)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":8655,"name":"Jakub Libosvar","email":"libosvar@redhat.com","username":"jlibosva"},"change_message_id":"94b0434d17cef2c57e363792c87ca63b912d0db7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"82fd9cdf_27ccbb8e","updated":"2026-07-29 15:58:17.000000000","message":"recheck - RPC issues in designate API","commit_id":"fdf0943dbecf577b4feabdbad331072116f15d43"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"548bdd1a0e8a540310f110c95123510e28e0e39b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"427e1ce0_557d6071","updated":"2026-07-29 20:16:40.000000000","message":"recheck other unstable jobs","commit_id":"fdf0943dbecf577b4feabdbad331072116f15d43"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"083b27a91eaf802c1d3bbf8762c3c557986f7f15","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"e1684cf4_407a81a6","updated":"2026-07-30 06:14:06.000000000","message":"recheck test_metadata_ipv6_only_network unstable","commit_id":"fdf0943dbecf577b4feabdbad331072116f15d43"}],"neutron/db/db_base_plugin_v2.py":[{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"72836ca367f5238197b7ada6e96ce780f47dc7df","unresolved":true,"context_lines":[{"line_number":1471,"context_line":"        # with visibility to a shared/RBAC network can reassign subnets"},{"line_number":1472,"context_line":"        # owned by another project to their own subnetpool, potentially"},{"line_number":1473,"context_line":"        # altering address-scope and L3 routing state for victim routers."},{"line_number":1474,"context_line":"        if not context.is_admin:"},{"line_number":1475,"context_line":"            network \u003d network_obj.Network.get_object("},{"line_number":1476,"context_line":"                context.elevated(), id\u003dnetwork_id)"},{"line_number":1477,"context_line":"            if network.project_id !\u003d context.project_id:"}],"source_content_type":"text/x-python","patch_set":1,"id":"ee22f047_34f70c82","line":1474,"updated":"2026-07-29 14:23:34.000000000","message":"For now I think we can move on with this but we should do follow-up to get rid of hardcoded `context.is_admin` in code and instead maybe do it properly in the API policies, at least for master branch","commit_id":"fdf0943dbecf577b4feabdbad331072116f15d43"},{"author":{"_account_id":16688,"name":"Rodolfo Alonso","email":"ralonsoh@redhat.com","username":"rodolfo-alonso-hernandez"},"change_message_id":"6f8b28976c11e48e03cfa4c9ced22203c28d0090","unresolved":false,"context_lines":[{"line_number":1471,"context_line":"        # with visibility to a shared/RBAC network can reassign subnets"},{"line_number":1472,"context_line":"        # owned by another project to their own subnetpool, potentially"},{"line_number":1473,"context_line":"        # altering address-scope and L3 routing state for victim routers."},{"line_number":1474,"context_line":"        if not context.is_admin:"},{"line_number":1475,"context_line":"            network \u003d network_obj.Network.get_object("},{"line_number":1476,"context_line":"                context.elevated(), id\u003dnetwork_id)"},{"line_number":1477,"context_line":"            if network.project_id !\u003d context.project_id:"}],"source_content_type":"text/x-python","patch_set":1,"id":"c0d34ed7_a68b5fde","line":1474,"in_reply_to":"ee22f047_34f70c82","updated":"2026-07-29 14:35:21.000000000","message":"Do you mean by adding a policy that checks if the user is non-admin + the parent project ID?\n\nThe problem is that this could be overridden by a custom policy.\n\nAs we commented in IRC, I\u0027ll propose a policy change and a document with potential issues (like this documented CVE).","commit_id":"fdf0943dbecf577b4feabdbad331072116f15d43"}]}
