Thursday, 2026-05-28

fricklerfyi grenade for 2025.1 seems to be broken, I've asked in the qa channel how we should deal with this. likely making the job n-v as a workaround would be needed as short term solution.14:00
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Temporarily make grenade non-voting  https://review.opendev.org/c/openstack/keystone/+/99047614:39
opendevreviewElod Illes proposed openstack/keystone stable/2025.1: DNM: CI health with tempest workaround  https://review.opendev.org/c/openstack/keystone/+/99047814:46
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Temporarily make grenade non-voting  https://review.opendev.org/c/openstack/keystone/+/99047615:02
opendevreviewArtem Goncharov proposed openstack/keystone master: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99048515:05
opendevreviewArtem Goncharov proposed openstack/keystone master: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99048615:05
opendevreviewArtem Goncharov proposed openstack/keystone master: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99048715:05
opendevreviewArtem Goncharov proposed openstack/keystone master: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99048815:05
opendevreviewArtem Goncharov proposed openstack/keystone master: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99048915:05
opendevreviewArtem Goncharov proposed openstack/keystone stable/2026.1: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99049015:05
opendevreviewArtem Goncharov proposed openstack/keystone stable/2026.1: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99049115:05
opendevreviewArtem Goncharov proposed openstack/keystone stable/2026.1: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99049215:05
opendevreviewArtem Goncharov proposed openstack/keystone stable/2026.1: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99049315:05
opendevreviewArtem Goncharov proposed openstack/keystone stable/2026.1: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99049415:05
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.2: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99049515:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.2: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99049615:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.2: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99049715:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.2: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99049815:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.2: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99049915:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99050015:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99050115:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99050215:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99050315:06
opendevreviewArtem Goncharov proposed openstack/keystone stable/2025.1: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99050415:06
fricklergtema: looks like there is a pep8 failure right at the bottom of the stack :( https://zuul.opendev.org/t/openstack/build/ebe0ccd76a5845eb97f0d16e8d7df12115:58
gtemathis is insane, but not unfamiliar failure - was dealing with it multiple times and still it squeezed through while I was running pep8 after every single commit and cherry-pick. git still has some rough ends16:00
opendevreviewArtem Goncharov proposed openstack/keystone master: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99048516:02
opendevreviewArtem Goncharov proposed openstack/keystone master: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99048616:02
opendevreviewArtem Goncharov proposed openstack/keystone master: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99048716:02
opendevreviewArtem Goncharov proposed openstack/keystone master: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99048816:02
opendevreviewArtem Goncharov proposed openstack/keystone master: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99048916:02
fricklerseems the keystone-tempest-oidc-federation job is also broken in an unrelated way, oh my https://zuul.opendev.org/t/openstack/build/ea577e8e07da4d5fba368449e37d033416:32
gtemayes, there is https://review.opendev.org/c/openstack/keystone/+/989615 addressing that that just didn't merge yet16:33
gtemaI pinged other cores, but with no luck. Can force-merge it myself though when necessary16:34
fricklergtema: oh, so that's only a devstack issue at least, good to know16:36
frickleroh, wait, that's the same failure I saw in my unmaintained backport yesterday. so iiuc that keycloak fix will need to be backported all the way back there ...17:02
gtemayes, I see this now also.17:02
gtemaand another failure in pep8 is crazy, because it passes for me locally17:02
gtemathis drives me so crazy17:02
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99048519:41
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99048619:41
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99048719:41
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99048819:41
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99048919:41
xekgtema, looks like at least one of the pep8 issues was fixed in the second patch, so running pep8 against the whole set didn't catch that there was an issue on the first patch19:46
gtemaI was running it after every single change. There is another issue with oep8 that bandit is failing while locally for me it passes19:52
opendevreviewMathieu Gagné proposed openstack/keystone master: Remove leading space from operation path user policy  https://review.opendev.org/c/openstack/keystone/+/99057421:08
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99048521:18
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99048921:30
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99048721:31
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99048621:33
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99048721:33
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99048821:33
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99048921:34
xek^ master patches should pass the gate now...21:54
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2026.1: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99049021:57
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2026.1: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99049121:57
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2026.1: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99049221:57
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2026.1: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99049321:57
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2026.1: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99049421:57
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.2: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99049521:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.2: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99049621:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.2: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99049721:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.2: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99049821:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.2: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99049921:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.1: Enforce delegation project boundary for delegated tokens  https://review.opendev.org/c/openstack/keystone/+/99050021:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.1: Fix user impersonation through application credentials (CVE-2026-42998)  https://review.opendev.org/c/openstack/keystone/+/99050121:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.1: Forbid trust operations using application credentials (CVE-2026-43000)  https://review.opendev.org/c/openstack/keystone/+/99050221:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.1: Preserve expires_at when rescoping federated tokens (CVE-2026-44394)  https://review.opendev.org/c/openstack/keystone/+/99050321:58
opendevreviewGrzegorz Grasza proposed openstack/keystone stable/2025.1: Prevent RBAC policy bypass via JSON body and query filters (CVE-2026-42999)  https://review.opendev.org/c/openstack/keystone/+/99050421:58

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!