)]}'
{"id":"openstack%2Foctavia~797322","triplet_id":"openstack%2Foctavia~master~Ib062c53ce2438485f3252bd6e1cf7db197b8a4cd","project":"openstack/octavia","branch":"master","topic":"fix-encode-url-path","hashtags":[],"change_id":"Ib062c53ce2438485f3252bd6e1cf7db197b8a4cd","subject":"fix(common): normalize url before render haproxy config","status":"NEW","created":"2021-06-21 15:07:33.000000000","updated":"2021-07-29 22:15:27.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":false,"submittable":false,"total_comment_count":1,"unresolved_comment_count":1,"has_review_started":true,"meta_rev_id":"41b8ba7827d4e8a4150bf4962d5bdd7cd763a558","_number":797322,"virtual_id_number":797322,"owner":{"_account_id":25290,"name":"Mikhail Ushanov","email":"gm.mephisto@gmail.com","username":"gmmephisto"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"tag":"autogenerated:zuul:check","value":1,"date":"2021-06-21 17:07:57.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"disliked":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"all":[{"value":-1,"date":"2021-06-21 18:01:55.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":-1,"default_value":0,"optional":true},"Workflow":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Backport-Candidate":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}],"values":{"-2":"Do Not Backport","-1":"Not A Backport Candidate"," 0":"Backport Review Needed","+1":"Proposed Backport","+2":"Should Backport"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-06-21 16:55:23.000000000","updated_by":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"reviewer":{"_account_id":29244,"name":"Gregory Thiemonge","email":"gthiemon@redhat.com","username":"gthiemonge"},"state":"REVIEWER"},{"updated":"2021-06-21 17:07:57.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-06-21 18:01:55.000000000","updated_by":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"reviewer":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"state":"REVIEWER"},{"updated":"2021-06-22 02:42:20.000000000","updated_by":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"reviewer":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"state":"REVIEWER"},{"updated":"2021-07-29 22:15:27.000000000","updated_by":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"reviewer":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"state":"REMOVED"}],"messages":[{"id":"17f2ddd6fdd00cd06d97ae3661c19edd33390f11","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25290,"name":"Mikhail Ushanov","email":"gm.mephisto@gmail.com","username":"gmmephisto"},"date":"2021-06-21 15:07:33.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"17ca11ff2e71ce7ce1b65a7674999a653310efcf","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-06-21 17:07:57.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/c4b21edabcd743d9bb6a0b5eedff519e : SUCCESS in 11m 29s\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/bdab20783eb147549d3b8709f43e0f0d : SUCCESS in 9m 07s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/9aff9bb7c6d54b3484e6f4df760ccf5e : SUCCESS in 7m 01s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/9d0972740a004bb6a3119b63e1ca0628 : SUCCESS in 6m 30s\n- openstack-tox-py38 https://zuul.opendev.org/t/openstack/build/573d348e0a6e404899bb34df6e158b00 : SUCCESS in 6m 39s\n- openstack-tox-py39 https://zuul.opendev.org/t/openstack/build/f20401cbc45e49b483a4e1818aa60d60 : SUCCESS in 7m 14s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/5094bd2b275e4582bcad7914137f67dc : SUCCESS in 12m 15s\n- octavia-tox-py37-tips https://zuul.opendev.org/t/openstack/build/d5b344867ebf401b9b6aa3b31b23b84a : SUCCESS in 6m 33s\n- octavia-tox-functional-py37-tips https://zuul.opendev.org/t/openstack/build/4a20e6b9b789499f9f7dbfa93239de57 : SUCCESS in 10m 31s\n- openstack-tox-pip-check-reqs https://zuul.opendev.org/t/openstack/build/5efb4195095c4fb08e87ed824fcdd2ad : SUCCESS in 6m 01s\n- openstack-tox-functional-py36 https://zuul.opendev.org/t/openstack/build/29f91ae8a5544eef9868255ebf61ae4e : SUCCESS in 8m 29s\n- octavia-v2-dsvm-noop-api https://zuul.opendev.org/t/openstack/build/88935c0346c9499e89e3c248aed04cf5 : SUCCESS in 1h 37m 35s\n- octavia-v2-dsvm-scenario https://zuul.opendev.org/t/openstack/build/4854c7b01f874811ae71d53dd0a2b9b7 : SUCCESS in 1h 56m 39s\n- octavia-v2-dsvm-tls-barbican https://zuul.opendev.org/t/openstack/build/dca228718e3841649a87dfe298bfe413 : SUCCESS in 57m 41s\n- octavia-v2-act-stdby-dsvm-scenario https://zuul.opendev.org/t/openstack/build/29a2c8b48b774ebe9732ebcc0d225e79 : SUCCESS in 43m 04s\n- octavia-grenade https://zuul.opendev.org/t/openstack/build/491c87be34f247d7ba4e8694f82078ad : SUCCESS in 48m 08s\n- octavia-v2-dsvm-cinder-amphora https://zuul.opendev.org/t/openstack/build/7faa8486f07e4222a2ff1d951be61f44 : SUCCESS in 1h 44m 19s (non-voting)\n- octavia-v2-dsvm-scenario-two-node https://zuul.opendev.org/t/openstack/build/aa1d66e0c0444ad29594576a6f061c28 : FAILURE in 16m 31s (non-voting)\n- octavia-v2-dsvm-scenario-ipv6-only https://zuul.opendev.org/t/openstack/build/bf47629582484d6fb8571118e9754070 : SUCCESS in 1h 58m 13s (non-voting)\n- octavia-v2-dsvm-scenario-amphora-v2 https://zuul.opendev.org/t/openstack/build/a089b4c9877f4af79de1fef66118c872 : SUCCESS in 1h 33m 46s (non-voting)\n- octavia-v2-dsvm-scenario-amphora-v2-no-jobboard https://zuul.opendev.org/t/openstack/build/da7a783f64384283a7ee23fbcbd77da3 : SUCCESS in 1h 58m 17s (non-voting)\n- octavia-v2-dsvm-scenario-centos-8 https://zuul.opendev.org/t/openstack/build/948d704b048a4f13b1929a4fe8e0599b : FAILURE in 9m 08s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"556239cdc15227449560ddf8964afe4f25182d44","author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"date":"2021-06-21 18:01:55.000000000","message":"Patch Set 1: Code-Review-1\n\n(1 comment)\n\nNote: To trigger this, the user must already have authorization to make changes to the load balancer. The scope of the issue is limited to the user running arbitrary code on their own load balancer instance.\n\nAlso, in the future, please help us by following the OpenStack security issue process here:\nhttps://security.openstack.org/vmt-process.html\n\nThat said, I think it would be better to enhance the existing validation for this field here:\nhttps://opendev.org/openstack/octavia/src/branch/master/octavia/common/validate.py#L52","accounts_in_message":[],"_revision_number":1},{"id":"f8f77ba10d97dd4e434b4d0bb986efd8a7993c43","author":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"},"date":"2021-06-21 20:34:02.000000000","message":"Patch Set 1:\n\nWe are going to want a functional test and release note for this as well.","accounts_in_message":[],"_revision_number":1},{"id":"41b8ba7827d4e8a4150bf4962d5bdd7cd763a558","tag":"autogenerated:gerrit:deleteReviewer","author":{"_account_id":1131,"name":"Brian Haley","email":"haleyb.dev@gmail.com","username":"brian-haley"},"date":"2021-07-29 22:15:27.000000000","message":"Removed reviewer Brian Haley.","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"bf44f093cc4e77af07bc8536ecd6e57a13801588","revisions":{"bf44f093cc4e77af07bc8536ecd6e57a13801588":{"kind":"REWORK","_number":1,"created":"2021-06-21 15:07:33.000000000","uploader":{"_account_id":25290,"name":"Mikhail Ushanov","email":"gm.mephisto@gmail.com","username":"gmmephisto"},"ref":"refs/changes/22/797322/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/22/797322/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/22/797322/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/22/797322/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/22/797322/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/22/797322/1"}}},"commit":{"parents":[{"commit":"1d77e93f2889627cb87f1aed3259b83e91e83239","subject":"Merge \"Fix new errors with SQLAlchemy 1.4\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/1d77e93f2889627cb87f1aed3259b83e91e83239"}]}],"author":{"name":"Mikhail Ushanov","email":"gm.mephisto@gmail.com","date":"2021-06-21 14:40:08.000000000","tz":180},"committer":{"name":"Mikhail Ushanov","email":"gm.mephisto@gmail.com","date":"2021-06-21 15:00:10.000000000","tz":180},"subject":"fix(common): normalize url before render haproxy config","message":"fix(common): normalize url before render haproxy config\n\nFix Remote Code Execution in HAProxy Amphora Agent that based on\nconfig injection throughout url_path attribute in HealthMonitor or\nredirect_url / redirect_prefix attributes in L7Policy.\n\nTask: 42656\nStory: 2008994\n\nChange-Id: Ib062c53ce2438485f3252bd6e1cf7db197b8a4cd\nSigned-off-by: Mikhail Ushanov \u003cgm.mephisto@gmail.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/bf44f093cc4e77af07bc8536ecd6e57a13801588"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/bf44f093cc4e77af07bc8536ecd6e57a13801588"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY","applied_by":{"_account_id":11628,"name":"Michael Johnson","email":"johnsomor@gmail.com","username":"johnsom"}},{"label":"Workflow","status":"MAY"},{"label":"Backport-Candidate","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Backport-Candidate","description":"Backport candidate status","status":"NOT_APPLICABLE","is_legacy":false,"applicability_expression_result":{"fulfilled":false,"status":"FAIL"},"submittability_expression_result":{"expression":"is:true","fulfilled":true,"status":"NOT_EVALUATED","passing_atoms":[],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
