)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"b005f6510305f25feaf6effe3f3f545a74a16a02","unresolved":true,"context_lines":[{"line_number":7,"context_line":"Support Reader Role for patch-strategy"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This commit adds support for reader role for sw-manager"},{"line_number":10,"context_line":"patch-strategy commands. The policy engine (policy.py) is an"},{"line_number":11,"context_line":"openstack based policy engine taken from sysinv, with minor"},{"line_number":12,"context_line":"adjustments. The behavior is that \"get\" commands like"},{"line_number":13,"context_line":"\"patch-strategy show\" requires reader role in the admin project."},{"line_number":14,"context_line":"Other commands requires admin role in the admin project. This commit"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"a347fc83_b82c04fa","line":11,"range":{"start_line":10,"start_character":43,"end_line":11,"end_character":47},"updated":"2022-08-19 19:36:31.000000000","message":"recommend migration to oslo_policy - please create a task for tracking (if not to be part of this review)","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"ee34f155e1a10d910cb8f59b7bcb88c1bfc79708","unresolved":false,"context_lines":[{"line_number":7,"context_line":"Support Reader Role for patch-strategy"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"This commit adds support for reader role for sw-manager"},{"line_number":10,"context_line":"patch-strategy commands. The policy engine (policy.py) is an"},{"line_number":11,"context_line":"openstack based policy engine taken from sysinv, with minor"},{"line_number":12,"context_line":"adjustments. The behavior is that \"get\" commands like"},{"line_number":13,"context_line":"\"patch-strategy show\" requires reader role in the admin project."},{"line_number":14,"context_line":"Other commands requires admin role in the admin project. This commit"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"f9871556_763921ac","line":11,"range":{"start_line":10,"start_character":43,"end_line":11,"end_character":47},"in_reply_to":"a347fc83_b82c04fa","updated":"2022-08-19 20:05:22.000000000","message":"Ack","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"b005f6510305f25feaf6effe3f3f545a74a16a02","unresolved":true,"context_lines":[{"line_number":17,"context_line":"Test Cases:"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"PASS: Existing admin user can execute all commands (patch-strategy"},{"line_number":20,"context_line":"      show, create, delete)"},{"line_number":21,"context_line":"PASS: New admin user with admin role in admin project behaves like"},{"line_number":22,"context_line":"      existing admin"},{"line_number":23,"context_line":"PASS: New user with reader role can only run patch-strategy show."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"4733654d_49a85cbf","line":20,"updated":"2022-08-19 19:36:31.000000000","message":"there\u0027s also \u0027apply\u0027 and \u0027abort\u0027","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"ee34f155e1a10d910cb8f59b7bcb88c1bfc79708","unresolved":false,"context_lines":[{"line_number":17,"context_line":"Test Cases:"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"PASS: Existing admin user can execute all commands (patch-strategy"},{"line_number":20,"context_line":"      show, create, delete)"},{"line_number":21,"context_line":"PASS: New admin user with admin role in admin project behaves like"},{"line_number":22,"context_line":"      existing admin"},{"line_number":23,"context_line":"PASS: New user with reader role can only run patch-strategy show."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"358090be_cb7c4e66","line":20,"in_reply_to":"4733654d_49a85cbf","updated":"2022-08-19 20:05:22.000000000","message":"Done","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"b005f6510305f25feaf6effe3f3f545a74a16a02","unresolved":true,"context_lines":[{"line_number":26,"context_line":"      or reader in the admin project is denied all access"},{"line_number":27,"context_line":"PASS: sw-manager kube-upgrade-strategy\u0027s old behavior is preserved."},{"line_number":28,"context_line":"      only admin can run commands, even get commands"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"Change-Id: I7edd0937ede1ebc315e2185f45ba113f6f6cc9d8"},{"line_number":31,"context_line":"Story: 2010149"},{"line_number":32,"context_line":"Task:  46015"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"b4092efd_6cfd82af","line":29,"updated":"2022-08-19 19:36:31.000000000","message":"should confirm integration with dcmanager patch-strategy as well","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"8e964e01312b937da7538cb0e02cb07f0a2c6fa6","unresolved":false,"context_lines":[{"line_number":26,"context_line":"      or reader in the admin project is denied all access"},{"line_number":27,"context_line":"PASS: sw-manager kube-upgrade-strategy\u0027s old behavior is preserved."},{"line_number":28,"context_line":"      only admin can run commands, even get commands"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"Change-Id: I7edd0937ede1ebc315e2185f45ba113f6f6cc9d8"},{"line_number":31,"context_line":"Story: 2010149"},{"line_number":32,"context_line":"Task:  46015"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"ae2930b7_d5bb63bd","line":29,"in_reply_to":"22d78435_08b1c549","updated":"2022-08-22 15:32:58.000000000","message":"oh and the current implementation allows additional users (reader role to run show commands) to run commands. The behavior with the existing admin account is not changed, so there should be no issue here","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"ee34f155e1a10d910cb8f59b7bcb88c1bfc79708","unresolved":false,"context_lines":[{"line_number":26,"context_line":"      or reader in the admin project is denied all access"},{"line_number":27,"context_line":"PASS: sw-manager kube-upgrade-strategy\u0027s old behavior is preserved."},{"line_number":28,"context_line":"      only admin can run commands, even get commands"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"Change-Id: I7edd0937ede1ebc315e2185f45ba113f6f6cc9d8"},{"line_number":31,"context_line":"Story: 2010149"},{"line_number":32,"context_line":"Task:  46015"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"22d78435_08b1c549","line":29,"in_reply_to":"b4092efd_6cfd82af","updated":"2022-08-19 20:05:22.000000000","message":"there is another task for dcmanager policy checks in the same story","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"b005f6510305f25feaf6effe3f3f545a74a16a02","unresolved":true,"context_lines":[{"line_number":29,"context_line":""},{"line_number":30,"context_line":"Change-Id: I7edd0937ede1ebc315e2185f45ba113f6f6cc9d8"},{"line_number":31,"context_line":"Story: 2010149"},{"line_number":32,"context_line":"Task:  46015"},{"line_number":33,"context_line":"Signed-off-by: Jerry Sun \u003cjerry.sun@windriver.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"c063588b_00565304","line":32,"range":{"start_line":32,"start_character":6,"end_line":32,"end_character":7},"updated":"2022-08-19 19:36:31.000000000","message":"extra space (prevents recognition as hyperlink)","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"ee34f155e1a10d910cb8f59b7bcb88c1bfc79708","unresolved":false,"context_lines":[{"line_number":29,"context_line":""},{"line_number":30,"context_line":"Change-Id: I7edd0937ede1ebc315e2185f45ba113f6f6cc9d8"},{"line_number":31,"context_line":"Story: 2010149"},{"line_number":32,"context_line":"Task:  46015"},{"line_number":33,"context_line":"Signed-off-by: Jerry Sun \u003cjerry.sun@windriver.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":9,"id":"cd972a9e_ed2e6e97","line":32,"range":{"start_line":32,"start_character":6,"end_line":32,"end_character":7},"in_reply_to":"c063588b_00565304","updated":"2022-08-19 20:05:22.000000000","message":"Done","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"dd0b41de7a8e5ea03302efa9c673d33eee22c171","unresolved":true,"context_lines":[{"line_number":26,"context_line":"      or reader in the admin project is denied all access"},{"line_number":27,"context_line":"PASS: sw-manager kube-upgrade-strategy\u0027s old behavior is preserved."},{"line_number":28,"context_line":"      only admin can run commands, even get commands"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"Change-Id: I7edd0937ede1ebc315e2185f45ba113f6f6cc9d8"},{"line_number":31,"context_line":"Story: 2010149"},{"line_number":32,"context_line":"Task: 46015"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":12,"id":"a8ca91c6_e0906b29","line":29,"updated":"2022-08-23 12:18:54.000000000","message":"testplan should be updated that this was tested with dcmanager user","commit_id":"545be7f11fbcb14e22c3806387f82660b84cc2af"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"9207f5d416c57387b2c3bc11430f288bd887d110","unresolved":false,"context_lines":[{"line_number":26,"context_line":"      or reader in the admin project is denied all access"},{"line_number":27,"context_line":"PASS: sw-manager kube-upgrade-strategy\u0027s old behavior is preserved."},{"line_number":28,"context_line":"      only admin can run commands, even get commands"},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"Change-Id: I7edd0937ede1ebc315e2185f45ba113f6f6cc9d8"},{"line_number":31,"context_line":"Story: 2010149"},{"line_number":32,"context_line":"Task: 46015"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":12,"id":"254b722e_c9bc3d19","line":29,"in_reply_to":"a8ca91c6_e0906b29","updated":"2022-08-24 19:53:46.000000000","message":"Done","commit_id":"545be7f11fbcb14e22c3806387f82660b84cc2af"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"f3be257c694104d10bb3a04d3189039a812db868","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"ac723213_524d9812","updated":"2022-08-15 12:21:55.000000000","message":"recheck","commit_id":"74dada2d5c8c308f34aae85e6f92b21dca746a90"},{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"029df2a3677bced3e4f374af7fc2592057b41dcf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"48b8c962_41cae58e","updated":"2022-08-15 21:14:21.000000000","message":"I am not seeing the same zuul setup failures\nhttps://review.opendev.org/c/starlingx/nfv/+/853175\n","commit_id":"655943d855755253dcb4152c65364aa5f8fb61f4"},{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"55b171321d76b8fb6a56fa62814717a96de55071","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"475ca709_d6584143","updated":"2022-08-15 21:15:08.000000000","message":"I will abandon my review, since the failure now is an actual pylint issue\n************* Module nfv_vim.api.acl.policy\nnfv-vim/nfv_vim/api/acl/policy.py:144:0: W1113: Keyword argument before variable positional arguments list in the definition of check function (keyword-arg-before-vararg)","commit_id":"655943d855755253dcb4152c65364aa5f8fb61f4"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"8154f549c1dd9f844f6537b7544d2e09bc5b2db6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"9b244666_dd9ae329","updated":"2022-08-17 13:33:14.000000000","message":"note that policy.py is a policy engine mostly from sysinv. I believe it originally came from openstack. It is not written from scratch.","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"95234ec5594a466241f633e7abd2206d1348dd00","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"f1cc42ed_70e8f30f","updated":"2022-08-17 17:59:48.000000000","message":"Jerry,  I think the code is good.\nCan you also try \u0027horizon\u0027 which calls into this API\nAlso, can you verify \u0027abort\u0027 (from a API perspective)\n","commit_id":"50b42320ca7db4129f9eb42bcc16a983c0ebace1"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"4f5542b219864f623dfd8490fa16fdd84e974562","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"b668259e_40e48ba4","in_reply_to":"f1cc42ed_70e8f30f","updated":"2022-08-17 18:37:36.000000000","message":"horizon works when i tried to create a patch strategy.\nabort works.","commit_id":"50b42320ca7db4129f9eb42bcc16a983c0ebace1"},{"author":{"_account_id":33487,"name":"João Victor Portal","display_name":"J. Portal","email":"Joao.VictorPortal@windriver.com","username":"jvportal"},"change_message_id":"d888bbcc9811d39f88ab0443b85f91dc1c547d04","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"b42dabd3_a76c4ebd","updated":"2022-08-18 00:32:08.000000000","message":"Example of rules that check both \"admin\" and \"services\" projects in sysinv: https://opendev.org/starlingx/config/src/commit/197fe530f53b8f467602cd5379469edb1071c391/sysinv/sysinv/sysinv/sysinv/api/policies/base.py .","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"a3e6759e3eb2493cc149c5f8d39bb7364f40c9c4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"052250e2_54cc5b8a","updated":"2022-08-17 18:41:30.000000000","message":"Oddly enough, this commit introduces oslo_log\nWe probably will convert all VIM logging to oslo_log in the future","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"00a3e67d97dc2b5789bb7491474e5b8673ea4b20","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"d67bab99_18ec5bb6","updated":"2022-08-22 21:01:17.000000000","message":"Jerry, am I right that changeset 12 only impacted the read-only  user, and not the authenticated ones (like horizon or the CLI use)","commit_id":"545be7f11fbcb14e22c3806387f82660b84cc2af"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"83257fec3ec6c53c509c2437b00c9082170f9e76","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":12,"id":"9ac962c0_cdfc8b67","in_reply_to":"d67bab99_18ec5bb6","updated":"2022-08-22 21:29:55.000000000","message":"it impacts all users.\nthe change is for any api class that i have not implemented an enforce_policy method for. Somewhere in the review, the rule name was changed, and I missed changing the reference here. Before patch 12, all other commands would be denied by a check on a rule that doesnt exist. After patch 12, it checks for admin role, which is the same behavior as before any of my changes, while also checking projects being admin and services. I tested patch 12 with the dcmanager user, the admin user, and a reader user that i created.","commit_id":"545be7f11fbcb14e22c3806387f82660b84cc2af"}],"nfv/nfv-vim/nfv_vim/api/acl/_application.py":[{"author":{"_account_id":33487,"name":"João Victor Portal","display_name":"J. Portal","email":"Joao.VictorPortal@windriver.com","username":"jvportal"},"change_message_id":"d888bbcc9811d39f88ab0443b85f91dc1c547d04","unresolved":true,"context_lines":[{"line_number":28,"context_line":"        policy_file_contents \u003d \"{}\""},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"        default_rule \u003d base.RuleDefault("},{"line_number":31,"context_line":"            name\u003d\u0027default\u0027,"},{"line_number":32,"context_line":"            check_str\u003d\u0027rule:admin\u0027,"},{"line_number":33,"context_line":"            description\u003d\"Base rule.\","},{"line_number":34,"context_line":"        )"}],"source_content_type":"text/x-python","patch_set":6,"id":"830a91dc_efa6f03d","line":31,"updated":"2022-08-18 00:32:08.000000000","message":"Probably this rule will not be used, but it would be better to enforce admin role in project \"admin\" or \"services\".","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"c5cbdbb1e1dcfbce7c31ff8685223bacdd638ca4","unresolved":false,"context_lines":[{"line_number":28,"context_line":"        policy_file_contents \u003d \"{}\""},{"line_number":29,"context_line":""},{"line_number":30,"context_line":"        default_rule \u003d base.RuleDefault("},{"line_number":31,"context_line":"            name\u003d\u0027default\u0027,"},{"line_number":32,"context_line":"            check_str\u003d\u0027rule:admin\u0027,"},{"line_number":33,"context_line":"            description\u003d\"Base rule.\","},{"line_number":34,"context_line":"        )"}],"source_content_type":"text/x-python","patch_set":6,"id":"7b829c59_5d0db5aa","line":31,"in_reply_to":"830a91dc_efa6f03d","updated":"2022-08-18 17:48:21.000000000","message":"Done","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"b005f6510305f25feaf6effe3f3f545a74a16a02","unresolved":true,"context_lines":[{"line_number":1,"context_line":"#"},{"line_number":2,"context_line":"# Copyright (c) 2016-2018 Wind River Systems, Inc."},{"line_number":3,"context_line":"#"},{"line_number":4,"context_line":"# SPDX-License-Identifier: Apache-2.0"},{"line_number":5,"context_line":"#"}],"source_content_type":"text/x-python","patch_set":9,"id":"ee123066_e5021156","line":2,"range":{"start_line":2,"start_character":21,"end_line":2,"end_character":26},"updated":"2022-08-19 19:36:31.000000000","message":"update copyright ... several files in review","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"ee34f155e1a10d910cb8f59b7bcb88c1bfc79708","unresolved":false,"context_lines":[{"line_number":1,"context_line":"#"},{"line_number":2,"context_line":"# Copyright (c) 2016-2018 Wind River Systems, Inc."},{"line_number":3,"context_line":"#"},{"line_number":4,"context_line":"# SPDX-License-Identifier: Apache-2.0"},{"line_number":5,"context_line":"#"}],"source_content_type":"text/x-python","patch_set":9,"id":"a265ba3f_9703e4db","line":2,"range":{"start_line":2,"start_character":21,"end_line":2,"end_character":26},"in_reply_to":"ee123066_e5021156","updated":"2022-08-19 20:05:22.000000000","message":"Done","commit_id":"43d6cbeb474648f2293a547cdf66b03607be3035"}],"nfv/nfv-vim/nfv_vim/api/acl/policies/base.py":[{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"8160b054b047dc9dec96b213688ecdb3ba775b2c","unresolved":true,"context_lines":[{"line_number":35,"context_line":"    RuleDefault("},{"line_number":36,"context_line":"        name\u003d\u0027admin\u0027,"},{"line_number":37,"context_line":"        check_str\u003d\u0027role:admin or role:administrator\u0027,"},{"line_number":38,"context_line":"        description\u003d\"Generic rule.\","},{"line_number":39,"context_line":"    ),"},{"line_number":40,"context_line":"    RuleDefault("},{"line_number":41,"context_line":"        name\u003d\u0027default\u0027,"}],"source_content_type":"text/x-python","patch_set":4,"id":"dbfd153a_55e0f0e9","line":38,"range":{"start_line":38,"start_character":20,"end_line":38,"end_character":35},"updated":"2022-08-17 13:19:25.000000000","message":"Do you think we should change this description.\nThey all say \u0027Generic rule\u0027","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"96d3764ed9d0ba215107e5fa13625944cfab474e","unresolved":false,"context_lines":[{"line_number":35,"context_line":"    RuleDefault("},{"line_number":36,"context_line":"        name\u003d\u0027admin\u0027,"},{"line_number":37,"context_line":"        check_str\u003d\u0027role:admin or role:administrator\u0027,"},{"line_number":38,"context_line":"        description\u003d\"Generic rule.\","},{"line_number":39,"context_line":"    ),"},{"line_number":40,"context_line":"    RuleDefault("},{"line_number":41,"context_line":"        name\u003d\u0027default\u0027,"}],"source_content_type":"text/x-python","patch_set":4,"id":"4f5f712b_6ae0291c","line":38,"range":{"start_line":38,"start_character":20,"end_line":38,"end_character":35},"in_reply_to":"dbfd153a_55e0f0e9","updated":"2022-08-17 17:56:39.000000000","message":"Done","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":33487,"name":"João Victor Portal","display_name":"J. Portal","email":"Joao.VictorPortal@windriver.com","username":"jvportal"},"change_message_id":"d888bbcc9811d39f88ab0443b85f91dc1c547d04","unresolved":true,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"base_rules \u003d ["},{"line_number":35,"context_line":"    RuleDefault("},{"line_number":36,"context_line":"        name\u003d\u0027admin\u0027,"},{"line_number":37,"context_line":"        check_str\u003d\u0027role:admin or role:administrator\u0027,"},{"line_number":38,"context_line":"        description\u003d\"Checks for admin role\","},{"line_number":39,"context_line":"    ),"}],"source_content_type":"text/x-python","patch_set":6,"id":"a77ba9d6_fca5abf1","line":36,"updated":"2022-08-18 00:32:08.000000000","message":"Rules \"admin\" and \"default\" can be deleted, as they are not used.","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"c5cbdbb1e1dcfbce7c31ff8685223bacdd638ca4","unresolved":false,"context_lines":[{"line_number":33,"context_line":""},{"line_number":34,"context_line":"base_rules \u003d ["},{"line_number":35,"context_line":"    RuleDefault("},{"line_number":36,"context_line":"        name\u003d\u0027admin\u0027,"},{"line_number":37,"context_line":"        check_str\u003d\u0027role:admin or role:administrator\u0027,"},{"line_number":38,"context_line":"        description\u003d\"Checks for admin role\","},{"line_number":39,"context_line":"    ),"}],"source_content_type":"text/x-python","patch_set":6,"id":"4a389b27_03dd221f","line":36,"in_reply_to":"a77ba9d6_fca5abf1","updated":"2022-08-18 17:48:21.000000000","message":"ill delete admin, but I would like to keep default. The policy engine looks like it uses default as a fallback, although I didn\u0027t have time to check exactly how. It doesn\u0027t hurt to keep it around.","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":33487,"name":"João Victor Portal","display_name":"J. Portal","email":"Joao.VictorPortal@windriver.com","username":"jvportal"},"change_message_id":"d888bbcc9811d39f88ab0443b85f91dc1c547d04","unresolved":true,"context_lines":[{"line_number":42,"context_line":"        check_str\u003d\u0027rule:admin\u0027,"},{"line_number":43,"context_line":"        description\u003d\"Default. Same behavior as before role checks\","},{"line_number":44,"context_line":"    ),"},{"line_number":45,"context_line":"    RuleDefault("},{"line_number":46,"context_line":"        name\u003d\u0027admin_in_project_admin\u0027,"},{"line_number":47,"context_line":"        check_str\u003d\u0027role:admin and project_name:admin\u0027,"},{"line_number":48,"context_line":"        description\u003d\"Generic rule for set-style requests\","}],"source_content_type":"text/x-python","patch_set":6,"id":"59563503_cc04ea4d","line":45,"updated":"2022-08-18 00:32:08.000000000","message":"Rules \"admin_in_project_admin\" and \"reader_in_project_admin\" should also check project services.","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"c5cbdbb1e1dcfbce7c31ff8685223bacdd638ca4","unresolved":false,"context_lines":[{"line_number":42,"context_line":"        check_str\u003d\u0027rule:admin\u0027,"},{"line_number":43,"context_line":"        description\u003d\"Default. Same behavior as before role checks\","},{"line_number":44,"context_line":"    ),"},{"line_number":45,"context_line":"    RuleDefault("},{"line_number":46,"context_line":"        name\u003d\u0027admin_in_project_admin\u0027,"},{"line_number":47,"context_line":"        check_str\u003d\u0027role:admin and project_name:admin\u0027,"},{"line_number":48,"context_line":"        description\u003d\"Generic rule for set-style requests\","}],"source_content_type":"text/x-python","patch_set":6,"id":"b90bdb0a_48bb5e44","line":45,"in_reply_to":"59563503_cc04ea4d","updated":"2022-08-18 17:48:21.000000000","message":"Done","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"}],"nfv/nfv-vim/nfv_vim/api/acl/policies/sw_update_strategy_policy.py":[{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"8160b054b047dc9dec96b213688ecdb3ba775b2c","unresolved":true,"context_lines":[{"line_number":19,"context_line":"POLICY_ROOT \u003d \u0027nfv_api:sw_update_strategy:%s\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"service_parameter_rules \u003d ["},{"line_number":23,"context_line":"    base.RuleDefault("},{"line_number":24,"context_line":"        name\u003dPOLICY_ROOT % \u0027add\u0027,"},{"line_number":25,"context_line":"        check_str\u003dbase.ADMIN_IN_PROJECT_ADMIN,"}],"source_content_type":"text/x-python","patch_set":4,"id":"ad060ae6_650b4207","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":23},"updated":"2022-08-17 13:19:25.000000000","message":"I think you want a different variable name here.\nservice_parameter was for those API rules in  sysinv","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"96d3764ed9d0ba215107e5fa13625944cfab474e","unresolved":false,"context_lines":[{"line_number":19,"context_line":"POLICY_ROOT \u003d \u0027nfv_api:sw_update_strategy:%s\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"service_parameter_rules \u003d ["},{"line_number":23,"context_line":"    base.RuleDefault("},{"line_number":24,"context_line":"        name\u003dPOLICY_ROOT % \u0027add\u0027,"},{"line_number":25,"context_line":"        check_str\u003dbase.ADMIN_IN_PROJECT_ADMIN,"}],"source_content_type":"text/x-python","patch_set":4,"id":"a2f12c28_a040d713","line":22,"range":{"start_line":22,"start_character":0,"end_line":22,"end_character":23},"in_reply_to":"ad060ae6_650b4207","updated":"2022-08-17 17:56:39.000000000","message":"Done","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"8160b054b047dc9dec96b213688ecdb3ba775b2c","unresolved":true,"context_lines":[{"line_number":49,"context_line":""},{"line_number":50,"context_line":""},{"line_number":51,"context_line":"def list_rules():"},{"line_number":52,"context_line":"    return service_parameter_rules"}],"source_content_type":"text/x-python","patch_set":4,"id":"dc89ab41_e96eb6bd","line":52,"updated":"2022-08-17 13:19:25.000000000","message":"ditto","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"96d3764ed9d0ba215107e5fa13625944cfab474e","unresolved":false,"context_lines":[{"line_number":49,"context_line":""},{"line_number":50,"context_line":""},{"line_number":51,"context_line":"def list_rules():"},{"line_number":52,"context_line":"    return service_parameter_rules"}],"source_content_type":"text/x-python","patch_set":4,"id":"9707da21_c1a55a84","line":52,"in_reply_to":"dc89ab41_e96eb6bd","updated":"2022-08-17 17:56:39.000000000","message":"Done","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":33487,"name":"João Victor Portal","display_name":"J. Portal","email":"Joao.VictorPortal@windriver.com","username":"jvportal"},"change_message_id":"d888bbcc9811d39f88ab0443b85f91dc1c547d04","unresolved":true,"context_lines":[{"line_number":19,"context_line":"POLICY_ROOT \u003d \u0027nfv_api:sw_update_strategy:%s\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"sw_update_strategy_rules \u003d ["},{"line_number":23,"context_line":"    base.RuleDefault("},{"line_number":24,"context_line":"        name\u003dPOLICY_ROOT % \u0027add\u0027,"},{"line_number":25,"context_line":"        check_str\u003dbase.ADMIN_IN_PROJECT_ADMIN,"}],"source_content_type":"text/x-python","patch_set":6,"id":"8adf23ae_aec18b71","line":22,"updated":"2022-08-18 00:32:08.000000000","message":"Change the check_str of the rules below to verify also project \"services\".","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"c5cbdbb1e1dcfbce7c31ff8685223bacdd638ca4","unresolved":false,"context_lines":[{"line_number":19,"context_line":"POLICY_ROOT \u003d \u0027nfv_api:sw_update_strategy:%s\u0027"},{"line_number":20,"context_line":""},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"sw_update_strategy_rules \u003d ["},{"line_number":23,"context_line":"    base.RuleDefault("},{"line_number":24,"context_line":"        name\u003dPOLICY_ROOT % \u0027add\u0027,"},{"line_number":25,"context_line":"        check_str\u003dbase.ADMIN_IN_PROJECT_ADMIN,"}],"source_content_type":"text/x-python","patch_set":6,"id":"478334e3_e31a2c82","line":22,"in_reply_to":"8adf23ae_aec18b71","updated":"2022-08-18 17:48:21.000000000","message":"Done","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"}],"nfv/nfv-vim/nfv_vim/api/acl/policy.py":[{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"8160b054b047dc9dec96b213688ecdb3ba775b2c","unresolved":true,"context_lines":[{"line_number":13,"context_line":"#    License for the specific language governing permissions and limitations"},{"line_number":14,"context_line":"#    under the License."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"\"\"\""},{"line_number":17,"context_line":"Common Policy Engine Implementation"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"Policies can be expressed in one of two forms: A list of lists, or a"}],"source_content_type":"text/x-python","patch_set":4,"id":"46ba8aeb_4db6a5c9","line":16,"updated":"2022-08-17 13:19:25.000000000","message":"I am fine with this, but keep in mind that this is similar to the old openstack.common.policy  which other components like keystone graduated away from around the \u0027juno\u0027 release.\nIt would be nice to move to oslo_policy,  maybe as a followup/cleanup story","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"96d3764ed9d0ba215107e5fa13625944cfab474e","unresolved":false,"context_lines":[{"line_number":13,"context_line":"#    License for the specific language governing permissions and limitations"},{"line_number":14,"context_line":"#    under the License."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"\"\"\""},{"line_number":17,"context_line":"Common Policy Engine Implementation"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"Policies can be expressed in one of two forms: A list of lists, or a"}],"source_content_type":"text/x-python","patch_set":4,"id":"90622f4c_3960ded2","line":16,"in_reply_to":"46ba8aeb_4db6a5c9","updated":"2022-08-17 17:56:39.000000000","message":"I have tried the oslo_policy based implementation when trying to get this to work. Unfortunately, other components like Sysinv already have an oslo setup, so it is easier to integrate. oslo_policy needs to set up things like oslo config, which vim was not that happy to cooperate with. When trying to get oslo_policy to work, vim didnt like the acl oslo policy or a separate one i tried to set up, which is why i stuck to the one here. I can open a followup story if you like.","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"},{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"95234ec5594a466241f633e7abd2206d1348dd00","unresolved":false,"context_lines":[{"line_number":13,"context_line":"#    License for the specific language governing permissions and limitations"},{"line_number":14,"context_line":"#    under the License."},{"line_number":15,"context_line":""},{"line_number":16,"context_line":"\"\"\""},{"line_number":17,"context_line":"Common Policy Engine Implementation"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"Policies can be expressed in one of two forms: A list of lists, or a"}],"source_content_type":"text/x-python","patch_set":4,"id":"99a13d83_506b2d86","line":16,"in_reply_to":"90622f4c_3960ded2","updated":"2022-08-17 17:59:48.000000000","message":"agreed.  I think this way is the quickest/cleanest/safest at this point.\nconverting nfv to oslo is more than just oslo_policy.\nI had to modify a ton of files to get sw-patch(debian) to use oslo_policy","commit_id":"6a1695ae524222d11cbb302fdcc739993ada47a6"}],"nfv/nfv-vim/nfv_vim/api/controllers/v1/orchestration/sw_update/_sw_update_strategy.py":[{"author":{"_account_id":33487,"name":"João Victor Portal","display_name":"J. Portal","email":"Joao.VictorPortal@windriver.com","username":"jvportal"},"change_message_id":"d888bbcc9811d39f88ab0443b85f91dc1c547d04","unresolved":true,"context_lines":[{"line_number":598,"context_line":"        DLOG.error(\"Unexpected result received, result\u003d%s.\" % response.result)"},{"line_number":599,"context_line":"        return pecan.abort(httplib.INTERNAL_SERVER_ERROR)"},{"line_number":600,"context_line":""},{"line_number":601,"context_line":"    def enforce_policy(self, method_name, auth_context_dict):"},{"line_number":602,"context_line":"        \"\"\"Check policy rules for each action of this controller.\"\"\""},{"line_number":603,"context_line":"        if method_name \u003d\u003d \"apply\":"},{"line_number":604,"context_line":"            policy.check(sw_update_strategy_policy.POLICY_ROOT % \"apply\", {},"}],"source_content_type":"text/x-python","patch_set":6,"id":"4e41cf36_3ce60d2a","line":601,"updated":"2022-08-18 00:32:08.000000000","message":"I found the method \"post\" that add/create patch strategy is found inside this class (SwPatchStrategyAPI) and the methods \"delete\", \"get_all\" and \"get_one\" in the parent class (SwUpdateStrategyAPI). Where can be found the methods \"apply\" and \"patch\"?","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"c5cbdbb1e1dcfbce7c31ff8685223bacdd638ca4","unresolved":false,"context_lines":[{"line_number":598,"context_line":"        DLOG.error(\"Unexpected result received, result\u003d%s.\" % response.result)"},{"line_number":599,"context_line":"        return pecan.abort(httplib.INTERNAL_SERVER_ERROR)"},{"line_number":600,"context_line":""},{"line_number":601,"context_line":"    def enforce_policy(self, method_name, auth_context_dict):"},{"line_number":602,"context_line":"        \"\"\"Check policy rules for each action of this controller.\"\"\""},{"line_number":603,"context_line":"        if method_name \u003d\u003d \"apply\":"},{"line_number":604,"context_line":"            policy.check(sw_update_strategy_policy.POLICY_ROOT % \"apply\", {},"}],"source_content_type":"text/x-python","patch_set":6,"id":"88cfcfac_ebf18da6","line":601,"in_reply_to":"4e41cf36_3ce60d2a","updated":"2022-08-18 17:48:21.000000000","message":"If you mean apply as in \"sw-manager patch-strategy apply\", then that uses \"post\". If you mean the rules checking method_name apply and patch, I am not aware of anything that uses them right now, but I chose to keep them because it is something that can potentially come in, and i wanted a rule ready in case it does.","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":33487,"name":"João Victor Portal","display_name":"J. Portal","email":"Joao.VictorPortal@windriver.com","username":"jvportal"},"change_message_id":"d888bbcc9811d39f88ab0443b85f91dc1c547d04","unresolved":true,"context_lines":[{"line_number":616,"context_line":"            policy.check(sw_update_strategy_policy.POLICY_ROOT % \"add\", {},"},{"line_number":617,"context_line":"                           auth_context_dict, exc\u003dpolicy.PolicyForbidden)"},{"line_number":618,"context_line":"        else:"},{"line_number":619,"context_line":"            policy.check(\u0027admin\u0027, {}, auth_context_dict)"},{"line_number":620,"context_line":""},{"line_number":621,"context_line":""},{"line_number":622,"context_line":"class SwUpgradeStrategyAPI(SwUpdateStrategyAPI):"}],"source_content_type":"text/x-python","patch_set":6,"id":"3302ddd8_7c697c9e","line":619,"range":{"start_line":619,"start_character":12,"end_line":619,"end_character":56},"updated":"2022-08-18 00:32:08.000000000","message":"I think it would be better here to throw an exception to force new actions implemented in this controller to be added as a case above.","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"c5cbdbb1e1dcfbce7c31ff8685223bacdd638ca4","unresolved":false,"context_lines":[{"line_number":616,"context_line":"            policy.check(sw_update_strategy_policy.POLICY_ROOT % \"add\", {},"},{"line_number":617,"context_line":"                           auth_context_dict, exc\u003dpolicy.PolicyForbidden)"},{"line_number":618,"context_line":"        else:"},{"line_number":619,"context_line":"            policy.check(\u0027admin\u0027, {}, auth_context_dict)"},{"line_number":620,"context_line":""},{"line_number":621,"context_line":""},{"line_number":622,"context_line":"class SwUpgradeStrategyAPI(SwUpdateStrategyAPI):"}],"source_content_type":"text/x-python","patch_set":6,"id":"95077094_769c40b1","line":619,"range":{"start_line":619,"start_character":12,"end_line":619,"end_character":56},"in_reply_to":"3302ddd8_7c697c9e","updated":"2022-08-18 17:48:21.000000000","message":"I want to keep it as a policy check in this commit. If we change it to an exception, then all the other sw-manager commands will throw an exception due to not having implemented any policy checks. When i do policy checks for all sw-manager commands, i would like to revisit throwing an exception here.","commit_id":"7f4c3290c97150920b1c247cc66ef6dc171cc4fa"}],"nfv/nfv-vim/nfv_vim/api/openstack/_objects.py":[{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"95caf6f2f9bf7e054d839ad075dd438e01762377","unresolved":true,"context_lines":[{"line_number":1,"context_line":"#"},{"line_number":2,"context_line":"# Copyright (c) 2015-2022 Wind River Systems, Inc."},{"line_number":3,"context_line":"#"},{"line_number":4,"context_line":"# SPDX-License-Identifier: Apache-2.0"},{"line_number":5,"context_line":"#"}],"source_content_type":"text/x-python","patch_set":10,"id":"80249ebf_505681af","line":2,"range":{"start_line":2,"start_character":16,"end_line":2,"end_character":25},"updated":"2022-08-19 21:07:55.000000000","message":"this should be 2015-2019, 2021-2022 to reflect those years the file was updated","commit_id":"71b62e07ab384cc86e167e05d50c5797aeadb3fc"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"00320d7b854adeaefd2d733fdb8707683c29868e","unresolved":false,"context_lines":[{"line_number":1,"context_line":"#"},{"line_number":2,"context_line":"# Copyright (c) 2015-2022 Wind River Systems, Inc."},{"line_number":3,"context_line":"#"},{"line_number":4,"context_line":"# SPDX-License-Identifier: Apache-2.0"},{"line_number":5,"context_line":"#"}],"source_content_type":"text/x-python","patch_set":10,"id":"5fa47212_79e5d4d7","line":2,"range":{"start_line":2,"start_character":16,"end_line":2,"end_character":25},"in_reply_to":"80249ebf_505681af","updated":"2022-08-22 13:13:13.000000000","message":"Done","commit_id":"71b62e07ab384cc86e167e05d50c5797aeadb3fc"}],"nfv/test-requirements.txt":[{"author":{"_account_id":15435,"name":"Al Bailey","email":"albailey1974@gmail.com","username":"albailey"},"change_message_id":"a9ed7f656e76dec0ee19286324aebc6a4ba0f243","unresolved":true,"context_lines":[{"line_number":11,"context_line":"pylint\u003c2.1.0;python_version\u003c\"3.0\" # GPLv2"},{"line_number":12,"context_line":"pylint\u003c2.4.0;python_version\u003e\u003d\"3.0\" # GPLv2"},{"line_number":13,"context_line":"testtools\u003e\u003d2.2.0 # MIT"},{"line_number":14,"context_line":"oslo.log # Apache-2.0"}],"source_content_type":"text/plain","patch_set":3,"id":"69e6550f_80d0528e","line":14,"range":{"start_line":14,"start_character":0,"end_line":14,"end_character":21},"updated":"2022-08-15 20:41:43.000000000","message":"Normally, we would put this in the requirements.txt file but apparently we dont have one in this repo.\nInstead we would add this to  tox.ini around line 49 (deps section)","commit_id":"655943d855755253dcb4152c65364aa5f8fb61f4"},{"author":{"_account_id":21776,"name":"Jerry Sun","email":"jerry.sun@windriver.com","username":"jerrysun"},"change_message_id":"4f5542b219864f623dfd8490fa16fdd84e974562","unresolved":false,"context_lines":[{"line_number":11,"context_line":"pylint\u003c2.1.0;python_version\u003c\"3.0\" # GPLv2"},{"line_number":12,"context_line":"pylint\u003c2.4.0;python_version\u003e\u003d\"3.0\" # GPLv2"},{"line_number":13,"context_line":"testtools\u003e\u003d2.2.0 # MIT"},{"line_number":14,"context_line":"oslo.log # Apache-2.0"}],"source_content_type":"text/plain","patch_set":3,"id":"ab05e643_32d82170","line":14,"range":{"start_line":14,"start_character":0,"end_line":14,"end_character":21},"in_reply_to":"69e6550f_80d0528e","updated":"2022-08-17 18:37:36.000000000","message":"Done","commit_id":"655943d855755253dcb4152c65364aa5f8fb61f4"}]}
