)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"353eb9d299f36b9f700f29f23554deb20b25380d","unresolved":true,"context_lines":[{"line_number":8,"context_line":""},{"line_number":9,"context_line":"The patch adds DB model that extends the subnet"},{"line_number":10,"context_line":"resource with a boolean to indicate leak_routes"},{"line_number":11,"context_line":"is enabled on the network."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"Assisted-By: Claude Opus 4.6 High"},{"line_number":14,"context_line":"Related-Bug: #2161353"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":4,"id":"44d4c68c_eca5578e","line":11,"range":{"start_line":11,"start_character":18,"end_line":11,"end_character":25},"updated":"2026-08-05 07:26:36.000000000","message":"Should that be subnet?","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"beacfa1fe7fb1f7c052154212dd9c66153824f9d","unresolved":false,"context_lines":[{"line_number":8,"context_line":""},{"line_number":9,"context_line":"The patch adds DB model that extends the subnet"},{"line_number":10,"context_line":"resource with a boolean to indicate leak_routes"},{"line_number":11,"context_line":"is enabled on the network."},{"line_number":12,"context_line":""},{"line_number":13,"context_line":"Assisted-By: Claude Opus 4.6 High"},{"line_number":14,"context_line":"Related-Bug: #2161353"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":4,"id":"ffbd812e_cc195c73","line":11,"range":{"start_line":11,"start_character":18,"end_line":11,"end_character":25},"in_reply_to":"44d4c68c_eca5578e","updated":"2026-08-06 20:35:30.000000000","message":"Because of the OVN limitation, it is going to leak the whole network.","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":34271,"name":"Miro Tomaska","display_name":"Miro Tomaska","email":"mtomaska@redhat.com","username":"mtomaska"},"change_message_id":"f45ffb3d92cb93f64bfb94c456f5b4baf12115bb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"e91a618a_347f2e8e","updated":"2026-08-10 19:47:39.000000000","message":"just one comment","commit_id":"a6150dbe8c58248029d70c94d1ac96a87d21c242"},{"author":{"_account_id":5756,"name":"Terry Wilson","email":"twilson@redhat.com","username":"otherwiseguy"},"change_message_id":"875ed70ac64344262fbe77d80cc77a9b436f4302","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"f283b958_5ad06587","updated":"2026-08-21 14:19:45.000000000","message":"I\u0027m not sure where, but somewhere it seems like it should be documented the reason why the spec mentions leaking routes on networks, but the implementation is on subnets and the side-effect of --leak-routes on a single subnet advertising the routes for other subnets on the network (but not adding routes for them, so advertising broken routes). I get that it is an OVN limitation, but I can imagine that behavior being surprising to an end-user. Maybe a recommendation that to avoid that not to have multiple subnets on a network that does not leak all of the subnets? Or some kind of cascade behavior where we actually do set it on network and propagate the setting down to all subnets on the network and advertise all of them?","commit_id":"e1be95dd147a7c23ff682911267b964023f17fdf"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"4010384cbeb5e61029b1e4f1e5c3f7a048c5f756","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"6ef3eacf_8d85858a","updated":"2026-09-01 17:39:56.000000000","message":"recheck unrelated evpn test failure","commit_id":"e1be95dd147a7c23ff682911267b964023f17fdf"},{"author":{"_account_id":5756,"name":"Terry Wilson","email":"twilson@redhat.com","username":"otherwiseguy"},"change_message_id":"b2ebf8c5a439e24e90680eaefbbd2cbdc04ccb4c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"00802192_0ec6b19e","in_reply_to":"1a5b7a2e_b6551020","updated":"2026-08-27 18:38:22.000000000","message":"Done","commit_id":"e1be95dd147a7c23ff682911267b964023f17fdf"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"6f783e16f5fc4d0f8183a374037d80f77dd8f1bf","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":7,"id":"1a5b7a2e_b6551020","in_reply_to":"f283b958_5ad06587","updated":"2026-08-27 17:58:51.000000000","message":"Documented here https://review.opendev.org/c/openstack/neutron/+/1002678","commit_id":"e1be95dd147a7c23ff682911267b964023f17fdf"}],"neutron/services/bgp/plugin.py":[{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"353eb9d299f36b9f700f29f23554deb20b25380d","unresolved":true,"context_lines":[{"line_number":73,"context_line":""},{"line_number":74,"context_line":"    @staticmethod"},{"line_number":75,"context_line":"    def _validate_no_cidr_overlap(context, cidr):"},{"line_number":76,"context_line":"        leaked_cidrs \u003d bgp_objects.SubnetBGPLeakRoutes.get_leaked_subnet_cidrs("},{"line_number":77,"context_line":"            context)"},{"line_number":78,"context_line":"        new_subnet \u003d netaddr.IPNetwork(cidr)"},{"line_number":79,"context_line":"        for subnet_id, subnet_cidr in leaked_cidrs:"}],"source_content_type":"text/x-python","patch_set":4,"id":"939962bb_18183466","line":76,"range":{"start_line":76,"start_character":55,"end_line":76,"end_character":78},"updated":"2026-08-05 07:26:36.000000000","message":"I have a question here: shouldn\u0027t we limit this query to the subnets belonging to a network? Because this query will return all leaked subnets from all networks.\n\nIf that is the case, we must consider calling this method with context.elevated(), in order to retrieve all subnets from all networks, even those not accessible by the user that can access only to this specific subnet/network.","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"10db72307c33656414153a9034d6ce0c6a575d80","unresolved":false,"context_lines":[{"line_number":73,"context_line":""},{"line_number":74,"context_line":"    @staticmethod"},{"line_number":75,"context_line":"    def _validate_no_cidr_overlap(context, cidr):"},{"line_number":76,"context_line":"        leaked_cidrs \u003d bgp_objects.SubnetBGPLeakRoutes.get_leaked_subnet_cidrs("},{"line_number":77,"context_line":"            context)"},{"line_number":78,"context_line":"        new_subnet \u003d netaddr.IPNetwork(cidr)"},{"line_number":79,"context_line":"        for subnet_id, subnet_cidr in leaked_cidrs:"}],"source_content_type":"text/x-python","patch_set":4,"id":"c7289405_8b5a26f9","line":76,"range":{"start_line":76,"start_character":55,"end_line":76,"end_character":78},"in_reply_to":"56d03ae4_033ddfab","updated":"2026-09-01 15:27:06.000000000","message":"So my comment makes sense: if you want to retrieve all the subnets with leaked_routers, regardless of the project they belong, you must use `context.elevated()` here","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"beacfa1fe7fb1f7c052154212dd9c66153824f9d","unresolved":false,"context_lines":[{"line_number":73,"context_line":""},{"line_number":74,"context_line":"    @staticmethod"},{"line_number":75,"context_line":"    def _validate_no_cidr_overlap(context, cidr):"},{"line_number":76,"context_line":"        leaked_cidrs \u003d bgp_objects.SubnetBGPLeakRoutes.get_leaked_subnet_cidrs("},{"line_number":77,"context_line":"            context)"},{"line_number":78,"context_line":"        new_subnet \u003d netaddr.IPNetwork(cidr)"},{"line_number":79,"context_line":"        for subnet_id, subnet_cidr in leaked_cidrs:"}],"source_content_type":"text/x-python","patch_set":4,"id":"56d03ae4_033ddfab","line":76,"range":{"start_line":76,"start_character":55,"end_line":76,"end_character":78},"in_reply_to":"939962bb_18183466","updated":"2026-08-06 20:35:30.000000000","message":"That\u0027s a good question. The object crafts a DB model query that does not filter on a project_id - so it should return all available leaked subnets regardless where who the subnet belongs to.","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"864538466f87c69d5e2b29fa3aa3cd3363242d66","unresolved":false,"context_lines":[{"line_number":73,"context_line":""},{"line_number":74,"context_line":"    @staticmethod"},{"line_number":75,"context_line":"    def _validate_no_cidr_overlap(context, cidr):"},{"line_number":76,"context_line":"        leaked_cidrs \u003d bgp_objects.SubnetBGPLeakRoutes.get_leaked_subnet_cidrs("},{"line_number":77,"context_line":"            context)"},{"line_number":78,"context_line":"        new_subnet \u003d netaddr.IPNetwork(cidr)"},{"line_number":79,"context_line":"        for subnet_id, subnet_cidr in leaked_cidrs:"}],"source_content_type":"text/x-python","patch_set":4,"id":"0101952a_15cb920c","line":76,"range":{"start_line":76,"start_character":55,"end_line":76,"end_character":78},"in_reply_to":"c45c84e0_37d0d5ef","updated":"2026-09-01 15:52:08.000000000","message":"Right, this is a direct sql query. `context.session` won\u0027t introduce any rbac filtering there, we are not using the NeutronDbObject facade. My bad.","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"05f07315d66fcc3df9fea7b74c71e723a18dcb79","unresolved":false,"context_lines":[{"line_number":73,"context_line":""},{"line_number":74,"context_line":"    @staticmethod"},{"line_number":75,"context_line":"    def _validate_no_cidr_overlap(context, cidr):"},{"line_number":76,"context_line":"        leaked_cidrs \u003d bgp_objects.SubnetBGPLeakRoutes.get_leaked_subnet_cidrs("},{"line_number":77,"context_line":"            context)"},{"line_number":78,"context_line":"        new_subnet \u003d netaddr.IPNetwork(cidr)"},{"line_number":79,"context_line":"        for subnet_id, subnet_cidr in leaked_cidrs:"}],"source_content_type":"text/x-python","patch_set":4,"id":"c45c84e0_37d0d5ef","line":76,"range":{"start_line":76,"start_character":55,"end_line":76,"end_character":78},"in_reply_to":"c7289405_8b5a26f9","updated":"2026-09-01 15:42:20.000000000","message":"I don\u0027t see why when the context is not used. Can you please explain why is it needed? It would also mean this test https://review.opendev.org/c/openstack/neutron/+/998220/4..7/neutron/tests/unit/services/bgp/test_plugin.py#304 doesn\u0027t work.","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"353eb9d299f36b9f700f29f23554deb20b25380d","unresolved":true,"context_lines":[{"line_number":140,"context_line":"                msg\u003d\u0027The leak_routes attribute is only supported on \u0027"},{"line_number":141,"context_line":"                    \u0027subnets belonging to geneve networks.\u0027)"},{"line_number":142,"context_line":""},{"line_number":143,"context_line":"        if leak_routes:"},{"line_number":144,"context_line":"            self._validate_gateway_router_for_subnet(context, subnet_id)"},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"        if leak_routes:"},{"line_number":147,"context_line":"            self._validate_no_cidr_overlap(context, updated[\u0027cidr\u0027])"},{"line_number":148,"context_line":"            bgp_objects.SubnetBGPLeakRoutes("},{"line_number":149,"context_line":"                context, subnet_id\u003dsubnet_id).create()"}],"source_content_type":"text/x-python","patch_set":4,"id":"a4cfa1f3_e28493c2","line":146,"range":{"start_line":143,"start_character":8,"end_line":146,"end_character":23},"updated":"2026-08-05 07:26:36.000000000","message":"Why not merging both?\n```\nif leak_routes:\n   self._validate_gateway_router_for_subnet(context, subnet_id)\n   self._validate_no_cidr_overlap(context, updated[\u0027cidr\u0027])\n   bgp_objects.SubnetBGPLeakRoutes(\n           context, subnet_id\u003dsubnet_id).create()\n   LOG.info(\"Subnet %s updated: leak_routes enabled\", subnet_id)\nelse: ...\n```","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"beacfa1fe7fb1f7c052154212dd9c66153824f9d","unresolved":false,"context_lines":[{"line_number":140,"context_line":"                msg\u003d\u0027The leak_routes attribute is only supported on \u0027"},{"line_number":141,"context_line":"                    \u0027subnets belonging to geneve networks.\u0027)"},{"line_number":142,"context_line":""},{"line_number":143,"context_line":"        if leak_routes:"},{"line_number":144,"context_line":"            self._validate_gateway_router_for_subnet(context, subnet_id)"},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"        if leak_routes:"},{"line_number":147,"context_line":"            self._validate_no_cidr_overlap(context, updated[\u0027cidr\u0027])"},{"line_number":148,"context_line":"            bgp_objects.SubnetBGPLeakRoutes("},{"line_number":149,"context_line":"                context, subnet_id\u003dsubnet_id).create()"}],"source_content_type":"text/x-python","patch_set":4,"id":"7b553833_b94bdfd6","line":146,"range":{"start_line":143,"start_character":8,"end_line":146,"end_character":23},"in_reply_to":"a4cfa1f3_e28493c2","updated":"2026-08-06 20:35:30.000000000","message":"Done","commit_id":"dab29c5b153a523ef2d9083b26529d7a9ba86d60"}],"neutron/tests/unit/services/bgp/test_plugin.py":[{"author":{"_account_id":34271,"name":"Miro Tomaska","display_name":"Miro Tomaska","email":"mtomaska@redhat.com","username":"mtomaska"},"change_message_id":"f45ffb3d92cb93f64bfb94c456f5b4baf12115bb","unresolved":true,"context_lines":[{"line_number":178,"context_line":"            res \u003d req.get_response(self.api)"},{"line_number":179,"context_line":"            self.assertEqual(webob.exc.HTTPBadRequest.code, res.status_int)"},{"line_number":180,"context_line":""},{"line_number":181,"context_line":"    def test_update_subnet_leak_routes_enabled(self):"},{"line_number":182,"context_line":"        _network, subnet, _router \u003d self._create_leakable_topology()"},{"line_number":183,"context_line":"        subnet_id \u003d subnet[\u0027subnet\u0027][\u0027id\u0027]"},{"line_number":184,"context_line":"        data \u003d {\u0027subnet\u0027: {ovn_bgp_apidef.LEAK_ROUTES: True}}"}],"source_content_type":"text/x-python","patch_set":5,"id":"b263de2e_20013bc4","line":181,"range":{"start_line":181,"start_character":8,"end_line":181,"end_character":46},"updated":"2026-08-10 19:47:39.000000000","message":"Consider adding idempotent test. I.e. setting to leak routes on a subnet that is already leaking routes. Similarly, unsetting leak routes where routes are not leaked.","commit_id":"a6150dbe8c58248029d70c94d1ac96a87d21c242"},{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"b77af3e7c0c2db9ca9c22f50d2bad03b57a3a7ee","unresolved":false,"context_lines":[{"line_number":178,"context_line":"            res \u003d req.get_response(self.api)"},{"line_number":179,"context_line":"            self.assertEqual(webob.exc.HTTPBadRequest.code, res.status_int)"},{"line_number":180,"context_line":""},{"line_number":181,"context_line":"    def test_update_subnet_leak_routes_enabled(self):"},{"line_number":182,"context_line":"        _network, subnet, _router \u003d self._create_leakable_topology()"},{"line_number":183,"context_line":"        subnet_id \u003d subnet[\u0027subnet\u0027][\u0027id\u0027]"},{"line_number":184,"context_line":"        data \u003d {\u0027subnet\u0027: {ovn_bgp_apidef.LEAK_ROUTES: True}}"}],"source_content_type":"text/x-python","patch_set":5,"id":"ce68d821_3ff637e8","line":181,"range":{"start_line":181,"start_character":8,"end_line":181,"end_character":46},"in_reply_to":"b263de2e_20013bc4","updated":"2026-08-10 19:58:19.000000000","message":"Done","commit_id":"a6150dbe8c58248029d70c94d1ac96a87d21c242"}]}
