Wednesday, 2026-04-29

opendevreviewMerged openstack/oslo.limit master: Fix new mypy errors  https://review.opendev.org/c/openstack/oslo.limit/+/98655811:55
opendevreviewMerged openstack/oslo.limit master: tox: Use new constraints option  https://review.opendev.org/c/openstack/oslo.limit/+/98640012:28
lajoskatonaHi shall I ask a 2nd review round for my patch for LDAP pw expiry: https://review.opendev.org/c/openstack/keystone/+/976618 , thanks in advance14:41
gtemalajoskatona - you can always ask, whether you will get what you ask is sadly a different question14:54
gtemaI leave a tab open in my browser14:55
lajoskatonagtema: thanks, I usually do the same :-)15:03
d34dh0r53#startmeeting keystone15:07
opendevmeetMeeting started Wed Apr 29 15:07:20 2026 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:07
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:07
opendevmeetThe meeting name has been set to 'keystone'15:07
d34dh0r53Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct15:07
d34dh0r53#link https://openinfra.dev/legal/code-of-conduct15:07
d34dh0r53#topic roll call15:07
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra15:08
gtemao/15:08
d34dh0r53o/15:09
blasseyeo/15:09
d34dh0r53#topic review past meeting work items15:10
d34dh0r53#link https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-04-15-15.06.html15:10
d34dh0r53nothing to review, PTG was last week, anything to review from there?15:10
gtemanope15:11
d34dh0r53#topic liaison updates15:11
d34dh0r53nothing from me15:11
gtemaneither on my side15:11
d34dh0r53#topic specification Secure RBAC (dmendiza)15:11
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:11
d34dh0r532026.1 Release Timeline15:12
d34dh0r53Update oslo.policy in keystone to enforce_new_defaults=True15:12
d34dh0r53Update oslo.policy in keystone to enforce_scope=True15:12
d34dh0r53not sure if dmendiza is around or not15:12
gtemayou've missed a special treatment of dmendiza ;-)15:13
d34dh0r53I did, here is YABDM (Yet Another Bespoke dmendiza mention)15:13
d34dh0r53:)15:13
gtemaapparently he is not around15:15
d34dh0r53I know we talked about this at the PTG, well, removal of the legacy policies. It's not on the etherpad whether a decision was made or not15:16
gtemawe ended up in +2 and -2 for re-adding protection tests as one part of the related topic15:17
d34dh0r53I'm looking at that review now15:17
d34dh0r53hmm, I see both sides. I'm leaning slightly in favor of moving and fixing the tests in KTP rather than here, but again it's a 50/50 call15:20
gtemaI am not strong on that, I have no problem rather than seeing potential brain explosion with a yet another remote context15:20
d34dh0r53indeed, that's my worry too, but at this point almost all of our testing is in that repo so people should know where to look15:21
gtemadeal. But then we need to take this consideration when reviewing changes adding policy related unit tests (for vulnerabilities tests)15:22
d34dh0r53agreed, a follow-on patch is mandatory15:22
d34dh0r53next up15:23
d34dh0r53#topic specification Secuirty Compliance Testing (dmendiza)15:23
d34dh0r53#link https://review.opendev.org/c/openstack/devstack/+/95796915:23
d34dh0r53That's getting blocked by Software Factory on devstack :/ not sure what to do there15:24
gtemanot really, there is also depends-on tempest15:24
gtemahttps://review.opendev.org/c/openstack/tempest/+/95402915:24
gtemaand that one is review -115:25
d34dh0r53ahh, I missed that one15:26
d34dh0r53Okay, I'll get someone to add release notes to that one so that we can get it merged15:27
d34dh0r53moving on15:27
d34dh0r53#topic keystone-rs15:27
d34dh0r53#link https://github.com/openstack-experimental/keystone15:27
gtemanot much happening this week since I am in the codegenerator (openstack-apis) madhouse15:28
gtemaanyway polishing the code adding bit more docstrings and contrib guide15:28
gtemathe mTLS is still on the desk as the next big thing15:28
gtemathat's it for now, sadly15:30
d34dh0r53ack, thanks15:32
d34dh0r53#topic open discussion15:33
gtemanothing from me15:33
d34dh0r53nor me15:33
moutazchaara[m]Only one patch from my side. Fixing ldap. 15:34
moutazchaara[m]https://review.opendev.org/c/openstack/keystone/+/98291315:34
moutazchaara[m]Not sure if we mentioned this in this meeting, i joined late15:35
d34dh0r53Thanks moutaz.chaara , I'll take a look15:36
d34dh0r53#topic bug review15:36
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:37
moutazchaara[m]thanks, it was already reviewed +2, but i discovred something else so i needed to push another commit ..15:37
d34dh0r53👍15:37
d34dh0r53some new bugs in keystone, not sure if we've gone over this first one yet15:37
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/214825915:37
d34dh0r53I think we have, looks like low hanging fruit if anyone wants to take a stab at it15:38
d34dh0r53next up #link https://bugs.launchpad.net/keystone/+bug/214859915:38
d34dh0r53This is what they asked for15:39
d34dh0r53That's a reviewathon discussion15:42
d34dh0r53next up15:42
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/214861715:42
gtemaso many bugs and so few time to keep the context of all of them15:43
d34dh0r53I know15:43
gtemaI still need to go back to security vuln bugs though15:44
gtemathe openapi madhouse distructed me so heavily that I understood I have a brain overflow15:44
d34dh0r53do you dream in json?15:45
gtemain jsonschemas, it is worse than just json15:45
d34dh0r53lol15:45
gtemamulti-level oneOf15:45
opendevreviewTakashi Kajinami proposed openstack/keystone master: zuul: Use ansible variable to configure tempest plugins  https://review.opendev.org/c/openstack/keystone/+/98668015:46
d34dh0r53this is an iteresting bug, but I agree with Boris it's a contrived example15:46
d34dh0r53Going to set it to low15:46
gtemayou mean the race one?15:46
d34dh0r53yeah15:46
gtemawell, no clue how to chace/fix those - python is not good for that15:47
gtemachase15:47
d34dh0r53Yeah, if you want to run that many threads in Python you're on your own15:48
d34dh0r53finally for keystone15:48
d34dh0r53#link https://bugs.launchpad.net/keystone/+bug/215008815:48
gtemayeah, I've seen that and agree, but we need to address security vulns first in that area to not to produce merge conflicts15:49
d34dh0r53indeed15:49
d34dh0r53cool, that does it for keystone, moving on15:49
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:49
d34dh0r53nothing new in python-keystoneclient15:50
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:50
d34dh0r53keystoneauth is goo15:50
d34dh0r53*good15:50
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:50
d34dh0r53no new bugs in keystonemiddleware15:50
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:50
d34dh0r53pycadf is good15:51
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:51
d34dh0r53as is ldappool15:51
d34dh0r53#topic conclusion15:51
d34dh0r53Thanks folks!15:51
gtemathanks Dave, and have a nice long weekend15:51
moutazchaara[m]thanks15:52
d34dh0r53Not for me :( Our day off is at the end of the month15:52
d34dh0r53But you enjoy your long weekend15:52
gtemahaven't you said no reviewathon this week?15:52
gtemaMay 1st - public holiday in many countries15:52
d34dh0r53Oops, NO REVIEWATHON this week15:52
d34dh0r53Public holiday15:52
gtema:)15:53
d34dh0r53I just canceled the calendar invite as well15:53
d34dh0r53Thanks for reminding me :)15:53
gtemayou are welcome15:53
d34dh0r53cheers!15:54
d34dh0r53#endmeeting15:54
opendevmeetMeeting ended Wed Apr 29 15:54:10 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:54
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-04-29-15.07.html15:54
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-04-29-15.07.txt15:54
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2026/keystone.2026-04-29-15.07.log.html15:54

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!