New issue
Advanced search Search tips

Issue 852077 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 3
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

Manual analyze request ACL didn't work as expected in infra repo

Project Member Reported by qyears...@chromium.org, Jun 12 2018

Issue description

I was trying to manually reproduce a run in the infra repo on tricium-dev via rpcexplorer and found that I was not authorized to do this.

URL:
https://tricium-dev.appspot.com/rpcexplorer/services/tricium.Tricium/Analyze?request={%20%20%20%20%22project%22:%20%22infra%22,%20%20%20%20%22files%22:%20[%20%20%20%20%20%20%20%20{%20%20%20%20%20%20%20%20%20%20%20%20%22path%22:%20%22data.proto%22%20%20%20%20%20%20%20%20}%20%20%20%20],%20%20%20%20%22gitCommit%22:%20{%20%20%20%20%20%20%20%20%22url%22:%20%22https://chromium.googlesource.com/infra/infra%22,%20%20%20%20%20%20%20%20%22ref%22:%20%22refs/changes/43/1097543/1%22%20%20%20%20}}

Expected result: run started, run ID returned
Actual:
Code: 7 (PERMISSION_DENIED)
Description: failed to execute analyze request

The permission to start analyze request here should be determined by the group "tricium-infra-requesters", and I'm logged in as qyearsley@google.com which I've explicitly added to that group.

This could be a matter of latency when updating the groups.
 
Components: Infra>Platform>Tricium
Components: -Infra>CodeAnalysis
Labels: -Tricium
Owner: ----
Status: Available (was: Assigned)
Cc: qyears...@chromium.org
Summary: Manual analyze request ACL didn't work as expected in infra repo (was: Failed to get authorization to send analyze request in infra repo)
Possibly related to  bug 908647 .
Status: WontFix (was: Available)
Mystery solved, same as  bug 908647  --

> tricium-dev.appspot.com uses chrome-infra-auth-dev for groups (see https://tricium-dev.appspot.com/admin/portal/auth_service)
> 
> chrome-infra-auth-dev doesn't have project-infra-committers or -tryjob-acccess groups. It is completely separate group namespaces.

Sign in to add a comment