)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"bb13c6cd2a256da0d513d483195c66dfaaa876bd","unresolved":true,"context_lines":[{"line_number":10,"context_line":"which is used to disable the policy scope enforcement."},{"line_number":11,"context_line":"- https://review.opendev.org/c/openstack/oslo.policy/+/986475"},{"line_number":12,"context_line":"- https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/thread/M72AY5ABQFXQ7XHLVEGHLBBK4XFQGVFK/"},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"It means scope will be enforced always and no way to disable it. Updating"},{"line_number":15,"context_line":"the placement tests accordingly."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Needed-By: https://review.opendev.org/c/openstack/nova/+/986946/"},{"line_number":18,"context_line":"Needed-By: https://review.opendev.org/c/openstack/oslo.policy/+/986475"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"b0306fb6_ddc0b701","line":15,"range":{"start_line":13,"start_character":1,"end_line":15,"end_character":32},"updated":"2026-06-24 10:45:41.000000000","message":"nit: wrap at \u003c\u003d 72 chars","commit_id":"f4fc14cb4f4aa0a4cd3fd09e23053d3fcbe7f3a0"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"34625a7a378aef5c0fbb622709ec974f26cdbdc9","unresolved":false,"context_lines":[{"line_number":10,"context_line":"which is used to disable the policy scope enforcement."},{"line_number":11,"context_line":"- https://review.opendev.org/c/openstack/oslo.policy/+/986475"},{"line_number":12,"context_line":"- https://lists.openstack.org/archives/list/openstack-discuss@lists.openstack.org/thread/M72AY5ABQFXQ7XHLVEGHLBBK4XFQGVFK/"},{"line_number":13,"context_line":""},{"line_number":14,"context_line":"It means scope will be enforced always and no way to disable it. Updating"},{"line_number":15,"context_line":"the placement tests accordingly."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Needed-By: https://review.opendev.org/c/openstack/nova/+/986946/"},{"line_number":18,"context_line":"Needed-By: https://review.opendev.org/c/openstack/oslo.policy/+/986475"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"de53f27a_43b3cbef","line":15,"range":{"start_line":13,"start_character":1,"end_line":15,"end_character":32},"in_reply_to":"b0306fb6_ddc0b701","updated":"2026-06-24 17:31:33.000000000","message":"Done","commit_id":"f4fc14cb4f4aa0a4cd3fd09e23053d3fcbe7f3a0"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"54f57c7ae3aa649b3d89623f9ae8e00eef857590","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"56f8e1c9_03bf896e","updated":"2026-06-17 22:10:52.000000000","message":"recheck refresh logs","commit_id":"1ebe14d575e3941eeff915bd265dc217579528e3"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"fa835929982b8e33ba992b36348097540945307f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":4,"id":"316399a2_1008e459","updated":"2026-06-23 20:24:09.000000000","message":"should we add a release note to call out the removal of the ablity to disabel scope enforcement as part of this and the policy implcaiton of that for system access?","commit_id":"485142b3fc9a01405deeee716c7f646e77ed6bcc"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"adb32e8e4a56f34b9bd001795e804be8a996ef36","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"5e08ddfc_6dbdc5e1","in_reply_to":"316399a2_1008e459","updated":"2026-06-24 02:55:29.000000000","message":"yeah, I think release notes will be helpful.","commit_id":"485142b3fc9a01405deeee716c7f646e77ed6bcc"},{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"41248b6bbfe606073896dd26b66a566b4f2804dd","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"9736a135_720e8478","updated":"2026-06-24 10:43:35.000000000","message":"As noted [on the oslo.poliy change](https://review.opendev.org/c/openstack/oslo.policy/+/986475), I think this is the wrong tack. As things stand, we\u0027re not actually changing any runtime defaults: we\u0027re just changing the test configuration and adding a release note.\n\nI think it would be better to raise an exception here (rather than silencing warnings) if the `enforce_scope` option is set to `False`. That way we are entirely in control of scope enforcement, rather than relying on a specific version of oslo.policy being used.","commit_id":"f4fc14cb4f4aa0a4cd3fd09e23053d3fcbe7f3a0"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a3483592850c216e275749fc877b1316ef6eb3ec","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"c62b04dc_51812783","in_reply_to":"9736a135_720e8478","updated":"2026-06-24 15:45:10.000000000","message":"I replied in the oslo.policy change about there is no benefit of keeping config option but do not allow to change it which is more confusing for users and does not qualify as a config option.\n\nRegarding the old oslo.policy, yes that is what we have workflow for deps (it is hard to make service projects to work with old and newer version of deps). But this is good point and I can bump the oslo.policy version here (once the oslo.policy release is done, I am trying to fix the projects testing first and then oslo.policy release otherwise it will break the gate). The whole idea here is to signal operators that scope enforcement disabling is not allowed now and also not tested as well.","commit_id":"f4fc14cb4f4aa0a4cd3fd09e23053d3fcbe7f3a0"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"34625a7a378aef5c0fbb622709ec974f26cdbdc9","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":6,"id":"cee256e7_d0b0056b","in_reply_to":"c62b04dc_51812783","updated":"2026-06-24 17:31:33.000000000","message":"I have separated the changes, this one to update the testing for the scope enforcement and the next one to mention the upgrade impact via new version of oslo.policy https://review.opendev.org/c/openstack/placement/+/994790/1","commit_id":"f4fc14cb4f4aa0a4cd3fd09e23053d3fcbe7f3a0"},{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"21bdf4a319e09499870eb223f77e491b7fa0acb1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"1567951e_62343c56","updated":"2026-06-25 22:22:03.000000000","message":"This is just updating the testing, looks OK to me.","commit_id":"d1ad2c6e6b23c9b8694e85304457006ee00248ef"}],"placement/tests/functional/gabbits/allocations-legacy-rbac.yaml":[{"author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"change_message_id":"21bdf4a319e09499870eb223f77e491b7fa0acb1","unresolved":true,"context_lines":[{"line_number":273,"context_line":"  request_headers: *project_admin_headers"},{"line_number":274,"context_line":"  data:"},{"line_number":275,"context_line":"    a0b15655-273a-4b3d-9792-2e579b7d5ad9:"},{"line_number":276,"context_line":"      consumer_generation: null"},{"line_number":277,"context_line":"      project_id: 42a32c07-3eeb-4401-9373-68a8cdca6784"},{"line_number":278,"context_line":"      user_id: 66cb2f29-c86d-47c3-8af5-69ae7b778c70"},{"line_number":279,"context_line":"      allocations:"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"4bfba3a9_9fb2a798","line":276,"updated":"2026-06-25 22:22:03.000000000","message":"Note to self: this has to be changed bc system admin can no longer update allocations on L164, so the consumer_generation will not have been incremented yet.","commit_id":"d1ad2c6e6b23c9b8694e85304457006ee00248ef"}],"releasenotes/notes/remove-disabling-rbac-scope-enforcement-4827620a50299038.yaml":[{"author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"change_message_id":"41248b6bbfe606073896dd26b66a566b4f2804dd","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"upgrade:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The deprecated ``[oslo_policy] enforce_scope`` configuration option has"},{"line_number":5,"context_line":"    been removed. Placement no longer has any way to disable RBAC policy"},{"line_number":6,"context_line":"    scope enforcement; scope checks are now always enforced regardless of"},{"line_number":7,"context_line":"    configuration."}],"source_content_type":"text/x-yaml","patch_set":6,"id":"f83aa42a_89021386","line":7,"range":{"start_line":4,"start_character":0,"end_line":7,"end_character":18},"updated":"2026-06-24 10:43:35.000000000","message":"This isn\u0027t really true: is oslo.policy is an older version, then scope checks will still be ignored. It feels like we should be explicitly overriding the configuration option on startup if it exists. I\u0027ve left a comment on the oslo.limit change.","commit_id":"f4fc14cb4f4aa0a4cd3fd09e23053d3fcbe7f3a0"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a3483592850c216e275749fc877b1316ef6eb3ec","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"upgrade:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The deprecated ``[oslo_policy] enforce_scope`` configuration option has"},{"line_number":5,"context_line":"    been removed. Placement no longer has any way to disable RBAC policy"},{"line_number":6,"context_line":"    scope enforcement; scope checks are now always enforced regardless of"},{"line_number":7,"context_line":"    configuration."}],"source_content_type":"text/x-yaml","patch_set":6,"id":"ce8ab283_e4a55c0e","line":7,"range":{"start_line":4,"start_character":0,"end_line":7,"end_character":18},"in_reply_to":"f83aa42a_89021386","updated":"2026-06-24 15:45:10.000000000","message":"I will say, this is valid for the newer oslo.policy version. If we want to continue supporting the old oslo.policy then it add unnecessary maintenance without any gain. We want this temporary added enforce_scope flag to go away entirly and if that is oslo.policy then we can say this things is achieved in project via newer version  of oslo.policy","commit_id":"f4fc14cb4f4aa0a4cd3fd09e23053d3fcbe7f3a0"}]}
