)]}'
{"id":"openstack%2Fneutron~780978","triplet_id":"openstack%2Fneutron~master~I0580bbabd1d9af7a5f2c60b63c42a977d73eeefe","project":"openstack/neutron","branch":"master","topic":"secure-rbac","hashtags":[],"change_id":"I0580bbabd1d9af7a5f2c60b63c42a977d73eeefe","subject":"Relax some API policy rules to make them available for project admins","status":"ABANDONED","created":"2021-03-16 21:13:44.000000000","updated":"2021-03-22 10:14:03.000000000","total_comment_count":15,"unresolved_comment_count":5,"has_review_started":true,"meta_rev_id":"225167bc91b82af5d84d0bfbff6e1b196a8599d5","_number":780978,"virtual_id_number":780978,"owner":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":1,"date":"2021-03-18 10:43:09.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},{"tag":"autogenerated:zuul:check","value":-1,"date":"2021-03-18 11:35:25.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"disliked":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},{"value":0,"date":"2021-03-22 08:43:15.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},{"value":-1,"date":"2021-03-19 17:44:26.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":-1,"default_value":0,"optional":true},"Workflow":{"rejected":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},{"value":-1,"date":"2021-03-19 07:45:02.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":2},"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},{"value":0,"date":"2021-03-22 10:13:28.000000000","permitted_voting_range":{"min":-1,"max":2},"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},{"value":0,"permitted_voting_range":{"min":-1,"max":2},"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Branch Freeze"," 0":"No Priority","+1":"Important Change","+2":"Gate Blocker Fix / Urgent Change"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]}],"REVIEWER":[{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-03-16 21:17:52.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"state":"CC"},{"updated":"2021-03-16 21:17:52.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":9954,"name":"Lance Bragstad","username":"lbragstad","inactive":true},"state":"REVIEWER"},{"updated":"2021-03-16 22:05:31.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2021-03-16 23:23:00.000000000","updated_by":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"reviewer":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2021-03-16 23:26:30.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-03-16 23:27:07.000000000","updated_by":{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},"reviewer":{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-03-17 11:57:15.000000000","updated_by":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"reviewer":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"state":"REVIEWER"},{"updated":"2021-03-18 08:27:26.000000000","updated_by":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"reviewer":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"state":"REVIEWER"},{"updated":"2021-03-18 09:23:17.000000000","updated_by":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"reviewer":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"state":"CC"},{"updated":"2021-03-18 09:24:43.000000000","updated_by":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"reviewer":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"state":"REVIEWER"}],"messages":[{"id":"fb818e7927e1398e35b488a66412fd133fcba444","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-16 21:13:44.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"e62439dcb3269164d5c718e68b2614e9d5efb98c","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-03-16 21:17:39.000000000","message":"Topic bp/secure-rbac-roles removed","accounts_in_message":[],"_revision_number":1},{"id":"e3f2463180b3188f709e21eaf9e6fe54f061c8c8","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"date":"2021-03-16 21:17:44.000000000","message":"Topic set to secure-rbac","accounts_in_message":[],"_revision_number":1},{"id":"a06bd4133976ee702cd24d4cd5c8c507a308fa89","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-16 22:05:31.000000000","message":"Patch Set 1:\n\nBuild succeeded (ARM64 pipeline).\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/8fe279f83f674bc9ae4d403f39cf1303 : SUCCESS in 45m 45s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/c5cc24740360459bbc2b8e2a0b38a86b : SUCCESS in 39m 51s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"49dfbc53c410d9da00e31359de93253e7f430f8c","author":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"date":"2021-03-16 23:23:00.000000000","message":"Patch Set 1:\n\nMerge Failed.\n\nThis change or one of its cross-repo dependencies was unable to be automatically merged with the current state of its repository. Please rebase the change and upload a new patchset.\nTo re-run the job post \u0027recheck neutron-mlnx\u0027 comment. For more information visit https://wiki.openstack.org/wiki/ThirdPartySystems/Mellanox_CI","accounts_in_message":[],"_revision_number":1},{"id":"fa1f475a56a88df2ceae21162c6abf0f9208d7ce","tag":"autogenerated:jenkins-gerrit-trigger","author":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"date":"2021-03-16 23:23:41.000000000","message":"Patch Set 1:\n\nBuild Failed \n\n* SRIOV-neutron-macvtap http://13.74.249.42/refs/changes/78/780978/1/SRIOV-neutron-macvtap : ABORTED\n\n* SRIOV-neutron-direct http://13.74.249.42/refs/changes/78/780978/1/SRIOV-neutron-direct : ABORTED","accounts_in_message":[],"_revision_number":1},{"id":"4b6dfeb5868cea8e8ad15d8bf7afd764a706cb57","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-16 23:26:30.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- neutron-tempest-plugin-api https://zuul.opendev.org/t/openstack/build/36360448ac7e4a6cb416b8dfcb4123dc : SUCCESS in 52m 55s\n- neutron-tempest-plugin-scenario-linuxbridge https://zuul.opendev.org/t/openstack/build/69850121ba134430848d563a44982dbd : SUCCESS in 1h 46m 33s\n- neutron-tempest-plugin-scenario-openvswitch https://zuul.opendev.org/t/openstack/build/848c2548cb8249c2ac1a48fc5a4ffc62 : SUCCESS in 1h 49m 18s\n- neutron-tempest-plugin-scenario-openvswitch-iptables_hybrid https://zuul.opendev.org/t/openstack/build/b59bfb2c547e46118179dbfdf83237cd : SUCCESS in 1h 32m 13s\n- neutron-tempest-plugin-scenario-ovn https://zuul.opendev.org/t/openstack/build/5167cc01d0c3493db71fc44b31ff6e5b : SUCCESS in 2h 07m 15s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/477663b569f24852ac8ba3df21482855 : SUCCESS in 45m 15s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/5818fca08c274d25891f480cd9e0c5c3 : SUCCESS in 38m 37s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/29716d377a79455ba77bcb21e78b6743 : SUCCESS in 13m 31s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/534a408c78634615bd9c3c3eca2f503a : SUCCESS in 36m 36s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/3c08784c5eb44560be43cd50c7b93783 : SUCCESS in 32m 57s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/cc205421c3564126b835726902bf59b1 : SUCCESS in 24m 30s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e6942e80a94941e0adf08fdf182c73b3 : SUCCESS in 9m 26s\n- neutron-functional-with-uwsgi https://zuul.opendev.org/t/openstack/build/b1b21a0456924805b1e0668a0982920c : SUCCESS in 44m 41s\n- neutron-fullstack-with-uwsgi https://zuul.opendev.org/t/openstack/build/b19d3e0b8ea64c0791fb425c6b830780 : SUCCESS in 1h 31m 34s\n- neutron-rally-task https://zuul.opendev.org/t/openstack/build/58c45cb8f24f4188afa55168256a59e7 : SUCCESS in 1h 08m 37s\n- neutron-grenade-multinode https://zuul.opendev.org/t/openstack/build/a137c8738f814026a545cb6878303a7f : SUCCESS in 58m 00s\n- neutron-grenade-dvr-multinode https://zuul.opendev.org/t/openstack/build/6833ee6b5d12410f8310f525c74c0069 : SUCCESS in 1h 10m 55s\n- neutron-tempest-multinode-full-py3 https://zuul.opendev.org/t/openstack/build/756b43ef0e054628875bf757d72c725e : SUCCESS in 1h 06m 58s\n- neutron-tempest-dvr-ha-multinode-full https://zuul.opendev.org/t/openstack/build/854fb7ce54a04eb19bdb02ad38ae2d8a : SUCCESS in 1h 22m 06s (non-voting)\n- neutron-tempest-slow-py3 https://zuul.opendev.org/t/openstack/build/6eedc0a2a42146988a25b964573eb5e7 : SUCCESS in 1h 16m 02s\n- neutron-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/96bd73fdc5154ad8a1fa8bb34215e44a : SUCCESS in 1h 16m 59s\n- neutron-ovn-tempest-ovs-release https://zuul.opendev.org/t/openstack/build/d28ddd0e0c484397aa3f1f47ec86c725 : SUCCESS in 1h 14m 38s\n- neutron-ovn-tempest-ovs-release-ipv6-only https://zuul.opendev.org/t/openstack/build/2732d47ce52c40a3bda14bca76e85df0 : SUCCESS in 37m 59s\n- neutron-ovn-rally-task https://zuul.opendev.org/t/openstack/build/85c1de817d9e4b85a369b072b80f1564 : SUCCESS in 1h 13m 35s (non-voting)\n- neutron-ovn-tempest-slow https://zuul.opendev.org/t/openstack/build/087ef63bb1394dc2b7b4b38662c976e8 : SUCCESS in 1h 26m 38s","accounts_in_message":[],"_revision_number":1},{"id":"51de893ce1634aec83257863fc65ea5547c7b9a2","author":{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},"date":"2021-03-16 23:27:07.000000000","message":"Patch Set 1: Verified+1\n\nArista third party testing PASSED [ https://arista-openstack-ci.arista.com:8000/March-2021/Arista_Tempest_Testrefs/changes/78/780978/1 ]\n\nFor testing details or any questions please check https://wiki.openstack.org/wiki/Arista-third-party-testing","accounts_in_message":[],"_revision_number":1},{"id":"ff01ef529b32b026403c499c0f2ab4c10e87a105","tag":"autogenerated:jenkins-gerrit-trigger","author":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"date":"2021-03-17 03:47:41.000000000","message":"Patch Set 1:\n\nBuild Successful \n\n* SRIOV-neutron-macvtap http://13.74.249.42/refs/changes/78/780978/1/SRIOV-neutron-macvtap : SUCCESS\n\n* SRIOV-neutron-direct http://13.74.249.42/refs/changes/78/780978/1/SRIOV-neutron-direct : SUCCESS","accounts_in_message":[],"_revision_number":1},{"id":"58ef7383b64b9c45f751a565ab66f2f00df42ea9","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-17 10:07:54.000000000","message":"Patch Set 1: Review-Priority+2","accounts_in_message":[],"_revision_number":1},{"id":"26174b566c24dc3ba67a550950c80131ec426d49","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-17 11:04:39.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"5242b838b13eac4ade244de273e9b101d468289b","author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"date":"2021-03-17 11:57:15.000000000","message":"Patch Set 2: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"c3481b569249301402ee003bf526ddb3c03c5a07","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-17 12:09:57.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/976d34a3f593422c8e7b3f8884ff5369 : FAILURE in 58m 11s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/91d3edf385db4e21b327bd0586c2a521 : FAILURE in 56m 02s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"56c50ab51a7b200dce7203c05364d816a3d7065e","author":{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},"date":"2021-03-17 12:16:52.000000000","message":"Patch Set 2:\n\nArista third party testing FAILED [ https://arista-openstack-ci.arista.com:8000/March-2021/Arista_Tempest_Testrefs/changes/78/780978/2 ]\n\nFor testing details or any questions please check https://wiki.openstack.org/wiki/Arista-third-party-testing","accounts_in_message":[],"_revision_number":2},{"id":"3b2fa5c8bb564b065536377fc2574a07df8630fe","tag":"autogenerated:jenkins-gerrit-trigger","author":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"date":"2021-03-17 12:17:03.000000000","message":"Patch Set 2:\n\nBuild Successful \n\n* SRIOV-neutron-direct http://13.74.249.42/refs/changes/78/780978/2/SRIOV-neutron-direct : SUCCESS\n\n* SRIOV-neutron-macvtap http://13.74.249.42/refs/changes/78/780978/2/SRIOV-neutron-macvtap : SUCCESS","accounts_in_message":[],"_revision_number":2},{"id":"deefb0c06596a12f4be38cb05b695f78d26119f6","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-17 13:12:15.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- neutron-tempest-plugin-api https://zuul.opendev.org/t/openstack/build/51a7bbae0cb044b09d0ad64e901823ac : SUCCESS in 49m 33s\n- neutron-tempest-plugin-scenario-linuxbridge https://zuul.opendev.org/t/openstack/build/691bce844d9049589673d4e260671d1a : SUCCESS in 1h 38m 57s\n- neutron-tempest-plugin-scenario-openvswitch https://zuul.opendev.org/t/openstack/build/b9993e77c21441c68d4498e97afbc1c7 : SUCCESS in 1h 10m 18s\n- neutron-tempest-plugin-scenario-openvswitch-iptables_hybrid https://zuul.opendev.org/t/openstack/build/eff0e9e95d1e49edaf130c4d21a56421 : SUCCESS in 1h 22m 57s\n- neutron-tempest-plugin-scenario-ovn https://zuul.opendev.org/t/openstack/build/a4852761b27c48339280a9c691f25dde : SUCCESS in 2h 03m 39s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/fe454b9e08184604b5be9b9ba00d153b : FAILURE in 42m 05s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/719709a0b6104b06b46907dd43b80623 : SUCCESS in 31m 15s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/a6faee48d57b4079b7391fe45d538514 : SUCCESS in 14m 49s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/7013d28d9da34f29a1aaad3c8b874399 : FAILURE in 36m 44s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/44055092c79a40b1a8626a3bd41258ba : FAILURE in 43m 09s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/169aa3cc7f4a4cd3a69512549569c330 : FAILURE in 31m 37s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/4d020c44e7af46679f020cde2c2c0de3 : SUCCESS in 9m 54s\n- neutron-functional-with-uwsgi https://zuul.opendev.org/t/openstack/build/0e3f5d489c9740b8b7858b1420fee731 : SUCCESS in 51m 49s\n- neutron-fullstack-with-uwsgi https://zuul.opendev.org/t/openstack/build/291bea7ca504454bb7a5d324c92e9e72 : SUCCESS in 1h 31m 04s\n- neutron-rally-task https://zuul.opendev.org/t/openstack/build/c809adc419e24425ae6b4916cde9025c : SUCCESS in 1h 29m 57s\n- neutron-grenade-multinode https://zuul.opendev.org/t/openstack/build/62e4637a536d4a359e6f75ee373a2275 : SUCCESS in 1h 06m 21s\n- neutron-grenade-dvr-multinode https://zuul.opendev.org/t/openstack/build/9082fe1626464918822d9f54178759e4 : SUCCESS in 1h 03m 44s\n- neutron-tempest-multinode-full-py3 https://zuul.opendev.org/t/openstack/build/2da1fdc2542b471783a8fdc5a3a95c7f : SUCCESS in 1h 22m 00s\n- neutron-tempest-dvr-ha-multinode-full https://zuul.opendev.org/t/openstack/build/06e1780f53fc4acf9e336632150e286f : FAILURE in 1h 17m 53s (non-voting)\n- neutron-tempest-slow-py3 https://zuul.opendev.org/t/openstack/build/9b44cf6e2ca345a9ba975ddfa1f646db : SUCCESS in 1h 32m 51s\n- neutron-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/56ec4095b3a64c539b273408200dca21 : SUCCESS in 57m 57s\n- neutron-ovn-tempest-ovs-release https://zuul.opendev.org/t/openstack/build/28dd31bad2414e8eb73489bc14d927a9 : SUCCESS in 1h 05m 25s\n- neutron-ovn-tempest-ovs-release-ipv6-only https://zuul.opendev.org/t/openstack/build/ed603fe709b74eb5b0ee1aa944da1820 : SUCCESS in 34m 41s\n- neutron-ovn-rally-task https://zuul.opendev.org/t/openstack/build/567a3a082907437d9ed5ea6cc1a6ec9f : SUCCESS in 1h 30m 09s (non-voting)\n- neutron-ovn-tempest-slow https://zuul.opendev.org/t/openstack/build/1906c081d7644d74a1c671f0a3dbf266 : SUCCESS in 1h 23m 37s","accounts_in_message":[],"_revision_number":2},{"id":"36e346e2e4f16efeea0a992100e8041be5ec50b8","author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"date":"2021-03-18 07:29:16.000000000","message":"Patch Set 2:\n\nHave to wait for https://review.opendev.org/c/openstack/neutron/+/780802","accounts_in_message":[],"_revision_number":2},{"id":"93973401b1ff6c4aaaa95b147afd04328b03b5d1","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-18 07:55:31.000000000","message":"Patch Set 2:\n\nrecheck","accounts_in_message":[],"_revision_number":2},{"id":"c636cb0077f5ca01e7ca61d784b5b9f28da01812","author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"date":"2021-03-18 08:27:26.000000000","message":"Patch Set 2: Code-Review-1\n\n(7 comments)\n\nSome related questions","accounts_in_message":[],"_revision_number":2},{"id":"5ae88afaa3b7bdf9411ab5aca85ff967c83a91cc","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-18 08:38:37.000000000","message":"Patch Set 2:\n\nBuild succeeded (ARM64 pipeline).\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/None : NODE_FAILURE in 0s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/None : NODE_FAILURE in 0s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"55dec51c6d0a98a39e7c0dd6253372c510bd1acd","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-18 09:07:56.000000000","message":"Patch Set 2:\n\n(7 comments)","accounts_in_message":[],"_revision_number":2},{"id":"b9c569f039d4043b535f85ac7499f843006b75d4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-18 09:08:13.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"0c6c9146c6e24f3659fe83f7605a82c2777c8c5c","tag":"autogenerated:jenkins-gerrit-trigger","author":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"date":"2021-03-18 09:10:30.000000000","message":"Patch Set 2:\n\nBuild Failed \n\n* SRIOV-neutron-direct http://13.74.249.42/refs/changes/78/780978/2/SRIOV-neutron-direct : ABORTED\n\n* SRIOV-neutron-macvtap http://13.74.249.42/refs/changes/78/780978/2/SRIOV-neutron-macvtap : SUCCESS","accounts_in_message":[],"_revision_number":2},{"id":"f2dc5b48594f36b42f7fad9862627c3f56291398","author":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"date":"2021-03-18 09:23:17.000000000","message":"Patch Set 3:\n\nWhile I understand the motivation of this change, I concerns this change.\nOnce we migrated the system-scope world, a project admin is considered as a persona who can view and modify data only within the project. They do not know resource usage outside of the project. However, we allow a project admin for example to specify a segment ID for a provider network. This apparently requires a coordination with an infrastructure team like a network team managing network switches. Considering this point, this change assumes a project admin is part of system operators.\n\nI understand this requires many changes in operations (like command lines) described in the commit message, so it is acceptable for me as a transitional workaround, but I don\u0027t think we should keep this forever. What do you think about the final plan?","accounts_in_message":[],"_revision_number":3},{"id":"5d581742d6b94b462c543904c1578087f4ebdbed","author":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"date":"2021-03-18 09:36:02.000000000","message":"Patch Set 3:\n\nI read the meeting log (I failed to join it....), but it is not clear whether it is transient or permanent. I think the meaning of \"admin\" role will be changed before and after the introduction of the system scope. In the old world without system-scope, operators need to use \"admin\" role as system admin, but in the system scope world \"system-scope\u003dall\" does this (so-called) role and a project \"admin\" will be considered just as a part of the project. Any roles of a project does not / cannot known details of the underlying infrastructure they use. Thus, I wonder this is to mitigate the pain of the migration or not.","accounts_in_message":[],"_revision_number":3},{"id":"3a37da61c02a3bd142f17bc50f8c79cdba22f5a1","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-18 10:04:03.000000000","message":"Patch Set 3:\n\nBuild succeeded (ARM64 pipeline).\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/2343c2a82cd04135a38e2f9cf22c1a14 : FAILURE in 48m 36s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/4ab22041cca14044aff165ee8bf49645 : FAILURE in 44m 12s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"cc979af9fe8232a44f5132b293d86226be1336a0","author":{"_account_id":9845,"name":"Arista CI","email":"arista-openstack-test@aristanetworks.com","username":"arista-test","tags":["SERVICE_USER"]},"date":"2021-03-18 10:43:09.000000000","message":"Patch Set 3: Verified+1\n\nArista third party testing PASSED [ https://arista-openstack-ci.arista.com:8000/March-2021/Arista_Tempest_Testrefs/changes/78/780978/3 ]\n\nFor testing details or any questions please check https://wiki.openstack.org/wiki/Arista-third-party-testing","accounts_in_message":[],"_revision_number":3},{"id":"c66ca6ab5b031dc89b68b7aef1775117b0239000","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-18 10:47:45.000000000","message":"Patch Set 3:\n\n\u003e Patch Set 3:\n\u003e \n\u003e I read the meeting log (I failed to join it....), but it is not clear whether it is transient or permanent. I think the meaning of \"admin\" role will be changed before and after the introduction of the system scope. In the old world without system-scope, operators need to use \"admin\" role as system admin, but in the system scope world \"system-scope\u003dall\" does this (so-called) role and a project \"admin\" will be considered just as a part of the project. Any roles of a project does not / cannot known details of the underlying infrastructure they use. Thus, I wonder this is to mitigate the pain of the migration or not.\n\nI totally agree with Your point. Those should be system scope things only. But I though that maybe we can change those defaults in the next release.\nOr TBH more I think about it now, more I\u0027m tend to abandon that patch and simply mention how it works in the release notes. Basically by default we are still using old rules so old behaviour will work. To enable those more secure roles, neutron\u0027s config has to be changed so it\u0027s kind of opt-in into the new behavior and if so, operator should be aware of what they are enabling.\nSo I can either abandon this patch now, or I will add TODO notes to remove that PROJECT_ADMIN from some those rules. Wdyt?","accounts_in_message":[],"_revision_number":3},{"id":"cd9fca0e288105a0d5b41fa48945c0ad84fa6eb5","tag":"autogenerated:jenkins-gerrit-trigger","author":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"date":"2021-03-18 11:11:02.000000000","message":"Patch Set 3:\n\nBuild Failed \n\n* SRIOV-neutron-macvtap http://13.74.249.42/refs/changes/78/780978/3/SRIOV-neutron-macvtap : FAILURE\n\n* SRIOV-neutron-direct http://13.74.249.42/refs/changes/78/780978/3/SRIOV-neutron-direct : SUCCESS","accounts_in_message":[],"_revision_number":3},{"id":"2c6e1f27ccaa5be1297379b8ad17d97b3a0c04de","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-18 11:35:25.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- neutron-tempest-plugin-api https://zuul.opendev.org/t/openstack/build/32422bd9d44848dcac416dae894ba325 : SUCCESS in 53m 17s\n- neutron-tempest-plugin-scenario-linuxbridge https://zuul.opendev.org/t/openstack/build/6609a482c48c4f9ca1abebc2b4beee69 : SUCCESS in 1h 27m 59s\n- neutron-tempest-plugin-scenario-openvswitch https://zuul.opendev.org/t/openstack/build/c107c4bcb0de4a259042d369b067cbf6 : SUCCESS in 1h 36m 37s\n- neutron-tempest-plugin-scenario-openvswitch-iptables_hybrid https://zuul.opendev.org/t/openstack/build/f95073edf4ac4b73ad24c683920cc8f2 : SUCCESS in 1h 50m 20s\n- neutron-tempest-plugin-scenario-ovn https://zuul.opendev.org/t/openstack/build/4c083da709554f519aa98eb7a064688c : SUCCESS in 1h 57m 25s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/2e2bbd107581427fb56a6fbc97b487f7 : FAILURE in 57m 35s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/3b8df1b82ba84ccd9862933d1a1b3f53 : SUCCESS in 54m 00s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/78d9594164f64b57ae4e1cb53cf6662f : SUCCESS in 12m 52s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/33e7519f5f9e404e87b02598168a5fd2 : FAILURE in 33m 23s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/189650e784f947c1b8e993967e79e336 : FAILURE in 49m 55s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/b528b70c41a2454ea9c405f6ad8892d9 : FAILURE in 32m 16s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/07eb55dc2b8c4c3aaa9a77afcc012dca : SUCCESS in 14m 21s\n- neutron-functional-with-uwsgi https://zuul.opendev.org/t/openstack/build/c42b6bcfcb034bde8dd60e2e83797d67 : SUCCESS in 50m 55s\n- neutron-fullstack-with-uwsgi https://zuul.opendev.org/t/openstack/build/2992a3d916a74317aa68cd47a2e6e44b : TIMED_OUT in 2h 15m 10s\n- neutron-rally-task https://zuul.opendev.org/t/openstack/build/1aade290a6d14e5cab7c813a651a1145 : SUCCESS in 1h 30m 58s\n- neutron-grenade-multinode https://zuul.opendev.org/t/openstack/build/631eff0e76784e9f98dbfff4f40d32d6 : SUCCESS in 1h 12m 36s\n- neutron-grenade-dvr-multinode https://zuul.opendev.org/t/openstack/build/e6305d24e5f0432f9ad85f8efce72f52 : FAILURE in 55m 42s\n- neutron-tempest-multinode-full-py3 https://zuul.opendev.org/t/openstack/build/3701a9d0d28046479bab86f50bc143c7 : SUCCESS in 1h 33m 10s\n- neutron-tempest-dvr-ha-multinode-full https://zuul.opendev.org/t/openstack/build/51ce0d18d44249248f408ef8b927086b : SUCCESS in 1h 29m 46s (non-voting)\n- neutron-tempest-slow-py3 https://zuul.opendev.org/t/openstack/build/1b4c3d306e35489f920d29e04a1d0ac0 : SUCCESS in 1h 33m 29s\n- neutron-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/a7ddf50dba2b4216a65aca13c5b2cf32 : SUCCESS in 1h 08m 38s\n- neutron-ovn-tempest-ovs-release https://zuul.opendev.org/t/openstack/build/fe1e5e58675a4066b445f90b5ee743e5 : SUCCESS in 1h 16m 32s\n- neutron-ovn-tempest-ovs-release-ipv6-only https://zuul.opendev.org/t/openstack/build/3a94644fb9734f75b65e2d8abc90f515 : SUCCESS in 43m 07s\n- neutron-ovn-rally-task https://zuul.opendev.org/t/openstack/build/dadac747c34347a5bf050a5afa6c5ca6 : SUCCESS in 1h 44m 05s (non-voting)\n- neutron-ovn-tempest-slow https://zuul.opendev.org/t/openstack/build/6384744d00e14952b43ecb9bcd378213 : SUCCESS in 1h 41m 08s","accounts_in_message":[],"_revision_number":3},{"id":"c2b7c6133b83f5ca4714ffe4aa1e58d3a3387074","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-18 14:48:49.000000000","message":"Topic bp/secure-rbac-roles removed","accounts_in_message":[],"_revision_number":3},{"id":"66ff9c7cf395a20f1c6417fc98599f569d525238","tag":"autogenerated:gerrit:setTopic","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-18 14:49:01.000000000","message":"Topic set to secure-rbac","accounts_in_message":[],"_revision_number":3},{"id":"89a35e0ca48f5e49df4faca75e8c23512806ab11","author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"date":"2021-03-19 07:20:11.000000000","message":"Patch Set 3: Code-Review+2\n\nrecheck\nhttps://review.opendev.org/c/openstack/neutron/+/780802 is merged now","accounts_in_message":[],"_revision_number":3},{"id":"b5faa5d4f2b14ccf1f5c2caca0e08cb36fef706b","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-19 07:45:02.000000000","message":"Patch Set 3: Workflow-1","accounts_in_message":[],"_revision_number":3},{"id":"a50bb8a103e00b73a2749eeee706ac33601c4582","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-19 08:15:47.000000000","message":"Patch Set 3:\n\nBuild succeeded (ARM64 pipeline).\n\n- openstack-tox-py38-arm64 https://zuul.opendev.org/t/openstack/build/9b69f712bcb145198cb94719fd67e537 : SUCCESS in 54m 48s (non-voting)\n- openstack-tox-py39-arm64 https://zuul.opendev.org/t/openstack/build/bd1d2af2b8b441a3ba757c9031e25e32 : SUCCESS in 43m 39s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"aabe38f317239c20b816a66d705ce79f0e4c6c53","tag":"autogenerated:jenkins-gerrit-trigger","author":{"_account_id":9732,"name":"Mellanox CI","email":"mlnx-openstack-ci@dev.mellanox.co.il","username":"mellanox","tags":["SERVICE_USER"]},"date":"2021-03-19 09:29:03.000000000","message":"Patch Set 3:\n\nBuild Successful \n\n* SRIOV-neutron-direct http://13.74.249.42/refs/changes/78/780978/3/SRIOV-neutron-direct : SUCCESS\n\n* SRIOV-neutron-macvtap http://13.74.249.42/refs/changes/78/780978/3/SRIOV-neutron-macvtap : SUCCESS","accounts_in_message":[],"_revision_number":3},{"id":"767d0d986e211cd82ce2ba51f8c27e74fe608d52","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-19 09:31:53.000000000","message":"Patch Set 3:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- neutron-tempest-plugin-api https://zuul.opendev.org/t/openstack/build/4fa71acf3e79461e858ec887de8c1794 : SUCCESS in 56m 43s\n- neutron-tempest-plugin-scenario-linuxbridge https://zuul.opendev.org/t/openstack/build/9266b4b003574752b144660683a53e76 : SUCCESS in 1h 26m 56s\n- neutron-tempest-plugin-scenario-openvswitch https://zuul.opendev.org/t/openstack/build/361526ddb77c457e8b31537d298bed48 : SUCCESS in 1h 56m 34s\n- neutron-tempest-plugin-scenario-openvswitch-iptables_hybrid https://zuul.opendev.org/t/openstack/build/9180d9d8730f4ee7a08cd9714a1ba376 : SUCCESS in 1h 53m 11s\n- neutron-tempest-plugin-scenario-ovn https://zuul.opendev.org/t/openstack/build/488bdb79e6004ac1ae0472edcc1d8cce : SUCCESS in 1h 46m 24s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/12b2c7c607554aea9f077d59a2f38388 : SUCCESS in 40m 28s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/f60c5bb3613340f09311219e0320d0d6 : SUCCESS in 27m 07s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/f778e213ab6f44b78c19440325de7d4f : SUCCESS in 16m 58s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/5b8a7fce132042ea8d6179663f4196e8 : SUCCESS in 47m 05s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/c25d2ff5476e414e93ab26a3a01c0ffd : SUCCESS in 33m 36s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/abeacaefd7ad4376879cd40dfe548eb4 : SUCCESS in 28m 56s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/aed839412e3742c68544ad2808e69a90 : SUCCESS in 12m 45s\n- neutron-functional-with-uwsgi https://zuul.opendev.org/t/openstack/build/7059f885451a4549bac4885765870b8b : SUCCESS in 49m 00s\n- neutron-fullstack-with-uwsgi https://zuul.opendev.org/t/openstack/build/ec27a346c36a40df9c914a3f25d652a3 : SUCCESS in 1h 44m 26s\n- neutron-rally-task https://zuul.opendev.org/t/openstack/build/7848c3f37405422387290a1f0b93a20d : SUCCESS in 2h 03m 59s\n- neutron-grenade-multinode https://zuul.opendev.org/t/openstack/build/0903a557e81d4b93a6cdbe0a6bc4dadd : SUCCESS in 1h 03m 28s\n- neutron-grenade-dvr-multinode https://zuul.opendev.org/t/openstack/build/8a124c172a6c450393bec161c6f5c78b : SUCCESS in 1h 01m 33s\n- neutron-tempest-multinode-full-py3 https://zuul.opendev.org/t/openstack/build/9ecee598304d4d628349fd4af1830292 : SUCCESS in 1h 53m 48s\n- neutron-tempest-dvr-ha-multinode-full https://zuul.opendev.org/t/openstack/build/f82373968c5346fa88c80996d63cb888 : SUCCESS in 1h 26m 00s (non-voting)\n- neutron-tempest-slow-py3 https://zuul.opendev.org/t/openstack/build/a595200e537049eaafc769ce0c714914 : SUCCESS in 2h 05m 57s\n- neutron-tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/dc64600f4eae40709bbe838109bd3149 : SUCCESS in 56m 20s\n- neutron-ovn-tempest-ovs-release https://zuul.opendev.org/t/openstack/build/472e12cd9e464857891aa67355aaad2b : FAILURE in 1h 04m 44s\n- neutron-ovn-tempest-ovs-release-ipv6-only https://zuul.opendev.org/t/openstack/build/13f4b02cd01544debe0f0e93a531011e : SUCCESS in 47m 44s\n- neutron-ovn-rally-task https://zuul.opendev.org/t/openstack/build/152d5f0f23db41268621a827b73da795 : SUCCESS in 1h 52m 28s (non-voting)\n- neutron-ovn-tempest-slow https://zuul.opendev.org/t/openstack/build/1bc83a81b0a2407bb6fc3d2936a3544b : SUCCESS in 1h 17m 54s","accounts_in_message":[],"_revision_number":3},{"id":"6e7c2c1b63e0cc09fbd55ce7aab33bfc3e97dda6","author":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"date":"2021-03-19 17:43:49.000000000","message":"Patch Set 3:\n\n\u003e I totally agree with Your point. Those should be system scope things only. But I though that maybe we can change those defaults in the next release.\n\u003e Or TBH more I think about it now, more I\u0027m tend to abandon that patch and simply mention how it works in the release notes. Basically by default we are still using old rules so old behaviour will work. To enable those more secure roles, neutron\u0027s config has to be changed so it\u0027s kind of opt-in into the new behavior and if so, operator should be aware of what they are enabling.\n\u003e So I can either abandon this patch now, or I will add TODO notes to remove that PROJECT_ADMIN from some those rules. Wdyt?\n\nMy current vote is not to relax rules as this change proposes.\n\nYou see a good point. The new secure RBAC role mechanism is opt-in. By default neutron\u0027s behavior is not changed and the existing operation workflows can be used as is. I think we can collect differences when we switch to the system-scope world in our documentation or somewhere. Operators who would like to switch to the system-scope world, they can check such differences.\n\nIn addition, there is an ongoing discussions on how users with system-scoped token interact with resources in a project. It was mentioned by a mailing list post by lbragstad [1][2]. The original discussion happens from nova, but I think the issue raised in this change is one of the examples discussed in the thread. I think we can follow the discussion and adjust the behavior in neutron in Xena.\n\n[1] http://lists.openstack.org/pipermail/openstack-discuss/2021-March/021131.html\n[2] https://etherpad.opendev.org/p/consuming-system-scope","accounts_in_message":[],"_revision_number":3},{"id":"a941cbfd991c36e0eecad4ea7c3f4098816ec02c","author":{"_account_id":841,"name":"Akihiro Motoki","email":"amotoki@gmail.com","username":"amotoki"},"date":"2021-03-19 17:44:26.000000000","message":"Patch Set 3: Code-Review-1","accounts_in_message":[],"_revision_number":3},{"id":"5f00c492d440701b21d5584b860d7808361df096","author":{"_account_id":8313,"name":"Lajos Katona","display_name":"lajoskatona","email":"katonalala@gmail.com","username":"elajkat","status":"Ericsson Software Technology"},"date":"2021-03-22 08:43:15.000000000","message":"Patch Set 3: -Code-Review","accounts_in_message":[],"_revision_number":3},{"id":"bb2f61749c6d9192ead8f47ce38246ecb6019309","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-22 10:13:28.000000000","message":"Patch Set 3: -Review-Priority\n\n\u003e Patch Set 3:\n\u003e \n\u003e \u003e I totally agree with Your point. Those should be system scope things only. But I though that maybe we can change those defaults in the next release.\n\u003e \u003e Or TBH more I think about it now, more I\u0027m tend to abandon that patch and simply mention how it works in the release notes. Basically by default we are still using old rules so old behaviour will work. To enable those more secure roles, neutron\u0027s config has to be changed so it\u0027s kind of opt-in into the new behavior and if so, operator should be aware of what they are enabling.\n\u003e \u003e So I can either abandon this patch now, or I will add TODO notes to remove that PROJECT_ADMIN from some those rules. Wdyt?\n\u003e \n\u003e My current vote is not to relax rules as this change proposes.\n\u003e \n\u003e You see a good point. The new secure RBAC role mechanism is opt-in. By default neutron\u0027s behavior is not changed and the existing operation workflows can be used as is. I think we can collect differences when we switch to the system-scope world in our documentation or somewhere. Operators who would like to switch to the system-scope world, they can check such differences.\n\u003e \n\u003e In addition, there is an ongoing discussions on how users with system-scoped token interact with resources in a project. It was mentioned by a mailing list post by lbragstad [1][2]. The original discussion happens from nova, but I think the issue raised in this change is one of the examples discussed in the thread. I think we can follow the discussion and adjust the behavior in neutron in Xena.\n\u003e \n\u003e [1] http://lists.openstack.org/pipermail/openstack-discuss/2021-March/021131.html\n\u003e [2] https://etherpad.opendev.org/p/consuming-system-scope\n\nThx for Your comment. I\u0027m abandoning this patch now.","accounts_in_message":[],"_revision_number":3},{"id":"225167bc91b82af5d84d0bfbff6e1b196a8599d5","tag":"autogenerated:gerrit:abandon","author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"date":"2021-03-22 10:14:03.000000000","message":"Abandoned\n\nWe decided to not relax those new policies.","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"db1a874576ab0b607b6cb1ab469e34bd898ebdcb","revisions":{"43608b11a4475627c46007d02e9a501404701a86":{"kind":"REWORK","_number":1,"created":"2021-03-16 21:13:44.000000000","uploader":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"ref":"refs/changes/78/780978/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/neutron","ref":"refs/changes/78/780978/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/neutron refs/changes/78/780978/1"}}},"commit":{"parents":[{"commit":"5f6fbcb155e19d0a46cef0e7bbfee553f0472ef3","subject":"Merge \"Implement secure RBAC for the l3 conntrack helper API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/5f6fbcb155e19d0a46cef0e7bbfee553f0472ef3"}]}],"author":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2021-03-16 21:09:10.000000000","tz":60},"committer":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2021-03-16 21:09:10.000000000","tz":60},"subject":"Relax some API policy rules to make them available for project admins","message":"Relax some API policy rules to make them available for project admins\n\nAs part of the migration to the new secure-rbac roles and personas we\nproposed new policy rules for our API.\nFor some of the calls, like e.g. creation of the provider networks with\nspecified physical network we originally made it to be available only\nfor the SYSTEM_ADMIN user as that is really SYSTEM specific thing.\nBut that would mean that such SYSTEM_ADMIN user would always need to\nspecify project_id to create such resource. And that would be\nsignificant change comparing to the old behaviour with \"admin\" user.\n\nSo this patch relax a bit those new policies to make them available also\nfor PROJECT_ADMIN users to mimic old behaviour, at least for now.\n\nChange-Id: I0580bbabd1d9af7a5f2c60b63c42a977d73eeefe\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/43608b11a4475627c46007d02e9a501404701a86"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/43608b11a4475627c46007d02e9a501404701a86"}]},"branch":"refs/heads/master"},"18491c2dcbf1667e6e61f6ca3a815e02662b6612":{"kind":"REWORK","_number":2,"created":"2021-03-17 11:04:39.000000000","uploader":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"ref":"refs/changes/78/780978/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/neutron","ref":"refs/changes/78/780978/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/neutron refs/changes/78/780978/2"}}},"commit":{"parents":[{"commit":"5f6fbcb155e19d0a46cef0e7bbfee553f0472ef3","subject":"Merge \"Implement secure RBAC for the l3 conntrack helper API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/5f6fbcb155e19d0a46cef0e7bbfee553f0472ef3"}]}],"author":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2021-03-16 21:09:10.000000000","tz":60},"committer":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2021-03-17 11:03:51.000000000","tz":60},"subject":"Relax some API policy rules to make them available for project admins","message":"Relax some API policy rules to make them available for project admins\n\nAs part of the migration to the new secure-rbac roles and personas we\nproposed new policy rules for our API.\nFor some of the calls, like e.g. creation of the provider networks with\nspecified physical network we originally made it to be available only\nfor the SYSTEM_ADMIN user as that is really SYSTEM specific thing.\nBut that would mean that such SYSTEM_ADMIN user would always need to\nspecify project_id to create such resource. And that would be\nsignificant change comparing to the old behaviour with \"admin\" user.\n\nSo this patch relax a bit those new policies to make them available also\nfor PROJECT_ADMIN users to mimic old behaviour, at least for now.\n\nChange-Id: I0580bbabd1d9af7a5f2c60b63c42a977d73eeefe\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/18491c2dcbf1667e6e61f6ca3a815e02662b6612"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/18491c2dcbf1667e6e61f6ca3a815e02662b6612"}]},"branch":"refs/heads/master"},"db1a874576ab0b607b6cb1ab469e34bd898ebdcb":{"kind":"REWORK","_number":3,"created":"2021-03-18 09:08:13.000000000","uploader":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"ref":"refs/changes/78/780978/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/neutron","ref":"refs/changes/78/780978/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/neutron refs/changes/78/780978/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/neutron refs/changes/78/780978/3"}}},"commit":{"parents":[{"commit":"5f6fbcb155e19d0a46cef0e7bbfee553f0472ef3","subject":"Merge \"Implement secure RBAC for the l3 conntrack helper API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/5f6fbcb155e19d0a46cef0e7bbfee553f0472ef3"}]}],"author":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2021-03-16 21:09:10.000000000","tz":60},"committer":{"name":"Slawek Kaplonski","email":"skaplons@redhat.com","date":"2021-03-18 09:07:14.000000000","tz":60},"subject":"Relax some API policy rules to make them available for project admins","message":"Relax some API policy rules to make them available for project admins\n\nAs part of the migration to the new secure-rbac roles and personas we\nproposed new policy rules for our API.\nFor some of the calls, like e.g. creation of the provider networks with\nspecified physical network we originally made it to be available only\nfor the SYSTEM_ADMIN user as that is really SYSTEM specific thing.\nBut that would mean that such SYSTEM_ADMIN user would always need to\nspecify project_id to create such resource. And that would be\nsignificant change comparing to the old behaviour with \"admin\" user.\n\nSo this patch relax a bit those new policies to make them available also\nfor PROJECT_ADMIN users to mimic old behaviour, at least for now.\n\nChange-Id: I0580bbabd1d9af7a5f2c60b63c42a977d73eeefe\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/db1a874576ab0b607b6cb1ab469e34bd898ebdcb"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/neutron/commit/db1a874576ab0b607b6cb1ab469e34bd898ebdcb"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
