)]}'
{"id":"openstack%2Fswift~942844","triplet_id":"openstack%2Fswift~master~If0f076d5ed4132c5e4b3299aaedede92f35841e3","project":"openstack/swift","branch":"master","topic":"p-systags-2","attention_set":{},"removed_from_attention_set":{"7847":{"account":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"last_update":"2025-02-28 17:58:51.000000000","reason":"\u003cGERRIT_ACCOUNT_7847\u003e replied on the change","reason_account":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"}}},"hashtags":[],"change_id":"If0f076d5ed4132c5e4b3299aaedede92f35841e3","subject":"encrypter: always send an override etag footer","status":"NEW","created":"2025-02-26 18:28:17.000000000","updated":"2025-02-28 17:58:51.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":2,"unresolved_comment_count":2,"has_review_started":true,"meta_rev_id":"b923cfd49edd646e7d20f5856a458f393eb901c6","_number":942844,"virtual_id_number":942844,"owner":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"actions":{},"labels":{"Verified":{"disliked":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},{"tag":"autogenerated:zuul:check","value":-1,"date":"2025-02-26 20:26:37.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":-1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-2,"max":2},"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"rejected":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"all":[{"value":-1,"date":"2025-02-28 17:58:51.000000000","permitted_voting_range":{"min":-1,"max":1},"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2025-02-26 20:26:37.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"c52c589ae71590f3a54ad2c364e18b1a4fc44ed0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"date":"2025-02-26 18:28:17.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"c5f231d965d92efede5bdd3c9f88443209130af4","author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"date":"2025-02-26 18:32:56.000000000","message":"Patch Set 1:\n\n(2 comments)","accounts_in_message":[],"_revision_number":1},{"id":"68ff896e16b35325bf6e9a595fe7e51d2b4e059d","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-02-26 20:26:37.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/7ed31f46777440deaf647b13afc383d6\n\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/94a76b1c2a1c481a81e6e727ba468d45 : SUCCESS in 8m 32s\n- grenade https://zuul.opendev.org/t/openstack/build/fc372a9fcde741fbbdcc6ca2066a560f : SUCCESS in 1h 00m 14s\n- grenade-skip-level-always https://zuul.opendev.org/t/openstack/build/4d597a6d8faf473fb2f56749eb509d22 : SUCCESS in 1h 04m 22s\n- tempest-integrated-object-storage https://zuul.opendev.org/t/openstack/build/7ef5eaadd752466b92354d6e29d2f4f7 : SUCCESS in 1h 40m 24s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/eaa27e1d3c2f4602bbcc53d24142721b : SUCCESS in 1h 51m 54s\n- swift-tox-func-py39-centos-9-stream-fips https://zuul.opendev.org/t/openstack/build/cb54d44863d64143b1408b360f73ea04 : SUCCESS in 11m 35s (non-voting)\n- swift-tox-func-encryption-py39-centos-9-stream-fips https://zuul.opendev.org/t/openstack/build/8d4f61cf3ff345eba3267a2705a3e043 : SUCCESS in 21m 36s (non-voting)\n- swift-tox-func-ec-py39-centos-9-stream-fips https://zuul.opendev.org/t/openstack/build/3552ebba4f5b481c8a3155a344d89e82 : SUCCESS in 19m 04s (non-voting)\n- swift-build-image https://zuul.opendev.org/t/openstack/build/8a1fbf8d8d4d4c58a959b401ea55c5d0 : SUCCESS in 6m 56s (non-voting)\n- swift-tox-py36 https://zuul.opendev.org/t/openstack/build/b7dc78b8d5184c7aa970af8a98176596 : SUCCESS in 18m 55s\n- swift-tox-py39 https://zuul.opendev.org/t/openstack/build/8739d6e5c6fa42e6bf30861e8f7291e2 : SUCCESS in 17m 05s\n- swift-tox-py312 https://zuul.opendev.org/t/openstack/build/fb87a2899db546f5a9e39ee4beca76ed : SUCCESS in 27m 04s\n- swift-tox-func-py312 https://zuul.opendev.org/t/openstack/build/920e0660db204e0d8acc7f3f6a7754b7 : SUCCESS in 17m 26s\n- swift-tox-func-encryption-py312 https://zuul.opendev.org/t/openstack/build/9b6d33de76a24c0c9b0f2b9fa5a9a694 : SUCCESS in 13m 40s\n- swift-tox-func-ec-py312 https://zuul.opendev.org/t/openstack/build/93825bf0e22c4d3b9fb6d931c41fc5ef : SUCCESS in 13m 32s\n- swift-func-cors https://zuul.opendev.org/t/openstack/build/eb176e7d933847c4908f9400ca89d6ec : SUCCESS in 6m 37s\n- swift-tox-func-s3api-ceph-s3tests-tempauth https://zuul.opendev.org/t/openstack/build/9c23a8614f5e4691899b003c96fa64a4 : SUCCESS in 14m 19s (non-voting)\n- swift-tox-func-s3api-tests-tempauth https://zuul.opendev.org/t/openstack/build/283c5799b1774ac4ba90fd05333e3598 : SUCCESS in 6m 25s\n- swift-probetests-centos-9-stream https://zuul.opendev.org/t/openstack/build/95481b5beb91490d98b5b20800960ecb : SUCCESS in 52m 10s\n- swift-dsvm-functional https://zuul.opendev.org/t/openstack/build/fc447bcfcc1e4cc88488c336811dfc9f : RETRY_LIMIT in 10m 50s\n- swift-dsvm-functional-ipv6 https://zuul.opendev.org/t/openstack/build/240d4156f4254631bf86d81f44d0f677 : RETRY_LIMIT in 22m 19s\n- swift-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/cfe1ddfbe7a44dd594e050446aa1e795 : SUCCESS in 20m 49s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e769771de73c4a678a9f0b6faa1b4291 : SUCCESS in 3m 51s\n- swift-multinode-rolling-upgrade https://zuul.opendev.org/t/openstack/build/a5ff689b16564a4d940da671ff558aaf : SUCCESS in 19m 16s\n- tempest-integrated-object-storage-ubuntu-jammy https://zuul.opendev.org/t/openstack/build/8a645a15386f480db3117877eb76b8e7 : SUCCESS in 59m 06s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/7f7bd2e67d544f4991f488da9f16be98 : SUCCESS in 1h 52m 03s","accounts_in_message":[],"_revision_number":1},{"id":"4fe715b2b58e618e25954d3ea1f1a56ddd086785","tag":"autogenerated:zuul:check-arm64","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2025-02-26 20:40:34.000000000","message":"Patch Set 1:\n\nBuild failed (ARM64 pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/04d541cc0a124ff4a194d9f8dddbae6d\n\n- swift-tox-py312-arm64 https://zuul.opendev.org/t/openstack/build/f8362de39a8b46a5b29445e89100fd4e : FAILURE in 2h 10m 03s","accounts_in_message":[],"_revision_number":1},{"id":"b923cfd49edd646e7d20f5856a458f393eb901c6","author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"date":"2025-02-28 17:58:51.000000000","message":"Patch Set 1: Workflow-1","accounts_in_message":[],"_revision_number":1}],"current_revision_number":1,"current_revision":"f3083d32616b6ceb7027691f1283bf38eae8c883","revisions":{"f3083d32616b6ceb7027691f1283bf38eae8c883":{"kind":"REWORK","_number":1,"created":"2025-02-26 18:28:17.000000000","uploader":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"ref":"refs/changes/44/942844/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/swift","ref":"refs/changes/44/942844/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/swift refs/changes/44/942844/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/swift refs/changes/44/942844/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/swift refs/changes/44/942844/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/swift refs/changes/44/942844/1"}}},"commit":{"parents":[{"commit":"044b9bcfe0adc4a173bd2264bfa58b0d6e22c647","subject":"Refactor and add some encrypter unit tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/swift/commit/044b9bcfe0adc4a173bd2264bfa58b0d6e22c647"}]}],"author":{"name":"Alistair Coles","email":"alistairncoles@gmail.com","date":"2025-02-26 12:59:32.000000000","tz":0},"committer":{"name":"Alistair Coles","email":"alistairncoles@gmail.com","date":"2025-02-26 15:18:06.000000000","tz":0},"subject":"encrypter: always send an override etag footer","message":"encrypter: always send an override etag footer\n\nPreviously, the encrypter middleware would often send an override-etag\nfooter [1] with an encrypted etag value, which ensured that the\ncontainer listing for the object had an encrypted version of the\nobject\u0027s etag.\n\nIf an override-etag footer was found then the encrypter would encrypt\nthis and replace it in the footers. Otherwise, if an override-etag\nheader was found then the encrypter would encrypt this and add it as\nan override-etag footer. Otherwise, the encrypter would encrypt the\nplaintext etag and add it as an override-etag footer.\n\nHowever, there were some cases when the encrypter did not send an\noverride-etag footer:\n\n1. No body was read and no override-etag was found in the headers or\n   footers from other middleware. An \u0027Etag\u0027 *is* added to the footers\n   with the value being the plaintext md5 hash of an empty string, and\n   this is considered sufficient.\n\n2. An override-etag footer is found whose value is the empty string.\n   This is left unchanged in the footers.\n\n3. An override-etag footer is not found, but an override-etag header\n   is found whose value is the empty string. This is not encrypted\n   and not added to the footers.\n\nCase (1) is reasonable.  The etag of an empty object is not encrypted\nbecause the object size reveals its content anyway. The override-etag\nfooter would have the same value as the Etag footer and is therefore\nunnecessary.\n\nCase (2) and (3) are less reasonable. An empty etag value in the\ncontainer listing is unexpected, and the encrypter has the plaintext\netag available, so it seems more reasonable that the encrypter should\nreplace an empty etag value with the encrypted plaintext etag.\n\nAll three cases make it harder to reason about the encrypter\u0027s\nbehaviour with respect to the override-etag footer.\n\nThis patch therefore modifies the encrypter middleware so that it\n*always* adds a non-empty override-etag footer. If the value of the\noverride-etag footer or header provided by other middlewares is the\nempty string (cases 2 and 3), then the encrypter now sets the\noverride-etag footer based on the plaintext etag. If no body has been\nread and there is no other override-etag value provided, the encrypter\nsets it to the md5 of an empty string.\n\n[1] \u0027X-Object-Sysmeta-Container-Update-Override-Etag\u0027\n\nChange-Id: If0f076d5ed4132c5e4b3299aaedede92f35841e3\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/swift/commit/f3083d32616b6ceb7027691f1283bf38eae8c883"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/swift/commit/f3083d32616b6ceb7027691f1283bf38eae8c883"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY","applied_by":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"}}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":["label:Workflow\u003dMIN"],"failing_atoms":["label:Workflow\u003dMAX"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
