Commit Graph

61991 Commits

Author SHA1 Message Date
Takashi Kajinami 1903028492 Accept an empty key for addresses
The name property of networks is optional in neutron. When a server is
attached to a network without name, the key can be empty.

Closes-Bug: #2142767
Change-Id: I31a82bb1574fab6ac03722571ff96443d7a3a51f
Signed-off-by: Takashi Kajinami <kajinamit@oss.nttdata.com>
2026-02-27 00:49:12 +09:00
Zuul 4b38430609 Merge "libvirt: Remove unnecessary arg" 2026-02-26 13:49:24 +00:00
Zuul 0e6505d3b3 Merge "api: Add runtime check for general additionalProperties" 2026-02-26 13:26:25 +00:00
Zuul 14ccb04330 Merge "api: Fix issue with instance usage audit log schema" 2026-02-26 13:26:09 +00:00
Zuul 18a7dcb6e8 Merge "tests: Invert validation check" 2026-02-26 08:50:37 +00:00
Zuul df75b7c13b Merge "api: Add response body schemas for server shares APIs" 2026-02-26 08:50:24 +00:00
Zuul 42ac2df1f8 Merge "api: Add response body schemas for servers APIs (6/6)" 2026-02-26 03:00:09 +00:00
Zuul afac8df46d Merge "api: Add response body schemas for servers APIs (5/6)" 2026-02-25 21:00:49 +00:00
Zuul 37a9596eb1 Merge "libvirt: Use firmware auto-selection by libvirt" 2026-02-25 18:13:09 +00:00
Zuul 4c32ea65e3 Merge "libvirt: Add capability to load smm feature from existing xml" 2026-02-25 17:47:46 +00:00
Stephen Finucane a5bde25463 api: Add runtime check for general additionalProperties
Change-Id: I959afd6e6fa89f0656c10599e50ecb179c87d354
Signed-off-by: Stephen Finucane <stephenfin@redhat.com>
2026-02-25 14:12:14 +00:00
Stephen Finucane 0c4c0d8ce8 api: Fix issue with instance usage audit log schema
We need another level of nesting [1].

[1] https://groups.google.com/g/json-schema/c/pK_Y1Gb5waM

Change-Id: I9828e287208a0dff8f909036df848f7539c534d4
Signed-off-by: Stephen Finucane <stephenfin@redhat.com>
2026-02-25 13:48:11 +00:00
Zuul ebb3175d9c Merge "tests: Fix bound" 2026-02-25 00:17:42 +00:00
Zuul c26c66afb3 Merge "api: Add response body schemas for servers APIs (4/6)" 2026-02-24 23:57:17 +00:00
Zuul 983fbc683b Merge "api: Add response body schemas for servers APIs (3/6)" 2026-02-24 23:57:05 +00:00
Zuul 7dd7a0ffe3 Merge "api: Add response body schemas for servers APIs (2/6)" 2026-02-24 23:45:11 +00:00
Zuul 02d083650b Merge "api: Add response body schemas for servers APIs (1/6)" 2026-02-24 23:44:56 +00:00
Zuul 9855b5c8cc Merge "libvirt: Add capability to load loader and nvram from xml" 2026-02-24 20:12:05 +00:00
Zuul adbea93431 Merge "libvirt: Add basic xml generation for firmware auto selection" 2026-02-24 20:11:42 +00:00
Zuul 04e926a38e Merge "libvirt: Extend functional test coverage of UEFI boot guests" 2026-02-24 19:14:59 +00:00
Zuul 5ed052061a Merge "Fix the negative sleep value in graceful_shutdown()" 2026-02-24 19:14:06 +00:00
Zuul 05a539ace9 Merge "Fix for bug 2140537" 2026-02-24 18:23:50 +00:00
Zuul 12ee1cd80d Merge "Add manager graceful shutdown, timeout, and wait" 2026-02-24 17:58:27 +00:00
Takashi Kajinami 5841095740 libvirt: Use firmware auto-selection by libvirt
Use the firmware auto-selection feature in libvirt to find the best
UEFI firmware file according to the requested feature.

Firmware files may be reselected when a libvirt domain is created from
scratch, while these are kept during hard-reboot (or live migration
which preserves the loader/nvram elements filled by libvirt).

Closes-Bug: #2122296
Related-Bug: #2122288
Implements: blueprint libvirt-firmware-auto-selection
Change-Id: Ie48b020597a1a2fb3280815eec5ba3565e396f9b
Signed-off-by: Takashi Kajinami <kajinamit@oss.nttdata.com>
2026-02-24 20:26:41 +09:00
Zuul a3e9095f02 Merge "Add VNC console support for the Ironic driver" 2026-02-23 19:04:09 +00:00
Ghanshyam Maan 48bdfc8b2f Fix the negative sleep value in graceful_shutdown()
This fixes the following comment to avoid having the
negative sleep value in manager graceful_shutdown()

- https://review.opendev.org/c/openstack/nova/+/975586/comment/d5e3a603_0c746704/

Change-Id: I07a994bd05ac1e7f734f2a2144327bd2559c1416
Signed-off-by: Ghanshyam Maan <gmaan.os14@gmail.com>
2026-02-23 18:51:43 +00:00
Zuul 64d6ba34c5 Merge "Fix the flasky test test_submit_second_while_delaying_first" 2026-02-19 20:21:47 +00:00
Ghanshyam Maan 2fb9113ed2 Add manager graceful shutdown, timeout, and wait
As per the part1 of the graceful shutdown timeouts[1], this commit
add/modifies the below timeout/wait needed for graceful shutdown:

- Override the default of the graceful_shutdown_timeout to 180.
- Add a new config option for manager shutdown timeout.

It also adds a graceful_shutdown() method on the manager side, which
will be called by the nova/service.py->stop() method before it stops
the 2nd RPC server. In part1, this will wait for the configurable wait
time, but part2 will implement a better solution to track the
in-progress tasks. The idea is to have this single interface from the
service manager (graceful_shutdown()) that will be called during
graceful shutdown and is responsible for finishing the required tasks
and cleanup.

Partial implement blueprint nova-services-graceful-shutdown-part1

[1] https://specs.openstack.org/openstack/nova-specs/specs/2026.1/approved/nova-services-graceful-shutdown-part1.html#graceful-shutdown-timeouts

Change-Id: I7c1934d3ec7854feac3fc8432627c25eba963ddf
Signed-off-by: Ghanshyam Maan <gmaan.os14@gmail.com>
2026-02-19 19:44:41 +00:00
Ghanshyam Maan b5c0a97582 Fix the flasky test test_submit_second_while_delaying_first
This test failied a few times and most recent faaailure is
- https://review.opendev.org/c/openstack/nova/+/975586 (PS8 run)

Traceback (most recent call last):
  File "/home/zuul/src/opendev.org/openstack/nova/nova/tests/unit/test_utils.py", line 2185, in test_submit_second_while_delaying_first
    self.assertGreater(task2_runtime, 2.0)
  File "/usr/lib/python3.12/unittest/case.py", line 1269, in assertGreater
    self.fail(self._formatMessage(msg, standardMsg))
  File "/usr/lib/python3.12/unittest/case.py", line 715, in fail
    raise self.failureException(msg)
AssertionError: 1.997275639999998 not greater than 2.0

From error, it seems we are capturing the start time after we
submit the task to executor who will count the task submit time
little ahead of test captured the task start time.

let's capture the task start time before task is submitted so that
we can caompare the time in more correct way.

Change-Id: I5a9845813b614c58e0f5a66e07f8a8c732f38eb3
Signed-off-by: Ghanshyam Maan <gmaan.os14@gmail.com>
2026-02-19 19:06:07 +00:00
Zuul 7a303bc1e2 Merge "Add 2nd RPC server for compute service" 2026-02-19 17:36:34 +00:00
Zuul 7dd05b7af6 Merge "FairLockGuard: Support cross-thread sharing and nesting" 2026-02-18 17:54:57 +00:00
Zuul 0d074c6775 Merge "Make nova recognize amx-capabilities" 2026-02-18 17:22:49 +00:00
Zuul 716fa5edb9 Merge "Fix injection of [cors] allowed_origin" 2026-02-18 15:21:32 +00:00
Zuul 00f554fd92 Merge "Fix full executor warning on noname executor" 2026-02-18 14:37:19 +00:00
Zuul 88adf2c870 Merge "Cleanup libvirt driver at service stop" 2026-02-18 14:37:06 +00:00
Zuul 3b23957f77 Merge "Remove spawn_after" 2026-02-18 14:01:19 +00:00
Takashi Kajinami e212a1e744 libvirt: Add capability to load smm feature from existing xml
Some firmwares require smm feature. While the feature doesn't have to
be explicitly enabled when auto-selection is enabled, it should be
enabled explicitly when firmware files are pre-defined.

Partially-Implements: blueprint libvirt-firmware-auto-selection
Change-Id: Ia194dcfacd2b743761e720d947a6807689a96da3
Signed-off-by: Takashi Kajinami <kajinamit@oss.nttdata.com>
2026-02-18 22:44:12 +09:00
Takashi Kajinami 3136d594a4 libvirt: Add capability to load loader and nvram from xml
... so that we can load these from existing guest XML.

This is a preparation work to use firmware auto-selection by libvirt,
and is required to avoid re-selection during hard-reboot.

Partially-Implements: blueprint libvirt-firmware-auto-selection
Change-Id: I899cb7d6ee364def8d1298b77c24cc5156c71126
Signed-off-by: Takashi Kajinami <kajinamit@oss.nttdata.com>
2026-02-18 22:44:10 +09:00
Takashi Kajinami 511518e493 libvirt: Add basic xml generation for firmware auto selection
Extend the existing (but unused) guest xml generation logic for
firmware detection, by adding the firmware features flags to require
secure boot support.

Partially-Implements: blueprint libvirt-firmware-auto-selection
Change-Id: I907c9c88f370a52b54b98e1e1cbda6c21d2bff62
Signed-off-by: Takashi Kajinami <kajinamit@oss.nttdata.com>
2026-02-18 22:43:06 +09:00
Takashi Kajinami 0c939329c5 libvirt: Extend functional test coverage of UEFI boot guests
Adds non-secure boot scenario and stateless firmware scenario to
demonstrate how guest xml contents look like when firmware files are
selected by libvirt.

Partially-Implements: blueprint libvirt-firmware-auto-selection
Change-Id: I88f0b81c8455630145efca8c6349fc00a0c29835
Signed-off-by: Takashi Kajinami <kajinamit@oss.nttdata.com>
2026-02-18 22:43:06 +09:00
Takashi Kajinami 97beb983e6 Fix injection of [cors] allowed_origin
Using a string value was deprecated in oslo.middleware 3.15.0[1] which
was released 9 years age. The value of this option has been treated as
a list value since then.

[1] 7e519d008f7743d75ec299095060a70d5fd00f99

The latest oslo.middelware release removed the deprecated handling.

Change-Id: Ib88c046af14f5d5de0d410a35a702b7a2322c832
Signed-off-by: Takashi Kajinami <kajinamit@oss.nttdata.com>
2026-02-18 22:08:54 +09:00
Sean Mooney 72132f89ee FairLockGuard: Support cross-thread sharing and nesting
This change improves FairLockGuard to properly support two previously
unsupported (or broken) usage patterns:

1. Cross-thread sharing: When threads share the same FairLockGuard
   instance, they now correctly wait for each other instead of raising
   TypeError. Fixed by:
   - Adding _active_thread tracking to identify the owning thread
   - Restructuring lock acquisition order: named locks are now acquired
     OUTSIDE of locks_lock to prevent deadlock when Thread-B waits on
     locks held by Thread-A
   - Only same-thread re-entry triggers the nesting logic, not
     cross-thread access

2. Same-thread nesting: The same FairLockGuard instance can now be
   nested within itself. Fixed by:
   - Adding _nesting_depth counter initialized to 0
   - Nested entries increment depth and return early (locks held)
   - Exits decrement depth; locks only released when depth reaches 0
   - This prevents lock leaks that would occur if inner exit cleared
     self.locks before outer exit could release them

Additional improvements:
- Exception handling during partial lock acquisition now properly
  releases any locks acquired before the failure
- Lock release moved outside locks_lock in __exit__ for consistency

The docstring has been updated to reflect that both patterns now work,
while continuing to discourage them in favor of creating separate
FairLockGuard instances for clarity.

New tests added:
- test_deep_nesting: Verifies 3+ levels of nesting
- test_nested_exception_outer_still_holds_locks: Verifies outer context
  retains locks when inner context raises an exception
- test_empty_lock_list: Verifies empty lock list edge case

Related-Bug: #2048837
Generated-By: claude-code opus 4.5
Change-Id: Ia937b0e2d76c814360f168d5f33b821bfc61aade
Signed-off-by: Sean Mooney <work@seanmooney.info>
2026-02-18 12:51:51 +00:00
Zuul 0383085510 Merge "Preserve UEFI NVRAM variable store" 2026-02-18 06:36:45 +00:00
Zuul c7e40ef573 Merge "Make disk.extend() pass format to qemu-img" 2026-02-18 01:20:15 +00:00
Sean Mooney 6c9110bb8b Handle missing libvirt services in evacuate hook
On Debian 13 (Trixie), libvirt packaging is modularized and
the libvirt-daemon-lock package (providing virtlockd) is
optional. The evacuate hook previously assumed all libvirt
services were installed and failed when stopping/starting
missing units.

Extract a reusable manage_libvirt_service.yaml task file that
checks if a service exists via systemctl list-unit-files
before managing its units. This prevents failures when
optional libvirt packages are not installed and future-proofs
against further packaging changes.

Generated-By: claude-code
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Change-Id: Ie84e2e8ab2d3065b1562ee5e256fa163541955f7
Signed-off-by: Sean Mooney <work@seanmooney.info>
2026-02-17 18:22:22 +00:00
Dan Smith 3eba22ff09 Make disk.extend() pass format to qemu-img
This fixes an instance of us passing a disk image to qemu-img for
resize where we don't constrain the format. As has previously been
identified, it is never safe to do that when the image itself is not
trusted. In this case, an instance with a previously-raw disk image
being used by imagebackend.Flat is susceptible to the user writing a
qcow2 (or other) header to their disk causing the unconstrained
qemu-img resize operation to interpret it as a qcow2 file.

Since Flat maintains the intended disk format in the disk.info file,
and since we would have safety-checked images we got from glance,
we should be able to trust the image.format specifier, which comes
from driver_format in imagebackend, which is read from disk.info.
Since only raw or qcow2 files should be resized anyway, we can further
constrain it to those.

Notes:
 1. qemu-img refuses to resize some types of VMDK files, but it may
    be able to resize others (there are many subformats). Technically,
    Flat will allow running an instance directly from a VMDK file,
    and so this change _could_ be limiting existing "unintentionally
    works" behavior.
 2. This assumes that disk.info is correct, present, etc. The code to
    handle disk.info will regenerate the file if it's missing or
    unreadable by probing the image without a safety check, which
    would be unsafe. However, that is a much more sophisticated attack,
    requiring either access to the system to delete the file or an
    errant operator action in the first place.

Change-Id: I07cbe90b7a7a0a416ef13fbc3a1b7e2272c90951
Closes-Bug: #2137507
Signed-off-by: Dan Smith <dansmith@redhat.com>
2026-02-17 06:35:35 -08:00
Zuul f3d9188a93 Merge "TPM: support live migration of host secret security" 2026-02-16 18:30:56 +00:00
Zuul c804c3ddb8 Merge "TPM: prepare to bump service version for live migration" 2026-02-16 18:30:42 +00:00
Zuul 2b30cafe98 Merge "Add vtpm_secret_(uuid|value) to LibvirtLiveMigrateData" 2026-02-16 18:28:29 +00:00
Nicolai Ruckel 35b1945522 Preserve UEFI NVRAM variable store
Preserve NVRAM variable store during stop/start, hard reboot, live
migration, and volume retype.

This does not affect cold migration or shelve.

For UEFI guests (hw_firmware_type=uefi), every time the instance is
started, the UEFI variable storage for that instance
(/var/lib/libvirt/qemu/nvram/instance-xxxxxxxx_VARS.fd) is deleted
and reinitialized from the default template.

The changes are based on this patch by Jonas Schäfer to preserve the
vTPM state:
https://review.opendev.org/c/openstack/nova/+/955657

Closes-Bug: #1633447
Closes-Bug: #2131730
Change-Id: I444a9285c07a04bf08a73772235f8dd73d75e513
Signed-off-by: Nicolai Ruckel <nicolai.ruckel@cloudandheat.com>
2026-02-13 23:55:41 +01:00