)]}'
{"id":"openstack%2Foslo.policy~654321","triplet_id":"openstack%2Foslo.policy~master~I7f450344d93424dc6c9379ae905e87f8f0dac09b","project":"openstack/oslo.policy","branch":"master","topic":"bug/1807697","hashtags":[],"change_id":"I7f450344d93424dc6c9379ae905e87f8f0dac09b","subject":"[PoC] Add new kind of check called \u0027tags\u0027","status":"ABANDONED","created":"2019-04-22 06:31:44.000000000","updated":"2019-12-18 11:34:06.000000000","total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"d15c22196916a71f836134bc58473e01204e1746","_number":654321,"virtual_id_number":654321,"owner":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"date":"2019-05-21 15:10:06.000000000","_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},{"value":1,"date":"2019-04-25 03:10:54.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"rejected":{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},"all":[{"value":-1,"date":"2019-05-21 14:43:06.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},{"date":"2019-05-21 15:54:57.000000000","_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"permitted_voting_range":{"min":-1,"max":0},"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Backport-Candidate":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do Not Backport","-1":"Not A Backport Candidate"," 0":"Backport Review Needed","+1":"Proposed Backport","+2":"Should Backport"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2019-04-25 03:10:54.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2019-05-21 14:43:06.000000000","updated_by":{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},"reviewer":{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},"state":"REVIEWER"},{"updated":"2019-05-21 15:54:57.000000000","updated_by":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"reviewer":{"_account_id":5046,"name":"Lance Bragstad","email":"lbragstad@redhat.com","username":"ldbragst"},"state":"REVIEWER"}],"messages":[{"id":"cdd561a4cd9b33e70ece2e3af0fe42a920397e11","author":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"date":"2019-04-22 06:31:44.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"8502a171ebf7f24b9638cad931219ac758f78623","author":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"date":"2019-04-22 06:33:15.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"545ee6cb75f07f5a521578b86d6cb24bbee9a9b0","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-22 08:29:04.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- tempest-full http://logs.openstack.org/21/654321/2/check/tempest-full/d9c3bf8/ : SUCCESS in 1h 48m 22s\n- tempest-full-py3 http://logs.openstack.org/21/654321/2/check/tempest-full-py3/57487d5/ : SUCCESS in 1h 25m 03s\n- openstack-tox-lower-constraints http://logs.openstack.org/21/654321/2/check/openstack-tox-lower-constraints/6257f2a/ : SUCCESS in 5m 49s\n- openstack-tox-pep8 http://logs.openstack.org/21/654321/2/check/openstack-tox-pep8/e78dab6/ : SUCCESS in 5m 36s\n- openstack-tox-py27 http://logs.openstack.org/21/654321/2/check/openstack-tox-py27/5c584a1/ : SUCCESS in 4m 37s\n- openstack-tox-py35 http://logs.openstack.org/21/654321/2/check/openstack-tox-py35/728dbd0/ : SUCCESS in 6m 17s\n- openstack-tox-py36 http://logs.openstack.org/21/654321/2/check/openstack-tox-py36/d6f6172/ : SUCCESS in 5m 32s\n- openstack-tox-py37 http://logs.openstack.org/21/654321/2/check/openstack-tox-py37/97c317d/ : SUCCESS in 6m 18s\n- openstack-tox-docs http://logs.openstack.org/21/654321/2/check/openstack-tox-docs/94fbd5a/html/ : SUCCESS in 4m 39s","accounts_in_message":[],"_revision_number":2},{"id":"6a8bfa5b7e0d604625a7dcab3bd5ce6a650ac8f1","author":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"date":"2019-04-25 01:12:18.000000000","message":"Uploaded patch set 3: Commit message was updated.","accounts_in_message":[],"_revision_number":3},{"id":"1e5c8a7ddefbfe55acfaf1c84ef68d53548cd66c","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-25 03:10:54.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- tempest-full http://logs.openstack.org/21/654321/3/check/tempest-full/119d874/ : SUCCESS in 1h 57m 05s\n- tempest-full-py3 http://logs.openstack.org/21/654321/3/check/tempest-full-py3/5f31277/ : SUCCESS in 1h 47m 35s\n- openstack-tox-lower-constraints http://logs.openstack.org/21/654321/3/check/openstack-tox-lower-constraints/37817e9/ : SUCCESS in 6m 23s\n- openstack-tox-pep8 http://logs.openstack.org/21/654321/3/check/openstack-tox-pep8/8bac457/ : SUCCESS in 4m 31s\n- openstack-tox-py27 http://logs.openstack.org/21/654321/3/check/openstack-tox-py27/05e262c/ : SUCCESS in 4m 47s\n- openstack-tox-py35 http://logs.openstack.org/21/654321/3/check/openstack-tox-py35/947b1ca/ : SUCCESS in 6m 10s\n- openstack-tox-py36 http://logs.openstack.org/21/654321/3/check/openstack-tox-py36/3ac38f7/ : SUCCESS in 5m 37s\n- openstack-tox-py37 http://logs.openstack.org/21/654321/3/check/openstack-tox-py37/7706854/ : SUCCESS in 6m 44s\n- openstack-tox-docs http://logs.openstack.org/21/654321/3/check/openstack-tox-docs/95a1b7c/html/ : SUCCESS in 4m 24s","accounts_in_message":[],"_revision_number":3},{"id":"767626f4c9767b5636cf90b919fa17b5e83367fe","author":{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},"date":"2019-05-21 14:27:58.000000000","message":"Patch Set 3: Code-Review-1\n\nWe should have unit tests for this new check. You can probably use the RoleCheck tests as an example: https://github.com/openstack/oslo.policy/blob/master/oslo_policy/tests/test_checks.py#L64","accounts_in_message":[],"_revision_number":3},{"id":"f7043de315892c761d87de466780a2e96087a71d","author":{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},"date":"2019-05-21 14:43:06.000000000","message":"Patch Set 3: -Code-Review Workflow-1\n\nSorry, just realized this is marked PoC. I\u0027ll drop my vote in the interest of getting other people to look at it.\n\nHowever, I see all of the deps have been abandoned. Can this be too?","accounts_in_message":[],"_revision_number":3},{"id":"fb5a3c29831146ad69746ca5ecabead28d7932cc","author":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"date":"2019-05-21 15:08:31.000000000","message":"Patch Set 3:\n\n\u003e Sorry, just realized this is marked PoC. I\u0027ll drop my vote in the\n \u003e interest of getting other people to look at it.\n \u003e \n \u003e However, I see all of the deps have been abandoned. Can this be\n \u003e too?\n\nKeystone does not accept \u0027tag\u0027 attribute exposition within auth-token, so that I abandoned all commits at keystone side. However, new rule for tag is still valid to be reviewed. \n\nI will find how to add \u0027tag\u0027 attribute in credential at service(nova/neutron..) side and  will be appreciated if you guys think of tag-based policy.","accounts_in_message":[],"_revision_number":3},{"id":"5895d4ba9931771ad473322a7c6de19e2a4e391d","author":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"date":"2019-05-21 15:10:06.000000000","message":"Patch Set 3:\n\n\u003e \u003e Sorry, just realized this is marked PoC. I\u0027ll drop my vote in the\n \u003e \u003e interest of getting other people to look at it.\n \u003e \u003e\n \u003e \u003e However, I see all of the deps have been abandoned. Can this be\n \u003e \u003e too?\n \u003e \n \u003e Keystone does not accept \u0027tag\u0027 attribute exposition within\n \u003e auth-token, so that I abandoned all commits at keystone side.\n \u003e However, new rule for tag is still valid to be reviewed.\n \u003e \n \u003e I will find how to add \u0027tag\u0027 attribute in credential at\n \u003e service(nova/neutron..) side and  will be appreciated if you guys\n \u003e think of tag-based policy.\n\n* s/guys think /guys let me know how/","accounts_in_message":[],"_revision_number":3},{"id":"ef7e2444b4b281032ffdad8e5a18d7e4c15115be","author":{"_account_id":6928,"name":"Ben Nemec","email":"openstack@nemebean.com","username":"bnemec"},"date":"2019-05-21 15:56:40.000000000","message":"Patch Set 3:\n\nOkay, this is probably a discussion to have with the Keystone policy experts. I\u0027m hesitant to pursue a feature that requires merging changes to every service, but if there\u0027s a compelling use case it might be worth it.\n\nI would suggest updating the commit message to reflect the current plan.","accounts_in_message":[],"_revision_number":3},{"id":"58256e3e7157635af9112a8a5de0a5122561e3b8","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2019-12-18 11:34:06.000000000","message":"Abandoned","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"bfee54992c42e41a0c9dbc099f82b3b208ba004f","revisions":{"eae8749d423ee4d3634565402788cfaa906c058e":{"kind":"REWORK","_number":1,"created":"2019-04-22 06:31:44.000000000","uploader":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"ref":"refs/changes/21/654321/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/oslo.policy","ref":"refs/changes/21/654321/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/1"}}},"commit":{"parents":[{"commit":"504b245d2e4ff031e9c6bdb054d9df002a899a22","subject":"OpenDev Migration Patch","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/504b245d2e4ff031e9c6bdb054d9df002a899a22"}]}],"author":{"name":"Yang Youseok","email":"ileixe@gmail.com","date":"2019-04-22 06:21:41.000000000","tz":540},"committer":{"name":"Yang Youseok","email":"ileixe@gmail.com","date":"2019-04-22 06:31:34.000000000","tz":540},"subject":"[PoC] Add new kind of check called \u0027tags\u0027","message":"[PoC] Add new kind of check called \u0027tags\u0027\n\nAdd new check kind for matching tag. Auth token from Keystone now\nexposes \u0027project_tags\u0027 and several sub components related to the\nattribute now accept new attribute.\n\nAdmin can control this kind of check using tag based policy per\nproject. Possible use cases are look like\n\n- \"tags:production\"\n- \"tags:develop\"\n- \"tags:staging and tags:test\"\n- \"tags:%(tags)\"\n\nTag is orginally list attribute so that this kind of check match\ntwo specified lists are overlapped. If there were any matched tagging\nfrom two lists, check returns True.\n\nDepends-On: https://review.opendev.org/#/c/654301\nDepends-On: https://review.opendev.org/#/c/654309\nDepends-On: https://review.opendev.org/#/c/654307\nDepends-On: https://review.opendev.org/#/c/654305\n\nChange-Id: I7f450344d93424dc6c9379ae905e87f8f0dac09b\nCloses-bug: #1807697\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/eae8749d423ee4d3634565402788cfaa906c058e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/eae8749d423ee4d3634565402788cfaa906c058e"}]},"branch":"refs/heads/master"},"7ccf265c10772d99d4b3228e83b8bf2992249c24":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2019-04-22 06:33:15.000000000","uploader":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"ref":"refs/changes/21/654321/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/oslo.policy","ref":"refs/changes/21/654321/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/2"}}},"commit":{"parents":[{"commit":"504b245d2e4ff031e9c6bdb054d9df002a899a22","subject":"OpenDev Migration Patch","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/504b245d2e4ff031e9c6bdb054d9df002a899a22"}]}],"author":{"name":"Yang Youseok","email":"ileixe@gmail.com","date":"2019-04-22 06:21:41.000000000","tz":540},"committer":{"name":"Yang Youseok","email":"ileixe@gmail.com","date":"2019-04-22 06:33:06.000000000","tz":540},"subject":"[PoC] Add new kind of check called \u0027tags\u0027","message":"[PoC] Add new kind of check called \u0027tags\u0027\n\nAdd new check kind for matching tag. Auth token from Keystone now\nexposes \u0027project_tags\u0027 and several sub components related to the\nattribute now accept new attribute.\n\nAdmin can control this kind of check using tag based policy per\nproject. Possible use cases are look like\n\n- \"tags:production\"\n- \"tags:develop\"\n- \"tags:staging and tags:test\"\n- \"tags:%(tags)s\"\n\nTag is orginally list attribute so that this kind of check match\ntwo specified lists are overlapped. If there were any matched tagging\nfrom two lists, check returns True.\n\nDepends-On: https://review.opendev.org/#/c/654301\nDepends-On: https://review.opendev.org/#/c/654309\nDepends-On: https://review.opendev.org/#/c/654307\nDepends-On: https://review.opendev.org/#/c/654305\n\nChange-Id: I7f450344d93424dc6c9379ae905e87f8f0dac09b\nCloses-bug: #1807697\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/7ccf265c10772d99d4b3228e83b8bf2992249c24"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/7ccf265c10772d99d4b3228e83b8bf2992249c24"}]},"branch":"refs/heads/master"},"bfee54992c42e41a0c9dbc099f82b3b208ba004f":{"kind":"NO_CODE_CHANGE","_number":3,"created":"2019-04-25 01:12:18.000000000","uploader":{"_account_id":26970,"name":"Yang Youseok","email":"ileixe@gmail.com","username":"ileixe"},"ref":"refs/changes/21/654321/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/oslo.policy","ref":"refs/changes/21/654321/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/oslo.policy refs/changes/21/654321/3"}}},"commit":{"parents":[{"commit":"504b245d2e4ff031e9c6bdb054d9df002a899a22","subject":"OpenDev Migration Patch","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/504b245d2e4ff031e9c6bdb054d9df002a899a22"}]}],"author":{"name":"Yang Youseok","email":"ileixe@gmail.com","date":"2019-04-22 06:21:41.000000000","tz":540},"committer":{"name":"Yang Youseok","email":"ileixe@gmail.com","date":"2019-04-25 01:11:22.000000000","tz":540},"subject":"[PoC] Add new kind of check called \u0027tags\u0027","message":"[PoC] Add new kind of check called \u0027tags\u0027\n\nAdd new check kind for matching tag. Auth token from Keystone now\nexposes \u0027project_tags\u0027 and several sub components related to the\nattribute now accept new attribute.\n\nAdmin can control this kind of check using tag based policy per\nproject. Possible use cases are look like\n\n- \"tags:production\"\n- \"tags:develop\"\n- \"tags:staging and tags:test\"\n- \"tags:%(tags)s\"\n\nTag is orginally list attribute so that this kind of check match\ntwo specified lists are overlapped. If there were any matched tagging\nfrom two lists, check returns True.\n\nDepends-On: https://review.opendev.org/#/c/654301\nDepends-On: https://review.opendev.org/#/c/654309\nDepends-On: https://review.opendev.org/#/c/654307\nDepends-On: https://review.opendev.org/#/c/654305\n\nChange-Id: I7f450344d93424dc6c9379ae905e87f8f0dac09b\nCloses-bug: #1807697\nCloses-bug: #1825336\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/bfee54992c42e41a0c9dbc099f82b3b208ba004f"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/oslo.policy/commit/bfee54992c42e41a0c9dbc099f82b3b208ba004f"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
