)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":21,"context_line":""},{"line_number":22,"context_line":"Also adds WEKAFS to SUPPORTED_SHARE_PROTOCOLS in constants.py, RST"},{"line_number":23,"context_line":"admin documentation, and updates the share backends feature support"},{"line_number":24,"context_line":"mapping."},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Implements: blueprint weka-share-driver"},{"line_number":27,"context_line":"Change-Id: Ic3f85449009b3a15a1219a01b8b4217132b41899"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":7,"id":"fb38e19b_eacb4be1","line":24,"updated":"2026-06-17 23:14:17.000000000","message":"Could you please add a release note: https://docs.openstack.org/manila/latest/contributor/adding_release_notes.html","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":21,"context_line":""},{"line_number":22,"context_line":"Also adds WEKAFS to SUPPORTED_SHARE_PROTOCOLS in constants.py, RST"},{"line_number":23,"context_line":"admin documentation, and updates the share backends feature support"},{"line_number":24,"context_line":"mapping."},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"Implements: blueprint weka-share-driver"},{"line_number":27,"context_line":"Change-Id: Ic3f85449009b3a15a1219a01b8b4217132b41899"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":7,"id":"77772bf4_d3231f8e","line":24,"in_reply_to":"fb38e19b_eacb4be1","updated":"2026-06-22 11:44:28.000000000","message":"Added a release note in PS8 (releasenotes/notes/add-weka-share-driver-*.yaml).","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":36686,"name":"Inyong Hong","display_name":"hongp","email":"inyong.hong@samsung.com","username":"hong-p"},"change_message_id":"a36c42e0b3cab890184971ad85e65af2f3a4c0e5","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":5,"id":"79d3924f_735004c7","updated":"2026-05-31 21:37:18.000000000","message":"Hi, We are very excited to see a Weka driver being contributed to Manila. We had actually reached out to Weka via email previously, and in the meantime we implemented our own Weka driver on a hard fork of Manila which we are currently running in production. We have a few questions and would appreciate your feedback.\n\nThe driver uses a single globally-configured weka_organization (defaulting to Root) for all share operations, which means there is no per-project organizational isolation at the Weka level.\n\nIn our experience implementing a Weka driver internally, we found this to be a serious security concern: \nsince all filesystems across all OpenStack projects live in the same Weka organization, all clients must use the same mount account and password regardless of which project they belong to. This means there is no organizational boundary between projects at the Weka level a client from project A and a client from project B are indistinguishable from Weka\u0027s perspective.\n\nWe addressed this by implementing share server support, mapping each Manila share server to a dedicated Weka organization — so each OpenStack project gets its own org context and mount account, and access is scoped accordingly.\n\nIs this single-org approach intentional, and do you consider it secure for multi-tenant deployments? We would appreciate your thoughts on whether our per-project org isolation approach would be a better direction.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"608e1ee25a95ec98251ffb74c87e6e1fd5d970a8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"9f6dcab4_be30fb67","updated":"2026-06-02 14:20:12.000000000","message":"Just started the review. Will incrementally review it. Had some initial comments below. Please take a look.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5cfd70406b1f8bada666dc197d0d315002190dfc","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":5,"id":"a053d8dc_04181e00","in_reply_to":"79d3924f_735004c7","updated":"2026-06-16 09:42:04.000000000","message":"Thanks for the detailed feedback, and for sharing your production experience — this is really useful. You\u0027re right: the driver uses a single configured weka_organization (default: Root) with driver_handles_share_servers\u003dFalse, so there\u0027s no per-project org boundary at the Weka level. \nThat\u0027s an intentional scope choice for this initial driver. We agree per-project Weka-org isolation via share-server support (DHSS\u003dTrue — one org + mount account per share server) is the stronger multi-tenant model, and it\u0027s a natural follow-up.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"0a4a63fd07da6b7de1ed48ee0f6834de028da52c","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":5,"id":"e12e2bc1_06f87de4","in_reply_to":"a053d8dc_04181e00","updated":"2026-06-22 11:44:26.000000000","message":"Following up: the single-org / DHSS\u003dfalse model is the intended initial scope. Per-project Weka-org isolation via share-server support is planned as a follow-up change. Thanks again for the production input.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f446506a7ed699cc3a04d935c02373db6eb2a4a6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"e3061231_f6ccdbe8","in_reply_to":"e12e2bc1_06f87de4","updated":"2026-07-03 13:26:25.000000000","message":"Marking resolved — tracked as a roadmap follow-up (per-project Weka-org isolation / DHSS\u003dtrue).","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39155,"name":"Itai Weisman","display_name":"Itai Weisman","email":"itai.weisman@weka.io","username":"itaiweismanweka"},"change_message_id":"dedf297e3ff6d3f76ce67277a0e044e4f042c9d9","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":6,"id":"7e1becb4_5788e611","updated":"2026-06-16 13:30:00.000000000","message":"Thank you Anoop and hongp for the review feedback. PS6 addresses the code-level items:\n\npool_connections and pool_maxsize are now configurable\nAdded inline comment in client.py linking _DEFAULT_TIMEOUT/_DEFAULT_RETRIES to the weka_api_timeout/weka_max_api_retries config options\nWEKAFS access control: IP-based security policies are on the roadmap as a follow-up patch\n\nHappy to answer any follow-up questions.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39155,"name":"Itai Weisman","display_name":"Itai Weisman","email":"itai.weisman@weka.io","username":"itaiweismanweka"},"change_message_id":"b025247ab626712c8f03d67ebc87e33fb1959def","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":6,"id":"e67825d1_5385a804","updated":"2026-06-16 13:31:02.000000000","message":"run-weka-ci","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"b9a625be2009025277cabfcbd634280fcf0ee697","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"fc045000_a018bc9b","in_reply_to":"7e1becb4_5788e611","updated":"2026-07-03 13:26:36.000000000","message":"Marking resolved — superseded by the later patchset summaries.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"b9a625be2009025277cabfcbd634280fcf0ee697","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"1326cfd1_0503ff4f","in_reply_to":"e67825d1_5385a804","updated":"2026-07-03 13:26:36.000000000","message":"Marking resolved — CI trigger comment, no longer needed.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"b7d13106_889f482d","updated":"2026-06-17 23:14:17.000000000","message":"Thanks for working on this. The CI results must be accessible to the community, please ensure that they\u0027re uploaded to a publicly accessible location. I\u0027ve several comments inline","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"b1e12030_d5a0c1b9","in_reply_to":"b7d13106_889f482d","updated":"2026-06-22 11:44:28.000000000","message":"The Weka third-party CI is now live (comment-triggered via \"run-weka-ci\"); results post to the review.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"272d86688d3d8c1af0196fca7b23f94b78173575","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"bddbac05_6d932206","updated":"2026-06-25 08:18:32.000000000","message":"Am still reviewing; found a couple of issues. The eventlet usage is a hard blocker unfortunately.. let me know if you\u0027d like any clarifications..","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39155,"name":"Itai Weisman","display_name":"Itai Weisman","email":"itai.weisman@weka.io","username":"itaiweismanweka"},"change_message_id":"796eed918198d58e70382152982a577b4511af43","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":11,"id":"30978b24_c127b40c","updated":"2026-06-23 05:16:16.000000000","message":"Hi Goutham, PS11 addresses all the feedback from your Code-Review -1. In summary:\n\nAdded a release note\nReplaced ensure_share with ensure_shares + get_backend_info\nReplaced root_helper\u003d\u0027sudo\u0027 with rootwrap-compatible run_as_root\u003dTrue\ncreate_share_from_snapshot now returns creating_from_snapshot status for async completion\ncreate_share returns proper dict format with status and export_locations\nRemoved dead code from client.py\nFixed install docs, index.rst placement, IPv6 rejection, reserved_percentage from config, manage_existing NFS cleanup, tempfile.mkdtemp(), and all the other items\nCI is green (Verified +1)\n\nThe 5 remaining open threads all have responses from us. Could you please take another look when you get a chance?","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":10910,"name":"Stig Telfer","email":"stig.openstack@telfer.org","username":"stigtelfer"},"change_message_id":"f253a1291b94050df9f9306cf4e51a57ef5cbbe9","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":11,"id":"a8ea454d_eb3879c7","updated":"2026-06-24 20:03:25.000000000","message":"Improved multi-tenancy support could perhaps be achievable with this relatively minor modification.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"882edb779e0beae1b061c6e98aa7b03e8cb9dd5c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"adeefa55_ab0f842d","in_reply_to":"30978b24_c127b40c","updated":"2026-07-03 13:26:43.000000000","message":"Marking resolved — superseded by the PS12 summary.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"882edb779e0beae1b061c6e98aa7b03e8cb9dd5c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"b97d158a_19e44a6a","in_reply_to":"41e62df8_bf068752","updated":"2026-07-03 13:26:43.000000000","message":"Marking resolved — tracked as a roadmap follow-up (multi-tenancy via share-type extra_specs override).","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f9a5fb54eefb6309fa69b34e5658b3b30bcf17a6","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":11,"id":"41e62df8_bf068752","in_reply_to":"a8ea454d_eb3879c7","updated":"2026-07-03 07:04:54.000000000","message":"Agreed the extra_specs-override approach is a relatively contained way to enable multi-tenancy; planned as a follow-up. Keeping this initial change scoped to single-org / DHSS\u003dfalse.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39155,"name":"Itai Weisman","display_name":"Itai Weisman","email":"itai.weisman@weka.io","username":"itaiweismanweka"},"change_message_id":"58cfb7ed884513e58e974e9a9fe8bc6dfab6532a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"201e88ac_564ef824","updated":"2026-07-22 08:17:44.000000000","message":"Friendly reminder: the July 30 new-driver deadline is 8 days away. PS12 is ready for review — all PS11 feedback addressed, Weka CI green, 0 unresolved comments. Pinging gouthamr and carloss for a re-review.","commit_id":"4138f8ce7cc6bf17270c3c0d6883707fbd1594c1"},{"author":{"_account_id":39155,"name":"Itai Weisman","display_name":"Itai Weisman","email":"itai.weisman@weka.io","username":"itaiweismanweka"},"change_message_id":"49e77d53d87c162f06bea0359cd3b091cb564d8f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":12,"id":"bbc8db29_dad2af85","updated":"2026-07-03 08:12:53.000000000","message":"PS12 is up addressing all PS11 feedback:\n\nReplaced import eventlet with native Python threads (following change 973519 as suggested by gouthamr in the Jun 25 meeting)\nFixed import order in manila/privsep/weka.py\nFixed alphabetical ordering in doc/source/admin/index.rst\ncreate_share_from_snapshot now returns \u0027error\u0027 if status is lost mid-copy\nAll remaining open comments left for reviewers to resolve (no code change needed)\n\nWeka CI is green on PS12 (903 tests, 0 failures). Would appreciate a re-review from gouthamr and Stig when you get a chance. We\u0027re tracking toward the July 30 new-driver deadline.","commit_id":"4138f8ce7cc6bf17270c3c0d6883707fbd1594c1"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"3c370ebabe7aca7172a0c65b4291667d8171ff5f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"302ec3fe_8b0815ce","in_reply_to":"bbc8db29_dad2af85","updated":"2026-07-03 13:26:48.000000000","message":"Marking resolved — all review items through PS12 are addressed.","commit_id":"4138f8ce7cc6bf17270c3c0d6883707fbd1594c1"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"8a9e2d835dc36e43c60c1a7c3d7c615f222ed1e2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":14,"id":"84162eab_8e4ef003","updated":"2026-08-04 04:56:20.000000000","message":"\u003e @gouthamr when you get a chance, I\u0027d appreciate your steer on the two questions above (keeping test_list_access_rules green while returning access_key for ip/user rules, and per-project vs per-rule credential mapping) so I can rework the delivery. Thanks!\n\nDon\u0027t you need a patch to the manila-tempest-plugin to include WEKAFS as a protocol? \n\nI\u0027m doing that for LUSTRE here: https://review.opendev.org/c/openstack/manila-tempest-plugin/+/996908\n\nWith such a patch, you can make sure that the test recognizes that \"access_key\" is set for both CEPHFS and WEKAFS","commit_id":"246f8e920b4d3494237e55a2dec3e08ebb3f25da"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"c213c39b21716396b4de745ce06f3c93d7b83533","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":14,"id":"1b950999_627ccc97","updated":"2026-08-02 23:18:54.000000000","message":"I haven\u0027t read through changes yet, but this caught my attention:\n\n\u003e Idiomatic mount-credential delivery: WEKAFS access rules now return no\n  access_key (upstream reserves access_key for cephx). The per-project\n  mount credential is surfaced in the share’s export-location metadata as\n  weka_mount_password (self-service, no operator hand-off).\n\n\nManila doesn\u0027t set \"access_key\" only for CephX access type. This field can be set for any access type. I find access secrets in share export location metadata problematic - this information is readily available to all OpenStack users that can enumerate share export locations. That would be inappropriate for a secret?\n\nWith \"access_key\", we have a feature where the visibility of this field can be controlled by the user creating the access rule.","commit_id":"246f8e920b4d3494237e55a2dec3e08ebb3f25da"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e8746ace3092d6d056f30db5975446a474bb236e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":16,"id":"ccee094f_51e750b5","updated":"2026-08-13 03:07:08.000000000","message":"@assaf@weka.io @itai.weisman@weka.io: Can you reduce the LLM bloat in this change?","commit_id":"e87c9b40104583f1bc444a3d502c8b19d1001528"}],"doc/source/admin/index.rst":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":64,"context_line":"   shared-file-systems-share-server-migration.rst"},{"line_number":65,"context_line":"   share_mount_point_name.rst"},{"line_number":66,"context_line":"   share_back_ends_feature_support_mapping"},{"line_number":67,"context_line":"   weka_share_driver"},{"line_number":68,"context_line":"   capabilities_and_extra_specs"},{"line_number":69,"context_line":"   group_capabilities_and_extra_specs"},{"line_number":70,"context_line":"   export_location_metadata"}],"source_content_type":"text/x-rst","patch_set":7,"id":"9a93787a_be84b886","line":67,"range":{"start_line":67,"start_character":0,"end_line":67,"end_character":20},"updated":"2026-06-17 23:14:17.000000000","message":"this should go into the \"Supported share back ends\" list below","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":64,"context_line":"   shared-file-systems-share-server-migration.rst"},{"line_number":65,"context_line":"   share_mount_point_name.rst"},{"line_number":66,"context_line":"   share_back_ends_feature_support_mapping"},{"line_number":67,"context_line":"   weka_share_driver"},{"line_number":68,"context_line":"   capabilities_and_extra_specs"},{"line_number":69,"context_line":"   group_capabilities_and_extra_specs"},{"line_number":70,"context_line":"   export_location_metadata"}],"source_content_type":"text/x-rst","patch_set":7,"id":"89e8c210_7b7fe6ba","line":67,"in_reply_to":"9a93787a_be84b886","updated":"2026-06-22 11:44:28.000000000","message":"Done in PS8 — moved into the \"Supported share back ends\" toctree.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"272d86688d3d8c1af0196fca7b23f94b78173575","unresolved":true,"context_lines":[{"line_number":112,"context_line":"   ../configuration/shared-file-systems/drivers/windows-smb-driver"},{"line_number":113,"context_line":"   zadara_driver"},{"line_number":114,"context_line":"   ../configuration/shared-file-systems/drivers/vastdata_driver"},{"line_number":115,"context_line":"   weka_share_driver"},{"line_number":116,"context_line":""}],"source_content_type":"text/x-rst","patch_set":11,"id":"88298d7b_f8c278c4","line":115,"updated":"2026-06-25 08:18:32.000000000","message":"alphabetical order please","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f9a5fb54eefb6309fa69b34e5658b3b30bcf17a6","unresolved":false,"context_lines":[{"line_number":112,"context_line":"   ../configuration/shared-file-systems/drivers/windows-smb-driver"},{"line_number":113,"context_line":"   zadara_driver"},{"line_number":114,"context_line":"   ../configuration/shared-file-systems/drivers/vastdata_driver"},{"line_number":115,"context_line":"   weka_share_driver"},{"line_number":116,"context_line":""}],"source_content_type":"text/x-rst","patch_set":11,"id":"ac396c7f_55d6d93d","line":115,"in_reply_to":"88298d7b_f8c278c4","updated":"2026-07-03 07:04:54.000000000","message":"Fixed in PS12: weka_share_driver moved to its alphabetical position in the toctree.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"}],"doc/source/admin/share_back_ends_feature_support_mapping.rst":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e8746ace3092d6d056f30db5975446a474bb236e","unresolved":false,"context_lines":[{"line_number":107,"context_line":"+----------------------------------------+-----------------------+-----------------------+--------------------------+--------------------------+------------------------+-----------------------------------+--------------------------+--------------------+--------------------+"},{"line_number":108,"context_line":"|              Vastdata                  |           D           |          \\-           |             D            |             D            |            D           |                \\-                 |            \\-            |           \\-       |          \\-        |"},{"line_number":109,"context_line":"+----------------------------------------+-----------------------+-----------------------+--------------------------+--------------------------+------------------------+-----------------------------------+--------------------------+--------------------+--------------------+"},{"line_number":110,"context_line":"|                  Weka                  |        2026.2         |        2026.2         |          2026.2          |          2026.2          |         2026.2         |              2026.2               |            \\-            |       2026.2       |          \\-        |"},{"line_number":111,"context_line":"+----------------------------------------+-----------------------+-----------------------+--------------------------+--------------------------+------------------------+-----------------------------------+--------------------------+--------------------+--------------------+"},{"line_number":112,"context_line":""},{"line_number":113,"context_line":"Mapping of share drivers and share access rules support"}],"source_content_type":"text/x-rst","patch_set":15,"id":"e57a3c17_6af6a90c","line":110,"range":{"start_line":110,"start_character":100,"end_line":110,"end_character":106},"updated":"2026-08-13 03:07:08.000000000","message":"this is inconsistent... we\u0027ve been using release lettering. But, I don\u0027t think that\u0027s going well either. I think we can just convert these into tick marks; and drop noting when something was introduced. Since this is in the admin guide that\u0027s versioned, people won\u0027t have trouble finding out.\n\nNothing for you to change, imo; something for me/manila maintainers to fix up","commit_id":"edc2a4d6d18cd31f020286bef66abe2bb2a22059"}],"doc/source/admin/weka_share_driver.rst":[{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"608e1ee25a95ec98251ffb74c87e6e1fd5d970a8","unresolved":true,"context_lines":[{"line_number":55,"context_line":"Supported Operations"},{"line_number":56,"context_line":"--------------------"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"* Create and delete shares"},{"line_number":59,"context_line":"* Extend and shrink shares"},{"line_number":60,"context_line":"* Ensure shares (re-mount on service restart)"},{"line_number":61,"context_line":"* Create, delete, and revert-to snapshots"}],"source_content_type":"text/x-rst","patch_set":5,"id":"d2be49a0_26671723","line":58,"range":{"start_line":58,"start_character":2,"end_line":58,"end_character":26},"updated":"2026-06-02 14:20:12.000000000","message":"I did not see some additional properties of shares mentioned in the spec or the code changes - eg. thick vs thin (space allocated), quality of service etc. Are these defaulted by the file system and do not require to be mentioned?","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"0a4a63fd07da6b7de1ed48ee0f6834de028da52c","unresolved":false,"context_lines":[{"line_number":55,"context_line":"Supported Operations"},{"line_number":56,"context_line":"--------------------"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"* Create and delete shares"},{"line_number":59,"context_line":"* Extend and shrink shares"},{"line_number":60,"context_line":"* Ensure shares (re-mount on service restart)"},{"line_number":61,"context_line":"* Create, delete, and revert-to snapshots"}],"source_content_type":"text/x-rst","patch_set":5,"id":"b38993ac_a711c5a2","line":58,"in_reply_to":"6f338009_fc06fbc0","updated":"2026-06-22 11:44:26.000000000","message":"PS8: added a provisioning note to weka_share_driver.rst — shares are thick-provisioned today; thin provisioning and QoS are planned via share-type extra specs.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5cfd70406b1f8bada666dc197d0d315002190dfc","unresolved":true,"context_lines":[{"line_number":55,"context_line":"Supported Operations"},{"line_number":56,"context_line":"--------------------"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"* Create and delete shares"},{"line_number":59,"context_line":"* Extend and shrink shares"},{"line_number":60,"context_line":"* Ensure shares (re-mount on service restart)"},{"line_number":61,"context_line":"* Create, delete, and revert-to snapshots"}],"source_content_type":"text/x-rst","patch_set":5,"id":"e3b9bb7c_a7d6516a","line":58,"range":{"start_line":58,"start_character":2,"end_line":58,"end_character":26},"in_reply_to":"d2be49a0_26671723","updated":"2026-06-16 09:42:04.000000000","message":"Currently the driver creates a standard (thick) filesystems, we plan to support later also thin provisioning via share type extra spec.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"faebba3115c42e55f17f7d58fa4630142a4527a5","unresolved":true,"context_lines":[{"line_number":55,"context_line":"Supported Operations"},{"line_number":56,"context_line":"--------------------"},{"line_number":57,"context_line":""},{"line_number":58,"context_line":"* Create and delete shares"},{"line_number":59,"context_line":"* Extend and shrink shares"},{"line_number":60,"context_line":"* Ensure shares (re-mount on service restart)"},{"line_number":61,"context_line":"* Create, delete, and revert-to snapshots"}],"source_content_type":"text/x-rst","patch_set":5,"id":"6f338009_fc06fbc0","line":58,"range":{"start_line":58,"start_character":2,"end_line":58,"end_character":26},"in_reply_to":"e3b9bb7c_a7d6516a","updated":"2026-06-19 05:15:38.000000000","message":"Do we want to mention this in the doc?","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":41,"context_line":"-------------"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"* **Weka cluster** version 5.0 or later (tested against 5.1.x)."},{"line_number":44,"context_line":"* **OpenStack Manila** 2023.1 (Antelope) or later."},{"line_number":45,"context_line":"* Network connectivity from the Manila host to the Weka cluster on TCP"},{"line_number":46,"context_line":"  port **14000** (REST API)."},{"line_number":47,"context_line":"* For WEKAFS protocol shares only: the WekaFS client package must be"}],"source_content_type":"text/x-rst","patch_set":6,"id":"958907af_734eb108","line":44,"range":{"start_line":44,"start_character":0,"end_line":44,"end_character":50},"updated":"2026-06-17 23:14:17.000000000","message":"You\u0027ll need to clarify if this was an out of tree driver prior to Hibiscus, or just drop this note. It\u0027s usually read in current context.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"ef5aa22b744161fd63c5d952f19966e372b5faee","unresolved":false,"context_lines":[{"line_number":41,"context_line":"-------------"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"* **Weka cluster** version 5.0 or later (tested against 5.1.x)."},{"line_number":44,"context_line":"* **OpenStack Manila** 2023.1 (Antelope) or later."},{"line_number":45,"context_line":"* Network connectivity from the Manila host to the Weka cluster on TCP"},{"line_number":46,"context_line":"  port **14000** (REST API)."},{"line_number":47,"context_line":"* For WEKAFS protocol shares only: the WekaFS client package must be"}],"source_content_type":"text/x-rst","patch_set":6,"id":"b3434829_e63601f8","line":44,"in_reply_to":"958907af_734eb108","updated":"2026-06-22 11:44:27.000000000","message":"PS8: removed the out-of-tree install/symlink section and the GitHub link; the doc now reads in in-tree context.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":91,"context_line":"Configuration"},{"line_number":92,"context_line":"-------------"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":"Install Driver"},{"line_number":95,"context_line":"~~~~~~~~~~~~~~"},{"line_number":96,"context_line":""},{"line_number":97,"context_line":"Clone the driver repository and symlink it into Manila\u0027s source tree:"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":".. code-block:: console"},{"line_number":100,"context_line":""},{"line_number":101,"context_line":"   $ git clone https://github.com/weka/manila-weka-driver.git \\"},{"line_number":102,"context_line":"         /opt/manila-weka-driver"},{"line_number":103,"context_line":"   $ ln -s /opt/manila-weka-driver/manila/share/drivers/weka \\"},{"line_number":104,"context_line":"         /path/to/manila/manila/share/drivers/weka"},{"line_number":105,"context_line":""},{"line_number":106,"context_line":"Install WekaFS Kernel Module (WEKAFS protocol only)"},{"line_number":107,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":6,"id":"c527d4d4_52a2566a","line":104,"range":{"start_line":94,"start_character":0,"end_line":104,"end_character":50},"updated":"2026-06-17 23:14:17.000000000","message":"not accurate for this intree driver.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"ef5aa22b744161fd63c5d952f19966e372b5faee","unresolved":false,"context_lines":[{"line_number":101,"context_line":"   $ git clone https://github.com/weka/manila-weka-driver.git \\"},{"line_number":102,"context_line":"         /opt/manila-weka-driver"},{"line_number":103,"context_line":"   $ ln -s /opt/manila-weka-driver/manila/share/drivers/weka \\"},{"line_number":104,"context_line":"         /path/to/manila/manila/share/drivers/weka"},{"line_number":105,"context_line":""},{"line_number":106,"context_line":"Install WekaFS Kernel Module (WEKAFS protocol only)"},{"line_number":107,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":6,"id":"28740fa1_f3df99a8","line":104,"in_reply_to":"c527d4d4_52a2566a","updated":"2026-06-22 11:44:27.000000000","message":"PS8: removed the clone/symlink \"Install Driver\" section — the driver ships with Manila in-tree.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":132,"context_line":"   share_driver \u003d manila.share.drivers.weka.driver.WekaShareDriver"},{"line_number":133,"context_line":"   share_backend_name \u003d weka"},{"line_number":134,"context_line":"   driver_handles_share_servers \u003d false"},{"line_number":135,"context_line":"   snapshot_support \u003d true"},{"line_number":136,"context_line":"   create_share_from_snapshot_support \u003d true"},{"line_number":137,"context_line":"   revert_to_snapshot_support \u003d true"},{"line_number":138,"context_line":""},{"line_number":139,"context_line":"   # Connection"},{"line_number":140,"context_line":"   weka_api_server      \u003d weka-cluster.example.com"}],"source_content_type":"text/x-rst","patch_set":6,"id":"2e4e5463_deb542b4","line":137,"range":{"start_line":135,"start_character":0,"end_line":137,"end_character":36},"updated":"2026-06-17 23:14:17.000000000","message":"These are config opts? Why would you allow administrators to control these via configuration? These are already optional features via share type extra specs, defauting to False.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"ef5aa22b744161fd63c5d952f19966e372b5faee","unresolved":false,"context_lines":[{"line_number":134,"context_line":"   driver_handles_share_servers \u003d false"},{"line_number":135,"context_line":"   snapshot_support \u003d true"},{"line_number":136,"context_line":"   create_share_from_snapshot_support \u003d true"},{"line_number":137,"context_line":"   revert_to_snapshot_support \u003d true"},{"line_number":138,"context_line":""},{"line_number":139,"context_line":"   # Connection"},{"line_number":140,"context_line":"   weka_api_server      \u003d weka-cluster.example.com"}],"source_content_type":"text/x-rst","patch_set":6,"id":"79616c1c_9c8a4fee","line":137,"in_reply_to":"2e4e5463_deb542b4","updated":"2026-06-22 11:44:27.000000000","message":"PS8: removed snapshot_support/create_share_from_snapshot_support/revert_to_snapshot_support from the manila.conf example — they are reported capabilities, not operator config opts.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":233,"context_line":""},{"line_number":234,"context_line":"* WEKAFS shares do not support Manila access rules.  All"},{"line_number":235,"context_line":"  ``share access create`` operations on WEKAFS shares return ``error``"},{"line_number":236,"context_line":"  state.  Manage access at the network layer or via Weka cluster user"},{"line_number":237,"context_line":"  management."},{"line_number":238,"context_line":"* ``create_share_from_snapshot`` copies data via an NFS-based ``rsync``."},{"line_number":239,"context_line":"  Copy time scales linearly with snapshot size."},{"line_number":240,"context_line":"* The WekaFS kernel module is incompatible with Linux kernel 6.17 or"}],"source_content_type":"text/x-rst","patch_set":6,"id":"61f54ac6_b9d0800e","line":237,"range":{"start_line":236,"start_character":52,"end_line":237,"end_character":13},"updated":"2026-06-17 23:14:17.000000000","message":"Is this not something that can be controlled via the driver?","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"ef5aa22b744161fd63c5d952f19966e372b5faee","unresolved":true,"context_lines":[{"line_number":234,"context_line":"* WEKAFS shares do not support Manila access rules.  All"},{"line_number":235,"context_line":"  ``share access create`` operations on WEKAFS shares return ``error``"},{"line_number":236,"context_line":"  state.  Manage access at the network layer or via Weka cluster user"},{"line_number":237,"context_line":"  management."},{"line_number":238,"context_line":"* ``create_share_from_snapshot`` copies data via an NFS-based ``rsync``."},{"line_number":239,"context_line":"  Copy time scales linearly with snapshot size."},{"line_number":240,"context_line":"* The WekaFS kernel module is incompatible with Linux kernel 6.17 or"}],"source_content_type":"text/x-rst","patch_set":6,"id":"66d1d827_2cc89140","line":237,"in_reply_to":"61f54ac6_b9d0800e","updated":"2026-06-22 11:44:27.000000000","message":"WEKAFS access enforcement via IP-based security policies is planned as a follow-up; the doc now states rules are accepted as a no-op. Tracking separately.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"b9a625be2009025277cabfcbd634280fcf0ee697","unresolved":false,"context_lines":[{"line_number":234,"context_line":"* WEKAFS shares do not support Manila access rules.  All"},{"line_number":235,"context_line":"  ``share access create`` operations on WEKAFS shares return ``error``"},{"line_number":236,"context_line":"  state.  Manage access at the network layer or via Weka cluster user"},{"line_number":237,"context_line":"  management."},{"line_number":238,"context_line":"* ``create_share_from_snapshot`` copies data via an NFS-based ``rsync``."},{"line_number":239,"context_line":"  Copy time scales linearly with snapshot size."},{"line_number":240,"context_line":"* The WekaFS kernel module is incompatible with Linux kernel 6.17 or"}],"source_content_type":"text/x-rst","patch_set":6,"id":"6783fcc0_57cecd99","line":237,"in_reply_to":"66d1d827_2cc89140","updated":"2026-07-03 13:26:36.000000000","message":"Marking resolved — tracked as a roadmap follow-up (WEKAFS IP-based access enforcement).","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":10910,"name":"Stig Telfer","email":"stig.openstack@telfer.org","username":"stigtelfer"},"change_message_id":"f253a1291b94050df9f9306cf4e51a57ef5cbbe9","unresolved":true,"context_lines":[{"line_number":122,"context_line":"   driver_handles_share_servers \u003d false"},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"   # Connection"},{"line_number":125,"context_line":"   weka_api_server      \u003d weka-cluster.example.com"},{"line_number":126,"context_line":"   weka_api_port        \u003d 14000"},{"line_number":127,"context_line":"   weka_ssl_verify      \u003d true"},{"line_number":128,"context_line":""}],"source_content_type":"text/x-rst","patch_set":11,"id":"a59f220a_ce54372f","line":125,"updated":"2026-06-24 20:03:25.000000000","message":"Multi-tenancy would be enabled if we could treat `weka_api_server` in the same way as `vast_vippool_name` in this review: https://review.opendev.org/c/openstack/manila/+/963494 - if a share type could be created with an extra_specs override value for weka_api_server, that could be mapped to a Weka network space (and associated tenancy) on Weka.  Creation of the Weka tenancy and network space would be out of scope for this driver.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f9a5fb54eefb6309fa69b34e5658b3b30bcf17a6","unresolved":true,"context_lines":[{"line_number":122,"context_line":"   driver_handles_share_servers \u003d false"},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"   # Connection"},{"line_number":125,"context_line":"   weka_api_server      \u003d weka-cluster.example.com"},{"line_number":126,"context_line":"   weka_api_port        \u003d 14000"},{"line_number":127,"context_line":"   weka_ssl_verify      \u003d true"},{"line_number":128,"context_line":""}],"source_content_type":"text/x-rst","patch_set":11,"id":"fcb996e2_4df9927e","line":125,"in_reply_to":"a59f220a_ce54372f","updated":"2026-07-03 07:04:54.000000000","message":"Thanks Stig — treating weka_api_server as a share-type extra_specs override (mapping to a Weka network space / tenancy, like vast_vippool_name in 963494) is a good direction. This is planned as a follow-up change; the initial scope here is the single-org / DHSS\u003dfalse model. Tracking separately.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"882edb779e0beae1b061c6e98aa7b03e8cb9dd5c","unresolved":false,"context_lines":[{"line_number":122,"context_line":"   driver_handles_share_servers \u003d false"},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"   # Connection"},{"line_number":125,"context_line":"   weka_api_server      \u003d weka-cluster.example.com"},{"line_number":126,"context_line":"   weka_api_port        \u003d 14000"},{"line_number":127,"context_line":"   weka_ssl_verify      \u003d true"},{"line_number":128,"context_line":""}],"source_content_type":"text/x-rst","patch_set":11,"id":"2a5df200_9da8bb74","line":125,"in_reply_to":"fcb996e2_4df9927e","updated":"2026-07-03 13:26:43.000000000","message":"Marking resolved — tracked as a roadmap follow-up (weka_api_server as a share-type extra_specs override).","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"}],"manila/common/constants.py":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":164,"context_line":""},{"line_number":165,"context_line":"SUPPORTED_SHARE_PROTOCOLS \u003d ("},{"line_number":166,"context_line":"    \u0027NFS\u0027, \u0027CIFS\u0027, \u0027GLUSTERFS\u0027, \u0027HDFS\u0027, \u0027CEPHFS\u0027, \u0027MAPRFS\u0027, \u0027WEKAFS\u0027)"},{"line_number":167,"context_line":""},{"line_number":168,"context_line":""},{"line_number":169,"context_line":"SECURITY_SERVICES_ALLOWED_TYPES \u003d [\u0027active_directory\u0027, \u0027ldap\u0027, \u0027kerberos\u0027]"},{"line_number":170,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"37e04b04_c8f2792d","line":167,"updated":"2026-06-17 23:14:17.000000000","message":"drop unnecessary blank line","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"9e17bd5d7fc3aa407949023b2e1078da420117ea","unresolved":false,"context_lines":[{"line_number":164,"context_line":""},{"line_number":165,"context_line":"SUPPORTED_SHARE_PROTOCOLS \u003d ("},{"line_number":166,"context_line":"    \u0027NFS\u0027, \u0027CIFS\u0027, \u0027GLUSTERFS\u0027, \u0027HDFS\u0027, \u0027CEPHFS\u0027, \u0027MAPRFS\u0027, \u0027WEKAFS\u0027)"},{"line_number":167,"context_line":""},{"line_number":168,"context_line":""},{"line_number":169,"context_line":"SECURITY_SERVICES_ALLOWED_TYPES \u003d [\u0027active_directory\u0027, \u0027ldap\u0027, \u0027kerberos\u0027]"},{"line_number":170,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"98c4d182_72962d7e","line":167,"in_reply_to":"37e04b04_c8f2792d","updated":"2026-06-22 11:44:04.000000000","message":"Done in PS8.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"}],"manila/privsep/weka.py":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"272d86688d3d8c1af0196fca7b23f94b78173575","unresolved":true,"context_lines":[{"line_number":29,"context_line":"    weka_privsep.rsync(src, dst)"},{"line_number":30,"context_line":"\"\"\""},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"import manila.privsep"},{"line_number":33,"context_line":"from oslo_concurrency import processutils"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"@manila.privsep.sys_admin_pctxt.entrypoint"}],"source_content_type":"text/x-python","patch_set":11,"id":"3b27b4cb_80c4280b","line":33,"range":{"start_line":32,"start_character":0,"end_line":33,"end_character":41},"updated":"2026-06-25 08:18:32.000000000","message":"Please follow the import order template:\n\nhttps://docs.openstack.org/hacking/latest/user/hacking.html#import-order-template","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f9a5fb54eefb6309fa69b34e5658b3b30bcf17a6","unresolved":false,"context_lines":[{"line_number":30,"context_line":"\"\"\""},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"import manila.privsep"},{"line_number":33,"context_line":"from oslo_concurrency import processutils"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":""},{"line_number":36,"context_line":"@manila.privsep.sys_admin_pctxt.entrypoint"}],"source_content_type":"text/x-python","patch_set":11,"id":"65a900fa_f4ee27b3","line":33,"in_reply_to":"3b27b4cb_80c4280b","updated":"2026-07-03 07:04:54.000000000","message":"Fixed in PS12: import order in manila/privsep/weka.py now follows the hacking import-order template (third-party oslo_concurrency before the first-party manila import).","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"}],"manila/share/drivers/weka/client.py":[{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"608e1ee25a95ec98251ffb74c87e6e1fd5d970a8","unresolved":true,"context_lines":[{"line_number":40,"context_line":""},{"line_number":41,"context_line":"LOG \u003d logging.getLogger(__name__)"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"_API_V2 \u003d \u0027/api/v2\u0027"},{"line_number":44,"context_line":"_DEFAULT_TIMEOUT \u003d 30"},{"line_number":45,"context_line":"_DEFAULT_RETRIES \u003d 3"},{"line_number":46,"context_line":""},{"line_number":47,"context_line":""},{"line_number":48,"context_line":"class WekaApiClient(object):"}],"source_content_type":"text/x-python","patch_set":5,"id":"ca354048_b165634e","line":45,"range":{"start_line":43,"start_character":0,"end_line":45,"end_character":20},"updated":"2026-06-02 14:20:12.000000000","message":"Are we planning to make these configurable?","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"0a4a63fd07da6b7de1ed48ee0f6834de028da52c","unresolved":false,"context_lines":[{"line_number":42,"context_line":""},{"line_number":43,"context_line":"_API_V2 \u003d \u0027/api/v2\u0027"},{"line_number":44,"context_line":"_DEFAULT_TIMEOUT \u003d 30"},{"line_number":45,"context_line":"_DEFAULT_RETRIES \u003d 3"},{"line_number":46,"context_line":""},{"line_number":47,"context_line":""},{"line_number":48,"context_line":"class WekaApiClient(object):"}],"source_content_type":"text/x-python","patch_set":5,"id":"a628d1f9_d7b860b4","line":45,"in_reply_to":"170635bf_27a81d4c","updated":"2026-06-22 11:44:26.000000000","message":"PS8: added an inline comment noting these defaults are overridden by the weka_api_timeout / weka_max_api_retries config options.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5cfd70406b1f8bada666dc197d0d315002190dfc","unresolved":true,"context_lines":[{"line_number":40,"context_line":""},{"line_number":41,"context_line":"LOG \u003d logging.getLogger(__name__)"},{"line_number":42,"context_line":""},{"line_number":43,"context_line":"_API_V2 \u003d \u0027/api/v2\u0027"},{"line_number":44,"context_line":"_DEFAULT_TIMEOUT \u003d 30"},{"line_number":45,"context_line":"_DEFAULT_RETRIES \u003d 3"},{"line_number":46,"context_line":""},{"line_number":47,"context_line":""},{"line_number":48,"context_line":"class WekaApiClient(object):"}],"source_content_type":"text/x-python","patch_set":5,"id":"170635bf_27a81d4c","line":45,"range":{"start_line":43,"start_character":0,"end_line":45,"end_character":20},"in_reply_to":"ca354048_b165634e","updated":"2026-06-16 09:42:04.000000000","message":"The effective values are already operator-configurable via the weka_api_timeout and weka_max_api_retries options in config.py, wired through do_setup(). I\u0027ll add an inline comment here pointing at those options to make the link explicit.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":38059,"name":"Anoop Kumar Shukla","display_name":"Anoop Shukla","email":"anoop.shukla@netapp.com","username":"anoop2","status":"NetApp"},"change_message_id":"608e1ee25a95ec98251ffb74c87e6e1fd5d970a8","unresolved":true,"context_lines":[{"line_number":85,"context_line":""},{"line_number":86,"context_line":"        self._session \u003d requests.Session()"},{"line_number":87,"context_line":"        adapter \u003d req_adapters.HTTPAdapter("},{"line_number":88,"context_line":"            max_retries\u003d0,  # handled manually"},{"line_number":89,"context_line":"            pool_connections\u003d4,"},{"line_number":90,"context_line":"            pool_maxsize\u003d10,"},{"line_number":91,"context_line":"        )"},{"line_number":92,"context_line":"        self._session.mount(\u0027https://\u0027, adapter)"},{"line_number":93,"context_line":"        self._session.mount(\u0027http://\u0027, adapter)"}],"source_content_type":"text/x-python","patch_set":5,"id":"087c29ed_148a0136","line":90,"range":{"start_line":88,"start_character":12,"end_line":90,"end_character":28},"updated":"2026-06-02 14:20:12.000000000","message":"shouldnt these be configurable?","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5cfd70406b1f8bada666dc197d0d315002190dfc","unresolved":true,"context_lines":[{"line_number":85,"context_line":""},{"line_number":86,"context_line":"        self._session \u003d requests.Session()"},{"line_number":87,"context_line":"        adapter \u003d req_adapters.HTTPAdapter("},{"line_number":88,"context_line":"            max_retries\u003d0,  # handled manually"},{"line_number":89,"context_line":"            pool_connections\u003d4,"},{"line_number":90,"context_line":"            pool_maxsize\u003d10,"},{"line_number":91,"context_line":"        )"},{"line_number":92,"context_line":"        self._session.mount(\u0027https://\u0027, adapter)"},{"line_number":93,"context_line":"        self._session.mount(\u0027http://\u0027, adapter)"}],"source_content_type":"text/x-python","patch_set":5,"id":"a4d8c2a6_f814c4c2","line":90,"range":{"start_line":88,"start_character":12,"end_line":90,"end_character":28},"in_reply_to":"087c29ed_148a0136","updated":"2026-06-16 09:42:04.000000000","message":"Yes, fixed","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"0a4a63fd07da6b7de1ed48ee0f6834de028da52c","unresolved":false,"context_lines":[{"line_number":87,"context_line":"        adapter \u003d req_adapters.HTTPAdapter("},{"line_number":88,"context_line":"            max_retries\u003d0,  # handled manually"},{"line_number":89,"context_line":"            pool_connections\u003d4,"},{"line_number":90,"context_line":"            pool_maxsize\u003d10,"},{"line_number":91,"context_line":"        )"},{"line_number":92,"context_line":"        self._session.mount(\u0027https://\u0027, adapter)"},{"line_number":93,"context_line":"        self._session.mount(\u0027http://\u0027, adapter)"}],"source_content_type":"text/x-python","patch_set":5,"id":"fe33a25e_62049de4","line":90,"in_reply_to":"a4d8c2a6_f814c4c2","updated":"2026-06-22 11:44:26.000000000","message":"Confirmed configurable in PS8 (inline comment added linking to the config options).","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":1,"context_line":"# Copyright 2024 Weka.IO Ltd."},{"line_number":2,"context_line":"#"},{"line_number":3,"context_line":"# Licensed under the Apache License, Version 2.0 (the \"License\"); you may"},{"line_number":4,"context_line":"# not use this file except in compliance with the License. You may obtain"}],"source_content_type":"text/x-python","patch_set":6,"id":"b9bf8bdb_d982e0c9","line":1,"range":{"start_line":1,"start_character":12,"end_line":1,"end_character":16},"updated":"2026-06-17 23:14:17.000000000","message":"2024?","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"ef5aa22b744161fd63c5d952f19966e372b5faee","unresolved":false,"context_lines":[{"line_number":1,"context_line":"# Copyright 2024 Weka.IO Ltd."},{"line_number":2,"context_line":"#"},{"line_number":3,"context_line":"# Licensed under the Apache License, Version 2.0 (the \"License\"); you may"},{"line_number":4,"context_line":"# not use this file except in compliance with the License. You may obtain"}],"source_content_type":"text/x-python","patch_set":6,"id":"5884d2d7_e76b54ab","line":1,"in_reply_to":"b9bf8bdb_d982e0c9","updated":"2026-06-22 11:44:27.000000000","message":"PS8: updated the copyright year to 2026 across the driver files.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"9eef2852_9854b23b","updated":"2026-06-17 23:14:17.000000000","message":"There\u0027s a lot of dead code in this module. Can you get rid of these unused methods?","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"ae300bef_33d5fad4","in_reply_to":"9eef2852_9854b23b","updated":"2026-06-22 11:44:28.000000000","message":"Removed 34 unused methods in PS8.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"5bdd0ef9a34cc499d68c33e153ead8a47a9e0371","unresolved":false,"context_lines":[{"line_number":777,"context_line":""},{"line_number":778,"context_line":"        DELETE /nfs/permissions/{uid}"},{"line_number":779,"context_line":"        \"\"\""},{"line_number":780,"context_line":"        return self._delete(\u0027/nfs/permissions/{uid}\u0027.format(uid\u003dpermission_uid))"},{"line_number":781,"context_line":""},{"line_number":782,"context_line":"    def list_client_groups(self):"},{"line_number":783,"context_line":"        \"\"\"Return all NFS client groups."}],"source_content_type":"text/x-python","patch_set":7,"id":"ba6cf04d_3eb7a2af","line":780,"updated":"2026-06-17 14:43:50.000000000","message":"pep8: E501 line too long (80 \u003e 79 characters)","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"5bdd0ef9a34cc499d68c33e153ead8a47a9e0371","unresolved":false,"context_lines":[{"line_number":810,"context_line":"        else:"},{"line_number":811,"context_line":"            payload \u003d {\u0027dns\u0027: rule_value}"},{"line_number":812,"context_line":"        result \u003d self._post("},{"line_number":813,"context_line":"            \u0027/nfs/clientGroups/{uid}/rules\u0027.format(uid\u003dgroup_uid), json\u003dpayload)"},{"line_number":814,"context_line":"        return result.get(\u0027data\u0027, result)"},{"line_number":815,"context_line":""},{"line_number":816,"context_line":"    def get_client_group(self, group_uid):"}],"source_content_type":"text/x-python","patch_set":7,"id":"aa834cba_68debfcf","line":813,"updated":"2026-06-17 14:43:50.000000000","message":"pep8: E501 line too long (80 \u003e 79 characters)","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"}],"manila/share/drivers/weka/config.py":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"c6aa4e04b333ca14f197629f2d33faba32df08d8","unresolved":true,"context_lines":[{"line_number":200,"context_line":"        ),"},{"line_number":201,"context_line":"    ),"},{"line_number":202,"context_line":"    cfg.IntOpt("},{"line_number":203,"context_line":"        \u0027weka_posix_mount_timeout\u0027,"},{"line_number":204,"context_line":"        default\u003d60,"},{"line_number":205,"context_line":"        min\u003d10,"},{"line_number":206,"context_line":"        max\u003d600,"}],"source_content_type":"text/x-python","patch_set":15,"id":"1c3cf67a_42e75f77","line":203,"updated":"2026-08-08 07:05:45.000000000","message":"`weka_posix_mount_timeout` is defined here but never referenced. Remove it if it is not needed.","commit_id":"edc2a4d6d18cd31f020286bef66abe2bb2a22059"}],"manila/share/drivers/weka/driver.py":[{"author":{"_account_id":36686,"name":"Inyong Hong","display_name":"hongp","email":"inyong.hong@samsung.com","username":"hong-p"},"change_message_id":"a36c42e0b3cab890184971ad85e65af2f3a4c0e5","unresolved":true,"context_lines":[{"line_number":657,"context_line":""},{"line_number":658,"context_line":"        return rule_state_map"},{"line_number":659,"context_line":""},{"line_number":660,"context_line":"    def _update_wekafs_access(self, share, add_rules, delete_rules):"},{"line_number":661,"context_line":"        \"\"\"Handle WekaFS access rules."},{"line_number":662,"context_line":""},{"line_number":663,"context_line":"        Access control for the WekaFS (POSIX client) protocol is managed"}],"source_content_type":"text/x-python","patch_set":5,"id":"d75ccb39_a0eee23d","line":660,"updated":"2026-05-31 21:37:18.000000000","message":"For WEKAFS protocol shares, _update_wekafs_access performs no actual operation — all access rules are accepted and immediately marked active without any enforcement being applied to the\n   Weka cluster. The docstring states that access control is \"managed via Weka filesystem authentication and mount tokens\", but looking at the implementation:\n\n1. Filesystems are created with auth_required\u003dFalse (hardcoded), so mount tokens are not required at all\n2. get_filesystem_mount_token() is implemented in client.py but is never called anywhere in driver.py\n\nCould you clarify the intended design here? Specifically:\n\nIf the plan is to use mount tokens, there is no clear way to expose the token to the end user. Manila surfaces share information through export locations and access rule responses neither of which has a standard field for carrying a short-lived mount token. How would a user actually retrieve the token they need to mount the share?\n\nWhy was the security policy approach not used for WEKAFS access control? Attaching IP-based security policies to the filesystem on update_access would map naturally to Manila\u0027s access rule model, similar to how the NFS side uses client groups.\n\nAs it stands, WEKAFS shares have no access control enforced at the Weka level regardless of what rules are configured in Manila. Is this an intentional interim state, or is there a follow-up patch planned?","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f446506a7ed699cc3a04d935c02373db6eb2a4a6","unresolved":false,"context_lines":[{"line_number":657,"context_line":""},{"line_number":658,"context_line":"        return rule_state_map"},{"line_number":659,"context_line":""},{"line_number":660,"context_line":"    def _update_wekafs_access(self, share, add_rules, delete_rules):"},{"line_number":661,"context_line":"        \"\"\"Handle WekaFS access rules."},{"line_number":662,"context_line":""},{"line_number":663,"context_line":"        Access control for the WekaFS (POSIX client) protocol is managed"}],"source_content_type":"text/x-python","patch_set":5,"id":"d5227da3_43d4bac5","line":660,"in_reply_to":"4701a7f2_b9f08513","updated":"2026-07-03 13:26:25.000000000","message":"Marking resolved — tracked as a roadmap follow-up (WEKAFS IP-based access enforcement).","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"0a4a63fd07da6b7de1ed48ee0f6834de028da52c","unresolved":true,"context_lines":[{"line_number":657,"context_line":""},{"line_number":658,"context_line":"        return rule_state_map"},{"line_number":659,"context_line":""},{"line_number":660,"context_line":"    def _update_wekafs_access(self, share, add_rules, delete_rules):"},{"line_number":661,"context_line":"        \"\"\"Handle WekaFS access rules."},{"line_number":662,"context_line":""},{"line_number":663,"context_line":"        Access control for the WekaFS (POSIX client) protocol is managed"}],"source_content_type":"text/x-python","patch_set":5,"id":"4701a7f2_b9f08513","line":660,"in_reply_to":"d423f5e1_0e75e152","updated":"2026-06-22 11:44:26.000000000","message":"PS8: the doc and code now consistently report WEKAFS access rules as accepted no-ops (\u0027active\u0027). IP-based security-policy enforcement for WEKAFS shares is planned as a follow-up.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5cfd70406b1f8bada666dc197d0d315002190dfc","unresolved":true,"context_lines":[{"line_number":657,"context_line":""},{"line_number":658,"context_line":"        return rule_state_map"},{"line_number":659,"context_line":""},{"line_number":660,"context_line":"    def _update_wekafs_access(self, share, add_rules, delete_rules):"},{"line_number":661,"context_line":"        \"\"\"Handle WekaFS access rules."},{"line_number":662,"context_line":""},{"line_number":663,"context_line":"        Access control for the WekaFS (POSIX client) protocol is managed"}],"source_content_type":"text/x-python","patch_set":5,"id":"d423f5e1_0e75e152","line":660,"in_reply_to":"d75ccb39_a0eee23d","updated":"2026-06-16 09:42:04.000000000","message":"We plan to add the ip based security policies later on.","commit_id":"77b9f5adcb7dd0ffec2f426067ada7779030b64a"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":368,"context_line":"            )"},{"line_number":369,"context_line":""},{"line_number":370,"context_line":"            # Allow the NFS server to apply the new permissions."},{"line_number":371,"context_line":"            time.sleep(5)"},{"line_number":372,"context_line":""},{"line_number":373,"context_line":"            os.makedirs(src_mnt, exist_ok\u003dTrue)"},{"line_number":374,"context_line":"            os.makedirs(dst_mnt, exist_ok\u003dTrue)"}],"source_content_type":"text/x-python","patch_set":6,"id":"ec6a1bbe_892563f3","line":371,"range":{"start_line":371,"start_character":0,"end_line":371,"end_character":25},"updated":"2026-06-17 23:14:17.000000000","message":"can we avoid this with a utils.retry instead?","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"ef5aa22b744161fd63c5d952f19966e372b5faee","unresolved":false,"context_lines":[{"line_number":368,"context_line":"            )"},{"line_number":369,"context_line":""},{"line_number":370,"context_line":"            # Allow the NFS server to apply the new permissions."},{"line_number":371,"context_line":"            time.sleep(5)"},{"line_number":372,"context_line":""},{"line_number":373,"context_line":"            os.makedirs(src_mnt, exist_ok\u003dTrue)"},{"line_number":374,"context_line":"            os.makedirs(dst_mnt, exist_ok\u003dTrue)"}],"source_content_type":"text/x-python","patch_set":6,"id":"179e9c2d_8415875f","line":371,"in_reply_to":"ec6a1bbe_892563f3","updated":"2026-06-22 11:44:27.000000000","message":"PS8: the ad-hoc retry was removed in the async create_share_from_snapshot refactor. API-level retries live in client._request (which also handles 401 re-auth).","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":475,"context_line":""},{"line_number":476,"context_line":"        fs_uid \u003d fs[\u0027uid\u0027]"},{"line_number":477,"context_line":""},{"line_number":478,"context_line":"        # Remove NFS permissions before deleting."},{"line_number":479,"context_line":"        try:"},{"line_number":480,"context_line":"            self._remove_all_nfs_permissions(fs_name)"},{"line_number":481,"context_line":"        except Exception as exc:"},{"line_number":482,"context_line":"            LOG.warning("},{"line_number":483,"context_line":"                \"Failed to remove NFS permissions for share %s: %s\","},{"line_number":484,"context_line":"                share[\u0027id\u0027], exc,"},{"line_number":485,"context_line":"            )"},{"line_number":486,"context_line":""},{"line_number":487,"context_line":"        # Unmount locally if mounted."},{"line_number":488,"context_line":"        mount_point \u003d self._mount_point(fs_name)"}],"source_content_type":"text/x-python","patch_set":6,"id":"63e49cc4_df9bd5db","line":485,"range":{"start_line":478,"start_character":7,"end_line":485,"end_character":13},"updated":"2026-06-17 23:14:17.000000000","message":"the driver gets an \"update_access\" call prior to deletion","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"ef5aa22b744161fd63c5d952f19966e372b5faee","unresolved":false,"context_lines":[{"line_number":482,"context_line":"            LOG.warning("},{"line_number":483,"context_line":"                \"Failed to remove NFS permissions for share %s: %s\","},{"line_number":484,"context_line":"                share[\u0027id\u0027], exc,"},{"line_number":485,"context_line":"            )"},{"line_number":486,"context_line":""},{"line_number":487,"context_line":"        # Unmount locally if mounted."},{"line_number":488,"context_line":"        mount_point \u003d self._mount_point(fs_name)"}],"source_content_type":"text/x-python","patch_set":6,"id":"3c5b19b5_66344ed0","line":485,"in_reply_to":"63e49cc4_df9bd5db","updated":"2026-06-22 11:44:27.000000000","message":"Acknowledged — the driver clears NFS exports on access removal/delete, so the update_access-before-deletion call is handled.","commit_id":"f66b016a919e08f034e28c85b2e18e95e1e358fa"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":37,"context_line":"  enabled_share_backends \u003d weka"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"  [weka]"},{"line_number":40,"context_line":"  share_driver \u003d manila.share.drivers.weka.driver:WekaShareDriver"},{"line_number":41,"context_line":"  share_backend_name \u003d weka"},{"line_number":42,"context_line":"  driver_handles_share_servers \u003d false"},{"line_number":43,"context_line":"  snapshot_support \u003d true"}],"source_content_type":"text/x-python","patch_set":7,"id":"ca3f6d66_cde24261","line":40,"range":{"start_line":40,"start_character":17,"end_line":40,"end_character":65},"updated":"2026-06-17 23:14:17.000000000","message":"`manila.share.drivers.weka.driver.WekaShareDriver`","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":37,"context_line":"  enabled_share_backends \u003d weka"},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"  [weka]"},{"line_number":40,"context_line":"  share_driver \u003d manila.share.drivers.weka.driver:WekaShareDriver"},{"line_number":41,"context_line":"  share_backend_name \u003d weka"},{"line_number":42,"context_line":"  driver_handles_share_servers \u003d false"},{"line_number":43,"context_line":"  snapshot_support \u003d true"}],"source_content_type":"text/x-python","patch_set":7,"id":"9caa4e0b_448a86a7","line":40,"in_reply_to":"ca3f6d66_cde24261","updated":"2026-06-22 11:44:28.000000000","message":"Done in PS8 — the docstring now uses the dotted module path.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":108,"context_line":"    \"\"\""},{"line_number":109,"context_line":"    if \u0027/\u0027 not in cidr_str:"},{"line_number":110,"context_line":"        return cidr_str"},{"line_number":111,"context_line":"    try:"},{"line_number":112,"context_line":"        net \u003d ipaddress.IPv4Network(cidr_str, strict\u003dFalse)"},{"line_number":113,"context_line":"        return \u0027{}/{}\u0027.format(str(net.network_address), str(net.netmask))"},{"line_number":114,"context_line":"    except ValueError:"},{"line_number":115,"context_line":"        return cidr_str"},{"line_number":116,"context_line":""},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"class WekaShareDriver(driver.ShareDriver):"}],"source_content_type":"text/x-python","patch_set":7,"id":"2de06654_c38e1e66","line":115,"range":{"start_line":111,"start_character":0,"end_line":115,"end_character":23},"updated":"2026-06-17 23:14:17.000000000","message":"Is IPv6 not supported? If it isn\u0027t reject the address rather than allowing it to be passed unchanged?","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":112,"context_line":"        net \u003d ipaddress.IPv4Network(cidr_str, strict\u003dFalse)"},{"line_number":113,"context_line":"        return \u0027{}/{}\u0027.format(str(net.network_address), str(net.netmask))"},{"line_number":114,"context_line":"    except ValueError:"},{"line_number":115,"context_line":"        return cidr_str"},{"line_number":116,"context_line":""},{"line_number":117,"context_line":""},{"line_number":118,"context_line":"class WekaShareDriver(driver.ShareDriver):"}],"source_content_type":"text/x-python","patch_set":7,"id":"ea319ccb_25e14498","line":115,"in_reply_to":"2de06654_c38e1e66","updated":"2026-06-22 11:44:28.000000000","message":"PS8: IPv6 IP rules are now rejected with InvalidShareAccess (the driver supports IPv4 access rules only) instead of being passed through unchanged.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":290,"context_line":"            \"Share %s created successfully (fs_uid\u003d%s)\", share[\u0027id\u0027], fs_uid)"},{"line_number":291,"context_line":"        return export_locations"},{"line_number":292,"context_line":""},{"line_number":293,"context_line":"    def create_share_from_snapshot(self, context, share, snapshot,"},{"line_number":294,"context_line":"                                   share_server\u003dNone, parent_share\u003dNone):"},{"line_number":295,"context_line":"        \"\"\"Create a new share populated with data from a snapshot."},{"line_number":296,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"4ae9e105_70326f38","line":293,"range":{"start_line":293,"start_character":8,"end_line":293,"end_character":34},"updated":"2026-06-17 23:14:17.000000000","message":"Hmm, this method does a full rsync through NFS mounts on the Manila host. This works for small shares, but has a scalability problem: all data is routed Weka → NFS → Manila host → NFS → Weka, and the method blocks the manager thread synchronously for the entire copy. So, A 500 GB share could take hours.\n\nThe `create_share_from_snapshot` contract was designed for exactly this\nsituation — drivers can return `{\u0027status\u0027: \u0027creating_from_snapshot\u0027}` to\nhand off to asynchronous completion, with `get_share_status` providing\nprogress polling. This driver doesn\u0027t implement `get_share_status`, so it can\u0027t use this path.\n\nSuggestions (any one would help):\n\n1. Async completion: kick off the rsync in a background thread/process,\n   return `{\u0027status\u0027: \u0027creating_from_snapshot\u0027}`, and implement \n   `get_share_status` to poll for completion. This unblocks the manager.\n\n2. Server-side data movement: investigate whether Weka writable snapshots or any\n   other cluster-side mechanism can keep the data copy off the Manila host \n   entirely. Even a temporary writable snapshot used as a CoW source\n   that gets detached afterward would be orders of magnitude faster \n   than rsync-over-NFS.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":290,"context_line":"            \"Share %s created successfully (fs_uid\u003d%s)\", share[\u0027id\u0027], fs_uid)"},{"line_number":291,"context_line":"        return export_locations"},{"line_number":292,"context_line":""},{"line_number":293,"context_line":"    def create_share_from_snapshot(self, context, share, snapshot,"},{"line_number":294,"context_line":"                                   share_server\u003dNone, parent_share\u003dNone):"},{"line_number":295,"context_line":"        \"\"\"Create a new share populated with data from a snapshot."},{"line_number":296,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"ed6af2bc_3a4ba820","line":293,"in_reply_to":"4ae9e105_70326f38","updated":"2026-06-22 11:44:28.000000000","message":"PS8: create_share_from_snapshot is now asynchronous — it returns \u0027creating_from_snapshot\u0027 and a new get_share_status() polls to completion, so the manager thread is no longer blocked. There is no server-side Weka clone API, so rsync remains the transport; the NFS path now fails fast if weka_nfs_server is unset.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        fs \u003d self._create_filesystem_idempotent("},{"line_number":329,"context_line":"            new_fs_name, group_name, size_bytes)"},{"line_number":330,"context_line":""},{"line_number":331,"context_line":"        nfs_server \u003d self.configuration.safe_get(\u0027weka_nfs_server\u0027)"},{"line_number":332,"context_line":"        if not nfs_server:"},{"line_number":333,"context_line":"            raise exception.ManilaException("},{"line_number":334,"context_line":"                message\u003d_(\u0027weka_nfs_server must be configured for \u0027"},{"line_number":335,"context_line":"                          \u0027create_share_from_snapshot\u0027))"},{"line_number":336,"context_line":""},{"line_number":337,"context_line":"        # Determine the local IP that routes to the NFS server."},{"line_number":338,"context_line":"        s \u003d socket.socket(socket.AF_INET, socket.SOCK_DGRAM)"}],"source_content_type":"text/x-python","patch_set":7,"id":"5861ed79_7ad83f62","line":335,"range":{"start_line":331,"start_character":0,"end_line":335,"end_character":56},"updated":"2026-06-17 23:14:17.000000000","message":"maybe do this check in the driver\u0027s init, set a global boolean variable and report that as the capability in `update_share_stats()`. That way you prevent this issue from the get go.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":332,"context_line":"        if not nfs_server:"},{"line_number":333,"context_line":"            raise exception.ManilaException("},{"line_number":334,"context_line":"                message\u003d_(\u0027weka_nfs_server must be configured for \u0027"},{"line_number":335,"context_line":"                          \u0027create_share_from_snapshot\u0027))"},{"line_number":336,"context_line":""},{"line_number":337,"context_line":"        # Determine the local IP that routes to the NFS server."},{"line_number":338,"context_line":"        s \u003d socket.socket(socket.AF_INET, socket.SOCK_DGRAM)"}],"source_content_type":"text/x-python","patch_set":7,"id":"6ed66c2b_adcb5284","line":335,"in_reply_to":"5861ed79_7ad83f62","updated":"2026-06-22 11:44:28.000000000","message":"PS8: the prerequisite check moved to do_setup (cached), create_share_from_snapshot fails fast when weka_nfs_server is unset, and the capability is reported in _update_share_stats.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":347,"context_line":"        tmp_cg_name \u003d \u0027manila-snap-{}\u0027.format(share[\u0027id\u0027][:8])"},{"line_number":348,"context_line":"        cg_uid \u003d None"},{"line_number":349,"context_line":"        rule_uid \u003d None"},{"line_number":350,"context_line":"        src_mnt \u003d \u0027/tmp/manila_snap_src_{}\u0027.format(share[\u0027id\u0027][:8])"},{"line_number":351,"context_line":"        dst_mnt \u003d \u0027/tmp/manila_snap_dst_{}\u0027.format(share[\u0027id\u0027][:8])"},{"line_number":352,"context_line":"        src_mounted \u003d False"},{"line_number":353,"context_line":"        dst_mounted \u003d False"},{"line_number":354,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"9527baeb_302d0f06","line":351,"range":{"start_line":350,"start_character":0,"end_line":351,"end_character":67},"updated":"2026-06-17 23:14:17.000000000","message":"these predictable paths are bad for security. \n\n(1) Manila\u0027s got a data directory that may be used for this\n(2) if you\u0027d like to use /tmp,  Use `tempfile.mkdtemp()` instead.\n\nalso, is the `WekaMount` construct useful for this?","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":348,"context_line":"        cg_uid \u003d None"},{"line_number":349,"context_line":"        rule_uid \u003d None"},{"line_number":350,"context_line":"        src_mnt \u003d \u0027/tmp/manila_snap_src_{}\u0027.format(share[\u0027id\u0027][:8])"},{"line_number":351,"context_line":"        dst_mnt \u003d \u0027/tmp/manila_snap_dst_{}\u0027.format(share[\u0027id\u0027][:8])"},{"line_number":352,"context_line":"        src_mounted \u003d False"},{"line_number":353,"context_line":"        dst_mounted \u003d False"},{"line_number":354,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"00563698_cac95b85","line":351,"in_reply_to":"9527baeb_302d0f06","updated":"2026-06-22 11:44:28.000000000","message":"PS8: switched to tempfile.mkdtemp() and the WekaMount context manager.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":353,"context_line":"        dst_mounted \u003d False"},{"line_number":354,"context_line":""},{"line_number":355,"context_line":"        try:"},{"line_number":356,"context_line":"            cg \u003d self._client.create_client_group(tmp_cg_name)"},{"line_number":357,"context_line":"            cg_uid \u003d cg[\u0027uid\u0027]"},{"line_number":358,"context_line":"            rule \u003d self._client.add_client_group_rule(cg_uid, \u0027IP\u0027, local_ip)"},{"line_number":359,"context_line":"            rule_uid \u003d rule.get(\u0027uid\u0027) if isinstance(rule, dict) else None"}],"source_content_type":"text/x-python","patch_set":7,"id":"c208f8e4_b6b4c3a9","line":356,"updated":"2026-06-17 23:14:17.000000000","message":"method is becoming too long to be readable.. maybe reuse existing access methods for this? or refactor into separate internal methods","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":353,"context_line":"        dst_mounted \u003d False"},{"line_number":354,"context_line":""},{"line_number":355,"context_line":"        try:"},{"line_number":356,"context_line":"            cg \u003d self._client.create_client_group(tmp_cg_name)"},{"line_number":357,"context_line":"            cg_uid \u003d cg[\u0027uid\u0027]"},{"line_number":358,"context_line":"            rule \u003d self._client.add_client_group_rule(cg_uid, \u0027IP\u0027, local_ip)"},{"line_number":359,"context_line":"            rule_uid \u003d rule.get(\u0027uid\u0027) if isinstance(rule, dict) else None"}],"source_content_type":"text/x-python","patch_set":7,"id":"cd05b41c_2c876fdd","line":356,"in_reply_to":"c208f8e4_b6b4c3a9","updated":"2026-06-22 11:44:28.000000000","message":"PS8: split into _run_snapshot_copy / _copy_snapshot_nfs / _copy_snapshot_wekafs / _rsync_snapshot.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":383,"context_line":"                \u0027mount\u0027, \u0027-t\u0027, \u0027nfs\u0027,"},{"line_number":384,"context_line":"                \u0027{}:/{}\u0027.format(nfs_server, src_fs_name),"},{"line_number":385,"context_line":"                src_mnt,"},{"line_number":386,"context_line":"                run_as_root\u003dTrue, root_helper\u003d\u0027sudo\u0027,"},{"line_number":387,"context_line":"            )"},{"line_number":388,"context_line":"            src_mounted \u003d True"},{"line_number":389,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"9d1462c5_7ebd513c","line":386,"range":{"start_line":386,"start_character":16,"end_line":386,"end_character":53},"updated":"2026-06-17 23:14:17.000000000","message":"this is not good.. \n\n`root_helper\u003d\u0027sudo\u0027` is used multiple places in this driver.\n\nManila drivers today pass `run_as_root\u003dTrue` without an explicit `root_helper`, which lets the system use the configured rootwrap (`sudo manila-rootwrap /etc/manila/rootwrap.conf`). Hardcoding `sudo` bypasses the rootwrap security layer that restricts which commands can be run as root.\n\nAlso, we\u0027re actively trying to kill rootwrap in favor of oslo-privsep: https://review.opendev.org/q/topic:%22bp/privsep-migration%22\n\nThis would be the most sustainable way to proceed. If you need help unpacking this, @ces.eduardo98@gmail.com can help.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"52b34d9809db7a58650fbd83eb4455de3338c2d0","unresolved":false,"context_lines":[{"line_number":383,"context_line":"                \u0027mount\u0027, \u0027-t\u0027, \u0027nfs\u0027,"},{"line_number":384,"context_line":"                \u0027{}:/{}\u0027.format(nfs_server, src_fs_name),"},{"line_number":385,"context_line":"                src_mnt,"},{"line_number":386,"context_line":"                run_as_root\u003dTrue, root_helper\u003d\u0027sudo\u0027,"},{"line_number":387,"context_line":"            )"},{"line_number":388,"context_line":"            src_mounted \u003d True"},{"line_number":389,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"9d016840_93a913ad","line":386,"in_reply_to":"9d1462c5_7ebd513c","updated":"2026-06-22 16:41:41.000000000","message":"Correction to my earlier note: PS11 migrates this to oslo-privsep rather than deferring it. mount/umount/rsync now run in manila\u0027s sys_admin privsep daemon via manila/privsep/weka.py entrypoints — no sudo/rootwrap in the driver. The Weka third-party CI on PS11 is green (create_share_from_snapshot exercises this path).","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":383,"context_line":"                \u0027mount\u0027, \u0027-t\u0027, \u0027nfs\u0027,"},{"line_number":384,"context_line":"                \u0027{}:/{}\u0027.format(nfs_server, src_fs_name),"},{"line_number":385,"context_line":"                src_mnt,"},{"line_number":386,"context_line":"                run_as_root\u003dTrue, root_helper\u003d\u0027sudo\u0027,"},{"line_number":387,"context_line":"            )"},{"line_number":388,"context_line":"            src_mounted \u003d True"},{"line_number":389,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"d9a70e10_8b42b9a9","line":386,"in_reply_to":"9d1462c5_7ebd513c","updated":"2026-06-22 11:44:28.000000000","message":"PS8: removed the hardcoded root_helper\u003d\u0027sudo\u0027 at all sites so the configured rootwrap is used. The oslo-privsep migration is noted as a follow-up.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":461,"context_line":""},{"line_number":462,"context_line":"        export_locations \u003d self._build_export_locations("},{"line_number":463,"context_line":"            share, new_fs_name, fs[\u0027uid\u0027], share_proto)"},{"line_number":464,"context_line":"        return export_locations"},{"line_number":465,"context_line":""},{"line_number":466,"context_line":"    def delete_share(self, context, share, share_server\u003dNone):"},{"line_number":467,"context_line":"        \"\"\"Delete a share\u0027s underlying Weka filesystem."}],"source_content_type":"text/x-python","patch_set":7,"id":"bb22249a_f230d35d","line":464,"range":{"start_line":464,"start_character":15,"end_line":464,"end_character":31},"updated":"2026-06-17 23:14:17.000000000","message":"This is returning a bare list of export locations (the legacy format). The current interface contract expects a dict:\n\n```\n{\u0027status\u0027: \u0027available\u0027, \u0027export_locations\u0027: [...]}\n```\n\nThe manager handles the legacy list format so this works today. But the dict format with an explicit `status` key is the documented contract and enables async completion via `\u0027creating_from_snapshot\u0027` status if needed in the future.\n\nFor example, all this rsync stuff that you\u0027re doing could be offloaded by the driver some day, and you can implement an async creation by letting manila know that you\u0027re \"creating_from_snapshot\" and manila will periodically check if the share is ready.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":461,"context_line":""},{"line_number":462,"context_line":"        export_locations \u003d self._build_export_locations("},{"line_number":463,"context_line":"            share, new_fs_name, fs[\u0027uid\u0027], share_proto)"},{"line_number":464,"context_line":"        return export_locations"},{"line_number":465,"context_line":""},{"line_number":466,"context_line":"    def delete_share(self, context, share, share_server\u003dNone):"},{"line_number":467,"context_line":"        \"\"\"Delete a share\u0027s underlying Weka filesystem."}],"source_content_type":"text/x-python","patch_set":7,"id":"df2c3e1e_95e9f1b1","line":464,"in_reply_to":"bb22249a_f230d35d","updated":"2026-06-22 11:44:28.000000000","message":"PS8: create_share_from_snapshot now returns the {\u0027status\u0027: ..., \u0027export_locations\u0027: ...} dict (creating_from_snapshot).","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":544,"context_line":"            \"Shrinking share %s to %s GiB\", share[\u0027id\u0027], new_size)"},{"line_number":545,"context_line":"        self._client.update_filesystem(fs_uid, total_capacity\u003dnew_bytes)"},{"line_number":546,"context_line":""},{"line_number":547,"context_line":"    def ensure_share(self, context, share, share_server\u003dNone):"},{"line_number":548,"context_line":"        \"\"\"Verify share is exported and return current export locations."},{"line_number":549,"context_line":""},{"line_number":550,"context_line":"        Called by Manila on restart/recovery to re-verify shares."}],"source_content_type":"text/x-python","patch_set":7,"id":"088073cc_20f944a2","line":547,"range":{"start_line":547,"start_character":0,"end_line":547,"end_character":62},"updated":"2026-06-17 23:14:17.000000000","message":"New drivers should implement \"ensure_shares\" instead of the deprecated \"ensure_share\" interface. \"ensure_shares\" is a bulk update entry point, and it is wired up to an API, in addition to being able to be a maintenance op on restarts. It is associated with \"get_backend_info\" (this has to be implemented).. \n\nHow the manager uses these (see `manila/share/manager.py`):\n\n1. On startup, the manager calls `get_backend_info()`. It hashes the returned dict and compares it to the hash from the previous run. If the hash is unchanged, the ensure_shares() is skipped entirely.\n2. If the hash changed (or it\u0027s the first run), the manager calls\n`ensure_shares(context, shares)` with the full list of shares at once.\n3. If either method raises `NotImplementedError`, the manager falls back\nto calling `ensure_share(context, share)` individually for every share\non every restart.. \n\n\nOn a backend with hundreds of shares, this means hundreds of individual `get_filesystem_by_name` API calls on every service restart even when nothing changed.\n\n\nSo, implement `get_backend_info`... have it return a dict of config/connection values that, if changed, mean exports need re-verification. Existing drivers return\nthings like API server address, export IPs, driver version, or mount paths. For Weka, something like:\n\n```\n      def get_backend_info(self, context):\n          return {\n              \u0027weka_api_server\u0027: self.configuration.safe_get(\u0027weka_api_server\u0027),\n              \u0027weka_mount_point_base\u0027: self.configuration.safe_get(\n                  \u0027weka_mount_point_base\u0027),\n          }\n```\n\n`ensure_shares` receives the full share list and returns a dict keyed by\nshare ID with updates (export locations, status, etc.). It can batch API\ncalls instead of doing one-at-a-time lookups:\n\n```\n      def ensure_shares(self, context, shares):\n          updates \u003d {}\n          for share in shares:\n              try:\n                  export_locations \u003d self._ensure_share(context, share)\n                  updates[share[\u0027id\u0027]] \u003d {\n                      \u0027export_locations\u0027: export_locations,\n                  }\n              except exception.ShareNotFound:\n                  updates[share[\u0027id\u0027]] \u003d {\u0027status\u0027: constants.STATUS_ERROR}\n          return updates\n```\n\nSee LVM, CephFS, VastData, and other drivers for real-world examples.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":544,"context_line":"            \"Shrinking share %s to %s GiB\", share[\u0027id\u0027], new_size)"},{"line_number":545,"context_line":"        self._client.update_filesystem(fs_uid, total_capacity\u003dnew_bytes)"},{"line_number":546,"context_line":""},{"line_number":547,"context_line":"    def ensure_share(self, context, share, share_server\u003dNone):"},{"line_number":548,"context_line":"        \"\"\"Verify share is exported and return current export locations."},{"line_number":549,"context_line":""},{"line_number":550,"context_line":"        Called by Manila on restart/recovery to re-verify shares."}],"source_content_type":"text/x-python","patch_set":7,"id":"ae8a596f_de44fb92","line":547,"in_reply_to":"088073cc_20f944a2","updated":"2026-06-22 11:44:28.000000000","message":"PS8: implemented ensure_shares + get_backend_info; ensure_shares fetches the filesystem list once.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":544,"context_line":"            \"Shrinking share %s to %s GiB\", share[\u0027id\u0027], new_size)"},{"line_number":545,"context_line":"        self._client.update_filesystem(fs_uid, total_capacity\u003dnew_bytes)"},{"line_number":546,"context_line":""},{"line_number":547,"context_line":"    def ensure_share(self, context, share, share_server\u003dNone):"},{"line_number":548,"context_line":"        \"\"\"Verify share is exported and return current export locations."},{"line_number":549,"context_line":""},{"line_number":550,"context_line":"        Called by Manila on restart/recovery to re-verify shares."},{"line_number":551,"context_line":"        \"\"\""},{"line_number":552,"context_line":"        fs_name \u003d self._share_name(share[\u0027id\u0027])"},{"line_number":553,"context_line":"        fs \u003d self._client.get_filesystem_by_name(fs_name)"},{"line_number":554,"context_line":"        if not fs:"},{"line_number":555,"context_line":"            raise exception.ShareNotFound(share_id\u003dshare[\u0027id\u0027])"},{"line_number":556,"context_line":""},{"line_number":557,"context_line":"        fs_uid \u003d fs[\u0027uid\u0027]"},{"line_number":558,"context_line":"        share_proto \u003d share[\u0027share_proto\u0027].upper()"},{"line_number":559,"context_line":""},{"line_number":560,"context_line":"        # Re-mount POSIX if needed."},{"line_number":561,"context_line":"        mount_point \u003d self._mount_point(fs_name)"},{"line_number":562,"context_line":"        if (share_proto \u003d\u003d _WEKAFS_PROTO"},{"line_number":563,"context_line":"                and not weka_posix.WekaMount.is_mounted(mount_point)):"},{"line_number":564,"context_line":"            LOG.info("},{"line_number":565,"context_line":"                \"Re-mounting WekaFS share %s at %s\","},{"line_number":566,"context_line":"                share[\u0027id\u0027], mount_point,"},{"line_number":567,"context_line":"            )"},{"line_number":568,"context_line":"            mnt \u003d weka_posix.WekaMount("},{"line_number":569,"context_line":"                backends\u003dself._get_backends(),"},{"line_number":570,"context_line":"                fs_name\u003dfs_name,"},{"line_number":571,"context_line":"                mount_point\u003dmount_point,"},{"line_number":572,"context_line":"                num_cores\u003dself.configuration.safe_get(\u0027weka_num_cores\u0027) or 1,"},{"line_number":573,"context_line":"                net\u003dself.configuration.safe_get(\u0027weka_net_device\u0027),"},{"line_number":574,"context_line":"            )"},{"line_number":575,"context_line":"            mnt.mount()"},{"line_number":576,"context_line":""},{"line_number":577,"context_line":"        return self._build_export_locations("},{"line_number":578,"context_line":"            share, fs_name, fs_uid, share_proto)"},{"line_number":579,"context_line":""},{"line_number":580,"context_line":"    # ------------------------------------------------------------------"},{"line_number":581,"context_line":"    # Access control"},{"line_number":582,"context_line":"    # ------------------------------------------------------------------"}],"source_content_type":"text/x-python","patch_set":7,"id":"622cb893_549c902f","line":579,"range":{"start_line":547,"start_character":4,"end_line":579,"end_character":0},"updated":"2026-06-17 23:14:17.000000000","message":"Please drop this, and instead implement \"ensure_shares()\" and \"get_backend_info()\". \n\nensure_shares hands you all the shares, and is tied to an API in addition to being a recovery mechanism on service restarts. The advantage of this mechanism is that get_backend_info can contain conditions to trigger it. \n\nIf you have any backend configuration opts that will need a","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":576,"context_line":""},{"line_number":577,"context_line":"        return self._build_export_locations("},{"line_number":578,"context_line":"            share, fs_name, fs_uid, share_proto)"},{"line_number":579,"context_line":""},{"line_number":580,"context_line":"    # ------------------------------------------------------------------"},{"line_number":581,"context_line":"    # Access control"},{"line_number":582,"context_line":"    # ------------------------------------------------------------------"}],"source_content_type":"text/x-python","patch_set":7,"id":"05a8345a_b4f1d075","line":579,"in_reply_to":"622cb893_549c902f","updated":"2026-06-22 11:44:28.000000000","message":"PS8: removed ensure_share and implemented ensure_shares + get_backend_info, as suggested.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":675,"context_line":"        workflow completes normally."},{"line_number":676,"context_line":"        \"\"\""},{"line_number":677,"context_line":"        rule_state_map \u003d {}"},{"line_number":678,"context_line":"        for rule in add_rules or []:"},{"line_number":679,"context_line":"            LOG.info("},{"line_number":680,"context_line":"                \"WekaFS shares do not enforce Manila access rules \""},{"line_number":681,"context_line":"                \"(type\u003d%s, rule\u003d%s). Access control for WEKAFS shares is \""},{"line_number":682,"context_line":"                \"managed via Weka filesystem authentication and mount tokens.\","},{"line_number":683,"context_line":"                rule[\u0027access_type\u0027], rule[\u0027access_id\u0027],"},{"line_number":684,"context_line":"            )"},{"line_number":685,"context_line":"            rule_state_map[rule[\u0027access_id\u0027]] \u003d {\u0027state\u0027: \u0027active\u0027}"},{"line_number":686,"context_line":"        return rule_state_map"},{"line_number":687,"context_line":""},{"line_number":688,"context_line":"    def _remove_nfs_rule(self, fs_name, rule):"},{"line_number":689,"context_line":"        \"\"\"Remove NFS permissions associated with an access rule."}],"source_content_type":"text/x-python","patch_set":7,"id":"a232fea5_065db0e7","line":686,"range":{"start_line":678,"start_character":8,"end_line":686,"end_character":29},"updated":"2026-06-17 23:14:17.000000000","message":"In the description , you describe setting all rules to \"error\". \n\nthey\u0027re being set to \"active\u0027 here. I\u0027d prefer \"active\".","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":683,"context_line":"                rule[\u0027access_type\u0027], rule[\u0027access_id\u0027],"},{"line_number":684,"context_line":"            )"},{"line_number":685,"context_line":"            rule_state_map[rule[\u0027access_id\u0027]] \u003d {\u0027state\u0027: \u0027active\u0027}"},{"line_number":686,"context_line":"        return rule_state_map"},{"line_number":687,"context_line":""},{"line_number":688,"context_line":"    def _remove_nfs_rule(self, fs_name, rule):"},{"line_number":689,"context_line":"        \"\"\"Remove NFS permissions associated with an access rule."}],"source_content_type":"text/x-python","patch_set":7,"id":"4eef839f_c9416761","line":686,"in_reply_to":"a232fea5_065db0e7","updated":"2026-06-22 11:44:28.000000000","message":"PS8: confirmed — WEKAFS rules are reported \u0027active\u0027; corrected the doc that previously said \u0027error\u0027.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":696,"context_line":"            perm_fs \u003d perm.get(\u0027filesystem\u0027, perm.get(\u0027filesystem_id\u0027, \u0027\u0027))"},{"line_number":697,"context_line":"            if perm_fs \u003d\u003d fs_name:"},{"line_number":698,"context_line":"                # Match by client group name which encodes the rule ID."},{"line_number":699,"context_line":"                cg_name \u003d perm.get(\u0027group\u0027, perm.get(\u0027client_group_name\u0027, \u0027\u0027))"},{"line_number":700,"context_line":"                if rule[\u0027access_id\u0027][:8] in cg_name:"},{"line_number":701,"context_line":"                    self._client.delete_nfs_permission(perm[\u0027uid\u0027])"},{"line_number":702,"context_line":""},{"line_number":703,"context_line":"    def _remove_all_nfs_permissions(self, fs_name):"},{"line_number":704,"context_line":"        \"\"\"Remove all NFS permissions for a filesystem (used during delete)."}],"source_content_type":"text/x-python","patch_set":7,"id":"abab578a_768babce","line":701,"range":{"start_line":699,"start_character":16,"end_line":701,"end_character":67},"updated":"2026-06-17 23:14:17.000000000","message":"does the client group itself get automatically deleted?","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":698,"context_line":"                # Match by client group name which encodes the rule ID."},{"line_number":699,"context_line":"                cg_name \u003d perm.get(\u0027group\u0027, perm.get(\u0027client_group_name\u0027, \u0027\u0027))"},{"line_number":700,"context_line":"                if rule[\u0027access_id\u0027][:8] in cg_name:"},{"line_number":701,"context_line":"                    self._client.delete_nfs_permission(perm[\u0027uid\u0027])"},{"line_number":702,"context_line":""},{"line_number":703,"context_line":"    def _remove_all_nfs_permissions(self, fs_name):"},{"line_number":704,"context_line":"        \"\"\"Remove all NFS permissions for a filesystem (used during delete)."}],"source_content_type":"text/x-python","patch_set":7,"id":"e6a5c9ac_bc0a0df1","line":701,"in_reply_to":"abab578a_768babce","updated":"2026-06-22 11:44:28.000000000","message":"Yes — removing a rule reclaims its Weka client group (both _remove_nfs_rule and _remove_all_nfs_permissions delete the group), so there is no leak.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":820,"context_line":"                \u0027pool_name\u0027: group_name,"},{"line_number":821,"context_line":"                \u0027total_capacity_gb\u0027: weka_utils.bytes_to_gb(total_bytes),"},{"line_number":822,"context_line":"                \u0027free_capacity_gb\u0027: weka_utils.bytes_to_gb(free_bytes),"},{"line_number":823,"context_line":"                \u0027reserved_percentage\u0027: 0,"},{"line_number":824,"context_line":"                \u0027reserved_snapshot_percentage\u0027: 0,"},{"line_number":825,"context_line":"                \u0027reserved_share_extend_percentage\u0027: 0,"},{"line_number":826,"context_line":"            }],"}],"source_content_type":"text/x-python","patch_set":7,"id":"22d06462_b15661f7","line":823,"range":{"start_line":823,"start_character":39,"end_line":823,"end_character":40},"updated":"2026-06-17 23:14:17.000000000","message":"no, this has to be read from configuration.. this, and the opts below are common configuration options for all drivers","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":820,"context_line":"                \u0027pool_name\u0027: group_name,"},{"line_number":821,"context_line":"                \u0027total_capacity_gb\u0027: weka_utils.bytes_to_gb(total_bytes),"},{"line_number":822,"context_line":"                \u0027free_capacity_gb\u0027: weka_utils.bytes_to_gb(free_bytes),"},{"line_number":823,"context_line":"                \u0027reserved_percentage\u0027: 0,"},{"line_number":824,"context_line":"                \u0027reserved_snapshot_percentage\u0027: 0,"},{"line_number":825,"context_line":"                \u0027reserved_share_extend_percentage\u0027: 0,"},{"line_number":826,"context_line":"            }],"}],"source_content_type":"text/x-python","patch_set":7,"id":"af6fcdc9_60578547","line":823,"in_reply_to":"22d06462_b15661f7","updated":"2026-06-22 11:44:28.000000000","message":"PS8: reserved_percentage and max_over_subscription_ratio are now read from configuration.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":831,"context_line":"    # Manage / unmanage"},{"line_number":832,"context_line":"    # ------------------------------------------------------------------"},{"line_number":833,"context_line":""},{"line_number":834,"context_line":"    def manage_existing(self, share, driver_options):"},{"line_number":835,"context_line":"        \"\"\"Bring an existing Weka filesystem under Manila management."},{"line_number":836,"context_line":""},{"line_number":837,"context_line":"        :param share: Share model (share[\u0027export_locations\u0027] holds the path)."}],"source_content_type":"text/x-python","patch_set":7,"id":"e41aca54_e65e6684","line":834,"range":{"start_line":834,"start_character":8,"end_line":834,"end_character":23},"updated":"2026-06-17 23:14:17.000000000","message":"Do you need to clear any access rules when managing?\n\n\nAfter bringing an existing share under Manila management, the driver\nmust ensure the share is in an \"unexported\" state with all existing\naccess rules removed. Users must explicitly request access through\nManila after the share is managed.\n\n\nIf a Weka filesystem already has NFS permissions or client groups\nconfigured, those remain in place after `manage_existing` returns. Manila\nwon\u0027t know about them, creating a security-relevant inconsistency: the\nshare has access rules that Manila cannot see, modify, or revoke.\n\nSo i\u0027d call `_remove_all_nfs_permissions(fs_name)` (and clean up\nassociated client groups) before returning from `manage_existing`.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":831,"context_line":"    # Manage / unmanage"},{"line_number":832,"context_line":"    # ------------------------------------------------------------------"},{"line_number":833,"context_line":""},{"line_number":834,"context_line":"    def manage_existing(self, share, driver_options):"},{"line_number":835,"context_line":"        \"\"\"Bring an existing Weka filesystem under Manila management."},{"line_number":836,"context_line":""},{"line_number":837,"context_line":"        :param share: Share model (share[\u0027export_locations\u0027] holds the path)."}],"source_content_type":"text/x-python","patch_set":7,"id":"82fcc7ad_3e13820a","line":834,"in_reply_to":"e41aca54_e65e6684","updated":"2026-06-22 11:44:28.000000000","message":"PS8: manage_existing now calls _remove_all_nfs_permissions so the managed share starts unexported and Manila owns access control.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":865,"context_line":"        size_gb \u003d max(1, int(weka_utils.bytes_to_gb(size_bytes)))"},{"line_number":866,"context_line":"        fs_uid \u003d fs.get(\u0027uid\u0027) or fs.get(\u0027id\u0027, \u0027\u0027)"},{"line_number":867,"context_line":""},{"line_number":868,"context_line":"        LOG.info("},{"line_number":869,"context_line":"            \"Managing existing share %s (FS \u0027%s\u0027, size %s GiB)\","},{"line_number":870,"context_line":"            share[\u0027id\u0027], fs_name, size_gb,"},{"line_number":871,"context_line":"        )"},{"line_number":872,"context_line":"        share_proto \u003d share.get(\u0027share_proto\u0027, _WEKAFS_PROTO).upper()"},{"line_number":873,"context_line":"        export_locations \u003d self._build_export_locations("},{"line_number":874,"context_line":"            share, fs_name, fs_uid, share_proto)"}],"source_content_type":"text/x-python","patch_set":7,"id":"8355d4b2_bb5101db","line":871,"range":{"start_line":868,"start_character":8,"end_line":871,"end_character":9},"updated":"2026-06-17 23:14:17.000000000","message":"Log after the work is done.. Logging info prior to the work isn\u0027t useful, use debug if it is necessary for debugging purposes","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":868,"context_line":"        LOG.info("},{"line_number":869,"context_line":"            \"Managing existing share %s (FS \u0027%s\u0027, size %s GiB)\","},{"line_number":870,"context_line":"            share[\u0027id\u0027], fs_name, size_gb,"},{"line_number":871,"context_line":"        )"},{"line_number":872,"context_line":"        share_proto \u003d share.get(\u0027share_proto\u0027, _WEKAFS_PROTO).upper()"},{"line_number":873,"context_line":"        export_locations \u003d self._build_export_locations("},{"line_number":874,"context_line":"            share, fs_name, fs_uid, share_proto)"}],"source_content_type":"text/x-python","patch_set":7,"id":"59b5d334_6d9ad593","line":871,"in_reply_to":"8355d4b2_bb5101db","updated":"2026-06-22 11:44:28.000000000","message":"PS8: moved the info log after the work completes / downgraded the pre-work line to debug.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"272d86688d3d8c1af0196fca7b23f94b78173575","unresolved":true,"context_lines":[{"line_number":67,"context_line":"  - create_share_from_snapshot runs the data copy in a background"},{"line_number":68,"context_line":"    eventlet greenlet.  If the manila-share process restarts mid-copy"},{"line_number":69,"context_line":"    the in-memory status is lost; get_share_status will conservatively"},{"line_number":70,"context_line":"    return \u0027available\u0027 in that case.  The NFS copy path requires"},{"line_number":71,"context_line":"    weka_nfs_server to be configured; an unconfigured NFS share raises"},{"line_number":72,"context_line":"    ShareBackendException before filesystem creation begins."},{"line_number":73,"context_line":"\"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"4cd781c3_c54075f4","line":70,"range":{"start_line":70,"start_character":12,"end_line":70,"end_character":21},"updated":"2026-06-25 08:18:32.000000000","message":"shouldn\u0027t it return \"error\" if it is conservative?\n\nDoing so will allow the user to delete the new/error share and re-attempt the cloning","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f9a5fb54eefb6309fa69b34e5658b3b30bcf17a6","unresolved":false,"context_lines":[{"line_number":67,"context_line":"  - create_share_from_snapshot runs the data copy in a background"},{"line_number":68,"context_line":"    eventlet greenlet.  If the manila-share process restarts mid-copy"},{"line_number":69,"context_line":"    the in-memory status is lost; get_share_status will conservatively"},{"line_number":70,"context_line":"    return \u0027available\u0027 in that case.  The NFS copy path requires"},{"line_number":71,"context_line":"    weka_nfs_server to be configured; an unconfigured NFS share raises"},{"line_number":72,"context_line":"    ShareBackendException before filesystem creation begins."},{"line_number":73,"context_line":"\"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"0d3cb481_fdfd68e2","line":70,"in_reply_to":"4cd781c3_c54075f4","updated":"2026-07-03 07:04:54.000000000","message":"Good point — fixed in PS12. get_share_status now returns \u0027error\u0027 (not \u0027available\u0027) when the in-memory copy state is missing after a process restart, so the user can delete the new/error share and re-attempt the clone.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"272d86688d3d8c1af0196fca7b23f94b78173575","unresolved":true,"context_lines":[{"line_number":79,"context_line":"import threading"},{"line_number":80,"context_line":"import time"},{"line_number":81,"context_line":""},{"line_number":82,"context_line":"import eventlet"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"from oslo_config import cfg"},{"line_number":85,"context_line":"from oslo_log import log as logging"}],"source_content_type":"text/x-python","patch_set":11,"id":"8f5ac53a_a56e1938","line":82,"range":{"start_line":82,"start_character":0,"end_line":82,"end_character":15},"updated":"2026-06-25 08:18:32.000000000","message":"hard -2 here. \n\nWe\u0027re actively getting rid of eventlet. Please use native python threads: https://governance.openstack.org/tc/goals/selected/remove-eventlet.html","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"f9a5fb54eefb6309fa69b34e5658b3b30bcf17a6","unresolved":false,"context_lines":[{"line_number":79,"context_line":"import threading"},{"line_number":80,"context_line":"import time"},{"line_number":81,"context_line":""},{"line_number":82,"context_line":"import eventlet"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"from oslo_config import cfg"},{"line_number":85,"context_line":"from oslo_log import log as logging"}],"source_content_type":"text/x-python","patch_set":11,"id":"12ef2dbe_ec4592d4","line":82,"in_reply_to":"8f5ac53a_a56e1938","updated":"2026-07-03 07:04:54.000000000","message":"Fixed in PS12: the eventlet.spawn call in create_share_from_snapshot is replaced with a native daemon threading.Thread, and the eventlet dependency is removed. Aligns with the community goal to remove eventlet.","commit_id":"66234b2e8aa8af28f6b413b321136285068d5525"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"c6aa4e04b333ca14f197629f2d33faba32df08d8","unresolved":true,"context_lines":[{"line_number":1042,"context_line":""},{"line_number":1043,"context_line":"        # Full-sync mode: Manila passes the full rule set in access_rules"},{"line_number":1044,"context_line":"        # with empty add/delete/update lists."},{"line_number":1045,"context_line":"        if not add_rules and not delete_rules and not update_rules:"},{"line_number":1046,"context_line":"            add_rules \u003d list(access_rules or [])"},{"line_number":1047,"context_line":""},{"line_number":1048,"context_line":"        # Access-level updates re-apply through the same idempotent path"}],"source_content_type":"text/x-python","patch_set":15,"id":"e53433a8_ee38c0f8","line":1045,"updated":"2026-08-08 07:05:45.000000000","message":"when `add_rules` and `delete_rules` are both empty, \"drivers should ensure that the rules present in `access_rules` are the same as those on the back end.\" This line treats full-sync as add-only (`add_rules \u003d list(access_rules or [])`) but never removes any stale backend resources. For NFS, orphaned `manila-*` client groups persist; for WEKAFS, orphaned security policies persist. This means access that Manila considers revoked could still be active on the backend after full-sync. Would you be able to list existing backend resources for the share, diff against `access_rules`, and remove the ones that are no longer present?","commit_id":"edc2a4d6d18cd31f020286bef66abe2bb2a22059"}],"manila/share/drivers/weka/posix.py":[{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"5bdd0ef9a34cc499d68c33e153ead8a47a9e0371","unresolved":false,"context_lines":[{"line_number":87,"context_line":"    :param sync_on_close: Flush on close (default False)."},{"line_number":88,"context_line":"    :param max_io_size: Override maximum IO size in bytes (optional)."},{"line_number":89,"context_line":"    :param iops_limit: IOPS limit for this mount (optional)."},{"line_number":90,"context_line":"    :param execute: Callable for shell commands (default: processutils.execute)."},{"line_number":91,"context_line":"    \"\"\""},{"line_number":92,"context_line":""},{"line_number":93,"context_line":"    def __init__(self, backends, fs_name, mount_point,"}],"source_content_type":"text/x-python","patch_set":7,"id":"22a2d489_0b72b540","line":90,"updated":"2026-06-17 14:43:50.000000000","message":"pep8: E501 line too long (80 \u003e 79 characters)","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"}],"manila/share/drivers/weka/utils.py":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"c6aa4e04b333ca14f197629f2d33faba32df08d8","unresolved":true,"context_lines":[{"line_number":92,"context_line":"    return sanitized"},{"line_number":93,"context_line":""},{"line_number":94,"context_line":""},{"line_number":95,"context_line":"def build_export_location(backends, fs_name, is_admin_only\u003dFalse,"},{"line_number":96,"context_line":"                          preferred\u003dTrue, metadata\u003dNone):"},{"line_number":97,"context_line":"    \"\"\"Build a Manila export location dict for a WekaFS share."},{"line_number":98,"context_line":""}],"source_content_type":"text/x-python","patch_set":15,"id":"4d1f8f3c_7ab82452","line":95,"updated":"2026-08-08 07:05:45.000000000","message":"`build_export_location()` is not called anywhere in the driver — only from its own tests. Remove this and its tests.","commit_id":"edc2a4d6d18cd31f020286bef66abe2bb2a22059"}],"manila/tests/unit/share/drivers/weka/fakes.py":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"3844236ac1ca4d535804df00f94f68398694b165","unresolved":true,"context_lines":[{"line_number":187,"context_line":""},{"line_number":188,"context_line":""},{"line_number":189,"context_line":"def fake_access_rule(rule_id\u003dNone, access_type\u003d\u0027ip\u0027,"},{"line_number":190,"context_line":"                     access_to\u003d\u002710.0.0.0/24\u0027,"},{"line_number":191,"context_line":"                     access_level\u003d\u0027rw\u0027):"},{"line_number":192,"context_line":"    return {"},{"line_number":193,"context_line":"        \u0027access_id\u0027: rule_id or _uid(),"}],"source_content_type":"text/x-python","patch_set":7,"id":"9b4c8f27_bc204616","line":190,"range":{"start_line":190,"start_character":32,"end_line":190,"end_character":43},"updated":"2026-06-17 23:14:17.000000000","message":"This uses a private (RFC 1918) address range. Per project/documentatiom conventions, test data and examples should use RFC 5737 documentation ranges: `192.0.2.0/24` (TEST-NET-1), `198.51.100.0/24` (TEST-NET-2), or `203.0.113.0/24` (TEST-NET-3).","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"},{"author":{"_account_id":39160,"name":"Assaf Giladi","display_name":"Assaf","email":"assaf@weka.io","username":"Assaf"},"change_message_id":"5e42d19f5b2d63c9e1643e05acdac417c1c7fe04","unresolved":false,"context_lines":[{"line_number":187,"context_line":""},{"line_number":188,"context_line":""},{"line_number":189,"context_line":"def fake_access_rule(rule_id\u003dNone, access_type\u003d\u0027ip\u0027,"},{"line_number":190,"context_line":"                     access_to\u003d\u002710.0.0.0/24\u0027,"},{"line_number":191,"context_line":"                     access_level\u003d\u0027rw\u0027):"},{"line_number":192,"context_line":"    return {"},{"line_number":193,"context_line":"        \u0027access_id\u0027: rule_id or _uid(),"}],"source_content_type":"text/x-python","patch_set":7,"id":"d91bace8_a237c58c","line":190,"in_reply_to":"9b4c8f27_bc204616","updated":"2026-06-22 11:44:28.000000000","message":"PS8: switched example IPs to RFC 5737 documentation ranges.","commit_id":"9783b8ceb645b9c87b73b036e90f79437000ce53"}]}
