)]}'
{"id":"openstack%2Foctavia~993688","triplet_id":"openstack%2Foctavia~master~Ia038baa8c271716747357627c777215761a74ac0","project":"openstack/octavia","branch":"master","topic":"pqc-check-spec","attention_set":{"38562":{"account":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"last_update":"2026-06-25 12:45:42.000000000","reason":"A robot voted negatively on a label"},"38360":{"account":{"_account_id":38360,"name":"Zachary Mark Raines","display_name":"Zachary Raines","email":"zachary.raines@canonical.com","username":"raineszm","status":"Sustaining Engineer @ Canonical"},"last_update":"2026-06-25 12:34:01.000000000","reason":"\u003cGERRIT_ACCOUNT_38562\u003e replied on the change","reason_account":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"}}},"removed_from_attention_set":{},"hashtags":["pqc-migration"],"change_id":"Ia038baa8c271716747357627c777215761a74ac0","subject":"Octavia Post Quantum Cryptography (PQC) check mode spec","status":"NEW","created":"2026-06-16 20:32:19.000000000","updated":"2026-08-13 16:12:58.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":26,"unresolved_comment_count":4,"has_review_started":true,"meta_rev_id":"cd4c348de38d8ea5b7191fae65f63db20d728635","_number":993688,"virtual_id_number":993688,"owner":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-06-25 13:05:35.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Backport-Candidate":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do Not Backport","-1":"Not A Backport Candidate"," 0":"Backport Review Needed","+1":"Proposed Backport","+2":"Should Backport"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"CC":[{"_account_id":38360,"name":"Zachary Mark Raines","display_name":"Zachary Raines","email":"zachary.raines@canonical.com","username":"raineszm","status":"Sustaining Engineer @ Canonical"}],"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-16 20:45:58.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2026-06-22 14:41:23.000000000","updated_by":{"_account_id":38360,"name":"Zachary Mark Raines","display_name":"Zachary Raines","email":"zachary.raines@canonical.com","username":"raineszm","status":"Sustaining Engineer @ Canonical"},"reviewer":{"_account_id":38360,"name":"Zachary Mark Raines","display_name":"Zachary Raines","email":"zachary.raines@canonical.com","username":"raineszm","status":"Sustaining Engineer @ Canonical"},"state":"CC"}],"messages":[{"id":"007b4495e49f777a50e7e4124fb6a91ba768b16c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-16 20:32:19.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"7057cd7a961f21f7bcea7ab96fc21c27428902a1","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-16 20:45:58.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/bf221ce65185491183015609fb14abbc\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/09bdc3f91b664667a3e71bebe7c4903d : FAILURE in 3m 03s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c25de7108e8642c6aedfff19dd8d1ed0 : FAILURE in 8m 25s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/302d898abb5344ecbf25a3addc55834b : FAILURE in 5m 22s","accounts_in_message":[],"_revision_number":1},{"id":"912fca46851deb5c8e8b595efdda99ec21371b51","tag":"autogenerated:claude-review","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-16 21:03:47.000000000","message":"Patch Set 1:\n\n(7 comments)\n\n*Reviewed by claude-sonnet-4-6*\n\n# Code Review: openstack/octavia - Change #993688\n\n**Gerrit URL**: https://review.opendev.org/c/openstack/octavia/+/993688\n**Patchset**: 1\n**Reviewed**: 2026-06-16 22:00:23\n**Reviewer**: claude-sonnet-4-6\n**First Review**\n\n---\n\n## Change Summary\n\nThis change introduces a spec (`specs/2026.2/pqc-strict-mode.rst`) proposing Post-Quantum Cryptography (PQC) check mode support for Octavia. The spec addresses three identified gaps: hardcoded RSA key generation for amphora mTLS certificates, no compliance checking on loaded certificates, and no operator-facing migration path or enforcement signal for quantum-safe algorithm adoption.\n\n**Files Modified**: 1\n**Lines Added**: +728\n**Lines Removed**: -0\n\n### Commit Message\n```\nOctavia Post Quantum Cryptography (PQC) check mode spec\n\nThis spec is a proposal to add a Post Quantum Cryptography check mode to Octavia.\nThis would allow operators to enable checks for cyptographic ciphers that are vulnerable to PQC methods\n\nSigned-off-by: Richard Cruise \u003crcruise@redhat.com\u003e\nCo-Authored-By: Claude Sonnet 4.6 (1M conext) \u003cnoreply@anthropic.com\u003e\n\nChange-Id: Ia038baa8c271716747357627c777215761a74ac0\n```\n\n### Purpose\n\nOctavia currently hardcodes RSA-2048 key generation for amphora mTLS certificates and performs no compliance checking on any loaded TLS certificates. This spec proposes:\n1. A configurable `key_algorithm` option to replace the hardcoded RSA call\n2. A new `pqc_utils.py` compliance-check utility\n3. Per-plane PQC check modes (DISABLED / PERMISSIVE / STRICT) for control plane (amphora mTLS) and data plane (listener/CA/pool certificates)\n\n### Scope\n\nThe spec touches `octavia/certificates/generator/local.py` (key generation and CSR construction), `octavia/common/tls_utils/cert_parser.py` (public key comparison), `octavia/certificates/manager/barbican.py`, `octavia/api/v2/controllers/base.py`, `octavia/common/constants.py`, `octavia/common/config.py`, and all four service entrypoints. This is a moderately broad change with no database schema impact.\n\n---\n\n## Test Results\n\n_No test commands configured._\n\n---\n\n## Code Analysis\n\n### Overall Assessment\n\nThis is a well-researched and clearly written spec that accurately diagnoses three real gaps in Octavia\u0027s cryptographic posture, confirms them against the actual source code, and proposes a technically sound design. The alternatives section is thorough, the migration procedure is practical, and the backward-compatibility commitment (both planes default to DISABLED) is correct. However, there are several design-level concerns and a few technical ambiguities that should be resolved before implementation begins.\n\n### Strengths\n\n- The three-part problem framing (hardcoded keygen, no compliance checking, no enforcement signal) accurately maps to real defects confirmed in `local.py` (lines 183–185) and `cert_parser.py` (lines 61–62).\n- Per-plane DISABLED / PERMISSIVE / STRICT modes cleanly model the real deployment scenario where control-plane and data-plane migrations proceed at different rates.\n- Explicit `key_algorithm` validation at startup (fail-fast `ConfigInvalidError`) is the right pattern — silent fallback to a weaker algorithm would be a security anti-pattern.\n- The RFC 5280 `KeyUsage` defect (`key_encipherment \u003d True` for ECDSA/ML-DSA keys) is correctly identified and scoped into this work.\n- The alternatives section is unusually comprehensive and well-reasoned.\n- The step-by-step operator migration procedure is thorough and includes the necessary warnings.\n- References to NIST FIPS 203/204/205 and RFC 5280 are appropriate and correctly cited.\n- DISABLED defaults throughout ensure zero impact on existing deployments.\n\n### Issues Found\n\n#### Critical Issues 🔴\n\n*None identified.*\n\n#### Major Issues 🟡\n\n1. **`ML-KEM-*` in `PQC_SAFE_ALGORITHMS` is technically incorrect for X.509 certificate compliance checking.** ML-KEM (FIPS 203) is a Key Encapsulation Mechanism — it is used for key exchange, not digital signatures. Standard X.509 TLS certificates authenticate via digital signatures; a certificate\u0027s public key algorithm field would not legitimately be `ML-KEM-*` under current TLS usage. Including ML-KEM in the allowlist for certificate compliance checking (`check_algorithm_compliance`) risks either (a) silently marking a malformed certificate as \"compliant,\" or (b) confusing implementers about what the allowlist governs. The spec should either remove ML-KEM from `PQC_SAFE_ALGORITHMS` for certificate checking, or split the constant into separate sets — one for signature algorithms (used in certificates) and one for key-exchange algorithms (used at the TLS negotiation layer, where Octavia has no direct control per the OpenSSL 3.5 note).\n\n2. **`check_algorithm_compliance` function signature conflates query and action.** The spec describes the function as returning `(algorithm_name, is_compliant)` *and* performing side effects (emitting `LOG.warning` in PERMISSIVE, raising `CertificateValidationException` in STRICT). In STRICT mode the function never returns — it raises. The return type is therefore meaningless in that path, and callers that pattern-match the tuple return will not see STRICT-mode failures unless they wrap the call in a try/except. This design is confusing. The spec should either (a) make the function a pure checker with a distinct `enforce_algorithm_compliance()` that performs actions based on the return value, or (b) explicitly document that callers must always wrap the call in a try/except and never rely on the boolean return in STRICT mode.\n\n3. **Work item 2 references the wrong file for config registration.** The work item states: *\"Add config options to `octavia/certificates/common/local.py`.\"* This file is not the correct location for oslo.config option registration in Octavia; config options are defined in their owning module and registered in `octavia/common/config.py`. The confusion between `octavia/certificates/common/local.py` (which does not exist as a standard config registration file) and the correct locations should be resolved before implementation. This should read something like: *\"Define config options in `octavia/certificates/generator/local.py` and register them in `octavia/common/config.py` under the `[certificates]` group.\"*\n\n4. **The `plane` parameter is an unvalidated bare string.** The spec defines `check_algorithm_compliance(cert_or_key, plane)` where `plane` accepts the string literals `\u0027control\u0027` or `\u0027data\u0027`. Using bare strings for an enumerated parameter creates a class of typo bugs (e.g. `\u0027ctrl\u0027`, `\u0027Control\u0027`) that will silently fall through — the function would read the wrong config option or fail with a non-obvious AttributeError. The spec should prescribe using constants (e.g. `constants.CERT_PLANE_CONTROL`, `constants.CERT_PLANE_DATA`) rather than bare strings.\n\n#### Minor Issues / Suggestions 🔵\n\n1. **The spec is silent on what happens when `check_algorithm_compliance` encounters an unrecognised key type.** The text says the function uses `isinstance` checks against pyca/cryptography key classes and OID comparison for PQC types. What is the contract if the key type is not in any of those branches? Fail open (treat as compliant, risk missing a novel quantum-vulnerable algorithm)? Fail closed (treat as non-compliant, risk breaking a legitimate deployment on an unusual but safe algorithm)? Log an error? The spec must state the intended behaviour.\n\n2. **SIGHUP / config-reload claim is not uniformly supported.** The spec states: *\"If the service is reloaded via SIGHUP (config reload), the function is called again.\"* oslo.config SIGHUP support is not uniformly implemented across all four Octavia services; in particular, `octavia-worker` and `octavia-health-manager` have historically had partial or no SIGHUP config reload paths. This claim should be verified against the actual service implementations and the text qualified appropriately (e.g. \"on services that support oslo.config SIGHUP reload\").\n\n3. **The spec defers `SLH-DSA-*` from `key_algorithm` but includes it in `PQC_SAFE_ALGORITHMS`.** The proposed `key_algorithm` values include ML-DSA variants but do not include SLH-DSA variants. The `PQC_SAFE_ALGORITHMS` constant includes SLH-DSA. While SLH-DSA is a valid signature algorithm and could in principle appear in an operator-supplied certificate, the inconsistency between what can be *generated* via `key_algorithm` and what is in the allowlist should be noted in the spec to avoid implementer confusion.\n\n4. **`public_bytes()` encoding not specified for the cert_parser fix.** The spec proposes replacing `.public_numbers()` comparison with `.public_bytes()` serialisation. `public_bytes()` requires two encoding parameters (encoding and format, e.g. `serialization.Encoding.DER` and `serialization.PublicFormat.SubjectPublicKeyInfo`). The spec should specify the intended encoding to avoid implementation inconsistency.\n\n5. **The startup algorithm-list warning fires only when *any* plane is non-DISABLED.** The spec states: *\"if any plane is non-DISABLED, compare `CONF.certificates.pqc_allowed_algorithms` against `constants.PQC_SAFE_ALGORITHMS`.\"* This means a deployment with both planes DISABLED will not be warned even if the operator has customised the allowlist — which could mask a misconfiguration. Consider whether the warning should fire whenever the list is customised, regardless of mode.\n\n6. **`pqc_allowed_algorithms` override-not-extend semantics should be flagged as a potential operator footgun more prominently.** The spec documents this correctly but only in prose. Because oslo.config list option replacement semantics are not intuitive (operators coming from additive-style configs may expect merging), the deployer impact section and config reference should include a concrete bad-example alongside the current good-example.\n\n#### Nits 🟢\n\n- Commit message subject: `\"cyptographic\"` is a typo — should be `\"cryptographic\"`.\n- Commit message `Co-Authored-By` line: `\"1M conext\"` should be `\"1M context\"`. Additionally, listing an AI system as a git Co-Author is unconventional in OpenStack and may attract questions from core reviewers; the author should be aware this may become a discussion point on Gerrit.\n- Spec filename `pqc-strict-mode.rst` does not accurately reflect the content — the spec covers three modes (DISABLED, PERMISSIVE, STRICT), not just strict mode. Consider renaming to `pqc-check-mode.rst` to match the spec title.\n- Spec section \"Assignee(s)\": both primary assignee and other contributors are `None`. For a spec of this scope, at least the primary assignee should be set.\n- Minor RST: the spec uses two-space sentence separation consistently — good practice for RST source.\n\n---\n\n## Security Analysis\n\nThe spec\u0027s security posture is sound overall. Key observations:\n\n**Positive**: The fail-fast `ConfigInvalidError` on startup for unsupported `key_algorithm` values is the correct security pattern. Silent fallback to RSA would be a regression. The DISABLED default prevents any existing deployment from being broken by the new checks.\n\n**Positive**: The startup warning when `pqc_allowed_algorithms` deviates from `PQC_SAFE_ALGORITHMS` provides an audit trail without preventing operator customisation — a good balance between security and operability.\n\n**Concern**: Including `ML-KEM-*` in `PQC_SAFE_ALGORITHMS` could produce a false sense of compliance for malformed certificates, as noted in the Major Issues section above. This is the most significant security-adjacent concern in the spec.\n\n**Concern**: The spec notes that `_generate_private_key()` and `_generate_csr()` are the most security-sensitive paths in Octavia (they generate amphora mTLS certificates). Implementers must be careful that the dispatch logic in `_generate_private_key()` cannot be manipulated into choosing a weaker algorithm than configured — in particular, the `ConfigInvalidError` path must fire before any key material is generated, not after.\n\n---\n*This review was generated by an AI and may contain errors.*","accounts_in_message":[],"_revision_number":1},{"id":"040f604ae2fabbb1beff7574af2d8f105908079f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-17 10:18:28.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"77ebe197c2bff6c7344b9f6967473480a4604d5a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-17 10:32:47.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/6a53f9be9aa243a9899a9fea999a075d\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/db2571990904416c9731b686abb189f5 : FAILURE in 4m 08s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/2fcf27fae17d4159bf3f5584f4b4ce08 : FAILURE in 6m 54s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/d1e1d5dbcc4b4719a021dc88ca20a12a : SUCCESS in 9m 04s","accounts_in_message":[],"_revision_number":2},{"id":"b2522407e24269364c336bfbb6e367f63f68596b","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-17 10:54:40.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":3},{"id":"f439c7dee4a82993bdc47eb8c51256a3a3db9a08","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-17 11:05:17.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/17953f28b7a74d958ba39597e746e3df\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/7fa534bb943641f08d7c8f2965f99fbd : SUCCESS in 4m 33s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e4114a3af1374b7aaa56365df2d51437 : FAILURE in 9m 06s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/aecc8fa13dbb48dfa54f7223405d32ae : SUCCESS in 3m 56s","accounts_in_message":[],"_revision_number":3},{"id":"6fc1bad18446cb32c92d6ca87cdd51609842d84a","tag":"autogenerated:claude-review","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-17 11:17:57.000000000","message":"Patch Set 3:\n\n*CI analysis by claude-sonnet-4-6*\n\n## Overall Recommendation\n\n**Action Required:** CODE FIX REQUIRED\n\nThe sole failing job `openstack-tox-docs` is a voting job and its failure is directly caused by a missing toctree entry for a new spec file introduced by this patchset. The fix is trivial (one line added to the appropriate `index.rst`) but must be made before the job will pass. Re-running without a code change will produce the same failure.\n\n### Jobs Requiring Code Fix\n\n- **openstack-tox-docs** — Add `pqc-strict-mode` to the `toctree` in `doc/source/contributor/specs/2026.2/index.rst` so the new spec file is reachable from the documentation tree.\n\n### Jobs That Can Be Re-Run\n\nNone.\n\n## Failing Jobs\n\n| Field | Value |\n|-------|-------|\n| Gerrit Change | [openstack/octavia #993688](https://review.opendev.org/c/openstack/octavia/+/993688) |\n| Patchset | 3 |\n| Pipeline | check |\n| Total Failing Jobs | 1 |\n| Analysis Date | 2026-06-17 12:15:32 UTC |\n\n---\n*This analysis was generated by an AI and may contain errors.*","accounts_in_message":[],"_revision_number":3},{"id":"4e3c32985b3a3ae28b9a68ee2771619e2381cd10","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-17 11:29:55.000000000","message":"Uploaded patch set 4.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":4},{"id":"f08cb37081c082f1ec25c8222768e2fca57fab18","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-17 11:44:45.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2b0f50a534854b7e8bbf080bf94b357f\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/030ef4761f8d402c8322e40496099c10 : SUCCESS in 3m 19s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/26ecb1252eca480b83f4b3a0295beba2 : SUCCESS in 13m 17s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/7be280d1a55140fc939869d41cf23a65 : SUCCESS in 4m 28s","accounts_in_message":[],"_revision_number":4},{"id":"12c59455c884dff97a7a9be14182759d8036f905","author":{"_account_id":38360,"name":"Zachary Mark Raines","display_name":"Zachary Raines","email":"zachary.raines@canonical.com","username":"raineszm","status":"Sustaining Engineer @ Canonical"},"date":"2026-06-22 14:41:23.000000000","message":"Patch Set 4:\n\n(6 comments)","accounts_in_message":[],"_revision_number":4},{"id":"2097882e84da9a02dd93098c7ca788f91c3d77c6","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-22 16:02:54.000000000","message":"Patch Set 4:\n\n(6 comments)","accounts_in_message":[],"_revision_number":4},{"id":"8591ab4a2fc78ab59fa94426df2f362d3c62f9cb","author":{"_account_id":38360,"name":"Zachary Mark Raines","display_name":"Zachary Raines","email":"zachary.raines@canonical.com","username":"raineszm","status":"Sustaining Engineer @ Canonical"},"date":"2026-06-23 18:23:27.000000000","message":"Patch Set 4:\n\n(2 comments)","accounts_in_message":[],"_revision_number":4},{"id":"7020c67f76f9c76e3e82f6160b639802c57e29a4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-25 12:28:35.000000000","message":"Uploaded patch set 5.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":5},{"id":"73687aed280681b0d9ab318aa70eb96005370d1e","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-25 12:34:01.000000000","message":"Patch Set 5:\n\n(5 comments)","accounts_in_message":[],"_revision_number":5},{"id":"0e2e951f7311ffca42e53943f438d447813dea1e","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-25 12:45:42.000000000","message":"Patch Set 5: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/155543d137cd4cfaae3aaa98963a8f11\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5919256e63c14b1380db423e9c02ef58 : FAILURE in 5m 51s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1204887ffdc64a0cbe2b00f21d73103b : SUCCESS in 12m 24s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/263087a333e54b8bac6738777c3bb5cc : SUCCESS in 9m 05s","accounts_in_message":[],"_revision_number":5},{"id":"53f07bb0de966f70bdc772fbd127afaab44b4ea5","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"date":"2026-06-25 12:52:29.000000000","message":"Uploaded patch set 6.\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":6},{"id":"63df959498da490eafb2a313e34608b4de64ace8","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-06-25 13:05:35.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/873c307e38a14b9196d6909069a4fcc4\n\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/cd089193ec5f4e91ade8da88965cada9 : SUCCESS in 3m 42s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8532f301a5944868985071aa3fbc1250 : SUCCESS in 6m 52s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/3cd0aee991f94c41a3ead26dfaead376 : SUCCESS in 8m 24s","accounts_in_message":[],"_revision_number":6},{"id":"cd4c348de38d8ea5b7191fae65f63db20d728635","tag":"autogenerated:gerrit:setHashtag","author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"date":"2026-08-13 16:12:58.000000000","message":"Hashtag added: pqc-migration","accounts_in_message":[],"_revision_number":6}],"current_revision_number":6,"current_revision":"dd3a94a07adae146a9589425cfe5b41bd6cceae5","revisions":{"59d1ed963724ce0f441d49e60246c7cebd24a3ff":{"kind":"REWORK","_number":1,"created":"2026-06-16 20:32:19.000000000","uploader":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"ref":"refs/changes/88/993688/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/88/993688/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/88/993688/1"}}},"commit":{"parents":[{"commit":"9ff4683c8212e4c043af69f1b5ebadc21651dc58","subject":"Merge \"Drop Python 3.10\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/9ff4683c8212e4c043af69f1b5ebadc21651dc58"}]}],"author":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-03 14:38:27.000000000","tz":60},"committer":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-16 20:30:22.000000000","tz":60},"subject":"Octavia Post Quantum Cryptography (PQC) check mode spec","message":"Octavia Post Quantum Cryptography (PQC) check mode spec\n\nThis spec is a proposal to add a Post Quantum Cryptography check mode to Octavia.\nThis would allow operators to enable checks for cyptographic ciphers that are vulnerable to PQC methods\n\nChange-Id: Ia038baa8c271716747357627c777215761a74ac0\nSigned-off-by: Richard Cruise \u003crcruise@redhat.com\u003e\nCo-Authored-By: Claude Sonnet 4.6 (1M conext) \u003cnoreply@anthropic.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/59d1ed963724ce0f441d49e60246c7cebd24a3ff"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/59d1ed963724ce0f441d49e60246c7cebd24a3ff"}]},"branch":"refs/heads/master"},"efb24b765d7e26fbb64ae92ef9c3197f1f6d88b0":{"kind":"REWORK","_number":2,"created":"2026-06-17 10:18:28.000000000","uploader":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"ref":"refs/changes/88/993688/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/88/993688/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/88/993688/2"}}},"commit":{"parents":[{"commit":"9ff4683c8212e4c043af69f1b5ebadc21651dc58","subject":"Merge \"Drop Python 3.10\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/9ff4683c8212e4c043af69f1b5ebadc21651dc58"}]}],"author":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-03 14:38:27.000000000","tz":60},"committer":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-17 10:18:19.000000000","tz":60},"subject":"Octavia Post Quantum Cryptography (PQC) check mode spec","message":"Octavia Post Quantum Cryptography (PQC) check mode spec\n\nThis spec is a proposal to add a Post Quantum Cryptography check mode to Octavia.\nThis would allow operators to enable checks for cyptographic ciphers that are vulnerable to PQC methods\n\nChange-Id: Ia038baa8c271716747357627c777215761a74ac0\nSigned-off-by: Richard Cruise \u003crcruise@redhat.com\u003e\nCo-Authored-By: Claude Sonnet 4.6 (1M conext) \u003cnoreply@anthropic.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/efb24b765d7e26fbb64ae92ef9c3197f1f6d88b0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/efb24b765d7e26fbb64ae92ef9c3197f1f6d88b0"}]},"branch":"refs/heads/master"},"356285a947626cca9ec1b3f10c1d26fbd11ab3e3":{"kind":"REWORK","_number":3,"created":"2026-06-17 10:54:40.000000000","uploader":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"ref":"refs/changes/88/993688/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/88/993688/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/88/993688/3"}}},"commit":{"parents":[{"commit":"9ff4683c8212e4c043af69f1b5ebadc21651dc58","subject":"Merge \"Drop Python 3.10\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/9ff4683c8212e4c043af69f1b5ebadc21651dc58"}]}],"author":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-03 14:38:27.000000000","tz":60},"committer":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-17 10:51:49.000000000","tz":60},"subject":"Octavia Post Quantum Cryptography (PQC) check mode spec","message":"Octavia Post Quantum Cryptography (PQC) check mode spec\n\nThis spec is a proposal to add a Post Quantum Cryptography check mode to Octavia.\nThis would allow operators to enable checks for cyptographic ciphers that are vulnerable to PQC methods\n\nChange-Id: Ia038baa8c271716747357627c777215761a74ac0\nSigned-off-by: Richard Cruise \u003crcruise@redhat.com\u003e\nCo-Authored-By: Claude Sonnet 4.6 (1M conext) \u003cnoreply@anthropic.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/356285a947626cca9ec1b3f10c1d26fbd11ab3e3"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/356285a947626cca9ec1b3f10c1d26fbd11ab3e3"}]},"branch":"refs/heads/master"},"20a4d449d4b8d38516e450a7021a84540225ea57":{"kind":"REWORK","_number":4,"created":"2026-06-17 11:29:55.000000000","uploader":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"ref":"refs/changes/88/993688/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/88/993688/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/88/993688/4"}}},"commit":{"parents":[{"commit":"9ff4683c8212e4c043af69f1b5ebadc21651dc58","subject":"Merge \"Drop Python 3.10\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/9ff4683c8212e4c043af69f1b5ebadc21651dc58"}]}],"author":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-03 14:38:27.000000000","tz":60},"committer":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-17 11:29:46.000000000","tz":60},"subject":"Octavia Post Quantum Cryptography (PQC) check mode spec","message":"Octavia Post Quantum Cryptography (PQC) check mode spec\n\nThis spec is a proposal to add a Post Quantum Cryptography check mode to Octavia.\nThis would allow operators to enable checks for cyptographic ciphers that are vulnerable to PQC methods\n\nChange-Id: Ia038baa8c271716747357627c777215761a74ac0\nSigned-off-by: Richard Cruise \u003crcruise@redhat.com\u003e\nCo-Authored-By: Claude Sonnet 4.6 (1M conext) \u003cnoreply@anthropic.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/20a4d449d4b8d38516e450a7021a84540225ea57"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/20a4d449d4b8d38516e450a7021a84540225ea57"}]},"branch":"refs/heads/master"},"b2ebf4c23c975f341c5a3c20c7c1d954a5a89561":{"kind":"REWORK","_number":5,"created":"2026-06-25 12:28:35.000000000","uploader":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"ref":"refs/changes/88/993688/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/88/993688/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/88/993688/5"}}},"commit":{"parents":[{"commit":"9ff4683c8212e4c043af69f1b5ebadc21651dc58","subject":"Merge \"Drop Python 3.10\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/9ff4683c8212e4c043af69f1b5ebadc21651dc58"}]}],"author":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-03 14:38:27.000000000","tz":60},"committer":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-25 12:28:04.000000000","tz":60},"subject":"Octavia Post Quantum Cryptography (PQC) check mode spec","message":"Octavia Post Quantum Cryptography (PQC) check mode spec\n\nThis spec is a proposal to add a Post Quantum Cryptography check mode to Octavia.\nThis would allow operators to enable checks for cyptographic ciphers that are vulnerable to PQC methods\n\nChange-Id: Ia038baa8c271716747357627c777215761a74ac0\nSigned-off-by: Richard Cruise \u003crcruise@redhat.com\u003e\nCo-Authored-By: Claude Sonnet 4.6 (1M conext) \u003cnoreply@anthropic.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/b2ebf4c23c975f341c5a3c20c7c1d954a5a89561"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/b2ebf4c23c975f341c5a3c20c7c1d954a5a89561"}]},"branch":"refs/heads/master"},"dd3a94a07adae146a9589425cfe5b41bd6cceae5":{"kind":"REWORK","_number":6,"created":"2026-06-25 12:52:29.000000000","uploader":{"_account_id":38562,"name":"Richard Cruise","email":"rcruise@redhat.com","username":"rcruise"},"ref":"refs/changes/88/993688/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/octavia","ref":"refs/changes/88/993688/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/octavia refs/changes/88/993688/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/octavia refs/changes/88/993688/6"}}},"commit":{"parents":[{"commit":"9ff4683c8212e4c043af69f1b5ebadc21651dc58","subject":"Merge \"Drop Python 3.10\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/9ff4683c8212e4c043af69f1b5ebadc21651dc58"}]}],"author":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-03 14:38:27.000000000","tz":60},"committer":{"name":"Richard Cruise","email":"rcruise@redhat.com","date":"2026-06-25 12:52:20.000000000","tz":60},"subject":"Octavia Post Quantum Cryptography (PQC) check mode spec","message":"Octavia Post Quantum Cryptography (PQC) check mode spec\n\nThis spec is a proposal to add a Post Quantum Cryptography check mode to Octavia.\nThis would allow operators to enable checks for cyptographic ciphers that are vulnerable to PQC methods\n\nChange-Id: Ia038baa8c271716747357627c777215761a74ac0\nSigned-off-by: Richard Cruise \u003crcruise@redhat.com\u003e\nCo-Authored-By: Claude Sonnet 4.6 (1M conext) \u003cnoreply@anthropic.com\u003e\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/dd3a94a07adae146a9589425cfe5b41bd6cceae5"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/octavia/commit/dd3a94a07adae146a9589425cfe5b41bd6cceae5"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"},{"label":"Backport-Candidate","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Backport-Candidate","description":"Backport candidate status","status":"NOT_APPLICABLE","is_legacy":false,"applicability_expression_result":{"fulfilled":false,"status":"FAIL"},"submittability_expression_result":{"expression":"is:true","fulfilled":true,"status":"NOT_EVALUATED","passing_atoms":[],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
