| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2022-01-27 | |||
| 17:13:59 | prometheanfire | sean-k-mooney: if you have suggestions on how to debug https://github.com/openstack/nova/commit/faad45b6323d7c52d35b7ccc45eacb5580b3b4d3#diff-67d0163175a798156def4ec53c18fa2ce6eba79b6400fa833a9219d3669e9a11R1465 I'd appreciate it :D | |
| 17:14:08 | prometheanfire | atm I'm about to put in a bunch of debug statements | |
| 17:16:20 | sean-k-mooney | what is the errror you are seeing | |
| 17:16:45 | prometheanfire | traceback nova.exception.UEFINotSupported: UEFI is not supported | |
| 17:17:02 | prometheanfire | which tracks down to just that get_loader function | |
| 17:17:10 | gmann | dansmith: one more easy one https://review.opendev.org/c/openstack/osc-placement/+/819203 | |
| 17:17:35 | sean-k-mooney | prometheanfire: but that is coming form use parsing libvirt | |
| 17:17:52 | sean-k-mooney | prometheanfire: so that impleis qemu is sayign secure boot is not supproted on debian | |
| 17:18:24 | prometheanfire | the ovmf files are there, it used to work, I'll look some more, I didn't see any errors on the libvirt-daemon side | |
| 17:18:24 | sean-k-mooney | prometheanfire: can you paste the output of vrish capablities adn vrish domcaps | |
| 17:18:29 | prometheanfire | k | |
| 17:18:38 | dansmith | gmann: done | |
| 17:18:54 | gmann | dansmith: thanks | |
| 17:22:29 | prometheanfire | sean-k-mooney: capabilities https://gist.github.com/prometheanfire/adb89403ef70a11301b9cc45b040cd4e | |
| 17:23:40 | sean-k-mooney | ack looks liek the loader info is not in the main caps proably dom caps | |
| 17:23:41 | prometheanfire | sean-k-mooney: domcaps https://gist.github.com/prometheanfire/49bf656542cacbf8e37c275cb08ca27b | |
| 17:23:54 | sean-k-mooney | ok yes | |
| 17:24:01 | sean-k-mooney | https://gist.github.com/prometheanfire/49bf656542cacbf8e37c275cb08ca27b#file-gistfile1-txt-L10-L25 | |
| 17:24:16 | sean-k-mooney | so ya libvirt said secure no | |
| 17:24:22 | sean-k-mooney | https://gist.github.com/prometheanfire/49bf656542cacbf8e37c275cb08ca27b#file-gistfile1-txt-L23 | |
| 17:24:30 | prometheanfire | but I don't want secure boot | |
| 17:24:33 | sean-k-mooney | because the files it looked at are not the secure boot ones | |
| 17:24:44 | sean-k-mooney | oh right | |
| 17:24:51 | sean-k-mooney | am let me reead the patch | |
| 17:24:51 | prometheanfire | is nova only supporting secure boot for uefi now? | |
| 17:24:55 | prometheanfire | ack | |
| 17:25:19 | sean-k-mooney | well yes secure boot is only supprote with uefi but no you shoudl be able to use uefi without secure boot | |
| 17:25:32 | prometheanfire | cool | |
| 17:26:30 | prometheanfire | so, domcaps says I should support uefi guests, but only without secure boot, nova is saying that's not good enough, I think | |
| 17:26:37 | prometheanfire | (to summarize) | |
| 17:28:16 | sean-k-mooney | ya still readign the code it was out of my cache | |
| 17:28:22 | sean-k-mooney | but that i belvie is incorect | |
| 17:28:31 | sean-k-mooney | we should not require secure boot unless you ask for it | |
| 17:29:02 | opendevreview | Merged openstack/osc-placement master: Updating python testing as per Yoga testing runtime https://review.opendev.org/c/openstack/osc-placement/+/819203 | |
| 17:29:46 | prometheanfire | elsewhere in debug logs it says UEFI support detected | |
| 17:32:10 | sean-k-mooney | prometheanfire: ok so i don tthink the get_loader part is the issue | |
| 17:32:20 | sean-k-mooney | it _get_loaders i think | |
| 17:32:38 | sean-k-mooney | https://github.com/openstack/nova/commit/faad45b6323d7c52d35b7ccc45eacb5580b3b4d3#diff-67d0163175a798156def4ec53c18fa2ce6eba79b6400fa833a9219d3669e9a11R97 | |
| 17:32:49 | sean-k-mooney | you have <value>/usr/share/OVMF/OVMF_CODE.fd</value> | |
| 17:33:00 | sean-k-mooney | we are checking | |
| 17:33:02 | sean-k-mooney | '/usr/share/qemu/firmware', | |
| 17:33:04 | sean-k-mooney | '/etc/qemu/firmware', | |
| 17:33:35 | prometheanfire | you are only checking json there though? | |
| 17:33:35 | sean-k-mooney | well maybe that is not the issue actuly | |
| 17:34:07 | prometheanfire | logs don't show the error message either | |
| 17:36:06 | sean-k-mooney | prometheanfire: bacicly im curently looking back in that patch to see where we determin if its supported or not | |
| 17:36:10 | sean-k-mooney | uefi that is | |
| 17:36:49 | prometheanfire | ack | |
| 17:37:02 | sean-k-mooney | prometheanfire: we really should have test that assert this behavior using xml by the way | |
| 17:37:26 | sean-k-mooney | if we dont we can use your gist as the sameple data and and see if we can repoduce | |
| 17:37:58 | prometheanfire | ack | |
| 17:43:06 | prometheanfire | I think this is a problem in OSA for xena on buster (and maybe bullseye), ovmf in debian buster-backports includes json and secboot files | |
| 17:43:13 | prometheanfire | instance booted with that | |
| 17:44:07 | prometheanfire | sean-k-mooney: https://gist.github.com/prometheanfire/1e2414828d7904daa2c568653c70cd15 | |
| 17:44:30 | prometheanfire | spatel: ^ I think ovmf needs to be installed from backports on buster at least | |
| 17:45:08 | spatel | hmm | |
| 17:47:42 | spatel | sean-k-mooney i had this issue in nova error logs when i was trying to do secure boot - nova error Secure boot requires SMM feature enabled | |
| 17:48:23 | sean-k-mooney | well SMM is enabled by default be libvirt | |
| 17:48:28 | sean-k-mooney | and we do not specify it at all | |
| 17:48:35 | sean-k-mooney | so that seams like a libvirt bug | |
| 17:48:46 | sean-k-mooney | what prometheanfire is reporting is more extream | |
| 17:49:01 | sean-k-mooney | e.g. uefi just does not work on non redhat distos | |
| 17:49:39 | prometheanfire | sean-k-mooney: I THINK that the missing json file may be a cause | |
| 17:49:39 | EugenMayer | i have an instance which has a 'stuck image backup task' - is there any way to clean this up? | |
| 17:50:02 | prometheanfire | /usr/share/qemu/firmware/60-edk2-x86_64.json in the backports version vs not in the main version | |
| 17:50:57 | sean-k-mooney | prometheanfire: ya i think kashyap had a converation with the ubuntu deves at somepoint | |
| 17:51:14 | sean-k-mooney | looking at the code it does seam to be tryign to pasrse that instead fo gettign suff from libvirt | |
| 17:51:19 | sean-k-mooney | but im not really sure | |
| 18:03:30 | opendevreview | Lee Yarwood proposed openstack/nova master: func: Allow compute_driver to be set and used by _IntegratedTestBase https://review.opendev.org/c/openstack/nova/+/764484 | |
| 18:03:31 | opendevreview | Lee Yarwood proposed openstack/nova master: block_device_info: Add swap to inline https://review.opendev.org/c/openstack/nova/+/826523 | |
| 18:03:31 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Improve creating images INFO log https://review.opendev.org/c/openstack/nova/+/826524 | |
| 18:03:32 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: default by_name image_type to config correctly https://review.opendev.org/c/openstack/nova/+/826526 | |
| 18:03:32 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Remove defunct comment https://review.opendev.org/c/openstack/nova/+/826525 | |
| 18:03:33 | opendevreview | Lee Yarwood proposed openstack/nova master: BlockDeviceMapping: Add encryption fields https://review.opendev.org/c/openstack/nova/+/760453 | |
| 18:03:33 | opendevreview | Lee Yarwood proposed openstack/nova master: image_meta: Add ephemeral encryption properties https://review.opendev.org/c/openstack/nova/+/760454 | |
| 18:03:34 | opendevreview | Lee Yarwood proposed openstack/nova master: compute: Update bdms with ephemeral encryption details when requested https://review.opendev.org/c/openstack/nova/+/764486 | |
| 18:03:34 | opendevreview | Lee Yarwood proposed openstack/nova master: BlockDeviceMapping: Add is_local property https://review.opendev.org/c/openstack/nova/+/764485 | |
| 18:03:36 | opendevreview | Lee Yarwood proposed openstack/nova master: scheduler: Add an ephemeral encryption pre filter https://review.opendev.org/c/openstack/nova/+/760456 | |
| 18:03:36 | opendevreview | Lee Yarwood proposed openstack/nova master: virt: Add ephemeral encryption flag https://review.opendev.org/c/openstack/nova/+/760455 | |
| 18:03:38 | opendevreview | Lee Yarwood proposed openstack/nova master: block_device: Add encryption attributes to image and ephemeral disks https://review.opendev.org/c/openstack/nova/+/826528 | |
| 18:03:38 | opendevreview | Lee Yarwood proposed openstack/nova master: block_device: Add DriverImageBlockDevice to block_device_info https://review.opendev.org/c/openstack/nova/+/826527 | |
| 18:03:40 | opendevreview | Lee Yarwood proposed openstack/nova master: blockinfo: Add encryption details to the disk_info mappings when provided https://review.opendev.org/c/openstack/nova/+/772272 | |
| 18:03:40 | opendevreview | Lee Yarwood proposed openstack/nova master: virt: Add block_device_info helper to find encrypted disks https://review.opendev.org/c/openstack/nova/+/826529 | |
| 18:03:42 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 18:03:42 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: Add disk_info_mapping as an optional attribute of Image https://review.opendev.org/c/openstack/nova/+/826530 | |
| 18:03:44 | opendevreview | Lee Yarwood proposed openstack/nova master: privsep: Return QemuImgInfo objects from qemu-img info calls https://review.opendev.org/c/openstack/nova/+/826751 | |
| 18:03:44 | opendevreview | Lee Yarwood proposed openstack/nova master: privsep: Move qemu-img create calls under nova.privsep.qemu https://review.opendev.org/c/openstack/nova/+/826750 | |
| 18:03:46 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Report ephemeral encryption traits based on imagebackend https://review.opendev.org/c/openstack/nova/+/826753 | |
| 18:03:46 | opendevreview | Lee Yarwood proposed openstack/nova master: privsep: Add encryption support to qemu-img create command https://review.opendev.org/c/openstack/nova/+/826752 | |
| 18:03:48 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: Add support to libvirt_info for LUKS based encryption https://review.opendev.org/c/openstack/nova/+/826755 | |
| 18:03:48 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Configure and teardown ephemeral encryption secrets https://review.opendev.org/c/openstack/nova/+/826754 | |
| 18:03:50 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: Cache the key manager when disk is encrypted https://review.opendev.org/c/openstack/nova/+/826756 | |
| 18:05:28 | sean-k-mooney | prometheanfire: so can you see if adding the file will actully resolve this | |
| 18:05:58 | prometheanfire | sean-k-mooney: fix already deployed :| | |
| 18:06:08 | sean-k-mooney | ok so you are fixing via packaging | |
| 18:06:19 | prometheanfire | yep, ovmf from buster-backports | |
| 18:06:20 | sean-k-mooney | i think we might stil need to update the doc | |
| 18:06:46 | prometheanfire | probably | |
| 18:10:13 | EugenMayer | to 'unstuck from a stuck iamge backup task' i used 'nova reset-state` .. eventhough the task did not show up, i can neither restart the instance soft or hard. So somehow it is still in an undefined state. Any hint how to get out of this (alive :) ) | |
| 18:13:41 | ganso | Hi folks. I see that since Wallaby the option --live has been removed from the migrate command, therefore not providing a way to bypass the scheduler. I have a customer that is trying to evacuate a host for maintenance and is not able to evacuate because of the anti-affinity policy, therefore the scheduler needs to be bypassed. I've looked at the evacuate commands but I strongly suspect that they will not bypass the scheduler | |