)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Replace the generic sensitive-name grammar with explicit"},{"line_number":10,"context_line":"object sysmeta declarations. Preserve opaque object sysmeta"},{"line_number":11,"context_line":"suffixes in the Crypto-Sysmeta envelope and restore original"},{"line_number":12,"context_line":"object sysmeta names on read. Propagate a trusted"},{"line_number":13,"context_line":"decrypted-field annotation through server-side COPY after"},{"line_number":14,"context_line":"middleware copy-source hooks run."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"31928368_7151cdc1","line":11,"range":{"start_line":11,"start_character":12,"end_line":11,"end_character":40},"updated":"2026-09-18 14:52:29.000000000","message":"what is the \"the Crypto-Sysmeta envelope\"?","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"493533f395104ee5c855d442454366268a7feffc","unresolved":false,"context_lines":[{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Replace the generic sensitive-name grammar with explicit"},{"line_number":10,"context_line":"object sysmeta declarations. Preserve opaque object sysmeta"},{"line_number":11,"context_line":"suffixes in the Crypto-Sysmeta envelope and restore original"},{"line_number":12,"context_line":"object sysmeta names on read. Propagate a trusted"},{"line_number":13,"context_line":"decrypted-field annotation through server-side COPY after"},{"line_number":14,"context_line":"middleware copy-source hooks run."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"3ab8cd34_6fb31ffb","line":11,"range":{"start_line":11,"start_character":12,"end_line":11,"end_character":40},"in_reply_to":"31928368_7151cdc1","updated":"2026-09-22 05:30:35.000000000","message":"replaced with ``stored encrypted sysmeta header``","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":9,"context_line":"Replace the generic sensitive-name grammar with explicit"},{"line_number":10,"context_line":"object sysmeta declarations. Preserve opaque object sysmeta"},{"line_number":11,"context_line":"suffixes in the Crypto-Sysmeta envelope and restore original"},{"line_number":12,"context_line":"object sysmeta names on read. Propagate a trusted"},{"line_number":13,"context_line":"decrypted-field annotation through server-side COPY after"},{"line_number":14,"context_line":"middleware copy-source hooks run."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"Keep the common first-party declaration catalog empty"},{"line_number":17,"context_line":"because this base has no producer. A later producer patch"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"0778568e_9d14ece7","line":14,"range":{"start_line":12,"start_character":30,"end_line":14,"end_character":32},"updated":"2026-09-18 14:52:29.000000000","message":"why?","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":13,"context_line":"decrypted-field annotation through server-side COPY after"},{"line_number":14,"context_line":"middleware copy-source hooks run."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"Keep the common first-party declaration catalog empty"},{"line_number":17,"context_line":"because this base has no producer. A later producer patch"},{"line_number":18,"context_line":"must add its exact common declaration and an end-to-end"},{"line_number":19,"context_line":"probe test before it enables production."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"b00c9d5e_4f0e9ae2","line":16,"range":{"start_line":16,"start_character":16,"end_line":16,"end_character":48},"updated":"2026-09-18 14:52:29.000000000","message":"what is a \"first-party declaration\"? is catalog meant to mean \"set\"?","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"493533f395104ee5c855d442454366268a7feffc","unresolved":false,"context_lines":[{"line_number":13,"context_line":"decrypted-field annotation through server-side COPY after"},{"line_number":14,"context_line":"middleware copy-source hooks run."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"Keep the common first-party declaration catalog empty"},{"line_number":17,"context_line":"because this base has no producer. A later producer patch"},{"line_number":18,"context_line":"must add its exact common declaration and an end-to-end"},{"line_number":19,"context_line":"probe test before it enables production."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"16fcd982_e8629a94","line":16,"range":{"start_line":16,"start_character":16,"end_line":16,"end_character":48},"in_reply_to":"b00c9d5e_4f0e9ae2","updated":"2026-09-22 05:30:35.000000000","message":"replaced with “The middleware for a use case must register its names before it writes a sensitive value.”","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":14,"context_line":"middleware copy-source hooks run."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"Keep the common first-party declaration catalog empty"},{"line_number":17,"context_line":"because this base has no producer. A later producer patch"},{"line_number":18,"context_line":"must add its exact common declaration and an end-to-end"},{"line_number":19,"context_line":"probe test before it enables production."},{"line_number":20,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"ea70c856_b1ecc2f5","line":17,"range":{"start_line":17,"start_character":37,"end_line":17,"end_character":57},"updated":"2026-09-18 14:52:29.000000000","message":"what is a \"producer patch\"?","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"493533f395104ee5c855d442454366268a7feffc","unresolved":false,"context_lines":[{"line_number":14,"context_line":"middleware copy-source hooks run."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"Keep the common first-party declaration catalog empty"},{"line_number":17,"context_line":"because this base has no producer. A later producer patch"},{"line_number":18,"context_line":"must add its exact common declaration and an end-to-end"},{"line_number":19,"context_line":"probe test before it enables production."},{"line_number":20,"context_line":""}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"8cd481b5_c2edbfde","line":17,"range":{"start_line":17,"start_character":37,"end_line":17,"end_character":57},"in_reply_to":"ea70c856_b1ecc2f5","updated":"2026-09-22 05:30:35.000000000","message":"replaced with \"use case patch\"","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"9dd44565f778980a05811824f6f5e58b65bcd3a3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"76311f13_e94cf585","updated":"2026-09-18 05:15:46.000000000","message":"I have some WIP change to update this squash patch according to suggestion from Tim(https://review.opendev.org/c/openstack/swift/+/1003424/comment/83bb3605_a52f9bdf/), basically keep the sensitive header in cleartext and don\u0027t encrypt them when cluster encryption is disabled.","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"7482f45f_3c149626","updated":"2026-09-18 14:52:29.000000000","message":"early review comments.\n\naside: I\u0027m noticing that (I assume) LLM generated comments and commit messages use terms and concepts that are not part of our vernacular, which I\u0027m finding unhelpful.\n\nIIUC this provides *three* ways in which a developer can declare sysmeta sensitive:\n\n* add it to the hard-coded list in registry.py\n* register it dynamically at runtime\n* add it to a SENSITIVE_SYSMETA_ENV_KEY list in the request environ (but that may not propagate to a subrequest?)\n\n...which is two more than the ideal ;-)\n\nThis also has a significant amount of code and complexity to support hypothetical future use cases w.r.t. copying. I wonder if we can avoid this by (a) stop copying all sysmeta and (b) recommending middlewares register a sensitive prefix to future proof themselves.","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"}],"swift/common/middleware/copy.py":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":560,"context_line":"                close_if_possible(source_resp.app_iter)"},{"line_number":561,"context_line":"                raise"},{"line_number":562,"context_line":""},{"line_number":563,"context_line":"        # Keep this annotation request-local. Middleware copy-source hooks run"},{"line_number":564,"context_line":"        # first, so only fields that they kept can tell destination crypto to"},{"line_number":565,"context_line":"        # re-encrypt."},{"line_number":566,"context_line":"        propagate_sensitive_sysmeta("}],"source_content_type":"text/x-python","patch_set":1,"id":"c1a561bc_b312fe13","line":563,"range":{"start_line":563,"start_character":31,"end_line":563,"end_character":44},"updated":"2026-09-18 14:52:29.000000000","message":"why?","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":564,"context_line":"        # first, so only fields that they kept can tell destination crypto to"},{"line_number":565,"context_line":"        # re-encrypt."},{"line_number":566,"context_line":"        propagate_sensitive_sysmeta("},{"line_number":567,"context_line":"            source_resp.environ, sink_req.environ, sink_req.headers)"},{"line_number":568,"context_line":""},{"line_number":569,"context_line":"        # Create response headers for PUT response"},{"line_number":570,"context_line":"        resp_headers \u003d self._create_response_headers(source_path,"}],"source_content_type":"text/x-python","patch_set":1,"id":"3159ed40_1f87555e","line":567,"updated":"2026-09-18 14:52:29.000000000","message":"IIUC this is going to force the re-encryption of sensitive headers on the copy PUT regardless of what is in the registry. So this ensures that when a middleware has not been upgraded to register sensitive names, a copy does not write them in the clear.\n\nWhy do we need a second mechanism to achieve this? why does the decrypter not just update the registry with everything it finds that has been encrypted? do we think there might be a use case where a middleware might want newly put sysmeta to NOT be encrypted but copies of the same sysmeta to remain encrypted?\n\nThis does make it impossible for a middleware to be updated to *stop* registering a particular sysmeta key, and then use a copy to decrypt or replace existing values.\n\nShould we also provide for the opposite case: registry on the copying proxy say to encrypt, but the source was not encrypted so leave the destination sysmeta unencrypted?","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"}],"swift/common/middleware/versioned_writes/object_versioning.py":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":369,"context_line":"        copy_header_subset(source_resp, put_req,"},{"line_number":370,"context_line":"                           lambda k: k.lower() !\u003d \u0027x-timestamp\u0027)"},{"line_number":371,"context_line":"        propagate_sensitive_sysmeta("},{"line_number":372,"context_line":"            source_resp.environ, put_req.environ, put_req.headers)"},{"line_number":373,"context_line":"        put_req.environ[\u0027wsgi.input\u0027] \u003d FileLikeIter(source_resp.app_iter)"},{"line_number":374,"context_line":"        slo_size \u003d put_req.headers.get(\u0027X-Object-Sysmeta-Slo-Size\u0027)"},{"line_number":375,"context_line":"        if slo_size:"}],"source_content_type":"text/x-python","patch_set":1,"id":"3defd186_6ed82a00","line":372,"updated":"2026-09-18 14:52:29.000000000","message":"oh, this is a significant case because this is a low-level copy where *do* want to preserve sysmeta","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":416,"context_line":""},{"line_number":417,"context_line":"        copy_header_subset(req, put_req, non_expiry_header)"},{"line_number":418,"context_line":"        propagate_sensitive_sysmeta("},{"line_number":419,"context_line":"            req.environ, put_req.environ, put_req.headers)"},{"line_number":420,"context_line":"        if \u0027swift.content_type_overridden\u0027 in req.environ:"},{"line_number":421,"context_line":"            put_req.environ[\u0027swift.content_type_overridden\u0027] \u003d \\"},{"line_number":422,"context_line":"                req.environ.pop(\u0027swift.content_type_overridden\u0027)"}],"source_content_type":"text/x-python","patch_set":1,"id":"f4948a89_806de556","line":419,"updated":"2026-09-18 14:52:29.000000000","message":"not sure this is applicable - this is copying headers from a client request, none of which will be encrypted","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"}],"swift/common/registry.py":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":90,"context_line":"_sensitive_headers \u003d set()"},{"line_number":91,"context_line":"_sensitive_params \u003d set()"},{"line_number":92,"context_line":""},{"line_number":93,"context_line":"# First-party declarations belong here so that encryption pipelines load them"},{"line_number":94,"context_line":"# without loading the middleware that produces the metadata. A producer patch"},{"line_number":95,"context_line":"# adds its declaration to these tuples before it starts to write the field."},{"line_number":96,"context_line":"SENSITIVE_SYSMETA_NAMES \u003d ()"},{"line_number":97,"context_line":"SENSITIVE_SYSMETA_PREFIXES \u003d ()"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":"SENSITIVE_SYSMETA_ENV_KEY \u003d \u0027swift.crypto.decrypted_sensitive_sysmeta\u0027"},{"line_number":100,"context_line":""}],"source_content_type":"text/x-python","patch_set":1,"id":"8ba31923_9e8d0f7c","line":97,"range":{"start_line":93,"start_character":0,"end_line":97,"end_character":31},"updated":"2026-09-18 14:52:29.000000000","message":"I don\u0027t understand why this is necessary. it seems to be forwards looking support for hard-coded sensitive sysmeta names, but do we have a use-case for that?\n\nAlso, here and elsewhere the comments are referring to concepts that are unfamiliar to me and undefined e.g. \"producer patch\" and \"first-party declarations\".","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"493533f395104ee5c855d442454366268a7feffc","unresolved":false,"context_lines":[{"line_number":90,"context_line":"_sensitive_headers \u003d set()"},{"line_number":91,"context_line":"_sensitive_params \u003d set()"},{"line_number":92,"context_line":""},{"line_number":93,"context_line":"# First-party declarations belong here so that encryption pipelines load them"},{"line_number":94,"context_line":"# without loading the middleware that produces the metadata. A producer patch"},{"line_number":95,"context_line":"# adds its declaration to these tuples before it starts to write the field."},{"line_number":96,"context_line":"SENSITIVE_SYSMETA_NAMES \u003d ()"},{"line_number":97,"context_line":"SENSITIVE_SYSMETA_PREFIXES \u003d ()"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":"SENSITIVE_SYSMETA_ENV_KEY \u003d \u0027swift.crypto.decrypted_sensitive_sysmeta\u0027"},{"line_number":100,"context_line":""}],"source_content_type":"text/x-python","patch_set":1,"id":"b50d9c41_5e2b125a","line":97,"range":{"start_line":93,"start_character":0,"end_line":97,"end_character":31},"in_reply_to":"8ba31923_9e8d0f7c","updated":"2026-09-22 05:30:35.000000000","message":"removed and simplified.","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":96,"context_line":"SENSITIVE_SYSMETA_NAMES \u003d ()"},{"line_number":97,"context_line":"SENSITIVE_SYSMETA_PREFIXES \u003d ()"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":"SENSITIVE_SYSMETA_ENV_KEY \u003d \u0027swift.crypto.decrypted_sensitive_sysmeta\u0027"},{"line_number":100,"context_line":""},{"line_number":101,"context_line":"_sensitive_sysmeta_names \u003d set()"},{"line_number":102,"context_line":"_sensitive_sysmeta_prefixes \u003d set()"}],"source_content_type":"text/x-python","patch_set":1,"id":"ec5dece6_538d4c34","line":99,"range":{"start_line":99,"start_character":29,"end_line":99,"end_character":42},"updated":"2026-09-18 14:52:29.000000000","message":"this seems to belong in crypto middleware, not this module.\n\nBut this also seems to be supporting a second mechanism for indicating sensitive headers i.e. via an environ set in addition to the registry.py set. Why do we need two ways?","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"493533f395104ee5c855d442454366268a7feffc","unresolved":false,"context_lines":[{"line_number":96,"context_line":"SENSITIVE_SYSMETA_NAMES \u003d ()"},{"line_number":97,"context_line":"SENSITIVE_SYSMETA_PREFIXES \u003d ()"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":"SENSITIVE_SYSMETA_ENV_KEY \u003d \u0027swift.crypto.decrypted_sensitive_sysmeta\u0027"},{"line_number":100,"context_line":""},{"line_number":101,"context_line":"_sensitive_sysmeta_names \u003d set()"},{"line_number":102,"context_line":"_sensitive_sysmeta_prefixes \u003d set()"}],"source_content_type":"text/x-python","patch_set":1,"id":"89580233_4e7ae867","line":99,"range":{"start_line":99,"start_character":29,"end_line":99,"end_character":42},"in_reply_to":"ec5dece6_538d4c34","updated":"2026-09-22 05:30:35.000000000","message":"removed and simplified.","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":124,"context_line":"    return name"},{"line_number":125,"context_line":""},{"line_number":126,"context_line":""},{"line_number":127,"context_line":"def register_sensitive_sysmeta(*, names\u003d(), prefixes\u003d()):"},{"line_number":128,"context_line":"    \"\"\""},{"line_number":129,"context_line":"    Register object sysmeta names whose non-empty values need encryption."},{"line_number":130,"context_line":""}],"source_content_type":"text/x-python","patch_set":1,"id":"7a328512_2f349852","line":127,"range":{"start_line":127,"start_character":31,"end_line":127,"end_character":33},"updated":"2026-09-18 14:52:29.000000000","message":"is \u0027*\u0027 this necessary i.e. do we feel we need to force keyword args? it is not covered by tests","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":128,"context_line":"    \"\"\""},{"line_number":129,"context_line":"    Register object sysmeta names whose non-empty values need encryption."},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"    Names and prefixes are case-insensitive, fully qualified HTTP header"},{"line_number":132,"context_line":"    names. Registrations are additive and idempotent."},{"line_number":133,"context_line":"    \"\"\""},{"line_number":134,"context_line":"    if isinstance(names, str) or isinstance(prefixes, str):"},{"line_number":135,"context_line":"        raise TypeError"}],"source_content_type":"text/x-python","patch_set":1,"id":"9500e674_78e52c95","line":132,"range":{"start_line":131,"start_character":4,"end_line":132,"end_character":9},"updated":"2026-09-18 14:52:29.000000000","message":"whereas ``names`` and ``prefixes`` are *tuples*! That\u0027s quite confusing.","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":132,"context_line":"    names. Registrations are additive and idempotent."},{"line_number":133,"context_line":"    \"\"\""},{"line_number":134,"context_line":"    if isinstance(names, str) or isinstance(prefixes, str):"},{"line_number":135,"context_line":"        raise TypeError"},{"line_number":136,"context_line":"    names \u003d {_normalize_sensitive_sysmeta(name) for name in names}"},{"line_number":137,"context_line":"    prefixes \u003d {"},{"line_number":138,"context_line":"        _normalize_sensitive_sysmeta(prefix, is_prefix\u003dTrue)"}],"source_content_type":"text/x-python","patch_set":1,"id":"e3e67ecc_9542fdd8","line":135,"updated":"2026-09-18 14:52:29.000000000","message":"but dicts are ok ?!","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"de725c844bfa27e1dc58ea225a2e3088f15d49af","unresolved":true,"context_lines":[{"line_number":160,"context_line":""},{"line_number":161,"context_line":"def propagate_sensitive_sysmeta(source, destination, headers):"},{"line_number":162,"context_line":"    \"\"\""},{"line_number":163,"context_line":"    Copy the request-local annotation for headers that remain."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"    ``headers`` must be a Request or Response header mapping."},{"line_number":166,"context_line":"    \"\"\""}],"source_content_type":"text/x-python","patch_set":1,"id":"e2575250_0bbc1dd8","line":163,"updated":"2026-09-18 14:52:29.000000000","message":"there is a curious distinction between enforcing re-encryption of copied headers whilst tolerating non-encryption of new un-copied headers that might be added with a PUT.","commit_id":"b0aaf11b7e2dfd57965912c157018fa271c0f1a3"}]}
