)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":2,"name":"Monty Taylor","email":"mordred@inaugust.com","username":"mordred"},"change_message_id":"841066d5dbfc3e8546e28264ba19cba6de09ef41","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"ca95f389_d3cd7d40","updated":"2024-06-15 19:41:43.000000000","message":"Loveit","commit_id":"6adb519918ed02a7c3cc252018df7d39d589ce23"},{"author":{"_account_id":37096,"name":"Fredrik Medley","display_name":"Fredrik Medley","email":"quic_fmedley@quicinc.com","username":"quic-fmedley"},"change_message_id":"f9be7701ac12462b6e1d71c90d1cdc017967a1b9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"e6e60fec_bf9d89cb","updated":"2024-06-18 22:08:39.000000000","message":"Looks generally good. Thank you for working on this.","commit_id":"f26d8217efe8f30ef82ab2058267513f8088ba63"}],"doc/source/developer/specs/configure-projects.rst":[{"author":{"_account_id":2,"name":"Monty Taylor","email":"mordred@inaugust.com","username":"mordred"},"change_message_id":"841066d5dbfc3e8546e28264ba19cba6de09ef41","unresolved":true,"context_lines":[{"line_number":34,"context_line":"Example"},{"line_number":35,"context_line":"-------"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"Consider the following example with Zuul as it is today: A"},{"line_number":38,"context_line":"superproject (which contains a .gitmodules file, or a repo-tool"},{"line_number":39,"context_line":"manifest.xml file) which references multiple subprojects.  Within the"},{"line_number":40,"context_line":"superproject, a Zuul `project-template` is defined which lists the"}],"source_content_type":"text/x-rst","patch_set":2,"id":"aff65b3b_510a11e5","line":37,"updated":"2024-06-15 19:41:43.000000000","message":"I don\u0027t have a great suggestion here - but the first time I read this I got confused and thought it was using Zuul as an example of a project that needed this facility. But of course Zuul doesn\u0027t have submodules - and that is not what you are saying. You are talking about an theoretical project with these characteristics and how it would be managed by zuul today.\n\nMight just be my brain having trouble reading the english. #notaminusone","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"71471aa3588ade319d40fadd348f43407aa7c5fa","unresolved":false,"context_lines":[{"line_number":34,"context_line":"Example"},{"line_number":35,"context_line":"-------"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"Consider the following example with Zuul as it is today: A"},{"line_number":38,"context_line":"superproject (which contains a .gitmodules file, or a repo-tool"},{"line_number":39,"context_line":"manifest.xml file) which references multiple subprojects.  Within the"},{"line_number":40,"context_line":"superproject, a Zuul `project-template` is defined which lists the"}],"source_content_type":"text/x-rst","patch_set":2,"id":"2aff6dfd_6b76c80b","line":37,"in_reply_to":"aff65b3b_510a11e5","updated":"2024-06-17 14:42:12.000000000","message":"Done.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"aa7f3834f24308b7724f1373a3531dfeb5f093fa","unresolved":true,"context_lines":[{"line_number":34,"context_line":"Example"},{"line_number":35,"context_line":"-------"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"Consider the following example with Zuul as it is today: A"},{"line_number":38,"context_line":"superproject (which contains a .gitmodules file, or a repo-tool"},{"line_number":39,"context_line":"manifest.xml file) which references multiple subprojects.  Within the"},{"line_number":40,"context_line":"superproject, a Zuul `project-template` is defined which lists the"}],"source_content_type":"text/x-rst","patch_set":2,"id":"9ab352ac_d0f7f4c3","line":37,"in_reply_to":"aff65b3b_510a11e5","updated":"2024-06-15 19:57:32.000000000","message":"Oh yep that was bad englishing.  The point I was trying to convey was that this is an example I\u0027m setting up with the current state of the world, not an example of the proposed change.  Mostly I added it because the immediately preceding sentence was a one-line summary of the proposed change, and I thought it might lead people to think this was an example of the proposed change.\n\nSo it should probably say:\n  Before we examine the proposed change, let\u0027s consider an example as things stand today:\n\nI\u0027ll incorporate that into the next update.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":27582,"name":"Simon Westphahl","email":"simon.westphahl@bmw.de","username":"simon.westphahl"},"change_message_id":"7f14355a966c0ebf0adc8d2b5bdbac632a723416","unresolved":true,"context_lines":[{"line_number":98,"context_line":"The syntax includes a list of project names for which the superproject"},{"line_number":99,"context_line":"is allowed to include `project` stanzas.  This list may be literal"},{"line_number":100,"context_line":"project names or regular expressions which are matched against project"},{"line_number":101,"context_line":"names.  If the list includes ``^.*$`` as a single regular expression,"},{"line_number":102,"context_line":"then the superproject has permission to write project stanzas for any"},{"line_number":103,"context_line":"project."},{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"}],"source_content_type":"text/x-rst","patch_set":2,"id":"9aabad30_4d3ecb45","line":103,"range":{"start_line":101,"start_character":8,"end_line":103,"end_character":8},"updated":"2024-06-17 05:52:45.000000000","message":"This would also match the config-project(s) and sounds like it would not work with the behavior described further down (see my next comment).","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"71471aa3588ade319d40fadd348f43407aa7c5fa","unresolved":false,"context_lines":[{"line_number":100,"context_line":"project names or regular expressions which are matched against project"},{"line_number":101,"context_line":"names.  If the list includes ``^.*$`` as a single regular expression,"},{"line_number":102,"context_line":"then the superproject has permission to write project stanzas for any"},{"line_number":103,"context_line":"project."},{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"}],"source_content_type":"text/x-rst","patch_set":2,"id":"2f42138f_252bf6f5","line":103,"in_reply_to":"9aabad30_4d3ecb45","updated":"2024-06-17 14:42:12.000000000","message":"Ack.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"71471aa3588ade319d40fadd348f43407aa7c5fa","unresolved":false,"context_lines":[{"line_number":100,"context_line":"project names or regular expressions which are matched against project"},{"line_number":101,"context_line":"names.  If the list includes ``^.*$`` as a single regular expression,"},{"line_number":102,"context_line":"then the superproject has permission to write project stanzas for any"},{"line_number":103,"context_line":"project."},{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"}],"source_content_type":"text/x-rst","patch_set":2,"id":"692ee5ea_1dfa0d2a","line":103,"in_reply_to":"9aabad30_4d3ecb45","updated":"2024-06-17 14:42:12.000000000","message":"Ack.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"ef101cfeb72a38b991a149143d651e7439c90854","unresolved":false,"context_lines":[{"line_number":100,"context_line":"project names or regular expressions which are matched against project"},{"line_number":101,"context_line":"names.  If the list includes ``^.*$`` as a single regular expression,"},{"line_number":102,"context_line":"then the superproject has permission to write project stanzas for any"},{"line_number":103,"context_line":"project."},{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"}],"source_content_type":"text/x-rst","patch_set":2,"id":"98eee152_9d396127","line":103,"in_reply_to":"9aabad30_4d3ecb45","updated":"2024-06-17 14:41:21.000000000","message":"Ack.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"71471aa3588ade319d40fadd348f43407aa7c5fa","unresolved":false,"context_lines":[{"line_number":100,"context_line":"project names or regular expressions which are matched against project"},{"line_number":101,"context_line":"names.  If the list includes ``^.*$`` as a single regular expression,"},{"line_number":102,"context_line":"then the superproject has permission to write project stanzas for any"},{"line_number":103,"context_line":"project."},{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"}],"source_content_type":"text/x-rst","patch_set":2,"id":"ca1d213b_d5265120","line":103,"in_reply_to":"9aabad30_4d3ecb45","updated":"2024-06-17 14:42:12.000000000","message":"Ack.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":27582,"name":"Simon Westphahl","email":"simon.westphahl@bmw.de","username":"simon.westphahl"},"change_message_id":"7f14355a966c0ebf0adc8d2b5bdbac632a723416","unresolved":true,"context_lines":[{"line_number":128,"context_line":""},{"line_number":129,"context_line":"All regular expressions will be re2-style regular expressions."},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"The projects listed under ``configure-projects`` must all be"},{"line_number":132,"context_line":"untrusted-projects (i.e., an untrusted-project is not permitted to"},{"line_number":133,"context_line":"declare a project stanza that matches a config-project)."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"Branches"}],"source_content_type":"text/x-rst","patch_set":2,"id":"3fdd2879_24ba44ee","line":132,"range":{"start_line":131,"start_character":49,"end_line":132,"end_character":18},"updated":"2024-06-17 05:52:45.000000000","message":"Doesn\u0027t this complicate the regex matching? In case I want to exclude all but the config projects, this would probably require a very complicated regex instead of just `^.*$` as mentioned above.\n\nSo maybe instead of an error in case the regex also matches a config-project, we should only consider untrusted-projects by convention and ignore the rest.\n\nOtherwise we\u0027d probably need a way to negate the regex (similar to other places in the Zuul config) as RE2 doesn\u0027t allow negative lookahead.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":27582,"name":"Simon Westphahl","email":"simon.westphahl@bmw.de","username":"simon.westphahl"},"change_message_id":"28d74cc1deac98c0db2d583634398b6887b1b1ca","unresolved":true,"context_lines":[{"line_number":129,"context_line":"All regular expressions will be re2-style regular expressions."},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"The projects listed under ``configure-projects`` must all be"},{"line_number":132,"context_line":"untrusted-projects (i.e., an untrusted-project is not permitted to"},{"line_number":133,"context_line":"declare a project stanza that matches a config-project)."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"Branches"}],"source_content_type":"text/x-rst","patch_set":2,"id":"d411d19c_5c3e6e8f","line":132,"in_reply_to":"30694ace_89209923","updated":"2024-06-19 05:20:10.000000000","message":"I\u0027d agree that a regex of a project stanza that lives in an untrusted project MUST NOT apply to config project and if it does, it should be an error.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"976ff42151065aaaefb74c4fc51bfa2aeb0c4c9d","unresolved":true,"context_lines":[{"line_number":129,"context_line":"All regular expressions will be re2-style regular expressions."},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"The projects listed under ``configure-projects`` must all be"},{"line_number":132,"context_line":"untrusted-projects (i.e., an untrusted-project is not permitted to"},{"line_number":133,"context_line":"declare a project stanza that matches a config-project)."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"Branches"}],"source_content_type":"text/x-rst","patch_set":2,"id":"5e2deac1_72237015","line":132,"in_reply_to":"3fdd2879_24ba44ee","updated":"2024-06-17 14:51:26.000000000","message":"If we allow the tenant config yaml to include but ignore config-projects, that raises the question of what to do if the actual project stanza has a regex that includes a config-project.  I\u0027ve opted to say that is an error, for two reasons:\n1) It is our last opportunity to provide pre-merge feedback that the configuration may not operate as\nexpected.\n2) It\u0027s easier to automate the creation of multiple project stanzas inside the repo to work around the inability to construct a regex that matches everything but a config project.\n\nHowever, your original point still stands, just in a different place, and users won\u0027t be able to create a project stanza that matches \u0027.*\u0027 and have it implicitly only include untrusted-projects.\n\nI\u0027m open to the idea that we should relax the restriction there and have it be implicit as well, but I didn\u0027t want to go too far; this seems conservative and workable.  Thoughts?","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"b286f43b5d15296d40455837aa5790cbbe571962","unresolved":false,"context_lines":[{"line_number":129,"context_line":"All regular expressions will be re2-style regular expressions."},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"The projects listed under ``configure-projects`` must all be"},{"line_number":132,"context_line":"untrusted-projects (i.e., an untrusted-project is not permitted to"},{"line_number":133,"context_line":"declare a project stanza that matches a config-project)."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"Branches"}],"source_content_type":"text/x-rst","patch_set":2,"id":"cfe35c51_b3504232","line":132,"in_reply_to":"3fdd2879_24ba44ee","updated":"2024-06-17 14:41:07.000000000","message":"That works for me.","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"daadf7d063594cfa540d48b20ec26d59ca40d2e1","unresolved":true,"context_lines":[{"line_number":129,"context_line":"All regular expressions will be re2-style regular expressions."},{"line_number":130,"context_line":""},{"line_number":131,"context_line":"The projects listed under ``configure-projects`` must all be"},{"line_number":132,"context_line":"untrusted-projects (i.e., an untrusted-project is not permitted to"},{"line_number":133,"context_line":"declare a project stanza that matches a config-project)."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"Branches"}],"source_content_type":"text/x-rst","patch_set":2,"id":"30694ace_89209923","line":132,"in_reply_to":"5e2deac1_72237015","updated":"2024-06-17 17:24:06.000000000","message":"(I think we should decide this question regardless of the following, but nevertheless, I do think we should add \"negate\" support to both of the regular expressions here (tenant config and project stanza).  I think the end state in zuul should be that all regular expressions are strings or dicts with regex and negate keys.  But I agree that it\u0027s not ideal for that to be necessary in such a simple case, at least in the tenant config.)","commit_id":"9f54db447e0db077d27113ea2a9d36b99a2e5af2"},{"author":{"_account_id":37096,"name":"Fredrik Medley","display_name":"Fredrik Medley","email":"quic_fmedley@quicinc.com","username":"quic-fmedley"},"change_message_id":"f9be7701ac12462b6e1d71c90d1cdc017967a1b9","unresolved":true,"context_lines":[{"line_number":90,"context_line":"                 configure-projects:"},{"line_number":91,"context_line":"                   - submodule1"},{"line_number":92,"context_line":"                   - othermodule"},{"line_number":93,"context_line":"                   - ^submodules/.*$"},{"line_number":94,"context_line":"             - submodule1"},{"line_number":95,"context_line":"             - othermodule"},{"line_number":96,"context_line":"             - submodules/foo"}],"source_content_type":"text/x-rst","patch_set":3,"id":"de75d4e9_f803b9de","line":93,"updated":"2024-06-18 22:08:39.000000000","message":"This configuration looks good. Gerrit has a similar specification, but the opposite direction, which also includes branch names. I think the simplification where specific branch allowance is not configured should be enough and can be added if needed at a later stage.","commit_id":"f26d8217efe8f30ef82ab2058267513f8088ba63"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"b57f026cb6e04cf71df37401e16d46259a8b9616","unresolved":true,"context_lines":[{"line_number":102,"context_line":"then the superproject has permission to write project stanzas for any"},{"line_number":103,"context_line":"project."},{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"},{"line_number":107,"context_line":"config-project.  For example:"},{"line_number":108,"context_line":""},{"line_number":109,"context_line":".. code-block:: yaml"},{"line_number":110,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"c87d5a78_381fa35a","line":107,"range":{"start_line":105,"start_character":0,"end_line":107,"end_character":14},"updated":"2024-07-01 21:09:06.000000000","message":"Will we limit the sorts of things that can be configured for a sub project? I think the main categories are queue, jobs, and vars. Vars the are the item that I\u0027m concerned may be potentially abusable. However, I guess if you can configure queue and job lists then setting vars to influence how the jobs run is also reasonable.","commit_id":"f26d8217efe8f30ef82ab2058267513f8088ba63"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"7e950f1781b60e6e563b3f7bcff19d9e73ca6192","unresolved":false,"context_lines":[{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"},{"line_number":107,"context_line":"config-project.  For example:"},{"line_number":108,"context_line":""},{"line_number":109,"context_line":".. code-block:: yaml"},{"line_number":110,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"47307e13_157ab939","line":107,"in_reply_to":"8f3f6245_31cd23d8","updated":"2024-07-18 22:02:12.000000000","message":"This makes sense. Basically there is risk but it is on the person configuring zuul to use this feature to consider and use appropriately. Not something we need to build guard rails in from the start for.","commit_id":"f26d8217efe8f30ef82ab2058267513f8088ba63"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"5eb590938c6bb548c6f798223ef3f73bb25cf138","unresolved":true,"context_lines":[{"line_number":104,"context_line":""},{"line_number":105,"context_line":"The syntax for configuring other projects within the superproject will"},{"line_number":106,"context_line":"be the same as it is today when the same is done within a"},{"line_number":107,"context_line":"config-project.  For example:"},{"line_number":108,"context_line":""},{"line_number":109,"context_line":".. code-block:: yaml"},{"line_number":110,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"8f3f6245_31cd23d8","line":107,"in_reply_to":"c87d5a78_381fa35a","updated":"2024-07-01 21:37:34.000000000","message":"I think all those should be configurable.  I think doing this at all grants a high degree of trust.  Given that the point is to force another project to run a job, and we can\u0027t make any guarantees like \"it\u0027s always safe to force another project to run a job\" (in fact, the opposite is true; it\u0027s dangerous to do that, you could make the project publish a release), then I think we have to accept that anything else is unlikely to be more risky.\n\nTLDR: setting project variables is a subset of the risk we already would be accepting.","commit_id":"f26d8217efe8f30ef82ab2058267513f8088ba63"}]}
