)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"f7260fefd13951b375caa0821368872e84caca04","unresolved":true,"context_lines":[{"line_number":27,"context_line":"connection-time errors like MissingAuthPlugin leak as KSA"},{"line_number":28,"context_line":"exceptions rather than sdk_exc.SDKException. The _client property"},{"line_number":29,"context_line":"translates these to SDKException so that _call_cyborg\u0027s existing"},{"line_number":30,"context_line":"catch handles them uniformly."},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"_call_cyborg now accepts a method name string (\u0027get\u0027, \u0027post\u0027,"},{"line_number":33,"context_line":"etc.) instead of a bound method reference. This ensures the"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"30f46941_859236b6","line":30,"updated":"2026-08-24 10:46:36.000000000","message":"As an aside, a patch against SDK for this would be warmly welcomed","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"e07b612f4332cb1be7f9b111b430fc381c448332","unresolved":true,"context_lines":[{"line_number":27,"context_line":"connection-time errors like MissingAuthPlugin leak as KSA"},{"line_number":28,"context_line":"exceptions rather than sdk_exc.SDKException. The _client property"},{"line_number":29,"context_line":"translates these to SDKException so that _call_cyborg\u0027s existing"},{"line_number":30,"context_line":"catch handles them uniformly."},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"_call_cyborg now accepts a method name string (\u0027get\u0027, \u0027post\u0027,"},{"line_number":33,"context_line":"etc.) instead of a bound method reference. This ensures the"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"88ec4851_33bc5e96","line":30,"in_reply_to":"30f46941_859236b6","updated":"2026-08-24 15:12:57.000000000","message":"Noted for follow up.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3494d3310f8542744855212bb8f4e34f5e3c35f6","unresolved":false,"context_lines":[{"line_number":27,"context_line":"connection-time errors like MissingAuthPlugin leak as KSA"},{"line_number":28,"context_line":"exceptions rather than sdk_exc.SDKException. The _client property"},{"line_number":29,"context_line":"translates these to SDKException so that _call_cyborg\u0027s existing"},{"line_number":30,"context_line":"catch handles them uniformly."},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"_call_cyborg now accepts a method name string (\u0027get\u0027, \u0027post\u0027,"},{"line_number":33,"context_line":"etc.) instead of a bound method reference. This ensures the"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"99fecc4e_d79a88d1","line":30,"in_reply_to":"88ec4851_33bc5e96","updated":"2026-08-26 11:40:35.000000000","message":"Acknowledged","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"f7260fefd13951b375caa0821368872e84caca04","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"10da6646_a3731d25","updated":"2026-08-24 10:46:36.000000000","message":"This was actually much smaller and more self-contained than I was expecting. Nice work.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"f1c431f0bd1e96e2d53f4755a13929eefc997c4a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"a6f28ab3_d7ae4f86","updated":"2026-08-24 10:32:19.000000000","message":"recheck unrelated post failure","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"5e83c94dfe5a57659a1eee5783fc36bff90ed082","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"8be66154_f26704b1","updated":"2026-08-24 15:25:09.000000000","message":"I\u0027m still happy with this","commit_id":"b4371cf2ea8251cf05f69339612439f0464717a3"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"3e6b5952c9fe7fe42abbe4920970c638eabd6c79","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"9e678db9_40d5df8e","updated":"2026-08-24 15:28:52.000000000","message":"Wait, I missed @smooney@redhat.com\u0027s comment","commit_id":"b4371cf2ea8251cf05f69339612439f0464717a3"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"227e00651cec2d51474a7e71ad2f156920186a05","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"545a5e2e_3cd33657","updated":"2026-08-24 15:29:16.000000000","message":"Working on fixing.","commit_id":"b4371cf2ea8251cf05f69339612439f0464717a3"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"cefca3bea865a52f1f5f0ad11c462b0ae9915119","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"f55da692_57505abe","updated":"2026-08-26 10:27:14.000000000","message":"I\u0027m going to leave my +2 here (despite this currently being marked as draft) to indicate that I\u0027m still happy with this. Barring any substantial rework, please feel free to carry my +2 forward on future revisions also.","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3494d3310f8542744855212bb8f4e34f5e3c35f6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"8d06984c_b4e4c7a1","updated":"2026-08-26 11:40:35.000000000","message":"i think this is now correct but we can impove this more by internalisting the ksa auth creation\n\nim more hten happy to do that in a followup however to not expand the scope fo this more","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"e3e8d708ced446058f598c55bff83a804b4a7102","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":11,"id":"11d36cd7_3b963d5d","updated":"2026-08-26 11:42:05.000000000","message":"note  i didnt +w as i wnat to give melanie time to read and respond to the comments but i think we can proceed with this. i will test it this morning and report back as well but melanine tested it last night in devstack and checcked the db content and confirmed the arq ownership was correct which was the one thing i wanted to confirm","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"514bf69ae6790d3c6139791964ba23abd69765f4","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":11,"id":"962adf6b_062f95e3","in_reply_to":"11d36cd7_3b963d5d","updated":"2026-08-26 13:25:00.000000000","message":"i tested this locally as well and the project stored in cybrog db appares to be correct so this seam to be working end to end wihtout regressing","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"}],"nova/accelerator/cyborg.py":[{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"f7260fefd13951b375caa0821368872e84caca04","unresolved":true,"context_lines":[{"line_number":152,"context_line":"        query \u003d {\"name\": dp_name}"},{"line_number":153,"context_line":"        err_msg \u003d None"},{"line_number":154,"context_line":""},{"line_number":155,"context_line":"        resp, err_msg \u003d self._call_cyborg(\u0027get\u0027,"},{"line_number":156,"context_line":"            self.DEVICE_PROFILE_URL, params\u003dquery)"},{"line_number":157,"context_line":""},{"line_number":158,"context_line":"        if err_msg:"}],"source_content_type":"text/x-python","patch_set":1,"id":"1005a9b5_c41c10a6","line":155,"updated":"2026-08-24 10:46:36.000000000","message":"Long term it would obviously be nicer to rely on the proxy layer rather than the raw HTTP layer, but this is already an improvement IMO.\n\nIt might make sense to add `_call_cyborg_get`, `_call_cyborg_post` etc. methods to avoid passing strings around, but if we would like to do the proxy layer rework later then we probably don\u0027t want to do this now.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"01ea673464b354928b5ccd8cfb7f97c6b3223366","unresolved":true,"context_lines":[{"line_number":152,"context_line":"        query \u003d {\"name\": dp_name}"},{"line_number":153,"context_line":"        err_msg \u003d None"},{"line_number":154,"context_line":""},{"line_number":155,"context_line":"        resp, err_msg \u003d self._call_cyborg(\u0027get\u0027,"},{"line_number":156,"context_line":"            self.DEVICE_PROFILE_URL, params\u003dquery)"},{"line_number":157,"context_line":""},{"line_number":158,"context_line":"        if err_msg:"}],"source_content_type":"text/x-python","patch_set":1,"id":"bdfab055_494b12ae","line":155,"in_reply_to":"1005a9b5_c41c10a6","updated":"2026-08-24 11:27:12.000000000","message":"in its current form i coudl rebase my feature on top of it but if we swap to the proxy layer in this patch we wont have tiem to merge the api in cybrog, merge the supprot in the sdk, release teh sdk and then merge the nova supprot before thursday.\n\nso i woudl either prefer to contineu with the microversion supprot in my https://review.opendev.org/c/openstack/nova/+/994579 patch using keyston auth and proceed with this patch after (using eitehr the raw client or proxy layer)\n\nor merge this first usign the raw client so i cna access teh new field in 2.4 before we add supprot in the sdk for that at the proxy level. and swap to the proxy api next cycle as was orginally planned.\n\n\nthe sdk conversion was intentially put out of scope fo the current cybrog/nova specs to limit the change requried in nova.\n\nso im happy to do that chagne as long as it does not put the current features at risk.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"e07b612f4332cb1be7f9b111b430fc381c448332","unresolved":true,"context_lines":[{"line_number":152,"context_line":"        query \u003d {\"name\": dp_name}"},{"line_number":153,"context_line":"        err_msg \u003d None"},{"line_number":154,"context_line":""},{"line_number":155,"context_line":"        resp, err_msg \u003d self._call_cyborg(\u0027get\u0027,"},{"line_number":156,"context_line":"            self.DEVICE_PROFILE_URL, params\u003dquery)"},{"line_number":157,"context_line":""},{"line_number":158,"context_line":"        if err_msg:"}],"source_content_type":"text/x-python","patch_set":1,"id":"1eb98fe7_2e21d5b5","line":155,"in_reply_to":"bad3e40a_c35f508a","updated":"2026-08-24 15:12:57.000000000","message":"Noted for a follow up.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"afc976683de55666e1c092eba00e23908f340ffb","unresolved":true,"context_lines":[{"line_number":152,"context_line":"        query \u003d {\"name\": dp_name}"},{"line_number":153,"context_line":"        err_msg \u003d None"},{"line_number":154,"context_line":""},{"line_number":155,"context_line":"        resp, err_msg \u003d self._call_cyborg(\u0027get\u0027,"},{"line_number":156,"context_line":"            self.DEVICE_PROFILE_URL, params\u003dquery)"},{"line_number":157,"context_line":""},{"line_number":158,"context_line":"        if err_msg:"}],"source_content_type":"text/x-python","patch_set":1,"id":"98bced8e_43534506","line":155,"in_reply_to":"bad3e40a_c35f508a","updated":"2026-08-24 15:18:36.000000000","message":"ack since we agree on the scope ill rebase my manage-mode change on top of this so that we can","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"2de2a0afa9af0694e992bbd5709bcdd4a72a005d","unresolved":true,"context_lines":[{"line_number":152,"context_line":"        query \u003d {\"name\": dp_name}"},{"line_number":153,"context_line":"        err_msg \u003d None"},{"line_number":154,"context_line":""},{"line_number":155,"context_line":"        resp, err_msg \u003d self._call_cyborg(\u0027get\u0027,"},{"line_number":156,"context_line":"            self.DEVICE_PROFILE_URL, params\u003dquery)"},{"line_number":157,"context_line":""},{"line_number":158,"context_line":"        if err_msg:"}],"source_content_type":"text/x-python","patch_set":1,"id":"bad3e40a_c35f508a","line":155,"in_reply_to":"bdfab055_494b12ae","updated":"2026-08-24 12:00:59.000000000","message":"\u003e or merge this first usign the raw client so i cna access teh new field in 2.4 before we add supprot in the sdk for that at the proxy level. and swap to the proxy api next cycle as was orginally planned.\n\nYes, sorry if I wasn\u0027t clear but the switch to the proxy can/should be a separate patch and isn\u0027t needed now.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"4f4d731f3e0744eb746ff96464c34205cab7c958","unresolved":true,"context_lines":[{"line_number":128,"context_line":"        global _ADAPTER"},{"line_number":129,"context_line":"        if _ADAPTER is None:"},{"line_number":130,"context_line":"            try:"},{"line_number":131,"context_line":"                _ADAPTER \u003d utils.get_sdk_adapter(\u0027accelerator\u0027, admin\u003dTrue)"},{"line_number":132,"context_line":"            except sdk_exc.SDKException:"},{"line_number":133,"context_line":"                raise"},{"line_number":134,"context_line":"            except Exception as e:"}],"source_content_type":"text/x-python","patch_set":2,"id":"1cab5aaa_0e65a66a","line":131,"range":{"start_line":131,"start_character":15,"end_line":131,"end_character":75},"updated":"2026-08-24 15:25:21.000000000","message":"this is unfortunetly broken\n\nfrom my llm while i was rebasign on top.\n\ntoday nova doe snot use an admin client to talk to cybrog it uses the users token\n\nin the future we will need to move to us nova admin client with the service role\nbut nova today uses the 2.0 microverion to create the arq with the users token\n\nnova is missign the logic to  use 2.1 where it can specify the project to bind the ARQ for https://docs.openstack.org/cyborg/latest/contributor/rest_api_version_history.html#maximum-in-victoria\n\n```\nCorrection: Gerrit 1002007 is functionally broken, not just affected by config drift. The 403 proves `get_sdk_adapter(..., admin\u003dTrue)` omits the user-token/service-token wrapper; it also\n creates ARQs under Nova’s service project.\n\n - Do not weaken Cyborg policy or hide this regression in 994579.\n - Delete failed server `434c343b-d644-4d1f-a7d8-d82b832f320c`; confirm ARQs and its Placement allocations are gone.\n - Rebase the two Nova commits onto current 1002007 PS2 (`b8b4d58a46`), preserving boundaries and Change-Ids.\n - Save the 403 journal evidence, then pause exact-stack lifecycle testing and escalate to the user/1002007 owner.\n - Recommend fixing 1002007 by creating a per-context SDK proxy using `service_auth.get_service_user_token_auth_plugin(context)`. Do not globally cache an authenticated proxy across request\n contexts. Extend `utils.get_sdk_adapter()` to accept that KSA auth plugin and build a session from it, with tests covering service-token transmission and distinct tenant contexts.\n - Offer a temporary uncommitted version of that fix only if the user wants feature-only local validation while awaiting PS3; clearly do not report that as validation of the exact review\n stack.\n```","commit_id":"b8b4d58a46fd551137ed3e37e28c4e0c99451c95"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"e6c4e56bd3154cabf31f4ada647c1358efbd0253","unresolved":true,"context_lines":[{"line_number":128,"context_line":"        global _ADAPTER"},{"line_number":129,"context_line":"        if _ADAPTER is None:"},{"line_number":130,"context_line":"            try:"},{"line_number":131,"context_line":"                _ADAPTER \u003d utils.get_sdk_adapter(\u0027accelerator\u0027, admin\u003dTrue)"},{"line_number":132,"context_line":"            except sdk_exc.SDKException:"},{"line_number":133,"context_line":"                raise"},{"line_number":134,"context_line":"            except Exception as e:"}],"source_content_type":"text/x-python","patch_set":2,"id":"fdb9eb0a_d49802af","line":131,"range":{"start_line":131,"start_character":15,"end_line":131,"end_character":75},"in_reply_to":"1cab5aaa_0e65a66a","updated":"2026-08-24 15:47:27.000000000","message":"the llm output sorry is not very coherent i was asking me how to proceed and that was its internal thinking trace\n\n\nbut tl;dr is i was testing this locally and it found that this used the wrong token to create teh arq adn as a result the arq is bound to the nova service proejct not the endusers.\n\nwe need to use 2.0 when creating arqs until noave has supprot for 2.1\n\nand 2.0 needs us to call cybrog with the users token as we use the user token to retrive the project id in that case.\n\n2.1 makes the project_id somethign nova can pass in\n\nin which case we can revert to useing the nova admin/service client\n\nin the future i am look to harden the nova/cybrog interaction by requiring teh service role to bind or unbined an arq\n\ntoday i require it on the service_user token like cinder does but that is not correct long term\n\nthat was doen purly to not break nova while closing \n\nhttps://bugs.launchpad.net/openstack-cyborg/+bug/2144056","commit_id":"b8b4d58a46fd551137ed3e37e28c4e0c99451c95"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"4b4bf27a64f26c5f849152c1585b81349aa5c8ce","unresolved":false,"context_lines":[{"line_number":128,"context_line":"        global _ADAPTER"},{"line_number":129,"context_line":"        if _ADAPTER is None:"},{"line_number":130,"context_line":"            try:"},{"line_number":131,"context_line":"                _ADAPTER \u003d utils.get_sdk_adapter(\u0027accelerator\u0027, admin\u003dTrue)"},{"line_number":132,"context_line":"            except sdk_exc.SDKException:"},{"line_number":133,"context_line":"                raise"},{"line_number":134,"context_line":"            except Exception as e:"}],"source_content_type":"text/x-python","patch_set":2,"id":"330a8fe9_4d7d944e","line":131,"range":{"start_line":131,"start_character":15,"end_line":131,"end_character":75},"in_reply_to":"8a9c9297_da162830","updated":"2026-08-24 21:52:57.000000000","message":"I think this is fixed now.","commit_id":"b8b4d58a46fd551137ed3e37e28c4e0c99451c95"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"b90afa20ecaa182cc9fb1658eb7e49d29437dfba","unresolved":true,"context_lines":[{"line_number":128,"context_line":"        global _ADAPTER"},{"line_number":129,"context_line":"        if _ADAPTER is None:"},{"line_number":130,"context_line":"            try:"},{"line_number":131,"context_line":"                _ADAPTER \u003d utils.get_sdk_adapter(\u0027accelerator\u0027, admin\u003dTrue)"},{"line_number":132,"context_line":"            except sdk_exc.SDKException:"},{"line_number":133,"context_line":"                raise"},{"line_number":134,"context_line":"            except Exception as e:"}],"source_content_type":"text/x-python","patch_set":2,"id":"8a9c9297_da162830","line":131,"range":{"start_line":131,"start_character":15,"end_line":131,"end_character":75},"in_reply_to":"fdb9eb0a_d49802af","updated":"2026-08-24 15:51:28.000000000","message":"this is still relevent to ps3\ni think the cybrog tempst job caught this as well\n\nhttps://84780944a52c9d1d060d-6e7916d5bc3a440226a61941870ebc18.ssl.cf1.rackcdn.com/openstack/1eb57239a96043369a41beb1c08b61c4/testr_results.html\n\nbut not sure\n\netails: {\u0027code\u0027: 400, \u0027message\u0027: \u0027Device profile name fpga-svc-token-test: Could not communicate with Cyborg.\u0027}\n\nis not what i expected but maybe","commit_id":"b8b4d58a46fd551137ed3e37e28c4e0c99451c95"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"e025dd73f816302ec40bb639629178c03aa58f1b","unresolved":true,"context_lines":[{"line_number":116,"context_line":"    def __init__(self, context):"},{"line_number":117,"context_line":"        self._context \u003d context"},{"line_number":118,"context_line":"        self._cached_client \u003d None"},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"    @property"},{"line_number":121,"context_line":"    def _client(self):"},{"line_number":122,"context_line":"        if self._cached_client is None:"},{"line_number":123,"context_line":"            auth \u003d service_auth.get_service_user_token_auth_plugin("},{"line_number":124,"context_line":"                self._context)"},{"line_number":125,"context_line":"            self._cached_client \u003d utils.get_sdk_adapter("},{"line_number":126,"context_line":"                \u0027accelerator\u0027, admin\u003dTrue, ksa_auth\u003dauth)"},{"line_number":127,"context_line":"        return self._cached_client"},{"line_number":128,"context_line":""},{"line_number":129,"context_line":"    def _call_cyborg(self, method, *args, **kwargs):"},{"line_number":130,"context_line":"        resp \u003d err_msg \u003d None"}],"source_content_type":"text/x-python","patch_set":8,"id":"6b7d5203_138e621d","line":127,"range":{"start_line":119,"start_character":1,"end_line":127,"end_character":34},"updated":"2026-08-25 18:07:20.000000000","message":"this still feed incorrect to me, when we are talking to cybrog today we are never using novas token so im not sure that caching the client since we will have to change the sesssion on every call makes sense\n\n\nin the future we willl start usign an admin clinet (well a client iwth the serviece roles) to talke to cybrog for some request but the client shoudl not have admin\u003dtrue today.","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"272dd2c376b536d2de445dfe887177df520fc6d6","unresolved":false,"context_lines":[{"line_number":116,"context_line":"    def __init__(self, context):"},{"line_number":117,"context_line":"        self._context \u003d context"},{"line_number":118,"context_line":"        self._cached_client \u003d None"},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"    @property"},{"line_number":121,"context_line":"    def _client(self):"},{"line_number":122,"context_line":"        if self._cached_client is None:"},{"line_number":123,"context_line":"            auth \u003d service_auth.get_service_user_token_auth_plugin("},{"line_number":124,"context_line":"                self._context)"},{"line_number":125,"context_line":"            self._cached_client \u003d utils.get_sdk_adapter("},{"line_number":126,"context_line":"                \u0027accelerator\u0027, admin\u003dTrue, ksa_auth\u003dauth)"},{"line_number":127,"context_line":"        return self._cached_client"},{"line_number":128,"context_line":""},{"line_number":129,"context_line":"    def _call_cyborg(self, method, *args, **kwargs):"},{"line_number":130,"context_line":"        resp \u003d err_msg \u003d None"}],"source_content_type":"text/x-python","patch_set":8,"id":"18cab384_a6c82ed1","line":127,"range":{"start_line":119,"start_character":1,"end_line":127,"end_character":34},"in_reply_to":"5f192877_40ddaa02","updated":"2026-08-25 22:24:38.000000000","message":"Done","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"042b12743ed52bda663654338693bf56f751d53a","unresolved":true,"context_lines":[{"line_number":116,"context_line":"    def __init__(self, context):"},{"line_number":117,"context_line":"        self._context \u003d context"},{"line_number":118,"context_line":"        self._cached_client \u003d None"},{"line_number":119,"context_line":""},{"line_number":120,"context_line":"    @property"},{"line_number":121,"context_line":"    def _client(self):"},{"line_number":122,"context_line":"        if self._cached_client is None:"},{"line_number":123,"context_line":"            auth \u003d service_auth.get_service_user_token_auth_plugin("},{"line_number":124,"context_line":"                self._context)"},{"line_number":125,"context_line":"            self._cached_client \u003d utils.get_sdk_adapter("},{"line_number":126,"context_line":"                \u0027accelerator\u0027, admin\u003dTrue, ksa_auth\u003dauth)"},{"line_number":127,"context_line":"        return self._cached_client"},{"line_number":128,"context_line":""},{"line_number":129,"context_line":"    def _call_cyborg(self, method, *args, **kwargs):"},{"line_number":130,"context_line":"        resp \u003d err_msg \u003d None"}],"source_content_type":"text/x-python","patch_set":8,"id":"5f192877_40ddaa02","line":127,"range":{"start_line":119,"start_character":1,"end_line":127,"end_character":34},"in_reply_to":"6b7d5203_138e621d","updated":"2026-08-25 18:40:35.000000000","message":"Sorry, I had thought I had `admin\u003dFalse` here but it must have been an earlier iteration.","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"}],"nova/conductor/manager.py":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"01ea673464b354928b5ccd8cfb7f97c6b3223366","unresolved":true,"context_lines":[{"line_number":887,"context_line":"            LOG.debug(\"Selected host: %s; Selected node: %s; Alternates: %s\","},{"line_number":888,"context_line":"                    host.service_host, host.nodename, alts, instance\u003dinstance)"},{"line_number":889,"context_line":""},{"line_number":890,"context_line":"            try:"},{"line_number":891,"context_line":"                accel_uuids \u003d self._create_and_bind_arq_for_instance("},{"line_number":892,"context_line":"                    context, instance, host.nodename, local_reqspec,"},{"line_number":893,"context_line":"                    requested_networks)"}],"source_content_type":"text/x-python","patch_set":1,"id":"a12cbc22_d09ca9ee","line":890,"updated":"2026-08-24 11:27:12.000000000","message":"althernitively we coudl move the comemnt here where its actully ilistrateve of passing nodename","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"e07b612f4332cb1be7f9b111b430fc381c448332","unresolved":false,"context_lines":[{"line_number":887,"context_line":"            LOG.debug(\"Selected host: %s; Selected node: %s; Alternates: %s\","},{"line_number":888,"context_line":"                    host.service_host, host.nodename, alts, instance\u003dinstance)"},{"line_number":889,"context_line":""},{"line_number":890,"context_line":"            try:"},{"line_number":891,"context_line":"                accel_uuids \u003d self._create_and_bind_arq_for_instance("},{"line_number":892,"context_line":"                    context, instance, host.nodename, local_reqspec,"},{"line_number":893,"context_line":"                    requested_networks)"}],"source_content_type":"text/x-python","patch_set":1,"id":"7482e65a_271f3a50","line":890,"in_reply_to":"a12cbc22_d09ca9ee","updated":"2026-08-24 15:12:57.000000000","message":"Chose not to move it here bc it seemed like the comment would only be useful if something was passing nodename in place of hostname or similar. This is just passing both host and node separately, which does not seem unexpected or in need of further explanation.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"f7260fefd13951b375caa0821368872e84caca04","unresolved":false,"context_lines":[{"line_number":914,"context_line":"            self, context, instance, hostname,"},{"line_number":915,"context_line":"            request_spec, requested_networks\u003dNone):"},{"line_number":916,"context_line":"        # Using nodename instead of hostname. See:"},{"line_number":917,"context_line":"        # http://lists.openstack.org/pipermail/openstack-discuss/2019-November/011044.html  # noqa"},{"line_number":918,"context_line":"        try:"},{"line_number":919,"context_line":"            resource_provider_mapping \u003d ("},{"line_number":920,"context_line":"                request_spec.get_request_group_mapping())"}],"source_content_type":"text/x-python","patch_set":1,"id":"2bb7d90e_55ef6a3a","line":917,"updated":"2026-08-24 10:46:36.000000000","message":"nit: I don\u0027t think you need `noqa` for overlong comment lines once the comment doesn\u0027t include spaces, but this is copy-paste","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"01ea673464b354928b5ccd8cfb7f97c6b3223366","unresolved":true,"context_lines":[{"line_number":914,"context_line":"            self, context, instance, hostname,"},{"line_number":915,"context_line":"            request_spec, requested_networks\u003dNone):"},{"line_number":916,"context_line":"        # Using nodename instead of hostname. See:"},{"line_number":917,"context_line":"        # http://lists.openstack.org/pipermail/openstack-discuss/2019-November/011044.html  # noqa"},{"line_number":918,"context_line":"        try:"},{"line_number":919,"context_line":"            resource_provider_mapping \u003d ("},{"line_number":920,"context_line":"                request_spec.get_request_group_mapping())"}],"source_content_type":"text/x-python","patch_set":1,"id":"8ccb5843_47841780","line":917,"in_reply_to":"2bb7d90e_55ef6a3a","updated":"2026-08-24 11:27:12.000000000","message":"so this comment is not true as we are actully using the hostname below right?\n\ni dont see nodename anywhere\n\nit true that for neutron port bindign and cyborg arq binding CONF.host should be set the same in nova cybrog and neutron that has always been reqruied\n\non the placmenet interaaction side neutron added a seperate config option to find the placement RP when the hyperverios_hostname is different form CONF.host\nthat was dicsussed here\n\nhttps://lists.openstack.org/pipermail/openstack-discuss/2019-November/011168.html \nhttps://bugs.launchpad.net/neutron/+bug/1853840\nhttps://review.opendev.org/c/openstack/neutron/+/699174\n\nalso i improved this somewhat in cybrog via \nhttps://github.com/openstack/cyborg/commit/0e9a632f3165af8d108301d7838ba2792de64222\n\nadding`[agent] resource_provider_name` that defautl to socket.getfqdn()\n\nso while CONF.host shoudl stil be the saem everywhere i think we can remvoe thie comment as given the fact i was directly invovled in resolving this across all 3 services at the tiem i still find this very confusing this proably wont help others.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"e07b612f4332cb1be7f9b111b430fc381c448332","unresolved":false,"context_lines":[{"line_number":914,"context_line":"            self, context, instance, hostname,"},{"line_number":915,"context_line":"            request_spec, requested_networks\u003dNone):"},{"line_number":916,"context_line":"        # Using nodename instead of hostname. See:"},{"line_number":917,"context_line":"        # http://lists.openstack.org/pipermail/openstack-discuss/2019-November/011044.html  # noqa"},{"line_number":918,"context_line":"        try:"},{"line_number":919,"context_line":"            resource_provider_mapping \u003d ("},{"line_number":920,"context_line":"                request_spec.get_request_group_mapping())"}],"source_content_type":"text/x-python","patch_set":1,"id":"d2f343a6_ad22903d","line":917,"in_reply_to":"8ccb5843_47841780","updated":"2026-08-24 15:12:57.000000000","message":"I have removed it based on the fact that there\u0027s no nodename being used here anymore.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"}],"nova/service_auth.py":[{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"836f5c3685efb76785e23deab5ae3ad4e3d2f6cb","unresolved":true,"context_lines":[{"line_number":35,"context_line":"    # endpoint_override configured (the default) and the SDK raises"},{"line_number":36,"context_line":"    # NotSupported during proxy creation. This can be removed once"},{"line_number":37,"context_line":"    # keystoneauth1 adds the delegation upstream."},{"line_number":38,"context_line":"    # See https://bugs.launchpad.net/keystoneauth/+bug/2164939"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"    def get_endpoint_data(self, session, **kwargs):"},{"line_number":41,"context_line":"        return self.user_auth.get_endpoint_data(session, **kwargs)"}],"source_content_type":"text/x-python","patch_set":8,"id":"71200b7f_c3095715","line":38,"updated":"2026-08-24 23:47:50.000000000","message":"Fix is proposed here: https://review.opendev.org/c/openstack/keystoneauth/+/1002219","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"ce1e49ef58b05fa37bed7090b7f3ab569b10a247","unresolved":false,"context_lines":[{"line_number":35,"context_line":"    # endpoint_override configured (the default) and the SDK raises"},{"line_number":36,"context_line":"    # NotSupported during proxy creation. This can be removed once"},{"line_number":37,"context_line":"    # keystoneauth1 adds the delegation upstream."},{"line_number":38,"context_line":"    # See https://bugs.launchpad.net/keystoneauth/+bug/2164939"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"    def get_endpoint_data(self, session, **kwargs):"},{"line_number":41,"context_line":"        return self.user_auth.get_endpoint_data(session, **kwargs)"}],"source_content_type":"text/x-python","patch_set":8,"id":"9a207d64_992dde36","line":38,"in_reply_to":"71200b7f_c3095715","updated":"2026-08-26 14:32:23.000000000","message":"Fix has merged.","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"2a14eac9a2d3754a701ef4037c92fe268129b8f4","unresolved":true,"context_lines":[{"line_number":101,"context_line":"    # user_auth may be passed in when the RequestContext is anonymous, such as"},{"line_number":102,"context_line":"    # when get_admin_context() is used for API calls by nova-manage."},{"line_number":103,"context_line":"    user_auth \u003d user_auth or context.get_auth_plugin()"},{"line_number":104,"context_line":"    LOG.debug(\u0027user_auth plugin type: %s\u0027, type(user_auth).__name__)"},{"line_number":105,"context_line":""},{"line_number":106,"context_line":"    if CONF.service_user.send_service_user_token:"},{"line_number":107,"context_line":"        service_auth \u003d get_service_auth_plugin("}],"source_content_type":"text/x-python","patch_set":8,"id":"e7ceb13b_6952815e","line":104,"updated":"2026-08-24 21:34:40.000000000","message":"This was meant to help with debugging the next fail but `cyborg-tempest-py3` has passed this time. Can remove this if we think it\u0027s not useful.","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"272dd2c376b536d2de445dfe887177df520fc6d6","unresolved":false,"context_lines":[{"line_number":101,"context_line":"    # user_auth may be passed in when the RequestContext is anonymous, such as"},{"line_number":102,"context_line":"    # when get_admin_context() is used for API calls by nova-manage."},{"line_number":103,"context_line":"    user_auth \u003d user_auth or context.get_auth_plugin()"},{"line_number":104,"context_line":"    LOG.debug(\u0027user_auth plugin type: %s\u0027, type(user_auth).__name__)"},{"line_number":105,"context_line":""},{"line_number":106,"context_line":"    if CONF.service_user.send_service_user_token:"},{"line_number":107,"context_line":"        service_auth \u003d get_service_auth_plugin("}],"source_content_type":"text/x-python","patch_set":8,"id":"25100d94_ab5dfa71","line":104,"in_reply_to":"e7ceb13b_6952815e","updated":"2026-08-25 22:24:38.000000000","message":"Done","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"}],"nova/test.py":[{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"8e33d2794b2cf3dcf71e19a5f45fce6c669a8b76","unresolved":true,"context_lines":[{"line_number":350,"context_line":"        nova.service_auth.reset_globals()"},{"line_number":351,"context_line":""},{"line_number":352,"context_line":"        # Reset the global Cyborg adapter"},{"line_number":353,"context_line":"        from nova.accelerator import cyborg"},{"line_number":354,"context_line":"        cyborg.reset_globals()"},{"line_number":355,"context_line":""},{"line_number":356,"context_line":"    def _setup_cells(self):"}],"source_content_type":"text/x-python","patch_set":2,"id":"2b35a6cf_d81a075d","line":353,"updated":"2026-08-24 15:16:51.000000000","message":"I wonder if this should be moved to the top-level import list instead of this?","commit_id":"b8b4d58a46fd551137ed3e37e28c4e0c99451c95"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"afc976683de55666e1c092eba00e23908f340ffb","unresolved":true,"context_lines":[{"line_number":350,"context_line":"        nova.service_auth.reset_globals()"},{"line_number":351,"context_line":""},{"line_number":352,"context_line":"        # Reset the global Cyborg adapter"},{"line_number":353,"context_line":"        from nova.accelerator import cyborg"},{"line_number":354,"context_line":"        cyborg.reset_globals()"},{"line_number":355,"context_line":""},{"line_number":356,"context_line":"    def _setup_cells(self):"}],"source_content_type":"text/x-python","patch_set":2,"id":"4e436df0_a1b4586c","line":353,"in_reply_to":"2b35a6cf_d81a075d","updated":"2026-08-24 15:18:36.000000000","message":"yes it should we only do inline import if it woudl create a cycle but the cybrog moudle shoudl not be importing nova.test","commit_id":"b8b4d58a46fd551137ed3e37e28c4e0c99451c95"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"c63b6a6f81e95e6a657930eee11548c74551b802","unresolved":false,"context_lines":[{"line_number":350,"context_line":"        nova.service_auth.reset_globals()"},{"line_number":351,"context_line":""},{"line_number":352,"context_line":"        # Reset the global Cyborg adapter"},{"line_number":353,"context_line":"        from nova.accelerator import cyborg"},{"line_number":354,"context_line":"        cyborg.reset_globals()"},{"line_number":355,"context_line":""},{"line_number":356,"context_line":"    def _setup_cells(self):"}],"source_content_type":"text/x-python","patch_set":2,"id":"2ad4620f_824625b0","line":353,"in_reply_to":"4e436df0_a1b4586c","updated":"2026-08-24 15:23:14.000000000","message":"Done","commit_id":"b8b4d58a46fd551137ed3e37e28c4e0c99451c95"}],"nova/tests/unit/accelerator/test_cyborg.py":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"01ea673464b354928b5ccd8cfb7f97c6b3223366","unresolved":true,"context_lines":[{"line_number":34,"context_line":"    def setUp(self):"},{"line_number":35,"context_line":"        super(CyborgTestCase, self).setUp()"},{"line_number":36,"context_line":"        self.context \u003d context.get_admin_context()"},{"line_number":37,"context_line":"        p \u003d mock.patch(\u0027nova.utils.get_sdk_adapter\u0027)"},{"line_number":38,"context_line":"        self.mock_get_sdk_adapter \u003d p.start()"},{"line_number":39,"context_line":"        self.mock_adapter \u003d mock.Mock()"},{"line_number":40,"context_line":"        self.mock_get_sdk_adapter.return_value \u003d self.mock_adapter"},{"line_number":41,"context_line":"        self.addCleanup(p.stop)"},{"line_number":42,"context_line":"        self.client \u003d cyborg.get_client(self.context)"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"    def test_get_client(self):"}],"source_content_type":"text/x-python","patch_set":1,"id":"916f9b3d_e46890e1","line":41,"range":{"start_line":37,"start_character":0,"end_line":41,"end_character":31},"updated":"2026-08-24 11:27:12.000000000","message":"nit: i woudl perfer the fixutres lib and self.useFixture over manually starting the patcher adn registring the cleanup especally when you have addtional lines between start and stop but this si ok its just more error prone.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"e07b612f4332cb1be7f9b111b430fc381c448332","unresolved":false,"context_lines":[{"line_number":34,"context_line":"    def setUp(self):"},{"line_number":35,"context_line":"        super(CyborgTestCase, self).setUp()"},{"line_number":36,"context_line":"        self.context \u003d context.get_admin_context()"},{"line_number":37,"context_line":"        p \u003d mock.patch(\u0027nova.utils.get_sdk_adapter\u0027)"},{"line_number":38,"context_line":"        self.mock_get_sdk_adapter \u003d p.start()"},{"line_number":39,"context_line":"        self.mock_adapter \u003d mock.Mock()"},{"line_number":40,"context_line":"        self.mock_get_sdk_adapter.return_value \u003d self.mock_adapter"},{"line_number":41,"context_line":"        self.addCleanup(p.stop)"},{"line_number":42,"context_line":"        self.client \u003d cyborg.get_client(self.context)"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"    def test_get_client(self):"}],"source_content_type":"text/x-python","patch_set":1,"id":"a24a2a4f_c22cfac9","line":41,"range":{"start_line":37,"start_character":0,"end_line":41,"end_character":31},"in_reply_to":"916f9b3d_e46890e1","updated":"2026-08-24 15:12:57.000000000","message":"Sorry I missed this, I don\u0027t know why it keeps using start/stop. Done. I\u0027ll try to look out for this in the future.","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"d9003c39b045889b700635d76e2d46efb4b236ef","unresolved":false,"context_lines":[{"line_number":34,"context_line":"    def setUp(self):"},{"line_number":35,"context_line":"        super(CyborgTestCase, self).setUp()"},{"line_number":36,"context_line":"        self.context \u003d context.get_admin_context()"},{"line_number":37,"context_line":"        p \u003d mock.patch(\u0027nova.utils.get_sdk_adapter\u0027)"},{"line_number":38,"context_line":"        self.mock_get_sdk_adapter \u003d p.start()"},{"line_number":39,"context_line":"        self.mock_adapter \u003d mock.Mock()"},{"line_number":40,"context_line":"        self.mock_get_sdk_adapter.return_value \u003d self.mock_adapter"},{"line_number":41,"context_line":"        self.addCleanup(p.stop)"},{"line_number":42,"context_line":"        self.client \u003d cyborg.get_client(self.context)"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"    def test_get_client(self):"}],"source_content_type":"text/x-python","patch_set":1,"id":"c1d7e7c9_36d557cf","line":41,"range":{"start_line":37,"start_character":0,"end_line":41,"end_character":31},"in_reply_to":"a24a2a4f_c22cfac9","updated":"2026-08-24 15:19:37.000000000","message":"i think its just becasue teh fixutres lib is less widely used\n\nthis is corect if using prue untites or without testtools/fixutres","commit_id":"8ae56023b1d6487cdf3c78c3992f6161c2402bd8"}],"nova/utils.py":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"e025dd73f816302ec40bb639629178c03aa58f1b","unresolved":true,"context_lines":[{"line_number":937,"context_line":"    confgrp \u003d conf_group or _get_conf_group(service_type)"},{"line_number":938,"context_line":""},{"line_number":939,"context_line":"    try:"},{"line_number":940,"context_line":"        if admin is False and ksa_auth is None:"},{"line_number":941,"context_line":"            if context is None:"},{"line_number":942,"context_line":"                raise ValueError("},{"line_number":943,"context_line":"                    \"If admin is set to False then context cannot be None.\")"}],"source_content_type":"text/x-python","patch_set":8,"id":"be396fee_4f9e4e8f","line":940,"range":{"start_line":940,"start_character":16,"end_line":940,"end_character":19},"updated":"2026-08-25 18:07:20.000000000","message":"nit: using is to compare to False is kind of odd\n\n\n\n```suggestion\n        if not admin and ksa_auth is None:\n```\n\nwould be more correct i think but that a prexising issue\n\nim a little confuise why we are making this chagne in gneral\n\nwe are expecting to take the if brnach for cybrog not the else branch\n\nsicne the goal here is to contolct a session using the end users token as the user toke with a service token generate fomr the nova config.","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"272dd2c376b536d2de445dfe887177df520fc6d6","unresolved":false,"context_lines":[{"line_number":937,"context_line":"    confgrp \u003d conf_group or _get_conf_group(service_type)"},{"line_number":938,"context_line":""},{"line_number":939,"context_line":"    try:"},{"line_number":940,"context_line":"        if admin is False and ksa_auth is None:"},{"line_number":941,"context_line":"            if context is None:"},{"line_number":942,"context_line":"                raise ValueError("},{"line_number":943,"context_line":"                    \"If admin is set to False then context cannot be None.\")"}],"source_content_type":"text/x-python","patch_set":8,"id":"20fc2640_96ec2f71","line":940,"range":{"start_line":940,"start_character":16,"end_line":940,"end_character":19},"in_reply_to":"be396fee_4f9e4e8f","updated":"2026-08-25 22:24:38.000000000","message":"Done","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"e025dd73f816302ec40bb639629178c03aa58f1b","unresolved":true,"context_lines":[{"line_number":959,"context_line":"                strict_proxies\u003dcheck_service,"},{"line_number":960,"context_line":"                **kwargs,"},{"line_number":961,"context_line":"            )"},{"line_number":962,"context_line":"        else:"},{"line_number":963,"context_line":"            # Create a connection based on nova\u0027s service user/pass"},{"line_number":964,"context_line":"            # or a provided auth plugin."},{"line_number":965,"context_line":"            sess \u003d _get_auth_and_session(confgrp, ksa_auth\u003dksa_auth)[1]"}],"source_content_type":"text/x-python","patch_set":8,"id":"808cf1be_b28ce247","line":962,"updated":"2026-08-25 18:07:20.000000000","message":"so we should not be takign this path for example","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"042b12743ed52bda663654338693bf56f751d53a","unresolved":true,"context_lines":[{"line_number":959,"context_line":"                strict_proxies\u003dcheck_service,"},{"line_number":960,"context_line":"                **kwargs,"},{"line_number":961,"context_line":"            )"},{"line_number":962,"context_line":"        else:"},{"line_number":963,"context_line":"            # Create a connection based on nova\u0027s service user/pass"},{"line_number":964,"context_line":"            # or a provided auth plugin."},{"line_number":965,"context_line":"            sess \u003d _get_auth_and_session(confgrp, ksa_auth\u003dksa_auth)[1]"}],"source_content_type":"text/x-python","patch_set":8,"id":"ccd61e3a_b0d67171","line":962,"in_reply_to":"808cf1be_b28ce247","updated":"2026-08-25 18:40:35.000000000","message":"Right. I will fix this.","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"272dd2c376b536d2de445dfe887177df520fc6d6","unresolved":false,"context_lines":[{"line_number":959,"context_line":"                strict_proxies\u003dcheck_service,"},{"line_number":960,"context_line":"                **kwargs,"},{"line_number":961,"context_line":"            )"},{"line_number":962,"context_line":"        else:"},{"line_number":963,"context_line":"            # Create a connection based on nova\u0027s service user/pass"},{"line_number":964,"context_line":"            # or a provided auth plugin."},{"line_number":965,"context_line":"            sess \u003d _get_auth_and_session(confgrp, ksa_auth\u003dksa_auth)[1]"}],"source_content_type":"text/x-python","patch_set":8,"id":"97eeb87b_aa9eb3e5","line":962,"in_reply_to":"ccd61e3a_b0d67171","updated":"2026-08-25 22:24:38.000000000","message":"Done","commit_id":"a192328e2e5002f49811aa2b86c4836c4039d4e2"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"3494d3310f8542744855212bb8f4e34f5e3c35f6","unresolved":true,"context_lines":[{"line_number":939,"context_line":"    confgrp \u003d conf_group or _get_conf_group(service_type)"},{"line_number":940,"context_line":""},{"line_number":941,"context_line":"    try:"},{"line_number":942,"context_line":"        if ksa_auth is not None:"},{"line_number":943,"context_line":"            # Create a connection based on a provided auth plugin (example:"},{"line_number":944,"context_line":"            # ServiceTokenAuthWrapper for user+service tokens, or any custom"},{"line_number":945,"context_line":"            # auth)."}],"source_content_type":"text/x-python","patch_set":11,"id":"af470658_1531dbf1","line":942,"updated":"2026-08-26 11:40:35.000000000","message":"so we are constucting this with \n```\n            auth \u003d service_auth.get_service_user_token_auth_plugin(\n                self._context)\n            self._adapter \u003d utils.get_sdk_adapter(\n                \u0027accelerator\u0027, admin\u003dFalse, ksa_auth\u003dauth)\n```\n\nthe relevent part of get_service_user_token_auth_plugin is\n\n```\n  user_auth \u003d user_auth or context.get_auth_plugin()\n\n    if CONF.service_user.send_service_user_token:\n        service_auth \u003d get_service_auth_plugin(\n                nova.conf.service_token.SERVICE_USER_GROUP)\n        ...\n   \n        return _ServiceTokenAuthWrapper(\n                   user_auth\u003duser_auth, service_auth\u003dservice_auth)\n```\n\nso if the service user section is defiend in the conf we will prepare an atho tok with the users token form the context and a service token form our config which is now required to to bind arqs in cybrog\n\ni think this is correct and required because i dont see a path today for the prior code to also include the service user token\n\n\nwith that said my suggestion is we shoul proably always try to  create a service user token in get_sdk_adapter when the config option allow\n\nso instead of passign in ksa_auth\n\ni would inline  \n```\nauth \u003d service_auth.get_service_user_token_auth_plugin(\n                self._context)\nsess \u003d _get_auth_and_session(confgrp, ksa_auth\u003dauth)\n```\nin the admin\u003d\u003dfalse  case\nand add a `get_admin_service_user_token_auth_plugin(context,confgrp)`\n\nthat will constuct the ksa_auth plugin usign the the cofnig section and service user token.\n\n\n\n```\nef get_admin_service_user_token_auth_plugin(context, conf_group):\n    \"\"\"Dynamically get an auth plugin for the config group with service user.\n\n    This function will use [service_user]send_service_user_token configuration\n    to determine whether to return either:\n\n        * a session based on the config group\n    or\n        * A wrapper around both the config auth and the service user\u0027s auth\n\n    This function should be used for calling any service with an confg derived\n    token, and will include the serviec user token when aviable.\n    \"\"\"\n    user_auth \u003d get_service_auth_plugin(conf_group)\n\n    if CONF.service_user.send_service_user_token:\n        service_auth \u003d get_service_auth_plugin(\n                nova.conf.service_token.SERVICE_USER_GROUP)\n\n        if service_auth is None:\n            # This indicates a misconfiguration so log a warning and\n            # return the user_auth.\n            LOG.warning(\u0027Unable to load auth from [service_user] \u0027\n                        \u0027configuration. Ensure \"auth_type\" is set.\u0027)\n            return user_auth\n\n        return _ServiceTokenAuthWrapper(\n                   user_auth\u003duser_auth, service_auth\u003dservice_auth)\n    return user_auth\n```","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"cea8704f8136bb2353356463be920ff5bd0d112f","unresolved":true,"context_lines":[{"line_number":939,"context_line":"    confgrp \u003d conf_group or _get_conf_group(service_type)"},{"line_number":940,"context_line":""},{"line_number":941,"context_line":"    try:"},{"line_number":942,"context_line":"        if ksa_auth is not None:"},{"line_number":943,"context_line":"            # Create a connection based on a provided auth plugin (example:"},{"line_number":944,"context_line":"            # ServiceTokenAuthWrapper for user+service tokens, or any custom"},{"line_number":945,"context_line":"            # auth)."}],"source_content_type":"text/x-python","patch_set":11,"id":"e638322e_cff95c6a","line":942,"in_reply_to":"400bdb91_e4f0e3e0","updated":"2026-08-26 15:17:28.000000000","message":"OK, I see where you are coming from. I\u0027m not sure I\u0027d go as far as to call it an active _bug_ but it\u0027s definitely \"legacy\" from before we had service token at all.\n\nAgree it\u0027s out of scope of this patch but it\u0027s tech debt that we should address.","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"c9c0eed623eb9b6e0fb36e2eb6e27daf3e53e0c5","unresolved":true,"context_lines":[{"line_number":939,"context_line":"    confgrp \u003d conf_group or _get_conf_group(service_type)"},{"line_number":940,"context_line":""},{"line_number":941,"context_line":"    try:"},{"line_number":942,"context_line":"        if ksa_auth is not None:"},{"line_number":943,"context_line":"            # Create a connection based on a provided auth plugin (example:"},{"line_number":944,"context_line":"            # ServiceTokenAuthWrapper for user+service tokens, or any custom"},{"line_number":945,"context_line":"            # auth)."}],"source_content_type":"text/x-python","patch_set":11,"id":"400bdb91_e4f0e3e0","line":942,"in_reply_to":"85b08e0d_a993285a","updated":"2026-08-26 15:06:48.000000000","message":"so that the thing if we have the service user configured in our config and send service topken is enabeld we shoudl never call a service without a service token\n\nso anything that uses 3 when the service token config is defiend is a latent bug IMO.\n\nbut that out of scope fo this patch.\n\nwe send the service_token with request so that if the user\u0027s token expries after nova recives it the operation we are dong does not end up in error whihc is imporant for thing like migraions or other long runing operations\n\nso for exmaple as soon as we supprot cold/live migration with manila shares it woudl be very impoant to send the service token when we are calling manilla even if its not required for it to work in general.","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"0c9c658675a8f1c0b29902da79b280f66e94ecf2","unresolved":true,"context_lines":[{"line_number":939,"context_line":"    confgrp \u003d conf_group or _get_conf_group(service_type)"},{"line_number":940,"context_line":""},{"line_number":941,"context_line":"    try:"},{"line_number":942,"context_line":"        if ksa_auth is not None:"},{"line_number":943,"context_line":"            # Create a connection based on a provided auth plugin (example:"},{"line_number":944,"context_line":"            # ServiceTokenAuthWrapper for user+service tokens, or any custom"},{"line_number":945,"context_line":"            # auth)."}],"source_content_type":"text/x-python","patch_set":11,"id":"85b08e0d_a993285a","line":942,"in_reply_to":"af470658_1531dbf1","updated":"2026-08-26 14:16:34.000000000","message":"I think we need the third option also though, to pass only a user token. So there are three modes:\n\n1. User token + service token\n2. Nova service user token\n3. User token\n\nSo if we inline stuff here, we still need a way to know when to use only a user token without a service token alongside (at the very least to preserve existing behavior where relevant).","commit_id":"5be4a1827ece302ed97765b6f90e827c27e9d60e"}]}
