[Yahoo-eng-team] [Bug 1915582] [NEW] Nested policy enforcement is confusing to end users and operators

2021-02-12 Thread Lance Bragstad
Public bug reported: Several APIs in glance use a pattern where an image is fetched from the backend before performing an operation, updating an image for example. The API code for updating an image calls the image repository, which ultimately enforces the policy for get_image [0][1]. This can

[Yahoo-eng-team] [Bug 1915543] [NEW] Glance returns 403 instead of 404 when images are not found

2021-02-12 Thread Dan Smith
Public bug reported: Glance is translating "Not Found" errors from the DB layer into "Not Authorized" errors in policy, which it should not be doing. In general, we should always return 404 when something either does not exist, or when permissions do not allow you to know if that thing exists.

[Yahoo-eng-team] [Bug 1915318] Re: User list cannot be retrieved when pointing user_tree_dn at top level of the root domain

2021-02-12 Thread Billy Olsen
Further discussion with Jeff indicated that replacing the { and } with ( and ) resolved the issue. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity

[Yahoo-eng-team] [Bug 1914037] Re: scenario tests tempest.scenario.test_network_v6.TestGettingAddress fails

2021-02-12 Thread Martin Kopec
https://review.opendev.org/c/openstack/tempest/+/774764 got merged ** Changed in: tempest Status: Triaged => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1914037

[Yahoo-eng-team] [Bug 1915540] [NEW] HTTP 403s are more confusing than HTTP 404s when evaluating authorization of a non-existent resource

2021-02-12 Thread Lance Bragstad
Public bug reported: When keystone implemented support for default personas (system-admin, system-member, system-reader, domain-admin, domain-member, domain- reader, project-admin, project-member, project-reader), we took the stance that HTTP 403s should be returned for non-existent resources

[Yahoo-eng-team] [Bug 1915308] Re: security group table doesn't observe Neutron policy settings

2021-02-12 Thread Jeremy Stanley
Thanks, I've switched this to a normal public bug and set our security advisory task to Won't Fix indicating there shouldn't be any advisory publication required. The OpenStack VMT is treating this as a class E report (neither a vulnerability nor hardening opportunity) per our taxonomy:

[Yahoo-eng-team] [Bug 1915530] [NEW] Openvswitch firewall - removing and adding security group breaks connectivity

2021-02-12 Thread Slawek Kaplonski
Public bug reported: How to reproduce the issue: 1. use neutron-ovs-agent with openvswitch firewall driver, 2. spawn vm with SG which has some rule to allow some kind of traffic (can be e.g. ssh to the instance) 3. establish connection according to the rule(s) in SG (e.g. connect through ssh

[Yahoo-eng-team] [Bug 1915513] [NEW] selected region from the available region listing is not being used which results into an error

2021-02-12 Thread Pawan Gupta
Public bug reported: I have multiple regions ( e.g. R1, R2) in my setup and I am providing those via "AVAILABLE_REGIONS" param in `local_settings` file. I have set "DEFAULT_SERVICE_REGIONS" param too with correct endpoints ( e.g. R2). Now while logging in I select `R2` from the Region dropdown,

[Yahoo-eng-team] [Bug 1864279] Re: Unable to attach more than 6 scsi volumes

2021-02-12 Thread Christian Ehrhardt 
>From libvirt package POV this is fixed in >=Focal (20.04) and the only release left affected is Bionic (18.04, libvirt 4.0). Fixing it in Bionic is IMHO worth to consider but low prio (if users can influence, they can set an address to 8-16 and it works, only the default-no-address use case is

[Yahoo-eng-team] [Bug 1864279] Re: Unable to attach more than 6 scsi volumes

2021-02-12 Thread Dincer Celik
** Also affects: cloud-archive Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1864279 Title: Unable to attach more than 6

[Yahoo-eng-team] [Bug 1864279] Re: Unable to attach more than 6 scsi volumes

2021-02-12 Thread Dincer Celik
** Project changed: cloud-archive => libvirt (Ubuntu) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1864279 Title: Unable to attach more than 6 scsi volumes Status in