Earlier  
Posted Nick Remark
#openstack-nova - 2019-11-05
21:58:38 sean-k-mooney you are ment to be able to just use aa-complain
21:58:52 sean-k-mooney to put it in warning/complain mode but it was not working for me
21:59:15 efried would this be... not a problem if I compiled a different version of libvirt?
21:59:25 sean-k-mooney i need to write a readme for that plugin and doument this and fix the other issue
21:59:41 sean-k-mooney no i hit the same issue
21:59:44 efried oh, the readme isn't "Come find sean-k-mooney on IRC"?
21:59:55 efried well, I didn't change 5.8 to 5.6 in my env
21:59:59 efried swhy I'm asking.
21:59:59 sean-k-mooney well it basicaly is right now
22:00:22 efried and if I reboot I have to restack, right?
22:00:48 sean-k-mooney there is another thing you coudl try first
22:00:53 sean-k-mooney but i did it the reboot way
22:01:22 sean-k-mooney you can add security_driver="none"
22:01:40 sean-k-mooney to /etc/libvirt/qemu.conf and restart libvirt-bin
22:01:55 sean-k-mooney but if you rerun stack.sh it will overwrite it
22:02:07 sean-k-mooney ill fix this up and automated in the plugin
22:02:12 sean-k-mooney its ment to do this for you
22:02:43 sean-k-mooney but as i said it has not been updated for ubuntu 18.04
22:04:13 efried sean-k-mooney: and tbc, is this the same issue as
22:04:14 efried ?
22:04:14 efried Connection to libvirt failed: authentication unavailable: no polkit agent available to authenticate action 'org.libvirt.unix.manage': libvirtError: authentication unavailable: no polkit agent available to authenticate action 'org.libvirt.unix.manage'
22:04:30 sean-k-mooney yes
22:04:32 efried k
22:05:15 sean-k-mooney polkit is used to interact with selinux via dbus on fedora/centos/rhel
22:05:24 sean-k-mooney is apparently the libvirt default
22:05:43 openstackgerrit Takashi NATSUME proposed openstack/nova master: Update keypairs in saving an instance object https://review.opendev.org/683043
22:05:44 sean-k-mooney im just not passing the correct flags when building it to have it auto install the apparmor files
22:06:06 sean-k-mooney i should prably just ask danpb how to do it correctly
22:11:18 melwitt mriedem: do you remember any func test change from the past made to avoid "{"forbidden": {"code": 403, "message": "Maximum number of ports exceeded"}}"
22:11:55 mriedem are you backporting something to queens or newton or something and hitting that?
22:11:57 melwitt I'm backporting stuff and hitting this because I'm presumably missing some underlying func test improvement
22:11:58 melwitt yes
22:12:24 melwitt I thought if anyone might remember something related to that, it would be you
22:12:39 mriedem not specifically, but i'd look for port quota stuff on the NeutronFixture
22:12:54 melwitt thanks, any direction helps a lot :)
22:13:11 mriedem https://review.opendev.org/#/q/I1dbccc2be6ba79bf267edac9208c80e187e6256a ?
22:13:36 mriedem https://review.opendev.org/#/c/587412/4/nova/tests/fixtures.py@1347 is the thing i'd think you want
22:14:23 melwitt looks promising
22:25:08 sean-k-mooney efried: ok i think i have fixed the issue locally ill work on a patch. but basically i need to tweak the /etc/libvirt/libvirtd.conf sligtly and nova will be happy
22:25:31 sean-k-mooney efried: http://paste.openstack.org/show/785827/
22:27:02 openstackgerrit Merged openstack/nova master: Follow up to I3e28c0163dc14dacf847c5a69730ba2e29650370 https://review.opendev.org/692856
22:27:04 efried Connection to libvirt failed: Failed to connect socket to '/var/run/libvirt/libvirt-sock': No such file or directory: libvirtError: Failed to connect socket to '/var/run/libvirt/libvirt-sock': No such file or directory
22:27:04 efried sean-k-mooney: okay. I tried doing that conf change and now it's doing this
22:28:12 sean-k-mooney where is that error? nova? virsh?
22:28:47 efried nova compute startup (journalctl)
22:29:15 sean-k-mooney ok what do you get if you do "sudo systemctl status libvirt-bin"
22:30:34 openstackgerrit Matt Riedemann proposed openstack/nova master: Improve metadata server performance with large security groups https://review.opendev.org/656084
22:30:37 mriedem this is a simple performance improvement fix, been sitting a long time waiting for the originaly author to touch it up ^
22:30:46 mriedem and when i went to do it, i realized there was a much simpler fix
22:31:30 efried d'oh, sorry, already started unstacking.
22:31:56 sean-k-mooney no worries
22:32:07 efried sean-k-mooney: I'm adding those extra libvirtd.conf lines (from within the plugin) and will restack.
22:32:32 sean-k-mooney by the way i have code in the pluging to fix the app armor stuff
22:32:34 sean-k-mooney sudo apparmor_parser -R /etc/apparmor.d/usr.sbin.libvirtd || /bin/true
22:32:39 sean-k-mooney im guessing that is failing
22:32:48 sean-k-mooney because i thinkg the package name chagned
22:32:55 sean-k-mooney so im fining that too
22:33:00 efried are we not set -e here?
22:33:27 efried oh, || true would ignore :(
22:33:34 sean-k-mooney yes
22:34:06 sean-k-mooney the /bin/ture was to ignore it on subsequent runs but its really just a hack
22:35:03 sean-k-mooney install_build_deps for libvirt-bin used to pull in the apparmor utils but i apparently does not anymore so ill install them direcly
22:35:16 sean-k-mooney im guessing you dont have apparmor_parser right
22:36:34 sean-k-mooney i should not really depend on the transitive depencies like that
22:37:58 efried sean-k-mooney: I have an apparmor_parser in /sbin
22:38:44 sean-k-mooney hum ok it should have remvoed the proifle then but ill document the other way in anycase
22:39:41 efried the file it's referring to doesn't exist fwiw
22:41:07 melwitt mriedem: you were right, that solved the 403. now it's on to 409 "Multiple possible networks found, use a Network ID to be more specific". I'm sifting through NeutronFixture changes
22:41:54 efried sean-k-mooney: with those extra lines, now stack fails when libvirt-bin won't start.
22:41:55 sean-k-mooney efried: there is still a profile in /etc/apparmor.d/libvirt/ in my case
22:42:32 efried File /etc/apparmor.d/usr.sbin.libvirtd not found, skipping...
22:42:32 efried +/opt/stack/devstack-plugin-libvirt-qemu/devstack/libs/libvirt:install_libvirt_qemu_src:210 sudo apparmor_parser -R /etc/apparmor.d/usr.sbin.libvirtd
22:42:32 efried that line is skipping
22:43:05 efried Nov 05 16:40:14 nucle systemd[1]: libvirtd.service: Failed with result 'exit-code'.
22:43:05 efried Nov 05 16:40:14 nucle systemd[1]: libvirtd.service: Start request repeated too quickly.
22:43:05 efried Nov 05 16:40:14 nucle systemd[1]: Stopped Virtualization daemon.
22:43:05 efried Nov 05 16:40:14 nucle systemd[1]: libvirtd.service: Scheduled restart job, restart counter is at 5.
22:43:05 efried Nov 05 16:40:14 nucle systemd[1]: libvirtd.service: Service hold-off time over, scheduling restart.
22:43:05 efried the libvirt-bin service is failing thusly:
22:43:06 efried Nov 05 16:40:14 nucle systemd[1]: Failed to start Virtualization daemon.
22:43:08 sean-k-mooney ya it has obviously moved
22:43:45 efried /opt/stack/libvirt/src/security/apparmor/usr.sbin.libvirtd
22:43:45 efried /etc/apparmor.d/cache/usr.sbin.libvirtd
22:43:45 efried I see these
22:43:46 sean-k-mooney do you have anything in the journal
22:44:18 efried Assuming I would find it with journalctl -u libvirt-bin, no
22:44:35 sean-k-mooney it would be libvirtd-bin
22:44:43 sean-k-mooney but i dont think that is where its logging
22:44:48 efried either way
22:44:49 efried no
22:45:03 sean-k-mooney ok give me a sec to push this up and test it
22:45:14 efried crap, I f'ed up the libvirtd.conf hack, sec.
22:47:50 melwitt mriedem: ok, looks like I just needed more of that change and now things are working. gonna try backporting the whole thing
22:48:57 mriedem melwitt: which target branch? is this upstream?
22:49:06 mriedem because i don't think we want to backport that whole thing...
22:50:09 melwitt mriedem: this is downstream queens. really? ok
22:50:19 mriedem well, it's big
22:50:26 mriedem note you already have an abandoned backport of that upstream on stable/queens
22:50:38 mriedem https://review.opendev.org/#/c/599764/
22:51:05 melwitt cause it looks like I need the bits removing the validate_networks stub, add the shared network stuff, and add stuff from this change too https://review.opendev.org/#/c/585385/15/nova/tests/fixtures.py

Earlier   Later