)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"f6edfe5adb58c4e850ed5ed002b1368b7f170952","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"1919698c_f22b47a0","updated":"2026-08-25 17:46:28.000000000","message":"recheck\n\nunsure if the apt cache issue is a new CI blocker or a flaky cache issue","commit_id":"29249a9fcacb512c9d4a9c71b5cb42fd56364d0a"}],"ossa/OSSA-2026-037.yaml":[{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"8fd7584b61f5181ddc4521e11c3c4b331e598164","unresolved":true,"context_lines":[{"line_number":13,"context_line":"  delegated."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"  A token scoped through an OAuth1 access token, an application"},{"line_number":16,"context_line":"  credential, or a trust could create new long-lived credentials or"},{"line_number":17,"context_line":"  authorize new delegations that persist independently of, and outlive,"},{"line_number":18,"context_line":"  the credential used to obtain them. Separately, tokens obtained"},{"line_number":19,"context_line":"  through any of these delegation mechanisms could be submitted to the"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"0cbf45a5_586387b7","line":16,"updated":"2026-08-25 16:35:14.000000000","message":"with only the 2 patches here, ec2 api can still be used to create long-lived credentials","commit_id":"00bc85374e7b748c3df918566f3e04683a6721b7"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"a9751f63447e007ace6f2e76b7bbb4231724424e","unresolved":true,"context_lines":[{"line_number":13,"context_line":"  delegated."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"  A token scoped through an OAuth1 access token, an application"},{"line_number":16,"context_line":"  credential, or a trust could create new long-lived credentials or"},{"line_number":17,"context_line":"  authorize new delegations that persist independently of, and outlive,"},{"line_number":18,"context_line":"  the credential used to obtain them. Separately, tokens obtained"},{"line_number":19,"context_line":"  through any of these delegation mechanisms could be submitted to the"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"5adcb0bb_0396b1c8","line":16,"in_reply_to":"0cbf45a5_586387b7","updated":"2026-08-25 16:41:23.000000000","message":"This is hinted at the note below:\n\n\n\u0027This advisory does not address a related weakness in EC2 credential\n (``ec2credential``) handling, which is being tracked and fixed in\n public and will be covered by a separate OpenStack Security Note\n (OSSN).\u0027\n\nDo you want to make it more explicit? Where would you insert that?","commit_id":"00bc85374e7b748c3df918566f3e04683a6721b7"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"b7f352e151825015ab0fbaf4509fb9ed02896b1b","unresolved":false,"context_lines":[{"line_number":13,"context_line":"  delegated."},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"  A token scoped through an OAuth1 access token, an application"},{"line_number":16,"context_line":"  credential, or a trust could create new long-lived credentials or"},{"line_number":17,"context_line":"  authorize new delegations that persist independently of, and outlive,"},{"line_number":18,"context_line":"  the credential used to obtain them. Separately, tokens obtained"},{"line_number":19,"context_line":"  through any of these delegation mechanisms could be submitted to the"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7a3fcacb_d4ddcc62","line":16,"in_reply_to":"5adcb0bb_0396b1c8","updated":"2026-08-25 16:51:50.000000000","message":"yes, I started from the beginning and then frantically tried to assess what should and shouldn\u0027t stay in the description, not looking at the notes on the bottom","commit_id":"00bc85374e7b748c3df918566f3e04683a6721b7"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"d7f9efcd3e28ae18ca77c1c6df711b2d7112f8f0","unresolved":true,"context_lines":[{"line_number":5,"context_line":"title: Inconsistent scope enforcement for delegated tokens in Keystone"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"description: \u003e"},{"line_number":8,"context_line":"  Grzegorz Grasza (Red Hat) and Tim Shephard (roiai.ca) independently"},{"line_number":9,"context_line":"  reported that OpenStack Keystone does not consistently enforce scope"},{"line_number":10,"context_line":"  restrictions on tokens obtained through delegated authentication. A"},{"line_number":11,"context_line":"  delegated token is intended to be a narrower grant than a normal user"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"9a810587_bd1d1383","line":8,"updated":"2026-08-25 15:53:20.000000000","message":"Tim discovered the fallback to default scope for app credentials, then what I found is that this issue also impacts ec2 tokens. An ec2credential token can rescope via POST /v3/auth/tokens methods\u003d[\"token\"] to an explicitly requested, arbitrary project - not just a default project fallback.\n\nSo these weren\u0027t independent findings of the same issue but I discovered a different based on what Tim had found.\n\nThe separate issue reported my me in https://bugs.launchpad.net/keystone/+bug/2153453 is a rescope by creating another \"token generator\", a different API from the token exchange API issue found in the other bug.","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"013d56c74e9ef0a963f0b0c9ef3ae15546238864","unresolved":true,"context_lines":[{"line_number":5,"context_line":"title: Inconsistent scope enforcement for delegated tokens in Keystone"},{"line_number":6,"context_line":""},{"line_number":7,"context_line":"description: \u003e"},{"line_number":8,"context_line":"  Grzegorz Grasza (Red Hat) and Tim Shephard (roiai.ca) independently"},{"line_number":9,"context_line":"  reported that OpenStack Keystone does not consistently enforce scope"},{"line_number":10,"context_line":"  restrictions on tokens obtained through delegated authentication. A"},{"line_number":11,"context_line":"  delegated token is intended to be a narrower grant than a normal user"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"eba13337_394e8ac5","line":8,"in_reply_to":"9a810587_bd1d1383","updated":"2026-08-25 16:09:14.000000000","message":"Ack I can fix this","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"d7f9efcd3e28ae18ca77c1c6df711b2d7112f8f0","unresolved":true,"context_lines":[{"line_number":48,"context_line":"reviews:"},{"line_number":49,"context_line":"  2026.2/hibiscus (development):"},{"line_number":50,"context_line":"    - https://review.opendev.org/1002301"},{"line_number":51,"context_line":"    - https://review.opendev.org/1002302"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2026.1/gazpacho:"},{"line_number":54,"context_line":"    - https://review.opendev.org/1002303"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"ae463a16_7c2e1495","line":51,"updated":"2026-08-25 15:53:20.000000000","message":"Additionally, https://review.opendev.org/c/openstack/keystone/+/1002082 and https://review.opendev.org/c/openstack/keystone/+/1002325, and https://review.opendev.org/c/openstack/keystone/+/1002330","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"251bbf52f370473725bac5836bcaa64b40feba46","unresolved":false,"context_lines":[{"line_number":48,"context_line":"reviews:"},{"line_number":49,"context_line":"  2026.2/hibiscus (development):"},{"line_number":50,"context_line":"    - https://review.opendev.org/1002301"},{"line_number":51,"context_line":"    - https://review.opendev.org/1002302"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2026.1/gazpacho:"},{"line_number":54,"context_line":"    - https://review.opendev.org/1002303"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"fe8ea050_c13203b0","line":51,"in_reply_to":"aaf955bd_dbf0f53a","updated":"2026-08-25 16:42:56.000000000","message":"makes sense. \n\nWe\u0027ll roll out an advisory soon as you\u0027ve the keystone team has patches reviewed/finalized. I\u0027ll switch https://bugs.launchpad.net/keystone/+bug/2159643 to public now","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"810f706765ef35015770a4edbee00f7cab35b550","unresolved":true,"context_lines":[{"line_number":48,"context_line":"reviews:"},{"line_number":49,"context_line":"  2026.2/hibiscus (development):"},{"line_number":50,"context_line":"    - https://review.opendev.org/1002301"},{"line_number":51,"context_line":"    - https://review.opendev.org/1002302"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2026.1/gazpacho:"},{"line_number":54,"context_line":"    - https://review.opendev.org/1002303"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"7ae42e04_67d8acbe","line":51,"in_reply_to":"aaf955bd_dbf0f53a","updated":"2026-08-25 16:43:09.000000000","message":"you could say 1002289 is hardening for the 2 main patches, but not hardening for the EC2 Keystone API ban.","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"013d56c74e9ef0a963f0b0c9ef3ae15546238864","unresolved":true,"context_lines":[{"line_number":48,"context_line":"reviews:"},{"line_number":49,"context_line":"  2026.2/hibiscus (development):"},{"line_number":50,"context_line":"    - https://review.opendev.org/1002301"},{"line_number":51,"context_line":"    - https://review.opendev.org/1002302"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2026.1/gazpacho:"},{"line_number":54,"context_line":"    - https://review.opendev.org/1002303"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"c934883b_7dcf7d65","line":51,"in_reply_to":"ae463a16_7c2e1495","updated":"2026-08-25 16:09:14.000000000","message":"https://review.opendev.org/c/openstack/keystone/+/1002082 is hinted through the OSSN... \n\nhttps://review.opendev.org/c/openstack/keystone/+/1002289 and its backports makes sense.. \n\nhttps://review.opendev.org/c/openstack/keystone/+/1002330 - this is https://bugs.launchpad.net/keystone/+bug/2159643 - currently private. I understand it\u0027s related. But is it required right now to be included in the same advisory?","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"6673864dd26705d806daa8a95ceb3e456d8f8632","unresolved":true,"context_lines":[{"line_number":48,"context_line":"reviews:"},{"line_number":49,"context_line":"  2026.2/hibiscus (development):"},{"line_number":50,"context_line":"    - https://review.opendev.org/1002301"},{"line_number":51,"context_line":"    - https://review.opendev.org/1002302"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2026.1/gazpacho:"},{"line_number":54,"context_line":"    - https://review.opendev.org/1002303"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"232e8f1a_4b5c90c9","line":51,"in_reply_to":"c934883b_7dcf7d65","updated":"2026-08-25 16:40:00.000000000","message":"On second thought, https://review.opendev.org/c/openstack/keystone/+/1002289 (and its backports) seems like hardening. Correct?\n\nCurrently https://review.opendev.org/c/openstack/keystone/+/1002301 makes it so that empty methods are treated as delegated and hence rejected.\n\n1002289 fixes the root cause that ec2credential and oauth2_credential aren\u0027t in the fernet bitmask so they get silently dropped on encode/decode, but from a security standpoint the threat is already addressed by 1002301\u0027s defensive handling. Fact check this for me.\n\nIMHO, this hardening can come along with the ec2credential/EC2 API ban (https://review.opendev.org/c/openstack/keystone/+/1002082 + backports) and we\u0027ll issue an OSSN for this.","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"f054909f804dce7258cb5e8cf99b190d138fdc34","unresolved":true,"context_lines":[{"line_number":48,"context_line":"reviews:"},{"line_number":49,"context_line":"  2026.2/hibiscus (development):"},{"line_number":50,"context_line":"    - https://review.opendev.org/1002301"},{"line_number":51,"context_line":"    - https://review.opendev.org/1002302"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2026.1/gazpacho:"},{"line_number":54,"context_line":"    - https://review.opendev.org/1002303"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"aaf955bd_dbf0f53a","line":51,"in_reply_to":"c934883b_7dcf7d65","updated":"2026-08-25 16:40:39.000000000","message":"on bug/2159643, only the part that pertains to the credentials api access, including creating, patching, deleting credentials (including ec2 credentials).","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"9d087a494243ce52cd6888f7644419a051105fa2","unresolved":false,"context_lines":[{"line_number":89,"context_line":"  - \u0027A related fix to the Keystone Tempest plugin test suite was"},{"line_number":90,"context_line":"    proposed at https://review.opendev.org/1002296\u0027"},{"line_number":91,"context_line":""},{"line_number":92,"context_line":"errata_history:"},{"line_number":93,"context_line":"  - 2026-08-25 - Original Version"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"d3bca386_c347b707","line":92,"updated":"2026-08-25 15:34:22.000000000","message":"Nit: We don\u0027t usually precreate the errata_history section, and only add it later when an initial errata edit is made. It\u0027s not technically incorrect to have it in here, and in this case we\u0027re very likely to have at least one errata once MITRE returns the requested CVE assignments anyway.","commit_id":"dfbced8114ab685ef52f379204df546d5639889c"}]}
