)]}'
{"id":"openstack%2Fnova-specs~641994","triplet_id":"openstack%2Fnova-specs~master~I4ad7de08d55ef0d8b74719f60966f545a36a12eb","project":"openstack/nova-specs","branch":"master","topic":"bp/amd-sev-libvirt-support","hashtags":[],"change_id":"I4ad7de08d55ef0d8b74719f60966f545a36a12eb","subject":"Re-approve AMD SEV support for Train","status":"MERGED","created":"2019-03-08 12:31:52.000000000","updated":"2019-04-24 20:28:06.000000000","submitted":"2019-04-24 11:44:46.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":69,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"641994-1556106286370-11ac1cc1","meta_rev_id":"2e99026268d9a4efc70646b386cb13f299697a8f","_number":641994,"virtual_id_number":641994,"owner":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"value":0,"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"value":0,"_account_id":2697,"name":"Jim Fehlig","email":"jfehlig@suse.com","username":"jfehlig"},{"value":0,"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},{"value":2,"date":"2019-04-24 11:44:46.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":0,"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":0,"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},{"value":0,"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"all":[{"value":0,"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"value":2,"date":"2019-04-24 11:28:59.000000000","_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"value":0,"_account_id":2697,"name":"Jim Fehlig","email":"jfehlig@suse.com","username":"jfehlig"},{"value":1,"date":"2019-04-24 00:20:32.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":1,"date":"2019-04-24 04:29:34.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":0,"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},{"value":1,"date":"2019-04-24 11:19:17.000000000","permitted_voting_range":{"min":1,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":2,"date":"2019-04-23 23:29:03.000000000","_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},{"value":0,"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"all":[{"value":0,"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"value":1,"date":"2019-04-24 11:28:59.000000000","_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"value":0,"_account_id":2697,"name":"Jim Fehlig","email":"jfehlig@suse.com","username":"jfehlig"},{"value":0,"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":0,"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":0,"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},{"value":0,"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"value":0,"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"value":0,"_account_id":2697,"name":"Jim Fehlig","email":"jfehlig@suse.com","username":"jfehlig"},{"value":0,"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":0,"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"value":0,"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},{"value":0,"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"}],"values":{" 0":"Default Priority","+1":"Contributor Review Promise","+2":"Core Review Promise"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},{"_account_id":2697,"name":"Jim Fehlig","email":"jfehlig@suse.com","username":"jfehlig"},{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},{"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},{"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2019-03-08 14:04:10.000000000","updated_by":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"reviewer":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"state":"REVIEWER"},{"updated":"2019-03-08 14:04:20.000000000","updated_by":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"reviewer":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"state":"REVIEWER"},{"updated":"2019-03-14 17:07:04.000000000","updated_by":{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},"reviewer":{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},"state":"REVIEWER"},{"updated":"2019-03-15 00:50:15.000000000","updated_by":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"reviewer":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"state":"REVIEWER"},{"updated":"2019-03-19 14:17:55.000000000","updated_by":{"_account_id":2697,"name":"Jim Fehlig","email":"jfehlig@suse.com","username":"jfehlig"},"reviewer":{"_account_id":2697,"name":"Jim Fehlig","email":"jfehlig@suse.com","username":"jfehlig"},"state":"REVIEWER"},{"updated":"2019-03-19 20:22:32.000000000","updated_by":{"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"},"reviewer":{"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"},"state":"REVIEWER"},{"updated":"2019-04-17 11:17:34.000000000","updated_by":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"reviewer":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"state":"REVIEWER"},{"updated":"2019-04-19 00:56:29.000000000","updated_by":{"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},"reviewer":{"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},"state":"REVIEWER"},{"updated":"2019-04-23 23:29:03.000000000","updated_by":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"reviewer":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"state":"REVIEWER"},{"updated":"2019-04-24 00:20:32.000000000","updated_by":{"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},"reviewer":{"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},"state":"REVIEWER"},{"updated":"2019-04-24 04:29:34.000000000","updated_by":{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},"reviewer":{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},"state":"REVIEWER"},{"updated":"2019-04-24 11:19:17.000000000","updated_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"reviewer":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"state":"REVIEWER"},{"updated":"2019-04-24 11:28:59.000000000","updated_by":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"reviewer":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"state":"REVIEWER"},{"updated":"2019-04-24 11:44:46.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"567f1cf3913f8410dac1b0abc2b98e3340ebdf3e","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-03-08 12:31:52.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"7be61b361dba9206f3abf45120a9f0730838c8c1","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-03-08 12:33:12.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"7c819fa2ad7eb4c64470c52df7d1c33c874a3090","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-03-08 12:38:09.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/1/check/openstack-tox-docs/cc2a945/html/ : SUCCESS in 5m 53s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/1/check/openstack-tox-pep8/95d5024/ : SUCCESS in 4m 45s","accounts_in_message":[],"_revision_number":1},{"id":"d173f11208442dff62955f99bc1c1890e6ff54ed","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-03-08 12:39:41.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"f18b6ad394b7c8adb7d156ba11db0fbf998d7a00","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-03-08 12:47:00.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/2/check/openstack-tox-docs/e1f0cb7/html/ : SUCCESS in 5m 50s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/2/check/openstack-tox-pep8/610fc88/ : SUCCESS in 4m 55s","accounts_in_message":[],"_revision_number":2},{"id":"10a008e7b19dd4186d64e8e47e054904160d61f7","author":{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},"date":"2019-03-14 17:07:04.000000000","message":"Patch Set 2: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"d2a9e43632d38d79bafb72bf7b4779c8c26a83fd","author":{"_account_id":4690,"name":"melanie witt","display_name":"melwitt","email":"melwittt@gmail.com","username":"melwitt"},"date":"2019-03-15 00:50:15.000000000","message":"Patch Set 2:\n\nIt looks like there\u0027s a serious concern about the spec in its current form, with regard to hard limiting memory per-VM. I think this spec should be adjusted to address this issue, before we re-approve it, and rather not re-approve it as-is because it was Previously-approved.","accounts_in_message":[],"_revision_number":2},{"id":"b7ad2f714a42f20d0ee9d6ac4b0cf2e1302f79b4","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-03-15 10:27:49.000000000","message":"Patch Set 2: Code-Review-1\n\nBased on Dan\u0027s concerns here, and a chat with Erik Skultetty from \nlibvirt this spec needs some more redesign.  \n\nAnother factor (other than security) to consider with the limit\ncalculation is scaling: people could potentially add hundreds of VirtIO devices to the guest, where a hard-coded memory value added on top of the current memory allocation might simply not be enough for the intended workload, thus causing the VMs fail to boot because of the hard limit.","accounts_in_message":[],"_revision_number":2},{"id":"45b19a98aa11936d2266153cc87564511cd42ef8","author":{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},"date":"2019-03-15 11:40:35.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"1ba38f4eb55967af462fcb2cc3d077d65b7d7a35","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-03-15 11:51:57.000000000","message":"Patch Set 2:\n\nA related quick note:\n\nIntel has an equivalent upcoming, called: \"MKTME\" (Multikey Total Memory Encryption).  Kernel enablement of Intel\u0027s MKTME is in-progress (https://lwn.net/Articles/758313/ -- MKTME enabling).  And they have expressed a desire to integrate MKTME into libvirt (refer: https://www.redhat.com/archives/libvir-list/2019-February/msg01730.html)\n\nSo we (Nova) might want to bear that in mind, too.","accounts_in_message":[],"_revision_number":2},{"id":"d8e294315d91cf4aa99819bde8c1c14e7b36c897","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-03-19 13:53:58.000000000","message":"Patch Set 2: Code-Review-1\n\n(2 comments)\n\ngiven the concerns raised i do think we should modify the spec but i dont think the issues are hard to adress.","accounts_in_message":[],"_revision_number":2},{"id":"962d6a42261f8a7b6fa24081767cc679edd3cd01","author":{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},"date":"2019-03-19 15:26:21.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"f9b5d4d0501875e879892919e6de4ee111e88d62","author":{"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"},"date":"2019-03-19 16:37:26.000000000","message":"Patch Set 2:\n\nCurrently, any memory region backed by the QEMU (including RAM, ROM,\nUEFI pflash and video RAM etc) are pinned for the SEV cases.\n\nThe SEV memory encryption engine uses a tweak such that two identical\nplaintext pages at the different location will have a different ciphertext. So swapping or moving ciphertext of two pages will not result in the plaintext being swapped. By pinning (i.e increasing reference count at kernel layer) we ensure that page will never get moved or migrated.\n\nThe hugepage will guarantee that pages are resident in the memory but  it does not guarantee that pages will never move (aka migrate). The pages are still free to migrate within the hugepages pool and it will be problem for the SEV guest.","accounts_in_message":[],"_revision_number":2},{"id":"76fe41a2962fe0e9cf4fffe7073f15ec8dadd3fe","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-03-19 18:54:49.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"b2a0285ec5a687cf782c23bfc735b09f033e95ae","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-03-19 19:01:35.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"6465d390b3227330bc4af6ab0a3caf21551b40bf","author":{"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"},"date":"2019-03-19 19:26:55.000000000","message":"Patch Set 2:\n\nThe mlock() syscall will ensure that pages are kept locked but the page migration is still possible. See \"migrating mlocked pages\" section in kernel-doc below\n\nhttps://www.kernel.org/doc/Documentation/vm/unevictable-lru.txt\n\nIn typical page migration the pgtable tables are updated and contents are copied from the source to the destination. In case of SEV, the contents copy phase will not provide correct results because the pages contains the encrypted data. Recent SEV firmware spec provides commands which can be used to copy the encrypted contents but it\u0027s not implemented yet. In addition, we also need to work with older firmware and kernel combination.\n\nThe \u003cmemtune\u003e parameter itself does not pin the memory, all it does is raises the rlimit for the process. As part of SEV guest flow QEMU issues a special KVM_MEMORY_ENCRYPT_{REG,UNREG}_REGION ioctls see https://www.kernel.org/doc/Documentation/virtual/kvm/api.txt\n\nThese icotls takes a memory region and pins it using the kernel APIs which ensures that those ranges are excluded from the page move rcu list. While pinning the pages, KVM checks the rlimit to ensure that it  does not blindly act upon the request. If rlimit is not large enough then pining the pages through this ioctl will fail.\n\nThe pages pinned using these icotl will never migrate whereas the pages pinned using the mlock() *can* migrate as you see in kernel-doc.","accounts_in_message":[],"_revision_number":2},{"id":"ef07918c283b8c051ea22d4cbc1377d406b02de6","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-03-19 19:50:56.000000000","message":"Patch Set 2:\n\nok so the requriement is that \nKVM_MEMORY_ENCRYPT_{REG,UNREG}_REGION ioctls are issued by qemu and that the rlimit is large enough that does ioctls dont fail.\n\nif we set the locked memory backing element rlimit is set to infinite and qemu can still use the ioctls to ensure the pages cannot migrate and we will ensure that the pages cant be swapped so that seam like the correc thing to do.\n\nsetting \n\n\u003cmemoryBacking\u003e\n    \u003clocked/\u003e\n\u003c/memoryBacking\u003e\n\nis not the same as calling mlock it  also remvoes the rlimit on locked pages.\n\nthat said unless we also use hugepages we will have acounting issues in placement and potential OOM issue as we will not be properly tracking free pages per numa node when spawning sev instance and risk exausing idiviual numa nodes.\n\nso really i think we need something more like this.\n\n\u003cmemoryBacking\u003e\n    \u003chugepages\u003e\n      \u003cpage size\u003d\"2\" unit\u003d\"M\" nodeset\u003d\"1\"/\u003e\n    \u003c/hugepages\u003e\n    \u003cnosharepages/\u003e\n    \u003clocked/\u003e\n    \u003csource type\u003d\"file\"/\u003e\n    \u003caccess mode\u003d\"shared\"/\u003e\n    \u003callocation mode\u003d\"immediate\"/\u003e\n  \u003c/memoryBacking\u003e\n\nif we dont use hugepages we will need to for the compute node ram allcoation ration to 1 for sev enabled hosts as the \nKVM_MEMORY_ENCRYPT_{REG,UNREG}_REGION ioctls will lock the memroy region in ram preventing oversubsrption via swapping.\nthat in trun will break the placment accounting if ram allocation ration is not 1 and since we would not be useign an explict memory backing we sould not use the resouce track to ensure we did not exaust a numa node as a result the sev guest would be at risk of being killed by the kerenl OOM process. using hugepages + locked will fix most of the issues and the KVM_MEMORY_ENCRYPT_{REG,UNREG}_REGION ioctls will solve the page migration issue allowing sev to work.","accounts_in_message":[],"_revision_number":2},{"id":"bb1fc3dbe75f66908ce8122de024eccc1be0e9c9","author":{"_account_id":30138,"name":"Brijesh Singh","email":"brijesh.singh@amd.com"},"date":"2019-03-19 20:22:32.000000000","message":"Patch Set 2:\n\nI am fairly new to libvirt, you all are well versed into libvirt and various xml tags. I don\u0027t have any strong preference for which tag to use.\n\nI wanted to highlight that just by using the hugepages is not sufficient, we need to ensure that pages does not move and for that  we need to set rlimit to either infinite or compute it otherwise SEV icots will fail.\n\nThe \u003cmemtune\u003e seems to do the trick for raising the rlimit. If there is something better then I am all for using that.\n\nIf \n\n\u003cmemoryBacking\u003e\n    \u003clocked/\u003e\n\u003c/memoryBacking\u003e\n\nsets the rlimit to unlimited then that should work fine.\n\nIf you are manually setting the rlimit then make sure you cover for more than the guest RAM size. Because as part of SEV flow we pin guest RAM, ROM, VRAM and UEFI Pflash regions.","accounts_in_message":[],"_revision_number":2},{"id":"4d0824c6dc3ce07f9052a83fa61aef6ee00923c8","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-03-20 13:49:30.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"a3909bdadb67f9043f722695ad3a102032fcd929","author":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"date":"2019-04-08 13:46:39.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"ef1b67da91a1ec22b5e17b2172260e4fd76868c4","author":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"date":"2019-04-08 13:50:33.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"8c227d7971e6f2f1d86bda9ca1f851da7c855244","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-08 14:13:07.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/4/check/openstack-tox-docs/6430cf2/html/ : SUCCESS in 9m 48s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/4/check/openstack-tox-pep8/bd2e079/ : FAILURE in 5m 03s","accounts_in_message":[],"_revision_number":4},{"id":"73a09225752df4502580ceb942f173563229e91f","author":{"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},"date":"2019-04-08 23:43:47.000000000","message":"Patch Set 4: Code-Review-1\n\n(1 comment)\n\nI\u0027d like a small change to remove \"SEV_ES\" from the policy because it is not ready.","accounts_in_message":[],"_revision_number":4},{"id":"f6f1f3686bdb818858b8dafc442aca82d071a76e","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-15 14:34:33.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"6a3962a4cf3a817503796cab4c6e7e2a55f0bae4","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-15 14:40:56.000000000","message":"Uploaded patch set 6: Commit message was updated.","accounts_in_message":[],"_revision_number":6},{"id":"ed7814d3802189d74f13990741413eeb67ae3b14","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-15 14:43:54.000000000","message":"Patch Set 6:\n\n(3 comments)","accounts_in_message":[],"_revision_number":6},{"id":"29cde13adceeb688b62150fb58697297a820b0e8","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-15 14:54:53.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/6/check/openstack-tox-docs/9eb21c6/html/ : SUCCESS in 8m 18s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/6/check/openstack-tox-pep8/7e772bf/ : SUCCESS in 5m 21s","accounts_in_message":[],"_revision_number":6},{"id":"fc8c33bd1da35da86d03776b95453e9c3725b742","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-16 10:51:24.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"3e0a56e312079389652a85eba8910ecff51cc5ac","author":{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},"date":"2019-04-16 11:00:07.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"102805a62e70852d95f33a0f5742fa15e0de7ea8","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-16 20:48:00.000000000","message":"Patch Set 6: Code-Review-1\n\n(6 comments)\n\nThe addition of the SEV_CONTEXT resource class makes all the trait work redundant. It sucks that you\u0027ve already done a bunch of the implementation, but is there some good reason we shouldn\u0027t just do that?\n\nIf there is a good reason, please mention it in Alternatives.","accounts_in_message":[],"_revision_number":6},{"id":"5222c6fba0ffb3cd6f6652f68584c7a814df1ac9","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-16 20:49:07.000000000","message":"Patch Set 6:\n\nBy the way, this spec feels really heavy on implementation details to me. Maybe that\u0027s intentional.","accounts_in_message":[],"_revision_number":6},{"id":"7fb7c529b6dbaf406b3e65b48cbcbf09d570a3f3","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-16 23:18:35.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"3a88e7cd3c762e55710bcba53ddbb9d1f4e45c54","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-16 23:34:20.000000000","message":"Patch Set 6:\n\n(6 comments)\n\n\u003e The addition of the SEV_CONTEXT resource class makes all the trait work redundant.\n\nUrgh, you are probably right :-/\n\n\u003e It sucks that you\u0027ve already done a bunch of the implementation,\n\nWell, actually not too much work has gone *directly* into the provision and consumption of HW_CPU_AMD_SEV specifically.  True, it\u0027s been merged into os-traits, but that was a small patch.  Much more effort has gone into the SEV detection and the configuration of an SEV guest.\n\nThe cost of change of direction might not be too big:\n\n- Introduce the SEV_CONTEXT resource class\n\n- Remove the HW_CPU_AMD_SEV trait, unless there\u0027s still a use for it we somehow missed.  Having a trait which noone used in the code for a single release is regrettable, but far from disastrous.\n\n- Change https://review.openstack.org/#/c/638680/7/nova/virt/libvirt/driver.py@640 to update the provider tree with the inventory for this class rather than using a new capability\n\n... and that\u0027s pretty much it.  The main sunk cost would be all the effort I put into implementing capabilities-to-traits conversion, but even if SEV ended up not using that, I would certainly expect it to be useful elsewhere based on what I\u0027ve been told.  Indeed I think I already saw Matt start some work which consumes it.  We could just agree that you cunningly hoodwinked me into doing it, and I\u0027ll consider a beer in Denver fair payment ;-)\n\n\u003e but is there some good reason we shouldn\u0027t just do that?\n\u003e If there is a good reason, please mention it in Alternatives.\n\nThere probably isn\u0027t.  I can adapt the spec, although I\u0027d prefer to hear what others think first.  Sean, Matt, Jay, Chris etc. - any opinions?\n\n\u003e By the way, this spec feels really heavy on implementation details to me. Maybe that\u0027s intentional.\n\nWell it started much lighter, but it\u0027s attracted a heavy amount of feedback, and each time concerns are addressed it gets a little bigger ;-)  Even getting it approved for Stein took 16 patch sets, and that was before the new wave of realisations which have arrived for this new round in Train.  If you think stuff can be taken out then suggestions are extremely welcome, but everything which has gone in so far seemed necessary in order to address concerns which were raised, so I suspect taking stuff out could cause some regressions...","accounts_in_message":[],"_revision_number":6},{"id":"d816317ebb504a1c7ce32a6fe6e27be16549e8d3","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-16 23:41:41.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/7/check/openstack-tox-docs/4693389/html/ : SUCCESS in 8m 30s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/7/check/openstack-tox-pep8/61d243a/ : SUCCESS in 6m 10s","accounts_in_message":[],"_revision_number":7},{"id":"e96e259d914b64200f854a56b490d556f3da4cf1","author":{"_account_id":1779,"name":"Daniel Berrange","email":"berrange@redhat.com","username":"berrange"},"date":"2019-04-17 08:25:22.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"c1a115e962c5f8b05aa7223ca61bbc5ab4a3f267","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-17 11:17:34.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"9e2e40c9004abb373d60925f8452d6d2596481d1","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-17 17:03:27.000000000","message":"Patch Set 7: Code-Review-1\n\n(3 comments)\n\n\u003e Remove the HW_CPU_AMD_SEV trait, unless there\u0027s still a use for it we somehow missed.\n\nNope, never remove things from os-traits.\n\n\u003e Having a trait which noone used in the code for a single release is regrettable, but far from disastrous.\n\nRight.\n\n\u003e The main sunk cost would be all the effort I put into implementing capabilities-to-traits conversion\n\nNot sunk, we needed that anyway.\n\n\u003e a beer in Denver fair payment ;-)\n\nDeal.\n\n\u003e I\u0027d prefer to hear what others think first.  Sean, Matt, Jay, Chris etc. - any opinions?\n\nYes, I would definitely want others in the conversation before you go to a lot of work to rewrite.\n\n\u003e \u003e By the way, this spec feels really heavy on implementation details to me. Maybe that\u0027s intentional.\n\u003csnip\u003e\n\u003e If you think stuff can be taken out then suggestions are extremely welcome\n\nNo; I really don\u0027t understand most of it, so I can\u0027t say whether it\u0027s necessary to include. Definitely defer to the SMEs on that, and they\u0027ve clearly guided it in this direction, so cool.\n\nVoting to register that we\u0027re not done talking through the trait-vs-rc issue.","accounts_in_message":[],"_revision_number":7},{"id":"fd090b7cba0c26e457617dd00fad64b988b6ea32","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-18 15:30:09.000000000","message":"Uploaded patch set 8.","accounts_in_message":[],"_revision_number":8},{"id":"ec0b47b3a74d9bb13d0f3a64ed968af27df97f17","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-18 15:33:49.000000000","message":"Uploaded patch set 9: Patch Set 8 was rebased.","accounts_in_message":[],"_revision_number":9},{"id":"369e998f059ef0938726a40693a996a9ec5c33f2","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-18 15:35:29.000000000","message":"Patch Set 7:\n\n(3 comments)\n\n\u003e \u003e Remove the HW_CPU_AMD_SEV trait, unless there\u0027s still a use for it we somehow missed.\n\u003e \n\u003e Nope, never remove things from os-traits.\n\nNot even if the trait has never been used, never has a chance of being used, and os-traits has no deprecation mechanism to prevent people from trying erroneously?\n\nI\u0027ve just submitted a new patch set which ditches the idea of using the trait and proposes removing it, but I can change that if there is compelling rationale for keeping it - just not sure what that might be at this point.\n\n\u003e \u003e The main sunk cost would be all the effort I put into implementing capabilities-to-traits conversion\n\u003e \n\u003e Not sunk, we needed that anyway.\n\nWell I said \"sunk\" not \"wasted\" ;-)\n\n\u003e \u003e I\u0027d prefer to hear what others think first.  Sean, Matt, Jay, Chris etc. - any opinions?\n\u003e \n\u003e Yes, I would definitely want others in the conversation before you go to a lot of work to rewrite.\n\nSure - I don\u0027t think it will be a *huge* amount of work, and certainly not to the extent of being a rewrite, but obviously getting feedback from others ASAP will be very helpful.\n\n\u003e \u003e By the way, this spec feels really heavy on implementation details to me. Maybe that\u0027s intentional.\n\u003e \n\u003e \u003csnip\u003e\n\u003e \n\u003e \u003e If you think stuff can be taken out then suggestions are extremely welcome\n\u003e \n\u003e No; I really don\u0027t understand most of it, so I can\u0027t say whether it\u0027s necessary to include. Definitely defer to the SMEs on that, and they\u0027ve clearly guided it in this direction, so cool.\n\nGot it ;-)\n\n\u003e \u003e Voting to register that we\u0027re not done talking through the trait-vs-rc issue.\n\nAck.","accounts_in_message":[],"_revision_number":7},{"id":"ed6585f9146195236ecd8a8731694bc69a64c583","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-18 15:45:55.000000000","message":"Patch Set 9: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/9/check/openstack-tox-docs/71456c0/html/ : SUCCESS in 7m 36s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/9/check/openstack-tox-pep8/6688d50/ : FAILURE in 5m 05s","accounts_in_message":[],"_revision_number":9},{"id":"e10535c84aefbcecdff098af84ecad27908e9329","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-18 17:07:18.000000000","message":"Uploaded patch set 10.","accounts_in_message":[],"_revision_number":10},{"id":"176ccf2595b09a1bf52685c973c739f813b8c8e0","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-18 17:21:20.000000000","message":"Patch Set 10: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/10/check/openstack-tox-docs/071a5b5/html/ : SUCCESS in 9m 21s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/10/check/openstack-tox-pep8/2752368/ : SUCCESS in 6m 58s","accounts_in_message":[],"_revision_number":10},{"id":"ef0ad5b86f45c4bce11cbb6567ce554618a56a09","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-18 17:55:47.000000000","message":"Patch Set 10: Code-Review-1\n\n(4 comments)\n\n\u003e Not even if the trait has never been used, never has a chance of being used, and os-traits has no deprecation mechanism to prevent people from trying erroneously?\n\nNot even then. The pathological theoretical case is where somebody (not limited to nova) is on 0.11.0 or 0.12.0, sees the trait and uses it for $whatever, then their world breaks when they upgrade to 0.13.0. Pin at 0.12.0? Not if they want to use some new trait introduced after that. Blacklist 0.11.0 and 0.12.0? Can\u0027t do that in an already-published release.\n\nAnd... it\u0027s just not that big a deal. I\u0027m only guessing, but I bet there\u0027s more than a few traits in there that haven\u0027t ever been used, and some that never will be. Shrug.\n\n\u003e I\u0027ve just submitted a new patch set which ditches the idea of using the trait and proposes removing it\n\nTo be clear, I\u0027m not suggesting reinstating use of the trait in this feature. Just saying we need to ignore the fact that the trait exists in os-traits and not worry about trying to remove it.\n\nSo - the downvote is to purge any mention of removing the trait from os-traits. I would also prefer we rethink the conf option a little bit, or explicitly punt that discussion to the implementation; but I\u0027ll defer to other reviewers\u0027 opinions on that.","accounts_in_message":[],"_revision_number":10},{"id":"937b7947404efb76db3e2b8d0a2044efc95fe881","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-18 23:20:42.000000000","message":"Uploaded patch set 11.","accounts_in_message":[],"_revision_number":11},{"id":"2998589ad62070be247518f08c81d3643f8556e5","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-18 23:20:52.000000000","message":"Patch Set 10:\n\n(4 comments)","accounts_in_message":[],"_revision_number":10},{"id":"92136d968ff36d3420a958e1ddcd23f670cc0ab3","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-18 23:32:55.000000000","message":"Patch Set 11: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/11/check/openstack-tox-docs/a439f50/html/ : SUCCESS in 7m 26s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/11/check/openstack-tox-pep8/8a13ae9/ : SUCCESS in 5m 00s","accounts_in_message":[],"_revision_number":11},{"id":"44ed33b71b101e740d9b2ce7b492ce43340c79fe","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-22 21:22:11.000000000","message":"Patch Set 11:\n\n(3 comments)\n\nPassive-aggressive no-vote for now, for the two issues noted inline.\n\nBut I think this is getting real close.","accounts_in_message":[],"_revision_number":11},{"id":"6e3eaf806cee0e3819efb25a7861e9eacaae3b35","author":{"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},"date":"2019-04-22 22:53:25.000000000","message":"Patch Set 11: Code-Review+1","accounts_in_message":[],"_revision_number":11},{"id":"5e22fedb653a93bdbcf4197ae37c0a3fdd8da044","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-23 15:29:38.000000000","message":"Patch Set 11:\n\n(2 comments)\n\nOne final thought: given that we already agreed that providing the trait still has merit, this would provide three different ways to initially request SEV via a flavor extra spec:\n\n(1) encrypt_memory\u003dtrue\n(2) resources:AMD_SEV_CONTEXT\u003d1 or resources:MEM_ENCRYPTED_CONTEXT\u003d1 or similar (depending on the outcome of that discussion)\n(3) trait:HW_CPU_AMD_SEV\n\n(1) seems like the clear winner, since (2) is potentially open to misuse with values other than 1, and (3) should not be used unless in conjunction with one of the other two, since by itself it does not take care of the per-host limit.","accounts_in_message":[],"_revision_number":11},{"id":"9d8a31c1c9363a148c0b854cd960ae683793a409","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-23 15:41:53.000000000","message":"Patch Set 11:\n\n@Dan Thanks a lot for all the info and advice.  I\u0027ve tried to incorporate it into the latest patchset - in particular the new \"Memory locking and accounting\" section:\n\nhttp://logs.openstack.org/94/641994/11/check/openstack-tox-docs/a439f50/html/specs/train/approved/amd-sev-libvirt-support.html#memory-locking-and-accounting\n\nHope it looks good to you now but don\u0027t hesitate to critique if you spot anything which still needs work.","accounts_in_message":[],"_revision_number":11},{"id":"406e0ef9a80e90a4085880d6e25b2f0cf2cd0afe","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2019-04-23 15:47:14.000000000","message":"Patch Set 11: Code-Review+2\n\n(4 comments)\n\nRelatively minor quibble about describing an inventory amount as a \"limit\", but overall I support the spec.\n\n-jay","accounts_in_message":[],"_revision_number":11},{"id":"700c7c884d7334353d70a7ec742c941d769e5aa7","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-23 17:53:41.000000000","message":"Patch Set 11:\n\n(2 comments)\n\n\u003e One final thought: given that we already agreed that providing the trait still has merit, this would provide three different ways to initially request SEV via a flavor extra spec:\n\u003e \n\u003e (1) encrypt_memory\u003dtrue\n\u003e (2) resources:AMD_SEV_CONTEXT\u003d1 or resources:MEM_ENCRYPTED_CONTEXT\u003d1 or similar (depending on the outcome of that discussion)\n\u003e (3) trait:HW_CPU_AMD_SEV\n\u003e \n\u003e (1) seems like the clear winner, since (2) is potentially open to misuse with values other than 1, and (3) should not be used unless in conjunction with one of the other two, since by itself it does not take care of the per-host limit.\n\nYes, this is a good point, it would technically be possible for the request to *land* on the SEV host with any of the three options above. However, at spawn time, the driver also needs to do whatever magic to make the SEV context actually attached to the VM (or however that\u0027s phrased). So we declare that we only support (1), and document it thus. And better yet, we add validation such that if (2) or (3) (the latter without corresponding (1)) is given, we error.","accounts_in_message":[],"_revision_number":11},{"id":"23cd7a345a63d259851fe9792c42664346641258","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-23 17:59:30.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"bbfc5324725658f5ac3866fdb16bcc267d77e832","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2019-04-23 18:05:33.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"7f7db86d62d6469fb136b2cb4d0fa45a9c884841","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-04-23 21:23:16.000000000","message":"Patch Set 11: Code-Review+1\n\n(2 comments)\n\nok we have been discussing this on irc. i think there are some minor nits w coudl clean up later but im fine with this verions","accounts_in_message":[],"_revision_number":11},{"id":"02eacf870cdc01123ead2d752ad83e524ded21ae","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-23 22:56:22.000000000","message":"Uploaded patch set 12.","accounts_in_message":[],"_revision_number":12},{"id":"1fc5e94e23ed75f9d9aee3471c99ef81bc0985bb","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-23 23:00:30.000000000","message":"Patch Set 11:\n\n(4 comments)\n\nThanks for all the helpful discussions today. Patch set 12 attempts to capture all the progress we made. Hopefully this is good enough now and any further refinements can be done as follow-ups reviews, although I suspect the remainder now are pretty much implementation details (e.g. the MAXINT one) which could be decided as the code gets written and reviewed.","accounts_in_message":[],"_revision_number":11},{"id":"0c4650a579ce42d5f7752b5e15f5ea2f65318a50","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-23 23:15:52.000000000","message":"Patch Set 12: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/12/check/openstack-tox-docs/1671132/html/ : SUCCESS in 8m 18s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/12/check/openstack-tox-pep8/20a63ec/ : SUCCESS in 5m 22s","accounts_in_message":[],"_revision_number":12},{"id":"775ed5b840f9d9b7277d9e0d380cca7ad6992c71","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-23 23:29:03.000000000","message":"Patch Set 12: Code-Review+2\n\n(1 comment)\n\nGood.\n\nOne thing we discussed that should maybe be mentioned: if we find an explicit placement-ese request for the MEM_ENCRYPTION_CONTEXT, we should error.\n\nThat could be a fup (or just don\u0027t forget it in the impl).","accounts_in_message":[],"_revision_number":12},{"id":"0d0d7b3ee886d31866f17b1338ff0e24add6d3c0","author":{"_account_id":24938,"name":"Bryan Stephenson","email":"bryan.stephenson@suse.com","username":"bryans"},"date":"2019-04-24 00:20:32.000000000","message":"Patch Set 12: Code-Review+1","accounts_in_message":[],"_revision_number":12},{"id":"b745927a5a988c97bc101b88e2760898e6b772a3","author":{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},"date":"2019-04-24 04:29:34.000000000","message":"Patch Set 12: Code-Review+1","accounts_in_message":[],"_revision_number":12},{"id":"0796dbc5d99bb7609e7f6db7b3ed47b11b21f798","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-04-24 11:19:17.000000000","message":"Patch Set 12: Code-Review+1\n\nyep im still good with this +1","accounts_in_message":[],"_revision_number":12},{"id":"f56c2569df4dd939817b8bd1b6af1939fee680b9","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2019-04-24 11:28:59.000000000","message":"Patch Set 12: Code-Review+2 Workflow+1\n\n(2 comments)\n\nI\u0027m happy with this. Thanks for the work and the patience.\n\n-jay","accounts_in_message":[],"_revision_number":12},{"id":"5c32a2760cf38608deb6f496b11e89fb0e8a4719","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-24 11:30:40.000000000","message":"Patch Set 12: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":12},{"id":"21d4fba958afd2e9c7e62243ca8198109b3b4021","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-24 11:44:46.000000000","message":"Patch Set 12: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/94/641994/12/gate/openstack-tox-docs/067b4c1/html/ : SUCCESS in 7m 31s\n- openstack-tox-pep8 http://logs.openstack.org/94/641994/12/gate/openstack-tox-pep8/cb5e5e4/ : SUCCESS in 4m 49s","accounts_in_message":[],"_revision_number":12},{"id":"c5c506cbb45699f2aa76245ce5bde640ade3fe83","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-24 11:44:46.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":12},{"id":"8a16122dd84f0b48b158be47dcd5bb9f87210899","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-24 14:12:10.000000000","message":"Patch Set 12:\n\n(1 comment)","accounts_in_message":[],"_revision_number":12},{"id":"aa0239e7361d7f752e0b27e681003dafbf4bf761","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-04-24 16:56:33.000000000","message":"Patch Set 12:\n\n(1 comment)","accounts_in_message":[],"_revision_number":12},{"id":"66b38e51ec6378c0f9221ab82dd01c52fcafc09b","author":{"_account_id":14070,"name":"Eric Fried","email":"openstack@fried.cc","username":"efried"},"date":"2019-04-24 20:28:06.000000000","message":"Patch Set 12:\n\n(1 comment)","accounts_in_message":[],"_revision_number":12}],"current_revision_number":12,"current_revision":"4671f102654c989db7f9911fc206e80b7aa2db2e","revisions":{"9bf96f8b6449e439098bd41daae16d53873a5b68":{"kind":"REWORK","_number":1,"created":"2019-03-08 12:31:52.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/1"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Stein, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/9bf96f8b6449e439098bd41daae16d53873a5b68"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/9bf96f8b6449e439098bd41daae16d53873a5b68"}]},"branch":"refs/heads/master"},"a3456cda878da568d77064d33b903944377b3a90":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2019-03-08 12:39:41.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/2"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:39:13.000000000","tz":0},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/a3456cda878da568d77064d33b903944377b3a90"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/a3456cda878da568d77064d33b903944377b3a90"}]},"branch":"refs/heads/master"},"7309ab422b9d4acdfbe81173c1cc6aa4e3550d92":{"kind":"REWORK","_number":3,"created":"2019-04-08 13:46:39.000000000","uploader":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"ref":"refs/changes/94/641994/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/3"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Boris Bobrov","email":"bbobrov@suse.com","date":"2019-04-08 13:46:37.000000000","tz":120},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n1. Memory locking is now done using \u003clocked/\u003e element of\n\u003cmemoryBacking\u003e. It is changed because, as pointed out in the review,\nwe cannot use \u003chard_limit\u003e.\n\n2. TODO: accounting metioned in the review\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7309ab422b9d4acdfbe81173c1cc6aa4e3550d92"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7309ab422b9d4acdfbe81173c1cc6aa4e3550d92"}]},"branch":"refs/heads/master"},"b14d6ac2f4d9f32f85bbc8dd96b68eacf8ee647c":{"kind":"REWORK","_number":4,"created":"2019-04-08 13:50:33.000000000","uploader":{"_account_id":13478,"name":"Boris Bobrov","email":"b.bobrov@sap.com","username":"bbobrov"},"ref":"refs/changes/94/641994/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/4"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Boris Bobrov","email":"bbobrov@suse.com","date":"2019-04-08 13:49:33.000000000","tz":120},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n1. Memory locking is now done using \u003clocked/\u003e element of\n\u003cmemoryBacking\u003e. It is changed because, as pointed out in the review,\nwe cannot use \u003chard_limit\u003e;\n\n2. Remove mentions of ``_set_features()`` because it had to be\nimplemented differently;\n\n3. TODO: accounting metioned in the review\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/b14d6ac2f4d9f32f85bbc8dd96b68eacf8ee647c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/b14d6ac2f4d9f32f85bbc8dd96b68eacf8ee647c"}]},"branch":"refs/heads/master"},"7e13c598e5d6f5d73c15434976d8de973a172184":{"kind":"REWORK","_number":5,"created":"2019-04-15 14:34:33.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/5"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-15 14:33:50.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n1. Memory locking is now done using \u003clocked/\u003e element of\n\u003cmemoryBacking\u003e. It is changed because, as pointed out in the review,\nwe cannot use \u003chard_limit\u003e;\n\n2. Remove mentions of ``_set_features()`` because it had to be\nimplemented differently;\n\n3. TODO: accounting metioned in the review\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7e13c598e5d6f5d73c15434976d8de973a172184"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7e13c598e5d6f5d73c15434976d8de973a172184"}]},"branch":"refs/heads/master"},"5819d99d9c5753e4293751b9e6e90f5cf4f925b3":{"kind":"NO_CODE_CHANGE","_number":6,"created":"2019-04-15 14:40:56.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/6"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-15 14:39:44.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n- Memory locking is now done using \u003clocked/\u003e element of\n  \u003cmemoryBacking\u003e. It is changed because, as pointed out in the\n  review, we cannot use \u003chard_limit\u003e;\n\n- Remove mentions of ``_set_features()`` because it had to be\n  implemented differently;\n\n- Incorporate a lot of feedback and new information which has arisen\n  regarding memory locking and accounting, both in the review and\n  elsewhere (mailing lists etc.).\n\n- Cover the per-machine limit for SEV guests (initially via a config\n  option, with plans to later auto-detect).\n\n- Drop SEV-ES from the policy.\n\n- Update to take into account work which has already been done.\n\n- Restructure some sections so that the amount of technical detail\n  is kept separately in order not to overwhelm the key messages.\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/5819d99d9c5753e4293751b9e6e90f5cf4f925b3"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/5819d99d9c5753e4293751b9e6e90f5cf4f925b3"}]},"branch":"refs/heads/master"},"b1560f569f52969969510b5a1a6eccf543ae3b86":{"kind":"REWORK","_number":7,"created":"2019-04-16 23:18:35.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/7"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-16 23:16:56.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n- Memory locking is now done using \u003clocked/\u003e element of\n  \u003cmemoryBacking\u003e. It is changed because, as pointed out in the\n  review, we cannot use \u003chard_limit\u003e;\n\n- Remove mentions of ``_set_features()`` because it had to be\n  implemented differently;\n\n- Incorporate a lot of feedback and new information which has arisen\n  regarding memory locking and accounting, both in the review and\n  elsewhere (mailing lists etc.).\n\n- Cover the per-machine limit for SEV guests (initially via a config\n  option, with plans to later auto-detect).\n\n- Drop SEV-ES from the policy.\n\n- Update to take into account work which has already been done.\n\n- Restructure some sections so that the amount of technical detail\n  is kept separately in order not to overwhelm the key messages.\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/b1560f569f52969969510b5a1a6eccf543ae3b86"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/b1560f569f52969969510b5a1a6eccf543ae3b86"}]},"branch":"refs/heads/master"},"ad273d7fae2225c9f643db8052bb5a56218afc61":{"kind":"REWORK","_number":8,"created":"2019-04-18 15:30:09.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/8"}}},"commit":{"parents":[{"commit":"d796b33774cc4e21c663885a57141e93052e5546","subject":"Merge \"Amend the detach-boot-volume design\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/d796b33774cc4e21c663885a57141e93052e5546"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-18 15:28:11.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n- Memory locking is now done using \u003clocked/\u003e element of\n  \u003cmemoryBacking\u003e. It is changed because, as pointed out in the\n  review, we cannot use \u003chard_limit\u003e;\n\n- Incorporate a lot of feedback and new information which has arisen\n  regarding memory locking and accounting, both in the review and\n  elsewhere (mailing lists etc.).\n\n- Switch from a trait-based approach to one based around a new\n  SEV_CONTEXT resource class.  This covers the per-machine limit for\n  SEV guests (initially via a config option, with plans to later\n  auto-detect).\n\n- Remove mentions of ``_set_features()`` because it had to be\n  implemented differently;\n\n- Drop SEV-ES from the suggested policy.\n\n- Update to take into account work which has already been done.\n\n- Restructure some sections so that the amount of technical detail\n  is kept separately in order not to overwhelm the key messages.\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/ad273d7fae2225c9f643db8052bb5a56218afc61"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/ad273d7fae2225c9f643db8052bb5a56218afc61"}]},"branch":"refs/heads/master"},"895306012885989f6febe2cec42440b834ea4c24":{"kind":"TRIVIAL_REBASE","_number":9,"created":"2019-04-18 15:33:49.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/9","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/9","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/9"}}},"commit":{"parents":[{"commit":"eb3afea28eba5fb74cf137e556abd2f47981d1c7","subject":"Add host and hypervisor_hostname flag to create server","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/eb3afea28eba5fb74cf137e556abd2f47981d1c7"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-18 15:33:41.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n- Memory locking is now done using \u003clocked/\u003e element of\n  \u003cmemoryBacking\u003e. It is changed because, as pointed out in the\n  review, we cannot use \u003chard_limit\u003e;\n\n- Incorporate a lot of feedback and new information which has arisen\n  regarding memory locking and accounting, both in the review and\n  elsewhere (mailing lists etc.).\n\n- Switch from a trait-based approach to one based around a new\n  SEV_CONTEXT resource class.  This covers the per-machine limit for\n  SEV guests (initially via a config option, with plans to later\n  auto-detect).\n\n- Remove mentions of ``_set_features()`` because it had to be\n  implemented differently;\n\n- Drop SEV-ES from the suggested policy.\n\n- Update to take into account work which has already been done.\n\n- Restructure some sections so that the amount of technical detail\n  is kept separately in order not to overwhelm the key messages.\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/895306012885989f6febe2cec42440b834ea4c24"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/895306012885989f6febe2cec42440b834ea4c24"}]},"branch":"refs/heads/master"},"1e3a26b82cf731aa3fded15a3ebcd4d3dc05178b":{"kind":"REWORK","_number":10,"created":"2019-04-18 17:07:18.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/10","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/10","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/10"}}},"commit":{"parents":[{"commit":"eb3afea28eba5fb74cf137e556abd2f47981d1c7","subject":"Add host and hypervisor_hostname flag to create server","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/eb3afea28eba5fb74cf137e556abd2f47981d1c7"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-18 17:05:58.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n- Memory locking is now done using \u003clocked/\u003e element of\n  \u003cmemoryBacking\u003e. It is changed because, as pointed out in the\n  review, we cannot use \u003chard_limit\u003e;\n\n- Incorporate a lot of feedback and new information which has arisen\n  regarding memory locking and accounting, both in the review and\n  elsewhere (mailing lists etc.).\n\n- Switch from a trait-based approach to one based around a new\n  SEV_CONTEXT resource class.  This covers the per-machine limit for\n  SEV guests (initially via a config option, with plans to later\n  auto-detect).\n\n- Remove mentions of ``_set_features()`` because it had to be\n  implemented differently;\n\n- Drop SEV-ES from the suggested policy.\n\n- Update to take into account work which has already been done.\n\n- Restructure some sections so that the amount of technical detail\n  is kept separately in order not to overwhelm the key messages.\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/1e3a26b82cf731aa3fded15a3ebcd4d3dc05178b"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/1e3a26b82cf731aa3fded15a3ebcd4d3dc05178b"}]},"branch":"refs/heads/master"},"93c25dbb3f1a0d214f9eb3a8cab6742a1dec220c":{"kind":"REWORK","_number":11,"created":"2019-04-18 23:20:42.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/11","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/11","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/11"}}},"commit":{"parents":[{"commit":"eb3afea28eba5fb74cf137e556abd2f47981d1c7","subject":"Add host and hypervisor_hostname flag to create server","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/eb3afea28eba5fb74cf137e556abd2f47981d1c7"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-18 23:16:27.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n- Memory locking is now done using \u003clocked/\u003e element of\n  \u003cmemoryBacking\u003e. It is changed because, as pointed out in the\n  review, we cannot use \u003chard_limit\u003e;\n\n- Incorporate a lot of feedback and new information which has arisen\n  regarding memory locking and accounting, both in the review and\n  elsewhere (mailing lists etc.).\n\n- Switch from a trait-based approach to one based around a new\n  SEV_CONTEXT resource class.  This covers the per-machine limit for\n  SEV guests (initially via a config option, with plans to later\n  auto-detect).\n\n- Remove mentions of ``_set_features()`` because it had to be\n  implemented differently;\n\n- Drop SEV-ES from the suggested policy.\n\n- Update to take into account work which has already been done.\n\n- Restructure some sections so that the amount of technical detail\n  is kept separately in order not to overwhelm the key messages.\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/93c25dbb3f1a0d214f9eb3a8cab6742a1dec220c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/93c25dbb3f1a0d214f9eb3a8cab6742a1dec220c"}]},"branch":"refs/heads/master"},"4671f102654c989db7f9911fc206e80b7aa2db2e":{"kind":"REWORK","_number":12,"created":"2019-04-23 22:56:22.000000000","uploader":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"ref":"refs/changes/94/641994/12","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/94/641994/12","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/94/641994/12"}}},"commit":{"parents":[{"commit":"eb3afea28eba5fb74cf137e556abd2f47981d1c7","subject":"Add host and hypervisor_hostname flag to create server","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/eb3afea28eba5fb74cf137e556abd2f47981d1c7"}]}],"author":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-03-08 12:22:12.000000000","tz":0},"committer":{"name":"Adam Spiers","email":"aspiers@suse.com","date":"2019-04-23 22:52:54.000000000","tz":60},"subject":"Re-approve AMD SEV support for Train","message":"Re-approve AMD SEV support for Train\n\nWork on AMD SEV support is progressing well:\n\n   https://review.openstack.org/#/q/topic:bp/amd-sev-libvirt-support\n\nbut unfortunately did not quite reach completion in time for the Stein\nrelease.  So re-submit the spec for approval for Train, according to\nthe process described at:\n\n   https://specs.openstack.org/openstack/nova-specs/readme.html#previously-approved-specifications\n\nIn addition to re-targeting, the following changes to the spec were\nmade:\n\n- Memory locking is now done using \u003clocked/\u003e element of\n  \u003cmemoryBacking\u003e. It is changed because, as pointed out in the\n  review, we cannot use \u003chard_limit\u003e;\n\n- Incorporate a lot of feedback and new information which has arisen\n  regarding memory locking and accounting, both in the review and\n  elsewhere (mailing lists etc.).\n\n- Switch from a trait-based approach to one based around a new\n  MEM_ENCRYPTION_CONTEXT resource class.  This covers the per-machine\n  limit for SEV guests (initially via a config option, with plans to\n  later auto-detect).\n\n- Propose a new extra spec / image property parameter\n  hw:mem_encryption which under the hood gets translated to a\n  requirement on the new resource class.\n\n- Remove mentions of ``_set_features()`` because it had to be\n  implemented differently;\n\n- Drop SEV-ES from the suggested policy.\n\n- Update to take into account work which has already been done.\n\n- Restructure some sections so that the amount of technical detail\n  is kept separately in order not to overwhelm the key messages.\n\nChange-Id: I4ad7de08d55ef0d8b74719f60966f545a36a12eb\nblueprint: amd-sev-libvirt-support\nPreviously-approved: Stein\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/4671f102654c989db7f9911fc206e80b7aa2db2e"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/4671f102654c989db7f9911fc206e80b7aa2db2e"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
