)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":4,"context_line":"Commit:     Stephen Finucane \u003cstephenfin@redhat.com\u003e"},{"line_number":5,"context_line":"CommitDate: 2026-09-24 18:33:12 +0100"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"privsep: Move luks utils to privsep"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Our first target for privsep\u0027ification. With privsep in charge of"},{"line_number":10,"context_line":"everything, there\u0027s no longer any reason to provide a rootwrap helper or"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":13,"id":"ca041144_def99c5a","line":7,"updated":"2026-09-24 18:28:01.000000000","message":"Worth noting in the message that this now depends on 1007280 and 1007281. 1007280 rewrites every connector constructor and changes RemoteFsConnector\u0027s positional order, which is a bigger public-API change than this patch; it should get its own review before this stack moves.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":35075,"name":"Alexander Deiter","email":"adeiter@infinidat.com","username":"adeiter"},"change_message_id":"95dba905cb347e6dee3757fb4fec80c5677d2d7d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"130feae2_b6ee2283","updated":"2023-03-30 11:12:33.000000000","message":"run-INFINIDAT","commit_id":"9a49e8ab6598e5d84641a1329d2d340a2f262d95"},{"author":{"_account_id":35075,"name":"Alexander Deiter","email":"adeiter@infinidat.com","username":"adeiter"},"change_message_id":"b1152fd9996c0c13683ae6285f5da35295554ca0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":10,"id":"05f78bd2_4bf41711","updated":"2023-06-02 19:48:24.000000000","message":"Looks good to me - thank you!","commit_id":"3369d168f4207daad508a4274fab4cb09cc79248"},{"author":{"_account_id":9236,"name":"Jon Bernard","email":"jobernar@redhat.com","username":"jbernard"},"change_message_id":"c7ce3424bb267ada701a91d10bd095d46e49617a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"d3db6b0c_48b4e460","updated":"2026-02-18 15:05:50.000000000","message":"recheck","commit_id":"b9aa17e8adc4449dc1c17e59a66873359b2b7f7c"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"6a868938_0a541877","updated":"2026-09-24 13:20:58.000000000","message":"The privsep split is clean, and I checked the two things that usually bite this kind of change: ProcessExecutionError keeps its exit_code across the privsep boundary (oslo.privsep re-raises with the original args, which include it), and processutils stringifies command arguments, so the int key_size nova passes is fine.\n\nOne real regression that the tests hide (extend_volume, comment at luks.py:229) and three test assertions that never assert. -1 for those two; everything else is small.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":13,"id":"c6cdc9bd_3ac3828b","updated":"2026-09-24 18:28:01.000000000","message":"Thanks for the quick turnaround. The extend_volume fix (privileged ``fs.device_size`` plus ``_utils.get_device_size``), the real assertions, the deduplicated privileged helpers and the release-note wording all look right, and the 64 encryptor/privileged/cache unit tests pass for me locally against PS13.\n\nThe ``*args``/``**kwargs`` shims that replaced the sentinels have four bugs, though, none covered by tests. I ran each against the PS13 tree to confirm. Two are on the compatibility paths the release note promises (``is_luks(device\u003d...)`` and out-of-tree ``VolumeEncryptor``), and one gives a silent wrong answer on the path nova uses to decide whether to _format_ a volume. -1 for those; details inline.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}],"mypy-files.txt":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":26,"context_line":"os_brick/privileged/rbd.py"},{"line_number":27,"context_line":"os_brick/privileged/rootwrap.py"},{"line_number":28,"context_line":"os_brick/remotefs/remotefs.py"},{"line_number":29,"context_line":"os_brick/utils.py"}],"source_content_type":"text/plain","patch_set":12,"id":"f503ae58_4b8a0ad5","line":29,"range":{"start_line":29,"start_character":0,"end_line":29,"end_character":17},"updated":"2026-09-24 13:20:58.000000000","message":"Duplicate of line 6","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":26,"context_line":"os_brick/privileged/rbd.py"},{"line_number":27,"context_line":"os_brick/privileged/rootwrap.py"},{"line_number":28,"context_line":"os_brick/remotefs/remotefs.py"},{"line_number":29,"context_line":"os_brick/utils.py"}],"source_content_type":"text/plain","patch_set":12,"id":"e56a96c8_6a0ece25","line":29,"range":{"start_line":29,"start_character":0,"end_line":29,"end_character":17},"in_reply_to":"f503ae58_4b8a0ad5","updated":"2026-09-24 16:58:42.000000000","message":"Indeed. As an aside, I have a local series to remove this file. Running it over files (as opposed to modules) means we lose many benefits of mypy.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":20,"context_line":"os_brick/initiator/linuxrbd.py"},{"line_number":21,"context_line":"os_brick/initiator/utils.py"},{"line_number":22,"context_line":"os_brick/local_dev/lvm.py"},{"line_number":23,"context_line":"os_brick/privileged/cryptsetup.py"},{"line_number":24,"context_line":"os_brick/privileged/luks.py"},{"line_number":25,"context_line":"os_brick/privileged/nvmeof.py"},{"line_number":26,"context_line":"os_brick/privileged/rbd.py"}],"source_content_type":"text/plain","patch_set":13,"id":"1a454f8b_4807143a","line":23,"range":{"start_line":23,"start_character":0,"end_line":23,"end_character":33},"updated":"2026-09-24 18:28:01.000000000","message":"The new ``os_brick/_utils.py`` and ``os_brick/privileged/fs.py`` are annotated too; please add them alongside these two (until your series to drop this file lands).","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}],"os_brick/encryptors/__init__.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":63,"context_line":"    :param: the connection information used to attach the volume"},{"line_number":64,"context_line":"    :returns VolumeEncryptor: the VolumeEncryptor for the volume"},{"line_number":65,"context_line":"    \"\"\""},{"line_number":66,"context_line":"    if root_helper !\u003d _NO_ARG_SENTINEL:"},{"line_number":67,"context_line":"        debtcollector.deprecate("},{"line_number":68,"context_line":"            \"The \u0027root_helper\u0027 argument is no longer used and will be \""},{"line_number":69,"context_line":"            \"removed in a future release; remove this argument.\""}],"source_content_type":"text/x-python","patch_set":12,"id":"5f3467a9_2448ae4d","line":66,"range":{"start_line":66,"start_character":0,"end_line":66,"end_character":39},"updated":"2026-09-24 13:20:58.000000000","message":"Nit, applies to every sentinel check in the series: ``is not _NO_ARG_SENTINEL`` / ``is _NO_ARG_SENTINEL`` rather than ``!\u003d`` / ``\u003d\u003d``. Identity is the idiom for sentinels and avoids calling ``__eq__`` on whatever the caller passed.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":63,"context_line":"    :param: the connection information used to attach the volume"},{"line_number":64,"context_line":"    :returns VolumeEncryptor: the VolumeEncryptor for the volume"},{"line_number":65,"context_line":"    \"\"\""},{"line_number":66,"context_line":"    if root_helper !\u003d _NO_ARG_SENTINEL:"},{"line_number":67,"context_line":"        debtcollector.deprecate("},{"line_number":68,"context_line":"            \"The \u0027root_helper\u0027 argument is no longer used and will be \""},{"line_number":69,"context_line":"            \"removed in a future release; remove this argument.\""}],"source_content_type":"text/x-python","patch_set":12,"id":"06ca8f3e_31b0b42f","line":66,"range":{"start_line":66,"start_character":0,"end_line":66,"end_character":39},"in_reply_to":"5f3467a9_2448ae4d","updated":"2026-09-24 16:58:42.000000000","message":"I\u0027ve reworked this somewhat to (hopefully) simplify it and remove the need for these sentinels.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"}],"os_brick/encryptors/base.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":72,"context_line":"        *,"},{"line_number":73,"context_line":"        connection_info,"},{"line_number":74,"context_line":"        keymgr,"},{"line_number":75,"context_line":"        **kwargs,"},{"line_number":76,"context_line":"    ):"},{"line_number":77,"context_line":"        warnings.warn("},{"line_number":78,"context_line":"            \u0027Support for out-of-tree encryptors is deprecated for removal. \u0027"}],"source_content_type":"text/x-python","patch_set":13,"id":"4328e12a_7fcee8e3","line":75,"range":{"start_line":75,"start_character":0,"end_line":75,"end_character":17},"updated":"2026-09-24 18:28:01.000000000","message":"Mixed legacy calls break. ``get_volume_encryptor(\u0027sudo\u0027, connection_info\u003dci, keymgr\u003dkm)`` takes the positional branch, sets ``connection_info``/``keymgr`` to None from the padded tuple, and then forwards ``**kwargs``, which still holds them:\n\n```\nTypeError: _get_volume_encryptor() got multiple values for keyword argument \u0027connection_info\u0027\n```\n\nNova and cinder use all-keyword calls today, so this is robustness rather than an immediate break, but the shim advertises legacy support. If args are present, take only what is there and ``kwargs.pop`` the rest.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":80,"context_line":"            DeprecationWarning,"},{"line_number":81,"context_line":"            stacklevel\u003d2,"},{"line_number":82,"context_line":"        )"},{"line_number":83,"context_line":"        super().__init("},{"line_number":84,"context_line":"            connection_info\u003dconnection_info,"},{"line_number":85,"context_line":"            keymgr\u003dkeymgr,"},{"line_number":86,"context_line":"            **kwargs,"}],"source_content_type":"text/x-python","patch_set":13,"id":"c079cbae_e88cf060","line":83,"range":{"start_line":83,"start_character":0,"end_line":83,"end_character":23},"updated":"2026-09-24 18:28:01.000000000","message":"``super().__init(`` is missing two underscores, so every out-of-tree subclass of ``VolumeEncryptor`` raises:\n\n```\nAttributeError: \u0027super\u0027 object has no attribute \u0027_VolumeEncryptor__init\u0027\n```\n\nWith the typo fixed it still cannot work: ``super().__init__(connection_info\u003d..., keymgr\u003d...)`` resolves via the MRO to ``Executor.__init__``, which requires ``root_helper`` positionally and does not accept those kwargs. Since ``get_volume_encryptor`` now pops ``root_helper``, the shim has to supply it itself:\n\n```\nexecutor.Executor.__init__(self, root_helper\u003dNone)\nBaseVolumeEncryptor.__init__(self, connection_info\u003dconnection_info, keymgr\u003dkeymgr, **kwargs)\n```\n\nThis class exists purely for compatibility, so it needs a test that instantiates a subclass through ``get_volume_encryptor`` with an out-of-tree provider string and asserts the DeprecationWarning.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}],"os_brick/encryptors/cryptsetup.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":20,"context_line":""},{"line_number":21,"context_line":"from os_brick.encryptors import base"},{"line_number":22,"context_line":"from os_brick import exception"},{"line_number":23,"context_line":"import os_brick.privileged.cryptsetup"},{"line_number":24,"context_line":""},{"line_number":25,"context_line":"LOG \u003d logging.getLogger(__name__)"},{"line_number":26,"context_line":""}],"source_content_type":"text/x-python","patch_set":13,"id":"f6794dd3_a31aa23e","line":23,"range":{"start_line":23,"start_character":0,"end_line":23,"end_character":37},"updated":"2026-09-24 18:28:01.000000000","message":"This module now calls ``os_brick.privileged.luks.is_available`` and ``replace_device_mapping`` but only imports ``os_brick.privileged.cryptsetup``. The ``luks`` attribute exists only if something else imported that module first; importing ``os_brick.encryptors.cryptsetup`` on its own leaves ``os_brick.privileged`` without it. Tests pass because ``mock.patch(\u0027os_brick.privileged.luks...\u0027)`` imports it as a side effect. Please add ``import os_brick.privileged.luks``.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}],"os_brick/encryptors/luks.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":49,"context_line":"        )"},{"line_number":50,"context_line":""},{"line_number":51,"context_line":"    if device \u003d\u003d _NO_ARG_SENTINEL:"},{"line_number":52,"context_line":"        raise TypeError(\u0027missing keymgr\u0027)"},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"    if execute !\u003d _NO_ARG_SENTINEL:"},{"line_number":55,"context_line":"        debtcollector.deprecate("}],"source_content_type":"text/x-python","patch_set":12,"id":"7ab0616d_31d305a7","line":52,"range":{"start_line":52,"start_character":0,"end_line":52,"end_character":41},"updated":"2026-09-24 13:20:58.000000000","message":"Copy-paste: the message should be ``\u0027missing device\u0027``, not ``\u0027missing keymgr\u0027``.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":49,"context_line":"        )"},{"line_number":50,"context_line":""},{"line_number":51,"context_line":"    if device \u003d\u003d _NO_ARG_SENTINEL:"},{"line_number":52,"context_line":"        raise TypeError(\u0027missing keymgr\u0027)"},{"line_number":53,"context_line":""},{"line_number":54,"context_line":"    if execute !\u003d _NO_ARG_SENTINEL:"},{"line_number":55,"context_line":"        debtcollector.deprecate("}],"source_content_type":"text/x-python","patch_set":12,"id":"38a1fc2b_5ad2bfa4","line":52,"range":{"start_line":52,"start_character":0,"end_line":52,"end_character":41},"in_reply_to":"7ab0616d_31d305a7","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":226,"context_line":"        passphrase \u003d self._get_encryption_key_as_passphrase(context)"},{"line_number":227,"context_line":"        os_brick.privileged.luks.extend_volume(symlink, passphrase)"},{"line_number":228,"context_line":""},{"line_number":229,"context_line":"        res \u003d utils.get_device_size(self, symlink)"},{"line_number":230,"context_line":"        LOG.debug(\u0027New size of mapping is %s\u0027, res)"},{"line_number":231,"context_line":"        return res"},{"line_number":232,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"99df85d4_6b2b4c81","line":229,"range":{"start_line":229,"start_character":0,"end_line":229,"end_character":50},"updated":"2026-09-24 13:20:58.000000000","message":"This is broken now. ``utils.get_device_size(executor, device)`` (utils.py:430-434) calls ``executor._execute(...)`` and reads ``executor._root_helper``. ``VolumeEncryptor`` no longer inherits ``Executor``, so ``self`` has neither and the first online extend of a LUKS volume raises AttributeError right after the resize has succeeded.\n\n``test_extend_volume`` mocks ``get_device_size``, which is why CI is green. Suggest a privileged ``get_device_size(device_path)`` entrypoint (blockdev --getsize64) and stop passing ``self``; or make the utils helper accept a plain path now that nothing else needs the executor.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":226,"context_line":"        passphrase \u003d self._get_encryption_key_as_passphrase(context)"},{"line_number":227,"context_line":"        os_brick.privileged.luks.extend_volume(symlink, passphrase)"},{"line_number":228,"context_line":""},{"line_number":229,"context_line":"        res \u003d utils.get_device_size(self, symlink)"},{"line_number":230,"context_line":"        LOG.debug(\u0027New size of mapping is %s\u0027, res)"},{"line_number":231,"context_line":"        return res"},{"line_number":232,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"fc602f5a_c7caa5e0","line":229,"range":{"start_line":229,"start_character":0,"end_line":229,"end_character":50},"in_reply_to":"99df85d4_6b2b4c81","updated":"2026-09-24 16:58:42.000000000","message":"Good catch. I\u0027ve kept `get_device_size` and added a new variant in a private `os_brick._utils` module to handle this.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":238,"context_line":"    \"\"\""},{"line_number":239,"context_line":""},{"line_number":240,"context_line":"    # TODO(stephenfin): Remove root_helper, execute in G or later"},{"line_number":241,"context_line":"    def __init__("},{"line_number":242,"context_line":"        self,"},{"line_number":243,"context_line":"        root_helper\u003d_NO_ARG_SENTINEL,"},{"line_number":244,"context_line":"        connection_info\u003d_NO_ARG_SENTINEL,"}],"source_content_type":"text/x-python","patch_set":12,"id":"8804e84c_732e626c","line":241,"range":{"start_line":241,"start_character":0,"end_line":241,"end_character":17},"updated":"2026-09-24 13:20:58.000000000","message":"This ``__init__`` repeats the parent\u0027s four checks and then calls super with the same arguments. ``LuksEncryptor.__init__`` already does all of it, so the override can be deleted.\n\nMore generally the same four-check block is pasted five times across the package (nop, cryptsetup, luks, luks2, ``get_volume_encryptor``). A small helper in ``base`` (or a decorator) would keep the deprecation text in one place.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":238,"context_line":"    \"\"\""},{"line_number":239,"context_line":""},{"line_number":240,"context_line":"    # TODO(stephenfin): Remove root_helper, execute in G or later"},{"line_number":241,"context_line":"    def __init__("},{"line_number":242,"context_line":"        self,"},{"line_number":243,"context_line":"        root_helper\u003d_NO_ARG_SENTINEL,"},{"line_number":244,"context_line":"        connection_info\u003d_NO_ARG_SENTINEL,"}],"source_content_type":"text/x-python","patch_set":12,"id":"e0e96722_d4783566","line":241,"range":{"start_line":241,"start_character":0,"end_line":241,"end_character":17},"in_reply_to":"8804e84c_732e626c","updated":"2026-09-24 16:58:42.000000000","message":"I\u0027ve removed all of this on the realisation that these are never called or created explicitly outside of os_brick. Users should be going through the `get_volume_encryptor` factory method.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":40,"context_line":"    \"\"\""},{"line_number":41,"context_line":"    if len(args):"},{"line_number":42,"context_line":"        # Handle legacy positional callers, e.g.:"},{"line_number":43,"context_line":"        #   get_volume_encryptor(\u0027sudo\u0027, \u0027/foo/dev\u0027)"},{"line_number":44,"context_line":"        #   get_volume_encryptor(\u0027sudo\u0027, \u0027/foo/dev\u0027, execute_fn)"},{"line_number":45,"context_line":"        warnings.warn("},{"line_number":46,"context_line":"            \"Passing arguments positionally is deprecated. Use keyword-only \""}],"source_content_type":"text/x-python","patch_set":13,"id":"8209d7c9_90922cae","line":43,"range":{"start_line":43,"start_character":0,"end_line":43,"end_character":52},"updated":"2026-09-24 18:28:01.000000000","message":"Nit: the comment examples say ``get_volume_encryptor(\u0027sudo\u0027, \u0027/foo/dev\u0027)``; they should be ``is_luks(...)``.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":48,"context_line":"            DeprecationWarning,"},{"line_number":49,"context_line":"            stacklevel\u003d2,"},{"line_number":50,"context_line":"        )"},{"line_number":51,"context_line":"        _, device, _ \u003d args + (None,) * (3 - len(args))"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"    device \u003d kwargs.get(\u0027device\u0027, device)"},{"line_number":54,"context_line":"    return _is_luks(device\u003ddevice)"}],"source_content_type":"text/x-python","patch_set":13,"id":"e14416c5_883b1d81","line":51,"range":{"start_line":51,"start_character":0,"end_line":51,"end_character":55},"updated":"2026-09-24 18:28:01.000000000","message":"A single positional argument is treated as ``root_helper``, ``device`` becomes None, and the privileged call runs ``cryptsetup isLuks None`` and returns False:\n\n```\n\u003e\u003e\u003e luks.is_luks(\u0027/dev/x\u0027)   # -\u003e privileged.is_luks(None) -\u003e False\n```\n\nNova\u0027s ``_attach_encryptor`` formats the device when ``is_luks`` returns False, so a caller that drops ``root_helper`` positionally (the obvious reaction to the deprecation warning) would get an existing LUKS volume reformatted. The one-argument form never existed in the old API, so ``len(args) \u003d\u003d 1`` should raise TypeError, and ``_is_luks`` should reject ``device is None`` rather than passing it through.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":50,"context_line":"        )"},{"line_number":51,"context_line":"        _, device, _ \u003d args + (None,) * (3 - len(args))"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"    device \u003d kwargs.get(\u0027device\u0027, device)"},{"line_number":54,"context_line":"    return _is_luks(device\u003ddevice)"},{"line_number":55,"context_line":""},{"line_number":56,"context_line":""}],"source_content_type":"text/x-python","patch_set":13,"id":"0eb21be4_f1c4c5b3","line":53,"range":{"start_line":53,"start_character":0,"end_line":53,"end_character":41},"updated":"2026-09-24 18:28:01.000000000","message":"``device`` is only bound inside the if ``len(args)`` block, so the keyword-only form raises:\n\n```\n\u003e\u003e\u003e luks.is_luks(device\u003d\u0027/dev/x\u0027)\nUnboundLocalError: cannot access local variable \u0027device\u0027 where it is not associated with a value\n```\n\nThat is exactly the calling form the release note now tells people to use. Initialise ``device \u003d None`` before the branch (or restructure as ``device \u003d kwargs.get(\u0027device\u0027)`` first). The old ``test_is_luks``/``test_is_luks_with_error`` were removed in PS12 and nothing tests this function now; please add keyword, two-positional and three-positional cases.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}],"os_brick/privileged/cryptsetup.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":21,"context_line":""},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"@os_brick.privileged.default.entrypoint"},{"line_number":24,"context_line":"def is_available(device_name: str) -\u003e bool:"},{"line_number":25,"context_line":"    \"\"\"Checks if the specified crypt device is available."},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"    :param device_name: the name of the device to check"}],"source_content_type":"text/x-python","patch_set":12,"id":"84cb04bd_4270ceff","line":24,"range":{"start_line":24,"start_character":0,"end_line":24,"end_character":43},"updated":"2026-09-24 13:20:58.000000000","message":"``is_available`` and ``replace_device_mapping`` (line 55) are copies of the luks.py versions with a ``check_exit_code\u003dTrue`` difference. Given the whole ``CryptsetupEncryptor`` is marked for removal in G, could this module just import the two from ``os_brick.privileged.luks`` rather than carrying a second copy?","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":21,"context_line":""},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"@os_brick.privileged.default.entrypoint"},{"line_number":24,"context_line":"def is_available(device_name: str) -\u003e bool:"},{"line_number":25,"context_line":"    \"\"\"Checks if the specified crypt device is available."},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"    :param device_name: the name of the device to check"}],"source_content_type":"text/x-python","patch_set":12,"id":"4da46402_c9fa8aac","line":24,"range":{"start_line":24,"start_character":0,"end_line":24,"end_character":43},"in_reply_to":"84cb04bd_4270ceff","updated":"2026-09-24 16:58:42.000000000","message":"Good idea. Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":115,"context_line":"    :returns: None"},{"line_number":116,"context_line":"    \"\"\""},{"line_number":117,"context_line":"    cmd \u003d [\u0027cryptsetup\u0027, \u0027remove\u0027, device_name]"},{"line_number":118,"context_line":"    # NOTE(mdbooth): luksClose will return 4 (wrong device specified) if"},{"line_number":119,"context_line":"    # the device doesn\u0027t exist. We assume here that the caller hasn\u0027t"},{"line_number":120,"context_line":"    # specified the wrong device, and that it doesn\u0027t exist because it"},{"line_number":121,"context_line":"    # isn\u0027t open. We don\u0027t fail in this case in order to make this"}],"source_content_type":"text/x-python","patch_set":12,"id":"58d595db_4a4b6518","line":118,"range":{"start_line":118,"start_character":0,"end_line":118,"end_character":72},"updated":"2026-09-24 13:20:58.000000000","message":"Comment says \"luksClose\" but the command here is remove. The original comment said \"remove will return 4\".","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":115,"context_line":"    :returns: None"},{"line_number":116,"context_line":"    \"\"\""},{"line_number":117,"context_line":"    cmd \u003d [\u0027cryptsetup\u0027, \u0027remove\u0027, device_name]"},{"line_number":118,"context_line":"    # NOTE(mdbooth): luksClose will return 4 (wrong device specified) if"},{"line_number":119,"context_line":"    # the device doesn\u0027t exist. We assume here that the caller hasn\u0027t"},{"line_number":120,"context_line":"    # specified the wrong device, and that it doesn\u0027t exist because it"},{"line_number":121,"context_line":"    # isn\u0027t open. We don\u0027t fail in this case in order to make this"}],"source_content_type":"text/x-python","patch_set":12,"id":"5dcb56ef_a97b150d","line":118,"range":{"start_line":118,"start_character":0,"end_line":118,"end_character":72},"in_reply_to":"58d595db_4a4b6518","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"}],"os_brick/privileged/luks.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":58,"context_line":"        # case, we will omit the warning message."},{"line_number":59,"context_line":"        if e.exit_code !\u003d 1:"},{"line_number":60,"context_line":"            LOG.warning("},{"line_number":61,"context_line":"                \u0027cryptsetup status %(device_name)s exited \u0027"},{"line_number":62,"context_line":"                \u0027abnormally (status %(exit_code)s): %(err)s\u0027,"},{"line_number":63,"context_line":"                {"},{"line_number":64,"context_line":"                    \u0027dev_name\u0027: device_name,"}],"source_content_type":"text/x-python","patch_set":12,"id":"c7514252_edfd39e0","line":61,"range":{"start_line":61,"start_character":0,"end_line":61,"end_character":59},"updated":"2026-09-24 13:20:58.000000000","message":"The format string uses ``%(device_name)s`` and ``%(err)s`` but the dict at 64 has ``dev_name``. This warning will raise a logging formatting error instead of rendering. The cryptsetup copy of this function has the keys right. ``test_is_available__with_error_disk`` mocks LOG so it cannot see this.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":58,"context_line":"        # case, we will omit the warning message."},{"line_number":59,"context_line":"        if e.exit_code !\u003d 1:"},{"line_number":60,"context_line":"            LOG.warning("},{"line_number":61,"context_line":"                \u0027cryptsetup status %(device_name)s exited \u0027"},{"line_number":62,"context_line":"                \u0027abnormally (status %(exit_code)s): %(err)s\u0027,"},{"line_number":63,"context_line":"                {"},{"line_number":64,"context_line":"                    \u0027dev_name\u0027: device_name,"}],"source_content_type":"text/x-python","patch_set":12,"id":"5c6bbdfd_8835e3ff","line":61,"range":{"start_line":61,"start_character":0,"end_line":61,"end_character":59},"in_reply_to":"c7514252_edfd39e0","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"}],"os_brick/privileged/test_fs.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":1,"context_line":"# Licensed under the Apache License, Version 2.0 (the \"License\"); you may"},{"line_number":2,"context_line":"# not use this file except in compliance with the License. You may obtain"},{"line_number":3,"context_line":"# a copy of the License at"},{"line_number":4,"context_line":"#"}],"source_content_type":"text/x-python","patch_set":13,"id":"b3bf20b3_5687b9a3","line":1,"updated":"2026-09-24 18:28:01.000000000","message":"This test module is under ``os_brick/privileged/`` instead of ``os_brick/tests/privileged/``, so stestr discovery never runs it and it ships in the package. Please move it, and rename ``PrivSSTestCase`` to ``PrivFSTestCase``.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}],"os_brick/tests/encryptors/test_luks.py":[{"author":{"_account_id":30615,"name":"Tushar Trambak Gite","email":"tushargite96@gmail.com","username":"tushargite96"},"change_message_id":"4c631dff46ebba26be107e9ad7af7bfc3dfe2f1a","unresolved":true,"context_lines":[{"line_number":286,"context_line":"                connection_info\u003dself.connection_info,"},{"line_number":287,"context_line":"                keymgr\u003dself.keymgr,"},{"line_number":288,"context_line":"                execute\u003d\u0027foo\u0027,"},{"line_number":289,"context_line":"            )  # would actually be a function but who cares"}],"source_content_type":"text/x-python","patch_set":9,"id":"5b3c9864_bf59293b","line":289,"updated":"2023-02-16 09:58:49.000000000","message":"LGTM , but this comment need to be removed before merge right","commit_id":"9a49e8ab6598e5d84641a1329d2d340a2f262d95"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":286,"context_line":"                connection_info\u003dself.connection_info,"},{"line_number":287,"context_line":"                keymgr\u003dself.keymgr,"},{"line_number":288,"context_line":"                execute\u003d\u0027foo\u0027,"},{"line_number":289,"context_line":"            )  # would actually be a function but who cares"}],"source_content_type":"text/x-python","patch_set":9,"id":"501f40da_ed08c632","line":289,"in_reply_to":"5b3c9864_bf59293b","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"9a49e8ab6598e5d84641a1329d2d340a2f262d95"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":79,"context_line":""},{"line_number":80,"context_line":"        self.encryptor.attach_volume(None)"},{"line_number":81,"context_line":""},{"line_number":82,"context_line":"        mock_open(self.dev_path, self.dev_name, fake_key)"},{"line_number":83,"context_line":"        mock_update_mapping(self.dev_name, self.symlink_path)"},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.replace_device_mapping\u0027)"}],"source_content_type":"text/x-python","patch_set":12,"id":"988742a2_fec14293","line":82,"range":{"start_line":82,"start_character":0,"end_line":82,"end_character":57},"updated":"2026-09-24 13:20:58.000000000","message":"These two lines call the mocks instead of asserting on them. ``mock_open(...)`` and ``mock_update_mapping(...)`` should be ``mock_open.assert_called_once_with(...)`` and ``mock_update_mapping.assert_called_once_with(...)``. As written, ``test_attach_volume`` verifies nothing about the attach path.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":79,"context_line":""},{"line_number":80,"context_line":"        self.encryptor.attach_volume(None)"},{"line_number":81,"context_line":""},{"line_number":82,"context_line":"        mock_open(self.dev_path, self.dev_name, fake_key)"},{"line_number":83,"context_line":"        mock_update_mapping(self.dev_name, self.symlink_path)"},{"line_number":84,"context_line":""},{"line_number":85,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.replace_device_mapping\u0027)"}],"source_content_type":"text/x-python","patch_set":12,"id":"ebed657c_4b278544","line":82,"range":{"start_line":82,"start_character":0,"end_line":82,"end_character":57},"in_reply_to":"988742a2_fec14293","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":117,"context_line":"        mock_format.assert_called_once_with("},{"line_number":118,"context_line":"            self.dev_path, fake_key, self.version, None, None"},{"line_number":119,"context_line":"        )"},{"line_number":120,"context_line":"        mock_update_mapping(self.dev_name, self.symlink_path)"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.is_luks\u0027)"},{"line_number":123,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.open_volume\u0027)"}],"source_content_type":"text/x-python","patch_set":12,"id":"9ff3bebf_dea2200a","line":120,"range":{"start_line":120,"start_character":0,"end_line":120,"end_character":61},"updated":"2026-09-24 13:20:58.000000000","message":"Same here: ``mock_update_mapping(...)`` is a call, not an assertion.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":117,"context_line":"        mock_format.assert_called_once_with("},{"line_number":118,"context_line":"            self.dev_path, fake_key, self.version, None, None"},{"line_number":119,"context_line":"        )"},{"line_number":120,"context_line":"        mock_update_mapping(self.dev_name, self.symlink_path)"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.is_luks\u0027)"},{"line_number":123,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.open_volume\u0027)"}],"source_content_type":"text/x-python","patch_set":12,"id":"1abc7d49_0642a9cd","line":120,"range":{"start_line":120,"start_character":0,"end_line":120,"end_character":61},"in_reply_to":"9ff3bebf_dea2200a","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":229,"context_line":"    @mock.patch(\u0027os_brick.utils.get_device_size\u0027)"},{"line_number":230,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.extend_volume\u0027)"},{"line_number":231,"context_line":"    @mock.patch.object(luks.LuksEncryptor, \u0027_get_encryption_key_as_passphrase\u0027)"},{"line_number":232,"context_line":"    def test_extend_volume(self, mock_pass, mock_extend, mock_size):"},{"line_number":233,"context_line":"        encryptor \u003d self.encryptor"},{"line_number":234,"context_line":"        res \u003d encryptor.extend_volume(mock.sentinel.context)"},{"line_number":235,"context_line":"        self.assertEqual(mock_size.return_value, res)"}],"source_content_type":"text/x-python","patch_set":12,"id":"1ec08563_b131ad49","line":232,"range":{"start_line":232,"start_character":0,"end_line":232,"end_character":68},"updated":"2026-09-24 13:20:58.000000000","message":"Please let ``get_device_size`` run for real here (mock ``processutils.execute`` instead) so the regression at luks.py:229 is actually covered.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":229,"context_line":"    @mock.patch(\u0027os_brick.utils.get_device_size\u0027)"},{"line_number":230,"context_line":"    @mock.patch(\u0027os_brick.privileged.luks.extend_volume\u0027)"},{"line_number":231,"context_line":"    @mock.patch.object(luks.LuksEncryptor, \u0027_get_encryption_key_as_passphrase\u0027)"},{"line_number":232,"context_line":"    def test_extend_volume(self, mock_pass, mock_extend, mock_size):"},{"line_number":233,"context_line":"        encryptor \u003d self.encryptor"},{"line_number":234,"context_line":"        res \u003d encryptor.extend_volume(mock.sentinel.context)"},{"line_number":235,"context_line":"        self.assertEqual(mock_size.return_value, res)"}],"source_content_type":"text/x-python","patch_set":12,"id":"80046e1a_d74824fe","line":232,"range":{"start_line":232,"start_character":0,"end_line":232,"end_character":68},"in_reply_to":"1ec08563_b131ad49","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"}],"os_brick/tests/privileged/test_luks.py":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":127,"context_line":"            \u0027/dev/mapper/crypt-test\u0027,"},{"line_number":128,"context_line":"            \u0027/dev/disk/by-path/\u0027,"},{"line_number":129,"context_line":"            check_exit_code\u003dTrue,"},{"line_number":130,"context_line":"        ),"},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"    @mock.patch(\u0027oslo_concurrency.processutils.execute\u0027)"},{"line_number":133,"context_line":"    def test_open_volume(self, mock_execute):"}],"source_content_type":"text/x-python","patch_set":12,"id":"bf18b583_9b09137b","line":130,"range":{"start_line":130,"start_character":0,"end_line":130,"end_character":10},"updated":"2026-09-24 13:20:58.000000000","message":"Trailing comma after ``assert_called_once_with(...)`` turns the statement into a one-element tuple. Harmless, but it looks like a leftover. Same at test_cryptsetup.py:104.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":127,"context_line":"            \u0027/dev/mapper/crypt-test\u0027,"},{"line_number":128,"context_line":"            \u0027/dev/disk/by-path/\u0027,"},{"line_number":129,"context_line":"            check_exit_code\u003dTrue,"},{"line_number":130,"context_line":"        ),"},{"line_number":131,"context_line":""},{"line_number":132,"context_line":"    @mock.patch(\u0027oslo_concurrency.processutils.execute\u0027)"},{"line_number":133,"context_line":"    def test_open_volume(self, mock_execute):"}],"source_content_type":"text/x-python","patch_set":12,"id":"9320deae_a150bb9f","line":130,"range":{"start_line":130,"start_character":0,"end_line":130,"end_character":10},"in_reply_to":"bf18b583_9b09137b","updated":"2026-09-24 16:58:42.000000000","message":"Done","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"}],"releasenotes/notes/privsepify-74949804e4f56877.yaml":[{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"3c4d2e42bc29249a92fff19df4b1e5bb357a7b1b","unresolved":true,"context_lines":[{"line_number":10,"context_line":"    The ``NoOpEncryptor``, ``LuksEncryptor``, ``Luks2Encryptor``, and"},{"line_number":11,"context_line":"    deprecated ``CryptsetupEncryptor`` encryptors no longer require"},{"line_number":12,"context_line":"    ``root_helper`` or ``execute`` arguments. These arguments have been"},{"line_number":13,"context_line":"    deprecated for removal in a future release. Callers can simply drop these"},{"line_number":14,"context_line":"    arguments."}],"source_content_type":"text/x-yaml","patch_set":12,"id":"756630d3_7417d49a","line":14,"range":{"start_line":13,"start_character":47,"end_line":14,"end_character":13},"updated":"2026-09-24 13:20:58.000000000","message":"This is only true for keyword callers. nova calls ``luks.is_luks(root_helper, device_path)`` positionally (nova/virt/libvirt/driver.py, ``_attach_encryptor``); if it drops the first argument without switching to ``device\u003d``, the path lands in ``root_helper`` and ``is_luks`` raises TypeError. Please say \"pass the remaining arguments by keyword\".\n\nAlso worth an upgrade note: ``VolumeEncryptor`` no longer subclasses ``Executor``, so out-of-tree encryptors (which ``get_volume_encryptor`` still loads via ``importutils``) lose ``self._execute`` and ``self._root_helper``.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"b4c11b91ea3b0fe4a55f46212bf313d5ea4ebb96","unresolved":false,"context_lines":[{"line_number":10,"context_line":"    The ``NoOpEncryptor``, ``LuksEncryptor``, ``Luks2Encryptor``, and"},{"line_number":11,"context_line":"    deprecated ``CryptsetupEncryptor`` encryptors no longer require"},{"line_number":12,"context_line":"    ``root_helper`` or ``execute`` arguments. These arguments have been"},{"line_number":13,"context_line":"    deprecated for removal in a future release. Callers can simply drop these"},{"line_number":14,"context_line":"    arguments."}],"source_content_type":"text/x-yaml","patch_set":12,"id":"87b222c2_85deeade","line":14,"range":{"start_line":13,"start_character":47,"end_line":14,"end_character":13},"in_reply_to":"756630d3_7417d49a","updated":"2026-09-24 16:58:42.000000000","message":"\u003e This is only true for keyword callers. nova calls ``luks.is_luks(root_helper, device_path)`` positionally (nova/virt/libvirt/driver.py, ``_attach_encryptor``); if it drops the first argument without switching to ``device\u003d``, the path lands in ``root_helper`` and ``is_luks`` raises TypeError. Please say \"pass the remaining arguments by keyword\".\n\nDone.\n\n\u003e Also worth an upgrade note: ``VolumeEncryptor`` no longer subclasses ``Executor``, so out-of-tree encryptors (which ``get_volume_encryptor`` still loads via ``importutils``) lose ``self._execute`` and ``self._root_helper``.\n\nI\u0027ve reworked this so ``VolumeEncryptor`` remains for any out-of-tree encryptors and ``BaseVolumeEncryptor`` is used for in-tree ones.","commit_id":"3dc5abda1af29858a03f182b0f07e9eeeb612faf"},{"author":{"_account_id":13425,"name":"Simon Dodsley","email":"simon@everpuredata.com","username":"sdodsley"},"change_message_id":"74d0083f11a77e7fe35e4512acabc4451733bab3","unresolved":true,"context_lines":[{"line_number":7,"context_line":"    cinder already use privsep elsewhere."},{"line_number":8,"context_line":"upgrade:"},{"line_number":9,"context_line":"  - |"},{"line_number":10,"context_line":"    The ``os_brick.encryptors.get_volume_encryptor`` factory method and"},{"line_number":11,"context_line":"    ``os_brick.encryptors.luks.is_luks`` helper method no longer require"},{"line_number":12,"context_line":"    ``root_helper`` or ``execute`` arguments. These arguments have been"},{"line_number":13,"context_line":"    deprecated for removal in a future release. Callers can simply drop these"}],"source_content_type":"text/x-yaml","patch_set":13,"id":"796a4307_bba1acd9","line":10,"updated":"2026-09-24 18:28:01.000000000","message":"Now that out-of-tree encryptors get a DeprecationWarning from ``VolumeEncryptor.__init__``, please say so in this upgrade section; the current text only covers the argument changes.","commit_id":"3dabd52aea333cbe8ca9ecd039f130a70b34e874"}]}
