| opendevreview | Bhavana proposed openstack/nova-specs master: Add spec for minimal-displacement MIG repartitioning https://review.opendev.org/c/openstack/nova-specs/+/996055 | 05:35 |
|---|---|---|
| opendevreview | Bhavana proposed openstack/nova master: Add Minimal Displacement Solver for MIG GPU Repartitioning https://review.opendev.org/c/openstack/nova/+/996058 | 06:54 |
| opendevreview | Thibaut Démaret proposed openstack/nova master: libvirt: add disk rotation_rate support for local disks https://review.opendev.org/c/openstack/nova/+/979693 | 07:12 |
| opendevreview | Ashish Gupta proposed openstack/nova master: tests: file-backed SQLite with WAL in threading mode for Database and CellDatabases Fixtures https://review.opendev.org/c/openstack/nova/+/988583 | 07:35 |
| Uggla | Hi gibi and bauzas, I will be on PTO for the next 3 weeks. Would you be able to run the upstream meeting on my behalf? | 08:28 |
| bauzas | I can do it | 08:41 |
| bauzas | maybe not on July 13th tho, I'll probably take the day off | 08:41 |
| bauzas | but that's something we can discuss | 08:41 |
| gibi | I can take July 13th if you take the others :) | 08:45 |
| bauzas | heh, looks like we have a plan ;) | 08:45 |
| gibi | OK | 08:45 |
| *** ykarel_ is now known as ykarel | 08:59 | |
| Uggla | gibi, bauzas thanks I'll update the agenda accordingly. | 09:05 |
| opendevreview | sean mooney proposed openstack/nova master: Add vTPM startup validation reproducer https://review.opendev.org/c/openstack/nova/+/990551 | 09:32 |
| opendevreview | sean mooney proposed openstack/nova master: Limit startup instance processing to libvirt https://review.opendev.org/c/openstack/nova/+/990552 | 09:32 |
| opendevreview | sean mooney proposed openstack/nova master: Reduce ProviderTree copy cost for Ironic https://review.opendev.org/c/openstack/nova/+/980676 | 09:32 |
| opendevreview | sean mooney proposed openstack/nova master: Parallelize per-node resource updates https://review.opendev.org/c/openstack/nova/+/980679 | 09:32 |
| opendevreview | sean mooney proposed openstack/nova master: perf: add ironic startup performance simulator https://review.opendev.org/c/openstack/nova/+/980641 | 09:32 |
| opendevreview | sean mooney proposed openstack/nova master: docs: add Ironic startup performance measurements https://review.opendev.org/c/openstack/nova/+/980680 | 09:32 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: Update documentations for AMD SEV-SNP support https://review.opendev.org/c/openstack/nova/+/995090 | 09:46 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: Remove [libvirt] num_memory_encrypted_guests https://review.opendev.org/c/openstack/nova/+/995120 | 09:46 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: Fix wrong comment in test https://review.opendev.org/c/openstack/nova/+/996070 | 09:49 |
| opendevreview | Ashish Gupta proposed openstack/nova master: tests: use file-backed Placement SQLite in functional threading https://review.opendev.org/c/openstack/nova/+/992581 | 09:51 |
| opendevreview | Bhavana proposed openstack/nova master: Add Minimal Displacement Solver for MIG GPU Repartitioning https://review.opendev.org/c/openstack/nova/+/996058 | 10:30 |
| opendevreview | Ashish Gupta proposed openstack/nova master: tests: Use per-database write locks instead of global lock https://review.opendev.org/c/openstack/nova/+/992862 | 10:39 |
| *** chandank` is now known as chandankumar | 11:21 | |
| tkajinam | gibi, thanks a lot for reviews and tests ! | 11:58 |
| gibi | tkajinam: thanks for the patches. I'm happy that we made a quick progress on SNP | 12:01 |
| tkajinam | yeah :-D | 12:01 |
| tkajinam | though it has been a long way for me, though, because SEV-SNP support has been the ultimate goal for me since I touched my initial work to support SEV-ES | 12:02 |
| tkajinam | but finally we are close to complete that long journey, hopefully | 12:03 |
| sean-k-mooney | tkajinam: we were talking about locked memory last week, i remembered at the weekend why we limited it to hugepages | 12:20 |
| sean-k-mooney | tkajinam: locked memory cannot be swapped | 12:20 |
| sean-k-mooney | tkajinam: so we limited it to hugepages becasuse hugepages cannot be overcommited | 12:20 |
| sean-k-mooney | if you use locked memory with out hugepageas and you memory allocation ration is > 1.0 | 12:20 |
| sean-k-mooney | then you will have OOM events | 12:20 |
| sean-k-mooney | so while it can work for non hugepage memory i.e hw:mem_page_size=small we require you to enabel the numa aware memory trackign which disables oversubsction to use it to prevent OOM events | 12:21 |
| sean-k-mooney | so it could work wiht annoumus memory but its not safe to use it that way unless you acount for it via ram allcoation ratio | 12:22 |
| sean-k-mooney | that was why that limitation exits today | 12:22 |
| sean-k-mooney | tkajinam: anyway that should not impact th sev-snp work just the background context the current design choice | 12:23 |
| sean-k-mooney | gmaan: as an fyi i somethime see test_cold_migration_dest_compute_graceful_shutdown fila in the the functional/coverage tests | 12:40 |
| sean-k-mooney | https://storage.bhs.cloud.ovh.net/v1/AUTH_dcaab5e32b234d56b626f72581e3644c/zuul_opendev_logs_dc2/openstack/dc227da7383b4f62ab0731d251d86e2f/testr_results.html | 12:41 |
| sean-k-mooney | so that may be unstable in some caes | 12:41 |
| opendevreview | sean mooney proposed openstack/nova master: Parallelize per-node resource updates https://review.opendev.org/c/openstack/nova/+/980679 | 12:50 |
| opendevreview | sean mooney proposed openstack/nova master: perf: add ironic startup performance simulator https://review.opendev.org/c/openstack/nova/+/980641 | 12:50 |
| opendevreview | sean mooney proposed openstack/nova master: docs: add Ironic startup performance measurements https://review.opendev.org/c/openstack/nova/+/980680 | 12:50 |
| *** haleyb|out is now known as haleyb | 13:07 | |
| tkajinam | sean-k-mooney, ah ok. thanks for sharing that context. | 13:08 |
| gibi | gmaan: bauzas: could one of take a look at this eventlet config patch https://review.opendev.org/c/openstack/nova/+/993760 this would be a helpful addition to our downstream performance testing efforts | 14:03 |
| gibi | also, do you think it would make sense / possible to backport this to Gazpacho? (not super important as it seems downstream folks are building from master directly, so I'm just curious what you think): | 14:05 |
| tkajinam | sean-k-mooney, I'm now reading your comment in https://review.opendev.org/c/openstack/nova/+/995835 ... I was thinking of rejecting usage of hw_firmware_stateles for bios boot because bios does support stateless/stateful concept and it's always stateless and am wondering what you think about it. | 14:15 |
| sean-k-mooney | i dont thin that is a good idea | 14:16 |
| sean-k-mooney | i think we shoudl only look at it if its uefi | 14:16 |
| sean-k-mooney | becuase if anywon has set both today we dont want to break them when they upgrae | 14:17 |
| sean-k-mooney | we have not been enforcing that restiction before correct? so enforcing it now would have an upgrade impact | 14:17 |
| sean-k-mooney | if we had enforced it when we intoduced it it woudl have been fine | 14:18 |
| sean-k-mooney | and perhaps correct | 14:18 |
| sean-k-mooney | but unless we fix the existign instance on nova-compute startup that going to be problematic i think | 14:19 |
| sean-k-mooney | if we enfoce it now then if you have an image with bios and stateless configured to any value then resize will fail | 14:19 |
| sean-k-mooney | and either an operator will need to fix it with nova-manage or you will need to rebuild | 14:20 |
| sean-k-mooney | so the best i think we can do is log a warning | 14:20 |
| tkajinam | that's correct, though the existing instance may have only bios boot with firmware_stateless=False which is incorrect | 14:20 |
| tkajinam | ok | 14:20 |
| tkajinam | I'll drop the validation and then add a warning message there | 14:20 |
| opendevreview | Ashish Gupta proposed openstack/nova master: tests: file-backed SQLite with WAL in threading mode for Database and CellDatabases Fixtures https://review.opendev.org/c/openstack/nova/+/988583 | 14:52 |
| opendevreview | Ashish Gupta proposed openstack/nova master: tests: use file-backed Placement SQLite in functional threading https://review.opendev.org/c/openstack/nova/+/992581 | 14:56 |
| Uggla | Reminder: upstream meeting in ~ 1h | 14:58 |
| opendevreview | Ashish Gupta proposed openstack/nova master: tests: Use per-database write locks instead of global lock https://review.opendev.org/c/openstack/nova/+/992862 | 15:04 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: Accept hw_firmware_stateless=True for BIOS firmware type https://review.opendev.org/c/openstack/nova/+/995835 | 15:25 |
| mhen | tkajinam: I won't be able to attend today's meeting but I'll see if I can do some tinkering with my SEV-SNP node tomorrow regarding my comment in https://review.opendev.org/c/openstack/nova/+/994930 and report back | 15:26 |
| tkajinam | mhen, thanks | 15:27 |
| tkajinam | mhen, if libvirt isn't able to correct the correct rom firmware then I suspect something is still wrong in libvirt firmware detection or descriptor file | 15:28 |
| tkajinam | the selection logic was updated to treat type: rom as stateless so stateless=true should trigger usage of type: rom (unless nothing else is selected) | 15:28 |
| tkajinam | I suspect there is still a legacy descriptor file with sev-snp I have to check which firmware is actually selected and how its descriptor looks like | 15:29 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: compute: Validate SEV/SEV-ES support at start up https://review.opendev.org/c/openstack/nova/+/994342 | 15:30 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: libvirt: Ignore SEV-ES when SEV-SNP is detected https://review.opendev.org/c/openstack/nova/+/994343 | 15:31 |
| opendevreview | Merged openstack/nova master: Return 400 for invalid properties for locked memory https://review.opendev.org/c/openstack/nova/+/995813 | 15:43 |
| Uggla | #startmeeting nova | 16:00 |
| opendevmeet | Meeting started Mon Jul 6 16:00:45 2026 UTC and is due to finish in 60 minutes. The chair is Uggla. Information about MeetBot at http://wiki.debian.org/MeetBot. | 16:00 |
| opendevmeet | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 16:00 |
| opendevmeet | The meeting name has been set to 'nova' | 16:00 |
| Uggla | Hello everyone | 16:00 |
| fwiesel | o/ | 16:01 |
| tkajinam | o/ | 16:01 |
| * gibi is distracted | 16:01 | |
| sambork | o/ | 16:02 |
| Uggla | Let's start | 16:02 |
| Uggla | #topic Bugs (stuck/critical) | 16:02 |
| Uggla | #info No Critical bug | 16:02 |
| Uggla | #topic Gate status | 16:03 |
| Uggla | #link https://bugs.launchpad.net/nova/+bugs?field.tag=gate-failure Nova gate bugs | 16:03 |
| Uggla | #link https://etherpad.opendev.org/p/nova-ci-failures-minimal | 16:03 |
| Uggla | #link https://zuul.openstack.org/builds?project=openstack%2Fnova&project=openstack%2Fplacement&branch=stable%2F*&branch=master&pipeline=periodic-weekly&skip=0 Nova&Placement periodic jobs status | 16:03 |
| Uggla | #info Please look at the gate failures and file a bug report with the gate-failure tag. | 16:03 |
| Uggla | #info Please try to provide a meaningful comment when you recheck | 16:03 |
| Uggla | Looking quickly at the gate, that looks ok. Please tell me if I'm wrong. | 16:04 |
| Uggla | #topic Release Planning | 16:05 |
| Uggla | #link https://releases.openstack.org/hibiscus/schedule.html | 16:05 |
| Uggla | #info Nova deadlines are set in the above schedule | 16:05 |
| Uggla | #info PTG etherpad for 2026.2 is available: https://etherpad.opendev.org/p/nova-2026.2-ptg | 16:05 |
| bauzas | o/ | 16:05 |
| Uggla | Nothing special on planning, we are ~5 weeks before Nova implementation review day | 16:06 |
| Uggla | #topic Review priorities | 16:06 |
| Uggla | #link New file for Hibiscus https://etherpad.opendev.org/p/nova-2026.2-status | 16:06 |
| Uggla | #info I have updated Launchpad and the above doc. Please ping me if you spot something missing. | 16:06 |
| Uggla | #info Starting: https://etherpad.opendev.org/p/nova-2026.2-status#L16 interesting bugs to review. | 16:06 |
| Uggla | Skipping Elod points because he is on pto | 16:07 |
| Uggla | #topic vmwareapi 3rd-party CI efforts Highlights | 16:07 |
| Uggla | fwiesel something you'd like to share. | 16:07 |
| fwiesel | Hi | 16:07 |
| fwiesel | I'm investigating recent failures in the pipeline. | 16:07 |
| fwiesel | I haven't gotten quite hold of the root cause yet | 16:07 |
| fwiesel | Bear with me, i hope I'll get it fixed tomorrow | 16:08 |
| fwiesel | That's from my side | 16:08 |
| Uggla | fwiesel 👍 | 16:08 |
| Uggla | thx | 16:09 |
| sean-k-mooney | o/ | 16:09 |
| Uggla | #topic Kamil's news about eventlet removal | 16:09 |
| * Uggla giving the mic to sambork or gibi | 16:09 | |
| sambork | So today we almost landed changes that add a config option to run with eventlet/threading mode. As a segue from that, we should have data from the performance run with logs in the next few days. The first run indicates a probable degradation in the rally tests. Other than that, Ashish made progress with the unit testing patches (https://review.opendev.org/c/openstack/nova/+/992862, https://review.opendev.org/c/openstack/nova/+/992581, | 16:10 |
| sambork | https://review.opendev.org/c/openstack/nova/+/988583, https://review.opendev.org/c/openstack/placement/+/993106) | 16:10 |
| sambork | I think thats i,t we didn't progress with anything else, and I give mic back (or maybe gibi have something to add) | 16:11 |
| gibi | I started looking at the functional test series from Ashish again today but I will need more time to have comments there | 16:11 |
| gibi | nothing else | 16:11 |
| Uggla | thanks sambork and gibi | 16:12 |
| Uggla | skipping Layos topic | 16:12 |
| Uggla | #topic Ironic review priorities | 16:12 |
| Uggla | cardoe do you have something ot share with us ? | 16:13 |
| cardoe | We've rebased the startup-time series at https://review.opendev.org/q/topic:%22startup-time%22 | 16:13 |
| cardoe | The spec for trunk ports in the metadata is still ready to go as well as are the patches. | 16:14 |
| cardoe | But that's all I've got. | 16:14 |
| Uggla | thanks cardoe | 16:14 |
| Uggla | #topic Confidential computing, status of SNP and TDX features | 16:14 |
| * Uggla giving the mic to tkajinam and antia | 16:15 | |
| Uggla | and gibi | 16:15 |
| antia | Resuming development this week, was on PTO last week | 16:15 |
| gibi | antia: welcome back :) | 16:16 |
| tkajinam | The implementations for SEV-SNP are still up for review. gibi already provided review many feedbacks and also completed the end to end testing (thanks a lot !!) | 16:16 |
| Uggla | 👍 | 16:17 |
| gibi | yeah for me that series looks good | 16:17 |
| tkajinam | gibi, just fyi. there is a problem pointed by sean in one of the base changes. I fixed it but I have to rebase the other changes later. | 16:18 |
| bauzas | yeah I started to look at the series | 16:18 |
| tkajinam | there are a few more feedbacks by sean-k-mooney I still have to check. I'm afraid it might be quite tricky to address these cleanly soon, and might need some more discussions to find out a good balance. | 16:18 |
| bauzas | thanks tkajinam I'll continue to review then | 16:18 |
| tkajinam | bauzas, thanks ! | 16:18 |
| sean-k-mooney | tkajinam: libvirt has the snp cpaablity in domain caps | 16:19 |
| sean-k-mooney | ill post an xml dump of that shortly | 16:19 |
| gibi | tkajinam: ack, I can do a quick re-test tomorrow. But then I have to give the HW back | 16:19 |
| tkajinam | sean-k-mooney, no it does not reflect actual cpu feature. | 16:19 |
| tkajinam | sean-k-mooney, it only shows whether libvirt supports it. | 16:19 |
| sean-k-mooney | ok but chekcing kernel option or proc is not ok | 16:19 |
| tkajinam | we should detect snp is enabled in bios, then appears in cpu flag | 16:19 |
| sean-k-mooney | so if we cant trust libvirt when it reports it | 16:20 |
| sean-k-mooney | then 1 that is a bug that shoudl be fixed in libvirt | 16:20 |
| sean-k-mooney | and 2 we woudl need a config option in nova | 16:20 |
| sean-k-mooney | it repots | 16:20 |
| sean-k-mooney | <launchSecurity supported='yes'> | 16:20 |
| sean-k-mooney | <enum name='sectype'> | 16:20 |
| sean-k-mooney | <value>sev</value> | 16:20 |
| sean-k-mooney | <value>sev-snp</value> | 16:20 |
| sean-k-mooney | </enum> | 16:20 |
| sean-k-mooney | </launchSecurity> | 16:20 |
| sean-k-mooney | <value>sev-snp</value> should not be there if the host is not configure for snp | 16:20 |
| tkajinam | the tricky point is that we should catch the case that sev-snp is enabled in firmware, but is not in kernel/qemu/libvirt | 16:21 |
| sean-k-mooney | not in nova | 16:21 |
| tkajinam | because enabling sev-snp in firmware immediately prohibits sev-es | 16:21 |
| sean-k-mooney | that is what libvirt is ment to be doing with that api | 16:21 |
| tkajinam | but kernel still reports sev_es is available which is annoying | 16:21 |
| gibi | (I like the CVE :) | 16:21 |
| sean-k-mooney | sure but libvirt does not | 16:22 |
| bauzas | fwiw we discussed that in the spec | 16:22 |
| sean-k-mooney | well it reqport generic sev which i guess we might be proxiting | 16:22 |
| sean-k-mooney | bauzas: we have rejected parsinc /proc before | 16:22 |
| sean-k-mooney | so i dont knwo why we woudl allow it now | 16:22 |
| bauzas | we said that the BIOS option is the difference between whether we support SNP or ES | 16:23 |
| bauzas | so, if the operator modified the bios option, then the system supports SNP and that's it | 16:23 |
| sean-k-mooney | ok so then nova does not need to check for this right | 16:23 |
| bauzas | correct | 16:23 |
| bauzas | that's what we agreed on the spec at least | 16:24 |
| sean-k-mooney | so if livbirt has sev-snp in the lauch capabliteis | 16:24 |
| sean-k-mooney | we should just report the trait | 16:24 |
| bauzas | we don't need to look at the firmware, because even if the firmware can support SNP, the host won't use this until the BIOS is modified | 16:24 |
| sean-k-mooney | and if the operator has not enabeld snp but did create snp flavors | 16:24 |
| sean-k-mooney | then we expect the vm boot to fail | 16:24 |
| gibi | it is about the fact the ES support disappears after that specific firmware upgrade and you can still have ES VMs on thehost | 16:25 |
| bauzas | libvirt provides SNP capabilities only once the BIOS option is modified | 16:25 |
| gibi | the complication is not about SNP, but the disappearence of ES | 16:25 |
| sean-k-mooney | bauzas: ack in that case then we jsut need to look at the libvirt output | 16:25 |
| bauzas | gibi: AFAICU, the ES support continues until the BIOS option is modified, that's my point | 16:25 |
| bauzas | tkajinam: am I right? | 16:26 |
| gibi | if you had a host with both ES and SNP enabled, and then update the firmware, ES disappears without BIOS changes | 16:26 |
| gibi | * BIOS config changes | 16:26 |
| bauzas | because you enabled SNP | 16:26 |
| tkajinam | bauzas, the problem is that /proc/cpuinfo is only the feasible way I could find to detect "the BIOS option is modified" | 16:26 |
| sean-k-mooney | well the sev section has | 16:26 |
| sean-k-mooney | <sev supported='yes'> | 16:26 |
| sean-k-mooney | <cbitpos>51</cbitpos> | 16:26 |
| gibi | bauzas: because you updated the firmware to fix a CVE | 16:26 |
| sean-k-mooney | <reducedPhysBits>1</reducedPhysBits> | 16:26 |
| sean-k-mooney | <maxGuests>500</maxGuests> | 16:26 |
| sean-k-mooney | <maxESGuests>9</maxESGuests> | 16:26 |
| sean-k-mooney | <cpu0Id>LlF/9YPV8hnqsGNCBpLJeRUbm9y/yr5uNhgTaW96/ZVoYXjZRRuIfEwSMFWWd9882pcNDLW6LW3E3tytpU7/2g==</cpu0Id> | 16:26 |
| sean-k-mooney | </sev> | 16:26 |
| sean-k-mooney | the max es gust is still reproted in snp mode | 16:26 |
| sean-k-mooney | but i think we need to look at the combidntion fo the lauchsecurit section and the sev section | 16:27 |
| gibi | beacuse the same set of ASIDs are used for ES and SNP | 16:27 |
| gibi | but a different set used for pure SEV | 16:27 |
| gibi | btw that CVE fix is actually good for us as we don't have to share resources between ES and SNP | 16:28 |
| bauzas | gibi: well, that's another concern, if the operator enabled SNP in the BIOS and then upgraded the firmware due to the CVE, they should know that ES is then disabled automatically | 16:28 |
| gibi | bauzas: | 16:28 |
| bauzas | that's unrelated to nova, right? | 16:28 |
| gibi | but nova has ES VMs on the host :): | 16:28 |
| gibi | so we cannot ignore it | 16:28 |
| tkajinam | bauzas, yes and that's why /proc/cpuflag is checked, because at that point sev-snp is not yet enabled in kvm ( so nova assumes sev-snp is not ready ) | 16:29 |
| bauzas | I think I wrote a spec comment saying about when we restart the compute | 16:29 |
| sean-k-mooney | gibi: do you happen to know if the host you are testing on has the firmware patch | 16:29 |
| bauzas | we can look at the instances and stop the service if we find ES-used instances | 16:29 |
| gibi | it has. It is not possible to boot ES VMs on it | 16:29 |
| gibi | qemu fails | 16:29 |
| tkajinam | https://review.opendev.org/c/openstack/nova/+/994343 | 16:30 |
| sean-k-mooney | ok and does it work with snp disabled | 16:30 |
| tkajinam | this is the actual change where this is being discussed | 16:30 |
| gibi | sean-k-mooney: I don't know that | 16:30 |
| sean-k-mooney | i dont think this is an upgrede concern for nova yet | 16:30 |
| sean-k-mooney | since nova didnt supprot snp before this firmware change | 16:30 |
| gibi | but it did support ES | 16:30 |
| sean-k-mooney | so we just need to document that operator can use oen of the other | 16:30 |
| sean-k-mooney | gibi: right if they flat out broke es with the cve fix | 16:30 |
| tkajinam | so reading actual implementation may give clearer view about the topic. | 16:31 |
| sean-k-mooney | that woudl be a problem but if it works just not when snp is enabeld in teh bios its not an upgrade probvlem | 16:31 |
| gibi | they actaully disabled ES on purpose as when SNP is enabled ES becomes voulnerable | 16:31 |
| bauzas | https://review.opendev.org/c/openstack/nova-specs/+/983376/20..21/specs/2026.2/approved/amd-sev-snp-libvirt-support.rst#b62 | 16:31 |
| sean-k-mooney | sure but as long as you can choose between the two its fine | 16:31 |
| bauzas | so the concern is that we need to look at /proc/cpuinfo ? | 16:31 |
| sean-k-mooney | from a nova point of view we just need to docuemnt that es and snp are mutally exclisive | 16:31 |
| sean-k-mooney | bauzas: yep | 16:32 |
| sean-k-mooney | bauzas: i dont think bypsassing libvirt to look at /proc/cpuinfo is ok | 16:32 |
| bauzas | and there are no other ways to detect a SNP-supported OS ? | 16:32 |
| sean-k-mooney | bauzas: i think that is reported in the launchSecurity section | 16:32 |
| sean-k-mooney | but we woudl have to disabel snp in the bios to confirm | 16:33 |
| sean-k-mooney | and im hesitent to ask gibi to do that | 16:33 |
| bauzas | yeah | 16:33 |
| tkajinam | sean-k-mooney, no launchSecurity does not fully match with sev_snp cpu flag | 16:33 |
| gibi | we agreed in the spec that if we have ES VMs on a host the nova-compute is restarted and sees that no ES capability is available any more due to SNP enabled then nova-compute will fail to start and let the deployer know that there is a mixup of configuration and ask for draining the ES VMs before enabling SNP | 16:33 |
| sean-k-mooney | so its list there whewn its disabeld in the bios | 16:33 |
| tkajinam | sean-k-mooney, for example if you are using an older libvirt then it doesn't have that option but you can enable snp in firmware | 16:33 |
| sean-k-mooney | ? | 16:33 |
| sean-k-mooney | tkajinam: that fine | 16:33 |
| sean-k-mooney | old libivrt is handled by a min version check | 16:33 |
| tkajinam | but that still disables sev-es | 16:33 |
| tkajinam | in hardware level | 16:34 |
| sean-k-mooney | gibi: yep that is the corect behvior | 16:34 |
| sean-k-mooney | its not enfocning that that i object too | 16:34 |
| sean-k-mooney | its how we are determinign that that is problematic | 16:35 |
| bauzas | don't we already look at the cpu capabilities other than using libvirt ? | 16:35 |
| sean-k-mooney | corect we do not | 16:35 |
| bauzas | hmmm | 16:36 |
| antia | does the kernel report sev-es support after firmware update? | 16:36 |
| sean-k-mooney | bauzas: to be clear i was told to go modify libvirt to get feature flags to report in the past more then once | 16:36 |
| tkajinam | bauzas, sean-k-mooney is correct and there is no other logic reading /proc/cpuinfo now | 16:36 |
| bauzas | antia: that depends on the BIOS option AFAICU | 16:36 |
| tkajinam | antia, yes. sev_es cpu flag is still reported, and kvm_amd module still reports sev_es capability | 16:36 |
| bauzas | tkajinam: if the operator didn't set the BIOS SNP option, right ? | 16:37 |
| sean-k-mooney | tkajinam: do you have a host that you are developing this on with the patch | 16:37 |
| tkajinam | bauzas, no, regardless of BIOS setting | 16:37 |
| sean-k-mooney | *with the patched firmware | 16:37 |
| bauzas | I see, of course | 16:38 |
| bauzas | if you set SNP in the BIOS, you will have *both* flags (sev_snp and sev_es) | 16:38 |
| tkajinam | I don't have the one with the said firmware update yet. I'm trying to get full machine time for it but it takes a bit more time. | 16:38 |
| tkajinam | I spent some time looking into kernel and actually sev_es flag is required when sev_snp flag is enabled in kvm_amd | 16:39 |
| tkajinam | so I don't think this behavior (es still reported after snp is enabled in bios) may change quite soon. | 16:39 |
| gibi | so what if we file a bug somewhere in the virt stack, and keep the /proc/cpuinfo check for a while? | 16:40 |
| bauzas | wfm | 16:40 |
| bauzas | with a big TODO/FIXME | 16:40 |
| Uggla | wfm | 16:40 |
| sean-k-mooney | im honestly borderline -2 on /proc/cpuinfo | 16:41 |
| sean-k-mooney | unless we replace usign libvirt for that in generla | 16:41 |
| sean-k-mooney | i really dont think that is correct | 16:41 |
| gibi | but as far as I see we don't have an alternative at the moment | 16:42 |
| tkajinam | there is still an option not to detect partial sev-snp configuration, and just fail only when sev-snp is flly configured | 16:42 |
| sean-k-mooney | we have at leat one check to do which is detemin if the lauch securit section chagnes in reponce to the bios chagne | 16:42 |
| sean-k-mooney | and we can have a config option for it | 16:42 |
| tkajinam | I mean, compute may not fail only when snp is enabled in BIOS, but then fails if operators try to enable snp fully. | 16:42 |
| gibi | tkajinam: but ES VM still fail | 16:43 |
| sean-k-mooney | the same way we had a config option for the number of sev isntance that can be coreated | 16:43 |
| gibi | in the partial config | 16:43 |
| sean-k-mooney | *created | 16:43 |
| tkajinam | gibi, yes | 16:43 |
| sean-k-mooney | until we fixed libvirt | 16:43 |
| gibi | I rather keep that ~10 lines of code in nova than partially detect the a failure | 16:43 |
| gibi | the config option route does not apply in my mind as the deployer probably don't know that snp disables es in the hardware otherwise he would drain the ES VMs already | 16:44 |
| gibi | so config is unreliable | 16:44 |
| sean-k-mooney | but the operator should know that | 16:44 |
| gibi | then we don't need the nova-compute startup check at all | 16:45 |
| gibi | as operator knows and drains :) | 16:45 |
| sean-k-mooney | right | 16:45 |
| sean-k-mooney | i also dont think we need that | 16:45 |
| sean-k-mooney | but that a seprate issue | 16:45 |
| sean-k-mooney | i want to make sure we are reporting the trait | 16:45 |
| sean-k-mooney | when a host supprot it or not for schduling | 16:45 |
| gibi | as far as I understand we need the /proc/cpuinfo because we would like to have a startup check | 16:45 |
| sean-k-mooney | and we shoudl do that based on what libvirt reports | 16:45 |
| gibi | sean-k-mooney: even if libvirt reports it wrongly? | 16:46 |
| sean-k-mooney | yes | 16:46 |
| gibi | I don't like that | 16:46 |
| sean-k-mooney | i dont think nova shoudl be secondguessing libvirt | 16:46 |
| sean-k-mooney | also we have not fully confirmed libvirt reports it incorrectly | 16:46 |
| sean-k-mooney | it repoce 2 diffent things | 16:46 |
| sean-k-mooney | it reporst the sev capastiy | 16:46 |
| sean-k-mooney | and seperate it reprot what modes can be used for sev to lauch a vm | 16:47 |
| sean-k-mooney | there wre 3 modes of sev sofar | 16:47 |
| sean-k-mooney | sev, sev-es and sev-snp | 16:47 |
| sean-k-mooney | in the lauch security section it only has sev and sev-snp | 16:47 |
| sean-k-mooney | not sev-es | 16:48 |
| sean-k-mooney | so i think libvirt is correctly reporting that sev-es cant be used | 16:48 |
| tkajinam | that's basically because they use same enum (sev) for sev and sev-es | 16:48 |
| tkajinam | sev-snp is there because they introduced a different enum (for different scheme) | 16:48 |
| sean-k-mooney | i see | 16:49 |
| tkajinam | I agree it's not quite ideal and doesn't show full items we want to know | 16:49 |
| sean-k-mooney | can we defer this and come back to it | 16:49 |
| sean-k-mooney | i.e. next week | 16:49 |
| sean-k-mooney | i really dont like this | 16:49 |
| tkajinam | I at least add large TODO there and consider how we can improve libvirt to get rid of that hack | 16:50 |
| sean-k-mooney | to be clear this hack is enouch to punt the feature until libvirt is fixed in my view | 16:50 |
| sean-k-mooney | im trying to come aroudn to a diffent approch | 16:50 |
| tkajinam | but if people can spend some time reviewing it and give some more feedback about this topic that would be appreciated | 16:50 |
| sean-k-mooney | but i have been toold by nova cores to go fix libvirt for similar issue multipel times | 16:50 |
| gibi | sean-k-mooney: I'm totally not OK punting a working feature just because we need self contained workaround for a libvirt / amd complication | 16:51 |
| gibi | I'm OK to wait a week and reasses | 16:51 |
| bauzas | tkajinam: as said I'll definitely review your series | 16:51 |
| tkajinam | bauzas, thanks | 16:51 |
| bauzas | and yeah we can revisit that next week | 16:52 |
| Uggla | guys I think that's the conclusion for today. | 16:52 |
| tkajinam | we also might need some discussion about how we implement the startup check but that would be less prioritized. the discussion can be found in the series so I appreciate any thoughts about it, too. | 16:52 |
| bauzas | (at least personnally I'll appreciate it to have more context :D ) | 16:52 |
| tkajinam | yup | 16:52 |
| Uggla | thanks tkajinam, antia and gibi | 16:53 |
| * Uggla moving to next topics as we are reaching the top of the hour | 16:53 | |
| sean-k-mooney | tkajinam: i htink we need my change to add the new driver fuction or you need to do it in the libvirt drivers init host but sure we can disucss in gerrit | 16:53 |
| Uggla | #topic Bug scrubbing | 16:54 |
| Uggla | #info up to 91 (-3) | 16:54 |
| Uggla | #link https://etherpad.opendev.org/p/nova-bug-triage-roster | 16:54 |
| Uggla | #link https://truc.uggla.fr/ to follow the trend. | 16:54 |
| tkajinam | sean-k-mooney, thanks. yeah I just opened your change and will check it soon. | 16:54 |
| Uggla | Next meeting (this week): [public] Upstream bug triage. Wednesday, July 8th · 15:30 – 16:00 UTC. Video call link: meet.google.com/zjr-rxus-hzj | 16:54 |
| Uggla | #topic Open discussion | 16:54 |
| Uggla | Uggla: PTO next 3 weeks. gibi will host the meeting next week then bauzas will host the next 2 ones. | 16:55 |
| gibi | yepp | 16:55 |
| Uggla | something you'd like to quickly share in the lastest 5 mn | 16:55 |
| gibi | - | 16:56 |
| Uggla | if not I guess we are done for today. | 16:56 |
| Uggla | Thanks for joining this meeting. Have a nice day/evening. | 16:56 |
| Uggla | #endmeeting | 16:56 |
| opendevmeet | Meeting ended Mon Jul 6 16:56:55 2026 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 16:56 |
| opendevmeet | Minutes: https://meetings.opendev.org/meetings/nova/2026/nova.2026-07-06-16.00.html | 16:56 |
| opendevmeet | Minutes (text): https://meetings.opendev.org/meetings/nova/2026/nova.2026-07-06-16.00.txt | 16:56 |
| opendevmeet | Log: https://meetings.opendev.org/meetings/nova/2026/nova.2026-07-06-16.00.log.html | 16:56 |
| gibi | thanks folks | 16:56 |
| tkajinam | thanks ! | 16:57 |
| antia | thanks :) | 16:57 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: libvirt: Detect AMD SEV-SNP support https://review.opendev.org/c/openstack/nova/+/994764 | 17:06 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: libvirt: Support launchSecurity element for SEV-SNP https://review.opendev.org/c/openstack/nova/+/994920 | 17:06 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: libvirt: Omit optional fields for SEV/SEV-ES https://review.opendev.org/c/openstack/nova/+/994921 | 17:07 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: libvirt: Drop sev capability check in launch instance flow https://review.opendev.org/c/openstack/nova/+/994929 | 17:07 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: AMD SEV: omit iommu='on' for virtio devices https://review.opendev.org/c/openstack/nova/+/909635 | 17:07 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: libvirt: Launch instances with SEV-SNP memory encryption https://review.opendev.org/c/openstack/nova/+/994930 | 17:09 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: Update documentations for AMD SEV-SNP support https://review.opendev.org/c/openstack/nova/+/995090 | 17:09 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: Remove [libvirt] num_memory_encrypted_guests https://review.opendev.org/c/openstack/nova/+/995120 | 17:09 |
| opendevreview | Merged openstack/nova master: Add concurrency_backend config option for Nova services https://review.opendev.org/c/openstack/nova/+/993760 | 17:17 |
| opendevreview | Takashi Kajinami proposed openstack/nova master: Fix wrong comment in test https://review.opendev.org/c/openstack/nova/+/996070 | 18:30 |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!