)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"61077a3fb1f96d61883b08587939f360dd1e05ee","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"44001310_e2f13a51","updated":"2022-11-23 14:16:01.000000000","message":"going to add a tht param to wire this setting into the script and kolla","commit_id":"c63588a30e5f9353c3e6924c9e1219e5522a644e"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"a9d34da669e597390caa0d353543ab9c2e7a3b19","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"57285f94_1b0dda49","updated":"2022-11-29 15:09:12.000000000","message":"ci tempest failures look real","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"7e979e98cc9894b835a80b356d0adce74563ddac","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"fda37e66_6ef06c2b","updated":"2022-11-29 15:11:54.000000000","message":"https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_2d6/865425/3/check/tripleo-ci-centos-9-standalone/2d672bc/logs/undercloud/var/log/containers/libvirt/index.html :\n\nundercloud/var/log/containers/libvirt/virtqemud.log:2022-11-28 15:14:52.531+0000: 108898: error : virStorageSourceReportBrokenChain:1231 : Cannot access storage file \u0027/var/lib/nova/instances/38be058c-6175-47bb-ab1b-fe68b29b3d77/disk\u0027 (as uid:107, gid:107): Permission denied\n","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"c20c180441149c06f6b34a61d435a0f7e152e697","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"9a8d3f20_b03768a3","updated":"2022-12-08 15:43:25.000000000","message":"thanks you for taking a thorough review Oliver!","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"dbaabec6ae23f880a58976169f194a7ff361b5f1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"5c1249c9_dafccb4d","updated":"2023-01-25 14:37:05.000000000","message":"https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_8b6/865425/6/check/tripleo-ci-centos-9-standalone/8b6c678/logs/undercloud/home/zuul/standalone_deploy.log\ntime\u003d\"2023-01-23T18:39:43Z\" level\u003dinfo msg\u003d\"Received shutdown.Stop(), terminating!\" PID\u003d105633\n+ command -v python3\n+ python3 /container-config-scripts/nova_statedir_ownership.py\nTraceback (most recent call last):\n  File \"/container-config-scripts/nova_statedir_ownership.py\", line 330, in \u003cmodule\u003e\n    NovaStatedirOwnershipManager(\n  File \"/container-config-scripts/nova_statedir_ownership.py\", line 305, in run\n    pathinfo.chmod(self.target_dir_mode)\n  File \"/container-config-scripts/nova_statedir_ownership.py\", line 149, in chmod\n    os.chmod(self.path, mode)\nTypeError: an integer is required (got type str)","commit_id":"ebeacbc43cae0c3bffb7835f161c809ea89f7b16"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"703ac9e793092b17c2908375de135700ec687933","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"4e4bdd13_639a935f","updated":"2023-01-26 12:02:09.000000000","message":"While we need futher tweaking of nova/qemu groups and umask to go with,\nthe script itself now worked as expected:\n\nhttps://3293bb8ceefb436e626f-9f324d44a8b8b4bcaa74562bb2dc2591.ssl.cf1.rackcdn.com/865425/8/check/tripleo-ci-centos-9-standalone/c7191b5/logs/undercloud/var/log/containers/stdouts/nova_statedir_owner.log\n\n2023-01-25T16:55:21.510101961+00:00 stdout F INFO:nova_statedir:Applying nova statedir ownership\n2023-01-25T16:55:21.510172704+00:00 stdout F INFO:nova_statedir:Target ownership for /var/lib/nova: 42436:42436, mode: 0o750\n2023-01-25T16:55:21.510285100+00:00 stdout F INFO:nova_statedir:Checking uid: 0 gid: 0 mode: 0o755 path: /var/lib/nova/\n2023-01-25T16:55:21.510601853+00:00 stdout F INFO:nova_statedir:Changed ownership of /var/lib/nova from 0:0 to 42436:42436\n2023-01-25T16:55:21.510744766+00:00 stdout F INFO:nova_statedir:Changed permissions of /var/lib/nova from 0o755 to 0o750\n2023-01-25T16:55:21.510814520+00:00 stdout F INFO:nova_statedir:Setting selinux context of /var/lib/nova to system_u:object_r:container_file_t:s0\n2023-01-25T16:55:21.510993083+00:00 stdout F INFO:nova_statedir:Checking uid: 0 gid: 0 mode: 0o750 path: /var/lib/nova/instances/\n2023-01-25T16:55:21.511099097+00:00 stdout F INFO:nova_statedir:Changed ownership of /var/lib/nova/instances from 0:0 to 42436:42436\n2023-01-25T16:55:21.511139076+00:00 stdout F INFO:nova_statedir:Permissions of /var/lib/nova/instances already 0o750\n2023-01-25T16:55:21.511219409+00:00 stdout F INFO:nova_statedir:Setting selinux context of /var/lib/nova/instances to system_u:object_r:container_file_t:s0\n2023-01-25T16:55:21.511313192+00:00 stdout F INFO:nova_statedir:Nova statedir ownership complete","commit_id":"e556aaf69e40cb31fb6550fdad68215b5c1cb6f7"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"02620b557e8c47f32fc2c17e6fba98243e463e30","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"ba02d4ff_d769b339","updated":"2023-01-26 12:13:08.000000000","message":"the permission denied issue remains to be addressed:\n\n2023-01-25 17:12:22.057 2 ERROR nova.compute.manager [instance: 8ed89df6-507f-4522-a79e-f228891ead34] libvirt.libvirtError: internal error: process exited while connecting to monitor: 2023-01-25T17:12:19.950950Z qemu-kvm: Unable to read /var/lib/libvirt/qemu/domain-12-instance-0000000c/master-key.aes: Failed to open file “/var/lib/libvirt/qemu/domain-12-instance-0000000c/master-key.aes”: Permission deniedne req-3eeca4f5-3e8f-4e60-b1c7-7f4caf377934","commit_id":"e556aaf69e40cb31fb6550fdad68215b5c1cb6f7"}],"container_config_scripts/nova_statedir_ownership.py":[{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"5e756668f4818d1e9c7ee8d5b480e4f97937b3de","unresolved":true,"context_lines":[{"line_number":90,"context_line":"            try:"},{"line_number":91,"context_line":"                os.chown(self.path, target_uid, target_gid)"},{"line_number":92,"context_line":"                self._update()"},{"line_number":93,"context_line":"                LOG.info(\u0027Changed ownership of %s from %d:%d to %d:%d\u0027,"},{"line_number":94,"context_line":"                         self.path,"},{"line_number":95,"context_line":"                         src_uid,"},{"line_number":96,"context_line":"                         src_gid,"}],"source_content_type":"text/x-python","patch_set":3,"id":"d44fa771_9a0bcea5","line":93,"range":{"start_line":93,"start_character":50,"end_line":93,"end_character":69},"updated":"2022-12-07 00:10:28.000000000","message":"I think it\u0027s better to log before the chown so we can see what we were trying to do if/when it fails, or include all of the details when logging the exception after it fails","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"845310423cf3d007356af58041ff906efd265f32","unresolved":false,"context_lines":[{"line_number":90,"context_line":"            try:"},{"line_number":91,"context_line":"                os.chown(self.path, target_uid, target_gid)"},{"line_number":92,"context_line":"                self._update()"},{"line_number":93,"context_line":"                LOG.info(\u0027Changed ownership of %s from %d:%d to %d:%d\u0027,"},{"line_number":94,"context_line":"                         self.path,"},{"line_number":95,"context_line":"                         src_uid,"},{"line_number":96,"context_line":"                         src_gid,"}],"source_content_type":"text/x-python","patch_set":3,"id":"4fba154d_63e92350","line":93,"range":{"start_line":93,"start_character":50,"end_line":93,"end_character":69},"in_reply_to":"a4fd30bb_cc0de370","updated":"2023-01-23 15:30:22.000000000","message":"now this looks done for real!","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"ad9b0513ffa84aa9b4e60512b0fde28bc2f6f113","unresolved":false,"context_lines":[{"line_number":90,"context_line":"            try:"},{"line_number":91,"context_line":"                os.chown(self.path, target_uid, target_gid)"},{"line_number":92,"context_line":"                self._update()"},{"line_number":93,"context_line":"                LOG.info(\u0027Changed ownership of %s from %d:%d to %d:%d\u0027,"},{"line_number":94,"context_line":"                         self.path,"},{"line_number":95,"context_line":"                         src_uid,"},{"line_number":96,"context_line":"                         src_gid,"}],"source_content_type":"text/x-python","patch_set":3,"id":"d668a18b_ebecf48f","line":93,"range":{"start_line":93,"start_character":50,"end_line":93,"end_character":69},"in_reply_to":"d44fa771_9a0bcea5","updated":"2023-01-23 13:40:51.000000000","message":"Done","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"cf6fd8f9f2a06b7b968992e852fdc98f1403e5d9","unresolved":false,"context_lines":[{"line_number":90,"context_line":"            try:"},{"line_number":91,"context_line":"                os.chown(self.path, target_uid, target_gid)"},{"line_number":92,"context_line":"                self._update()"},{"line_number":93,"context_line":"                LOG.info(\u0027Changed ownership of %s from %d:%d to %d:%d\u0027,"},{"line_number":94,"context_line":"                         self.path,"},{"line_number":95,"context_line":"                         src_uid,"},{"line_number":96,"context_line":"                         src_gid,"}],"source_content_type":"text/x-python","patch_set":3,"id":"a4fd30bb_cc0de370","line":93,"range":{"start_line":93,"start_character":50,"end_line":93,"end_character":69},"in_reply_to":"d668a18b_ebecf48f","updated":"2023-01-23 13:46:38.000000000","message":"actually, no, I think I lost this change","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"5e756668f4818d1e9c7ee8d5b480e4f97937b3de","unresolved":true,"context_lines":[{"line_number":130,"context_line":"    def chmod(self, mode):"},{"line_number":131,"context_line":"        target_mode \u003d None"},{"line_number":132,"context_line":"        src_mode \u003d self.mode"},{"line_number":133,"context_line":"        if src_mode !\u003d mode:"},{"line_number":134,"context_line":"            target_mode \u003d mode"},{"line_number":135,"context_line":"        if target_mode is not None:"},{"line_number":136,"context_line":"            try:"}],"source_content_type":"text/x-python","patch_set":3,"id":"f86b867b_12eb60dd","line":133,"range":{"start_line":133,"start_character":11,"end_line":133,"end_character":27},"updated":"2022-12-07 00:10:28.000000000","message":"Need to convert do the octal/str conversion before comparing here....\nHowever I think it would be better to get rid of all the conversions and just use int everywhere. Convert to/from octal base at the external I/O boundaries e.g convert from str when getting the env var and convert to str when printing/logging, similar to how unicode is handled","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"845310423cf3d007356af58041ff906efd265f32","unresolved":false,"context_lines":[{"line_number":130,"context_line":"    def chmod(self, mode):"},{"line_number":131,"context_line":"        target_mode \u003d None"},{"line_number":132,"context_line":"        src_mode \u003d self.mode"},{"line_number":133,"context_line":"        if src_mode !\u003d mode:"},{"line_number":134,"context_line":"            target_mode \u003d mode"},{"line_number":135,"context_line":"        if target_mode is not None:"},{"line_number":136,"context_line":"            try:"}],"source_content_type":"text/x-python","patch_set":3,"id":"7120edeb_e3033548","line":133,"range":{"start_line":133,"start_character":11,"end_line":133,"end_character":27},"in_reply_to":"91c83be8_69e489a1","updated":"2023-01-23 15:30:22.000000000","message":"Done","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"ad9b0513ffa84aa9b4e60512b0fde28bc2f6f113","unresolved":true,"context_lines":[{"line_number":130,"context_line":"    def chmod(self, mode):"},{"line_number":131,"context_line":"        target_mode \u003d None"},{"line_number":132,"context_line":"        src_mode \u003d self.mode"},{"line_number":133,"context_line":"        if src_mode !\u003d mode:"},{"line_number":134,"context_line":"            target_mode \u003d mode"},{"line_number":135,"context_line":"        if target_mode is not None:"},{"line_number":136,"context_line":"            try:"}],"source_content_type":"text/x-python","patch_set":3,"id":"91c83be8_69e489a1","line":133,"range":{"start_line":133,"start_character":11,"end_line":133,"end_character":27},"in_reply_to":"f86b867b_12eb60dd","updated":"2023-01-23 13:40:51.000000000","message":"no need, and the code and tests cover that, both can take only octal values. But there is indeed a tecase where pathinfo.chmod(0o641) and this needs to be covered. nice catch!\n\nI wish we could just convert at input and output, but st_mode handling complicates things. I\u0027ll try though","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"5e756668f4818d1e9c7ee8d5b480e4f97937b3de","unresolved":true,"context_lines":[{"line_number":211,"context_line":"                LOG.warn(\"Unexpected umask %s is not in \""},{"line_number":212,"context_line":"                         \"allowed umask %s: using default %s\","},{"line_number":213,"context_line":"                         umask, ALLOWED_UMASK, DEFAULT_UMASK)"},{"line_number":214,"context_line":"                self.umask \u003d DEFAULT_UMASK"},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"        self.target_dir_mode \u003d self._get_umasked_mode(\u00270o777\u0027)"},{"line_number":217,"context_line":"        self.target_file_mode \u003d self._get_umasked_mode(\u00270o666\u0027)"}],"source_content_type":"text/x-python","patch_set":3,"id":"dcc990cb_3dd8f8f8","line":214,"range":{"start_line":214,"start_character":16,"end_line":214,"end_character":42},"updated":"2022-12-07 00:10:28.000000000","message":"Should fail hard if the input is not valid.\n\nBut could perform the input validation/defaulting/conversion outside of this when reading the env var. Would make this a lot cleaner, can just be:\n\n    def __init__(self, statedir, umask ...):\n        self.statedir \u003d statedir\n        self.nova_user \u003d nova_user\n        self.umask \u003d umask","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"cf6fd8f9f2a06b7b968992e852fdc98f1403e5d9","unresolved":false,"context_lines":[{"line_number":211,"context_line":"                LOG.warn(\"Unexpected umask %s is not in \""},{"line_number":212,"context_line":"                         \"allowed umask %s: using default %s\","},{"line_number":213,"context_line":"                         umask, ALLOWED_UMASK, DEFAULT_UMASK)"},{"line_number":214,"context_line":"                self.umask \u003d DEFAULT_UMASK"},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"        self.target_dir_mode \u003d self._get_umasked_mode(\u00270o777\u0027)"},{"line_number":217,"context_line":"        self.target_file_mode \u003d self._get_umasked_mode(\u00270o666\u0027)"}],"source_content_type":"text/x-python","patch_set":3,"id":"f070b290_41e570b5","line":214,"range":{"start_line":214,"start_character":16,"end_line":214,"end_character":42},"in_reply_to":"1fa144ff_ec703d0d","updated":"2023-01-23 13:46:38.000000000","message":"actually, no, I think I lost this change","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"ad9b0513ffa84aa9b4e60512b0fde28bc2f6f113","unresolved":false,"context_lines":[{"line_number":211,"context_line":"                LOG.warn(\"Unexpected umask %s is not in \""},{"line_number":212,"context_line":"                         \"allowed umask %s: using default %s\","},{"line_number":213,"context_line":"                         umask, ALLOWED_UMASK, DEFAULT_UMASK)"},{"line_number":214,"context_line":"                self.umask \u003d DEFAULT_UMASK"},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"        self.target_dir_mode \u003d self._get_umasked_mode(\u00270o777\u0027)"},{"line_number":217,"context_line":"        self.target_file_mode \u003d self._get_umasked_mode(\u00270o666\u0027)"}],"source_content_type":"text/x-python","patch_set":3,"id":"1fa144ff_ec703d0d","line":214,"range":{"start_line":214,"start_character":16,"end_line":214,"end_character":42},"in_reply_to":"dcc990cb_3dd8f8f8","updated":"2023-01-23 13:40:51.000000000","message":"Done","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"845310423cf3d007356af58041ff906efd265f32","unresolved":false,"context_lines":[{"line_number":211,"context_line":"                LOG.warn(\"Unexpected umask %s is not in \""},{"line_number":212,"context_line":"                         \"allowed umask %s: using default %s\","},{"line_number":213,"context_line":"                         umask, ALLOWED_UMASK, DEFAULT_UMASK)"},{"line_number":214,"context_line":"                self.umask \u003d DEFAULT_UMASK"},{"line_number":215,"context_line":""},{"line_number":216,"context_line":"        self.target_dir_mode \u003d self._get_umasked_mode(\u00270o777\u0027)"},{"line_number":217,"context_line":"        self.target_file_mode \u003d self._get_umasked_mode(\u00270o666\u0027)"}],"source_content_type":"text/x-python","patch_set":3,"id":"0c4984af_c2d05684","line":214,"range":{"start_line":214,"start_character":16,"end_line":214,"end_character":42},"in_reply_to":"f070b290_41e570b5","updated":"2023-01-23 15:30:22.000000000","message":"now this looks done for real!","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"5e756668f4818d1e9c7ee8d5b480e4f97937b3de","unresolved":true,"context_lines":[{"line_number":245,"context_line":"        except Exception:"},{"line_number":246,"context_line":"            LOG.warn(\"Failed to apply umask %s for permissions %s\","},{"line_number":247,"context_line":"                     self.umask, pattern)"},{"line_number":248,"context_line":"            result \u003d \u00270o000\u0027"},{"line_number":249,"context_line":"        return result"},{"line_number":250,"context_line":""},{"line_number":251,"context_line":"    def _walk(self, top, chcon\u003dTrue):"},{"line_number":252,"context_line":"        for f in os.listdir(top):"}],"source_content_type":"text/x-python","patch_set":3,"id":"b100f1c8_4af52413","line":249,"range":{"start_line":248,"start_character":12,"end_line":249,"end_character":21},"updated":"2022-12-07 00:10:28.000000000","message":"0o000 is technically a valid mode. Better to use None to signal no value. Can just return on L244. Use `if \u003cvar\u003e is None:` in the caller","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"845310423cf3d007356af58041ff906efd265f32","unresolved":false,"context_lines":[{"line_number":245,"context_line":"        except Exception:"},{"line_number":246,"context_line":"            LOG.warn(\"Failed to apply umask %s for permissions %s\","},{"line_number":247,"context_line":"                     self.umask, pattern)"},{"line_number":248,"context_line":"            result \u003d \u00270o000\u0027"},{"line_number":249,"context_line":"        return result"},{"line_number":250,"context_line":""},{"line_number":251,"context_line":"    def _walk(self, top, chcon\u003dTrue):"},{"line_number":252,"context_line":"        for f in os.listdir(top):"}],"source_content_type":"text/x-python","patch_set":3,"id":"9f41374f_bb4ac3d5","line":249,"range":{"start_line":248,"start_character":12,"end_line":249,"end_character":21},"in_reply_to":"8e86172b_23166ef1","updated":"2023-01-23 15:30:22.000000000","message":"now this looks done for real!","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"ad9b0513ffa84aa9b4e60512b0fde28bc2f6f113","unresolved":false,"context_lines":[{"line_number":245,"context_line":"        except Exception:"},{"line_number":246,"context_line":"            LOG.warn(\"Failed to apply umask %s for permissions %s\","},{"line_number":247,"context_line":"                     self.umask, pattern)"},{"line_number":248,"context_line":"            result \u003d \u00270o000\u0027"},{"line_number":249,"context_line":"        return result"},{"line_number":250,"context_line":""},{"line_number":251,"context_line":"    def _walk(self, top, chcon\u003dTrue):"},{"line_number":252,"context_line":"        for f in os.listdir(top):"}],"source_content_type":"text/x-python","patch_set":3,"id":"c081d515_6bdd23fb","line":249,"range":{"start_line":248,"start_character":12,"end_line":249,"end_character":21},"in_reply_to":"b100f1c8_4af52413","updated":"2023-01-23 13:40:51.000000000","message":"Done","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"cf6fd8f9f2a06b7b968992e852fdc98f1403e5d9","unresolved":false,"context_lines":[{"line_number":245,"context_line":"        except Exception:"},{"line_number":246,"context_line":"            LOG.warn(\"Failed to apply umask %s for permissions %s\","},{"line_number":247,"context_line":"                     self.umask, pattern)"},{"line_number":248,"context_line":"            result \u003d \u00270o000\u0027"},{"line_number":249,"context_line":"        return result"},{"line_number":250,"context_line":""},{"line_number":251,"context_line":"    def _walk(self, top, chcon\u003dTrue):"},{"line_number":252,"context_line":"        for f in os.listdir(top):"}],"source_content_type":"text/x-python","patch_set":3,"id":"8e86172b_23166ef1","line":249,"range":{"start_line":248,"start_character":12,"end_line":249,"end_character":21},"in_reply_to":"c081d515_6bdd23fb","updated":"2023-01-23 13:46:38.000000000","message":"actually, no, I think I lost this change","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"}],"deployment/nova/nova-compute-container-puppet.yaml":[{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"5e756668f4818d1e9c7ee8d5b480e4f97937b3de","unresolved":true,"context_lines":[{"line_number":1375,"context_line":"                list_join:"},{"line_number":1376,"context_line":"                  - \u0027:\u0027"},{"line_number":1377,"context_line":"                  - {get_param: NovaStatedirOwnershipSkip}"},{"line_number":1378,"context_line":"              TRIPLEO_KOLLA_UMASK: {get_param: NovaLibvirtUmask}"},{"line_number":1379,"context_line":"        step_5:"},{"line_number":1380,"context_line":"          map_merge:"},{"line_number":1381,"context_line":"            - nova_compute:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"c8e21688_8bbf7863","line":1378,"range":{"start_line":1378,"start_character":14,"end_line":1378,"end_character":33},"updated":"2022-12-07 00:10:28.000000000","message":"I would name this NOVA_STATEDIR_UMASK","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"5c78650e740f478bbdebc56bab33e756c899fbc9","unresolved":false,"context_lines":[{"line_number":1375,"context_line":"                list_join:"},{"line_number":1376,"context_line":"                  - \u0027:\u0027"},{"line_number":1377,"context_line":"                  - {get_param: NovaStatedirOwnershipSkip}"},{"line_number":1378,"context_line":"              TRIPLEO_KOLLA_UMASK: {get_param: NovaLibvirtUmask}"},{"line_number":1379,"context_line":"        step_5:"},{"line_number":1380,"context_line":"          map_merge:"},{"line_number":1381,"context_line":"            - nova_compute:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"598f063e_02dcb485","line":1378,"range":{"start_line":1378,"start_character":14,"end_line":1378,"end_character":33},"in_reply_to":"42f6c2f2_64546ca3","updated":"2023-01-23 15:41:11.000000000","message":"Done","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"215491831f06cdbcb8e2cf2f188559af31cc7cb3","unresolved":false,"context_lines":[{"line_number":1375,"context_line":"                list_join:"},{"line_number":1376,"context_line":"                  - \u0027:\u0027"},{"line_number":1377,"context_line":"                  - {get_param: NovaStatedirOwnershipSkip}"},{"line_number":1378,"context_line":"              TRIPLEO_KOLLA_UMASK: {get_param: NovaLibvirtUmask}"},{"line_number":1379,"context_line":"        step_5:"},{"line_number":1380,"context_line":"          map_merge:"},{"line_number":1381,"context_line":"            - nova_compute:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"f5d57a24_6fccc697","line":1378,"range":{"start_line":1378,"start_character":14,"end_line":1378,"end_character":33},"in_reply_to":"598f063e_02dcb485","updated":"2023-01-25 14:27:14.000000000","message":"I was confused by these names, sorry.\nSo we shoud stick to a generic tripleo env var TRIPLEO_KOLLA_UMASK, as that provides a common interface for tripleo-kolla containers to run with a given umask.","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"d5ca1db3b552e725bc6475fcc142290e8e795e16","unresolved":false,"context_lines":[{"line_number":1375,"context_line":"                list_join:"},{"line_number":1376,"context_line":"                  - \u0027:\u0027"},{"line_number":1377,"context_line":"                  - {get_param: NovaStatedirOwnershipSkip}"},{"line_number":1378,"context_line":"              TRIPLEO_KOLLA_UMASK: {get_param: NovaLibvirtUmask}"},{"line_number":1379,"context_line":"        step_5:"},{"line_number":1380,"context_line":"          map_merge:"},{"line_number":1381,"context_line":"            - nova_compute:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"cea7e5e3_62e8ed73","line":1378,"range":{"start_line":1378,"start_character":14,"end_line":1378,"end_character":33},"in_reply_to":"c8e21688_8bbf7863","updated":"2022-12-08 15:44:30.000000000","message":"...naming things 😊\nwe already have this value in use, if you don\u0027t mind","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"e79e2ac5b304bdee10d08a418e318954b259c7b4","unresolved":true,"context_lines":[{"line_number":1375,"context_line":"                list_join:"},{"line_number":1376,"context_line":"                  - \u0027:\u0027"},{"line_number":1377,"context_line":"                  - {get_param: NovaStatedirOwnershipSkip}"},{"line_number":1378,"context_line":"              TRIPLEO_KOLLA_UMASK: {get_param: NovaLibvirtUmask}"},{"line_number":1379,"context_line":"        step_5:"},{"line_number":1380,"context_line":"          map_merge:"},{"line_number":1381,"context_line":"            - nova_compute:"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"42f6c2f2_64546ca3","line":1378,"range":{"start_line":1378,"start_character":14,"end_line":1378,"end_character":33},"in_reply_to":"cea7e5e3_62e8ed73","updated":"2022-12-08 18:07:34.000000000","message":"ack, but in the other case it\u0027s used by the kolla start script. In this case it\u0027s used the the nova statedir script. The kolla start script will not run so setting an env var for that script could cause confusion","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"593c46e28519e4bbdbcbd4e336cb20361f1dc5bb","unresolved":true,"context_lines":[{"line_number":1463,"context_line":"              - { \u0027path\u0027: /var/lib/nova, \u0027setype\u0027: container_file_t }"},{"line_number":1464,"context_line":"              - { \u0027path\u0027: /var/lib/_nova_secontext, \u0027setype\u0027: container_file_t}"},{"line_number":1465,"context_line":"              - { \u0027path\u0027: /var/lib/nova/instances, \u0027setype\u0027: container_file_t, \u0027mode\u0027: \u00270750\u0027 }"},{"line_number":1466,"context_line":"              - { \u0027path\u0027: /var/lib/libvirt, \u0027setype\u0027: container_file_t, \u0027mode\u0027: \u00270750\u0027 }"},{"line_number":1467,"context_line":"          - name: Mount Nova NFS Share"},{"line_number":1468,"context_line":"            vars:"},{"line_number":1469,"context_line":"              nfs_backend_enable: {get_attr: [RoleParametersValue, value, nfs_backend_enable]}"}],"source_content_type":"text/x-yaml","patch_set":8,"id":"e6796223_e1e41f81","line":1466,"updated":"2023-01-26 12:16:33.000000000","message":"@Oliver, this should be crux, I\u0027ll try 0770","commit_id":"e556aaf69e40cb31fb6550fdad68215b5c1cb6f7"}],"deployment/nova/nova-modular-libvirt-container-puppet.yaml":[{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"5e756668f4818d1e9c7ee8d5b480e4f97937b3de","unresolved":true,"context_lines":[{"line_number":30,"context_line":"    description: \u003e"},{"line_number":31,"context_line":"      Controls how dynamic permissions applied for libvirt-managed VM-disk"},{"line_number":32,"context_line":"      files and static permissions configuration for /var/lib/nova/* paths"},{"line_number":33,"context_line":"    default: \u00270027\u0027"},{"line_number":34,"context_line":"  ServiceData:"},{"line_number":35,"context_line":"    default: {}"},{"line_number":36,"context_line":"    description: Dictionary packing service data"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"b2e7a813_fa031946","line":33,"range":{"start_line":33,"start_character":14,"end_line":33,"end_character":18},"updated":"2022-12-07 00:10:28.000000000","message":"Should that be 0007?","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"e79e2ac5b304bdee10d08a418e318954b259c7b4","unresolved":true,"context_lines":[{"line_number":30,"context_line":"    description: \u003e"},{"line_number":31,"context_line":"      Controls how dynamic permissions applied for libvirt-managed VM-disk"},{"line_number":32,"context_line":"      files and static permissions configuration for /var/lib/nova/* paths"},{"line_number":33,"context_line":"    default: \u00270027\u0027"},{"line_number":34,"context_line":"  ServiceData:"},{"line_number":35,"context_line":"    default: {}"},{"line_number":36,"context_line":"    description: Dictionary packing service data"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"a44f7d47_c9eed045","line":33,"range":{"start_line":33,"start_character":14,"end_line":33,"end_character":18},"in_reply_to":"30482b27_d07580de","updated":"2022-12-08 18:07:34.000000000","message":"ack, IIRC NovaLibvirtUmask overrides that though so I think https://review.opendev.org/c/openstack/tripleo-heat-templates/+/866814 (which failed) will have used 0007","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"67bb27d7d857dfc7f8c1f871ce4ea9b30db7bceb","unresolved":false,"context_lines":[{"line_number":30,"context_line":"    description: \u003e"},{"line_number":31,"context_line":"      Controls how dynamic permissions applied for libvirt-managed VM-disk"},{"line_number":32,"context_line":"      files and static permissions configuration for /var/lib/nova/* paths"},{"line_number":33,"context_line":"    default: \u00270027\u0027"},{"line_number":34,"context_line":"  ServiceData:"},{"line_number":35,"context_line":"    default: {}"},{"line_number":36,"context_line":"    description: Dictionary packing service data"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"30482b27_d07580de","line":33,"range":{"start_line":33,"start_character":14,"end_line":33,"end_character":18},"in_reply_to":"70e4853e_47f9430e","updated":"2022-12-08 15:42:50.000000000","message":"just to note, this patch extends another patch, and we\u0027ve already applied 0027 as default umask for libvirt dynamic permissions base calculations","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"d202084449c8ecb53b8ea42444fce5327322bd8e","unresolved":false,"context_lines":[{"line_number":30,"context_line":"    description: \u003e"},{"line_number":31,"context_line":"      Controls how dynamic permissions applied for libvirt-managed VM-disk"},{"line_number":32,"context_line":"      files and static permissions configuration for /var/lib/nova/* paths"},{"line_number":33,"context_line":"    default: \u00270027\u0027"},{"line_number":34,"context_line":"  ServiceData:"},{"line_number":35,"context_line":"    default: {}"},{"line_number":36,"context_line":"    description: Dictionary packing service data"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"6feff6cf_24c7c862","line":33,"range":{"start_line":33,"start_character":14,"end_line":33,"end_character":18},"in_reply_to":"a44f7d47_c9eed045","updated":"2023-01-26 12:25:10.000000000","message":"let\u0027s try w/o changing permissions of /var/lib/libvirt (it\u0027s out of nova/tripleo control scope anyway)","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"},{"author":{"_account_id":23811,"name":"Oliver Walsh","email":"owalsh@redhat.com","username":"owalsh"},"change_message_id":"55045823b61ce8a56c69cee701022c1567bd0f2e","unresolved":true,"context_lines":[{"line_number":30,"context_line":"    description: \u003e"},{"line_number":31,"context_line":"      Controls how dynamic permissions applied for libvirt-managed VM-disk"},{"line_number":32,"context_line":"      files and static permissions configuration for /var/lib/nova/* paths"},{"line_number":33,"context_line":"    default: \u00270027\u0027"},{"line_number":34,"context_line":"  ServiceData:"},{"line_number":35,"context_line":"    default: {}"},{"line_number":36,"context_line":"    description: Dictionary packing service data"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"70e4853e_47f9430e","line":33,"range":{"start_line":33,"start_character":14,"end_line":33,"end_character":18},"in_reply_to":"b2e7a813_fa031946","updated":"2022-12-07 11:43:52.000000000","message":"virtqemud still has permission denied with 0007. I don\u0027t have an env to check right now but IIRC the VM disk is owned by root:root. It probably needs to be root:qemu.","commit_id":"d1d9f155446626dcfcfa91c0104d0efcba02e3d6"}]}
