| *** mhen_ is now known as mhen | 02:44 | |
| opendevreview | melanie witt proposed openstack/nova master: Refactor service user authentication https://review.opendev.org/c/openstack/nova/+/974267 | 04:01 |
|---|---|---|
| opendevreview | melanie witt proposed openstack/nova master: Refactor service user authentication https://review.opendev.org/c/openstack/nova/+/974267 | 05:04 |
| jkulik | melwitt: if you find some time, we'd appreciate a review on https://review.opendev.org/c/openstack/nova/+/699176 ("Faults from cell DB missing in GET /servers/detail") | 07:53 |
| opendevreview | Esra Ozkan proposed openstack/nova master: Fix Concurrent VM Live Migrate - Volume Backup Error https://review.opendev.org/c/openstack/nova/+/973750 | 07:56 |
| opendevreview | Taketani Ryo proposed openstack/nova master: mem-enc: stop using _get_mem_encryption_config() for SEV checks https://review.opendev.org/c/openstack/nova/+/967970 | 09:22 |
| opendevreview | Taketani Ryo proposed openstack/nova master: mem-enc: refactor memory encryption trait logic for extensiblity https://review.opendev.org/c/openstack/nova/+/967971 | 09:22 |
| opendevreview | Taketani Ryo proposed openstack/nova master: mem-enc: make RP creation independent of specific encryption models https://review.opendev.org/c/openstack/nova/+/967972 | 09:22 |
| opendevreview | Taketani Ryo proposed openstack/nova master: mem-enc: refactor _guest_configure_mem_encryption() for extensibility https://review.opendev.org/c/openstack/nova/+/967973 | 09:22 |
| opendevreview | Taketani Ryo proposed openstack/nova master: mem-enc: adjust requirement checks for mem_encryption guests https://review.opendev.org/c/openstack/nova/+/967974 | 09:22 |
| opendevreview | Taketani Ryo proposed openstack/nova master: mem-enc: introduce a check between mem_encryption and locked_memory https://review.opendev.org/c/openstack/nova/+/971300 | 09:22 |
| RomanHros[m] | Hello guys, I have the following problem.... (full message at <https://matrix.org/oftc/media/v1/media/download/ARKuyhvh_dMCVP_iifQ_N7pqYUCJHPZCCUZ85LfdunjJgzP7Ip4KsQrfsaTxfiLYItD4jSD9QFMw_X2sz8kxdQ1CecLR3rwQAG1hdHJpeC5vcmcvR3dDTXJQcUt1dXhKQ3hGSVJpcUZXb0hL>) | 09:24 |
| opendevreview | Balazs Gibizer proposed openstack/nova master: Libvirt event handling without eventlet https://review.opendev.org/c/openstack/nova/+/965949 | 09:45 |
| opendevreview | Balazs Gibizer proposed openstack/nova master: Run nova-compute in native threading mode https://review.opendev.org/c/openstack/nova/+/965467 | 09:45 |
| opendevreview | Balazs Gibizer proposed openstack/nova master: DNM:Test with oslo.vmware + compute eventlet removal patches https://review.opendev.org/c/openstack/nova/+/973468 | 09:45 |
| opendevreview | Balazs Gibizer proposed openstack/nova master: Prevent leaking RPC poller thread between tests https://review.opendev.org/c/openstack/nova/+/974299 | 09:45 |
| opendevreview | melanie witt proposed openstack/nova master: TPM: support instances with `deployment` secret security https://review.opendev.org/c/openstack/nova/+/942021 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: Add vtpm_secret_(uuid|value) to LibvirtLiveMigrateData https://review.opendev.org/c/openstack/nova/+/952628 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: TPM: prepare to bump service version for live migration https://review.opendev.org/c/openstack/nova/+/962051 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: TPM: support live migration of `host` secret security https://review.opendev.org/c/openstack/nova/+/941483 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: TPM: support live migration of `deployment` secret security https://review.opendev.org/c/openstack/nova/+/925771 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: TPM: test live migration between hosts with different security https://review.opendev.org/c/openstack/nova/+/952629 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: TPM: add late check for supported TPM secret security https://review.opendev.org/c/openstack/nova/+/956975 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: TPM: opt-in to new TPM secret security via resize https://review.opendev.org/c/openstack/nova/+/962052 | 11:40 |
| opendevreview | melanie witt proposed openstack/nova master: DNM vtpm tempest https://review.opendev.org/c/openstack/nova/+/957477 | 11:40 |
| opendevreview | Masanori Kuroha proposed openstack/nova master: Copy applied provider config https://review.opendev.org/c/openstack/nova/+/948304 | 12:35 |
| LarsErikP | hello! I've asked this before, but I would really love to have nova >= 31.1.0 in UCA. especially to get this fix: https://bugs.launchpad.net/nova/+bug/2098496 | 14:26 |
| LarsErikP | who do we talk to in order to get that going? | 14:27 |
| dansmith | someone at canonical I imagine, but not here | 14:29 |
| LarsErikP | right.. hmm | 14:31 |
| haleyb | LarsErikP: so you're asking about Epoxy? it's going EOL in April so doubtful to get a point release before that imo. we would typically do an SRU for a single change, but i haven't seen that one reported by a customer | 15:15 |
| LarsErikP | I've tried reach out to jamespage over on #ubuntu-server at least. We have just upgraded from Caracal to Epoxy, and encountered this... | 15:17 |
| haleyb | LarsErikP: james no longer works at canonical... | 15:18 |
| LarsErikP | oh... | 15:18 |
| LarsErikP | he was listed here :P https://documentation.ubuntu.com/project/SRU/reference/exception-OpenStack-Updates/ | 15:18 |
| LarsErikP | I guess, don't trust stuff you read on the internet | 15:19 |
| haleyb | i think only two of the people in that list still work here | 15:19 |
| LarsErikP | who? (A) | 15:19 |
| haleyb | well, i don't know who icey is to start | 15:20 |
| LarsErikP | james is the only one of them, that's actually present on #ubuntu-server right now :P | 15:21 |
| haleyb | right, and corey is at mozilla | 15:24 |
| haleyb | like i said, for epoxy there won't be much desire | 15:25 |
| melwitt | jkulik: thanks for the reminder, I will try to look soon | 16:36 |
| opendevreview | Lajos Katona proposed openstack/nova master: Use SDK for Neutron networks https://review.opendev.org/c/openstack/nova/+/928022 | 18:33 |
| Zhan[m] | while checking the live migration related stuff, I noticed that there are some features/params that are available on libvirt but not yet available in nova (e.g., additional auto converge params, compressions, etc.). I see recently that the parallel connection feature was added in https://review.opendev.org/c/openstack/nova/+/955784, so I'm thinking about just adding all features that are available on libvirt to nova. do we have plans | 20:07 |
| Zhan[m] | regarding this, or if not then maybe I can pick this up? thanks :D | 20:07 |
| dansmith | just because it's in libvirt doesn't necessarily mean it should be in nova, and also, we won't generally add things that are in versions of libvirt that are not yet in an enterprise distro | 20:28 |
| dansmith | best thing would be to identify important missing and relevant things and write a small spec explaining how they would be configured and what benefit they bring | 20:28 |
| Zhan[m] | make sense. in terms of the versions, I'm assuming I should check https://docs.openstack.org/nova/latest/reference/libvirt-distro-support-matrix.html? | 20:45 |
| dansmith | sure, but those are old, so best to look in the code to see what current master is currently targeting (which may be currently still set to the previous release) | 21:11 |
| opendevreview | Merged openstack/nova master: Prevent leaking RPC poller thread between tests https://review.opendev.org/c/openstack/nova/+/974299 | 21:25 |
| gmaan | melwitt: commented on vtpm 'deployment' security change ( 942021), am i missing something on testing the no-vtpm to/from vtpm resize ? they should be supported right? | 21:26 |
| melwitt | gmaan: cool thanks, I will look. basically all resizes are supported _except_ resizes that would need a change in secret ownership. 'deployment' secret owner is the nova service user, 'host' and 'user' secret owner is the normal user | 21:29 |
| melwitt | gmaan: there is a patch at the end of the series which enables resize from TPM 'deployment' => TPM 'host' or 'user' and TPM 'host' or 'user' => TPM 'deployment'. it's just initially not supported bc it is a lot of code and I suspect will be the most difficult part to review | 21:31 |
| gmaan | melwitt: I think that is ok but the test I pointed in review is asserting that the no-vtpm <-> 'deployement' is unsupported unless i missed to understand the tetst | 21:35 |
| melwitt | gmaan: ok I think the confusion is the difference between "instance has no TPM" and "instance has a TPM but secret_security=None bc the user didn't specify one" | 21:39 |
| melwitt | gmaan: if the instance has a TPM and the user did not specify a secret security type (i.e. secret_security=None) then they get the default policy of 'user' | 21:39 |
| melwitt | so TPM 'user' <=> TPM 'deployment' is not allowed for now. no TPM <=> TPM 'deployment' is allowed | 21:41 |
| Zhan[m] | dansmith: spot checking some features, the newest one I found (zlib/zstd compression) is in the NEXT_MIN_{LIBVIRT/QEMU}_VERSION of 2025.2, and it is also in Ubuntu Noble and Debian Trixie so I think it's cool. will run some tests to see how effective they are though. | 21:43 |
| dansmith | melwitt: ohh.. confusing | 21:43 |
| gmaan | melwitt: ohk, i missed to see 'hw:tpm_version' in extra spec of initial server creation. | 21:45 |
| melwitt | yeah. not sure if test names can be improved to something less confusing. at a minimum I could rewrite the docstrings to say more clearly if a test is about TPM <=> TPM vs no TPM <=> TPM | 21:45 |
| gmaan | yeah, that will be helpful, I think renaming test to test_resize_vtpm_server_secret_security_deployment_* can help (*_server* -> _vtpm_server*) | 21:47 |
| melwitt | sure, I can do those. thanks for suggesting | 21:49 |
| gmaan | thanks | 21:49 |
Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!