Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 966431

Summary: Keystone Trusts API fails to list trusts with roles specified
Product: Red Hat OpenStack Reporter: Pavel Sedlák <psedlak>
Component: openstack-keystoneAssignee: Jamie Lennox <jlennox>
Status: CLOSED ERRATA QA Contact: Udi Kalifon <ukalifon>
Severity: high Docs Contact:
Priority: high    
Version: 3.0CC: ajeain, apevec, ayoung, jagee, jkt, jlennox, mlopes, nkinder, psedlak
Target Milestone: z2Keywords: Rebase, Triaged, ZStream
Target Release: 4.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openstack-keystone-2013.2.2-1.el6ost Doc Type: Rebase: Bug Fixes Only
Doc Text:
Previously, listing Trusts would result in a 500 error. This was due to an invalid attempt to append the result with information regarding the roles assigned to the trust. With this update, this information has been removed from the API call, and consequently the 500 error is no longer presented.
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-03-04 20:12:18 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1065319    
Bug Blocks:    

Description Pavel Sedlák 2013-05-23 09:31:03 UTC
Discovered with and applies to openstack-keystone-2013.1.1-1.el6ost.

When there are existing Trusts with Roles specified, the list-trusts request fails with 500 Internal Server Error.

When there are Trusts but non of them has the Role(s) specified, or after they were deleted, listing of Trusts works correctly.

1) Create Role/User/Project and add that role to the user on that project
> keystone tenant-create/user-create ...
> keystone role-create --name testRole
> keystone user-role-add --user yourUser --role testRole --tenant yourProject

2) Create Trust with a Role(s) specified with request like this:
> localhost:5000 POST /v3/OS-TRUST/trusts
> {"trust":
>  {"impersonation":false,
>   "project_id":"<your-project-id>",
>   "trustor_user_id":"<your-user-id>",
>   "trustee_user_id":"<other-user-id>",
>   "roles":[{"name":"testRole"}]
>   }}

3) List Trusts
> localhost:5000 GET /v3/OS-TRUST/trusts
which ends with 500 error instead of response with list of Trusts:
> reply: 'HTTP/1.1 500 Internal Server Error\r\n'
> header: Vary: X-Auth-Token
> header: Content-Type: application/json
> header: Content-Length: 148
> header: Date: Wed, 22 May 2013 15:30:33 GMT
> Reply body:
> {'error': {'code': 500,
>            'message': "An unexpected error prevented the server from
>                        fulfilling your request. 'id'",
>            'title': 'Internal Server Error'}}

In the keystone.log there is following backtrace after such request:
> 2013-05-22 17:30:33    ERROR [root] 'id'
> Traceback (most recent call last):
>  File "/usr/lib/python2.6/site-packages/keystone/common/wsgi.py", line 236, in __call__
>    result = method(context, **params)
>  File "/usr/lib/python2.6/site-packages/keystone/common/controller.py", line 104, in wrapper
>    return f(self, context, **kwargs)
>  File "/usr/lib/python2.6/site-packages/keystone/trust/controllers.py", line 181, in list_trusts
>    self._fill_in_roles(context, trust, global_roles)
>  File "/usr/lib/python2.6/site-packages/keystone/trust/controllers.py", line 76, in _fill_in_roles
>    if x['id'] == trust_role['id']]
> KeyError: 'id'

Comment 5 Jamie Lennox 2013-11-22 07:47:16 UTC
Discovered this as well today. It is only reproducable when using role_names not the ids.

Comment 8 Adam Young 2014-01-10 04:35:59 UTC
Upstream bug was marked as a duplicate.  Fix was commited in

Reviewed: https://review.openstack.org/60301
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=ab0e2c7667a9adc46fece742e1ee8160879b497b

Comment 11 Pavel Sedlák 2014-01-17 15:34:46 UTC
Seems that now this bug applies to stable branches, not just master where it was fixed, so maybe it should be backported stable/havana?

Comment 18 Udi Kalifon 2014-02-20 12:51:23 UTC
successfully listed trusts in:
openstack-keystone-2013.2.2-1.el6ost.noarch

Comment 20 errata-xmlrpc 2014-03-04 20:12:18 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2014-0213.html