Tuesday, 2026-04-07

opendevreviewShreya Vishwajeet Desai proposed openstack/keystone master: Fix system role assignments in effective role listing  https://review.opendev.org/c/openstack/keystone/+/98349702:46
opendevreviewArtem Goncharov proposed openstack/keystone master: Prevent unauthorized EC2 credential creation and deletion  https://review.opendev.org/c/openstack/keystone/+/98358716:03
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.2: Prevent unauthorized EC2 credential creation and deletion  https://review.opendev.org/c/openstack/keystone/+/98358816:09
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Prevent unauthorized EC2 credential creation and deletion  https://review.opendev.org/c/openstack/keystone/+/98358916:11
opendevreviewArtem Goncharov proposed openstack/keystone stable/2024.2: Prevent unauthorized EC2 credential creation and deletion  https://review.opendev.org/c/openstack/keystone/+/98359116:12
opendevreviewArtem Goncharov proposed openstack/keystone stable/2026.1: Prevent unauthorized EC2 credential creation and deletion  https://review.opendev.org/c/openstack/keystone/+/98359316:15
fungigtema: thanks for pushing those. i saw xek had also attached a backport for unmaintained/2024.1, were you going to push that as well or should i refrain from mentioning it in the advisory?16:33
fungii'm good with either option, just want to make sure i'm not still waiting for that last upload16:33
gtemaah, that is the unmaintained now. I was heavily strugling since the opendev.org was not reachable at all for me and I wasn't even able to list correct branch names16:34
gtemaI'll push it now16:34
gtemabut actually, it is unmaintained, so there is no need to wait for that.16:35
gtemaI am not even sure our CI is working there16:36
fungiwell, we merely link the review url, it doesn't necessarily need to merge. if there's a backport to unmaintained branches we link them in the advisory and include a note saying that it was provided as a convenience but that there won't be any point releases that include it16:38
gtemaok, I pushed it (https://review.opendev.org/c/openstack/keystone/+/983597) but don't see a bot message here16:41
fungithanks, and yeah it's likely gerritbot isn't matching on unmaintained/.* for that so wouldn't report it here16:43
fungiit did show up in the lp bug though16:43
gtemaok, good16:44
-opendevstatus- NOTICE: Load on the opendev.org Gitea backends is under control again for now, if any Zuul jobs failed with SSL errors or disconnects reaching the service prior to 16:15 UTC they can be safely rechecked17:03
opendevreviewIvan Anfimov proposed openstack/keystone stable/2024.2: fix(pep8): pin setuptools<82 for flake8-import-order compatibility  https://review.opendev.org/c/openstack/keystone/+/98265820:39
opendevreviewBoris Bobrov proposed openstack/keystone master: Add tests for restricted app cred guard on EC2 credential creation  https://review.opendev.org/c/openstack/keystone/+/98364821:36
opendevreviewBoris Bobrov proposed openstack/keystone master: Add tests for restricted app cred guard  https://review.opendev.org/c/openstack/keystone/+/98364821:36
opendevreviewBoris Bobrov proposed openstack/keystone master: Block restricted app creds from creating EC2 credentials via /credentials  https://review.opendev.org/c/openstack/keystone/+/98365521:57
opendevreviewBoris Bobrov proposed openstack/keystone master: Block app cred tokens from authorizing OAuth1 requests  https://review.opendev.org/c/openstack/keystone/+/98365621:57

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!