Friday, 2026-08-21

*** erlon4 is now known as erlon00:30
opendevreviewBrian Haley proposed openstack/nova master: Change neutron API calls to use project_id  https://review.opendev.org/c/openstack/nova/+/99432102:35
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Extract share management from ComputeManager  https://review.opendev.org/c/openstack/nova/+/99934905:37
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Support cold migration with virtiofs shares  https://review.opendev.org/c/openstack/nova/+/98963305:37
*** benj_2 is now known as benj_06:12
antiagmaan: Thanks for reviewing the TDX series. I replied to some of the comments and will make changes to address the rest. 07:38
*** chandank` is now known as chandankumar`12:08
sean-k-mooneyantia: are you expecting to push new version of the patches today. i had hoped you would have prepared them on wednesday orginally?13:13
antiasean-k-mooney: yes, just finalizing now 13:14
sean-k-mooneyack ill try an loop back to them so before i drop fo rthe weekend13:28
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Add Intel TDX host capability detection  https://review.opendev.org/c/openstack/nova/+/99442113:41
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Generalize memory encryption config  https://review.opendev.org/c/openstack/nova/+/99846613:41
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Add memory encryption config for TDX  https://review.opendev.org/c/openstack/nova/+/99860813:41
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Launch security Intel TDX  https://review.opendev.org/c/openstack/nova/+/99924913:41
opendevreviewAnton Iacobaeus proposed openstack/nova master: doc: Add documentation for Intel TDX  https://review.opendev.org/c/openstack/nova/+/100008113:41
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: reject_mem_enc_instances  https://review.opendev.org/c/openstack/nova/+/100008213:41
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Add os_firmware_secure  https://review.opendev.org/c/openstack/nova/+/100047213:41
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Check only x86_64 arch for Intel TDX  https://review.opendev.org/c/openstack/nova/+/100080513:41
antiasean-k-mooney: submitted a new version of the patches now, but this is without moving the os_firmware_secure patch13:41
sean-k-mooneyack13:42
sean-k-mooneythat order is ok was well13:42
sean-k-mooneyits a littel cleaner the other way but it shoudl be fien as is13:42
sean-k-mooneythe how woudl be to merge the full series before FF in anycase13:42
sean-k-mooneyill need to to do one or two things before i have tiem to re reivew but ill try an do a pass over them in an hour or so13:44
antiathanks!13:47
opendevreviewClif Houck proposed openstack/nova master: perf(ironic): eliminate O(N²) ProviderTree deepcopy at startup  https://review.opendev.org/c/openstack/nova/+/98067613:51
opendevreviewClif Houck proposed openstack/nova master: Parallelize per-node resource updates  https://review.opendev.org/c/openstack/nova/+/98067913:51
sean-k-mooneyantia: one thing to keep in mind, in openstack we try to ensure that every commit is indepently correct14:01
sean-k-mooneybecause we want master to be constaly deployable into production14:01
sean-k-mooneyso we allow follow up patches but only when they are not requried for correctness14:02
antiathat makes sense 14:02
sean-k-mooneythat why even if its fixed in a later patch if its a correctness issue we as for it to be fixed in teh relevent patch that intoduced the issue just as wider context14:02
sean-k-mooneythat partly because we use gerrit but more because we do not belive in squash merging series14:03
dansmithgmaan: looks like we're in good shape on the graceful patches.. I'll try to hit the last one today14:16
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Add Intel TDX host capability detection  https://review.opendev.org/c/openstack/nova/+/99442114:56
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Generalize memory encryption config  https://review.opendev.org/c/openstack/nova/+/99846614:56
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Add memory encryption config for TDX  https://review.opendev.org/c/openstack/nova/+/99860814:56
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Add os_firmware_secure  https://review.opendev.org/c/openstack/nova/+/100047214:56
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Launch security Intel TDX  https://review.opendev.org/c/openstack/nova/+/99924914:56
opendevreviewAnton Iacobaeus proposed openstack/nova master: doc: Add documentation for Intel TDX  https://review.opendev.org/c/openstack/nova/+/100008114:56
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: reject_mem_enc_instances  https://review.opendev.org/c/openstack/nova/+/100008214:56
opendevreviewAnton Iacobaeus proposed openstack/nova master: libvirt: Check only x86_64 arch for Intel TDX  https://review.opendev.org/c/openstack/nova/+/100080514:56
gmaanantia: thanks, will check today. i finished till doc yesterday but that is most of the key thing and last two were good maybe, 15:03
gmaandansmith: ack, thanks15:03
gmaandansmith: and this doc/releasenotes one is last https://review.opendev.org/c/openstack/nova/+/997141/1015:03
dansmithgmaan: yep, I know15:09
gmaandansmith: k. I will fix this if i re-spin it otherwise sometime later https://review.opendev.org/c/openstack/nova/+/1000211/comment/734dd672_9a340618/ 15:10
gmaanor you want to push me a followup in thtis series?15:10
dansmithnot critical, see what other people think15:12
gmaanack15:15
dansmithugh, I can't put my finger on it right now.. Uggla when is FF?15:17
UgglaThursday next week15:18
gmaanAug 28, end of next week15:18
dansmithduh, linked from the top of the H page15:18
sean-k-mooneythe non client lib freze shoudl have been yesterday i think as well15:18
sean-k-mooneyi was about to check if the os-tirat release we are waitign on happend?15:18
dansmithack, so I think we have plenty of time for gouthamr to at least try for a follow-up patch for reconciling missed share access rules15:18
sean-k-mooneyUggla: do you know?15:18
dansmithUggla: I assume you would be up for a FFE if necessary to get that over the line if the rest of it is landed?15:19
gmaanantia: sean-k-mooney on TDX one,  before you both goes offline. one thing to discuss. i have to check the updated series but i cannot see VM create is rejected if os_secure_boot=required and TDX requested, https://review.opendev.org/c/openstack/nova/+/999249/5/nova/virt/libvirt/driver.py#796715:19
Uggladansmith yes if we have a chance to do it.15:19
gmaanis update/re-aranging series done or shoud i wait15:19
sean-k-mooneyUggla: looks like the last release was 2 months ago so im going to go request a new release now15:20
sean-k-mooneyhttps://github.com/openstack/releases/blob/master/deliverables/_independent/os-traits.yaml#L115-L11815:20
Ugglasean-k-mooney, I don't know. But things are probably lagging a bit because Elod is on pto15:21
dansmithUggla: AFAIK we're now just waiting for you to circle back on the exception handling comment here: https://review.opendev.org/c/openstack/nova/+/99934915:22
sean-k-mooneywell sylvain is the release liason so they would have been teh one to propeose it normally but they are also on pto15:22
sean-k-mooneyrather then elod15:22
dansmithotherwise I think I'm +2 on both assuming gouthamr will propose a followup for a periodic resync of the share access rules15:22
gmaanantia: this one https://review.opendev.org/c/openstack/nova/+/999249/3..5/nova/virt/libvirt/driver.py#b797615:24
gmaani was expecting we reject the request when we find os_secure_boot is required and tdx-requested otherwise it still ignore it. no?15:25
Uggladansmith, thanks I'm gonna answer. Did you test with nfs or cephfs ?15:26
dansmithnfs15:26
dansmithUggla: I put notes in the comments about the things I tested (although notably left out which driver I was using)15:27
antiagmaan: There is a follow up patch, which I now moved to be in front, which solves the secure boot interaction with TDX15:27
Ugglaok I have just setup a cephfs devstack for testing it. That should not fundamentally change. But it will be another check.15:27
dansmithvery good15:28
antiahttps://review.opendev.org/c/openstack/nova/+/1000472 with this it shouldn't be required to reject on os_secure_boot=required for TDX15:28
gmaanantia: ok, let me go through the whole series again, will do after sometime. btw which TZ you are in?15:29
sean-k-mooneydid gibi or you have time to test that secure boot actully worked in that version15:29
antiagmaan: UTC+2, so just about to head off for the weekend :) 15:30
Uggladansmith, I would have progressed more without yesterday escalation.15:30
gmaani did not have HW access, gibi had. i asked him about it but we will get to know on monday. 15:30
gmaanantia: ack15:30
gmaanor antia may have tested?15:30
sean-k-mooneygmaan: sorry that question was to antia 15:30
antiaboth me and gibi tested it 15:30
gmaanyeah, i know. just saying15:30
sean-k-mooneyack we can stage thigns ready for gibi to +w on monday if we think its otehrwse ready adn he can do a final test if they have time15:31
gmaani asked gibi also but can we publish the testing results (if you can upload yours) somewhere, as we will not be testing it in upstream, it will be good ref to know what is tested and working fine15:32
sean-k-mooneyim almost done with the cybrog things i need to do today so ill be starting on the tdx review again in a bit15:32
antialogs of my tests (but this is before the most recent changes): https://paste.openstack.org/show/bdbleKLLworBpma70kXB/15:32
gmaannot sure where we can share as permanent doc 15:32
sean-k-mooneyantia: but that does not actully should you checkign theat secure boot was enabled in the guest os image15:33
sean-k-mooneyand tha tit booted with that15:33
gmaani was thinking to have some doc existing in Nova repo with all testing you did. not detail maybe15:33
sean-k-mooneywe proably shoud nto merge that15:33
antiasean-k-mooney: Ah that is true! I can do some more testing after the weekend15:33
sean-k-mooneyunless it written as a guide to testing15:34
sean-k-mooneygmaan: we have similar guide for some numa stuff15:34
sean-k-mooneygmaan: so somethign like https://github.com/openstack/nova/tree/master/doc/source/contributor/testing15:34
gmaansean-k-mooney: ++ yeah. i did not check numa one but yes guide to test/results15:35
sean-k-mooneywell i dont thinik we should comemit one off results15:35
gmaanyup, kind of this15:35
sean-k-mooneybut we can commit docs of how to test it manually properly15:35
gmaanat least, which one worked or not15:35
sean-k-mooneyso of this is going to end up automated later in whitebox/tempest too15:36
sean-k-mooneythe system gibi borrowed may eventully end up geting used to test this perodicily downstream15:37
gmaan++ for tempest/whitebox testing but if we have some 3rd party CI to run them somewhere15:37
sean-k-mooneywe kind of do. righ tnow we are not allwoe do report reuslt publicly because of infra info discustore risks15:37
sean-k-mooneygmaan: we have internal nightly master job for cybrog15:38
gmaananyways, let's start with similar doc first, antia are you ok to push something next week. I am saying that is blocker for series to merge but good to have when we are merging it15:38
sean-k-mooneywe shoudl be able to do the saem for TDX in the coming weeks15:38
sean-k-mooneynot a blocker for the feature15:38
gmaanyeah15:38
sean-k-mooneyjsut fyi that we hope to have that in place proably before the year is up15:39
sean-k-mooneywe are still exploring options for public third party ci bu thats complicated15:39
antiawould it be a document about TDX testing in https://github.com/openstack/nova/tree/master/doc/source/contributor/testing?15:39
sean-k-mooneyyes so like https://github.com/openstack/nova/blob/master/doc/source/contributor/testing/serial-console.rst15:41
sean-k-mooneyor the numa one15:41
antiasomething like that I can fix 15:41
sean-k-mooneybasiclly it woudl explain how to verify the feature is workign corectly 15:41
sean-k-mooneyantia: i would keep that as a follwup patch provided that works for gmaan 15:42
gmaanyeah, works for me at the end of series. do not change existing series15:42
antiasounds good15:42
gmaanthanks15:42
antiahave a nice weekend all, and thanks for reviewing!15:43
gmaanhave a nice weekend antia 15:43
gmaansean-k-mooney: I am not sure you are planning to go through series today but I will be able to do during end of my day. I will leave the merge things until gibi or you recheck. we still have 1 week before FF15:43
sean-k-mooneyim going to be aound for another hour or two15:44
sean-k-mooneyim trying to complete the cybrog nvme serise first15:44
sean-k-mooneythen loop back to this after15:44
gmaanack15:44
sean-k-mooneythe os-triats question above was we have a depency on the new os-trait release in that15:45
gmaanwe released that right? i thought changes was done in advanbce and released15:45
sean-k-mooneythey were don but not released15:45
sean-k-mooneyhttps://review.opendev.org/c/openstack/releases/+/1001835/1/deliverables/_independent/os-traits.yaml15:45
sean-k-mooneyi just created that15:45
sean-k-mooneyim going to raise it in the release channel shortly15:46
gmaansean-k-mooney: humm, tdx series added 3.8.0 in requirement.txt15:46
sean-k-mooneyyep that was done 2 months ago15:46
sean-k-mooneythe cyborg traits for nvme secure erase modes15:46
sean-k-mooneymerge last week15:46
gmaansean-k-mooney: its there https://github.com/openstack/os-traits/blob/3.8.0/os_traits/hw/cpu/x86/intel.py#L2815:46
gmaanyeah, os-traits updates was done long back15:47
sean-k-mooneygmaan: right but we need a new release for a differnt feature15:47
sean-k-mooneythis isnt needed in nova but is needed in placment and cybrog15:47
gmaanohk, i thought you are saying TDX part is not released yet15:48
sean-k-mooneyno that is there15:48
gmaanyeah15:48
sean-k-mooneybut i need to complete the nvme feature review before going back to the tdx series15:48
gmaangot it15:49
sean-k-mooneyim trying to see if i can get os-traits 3.9.0 released so we can fully supprot requeting nvme devices based on tehre secure erase capabliteis15:49
gmaanmaybe we need more people here https://github.com/openstack/governance/blob/master/reference/projects.yaml#L103915:49
sean-k-mooneyUggla if you can appove https://review.opendev.org/c/openstack/releases/+/1001835 that woudl help15:50
gmaanUggla: ^^ idea to add a few more as release will stuck if you and bauzas both are on PTO15:50
sean-k-mooneyhaving more then one is nice for pto coverage but the ptl can alwasy approve as well15:50
gmaanyeah, just thinking to have 1 or 2 more along with PTL15:51
sean-k-mooneyfor cybrog and watcher we have 2 release liasons seperate form teh ptl with 3 possbel aprpovers we are genneraly pretty PTO resitent15:51
Ugglasean-k-mooney, done. Tbh I was here this week but forget about it.15:54
sean-k-mooneyno worries am we shoudl check os-vif and os-resouce classees for pendign release as well15:54
sean-k-mooneybut im not aware of any critial patches in those15:55
sean-k-mooneyos vif was milestone 215:56
sean-k-mooneywe actuul;y do have a few fixes we shoudl include in 2026.215:56
sean-k-mooneyill also prospoe that now15:56
sean-k-mooneywe specificly want https://github.com/openstack/os-vif/commit/8f2d2cc92d6f79c85e03e52d61b0f71d08a0cca215:57
sean-k-mooneyUggla: https://review.opendev.org/c/openstack/releases/+/100184415:58
Ugglasean-k-mooney i approved16:05
opendevreviewClif Houck proposed openstack/nova master: Parallelize per-node resource updates  https://review.opendev.org/c/openstack/nova/+/98067916:19
opendevreviewGhanshyam Maan proposed openstack/nova master: Add doc and release notes for the graceful shutdown task tracking  https://review.opendev.org/c/openstack/nova/+/99714117:26
* gouthamr reads scrollback.. 17:54
gouthamrack on the periodic cleanup on the virtiofs/cold migration patch dansmith.. 17:55
gouthamri'm working on it17:55
dansmithgouthamr: cool18:02
gmaandansmith: updated the doc change18:20
dansmithgmaan: got it18:33
* dansmith dusts hands18:33
gmaandansmith: thanks for reviews on the whole series.  18:34
* dansmith nods18:43
*** nicolairuckel_ is now known as nicolairuckel20:07
opendevreviewMerged openstack/nova master: Report OWNER_NOVA trait on resource providers  https://review.opendev.org/c/openstack/nova/+/99429921:01
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Use a per-instance cephx identity for CephFS shares  https://review.opendev.org/c/openstack/nova/+/100190021:17
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Use a per-instance cephx identity for CephFS shares  https://review.opendev.org/c/openstack/nova/+/100190021:46
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Extract share management from ComputeManager  https://review.opendev.org/c/openstack/nova/+/99934921:46
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Support cold migration with virtiofs shares  https://review.opendev.org/c/openstack/nova/+/98963321:46
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Use a per-instance cephx identity for CephFS shares  https://review.opendev.org/c/openstack/nova/+/100190022:28
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Extract share management from ComputeManager  https://review.opendev.org/c/openstack/nova/+/99934922:28
opendevreviewGoutham Pacha Ravi proposed openstack/nova master: Support cold migration with virtiofs shares  https://review.opendev.org/c/openstack/nova/+/98963322:28

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!