)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"6f994c7f1b7fcc9186419187e0ab5fa4dbb0edc5","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     Stephen Finucane \u003cstephenfin@redhat.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2026-09-23 15:17:42 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"encryptors: Drop support for out-of-tree encryptors"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This should have been done in Queens. Do it now."},{"line_number":10,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"85295338_df8d1a90","line":7,"updated":"2026-09-24 13:53:24.000000000","message":"\"This should have been done in Queens\" is fair, but the commit message should say what the prerequisites are (cinder migration, nova and cinder dropping the map) and carry Depends-On lines once those changes exist.","commit_id":"771c6bfefbdc8abcd3f5a7bd5a7eb435da18a2b0"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"6f994c7f1b7fcc9186419187e0ab5fa4dbb0edc5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"a2f85978_3b0dc041","updated":"2026-09-24 13:53:24.000000000","message":"Both Zuul failures are caused by this patch, not flakes: nova and cinder still import ``LEGACY_PROVIDER_CLASS_TO_FORMAT_MAP`` at runtime, so every encrypted volume attach fails with AttributeError (details inline at line 30). Lee\u0027s 2021 point about legacy provider names still living in cinder\u0027s database also stands, and there is no cinder migration open.\n\n-1. The order has to be: cinder migrates legacy ``provider`` values and tightens the API schema, nova and cinder stop using the map, then this. Alternatively keep the map exported with a deprecation for one cycle so this can merge now.","commit_id":"771c6bfefbdc8abcd3f5a7bd5a7eb435da18a2b0"}],"os_brick/encryptors/__init__.py":[{"author":{"_account_id":1736,"name":"Ivan Kolodyazhny","email":"e0ne@e0ne.info","username":"e0ne"},"change_message_id":"0fdb228cfcc3cb7740ff64426a9553d7c0a0f97f","unresolved":true,"context_lines":[{"line_number":26,"context_line":"LUKS2 \u003d \"luks2\""},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"FORMAT_TO_FRONTEND_ENCRYPTOR_MAP \u003d {"},{"line_number":29,"context_line":"    LUKS: \u0027os_brick.encryptors.luks.LuksEncryptor\u0027,"},{"line_number":30,"context_line":"    LUKS2: \u0027os_brick.encryptors.luks.Luks2Encryptor\u0027,"},{"line_number":31,"context_line":"}"},{"line_number":32,"context_line":""}],"source_content_type":"text/x-python","patch_set":4,"id":"7eeb88a2_a32c96a9","line":29,"updated":"2022-02-14 11:32:13.000000000","message":"Since we drop support ou out of tree encryptors, we can simplify this map to:\nFORMAT_TO_FRONTEND_ENCRYPTOR_MAP \u003d {\n    LUKS: os_brick.encryptors.luks.LuksEncryptor,\n    LUKS2: os_brick.encryptors.luks.Luks2Encryptor,\n    None: os_brick.encryptors.nop.NoOpEncryptor\n}\n\nIt means, we don\u0027t need to store classes names as string and use importutils anymore","commit_id":"09df39f401b7a4c3c06c16bffb2b994f755f5e56"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"80fcc943e3caac73323895087b79c80264c495e2","unresolved":false,"context_lines":[{"line_number":26,"context_line":"LUKS2 \u003d \"luks2\""},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"FORMAT_TO_FRONTEND_ENCRYPTOR_MAP \u003d {"},{"line_number":29,"context_line":"    LUKS: \u0027os_brick.encryptors.luks.LuksEncryptor\u0027,"},{"line_number":30,"context_line":"    LUKS2: \u0027os_brick.encryptors.luks.Luks2Encryptor\u0027,"},{"line_number":31,"context_line":"}"},{"line_number":32,"context_line":""}],"source_content_type":"text/x-python","patch_set":4,"id":"b3b6280b_8b6ec019","line":29,"in_reply_to":"7eeb88a2_a32c96a9","updated":"2022-04-11 15:55:09.000000000","message":"Done","commit_id":"09df39f401b7a4c3c06c16bffb2b994f755f5e56"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"6f994c7f1b7fcc9186419187e0ab5fa4dbb0edc5","unresolved":true,"context_lines":[{"line_number":27,"context_line":"LUKS \u003d \"luks\""},{"line_number":28,"context_line":"LUKS2 \u003d \"luks2\""},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"FORMAT_TO_FRONTEND_ENCRYPTOR_MAP \u003d {"},{"line_number":31,"context_line":"    LUKS: luks_encryptor.LuksEncryptor,"},{"line_number":32,"context_line":"    LUKS2: luks_encryptor.Luks2Encryptor,"},{"line_number":33,"context_line":"    None: nop_encryptor.NoOpEncryptor,"}],"source_content_type":"text/x-python","patch_set":9,"id":"5af38fc7_16e3d614","line":30,"range":{"start_line":30,"start_character":0,"end_line":30,"end_character":36},"updated":"2026-09-24 13:53:24.000000000","message":"Removing ``LEGACY_PROVIDER_CLASS_TO_FORMAT_MAP`` from the module breaks both consumers:\n\n  * nova ``virt/libvirt/driver.py:2312`` (``_use_native_luks``), on every encrypted attach\n  * cinder ``volume/volume_utils.py:1266`` (``check_encryption_provider``), used by the RBD, remotefs and vmstore drivers on encrypted create\n  * cinder ``volume/drivers/vmstore/nfs.py:390``\n  \nThe n-cpu and c-vol logs from both failed jobs show ``AttributeError: module \u0027os_brick.encryptors\u0027 has no attribute \u0027LEGACY_PROVIDER_CLASS_TO_FORMAT_MAP\u0027``; that is the six encryption scenario failures in lvm-lio-barbican and the two ``test_boot_server_from_encrypted_volume_*`` failures in tempest-full-py3.\n\nTwo ways forward: land nova and cinder cleanups first with an os-brick minimum bump, or keep the name exported here (a module-level ``__getattr__`` with a debtcollector warning, or just leave the dict in place) for one cycle.\n\nAlso note the value type of F``ORMAT_TO_FRONTEND_ENCRYPTOR_MAP`` changes from string to class. Nothing in cinder or nova master reads it, so that is safe, but please mention it in the release note.","commit_id":"771c6bfefbdc8abcd3f5a7bd5a7eb435da18a2b0"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"6f994c7f1b7fcc9186419187e0ab5fa4dbb0edc5","unresolved":true,"context_lines":[{"line_number":34,"context_line":"}"},{"line_number":35,"context_line":""},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"def get_volume_encryptor(root_helper: str,"},{"line_number":38,"context_line":"                         connection_info: dict[str, Any],"},{"line_number":39,"context_line":"                         keymgr,"},{"line_number":40,"context_line":"                         execute\u003dNone,"}],"source_content_type":"text/x-python","patch_set":9,"id":"0ba7d37b_3d7c7d0a","line":37,"range":{"start_line":37,"start_character":4,"end_line":37,"end_character":24},"updated":"2026-09-24 13:53:24.000000000","message":"Even once the imports above are fixed, cinder never migrated the ``encryption.provider`` column and the API accepts any string, so long-running deployments have volume types (and attached volumes) with ``nova.volume.encryptors.luks.LuksEncryptor`` or ``LuksEncryptor`` as the provider. After this merges those volumes fail to attach with the TypeError below. That needs a cinder data migration (or an online fix-up in ``check_encryption_provider`` plus schema validation) before os-brick drops the mapping. Lee raised this on PS2 in 2021 and nothing has landed in cinder since.","commit_id":"771c6bfefbdc8abcd3f5a7bd5a7eb435da18a2b0"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"6f994c7f1b7fcc9186419187e0ab5fa4dbb0edc5","unresolved":true,"context_lines":[{"line_number":64,"context_line":"                \u0027longer supports out-of-tree encryptor classes\u0027,"},{"line_number":65,"context_line":"                {\u0027provider\u0027: provider},"},{"line_number":66,"context_line":"            )"},{"line_number":67,"context_line":"            raise TypeError("},{"line_number":68,"context_line":"                \u0027Unrecognized encryptor class %(provider)s; os-brick no \u0027"},{"line_number":69,"context_line":"                \u0027longer supports out-of-tree encryptor classes\u0027"},{"line_number":70,"context_line":"                % {\u0027provider\u0027: provider}"}],"source_content_type":"text/x-python","patch_set":9,"id":"73474c78_930eba57","line":67,"range":{"start_line":67,"start_character":0,"end_line":67,"end_character":28},"updated":"2026-09-24 13:53:24.000000000","message":"``TypeError`` is the wrong exception for a bad value. Previous behaviour was ValueError (from ``import_object``). Suggest ValueError, or an ``os_brick.exception.BrickException`` subclass so callers can catch something specific.","commit_id":"771c6bfefbdc8abcd3f5a7bd5a7eb435da18a2b0"}],"os_brick/tests/encryptors/test_base.py":[{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"53792393280f7db681e48e84b357b3422ecbd0de","unresolved":false,"context_lines":[{"line_number":155,"context_line":"    def test_error_log(self, mock_log):"},{"line_number":156,"context_line":"        encryption \u003d {\u0027control_location\u0027: \u0027front-end\u0027}"},{"line_number":157,"context_line":"        provider \u003d encryptors.LUKS"},{"line_number":158,"context_line":"        e \u003d self.assertRaises("},{"line_number":159,"context_line":"            Exception,"},{"line_number":160,"context_line":"            encryptors.get_volume_encryptor,"},{"line_number":161,"context_line":"            root_helper\u003dself.root_helper,"}],"source_content_type":"text/x-python","patch_set":7,"id":"2fc19848_a5d46c2c","line":158,"updated":"2026-09-22 17:50:16.000000000","message":"pep8: H202: assertRaises Exception too broad","commit_id":"3a1d6a8dba1e49c600687e956d320cb6e4cd220a"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"6f994c7f1b7fcc9186419187e0ab5fa4dbb0edc5","unresolved":true,"context_lines":[{"line_number":91,"context_line":"    def test_get_encryptors(self):"},{"line_number":92,"context_line":"        self._test_get_encryptor(\u0027luks\u0027, encryptors.luks.LuksEncryptor)"},{"line_number":93,"context_line":"        self._test_get_encryptor(None, encryptors.nop.NoOpEncryptor)"},{"line_number":94,"context_line":"        self._test_get_encryptor(\u0027luks\u0027, encryptors.luks.LuksEncryptor)"},{"line_number":95,"context_line":""},{"line_number":96,"context_line":"    @mock.patch(\u0027os_brick.encryptors.base.VolumeEncryptor._get_key\u0027)"},{"line_number":97,"context_line":"    def test__get_encryption_key_as_passphrase_hexlify(self, mock_key):"}],"source_content_type":"text/x-python","patch_set":9,"id":"736226e8_9c05ac95","line":94,"range":{"start_line":94,"start_character":0,"end_line":94,"end_character":71},"updated":"2026-09-24 13:53:24.000000000","message":"This repeats the ``luks`` assertion from line 92. It should be ``encryptors.LUKS2`` to ``encryptors.luks.Luks2Encryptor``, otherwise luks2 is not covered by this test.","commit_id":"771c6bfefbdc8abcd3f5a7bd5a7eb435da18a2b0"}],"releasenotes/notes/drop-legacy-provider-class-encryptor-support-28b20f851c6a79da.yaml":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"6f994c7f1b7fcc9186419187e0ab5fa4dbb0edc5","unresolved":true,"context_lines":[{"line_number":2,"context_line":"upgrade:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    Support for legacy classpath-based encryptor formats and out-of-tree"},{"line_number":5,"context_line":"    encryptors has been dropped. You must use enums. Currently two"},{"line_number":6,"context_line":"    encryptor formats are supported: ``luks`` and ``luks2``. For example::"},{"line_number":7,"context_line":""},{"line_number":8,"context_line":"      $ openstack volume type create \\"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"3c153323_26bb75d8","line":5,"range":{"start_line":5,"start_character":33,"end_line":5,"end_character":51},"updated":"2026-09-24 13:53:24.000000000","message":"\"You must use enums\" is not actionable for an operator. Please list the exact legacy strings that stop working (``LuksEncryptor``, ``NoOpEncryptor``, ``nova.volume.encryptors.*``, ``os_brick.encryptors.*``) and give them a way to find affected types, e.g. ``openstack volume type list --encryption-type`` or the SQL against the ``encryption`` table, plus a pointer to the cinder migration once it exists.","commit_id":"771c6bfefbdc8abcd3f5a7bd5a7eb435da18a2b0"}]}
