-by: Claude Code (Opus 4.6)\nChange-Id: I238870bb859928b7152f62dec54c51c0c1d2819b\nSigned-off-by: Dave Wilde \u003cdwilde@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a38c49e47955bc2ecf51b54613dbc866b0bdc78e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/a38c49e47955bc2ecf51b54613dbc866b0bdc78e"}]},"branch":"refs/heads/stable/2025.1"},"52c167fb2504bc9963d17248c4c506140e035757":{"kind":"REWORK","_number":5,"created":"2026-05-19 23:37:30.000000000","uploader":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"},"ref":"refs/changes/03/989203/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/keystone","ref":"refs/changes/03/989203/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/keystone refs/changes/03/989203/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/keystone refs/changes/03/989203/5"}}},"commit":{"parents":[{"commit":"33744fef63a618e074af4915f03427a054ac4bc8","subject":"Block app cred tokens from authorizing OAuth1 requests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/33744fef63a618e074af4915f03427a054ac4bc8"}]}],"author":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 18:43:56.000000000","tz":-300},"committer":{"name":"Dave Wilde (d34dh0r53)","email":"dwilde@redhat.com","date":"2026-05-19 23:37:21.000000000","tz":-300},"subject":"Use branch constraints for tempest venv on stable/2025.1","message":"Use branch constraints for tempest venv on stable/2025.1\n\nThe stable/2025.1 gate is completely broken for all Keystone changes.\nThe grenade, grenade-skip-level, k2k federation, and other devstack-\nbased jobs fail during configure_tempest because tox creates a \u0027venv\u0027\nenvironment using master\u0027s upper-constraints.txt, which pins\nSphinx\u003d\u003d\u003d9.0.4. This conflicts with tempest\u0027s doc/requirements.txt\n(sphinx\u003e\u003d2.0.0,!\u003d2.1.0), producing a ResolutionImpossible error from\npip. No Keystone code executes before the failure.\n\nFix this by setting TEMPEST_VENV_UPPER_CONSTRAINTS to the branch-\nspecific constraints file from the locally cloned requirements repo.\nDevStack already supports this: when the variable is set to a file\npath (not \"master\"), set_tempest_venv_constraints in lib/tempest\nreads the file and exports UPPER_CONSTRAINTS_FILE pointing to it.\nThe cloned requirements repo on each branch has a compatible Sphinx\npin, eliminating the resolution conflict.\n\nFor grenade jobs, the variable is set via grenade_devstack_localrc\n(shared) so it applies to both old-side and new-side devstack. On\nthe old side (stable/2024.2), $DEST expands to /opt/stack/old and\nthe requirements repo is cloned from stable/2024.2. On the new side,\n$DEST is /opt/stack/new with stable/2025.1 constraints. Both have\nSphinx pins compatible with their respective tempest versions.\n\nThis is a standalone CI configuration change, separate from change\n988237 (the EC2 credential policy fix that was blocked by this gate\nfailure).\n\nAssisted-by: Claude Code (Opus 4.6)\nChange-Id: I238870bb859928b7152f62dec54c51c0c1d2819b\nSigned-off-by: Dave Wilde \u003cdwilde@redhat.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/52c167fb2504bc9963d17248c4c506140e035757"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/keystone/commit/52c167fb2504bc9963d17248c4c506140e035757"}]},"branch":"refs/heads/stable/2025.1"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":7414,"name":"David Wilde","email":"dwilde@redhat.com","username":"d34dh0r53"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
