)]}'
{"id":"openstack%2Fsecurity-doc~784078","triplet_id":"openstack%2Fsecurity-doc~master~I5cbc4ec8f15ca7c66ca9562b536299524ab5999c","project":"openstack/security-doc","branch":"master","topic":"bug/1919357","hashtags":[],"change_id":"I5cbc4ec8f15ca7c66ca9562b536299524ab5999c","subject":"OSSN-0089: Missing configuration option in Secure Live Migration guide","status":"MERGED","created":"2021-03-31 11:46:59.000000000","updated":"2021-04-12 21:25:36.000000000","submitted":"2021-04-12 21:23:43.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":10,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"784078-bug/1919357","meta_rev_id":"aa92b6970586e66e2f262eff6128aeb11e2cd5b4","_number":784078,"virtual_id_number":784078,"owner":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:gate","value":2,"date":"2021-04-12 21:23:20.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"all":[{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2021-04-12 21:17:48.000000000","_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":2,"date":"2021-04-12 18:00:51.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"all":[{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":1,"date":"2021-04-12 21:17:48.000000000","_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"value":0,"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-03-31 11:57:18.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-04-03 00:45:57.000000000","updated_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"reviewer":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"state":"REVIEWER"},{"updated":"2021-04-12 18:00:51.000000000","updated_by":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"reviewer":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"state":"REVIEWER"}],"messages":[{"id":"426686d9d2af7ff50754f8119657c853cccf5407","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2021-03-31 11:46:59.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"5ef3ae642f6c5ca36fd0317afce63f4f3c41f4a8","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-31 11:57:18.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/806d9e7abaf140e590fa5af6d83c93b1 : FAILURE in 4m 25s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/68b702c2c2ff44cdb8c9e25c58c1bd40 : SUCCESS in 4m 23s","accounts_in_message":[],"_revision_number":1},{"id":"61bbb46d73e9365bc7c099fd949d38ebc67673db","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2021-03-31 12:23:59.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"ce6034b7238cb076ad9cc1963763c1353971941b","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-03-31 12:33:07.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/d969e78504c34f9c9b0d8d99428bfa2e : SUCCESS in 3m 56s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/b208c3bfce13402aadbef2737ef4e40d : SUCCESS in 4m 09s","accounts_in_message":[],"_revision_number":2},{"id":"8243604461556b3df69f08d5a911e5e0ffa0492e","author":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"date":"2021-04-03 00:45:57.000000000","message":"Patch Set 2: Code-Review-1\n\n(5 comments)\n\nLooks ok to me, a couple spelling/grammar changes noted.","accounts_in_message":[],"_revision_number":2},{"id":"3ee04ae644b4c1ca2b8c320801282c9ccee7fe75","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2021-04-12 07:46:40.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"a96c000d3784c5e45af9f501f0a78404e95af579","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-12 07:51:10.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/669b80524de54a4fa26ad669727d8cea : SUCCESS in 3m 27s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/99ddbbcda38e4bd38fbb34dfb4662544 : SUCCESS in 3m 57s","accounts_in_message":[],"_revision_number":3},{"id":"506f682696c7ac89944a1cf5e165b1f2b105d66c","author":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"date":"2021-04-12 07:52:48.000000000","message":"Patch Set 3:\n\n(5 comments)\n\nI edited everything you have found. German is more strict on commas though :D","accounts_in_message":[],"_revision_number":3},{"id":"9dc2d992632fcdb3e098770a59c6327e999add56","author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"date":"2021-04-12 18:00:51.000000000","message":"Patch Set 3: Code-Review+2\n\nThanks for reporting, fixing, and putting this guidance together!","accounts_in_message":[],"_revision_number":3},{"id":"98264d61d6d43618291ae4a50c0e47d6a798443c","author":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"},"date":"2021-04-12 21:17:48.000000000","message":"Patch Set 3: Code-Review+2 Workflow+1\n\nThanks Josephine!","accounts_in_message":[],"_revision_number":3},{"id":"7a947e77f00d3d08986573a8be85e6f4c2bb014a","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-12 21:18:10.000000000","message":"Patch Set 3: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":3},{"id":"1cf31a2486d31a875b034d34f089c1976dd057d0","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-12 21:23:20.000000000","message":"Patch Set 3: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/2341e286e8514b78aeb6428881da648b : SUCCESS in 3m 59s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/beb8ac8d75de4a35b263e745f2b231ed : SUCCESS in 4m 09s","accounts_in_message":[],"_revision_number":3},{"id":"1b4e0159efac1d83e60b809e87c1a8c02d3fd1c2","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-12 21:23:43.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":3},{"id":"aa92b6970586e66e2f262eff6128aeb11e2cd5b4","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-12 21:25:36.000000000","message":"Patch Set 3:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-manuals https://zuul.opendev.org/t/openstack/build/f989192ab16349ef9629c21555694bf6 : SUCCESS in 1m 07s","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b","revisions":{"1fbae2ccfa23e79448497232ee042d924e93ee96":{"kind":"REWORK","_number":1,"created":"2021-03-31 11:46:59.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/78/784078/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/security-doc","ref":"refs/changes/78/784078/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/security-doc refs/changes/78/784078/1"}}},"commit":{"parents":[{"commit":"5e667944ab76756e9bd2bc3c563fc906bfb912e9","subject":"Updated from openstack-manuals","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/5e667944ab76756e9bd2bc3c563fc906bfb912e9"}]}],"author":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2021-03-31 11:42:18.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2021-03-31 11:42:18.000000000","tz":120},"subject":"OSSN-0089: Missing configuration option in Secure Live Migration guide","message":"OSSN-0089: Missing configuration option in Secure Live Migration guide\n\nThe guide to enable secure live migration with QEMU-native tls on\nnova compute nodes missed an important config option. Without this\noption a default connection is uses which is TCP instead of TLS.\nThis leads to an unecrypted migration of the ram.\n\nCloses-Bug: #1919357\nChange-Id: I5cbc4ec8f15ca7c66ca9562b536299524ab5999c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/1fbae2ccfa23e79448497232ee042d924e93ee96"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/1fbae2ccfa23e79448497232ee042d924e93ee96"}]},"branch":"refs/heads/master"},"18e745bb14537500a557fdd6f22413f695da7ca5":{"kind":"REWORK","_number":2,"created":"2021-03-31 12:23:59.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/78/784078/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/security-doc","ref":"refs/changes/78/784078/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/security-doc refs/changes/78/784078/2"}}},"commit":{"parents":[{"commit":"5e667944ab76756e9bd2bc3c563fc906bfb912e9","subject":"Updated from openstack-manuals","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/5e667944ab76756e9bd2bc3c563fc906bfb912e9"}]}],"author":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2021-03-31 11:42:18.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2021-03-31 12:23:36.000000000","tz":120},"subject":"OSSN-0089: Missing configuration option in Secure Live Migration guide","message":"OSSN-0089: Missing configuration option in Secure Live Migration guide\n\nThe guide to enable secure live migration with QEMU-native tls on\nnova compute nodes missed an important config option. Without this\noption a default connection is uses which is TCP instead of TLS.\nThis leads to an unecrypted migration of the ram.\n\nCloses-Bug: #1919357\nChange-Id: I5cbc4ec8f15ca7c66ca9562b536299524ab5999c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/18e745bb14537500a557fdd6f22413f695da7ca5"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/18e745bb14537500a557fdd6f22413f695da7ca5"}]},"branch":"refs/heads/master"},"8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b":{"kind":"REWORK","_number":3,"created":"2021-04-12 07:46:40.000000000","uploader":{"_account_id":28271,"name":"Josephine Seifert","email":"josephine.seifert@cloudandheat.com","username":"josei"},"ref":"refs/changes/78/784078/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/security-doc","ref":"refs/changes/78/784078/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/784078/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/security-doc refs/changes/78/784078/3"}}},"commit":{"parents":[{"commit":"5e667944ab76756e9bd2bc3c563fc906bfb912e9","subject":"Updated from openstack-manuals","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/5e667944ab76756e9bd2bc3c563fc906bfb912e9"}]}],"author":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2021-03-31 11:42:18.000000000","tz":120},"committer":{"name":"Josephine Seifert","email":"josephine.seifert@secustack.com","date":"2021-04-12 07:46:12.000000000","tz":120},"subject":"OSSN-0089: Missing configuration option in Secure Live Migration guide","message":"OSSN-0089: Missing configuration option in Secure Live Migration guide\n\nThe guide to enable secure live migration with QEMU-native tls on\nnova compute nodes missed an important config option. Without this\noption a default connection is uses which is TCP instead of TLS.\nThis leads to an unecrypted migration of the ram.\n\nCloses-Bug: #1919357\nChange-Id: I5cbc4ec8f15ca7c66ca9562b536299524ab5999c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"status":"CLOSED","labels":[{"label":"Verified","status":"OK","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"OK","applied_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"}},{"label":"Workflow","status":"OK","applied_by":{"_account_id":21420,"name":"Gage Hugo","email":"gagehugo@gmail.com","username":"ghugo"}}]}],"submit_requirements":[{"name":"Verified","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Verified\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}},{"name":"Workflow","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Workflow\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}}]}
