15:03:20 #startmeeting keystone 15:03:20 Meeting started Tue May 30 15:03:20 2023 UTC and is due to finish in 60 minutes. The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:03:20 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:03:20 The meeting name has been set to 'keystone' 15:03:26 o/ 15:03:32 #topic roll call 15:03:39 o/ 15:03:40 admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m] 15:03:42 o/ 15:03:56 🙋‍♂️ 15:04:16 #topic review past meeting work items 15:04:35 #link https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-05-23-15.12.html 15:05:39 I need to push the action items for myself a week, there is a security bug that is likely a CVE that I'm trying to track down 15:05:56 #action d34dh0r53 investigate https://bugs.launchpad.net/keystone/+bug/2009752 15:06:12 #action d34dh0r53 Look into adding/restoring a known issues section to our documentation 15:06:27 #action d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation 15:06:55 #action d34dh0r53 update https://review.opendev.org/c/openstack/keystonemiddleware/+/882401 to include test_ec2_token_middleware.py 15:07:15 #action d34dh0r53 look at https://bugs.launchpad.net/keystone/+bug/2018644 15:07:21 Hiromu Asahina proposed openstack/keystone-specs master: External OAuth2.0 Authorization Server Support https://review.opendev.org/c/openstack/keystone-specs/+/861554 15:07:30 drencrom look at https://review.opendev.org/c/openstack/keystonemiddleware/+/878027 to see if we can add the test_ec2_token_middleware.py to it 15:08:58 #action drencrom look at https://review.opendev.org/c/openstack/keystonemiddleware/+/878027 to see if we can add the test_ec2_token_middleware.py to it 15:09:04 moving on 15:09:19 #topic liaison update 15:09:37 as I said there is a security bug that I'm prioritizing 15:09:42 nothing else for VMT 15:11:07 #topic specification OAuth 2.0 (hiromu) 15:12:39 I've just updated the spec as shown the above. Sorry for interrupting to the meeting. 15:13:27 no problem, I'll take a look 15:13:45 need anything else from us hiromu ? 15:14:42 ok, next up 15:15:02 #topic Secure RBAC (dmendiza[m]) 15:15:17 #link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_ 15:15:18 Service Role Implementation 15:15:20 #link https://review.opendev.org/c/openstack/keystone/+/863420 15:15:22 Manager Role Implementation 15:15:23 thank you :d34dh0r53, nothing 15:15:24 #link https://review.opendev.org/c/openstack/keystone/+/822601 15:15:52 Haven't made any progress yet ... 😅 15:16:59 :) 15:17:19 ok, next up 15:17:36 #topic SQLAlchemy 2.0 (stephenfin) 15:17:49 #link https://review.opendev.org/q/topic:sqlalchemy-20+is:open+project:openstack/keystone 15:17:51 Can I get reviews on this, while I have context/time to close it out? 15:17:53 What more do you need from me? 15:18:44 thanks for the reviews on those, I see that most have a +1 so if the cores can review that would be a big help 15:21:09 #topic open discussion 15:22:23 (drencrom) We need to merge these backports to fix pep8 tests 15:22:31 Hey, about the victoria backport mentioned before I could not change it to add the token patch, so I'm thinking on abandoning it and creating anew patch with everything included 15:22:51 But I noteced another issue related to victoria and ussuri backports 15:23:05 yeah, I'm looking at that now drencrom 15:26:41 In wallaby the test actually exists but it is non-voting 15:26:58 yeah, just saw that 15:27:11 maybe we should just do that for u and v 15:29:46 In any case we still need another +1 in those pep8 patches at least up to wallaby where they pass CI 15:30:08 +2 sorry 15:31:01 ack, dmendiza[m], xek, knikolla ^ 15:31:19 next up 15:31:22 (mustafakemalgilor) PooledLdapHandler message.clean() patch backports 15:31:24 review request 15:31:26 #link ussuri: https://review.opendev.org/c/openstack/keystone/+/874846 15:31:28 #link victoria: https://review.opendev.org/c/openstack/keystone/+/874847 15:31:30 #link wallaby: https://review.opendev.org/c/openstack/keystone/+/874844 15:32:30 failure on the wallaby backport 15:33:09 keystoneauth version mismatch 15:33:20 need to look at that one 15:35:03 > ERROR: Could not find a version that satisfies the requirement keystoneauth1>=5.1.1 (from keystone-tempest-plugin) 15:35:13 yeah 15:35:17 Yay dependency resolution bugs! 15:35:23 hooray! 15:37:04 ok, need to see what's going on there 15:38:51 #action investigate dependency issue in this patch wallaby: https://review.opendev.org/c/openstack/keystone/+/874844 15:39:03 #topic bug review 15:39:18 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:39:47 there are three new bugs, one is a dupe of the other and I'm not sure of the validity of any of them 15:40:42 #link https://bugs.launchpad.net/keystone/+bug/2020766 15:40:49 I closed the dupe of that one 15:41:15 not sure if that is a keystone bug, looks incomplete to me but it needs some more investigation 15:41:20 next up is 15:41:29 #link https://bugs.launchpad.net/keystone/+bug/2020847 15:41:47 I'm unsure as to why that was moved to keystone 15:42:36 I see, I read that wrong, so keystone is accepting an MTU on a project via curl 15:42:40 when it shouldn't 15:43:30 asking for more information on that one 15:43:37 next up 15:43:43 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:43:48 no new bugs there 15:44:19 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:44:26 no new bugs here either 15:44:47 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:44:53 one new bug in keystonemiddleware 15:45:03 #link https://bugs.launchpad.net/keystonemiddleware/+bug/2020821 15:45:31 this is a feature request 15:48:02 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:48:07 no new bugs in pycadf 15:48:17 #link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=0 15:48:22 no new bugs in ldappool 15:48:31 #topic conclusion 15:48:39 how did the reviewathon go? 15:49:00 Trying to remember. I think it was just Doug and I. 15:49:07 No, Greg too 15:49:56 I forgot to beg for https://review.opendev.org/c/openstack/keystone/+/874346 although it was a perfect opportunity. 15:50:06 Just to finish the previous discussion, I'll submit patches to make the lower-constraint test to be non-voting in ussuri and victoria if it is ok for you. 15:51:33 drencrom: ack, that would be awesome, thank you 15:53:47 Ok, thanks everyone, see y'all on Friday 15:53:52 #endmeeting