| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2022-01-27 | |||
| 17:18:24 | prometheanfire | the ovmf files are there, it used to work, I'll look some more, I didn't see any errors on the libvirt-daemon side | |
| 17:18:24 | sean-k-mooney | prometheanfire: can you paste the output of vrish capablities adn vrish domcaps | |
| 17:18:29 | prometheanfire | k | |
| 17:18:38 | dansmith | gmann: done | |
| 17:18:54 | gmann | dansmith: thanks | |
| 17:22:29 | prometheanfire | sean-k-mooney: capabilities https://gist.github.com/prometheanfire/adb89403ef70a11301b9cc45b040cd4e | |
| 17:23:40 | sean-k-mooney | ack looks liek the loader info is not in the main caps proably dom caps | |
| 17:23:41 | prometheanfire | sean-k-mooney: domcaps https://gist.github.com/prometheanfire/49bf656542cacbf8e37c275cb08ca27b | |
| 17:23:54 | sean-k-mooney | ok yes | |
| 17:24:01 | sean-k-mooney | https://gist.github.com/prometheanfire/49bf656542cacbf8e37c275cb08ca27b#file-gistfile1-txt-L10-L25 | |
| 17:24:16 | sean-k-mooney | so ya libvirt said secure no | |
| 17:24:22 | sean-k-mooney | https://gist.github.com/prometheanfire/49bf656542cacbf8e37c275cb08ca27b#file-gistfile1-txt-L23 | |
| 17:24:30 | prometheanfire | but I don't want secure boot | |
| 17:24:33 | sean-k-mooney | because the files it looked at are not the secure boot ones | |
| 17:24:44 | sean-k-mooney | oh right | |
| 17:24:51 | sean-k-mooney | am let me reead the patch | |
| 17:24:51 | prometheanfire | is nova only supporting secure boot for uefi now? | |
| 17:24:55 | prometheanfire | ack | |
| 17:25:19 | sean-k-mooney | well yes secure boot is only supprote with uefi but no you shoudl be able to use uefi without secure boot | |
| 17:25:32 | prometheanfire | cool | |
| 17:26:30 | prometheanfire | so, domcaps says I should support uefi guests, but only without secure boot, nova is saying that's not good enough, I think | |
| 17:26:37 | prometheanfire | (to summarize) | |
| 17:28:16 | sean-k-mooney | ya still readign the code it was out of my cache | |
| 17:28:22 | sean-k-mooney | but that i belvie is incorect | |
| 17:28:31 | sean-k-mooney | we should not require secure boot unless you ask for it | |
| 17:29:02 | opendevreview | Merged openstack/osc-placement master: Updating python testing as per Yoga testing runtime https://review.opendev.org/c/openstack/osc-placement/+/819203 | |
| 17:29:46 | prometheanfire | elsewhere in debug logs it says UEFI support detected | |
| 17:32:10 | sean-k-mooney | prometheanfire: ok so i don tthink the get_loader part is the issue | |
| 17:32:20 | sean-k-mooney | it _get_loaders i think | |
| 17:32:38 | sean-k-mooney | https://github.com/openstack/nova/commit/faad45b6323d7c52d35b7ccc45eacb5580b3b4d3#diff-67d0163175a798156def4ec53c18fa2ce6eba79b6400fa833a9219d3669e9a11R97 | |
| 17:32:49 | sean-k-mooney | you have <value>/usr/share/OVMF/OVMF_CODE.fd</value> | |
| 17:33:00 | sean-k-mooney | we are checking | |
| 17:33:02 | sean-k-mooney | '/usr/share/qemu/firmware', | |
| 17:33:04 | sean-k-mooney | '/etc/qemu/firmware', | |
| 17:33:35 | prometheanfire | you are only checking json there though? | |
| 17:33:35 | sean-k-mooney | well maybe that is not the issue actuly | |
| 17:34:07 | prometheanfire | logs don't show the error message either | |
| 17:36:06 | sean-k-mooney | prometheanfire: bacicly im curently looking back in that patch to see where we determin if its supported or not | |
| 17:36:10 | sean-k-mooney | uefi that is | |
| 17:36:49 | prometheanfire | ack | |
| 17:37:02 | sean-k-mooney | prometheanfire: we really should have test that assert this behavior using xml by the way | |
| 17:37:26 | sean-k-mooney | if we dont we can use your gist as the sameple data and and see if we can repoduce | |
| 17:37:58 | prometheanfire | ack | |
| 17:43:06 | prometheanfire | I think this is a problem in OSA for xena on buster (and maybe bullseye), ovmf in debian buster-backports includes json and secboot files | |
| 17:43:13 | prometheanfire | instance booted with that | |
| 17:44:07 | prometheanfire | sean-k-mooney: https://gist.github.com/prometheanfire/1e2414828d7904daa2c568653c70cd15 | |
| 17:44:30 | prometheanfire | spatel: ^ I think ovmf needs to be installed from backports on buster at least | |
| 17:45:08 | spatel | hmm | |
| 17:47:42 | spatel | sean-k-mooney i had this issue in nova error logs when i was trying to do secure boot - nova error Secure boot requires SMM feature enabled | |
| 17:48:23 | sean-k-mooney | well SMM is enabled by default be libvirt | |
| 17:48:28 | sean-k-mooney | and we do not specify it at all | |
| 17:48:35 | sean-k-mooney | so that seams like a libvirt bug | |
| 17:48:46 | sean-k-mooney | what prometheanfire is reporting is more extream | |
| 17:49:01 | sean-k-mooney | e.g. uefi just does not work on non redhat distos | |
| 17:49:39 | prometheanfire | sean-k-mooney: I THINK that the missing json file may be a cause | |
| 17:49:39 | EugenMayer | i have an instance which has a 'stuck image backup task' - is there any way to clean this up? | |
| 17:50:02 | prometheanfire | /usr/share/qemu/firmware/60-edk2-x86_64.json in the backports version vs not in the main version | |
| 17:50:57 | sean-k-mooney | prometheanfire: ya i think kashyap had a converation with the ubuntu deves at somepoint | |
| 17:51:14 | sean-k-mooney | looking at the code it does seam to be tryign to pasrse that instead fo gettign suff from libvirt | |
| 17:51:19 | sean-k-mooney | but im not really sure | |
| 18:03:30 | opendevreview | Lee Yarwood proposed openstack/nova master: func: Allow compute_driver to be set and used by _IntegratedTestBase https://review.opendev.org/c/openstack/nova/+/764484 | |
| 18:03:31 | opendevreview | Lee Yarwood proposed openstack/nova master: block_device_info: Add swap to inline https://review.opendev.org/c/openstack/nova/+/826523 | |
| 18:03:31 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Improve creating images INFO log https://review.opendev.org/c/openstack/nova/+/826524 | |
| 18:03:32 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: default by_name image_type to config correctly https://review.opendev.org/c/openstack/nova/+/826526 | |
| 18:03:32 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Remove defunct comment https://review.opendev.org/c/openstack/nova/+/826525 | |
| 18:03:33 | opendevreview | Lee Yarwood proposed openstack/nova master: BlockDeviceMapping: Add encryption fields https://review.opendev.org/c/openstack/nova/+/760453 | |
| 18:03:33 | opendevreview | Lee Yarwood proposed openstack/nova master: image_meta: Add ephemeral encryption properties https://review.opendev.org/c/openstack/nova/+/760454 | |
| 18:03:34 | opendevreview | Lee Yarwood proposed openstack/nova master: compute: Update bdms with ephemeral encryption details when requested https://review.opendev.org/c/openstack/nova/+/764486 | |
| 18:03:34 | opendevreview | Lee Yarwood proposed openstack/nova master: BlockDeviceMapping: Add is_local property https://review.opendev.org/c/openstack/nova/+/764485 | |
| 18:03:36 | opendevreview | Lee Yarwood proposed openstack/nova master: scheduler: Add an ephemeral encryption pre filter https://review.opendev.org/c/openstack/nova/+/760456 | |
| 18:03:36 | opendevreview | Lee Yarwood proposed openstack/nova master: virt: Add ephemeral encryption flag https://review.opendev.org/c/openstack/nova/+/760455 | |
| 18:03:38 | opendevreview | Lee Yarwood proposed openstack/nova master: block_device: Add encryption attributes to image and ephemeral disks https://review.opendev.org/c/openstack/nova/+/826528 | |
| 18:03:38 | opendevreview | Lee Yarwood proposed openstack/nova master: block_device: Add DriverImageBlockDevice to block_device_info https://review.opendev.org/c/openstack/nova/+/826527 | |
| 18:03:40 | opendevreview | Lee Yarwood proposed openstack/nova master: blockinfo: Add encryption details to the disk_info mappings when provided https://review.opendev.org/c/openstack/nova/+/772272 | |
| 18:03:40 | opendevreview | Lee Yarwood proposed openstack/nova master: virt: Add block_device_info helper to find encrypted disks https://review.opendev.org/c/openstack/nova/+/826529 | |
| 18:03:42 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Introduce support for qcow2 with LUKS https://review.opendev.org/c/openstack/nova/+/772273 | |
| 18:03:42 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: Add disk_info_mapping as an optional attribute of Image https://review.opendev.org/c/openstack/nova/+/826530 | |
| 18:03:44 | opendevreview | Lee Yarwood proposed openstack/nova master: privsep: Return QemuImgInfo objects from qemu-img info calls https://review.opendev.org/c/openstack/nova/+/826751 | |
| 18:03:44 | opendevreview | Lee Yarwood proposed openstack/nova master: privsep: Move qemu-img create calls under nova.privsep.qemu https://review.opendev.org/c/openstack/nova/+/826750 | |
| 18:03:46 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Report ephemeral encryption traits based on imagebackend https://review.opendev.org/c/openstack/nova/+/826753 | |
| 18:03:46 | opendevreview | Lee Yarwood proposed openstack/nova master: privsep: Add encryption support to qemu-img create command https://review.opendev.org/c/openstack/nova/+/826752 | |
| 18:03:48 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: Add support to libvirt_info for LUKS based encryption https://review.opendev.org/c/openstack/nova/+/826755 | |
| 18:03:48 | opendevreview | Lee Yarwood proposed openstack/nova master: libvirt: Configure and teardown ephemeral encryption secrets https://review.opendev.org/c/openstack/nova/+/826754 | |
| 18:03:50 | opendevreview | Lee Yarwood proposed openstack/nova master: imagebackend: Cache the key manager when disk is encrypted https://review.opendev.org/c/openstack/nova/+/826756 | |
| 18:05:28 | sean-k-mooney | prometheanfire: so can you see if adding the file will actully resolve this | |
| 18:05:58 | prometheanfire | sean-k-mooney: fix already deployed :| | |
| 18:06:08 | sean-k-mooney | ok so you are fixing via packaging | |
| 18:06:19 | prometheanfire | yep, ovmf from buster-backports | |
| 18:06:20 | sean-k-mooney | i think we might stil need to update the doc | |
| 18:06:46 | prometheanfire | probably | |
| 18:10:13 | EugenMayer | to 'unstuck from a stuck iamge backup task' i used 'nova reset-state` .. eventhough the task did not show up, i can neither restart the instance soft or hard. So somehow it is still in an undefined state. Any hint how to get out of this (alive :) ) | |
| 18:13:41 | ganso | Hi folks. I see that since Wallaby the option --live has been removed from the migrate command, therefore not providing a way to bypass the scheduler. I have a customer that is trying to evacuate a host for maintenance and is not able to evacuate because of the anti-affinity policy, therefore the scheduler needs to be bypassed. I've looked at the evacuate commands but I strongly suspect that they will not bypass the scheduler | |
| 18:13:55 | ganso | Is there any other way to bypass the scheduler? | |
| 18:16:52 | EugenMayer | ganso there was a hack i got told, but i forgot about it (had the same question). I ended up backing up the instance and restoring it with the other affinity policy, the moving it to the new host during the restore | |
| 18:17:36 | ganso | EugenMayer: thanks! unfortunately the instance cannot be shutdown :\ | |
| 18:17:37 | EugenMayer | All in one, comparing to what i know from k8s, affinity policies in openstack are really clunky since changing the basically means 'rebuilding the instance' | |
| 18:17:54 | EugenMayer | ganso well, no clue then, sorry | |
| 18:18:24 | ganso | EugenMayer: yea the instance cannot be removed from the group, it is only added to the group when it is created and removed only when deleted... I'm trying to avoid DB surgery | |
| 18:19:22 | EugenMayer | ah i remember what it was, i think you just downgrade the API level in the cli and force the parameter anyway - i think that was it | |
| 18:19:34 | EugenMayer | you should test that though - do not trust me :) | |