Keystone's stable/newton gate is broken [0] [1]. The TL;DR is that our keystone_tempest_plugin is validating federated mappings before updating the protocol [2]. The lack of validation was a bug [3] that was fixed in Ocata, but the fix [4] was never backported. Since stable/newton is in Phase II, I would consider this a critical fix to unblock the stable/newton gate. I have a backport up for review [5]. [0] https://review.openstack.org/#/c/469514/ [1] http://logs.openstack.org/14/469514/1/check/gate-keystone-dsvm-functional-ubuntu-xenial/a4aac66/console.html [2] https://github.com/openstack/keystone-tempest-plugin/blob/360bbafa385624f1e86841875baabbbf1104e877/keystone_tempest_plugin/tests/api/identity/v3/test_identity_providers.py#L228-L244 [3] https://bugs.launchpad.net/keystone/+bug/1571878 [4] https://review.openstack.org/#/c/362397/ [5] https://review.openstack.org/#/c/478994/ -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 819 bytes Desc: OpenPGP digital signature URL: <http://lists.openstack.org/pipermail/openstack-dev/attachments/20170629/575fe6c1/attachment.sig>