Monday, 2026-07-20

*** Jeff is now known as Guest1375701:13
*** Guest13757 is now known as JeffYang01:44
*** M00SE7 is now known as M00SE08:30
tkajinamgibi, hi, are you around ?10:20
gibitkajinam: not right now but I will be back from a call hopefully in an hour11:56
gibitkajinam: feel free to leave me some stuff to answer :)11:56
gibiI see that SNP is mostly landed so I'm not worrying about that any more :) 12:05
gibimore worried about the TDX work12:05
tkajinamyeah12:43
tkajinamgibi, I tested https://review.opendev.org/c/openstack/nova/+/996316 in my local env and verified it. I wonder if you agree with merging it (unfortunately the node is in a bit secured space so I can't bring logs easily from there)12:44
tkajinamassuming testing in real hardware is the only pending work item12:45
tkajinamonce that and a few follow-up tests are merged, I can help rebasing and implementing the rest of TDX bits according to what I've implemented for snp, if that could be helpful12:46
*** haleyb|out is now known as haleyb13:23
*** iurygregory_ is now known as iurygregory13:36
*** noonedeadpunk is now known as noonedeadpunk_13:51
*** noonedeadpunk_ is now known as noonedeadpunk13:51
tkajinamantia, hi. around ?13:55
antiahi yes13:57
antiaSaw your comment, sounds reasonable to have it be one version bump 13:58
tkajinamyeah13:58
tkajinamantia, I wonder if you managed to rebase your change on top of current master13:59
tkajinamI pulled your change and rebased on top of the latest master. If not, then I can push it from my end.14:00
tkajinamI can also rebase again the change on top of a few remaining sev-snp change to pull base structure for functional tests you likely have to add14:00
tkajinamhttps://review.opendev.org/c/openstack/nova/+/997635 is the one I'm talking about14:01
tkajinamIf you are ready to submit an updated version then I'll leave it to you.14:01
antiaI was just working on it, since I had it previously rebased against your patch. Mine has a second version bump though. Would yours be with one version bump?14:03
gibitkajinam: re https://review.opendev.org/c/openstack/nova/+/996316 I trust your verification. I will push the necessary buttons..14:03
tkajinamgibi, thanks !14:04
tkajinamantia, my local rebase is yet to do another version bump but we can revert that part. maybe we want to discuss that during the upcoming meeting14:05
gibiantia: tkajinam: any progress on intel TDX is very welcome we have 5 weeks left to land it and I have dedicated review cycles promised to get it reviewed as fast as I can14:07
gibiso even if a half done series pushed up would help me help you :)14:08
antiatkajinam, yes that sounds reasonable. Regarding https://review.opendev.org/c/openstack/nova/+/997635, atleast the changes to LibvirtReportTraitsTestBase will be relevant so I think it is good to rebase against it already14:08
antiagibi, yes apologies I had to take PTO for personal reasons last week. I am now fully back and will work full time on it until the deadline. 14:10
antiawill push what I have today so we have something to start with14:11
gibiantia: sounds good. thanks14:14
tkajinambauzas, thanks for approving the remaining patches !14:20
bauzastkajinam: sorry was pretty packed with other stuff downstream but I reviewed the whole series :)14:20
bauzasthanks for the hard work !14:21
gmaangibi: i replied on the security group name (trailiing/leading whitespace) issue, https://review.opendev.org/c/openstack/nova/+/99507314:42
gibigmaan: thanks14:43
gmaanit seems we need to fix it with microverison. If so then i know we said every API change need spec but this seems straight forward issue to fix so not sure if we can wave off the spec requirement here and fix as specless BP or just bug tracking14:44
gmaanfor me, we do not need to do spec here and can just review/merge the fix but would like to know what other things14:45
gmaani can add it in today meeting agenda though 14:45
gibigmaan: yeah. I'm a bit sad about this needed a new microversion. It feels our microversion rules are too strict regarding bugs. But I'm not dying on this specific bugfix hill. 14:45
gmaani know sometime microversion are overkil but that is what we have14:46
gibiregarding fixing in specless bp we need the core team's overall agreement but I'm OK if it is really just changing the schema to allow what neutron allows14:46
gibigmaan: "that is what we have" I feel like we are fully in charge to decide what we have as a rule :)14:47
gmaanwell, its interop issue not backward compatiblity and we have taken both into account in past. I am ok if we want to change some rule to relax the microversion bump need but that will be agreed separatly as overall policy14:49
gmaanok, as the use case itself is not good/weired, let it go in it own pace then. I will ask author to propose spec and it can go in next cycle as this cycle spec is done14:50
gibiinterop as two clouds with the same API microversion behaving differently because they are on different nova-api software level?14:52
gibiif so, that is super limiting. I.e. if a bugfix changes a nova 500 to a nova 200 and an active server, that is an interop issue in that definition as such bug fix changes the observed behavior of nova on the same microversion14:53
gibibut we are tend to fix bug to change the observed behavior of nova14:53
gibianyhow this is a wider discussion 14:54
gmaanyeah, we had one such cases 2.42 microversion for network device tag which we added in 2.33 microversion, introduced bug which removed it from schema 2.37?, then added back in 2.42 microversion14:55
gmaanit is mainly issue for users/apps moving from cloud allowing whitespace SG name to cloud rejecting them14:56
opendevreviewBalazs Gibizer proposed openstack/nova master: Stabilize test_failed_count_with_anti_affinity_violation  https://review.opendev.org/c/openstack/nova/+/99800114:58
bauzasreminder : nova meeting here in ~50 mins15:09
gmaanany one would like to add 2nd +2 on these enforce_scope release notes/requirement bump https://review.opendev.org/q/hashtag:%22remove-enforce-scope-flag%22+hashtag:%22nova%22status:open15:35
opendevreviewTakashi Kajinami proposed openstack/os-traits master: Update supported python versions  https://review.opendev.org/c/openstack/os-traits/+/99801115:37
opendevreviewTakashi Kajinami proposed openstack/os-resource-classes master: Update supported python versions  https://review.opendev.org/c/openstack/os-resource-classes/+/99801215:39
opendevreviewTakashi Kajinami proposed openstack/os-vif master: Declare Python 3.14 support  https://review.opendev.org/c/openstack/os-vif/+/99801315:42
bauzas#startmeeting nova16:00
opendevmeetMeeting started Mon Jul 20 16:00:22 2026 UTC and is due to finish in 60 minutes.  The chair is bauzas. Information about MeetBot at http://wiki.debian.org/MeetBot.16:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.16:00
opendevmeetThe meeting name has been set to 'nova'16:00
bauzas#link https://wiki.openstack.org/wiki/Meetings/Nova16:00
bauzashey folks, chairing the meeting due to Uggla's PTO 16:01
elodilleso/16:01
gibio/16:01
samborko/16:01
bauzaslet's try to have a short one :) 16:01
bauzas#topic Bugs (stuck/critical) 16:01
antiao/16:01
bauzas#info No Critical bug16:01
bauzas#topic Gate status 16:01
fwieselo/16:01
tkajinamo/16:01
bauzas#link https://bugs.launchpad.net/nova/+bugs?field.tag=gate-failure Nova gate bugs 16:01
bauzas#link https://zuul.openstack.org/builds?project=openstack%2Fnova&project=openstack%2Fplacement&branch=stable%2F*&branch=master&pipeline=periodic-weekly&skip=0 Nova&Placement periodic jobs status16:02
bauzas#info Please look at the gate failures and file a bug report with the gate-failure tag.16:02
bauzas#info Please try to provide a meaningful comment when you recheck16:02
bauzasanything to mention about the gate ?16:02
bauzasI think we no longer have a gate failure now :)16:02
tkajinamyeah16:03
bauzascool16:03
bauzasmoving on16:03
bauzas#topic Release Planning 16:04
bauzas#link https://releases.openstack.org/hibiscus/schedule.html16:04
bauzas#info Nova deadlines are set in the above schedule16:04
gmaano/16:04
bauzas#topic Review priorities 16:04
bauzas#link New file for Hibiscus https://etherpad.opendev.org/p/nova-2026.2-status16:04
bauzas#info Uggla has updated Launchpad and the above doc. Please ping me if you spot something missing.16:05
bauzas#undo16:05
opendevmeetRemoving item from minutes: #info Uggla has updated Launchpad and the above doc. Please ping me if you spot something missing.16:05
bauzas#info Uggla has updated Launchpad and the above doc. Please ping him if you spot something missing.16:05
bauzas#info Starting: https://etherpad.opendev.org/p/nova-2026.2-status#L16 interesting bugs to review.16:05
bauzasanything to discuss about the statuses ?16:05
bauzaskk16:06
bauzas#topic Stable Branches 16:06
bauzaselodilles: your time :)16:06
elodillesthanks :)16:06
elodilles#info placement stable/2025.1 is blocked - workaround: https://review.opendev.org/c/openstack/placement/+/99229916:06
elodilles#info other stable gates should be OK16:06
bauzasapproved the workaround16:07
elodillessean-k-mooney's backports fixed stable/2025.1 nova gate. thanks all o/16:07
elodillesbauzas: thanks!!!! \o/16:07
bauzasanything else ?16:07
elodillesonly this one:16:08
elodilles#info stable branch status / gate failures tracking etherpad: https://etherpad.opendev.org/p/nova-stable-branch-ci16:08
elodilles:)16:08
elodillesbauzas: back to you16:08
bauzask16:08
bauzas#topic vmwareapi 3rd-party CI efforts Highlights16:08
bauzasfwiesel: around ?16:08
fwieselHi16:08
bauzaso/16:08
fwieselYes, I looked into the pipeline failures, and instance creations were slowed down to that extend that no instances were being created.16:09
fwiesel#link https://review.opendev.org/c/openstack/oslo.vmware/+/99726916:09
fwieselThis should reduce the overhead of doing api calls against VSphere, but I am suspecting it is not the full picture.16:10
fwieselStill digging into it.16:10
fwieselThat's from my side.16:10
bauzascool thanks16:11
bauzas#topic Kamil's news about eventlet removal16:11
bauzassambork ?16:11
samborko/16:11
samborklast week was dominated by test stabilization: the unit test exclude list is gone, and there's a push to make the threading functional CI job voting.16:12
gibie.g. https://bugs.launchpad.net/nova/+bug/2161293 ^^16:12
samborkhe code cleanup is moving forward by replacing Nova-internal threading utilities with futurist primitives (both nova and futurist patch are pushed and ready for review)16:13
samborkeom16:13
samborkanything to add gibi? (thanks for bug above)16:13
gibifwiesel's finding is sort of eventlet related and I made mental note about performanc of the oslo retry decorator that could effect nova as well not just oslo.vmware16:14
gibiwe might want to take a hard look of the usage of that and consider tenacity's cheaper retry all over the place16:14
gibiaaand I still haven't filed the bug to switch the default of our unit test execution to threading and just keep one tox job for unit test + eventlet16:15
gibibut I will I promise... eventually...16:15
bauzasthat's nice we no longer have unit test exclude list16:15
gibibtw the functional threading job has only 2 test case excluded 16:16
bauzasnice16:16
gibiand at least I understand the problem in one of them :):16:16
bauzasnice16:16
samborkdo we need additional ticket for checking retries? and do we wan to priorities this?16:17
gibisambork: please file a bug just to not forget it16:17
gibiright now I don't feel it has a high prio16:17
samborkack16:18
gibibut it might become one based on performance results from downstream testing16:18
opendevreviewMerged openstack/nova master: Use domain capabilities to detect SEV-SNP support  https://review.opendev.org/c/openstack/nova/+/99631616:19
opendevreviewMerged openstack/nova master: Extend tests for _is_supported_mem_encryption_model helper  https://review.opendev.org/c/openstack/nova/+/99766316:19
opendevreviewMerged openstack/nova master: Refactor CPU traits functional tests for AMD SEV support  https://review.opendev.org/c/openstack/nova/+/99763516:19
gibithat is basically the report for the SNP status ^^^ :)16:19
antiaperfect timing :)16:19
gibiyeah16:19
gibiwe can move on 16:19
bauzasack16:20
bauzas#topic Nova using openstack sdk for neutron16:20
bauzaswho is leading that ?16:20
elodillesthis is Lajos' topic if i'm not mistaken and he is still on PTO16:21
bauzascool moving on then16:21
bauzas#topic Ironic review priorities16:21
bauzasanything to say ?16:21
bauzaslooks not16:23
bauzas#topic Confidential computing, status of SNP and TDX features16:23
bauzasI've seen good news16:23
tkajinamthe remaining sev-snp patches lust landed so sev-snp support was completed16:24
tkajinam\o/16:24
gibi\o/16:24
tkajinamI just noticed that https://blueprints.launchpad.net/nova/+spec/amd-sev-snp-libvirt-support is not yet approved. can someone do so ?16:24
tkajinamthen I'd update its implementation status16:24
gibidone16:25
antiaI suppose the same for https://blueprints.launchpad.net/nova/+spec/intel-tdx-libvirt-support16:25
tkajinambecause these changes were merged tdx needs another rebase but I think we are now fully ready to start it.16:26
antiaanyway I ended up with PTO last week so not much on TDX side16:26
gibiantia: fixed the bp for that too16:26
antiagibi: thanks!16:26
gibiI will grab a TDX hardware this week (hopefully)16:27
antiastarted with some catch up with SNP and rebased with master, noticed some changes to the test structure which results in errors for me16:27
antiaI suspect it’s because the exists mock that was dropped in https://review.opendev.org/c/openstack/nova/+/994343/18/nova/tests/fixtures/libvirt.py16:27
antiaSince this is the error "Exception: This test invokes builtins.open on /sys/module/kvm_intel/parameters/tdx. It is bad, you should mock it."16:27
antiagibi: Cool! Will get you something to test :)16:28
antiaIn the end the sys fs check is not needed for TDX since Libvirt does it anyway so the easy fix is probably to drop it, but mostly curious if it was solved in some other way for SEV16:29
gibiantia, tkajinam re mock, yeah we should either mock open or have a different way to check the status16:29
gibitkajinam: did we fully removed the reliance on the kernel module parameter?16:29
gibiif so, and that worked for SNP, I hope we can do the same for TDX as well16:30
tkajinamgibi, no we have to rely on it for snp but we can drop it for tdx16:30
gibitkajinam: due to the ES/SNP CVE?16:30
tkajinamno. due to libvirt not checking the flags for es and snp16:31
tkajinamwe could probably get rid of access to sev flag, though16:31
antiaI'll just drop it as part of the rebase and we should be good 16:31
gibitkajinam: antia: so for TDX we could go with the domain capabilities route?16:31
tkajinamI mean it only checks /sys/module/kvm_amd/parameters/sev and does not check /sys/module/kvm_amd/parameters/sev_es or /sys/module/kvm_amd/parameters/sev_snp16:31
tkajinamgibi, yes, libvirt checks the tdx flag when it declares <tdx support='yes'/>16:32
antiagibi: Yes exactly. Right now it does both the sys fs check and domain capabilities which is not needed16:32
gibicool then you can get rid of the problem by not relying on reading that file :)16:32
tkajinamyeah using only domain capabilities simplifies the logic and tests largely 16:33
antiatried it before and tests were quite annoying to fix, but I think that has been fixed already so should be simple enough16:33
gibicool16:34
tkajinamone question I got during reviewing the tdx series is whether we need to bump object version again for tdx or can reuse the existing version for snp assuming tdx would be merged this cycle16:35
tkajinamI mean for snp we bumped ImageMeta object version due to hw_mem_encryption_model supporting new amd-sev-snp16:35
tkajinamand I'm wondering if we should bump the version again when hw_mem_encryption_model supports new intel-tdx or we can handle it within the same version16:35
gibibump the version please16:36
gibiobject versions are cheap16:36
tkajinamok16:36
antiaeither is fine with me16:37
antiawill bump it 16:37
gibithanks16:37
tkajinamquick conclusion :-)16:37
gibi:)16:37
tkajinamnothing else from my end. I reviewed tdx sceries and left a few comments there.16:37
antiathanks for the review!16:38
tkajinamantia, in case you need help to follow existing sev thing then feel free to ping me16:38
antiawill do :)16:38
gibiI will keep myself in the loop :)16:38
gibiwe can move on16:39
tkajinamyup16:40
gibibauzas: are you still with us?16:42
gibiOK I'm taking over :)16:43
bauzassorry back16:43
bauzas #topic Bug scrubbing 16:43
bauzas#topic Bug scrubbing 16:43
bauzasI haven't looked at the numbers tbh16:43
bauzasmoving on so ?16:43
bauzas#topic Open discussion16:43
bauzasanything ?16:43
gibi-16:44
tkajinama quick one16:44
tkajinamwhile working on sev-snp work I found several potential cleanups in current libvirt driver code (mainly due to remaining checks for old versions which are non longer supported)16:44
tkajinamhttps://review.opendev.org/q/hashtag:%22libvirt-cleanups%22+(status:open%20OR%20status:merged)16:45
tkajinamI'll capture these in this hash tag so if you have spare time I appreciate your review :-)16:45
gibigood initiative16:45
tkajinamI think we managed to drop number of unnecessary logics as part of snp work :-)16:45
gibieverything that delete codes worth the review time16:45
tkajinamless code, better life16:46
tkajinamthere is also removal of vcpu_pin_set which drops large amount of code just fyi (though I find it a bit complicated for review)16:47
tkajinamhttps://review.opendev.org/c/openstack/nova/+/99601616:47
tkajinamthat's all from me for today !16:47
gibi:)16:47
gibi(maybe we need a couple of sprints just to fix bugs and land cleanups)16:48
gmaanone review request, enforce_scope releasenotes and one cleanup need 2nd core to check those 16:48
gmaan#link https://review.opendev.org/q/hashtag:%22remove-enforce-scope-flag%22+hashtag:%22nova%22status:open16:48
gibigmaan: I will check it out now16:48
gmaanthanks16:49
bauzascool, closing now the meeting, thanks all16:49
bauzas#endmeeting16:49
opendevmeetMeeting ended Mon Jul 20 16:49:45 2026 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)16:49
opendevmeetMinutes:        https://meetings.opendev.org/meetings/nova/2026/nova.2026-07-20-16.00.html16:49
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/nova/2026/nova.2026-07-20-16.00.txt16:49
opendevmeetLog:            https://meetings.opendev.org/meetings/nova/2026/nova.2026-07-20-16.00.log.html16:49
antiathanks16:49
gibibauzas: thanks16:49
elodillesthanks o/16:50
tkajinamthank you16:50
melwitthas anyone else noticed in devstack nova-compute no longer logs config options setting when it starts up?16:51
dansmithis that an oslo.service change, perhaps related to the eventlet stuff?16:52
melwittyeah I'm guessing it has something to do with the change to threading, somehow16:53
tkajinamhmm that's wired16:56
tkajinamfor threading we use cotyledon and cotyledon has similar debug logs triggered by log_options opt16:56
gmaanonly functional change between oslo.service 4.6.0 and 4.7.0(new one in u-c) is this which is just periodic tasks change https://review.opendev.org/c/openstack/oslo.service/+/98241816:59
melwittyeah I dunno, picking a tempest-integrated-compute job from one of the enforce_scope patches I see the lack of conf options logging https://zuul.opendev.org/t/openstack/build/f4cc4f17dd414959b5d04cbfddffe410/log/controller/logs/screen-n-cpu.txt17:09
tkajinamit's wired we see the expected debug logs in nova-scheduler on the other hand17:19
tkajinammaybe nova-compute uses a different service launching method (but I don't feel so now)17:19
tkajinamregarding the file access for sev detection it seems although libvirt reads /sys/module/kvm_amd/parameters/sev it does not use that value when it determines sev elements in capabilities .. we have to fix it along with the missing check for sev_es/snp later17:19
* tkajinam was checking libvirt logic...17:19
tkajinamfor now we should be ok as long as we keep the current file accesses for snp17:20
tkajinam s/snp/sev/17:20
opendevreviewMerged openstack/placement stable/2025.1: [CI][stable-only] Pin tempest for Jammy based job  https://review.opendev.org/c/openstack/placement/+/99229918:10
opendevreviewSylvain Desgrais proposed openstack/nova-specs master: Add spec for allowing security group name spaces  https://review.opendev.org/c/openstack/nova-specs/+/99804918:55
opendevreviewMerged openstack/nova master: [Trivial] use the new variable name for RBAC new defaults  https://review.opendev.org/c/openstack/nova/+/99558019:07
opendevreviewMerged openstack/nova master: Remove disabling the scope enforcement  https://review.opendev.org/c/openstack/nova/+/99495019:08
opendevreviewMerged openstack/placement master: Remove disabling the scope enforecment  https://review.opendev.org/c/openstack/placement/+/99479019:08
opendevreviewMerged openstack/os-vif master: Declare Python 3.14 support  https://review.opendev.org/c/openstack/os-vif/+/99801323:06
opendevreviewMike Lowe proposed openstack/nova master: libvirt: Fix false mem-encryption/UEFI conflict with cpu_mode=custom  https://review.opendev.org/c/openstack/nova/+/99725923:32

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!