)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"e55e9f52ac45e5a828e33bd303fb2bae236545b7","unresolved":true,"context_lines":[{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Drop unset values from kolla_toolbox module_args"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"In Ansible, the omit filter only removes top-level module parameters. When used as a value inside nested dictionaries like kolla_toolbox\u0027s module_args, it reaches the invoked module as a literal \u0027omit_place_holder...\u0027 string. Similarly, empty variables (like an empty openstack_cacert) are passed as literal empty strings."},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"This causes unexpected behavior across various modules that expect parameters to be completely absent or None. For example, community.mysql evaluates its TLS parameters against None, treating both the omit placeholder and empty strings as actively set values. This specific case causes PyMySQL to wrongly verify the server certificate against the system trust store, resulting in a CERTIFICATE_VERIFY_FAILED error."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"To solve this globally, module_args are now sanitized inside kolla_toolbox to drop both omit placeholders and empty strings before the playbook is written. This centralized approach fixes the underlying dictionary issue in one place, removing the need to apply workarounds in every role (e.g., for ca_cert). Values that are meaningful while falsy, such as False, 0, or None, are safely preserved and forwarded."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Closes-Bug: #2161647"},{"line_number":16,"context_line":"Change-Id: If5c1a02f8e6efac4613f4aeb42f1aa422e5043e8"},{"line_number":17,"context_line":"Signed-off-by: kkaptanoglu \u003ckubilay@kaptanoglu.me\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":8,"id":"a23b8614_ec698a37","line":14,"range":{"start_line":9,"start_character":0,"end_line":14,"end_character":0},"updated":"2026-09-08 11:30:23.000000000","message":"These long lines should be wrapped and AI-generated content should be shortened.","commit_id":"aa83662e938fa940fd4a3edf6f5ba57876cae516"},{"author":{"_account_id":38863,"name":"Kubilay Kaptanoglu","display_name":"kkaptanoglu","email":"kkaptanoglu@vmind.com.tr","username":"kkaptanoglu"},"change_message_id":"5f7d60c27eb59e227ef036cfe4f8feb4e0d37f39","unresolved":true,"context_lines":[{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Drop unset values from kolla_toolbox module_args"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"In Ansible, the omit filter only removes top-level module parameters. When used as a value inside nested dictionaries like kolla_toolbox\u0027s module_args, it reaches the invoked module as a literal \u0027omit_place_holder...\u0027 string. Similarly, empty variables (like an empty openstack_cacert) are passed as literal empty strings."},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"This causes unexpected behavior across various modules that expect parameters to be completely absent or None. For example, community.mysql evaluates its TLS parameters against None, treating both the omit placeholder and empty strings as actively set values. This specific case causes PyMySQL to wrongly verify the server certificate against the system trust store, resulting in a CERTIFICATE_VERIFY_FAILED error."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"To solve this globally, module_args are now sanitized inside kolla_toolbox to drop both omit placeholders and empty strings before the playbook is written. This centralized approach fixes the underlying dictionary issue in one place, removing the need to apply workarounds in every role (e.g., for ca_cert). Values that are meaningful while falsy, such as False, 0, or None, are safely preserved and forwarded."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Closes-Bug: #2161647"},{"line_number":16,"context_line":"Change-Id: If5c1a02f8e6efac4613f4aeb42f1aa422e5043e8"},{"line_number":17,"context_line":"Signed-off-by: kkaptanoglu \u003ckubilay@kaptanoglu.me\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":8,"id":"918236d0_c7f8f120","line":14,"range":{"start_line":9,"start_character":0,"end_line":14,"end_character":0},"in_reply_to":"181e198b_87558796","updated":"2026-09-08 13:06:22.000000000","message":"thank you for the detailed explanation.","commit_id":"aa83662e938fa940fd4a3edf6f5ba57876cae516"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"0b69967ec0a719b073b6b77808186f9b209f66cc","unresolved":true,"context_lines":[{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Drop unset values from kolla_toolbox module_args"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"In Ansible, the omit filter only removes top-level module parameters. When used as a value inside nested dictionaries like kolla_toolbox\u0027s module_args, it reaches the invoked module as a literal \u0027omit_place_holder...\u0027 string. Similarly, empty variables (like an empty openstack_cacert) are passed as literal empty strings."},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"This causes unexpected behavior across various modules that expect parameters to be completely absent or None. For example, community.mysql evaluates its TLS parameters against None, treating both the omit placeholder and empty strings as actively set values. This specific case causes PyMySQL to wrongly verify the server certificate against the system trust store, resulting in a CERTIFICATE_VERIFY_FAILED error."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"To solve this globally, module_args are now sanitized inside kolla_toolbox to drop both omit placeholders and empty strings before the playbook is written. This centralized approach fixes the underlying dictionary issue in one place, removing the need to apply workarounds in every role (e.g., for ca_cert). Values that are meaningful while falsy, such as False, 0, or None, are safely preserved and forwarded."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Closes-Bug: #2161647"},{"line_number":16,"context_line":"Change-Id: If5c1a02f8e6efac4613f4aeb42f1aa422e5043e8"},{"line_number":17,"context_line":"Signed-off-by: kkaptanoglu \u003ckubilay@kaptanoglu.me\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":8,"id":"181e198b_87558796","line":14,"range":{"start_line":9,"start_character":0,"end_line":14,"end_character":0},"in_reply_to":"281a148d_22d353cf","updated":"2026-09-08 12:34:45.000000000","message":"still very long\nplease read: https://wiki.openstack.org/wiki/GitCommitMessages#Summary_of_Git_commit_message_structure","commit_id":"aa83662e938fa940fd4a3edf6f5ba57876cae516"},{"author":{"_account_id":14200,"name":"Maksim Malchuk","email":"maksim.malchuk@gmail.com","username":"mmalchuk"},"change_message_id":"a5fb226c29cf7ffc049036f5093b317456e2bb87","unresolved":false,"context_lines":[{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Drop unset values from kolla_toolbox module_args"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"In Ansible, the omit filter only removes top-level module parameters. When used as a value inside nested dictionaries like kolla_toolbox\u0027s module_args, it reaches the invoked module as a literal \u0027omit_place_holder...\u0027 string. Similarly, empty variables (like an empty openstack_cacert) are passed as literal empty strings."},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"This causes unexpected behavior across various modules that expect parameters to be completely absent or None. For example, community.mysql evaluates its TLS parameters against None, treating both the omit placeholder and empty strings as actively set values. This specific case causes PyMySQL to wrongly verify the server certificate against the system trust store, resulting in a CERTIFICATE_VERIFY_FAILED error."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"To solve this globally, module_args are now sanitized inside kolla_toolbox to drop both omit placeholders and empty strings before the playbook is written. This centralized approach fixes the underlying dictionary issue in one place, removing the need to apply workarounds in every role (e.g., for ca_cert). Values that are meaningful while falsy, such as False, 0, or None, are safely preserved and forwarded."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Closes-Bug: #2161647"},{"line_number":16,"context_line":"Change-Id: If5c1a02f8e6efac4613f4aeb42f1aa422e5043e8"},{"line_number":17,"context_line":"Signed-off-by: kkaptanoglu \u003ckubilay@kaptanoglu.me\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":8,"id":"340c21fc_dc9e8a1e","line":14,"range":{"start_line":9,"start_character":0,"end_line":14,"end_character":0},"in_reply_to":"918236d0_c7f8f120","updated":"2026-09-08 13:28:56.000000000","message":"Done","commit_id":"aa83662e938fa940fd4a3edf6f5ba57876cae516"},{"author":{"_account_id":38863,"name":"Kubilay Kaptanoglu","display_name":"kkaptanoglu","email":"kkaptanoglu@vmind.com.tr","username":"kkaptanoglu"},"change_message_id":"fb9227ce6d5c172f5afb3936c60503e353c03c8e","unresolved":true,"context_lines":[{"line_number":6,"context_line":""},{"line_number":7,"context_line":"Drop unset values from kolla_toolbox module_args"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"In Ansible, the omit filter only removes top-level module parameters. When used as a value inside nested dictionaries like kolla_toolbox\u0027s module_args, it reaches the invoked module as a literal \u0027omit_place_holder...\u0027 string. Similarly, empty variables (like an empty openstack_cacert) are passed as literal empty strings."},{"line_number":10,"context_line":""},{"line_number":11,"context_line":"This causes unexpected behavior across various modules that expect parameters to be completely absent or None. For example, community.mysql evaluates its TLS parameters against None, treating both the omit placeholder and empty strings as actively set values. This specific case causes PyMySQL to wrongly verify the server certificate against the system trust store, resulting in a CERTIFICATE_VERIFY_FAILED error."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"To solve this globally, module_args are now sanitized inside kolla_toolbox to drop both omit placeholders and empty strings before the playbook is written. This centralized approach fixes the underlying dictionary issue in one place, removing the need to apply workarounds in every role (e.g., for ca_cert). Values that are meaningful while falsy, such as False, 0, or None, are safely preserved and forwarded."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"Closes-Bug: #2161647"},{"line_number":16,"context_line":"Change-Id: If5c1a02f8e6efac4613f4aeb42f1aa422e5043e8"},{"line_number":17,"context_line":"Signed-off-by: kkaptanoglu \u003ckubilay@kaptanoglu.me\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":8,"id":"281a148d_22d353cf","line":14,"range":{"start_line":9,"start_character":0,"end_line":14,"end_character":0},"in_reply_to":"a23b8614_ec698a37","updated":"2026-09-08 12:16:37.000000000","message":"These long texts have been shortened","commit_id":"aa83662e938fa940fd4a3edf6f5ba57876cae516"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":37313,"name":"Alma MAILLET-CONTOZ","display_name":"Alma MAILLET-CONTOZ","email":"alma.maillet-contoz@infomaniak.com","username":"nicolasmc","status":"Intern SRE at Infomaniak"},"change_message_id":"52bf694dc3a2268f4cd82ed730f199e5b47f4062","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"403de5e4_92a5f5a3","updated":"2026-08-17 20:51:02.000000000","message":"`_sanitize_module_args` is a good approach. It\u0027s more sustainable that doing the changes over all the files.\n\nIMO you should only keep that, add more tests on it and drop the fixes in all the roles.","commit_id":"451c181b138e684c3632b1b4a4a198b5625f0640"},{"author":{"_account_id":38863,"name":"Kubilay Kaptanoglu","display_name":"kkaptanoglu","email":"kkaptanoglu@vmind.com.tr","username":"kkaptanoglu"},"change_message_id":"5090c6f7f31a33cef535d26bb33a98fbd31bd5e6","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"9a414f8a_4247f52d","in_reply_to":"403de5e4_92a5f5a3","updated":"2026-08-18 12:25:35.000000000","message":"One additional point I\u0027d like to clarify before proceeding.\n\nThe issue is that when ca_cert is an empty string, the MySQL module still tries to use it and fails during TLS verification:\n\n\nca_cert: \"\"\n\n\n[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate\n\n\nI\u0027m a bit concerned that making _sanitize_module_args skip all empty strings could have broader, project-wide side effects, since kolla_toolbox is used by multiple modules.\n\nWould you prefer us to handle empty strings globally in _sanitize_module_args, or limit the fix specifically to TLS-related parameters such as ca_cert?\n\nI\u0027m leaning towards the narrower approach to keep the blast radius small, but I\u0027m open to your preference.","commit_id":"451c181b138e684c3632b1b4a4a198b5625f0640"},{"author":{"_account_id":38863,"name":"Kubilay Kaptanoglu","display_name":"kkaptanoglu","email":"kkaptanoglu@vmind.com.tr","username":"kkaptanoglu"},"change_message_id":"61720afed2a7dc1a0d1d0be9a1f98cff659b83d1","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"a97523b5_f04e0fce","in_reply_to":"59d4fb8c_6582e18d","updated":"2026-08-20 07:16:17.000000000","message":"Changes applied","commit_id":"451c181b138e684c3632b1b4a4a198b5625f0640"},{"author":{"_account_id":38863,"name":"Kubilay Kaptanoglu","display_name":"kkaptanoglu","email":"kkaptanoglu@vmind.com.tr","username":"kkaptanoglu"},"change_message_id":"2967e341b582ac02067c878c25e3e752d1228f5d","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"59d4fb8c_6582e18d","in_reply_to":"8232aaa9_0558722b","updated":"2026-08-18 12:38:52.000000000","message":"in that case, I will implement the changes within kolla_toolbox and add the necessary tests to cover the relevant cases. I will check and update this page.","commit_id":"451c181b138e684c3632b1b4a4a198b5625f0640"},{"author":{"_account_id":37313,"name":"Alma MAILLET-CONTOZ","display_name":"Alma MAILLET-CONTOZ","email":"alma.maillet-contoz@infomaniak.com","username":"nicolasmc","status":"Intern SRE at Infomaniak"},"change_message_id":"6d103bff778ca11c7c3805ad2ac56727c260be2f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"8232aaa9_0558722b","in_reply_to":"9a414f8a_4247f52d","updated":"2026-08-18 12:34:21.000000000","message":"Well, anyway doing both is useless. And as the problem you raise could happen in another context, it would be better to fix that once and for all imo.\n\nAs for the blast radius, if the function has enough \u0026 good tests, it should be fine c:","commit_id":"451c181b138e684c3632b1b4a4a198b5625f0640"},{"author":{"_account_id":37313,"name":"Alma MAILLET-CONTOZ","display_name":"Alma MAILLET-CONTOZ","email":"alma.maillet-contoz@infomaniak.com","username":"nicolasmc","status":"Intern SRE at Infomaniak"},"change_message_id":"5a38546f422b209c31719c6a08bf3469639c7ad4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b19c4e77_ea59146a","in_reply_to":"a97523b5_f04e0fce","updated":"2026-08-20 09:08:09.000000000","message":"Perfect, thanks!","commit_id":"451c181b138e684c3632b1b4a4a198b5625f0640"},{"author":{"_account_id":37313,"name":"Alma MAILLET-CONTOZ","display_name":"Alma MAILLET-CONTOZ","email":"alma.maillet-contoz@infomaniak.com","username":"nicolasmc","status":"Intern SRE at Infomaniak"},"change_message_id":"5a38546f422b209c31719c6a08bf3469639c7ad4","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":5,"id":"5a21b8b9_de3df310","updated":"2026-08-20 09:08:09.000000000","message":"Could you change the reno to be more global about changing the kolla toolbox ?!","commit_id":"1bd6f2c467020c950ac6eab2874c02dfa3262672"},{"author":{"_account_id":37313,"name":"Alma MAILLET-CONTOZ","display_name":"Alma MAILLET-CONTOZ","email":"alma.maillet-contoz@infomaniak.com","username":"nicolasmc","status":"Intern SRE at Infomaniak"},"change_message_id":"95905100f4af7b9655f589d3cb36792ac9bc899c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"4e357ff6_18e3bbc1","in_reply_to":"5a21b8b9_de3df310","updated":"2026-08-20 10:03:20.000000000","message":"Done","commit_id":"1bd6f2c467020c950ac6eab2874c02dfa3262672"},{"author":{"_account_id":37203,"name":"Bertrand Lanson","display_name":"Bertrand Lanson","email":"bertrand.lanson@infomaniak.com","username":"lanson","status":"Infomaniak Network SA"},"change_message_id":"516ad0cfcd2978cb28e4f210b02ddd4e94a94a37","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"244bf7e0_a55e8451","updated":"2026-09-08 11:25:36.000000000","message":"This LGTM, thaks @alma.maillet-contoz@infomaniak.com for the review !","commit_id":"aa83662e938fa940fd4a3edf6f5ba57876cae516"},{"author":{"_account_id":37203,"name":"Bertrand Lanson","display_name":"Bertrand Lanson","email":"bertrand.lanson@infomaniak.com","username":"lanson","status":"Infomaniak Network SA"},"change_message_id":"b974753249e6efaf6ccfe738a0e73b8bb8958fbb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"b323c991_00ffc05e","updated":"2026-09-09 21:02:19.000000000","message":"LGTM, I think this could be backported aswell","commit_id":"d8458d61333fb1f7a5ffb57f1b98b3ff3d4316bc"}],"tests/test_kolla_toolbox.py":[{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"750e2bc27a80189b4fcff18c1bcbce7217ba9e5f","unresolved":false,"context_lines":[{"line_number":237,"context_line":"        self.assertEqual({\u0027login_user\u0027: \u0027root\u0027}, task_args)"},{"line_number":238,"context_line":""},{"line_number":239,"context_line":"    def test_sanitize_module_args(self):"},{"line_number":240,"context_line":"        module_args \u003d {\u0027login_user\u0027: \u0027root\u0027, \u0027ca_cert\u0027: \u0027\u0027, \u0027client_cert\u0027: None}"},{"line_number":241,"context_line":"        sanitized_args \u003d kolla_toolbox._sanitize_module_args(module_args)"},{"line_number":242,"context_line":"        self.assertEqual({\u0027login_user\u0027: \u0027root\u0027, \u0027client_cert\u0027: None},"},{"line_number":243,"context_line":"                         sanitized_args)"}],"source_content_type":"text/x-python","patch_set":4,"id":"d542efb3_f2724ef5","line":240,"updated":"2026-08-19 10:41:52.000000000","message":"linters: E501 line too long (80 \u003e 79 characters)","commit_id":"f7ae031369752c678bffaa3d2068e28457876a7e"},{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"750e2bc27a80189b4fcff18c1bcbce7217ba9e5f","unresolved":false,"context_lines":[{"line_number":237,"context_line":"        self.assertEqual({\u0027login_user\u0027: \u0027root\u0027}, task_args)"},{"line_number":238,"context_line":""},{"line_number":239,"context_line":"    def test_sanitize_module_args(self):"},{"line_number":240,"context_line":"        module_args \u003d {\u0027login_user\u0027: \u0027root\u0027, \u0027ca_cert\u0027: \u0027\u0027, \u0027client_cert\u0027: None}"},{"line_number":241,"context_line":"        sanitized_args \u003d kolla_toolbox._sanitize_module_args(module_args)"},{"line_number":242,"context_line":"        self.assertEqual({\u0027login_user\u0027: \u0027root\u0027, \u0027client_cert\u0027: None},"},{"line_number":243,"context_line":"                         sanitized_args)"}],"source_content_type":"text/x-python","patch_set":4,"id":"19113374_c737d874","line":240,"updated":"2026-08-19 10:41:52.000000000","message":"pep8: E501 line too long (80 \u003e 79 characters)","commit_id":"f7ae031369752c678bffaa3d2068e28457876a7e"}]}
