)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"d643e47333ef7c9ccbda071a84ee22b2a25f01b7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"dcac08d0_9c40c6f0","updated":"2025-05-22 10:03:22.000000000","message":"The failing CI jobs don\u0027t seem to be related to the patch itself:\n- openstack-meta-content-provider: opened OSPCIX-871.\n- whitebox-neutron-tempest-plugin-ovn-single-thread: failed tests match the latest periodic run.","commit_id":"31826b671b6f81764501f1b716d8e467938d1bb1"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"8684a263fb8218d8a48c62ff92f531d7659db4d1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"191f2f74_0f14b7d1","updated":"2025-05-21 08:46:15.000000000","message":"recheck openstack-meta-content-provider","commit_id":"31826b671b6f81764501f1b716d8e467938d1bb1"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"03a79b01167b216509543f508deee50db5dba1ab","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"70c8075a_b415979b","updated":"2025-05-21 12:25:54.000000000","message":"recheck unrelated failures","commit_id":"31826b671b6f81764501f1b716d8e467938d1bb1"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"bad201d6080109557f3f2373084762b3a395e29d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"d93f100c_6f9cf106","updated":"2025-05-22 09:17:16.000000000","message":"recheck unrelated failures","commit_id":"31826b671b6f81764501f1b716d8e467938d1bb1"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"14df4a25a1577faf4cc7078bfd18ab74e9813dab","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"fbf0422b_1ecd9616","updated":"2025-05-21 10:03:04.000000000","message":"recheck unrelated failures","commit_id":"31826b671b6f81764501f1b716d8e467938d1bb1"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"1bd6b76f020bbf3030114ff42eaae6dcef799c69","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"568740ec_66eefd93","updated":"2025-05-26 15:19:40.000000000","message":"recheck whitebox-neutron-tempest-plugin-ovn-single-thread","commit_id":"f244998c6a72cd113b5b0a679074f40746335160"},{"author":{"_account_id":33341,"name":"Maor Blaustein","email":"mblue@redhat.com","username":"blue"},"change_message_id":"b07b3a61f40c870023b7c9649185cd8c7de9ece9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"20f41c0b_35ac2466","updated":"2025-06-03 14:09:39.000000000","message":"@rxiao@redhat.com As for the devstack `test_metadata_base_and_burst_rate_limiting` failure - since this patch didn\u0027t change that test related code, this is another issue, so lets verify and work with different job instead of devstack for now.\n\nThis other issue can be handled separately later.","commit_id":"233c5d65fc8c0fa686b5da1bc14c3c9a1244c370"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"717c034d0eaeceb14c8dd9b97b2a9018a0b40f47","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"8a15a40f_e1edf550","updated":"2025-05-27 09:48:58.000000000","message":"recheck test_metadata_rate_limiting","commit_id":"233c5d65fc8c0fa686b5da1bc14c3c9a1244c370"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"bd133b476557f53771439ac4099bd60fcf851e3f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"65611bda_b4d36570","updated":"2025-06-05 08:39:40.000000000","message":"Hi, this is tested in d/s: https://gitlab.cee.redhat.com/ci-framework/ci-framework-testproject/-/merge_requests/1316","commit_id":"d0fb874a6c8497f30618b91aa4b1677932aa86a6"},{"author":{"_account_id":29088,"name":"Candido Campos Rivas","email":"ccamposr@redhat.com","username":"ccamposr"},"change_message_id":"da659608849ae1c5b8480c8a875de3b4a2deefbb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"7e29c539_cefa5377","updated":"2025-06-10 09:24:12.000000000","message":"I have pending to merge this more complete change, i\n\nhttps://review.opendev.org/c/x/whitebox-neutron-tempest-plugin/+/944616/16/whitebox_neutron_tempest_plugin/tests/scenario/test_metadata_rate_limiting.py","commit_id":"d0fb874a6c8497f30618b91aa4b1677932aa86a6"},{"author":{"_account_id":29088,"name":"Candido Campos Rivas","email":"ccamposr@redhat.com","username":"ccamposr"},"change_message_id":"d79140a906e2fe8eba2334e841fcccb67f149dcb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"88b07743_28f21fb4","updated":"2025-06-10 09:21:37.000000000","message":"https://review.opendev.org/c/x/whitebox-neutron-tempest-plugin/+/944616/16/whitebox_neutron_tempest_plugin/tests/scenario/test_metadata_rate_limiting.py","commit_id":"d0fb874a6c8497f30618b91aa4b1677932aa86a6"}],"whitebox_neutron_tempest_plugin/tests/scenario/test_metadata_rate_limiting.py":[{"author":{"_account_id":33341,"name":"Maor Blaustein","email":"mblue@redhat.com","username":"blue"},"change_message_id":"e1e964513c3bee5df9d8b67e10123a42c82ba460","unresolved":true,"context_lines":[{"line_number":306,"context_line":""},{"line_number":307,"context_line":"        # Test burst limit"},{"line_number":308,"context_line":"        self._test_limiting(burst_query_rate_limit, vm_a, exceed\u003dFalse)"},{"line_number":309,"context_line":"        self._test_limiting(1, vm_b, exceed\u003dFalse)"},{"line_number":310,"context_line":"        self._test_limiting(1, vm_c, exceed\u003dFalse)"},{"line_number":311,"context_line":""},{"line_number":312,"context_line":"        # Wait for burst window to reset, but still be under the base window"},{"line_number":313,"context_line":"        sleep(burst_window_duration * 2)"},{"line_number":314,"context_line":""}],"source_content_type":"text/x-python","patch_set":2,"id":"3b8d4846_196c8ddd","line":311,"range":{"start_line":309,"start_character":0,"end_line":311,"end_character":0},"updated":"2025-05-22 17:26:52.000000000","message":"Thank you.\n\nWhen looked on the specs for feature [1], I was thinking in ticket to attempt the DoS mentioned there, so we do need to `exceed\u003dTrue` and check that limits apply per VM (ip) as specs suggested it should, so numbers like 10 per VM to get more specific accurate results.\n\nFor simplicity it is possible to test in different method only the base longer duration.\n\nMaybe even try one VM on external network like `vm_c` to have more difference covered in test, so 2 VMs in same internal network, and 1 VM on external, all checking their individual limits.\n\nIf 2 VMs are on internal network and NATed, not sure if metadata will limit them on different counter, interesting to check it all :) \n\n[1] https://specs.openstack.org/openstack/neutron-specs/specs/2023.1/metadata-rate-limit.html\n\n```\nPlatform administrators would benefit from being able to rate-limit requests handled by metadata in order to protect other OpenStack components from DoS.\n```\n\n```\nRequests should be rate-limited by source IP\n```","commit_id":"ec18c0c74bbacc2adff1a164aaec799619209cc6"},{"author":{"_account_id":33341,"name":"Maor Blaustein","email":"mblue@redhat.com","username":"blue"},"change_message_id":"b07b3a61f40c870023b7c9649185cd8c7de9ece9","unresolved":false,"context_lines":[{"line_number":306,"context_line":""},{"line_number":307,"context_line":"        # Test burst limit"},{"line_number":308,"context_line":"        self._test_limiting(burst_query_rate_limit, vm_a, exceed\u003dFalse)"},{"line_number":309,"context_line":"        self._test_limiting(1, vm_b, exceed\u003dFalse)"},{"line_number":310,"context_line":"        self._test_limiting(1, vm_c, exceed\u003dFalse)"},{"line_number":311,"context_line":""},{"line_number":312,"context_line":"        # Wait for burst window to reset, but still be under the base window"},{"line_number":313,"context_line":"        sleep(burst_window_duration * 2)"},{"line_number":314,"context_line":""}],"source_content_type":"text/x-python","patch_set":2,"id":"174dbc2c_71eefcf8","line":311,"range":{"start_line":309,"start_character":0,"end_line":311,"end_character":0},"in_reply_to":"36ccdf04_43891276","updated":"2025-06-03 14:09:39.000000000","message":"No problem.\nLooked into it a bit, so seems that requests aren\u0027t NATed with internal tenant VM sending requests for metadata service but there is still use of different way of HTTP headers, IMO still good to check internal and external as suggested for more extensive test coverage, generally more ways that could be handled differently to catch issues.\n\nI see that code was added so I will mark this as resolved.","commit_id":"ec18c0c74bbacc2adff1a164aaec799619209cc6"},{"author":{"_account_id":37280,"name":"Renjing Xiao","display_name":"Renjing Xiao","email":"rxiao@redhat.com","username":"rxiao"},"change_message_id":"72e28296459ad982fdbac6e55351e2df89743ad7","unresolved":true,"context_lines":[{"line_number":306,"context_line":""},{"line_number":307,"context_line":"        # Test burst limit"},{"line_number":308,"context_line":"        self._test_limiting(burst_query_rate_limit, vm_a, exceed\u003dFalse)"},{"line_number":309,"context_line":"        self._test_limiting(1, vm_b, exceed\u003dFalse)"},{"line_number":310,"context_line":"        self._test_limiting(1, vm_c, exceed\u003dFalse)"},{"line_number":311,"context_line":""},{"line_number":312,"context_line":"        # Wait for burst window to reset, but still be under the base window"},{"line_number":313,"context_line":"        sleep(burst_window_duration * 2)"},{"line_number":314,"context_line":""}],"source_content_type":"text/x-python","patch_set":2,"id":"36ccdf04_43891276","line":311,"range":{"start_line":309,"start_character":0,"end_line":311,"end_character":0},"in_reply_to":"3b8d4846_196c8ddd","updated":"2025-05-26 11:55:06.000000000","message":"Thank you so much for the review. Would the two VMs created by `_create_vms_by_topology` be considered NATed if they are on the same internal network and share the same router? or were you suggesting to cover another scenario beyond this?","commit_id":"ec18c0c74bbacc2adff1a164aaec799619209cc6"},{"author":{"_account_id":33341,"name":"Maor Blaustein","email":"mblue@redhat.com","username":"blue"},"change_message_id":"b07b3a61f40c870023b7c9649185cd8c7de9ece9","unresolved":true,"context_lines":[{"line_number":316,"context_line":"        Steps:"},{"line_number":317,"context_line":"        1. Create two servers on internal network, and another on external."},{"line_number":318,"context_line":"        2. Send a series of requests to the metadata service from each server."},{"line_number":319,"context_line":"        4. Check the responses to verify the rate limiting behavior."},{"line_number":320,"context_line":"        \"\"\""},{"line_number":321,"context_line":""},{"line_number":322,"context_line":"        LOG.debug(\"Test the metadata service\u0027s rate limiting per VM\")"}],"source_content_type":"text/x-python","patch_set":5,"id":"3ebb59f3_c05b8e4d","line":319,"range":{"start_line":319,"start_character":8,"end_line":319,"end_character":10},"updated":"2025-06-03 14:09:39.000000000","message":"nit: number 3 skipped","commit_id":"233c5d65fc8c0fa686b5da1bc14c3c9a1244c370"}]}
