)]}'
{"id":"openstack%2Fmistral~1001632","triplet_id":"openstack%2Fmistral~master~I695f3bddc51d7fd553759d74ba89426a2908bb17","project":"openstack/mistral","branch":"master","hashtags":[],"change_id":"I695f3bddc51d7fd553759d74ba89426a2908bb17","subject":"Add an outbound egress policy to std.http and the webhook notifier","status":"MERGED","created":"2026-08-20 09:13:51.000000000","updated":"2026-08-21 09:18:03.000000000","submitted":"2026-08-21 09:17:12.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1001632","meta_rev_id":"f7eeb14cd8e01a0ee9703037e2a45255e52ddb90","_number":1001632,"virtual_id_number":1001632,"owner":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:gate","value":2,"date":"2026-08-21 09:17:11.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"all":[{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2026-08-21 08:31:17.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"all":[{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":1,"date":"2026-08-21 08:31:17.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-20 09:47:10.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"1732438f46f964c996c9867b3283d8fccac20a08","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"date":"2026-08-20 09:13:51.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"3f616c591ecef8300d26b70fd414701c8d3e2c22","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-20 09:47:10.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/483bff4ab34d4041bf78a6a2398fd037\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/f278da336b9240aa931027381e374126 : SUCCESS in 2m 55s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/c1caa62a79304e70a9dd2e44ced3150b : SUCCESS in 10m 28s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/5b1ac6c385a54a3a9f13988ff5bf8504 : SUCCESS in 8m 50s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/5ec2fe48aa1247a4be54c56aa700186d : SUCCESS in 11m 00s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/963ada4594e4431ebf18352fc25a492e : SUCCESS in 6m 27s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/2670241a9c11498a9517f4e654bc6c9e : SUCCESS in 3m 05s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f7c42209ec5d4903b20ed11d22f12931 : SUCCESS in 13m 47s (non-voting)\n- mistral-devstack https://zuul.opendev.org/t/openstack/build/8b6d6af6e707458d8bf0497d560386b2 : SUCCESS in 31m 40s\n- mistral-devstack-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/06a178db21304618832055f3a03b7976 : SUCCESS in 26m 23s","accounts_in_message":[],"_revision_number":1},{"id":"96233cd64069e7786d1f08455c680724107dcf3d","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"date":"2026-08-20 12:10:58.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"476c5cd84a9783451fcde2a14db570d9b5f8d93a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-20 13:17:02.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/13e6752e4ada40d49b817bd7191a2079\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/68ca45d1cd444fca8b3c44a744036aa4 : SUCCESS in 4m 59s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/14e865fe16c54ed28b604a75b1a03bce : SUCCESS in 11m 39s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/d467b19ce32e44418674fe416b49d6cc : SUCCESS in 12m 01s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/4df30e05cf5349798adc400674ea5cf5 : SUCCESS in 13m 49s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/7c3d6bbdad2d4b1a9d502cf64236095b : SUCCESS in 8m 22s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/67c8100327f94950a96bbc60b8800c1f : SUCCESS in 5m 37s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c7f0825505fd436d95c4f49221e4da69 : SUCCESS in 15m 42s (non-voting)\n- mistral-devstack https://zuul.opendev.org/t/openstack/build/982afe104ff2441ea907bbb3039e8dbd : SUCCESS in 38m 27s\n- mistral-devstack-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/8d6ef072b0154ef7a60d9197f8485220 : SUCCESS in 41m 34s","accounts_in_message":[],"_revision_number":2},{"id":"a6ffd804252cd7e355725626b279a6a66119aee4","author":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"date":"2026-08-21 08:31:17.000000000","message":"Patch Set 2: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":2},{"id":"66001d3cc602679b616559da04cc1c8c6229ceb5","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-21 08:31:46.000000000","message":"Patch Set 2: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":2},{"id":"5319ad430da758fd937f7ceba8b6adaa724b8fa6","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-21 09:17:11.000000000","message":"Patch Set 2: Verified+2\n\nBuild succeeded (gate pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/8d27cbf530f14a0385c3d079587eb9ec\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/4462608fc1f547dc9866d78d9e7ea3e2 : SUCCESS in 4m 04s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/7ec79cec4a0f49258b1a590608a2926d : SUCCESS in 11m 01s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/b40674ee7f0f401b972616ad19f1a6da : SUCCESS in 10m 19s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/08587f8a8b334cfebe719c81cdae9318 : SUCCESS in 8m 27s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/a20e9dd97320480886db3ec02546b6c4 : SUCCESS in 4m 33s\n- mistral-devstack https://zuul.opendev.org/t/openstack/build/e0254fd150d443778ef55aa5404bd1e8 : SUCCESS in 39m 48s\n- mistral-devstack-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/034531c3d08e44fd9535e6c95e81f849 : SUCCESS in 40m 34s","accounts_in_message":[],"_revision_number":2},{"id":"ee8b710a63df72dd456c34b66aab629f77123881","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-21 09:17:12.000000000","message":"Change has been successfully merged","accounts_in_message":[],"_revision_number":2},{"id":"f7eeb14cd8e01a0ee9703037e2a45255e52ddb90","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-21 09:18:03.000000000","message":"Patch Set 2:\n\nBuild succeeded (promote pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/643ae60c5ad44102a1edf7309145dc2e\n\n- promote-openstack-tox-docs https://zuul.opendev.org/t/openstack/build/fe8c26ca44c8439e92cb5fceb36d0782 : SUCCESS in 40s\n- promote-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/1b48c02ae2fb40d9a621436053e878bb : SUCCESS in 38s","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"88508624e2002737353bdb4283fbc17ac3e6d7fb","revisions":{"6ad1768db8a9acd9ff2e232187bfbea4ef1fa4de":{"kind":"REWORK","_number":1,"created":"2026-08-20 09:13:51.000000000","uploader":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"ref":"refs/changes/32/1001632/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/mistral","ref":"refs/changes/32/1001632/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/mistral refs/changes/32/1001632/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/mistral refs/changes/32/1001632/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/mistral refs/changes/32/1001632/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/mistral refs/changes/32/1001632/1"}}},"commit":{"parents":[{"commit":"e07375b0f8dc64e1002e0f717d451fdb6b1bd49a","subject":"Set up logging in the WSGI entry point","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/mistral/commit/e07375b0f8dc64e1002e0f717d451fdb6b1bd49a"}]}],"author":{"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","date":"2026-08-20 09:06:14.000000000","tz":120},"committer":{"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","date":"2026-08-20 09:12:23.000000000","tz":120},"subject":"Add an outbound egress policy to std.http and the webhook notifier","message":"Add an outbound egress policy to std.http and the webhook notifier\n\nThe std.http action and the webhook notifier passed a user-supplied\nURL straight to requests with no validation, so any authenticated\ntenant able to define/run a workflow could make the executor/engine\nreach the cloud metadata service (169.254.169.254) or internal-only\nendpoints - a readable SSRF via std.http (the response is returned as\nthe action result) and a blind SSRF via the webhook notify param.\n\nAdd mistral/utils/egress.py:validate_url(), called from HTTPAction.run\nand WebhookPublisher.publish. It rejects non-http(s) schemes and\nresolves the host, rejecting any request whose target resolves to a\ndenied CIDR (this also defeats a public hostname resolving to an\ninternal IP).\n\nThe deny-list is entirely operator-controlled via\n[action_std_http] denied_cidrs, which defaults to loopback and\nlink-local so the metadata service and localhost are blocked out of\nthe box. An operator can widen it (e.g. add RFC1918) or narrow it -\neven to an empty list - to re-enable those targets, since keeping\nstd.http reachable is a deliberate operator choice; operators who do\nnot want the action at all can disable it via the action provider\ndenylist. An optional [action_std_http] allowed_hosts restricts\nconnections to an explicit allow-list.\n\nAlso bound std.http resource usage: a default request timeout\n([action_std_http] default_timeout, default 60s) applied when the\naction does not set its own, and an optional response-size cap\n([action_std_http] max_response_size_bytes, default 0 \u003d disabled)\nchecked against Content-Length before buffering. The webhook notifier\nno longer follows redirects and uses a bounded timeout.\n\nGenerated-By: Claude Fable 5 (Anthropic AI assistant)\nSigned-off-by: Arnaud Morin \u003carnaud.morin@gmail.com\u003e\nChange-Id: I695f3bddc51d7fd553759d74ba89426a2908bb17\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/mistral/commit/6ad1768db8a9acd9ff2e232187bfbea4ef1fa4de"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/mistral/commit/6ad1768db8a9acd9ff2e232187bfbea4ef1fa4de"}]},"branch":"refs/heads/master"},"88508624e2002737353bdb4283fbc17ac3e6d7fb":{"kind":"REWORK","_number":2,"created":"2026-08-20 12:10:58.000000000","uploader":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"},"ref":"refs/changes/32/1001632/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/mistral","ref":"refs/changes/32/1001632/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/mistral refs/changes/32/1001632/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/mistral refs/changes/32/1001632/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/mistral refs/changes/32/1001632/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/mistral refs/changes/32/1001632/2"}}},"commit":{"parents":[{"commit":"9a74696ff54b1183eb6ddad35423c30b9d290442","subject":"Merge \"Remove PostgreSQL references from the documentation\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/mistral/commit/9a74696ff54b1183eb6ddad35423c30b9d290442"}]}],"author":{"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","date":"2026-08-20 09:06:14.000000000","tz":120},"committer":{"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","date":"2026-08-20 12:09:30.000000000","tz":120},"subject":"Add an outbound egress policy to std.http and the webhook notifier","message":"Add an outbound egress policy to std.http and the webhook notifier\n\nThe std.http action and the webhook notifier passed a user-supplied\nURL straight to requests with no validation, so any authenticated\ntenant able to define/run a workflow could make the executor/engine\nreach the cloud metadata service (169.254.169.254) or internal-only\nendpoints - a readable SSRF via std.http (the response is returned as\nthe action result) and a blind SSRF via the webhook notify param.\n\nAdd mistral/utils/egress.py:validate_url(), called from HTTPAction.run\nand WebhookPublisher.publish. It rejects non-http(s) schemes and\nresolves the host, rejecting any request whose target resolves to a\ndenied CIDR (this also defeats a public hostname resolving to an\ninternal IP).\n\nThe deny-list is entirely operator-controlled via\n[action_std_http] denied_cidrs, which defaults to loopback and\nlink-local so the metadata service and localhost are blocked out of\nthe box. An operator can widen it (e.g. add RFC1918) or narrow it -\neven to an empty list - to re-enable those targets, since keeping\nstd.http reachable is a deliberate operator choice; operators who do\nnot want the action at all can disable it via the action provider\ndenylist. An optional [action_std_http] allowed_hosts restricts\nconnections to an explicit allow-list.\n\nAlso bound std.http resource usage: a default request timeout\n([action_std_http] default_timeout, default 60s) applied when the\naction does not set its own, and an optional response-size cap\n([action_std_http] max_response_size_bytes, default 0 \u003d disabled)\nchecked against Content-Length before buffering. The webhook notifier\nno longer follows redirects and uses a bounded timeout.\n\nGenerated-By: Claude Fable 5 (Anthropic AI assistant)\nSigned-off-by: Arnaud Morin \u003carnaud.morin@gmail.com\u003e\nChange-Id: I695f3bddc51d7fd553759d74ba89426a2908bb17\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/mistral/commit/88508624e2002737353bdb4283fbc17ac3e6d7fb"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/mistral/commit/88508624e2002737353bdb4283fbc17ac3e6d7fb"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"CLOSED","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"}},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":11583,"name":"Arnaud Morin","email":"arnaud.morin@gmail.com","username":"arnaudmorin"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dMAX"],"failing_atoms":["label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dMAX"],"failing_atoms":["label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"SATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dMAX"],"failing_atoms":["label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
