)]}'
{"id":"openstack%2Fnova~828980","triplet_id":"openstack%2Fnova~stable%2Fussuri~I75408b4e8fbd0fd3e44ce2a3b417107b4cff3d38","project":"openstack/nova","branch":"stable/ussuri","topic":"bug/1960758-ussuri-v2","attention_set":{},"removed_from_attention_set":{"28621":{"account":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"last_update":"2022-04-19 18:11:18.000000000","reason":"Change was abandoned"}},"hashtags":[],"change_id":"I75408b4e8fbd0fd3e44ce2a3b417107b4cff3d38","subject":"[stable-only] libvirt: UEFI: skip OVMF_CODE.secboot.fd on pc if possible","status":"ABANDONED","created":"2022-02-13 22:28:23.000000000","updated":"2022-04-19 20:10:39.000000000","total_comment_count":5,"unresolved_comment_count":1,"has_review_started":true,"meta_rev_id":"d08e60686a03f4a2c588eb9f851280ad52f1ee62","_number":828980,"virtual_id_number":828980,"owner":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"tag":"autogenerated:zuul:check","value":1,"date":"2022-03-06 00:59:47.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"disliked":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"all":[{"value":-1,"date":"2022-04-12 10:04:04.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":-1,"default_value":0,"optional":true},"Workflow":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"permitted_voting_range":{"min":0,"max":2},"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"permitted_voting_range":{"min":0,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{" 0":"Default Priority","+1":"Contributor Review Promise","+2":"Core Review Promise"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"CC":[{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2022-02-13 23:43:19.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2022-02-14 00:22:00.000000000","updated_by":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"reviewer":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"state":"CC"},{"updated":"2022-04-12 10:04:04.000000000","updated_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"reviewer":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"state":"REVIEWER"}],"messages":[{"id":"2f47ce877df971a3ca1f57744be89ed3accc7dd8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-02-13 22:28:23.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"9a51e1290c4b9f7967f8ac642a0e2d1d050417d8","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-02-13 23:43:19.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- tempest-integrated-compute https://zuul.opendev.org/t/openstack/build/51ff0a9ef2bf4d8e87f4a3d2eee3999d : SUCCESS in 1h 01m 27s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/be9eb0aa8b554ba898be97d447a15971 : SUCCESS in 43m 40s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f9050e41743842aea27929cbf483a2f2 : SUCCESS in 14m 28s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/db76775b1dab44798f9c64c6de3899f1 : SUCCESS in 8m 32s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/a4bbeed3263a46ffbc87bd5d1905278b : SUCCESS in 12m 03s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/76e2b036daea4a31b075b603d9f98459 : SUCCESS in 12m 15s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/1a11233fd6c3413aa09748992bd3791e : SUCCESS in 10m 34s\n- ironic-tempest-ipa-wholedisk-bios-agent_ipmitool-tinyipa https://zuul.opendev.org/t/openstack/build/abd320ee481e43248060e10909dfbfe6 : SUCCESS in 48m 47s (non-voting)\n- devstack-plugin-ceph-tempest-py3 https://zuul.opendev.org/t/openstack/build/c4032e93bf20442da5e904c7433e7340 : SUCCESS in 1h 10m 14s (non-voting)\n- nova-live-migration https://zuul.opendev.org/t/openstack/build/7b3bf857a98b4b5bb9bb0f37b30fcc0f : SUCCESS in 46m 26s\n- nova-lvm https://zuul.opendev.org/t/openstack/build/de5c590dc1424e6b9a56ec334f12b3d9 : SUCCESS in 44m 18s (non-voting)\n- nova-multi-cell https://zuul.opendev.org/t/openstack/build/18c83a5cd9be45eda168817f8398795a : SUCCESS in 1h 09m 00s\n- nova-next https://zuul.opendev.org/t/openstack/build/725a36802f124c0ab3ff4a98d2b9b1b1 : SUCCESS in 1h 06m 50s\n- nova-tox-functional-py36 https://zuul.opendev.org/t/openstack/build/db9bc53c39704d999bf2ad3cde81fa86 : SUCCESS in 14m 21s\n- nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/11907f715a654f63a7a523beca0ae196 : FAILURE in 5m 57s (non-voting)\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/b5d036bc26704589b5bcc9ea164afc25 : SUCCESS in 14m 04s (non-voting)\n- nova-grenade-multinode https://zuul.opendev.org/t/openstack/build/4c87d1280c5742c9894e34dee4a5786f : SUCCESS in 54m 50s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/b5b444e49fd5454e82886e02a4051c27 : SUCCESS in 45m 35s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/edca05ba548d4411895075e5fc4baf0e : SUCCESS in 27m 55s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"39ec568201db8ac9694888cffcb5d9322eff3036","author":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"date":"2022-02-14 00:22:00.000000000","message":"Patch Set 1:\n\nBuild succeeded. Test completed on IBM PowerKVM platform. For rechecking only on the IBM PowerKVM CI, add a review comment with pkvm- recheck. For contact and more information, see https://wiki.openstack.org/wiki/PowerKVM\n\n- tempest-dsvm-full-bionic https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/1/check/tempest-dsvm-full-bionic/c1f8861/ : SUCCESS in 1h 49m 21s\n- tempest-dsvm-full-bionic-py3 https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/1/check/tempest-dsvm-full-bionic-py3/5906675/ : SUCCESS in 1h 46m 21s","accounts_in_message":[],"_revision_number":1},{"id":"3286bb2c14ad9b43e1734e0ece8a83a7ecab608c","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-02-14 12:45:25.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"364edf85e63edcb540d21feafb2551ffe6582ad9","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-02-14 14:58:44.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- tempest-integrated-compute https://zuul.opendev.org/t/openstack/build/8d76a36a26c64701a0b17208d9ad5d2e : SUCCESS in 1h 01m 24s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/876efbb3c6e64c5f8ceabddf5f989999 : SUCCESS in 47m 45s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/fad0ffa24e784947be19ef7ee7a636fe : SUCCESS in 14m 55s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5b287d87fa444487a95ac22be5abb8d0 : SUCCESS in 11m 26s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/5713813fed8140d7af0ede4f12b26e74 : SUCCESS in 10m 58s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/67a3b4d17d13424ba272af2d53db8a1d : SUCCESS in 13m 48s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/3d25e924798d4552b1da3be440ceb55a : SUCCESS in 11m 16s\n- ironic-tempest-ipa-wholedisk-bios-agent_ipmitool-tinyipa https://zuul.opendev.org/t/openstack/build/b6ef24c25bbb46bdb61013cb7b0079b9 : SUCCESS in 55m 04s (non-voting)\n- devstack-plugin-ceph-tempest-py3 https://zuul.opendev.org/t/openstack/build/9b7d437342d94db2b327dc964d4deb77 : SUCCESS in 1h 07m 06s (non-voting)\n- nova-live-migration https://zuul.opendev.org/t/openstack/build/fe8c07982b3247a3baa44c9c167720a8 : SUCCESS in 44m 58s\n- nova-lvm https://zuul.opendev.org/t/openstack/build/39ed5baa42ba4085a9b46dfe1da272ce : SUCCESS in 38m 35s (non-voting)\n- nova-multi-cell https://zuul.opendev.org/t/openstack/build/cd3d5a5dd957467caa6fd6411f983b13 : SUCCESS in 1h 09m 50s\n- nova-next https://zuul.opendev.org/t/openstack/build/d260ae2534814e8eb25d0d51388c71ed : SUCCESS in 2h 06m 37s\n- nova-tox-functional-py36 https://zuul.opendev.org/t/openstack/build/83bca858919b4664b9464e109d269b37 : SUCCESS in 15m 44s\n- nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/f3be663e40da448ab0f16258daed8e58 : SUCCESS in 5m 26s (non-voting)\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/9d22fae1ed054875b277a1ee257d06d7 : SUCCESS in 16m 20s (non-voting)\n- nova-grenade-multinode https://zuul.opendev.org/t/openstack/build/31adf21434cc46d7bf499d03cd4d5f9c : SUCCESS in 1h 05m 34s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/583b19dbf4364bb4bf6f8fbea426292d : SUCCESS in 1h 02m 29s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/cf7b9e67ee1e428f9c50976624f42f63 : SUCCESS in 22m 31s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"c6420e5abbb540acc383d621fd7d903a505a16d4","author":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"date":"2022-02-14 15:26:53.000000000","message":"Patch Set 2:\n\nBuild failed. Test completed on IBM PowerKVM platform. For rechecking only on the IBM PowerKVM CI, add a review comment with pkvm- recheck. For contact and more information, see https://wiki.openstack.org/wiki/PowerKVM\n\n- tempest-dsvm-full-bionic https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/2/check/tempest-dsvm-full-bionic/a1ff1a4/ : SUCCESS in 2h 21m 51s\n- tempest-dsvm-full-bionic-py3 tempest-dsvm-full-bionic-py3 : NODE_FAILURE in 0s","accounts_in_message":[],"_revision_number":2},{"id":"fbf98c0b7dfede8fe36a60a3e69f62441bf46d42","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-03-04 23:02:45.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"28c91f1fb46772b8a0b5a614083aab4e06346dcc","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-03-05 00:37:18.000000000","message":"Patch Set 3: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- tempest-integrated-compute https://zuul.opendev.org/t/openstack/build/bec5473c655a42ab878f084c7abe51bf : SUCCESS in 1h 28m 51s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/30ea9654ca824b3bae2d289ac58edf25 : SUCCESS in 54m 26s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/bdc0b54f90ea4b8facd671263c198982 : SUCCESS in 19m 54s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/4e7f8f3f563b4a4eba0bd548a331e84d : SUCCESS in 8m 55s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/9f872c3f1f3b4a0b9fc35022b4a862fb : SUCCESS in 13m 54s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/cd81cb2d7f49471db9bbdbd7cc3fd384 : SUCCESS in 14m 49s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/8ee8024883534d828fac09a70beb120a : SUCCESS in 11m 08s\n- ironic-tempest-ipa-wholedisk-bios-agent_ipmitool-tinyipa https://zuul.opendev.org/t/openstack/build/41521ad7e2a74073b358fc44f76d7d84 : FAILURE in 1h 05m 40s (non-voting)\n- devstack-plugin-ceph-tempest-py3 https://zuul.opendev.org/t/openstack/build/646358f96a0546f2996418346425be77 : SUCCESS in 1h 19m 28s (non-voting)\n- nova-live-migration https://zuul.opendev.org/t/openstack/build/19083d280b1145d2a2d0a3ad26b90014 : FAILURE in 59m 34s\n- nova-lvm https://zuul.opendev.org/t/openstack/build/0494fdd626604415902594bb61f7cad4 : SUCCESS in 55m 28s (non-voting)\n- nova-multi-cell https://zuul.opendev.org/t/openstack/build/6719cfdbe8b4497caf31bc4dea839c39 : SUCCESS in 1h 28m 31s\n- nova-next https://zuul.opendev.org/t/openstack/build/114dad2caf7b42b9b98fe854f32e49ff : FAILURE in 1h 23m 32s\n- nova-tox-functional-py36 https://zuul.opendev.org/t/openstack/build/8f631ad4d3954d45bff4b95dd955bac5 : SUCCESS in 18m 11s\n- nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/edf977602312436aa47a8ebc2055fce8 : SUCCESS in 6m 06s (non-voting)\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/c7eab36d9cf14990bf4a6886e5242c0c : SUCCESS in 17m 41s (non-voting)\n- nova-grenade-multinode https://zuul.opendev.org/t/openstack/build/4ce242fdbf684f478ead03cc26734795 : FAILURE in 52m 31s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/162803defa6145c1a6876427ad30c814 : SUCCESS in 55m 18s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/5a4c10b3645f402da18a0ecc822fe7bd : SUCCESS in 32m 54s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"4384030dfb6f69db49f8712351c1496e09474d7e","author":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"date":"2022-03-05 00:59:11.000000000","message":"Patch Set 3:\n\nBuild succeeded. Test completed on IBM PowerKVM platform. For rechecking only on the IBM PowerKVM CI, add a review comment with pkvm- recheck. For contact and more information, see https://wiki.openstack.org/wiki/PowerKVM\n\n- tempest-dsvm-full-bionic https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic/7d65b79/ : SUCCESS in 1h 51m 23s\n- tempest-dsvm-full-bionic-py3 https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic-py3/04a4bca/ : SUCCESS in 1h 50m 39s","accounts_in_message":[],"_revision_number":3},{"id":"69e629a7671fb02d4d6d096da43a318831113ade","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-03-05 19:01:01.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"a4e286733e8ab4802e2bfcf5d78f1f41b9c70629","author":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"date":"2022-03-05 20:50:01.000000000","message":"Patch Set 3:\n\nBuild succeeded. Test completed on IBM PowerKVM platform. For rechecking only on the IBM PowerKVM CI, add a review comment with pkvm- recheck. For contact and more information, see https://wiki.openstack.org/wiki/PowerKVM\n\n- tempest-dsvm-full-bionic https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic/ab30e3e/ : SUCCESS in 1h 39m 43s\n- tempest-dsvm-full-bionic-py3 https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic-py3/5305d5d/ : SUCCESS in 1h 35m 44s","accounts_in_message":[],"_revision_number":3},{"id":"c416c4c654420a3bb5d8309f992161c3d9ba8410","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-03-05 20:52:52.000000000","message":"Patch Set 3:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- tempest-integrated-compute https://zuul.opendev.org/t/openstack/build/d691f8362edd44498a8075d3c62af03c : SUCCESS in 1h 29m 36s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/87942e4c7b8e452ea143b36747640560 : SUCCESS in 1h 05m 48s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/540bfa51119a4b8b9231c5f500ec7981 : SUCCESS in 17m 15s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/d9fd6782a9c54d60a8182eed5d829fe4 : SUCCESS in 9m 01s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/693e5e0500a541d0815487591b6df84c : SUCCESS in 13m 38s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/606671b6596d48a59bf07d2b5c210ffa : SUCCESS in 14m 08s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/81febe80176747f7bd1993f92723395c : SUCCESS in 11m 30s\n- ironic-tempest-ipa-wholedisk-bios-agent_ipmitool-tinyipa https://zuul.opendev.org/t/openstack/build/919ec786a01744e4ba1f3e6593fa8e2e : FAILURE in 1h 02m 28s (non-voting)\n- devstack-plugin-ceph-tempest-py3 https://zuul.opendev.org/t/openstack/build/fe7e53fd812147e2b085547d5f75c615 : SUCCESS in 1h 13m 16s (non-voting)\n- nova-live-migration https://zuul.opendev.org/t/openstack/build/0cb08711e7664a029d166617c2a50b6e : FAILURE in 53m 36s\n- nova-lvm https://zuul.opendev.org/t/openstack/build/2df4120397cc43aaa87e41e77a833848 : FAILURE in 1h 01m 30s (non-voting)\n- nova-multi-cell https://zuul.opendev.org/t/openstack/build/8ebbbba4e79c4ed9becc21745566d7a1 : SUCCESS in 1h 13m 48s\n- nova-next https://zuul.opendev.org/t/openstack/build/364ad8c6a40c467f9a02cf69f1fc8fa2 : SUCCESS in 1h 43m 19s\n- nova-tox-functional-py36 https://zuul.opendev.org/t/openstack/build/b4d0c03250ea465aa5a8ee59863b1b90 : SUCCESS in 18m 43s\n- nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/f9ea899a2653492f874615d0d3bfd777 : SUCCESS in 6m 41s (non-voting)\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/bc1a76cb7b264e898c110a858b25e8d6 : SUCCESS in 15m 25s (non-voting)\n- nova-grenade-multinode https://zuul.opendev.org/t/openstack/build/04c562d66e0f46cfbc1777c32eb0c114 : SUCCESS in 1h 22m 09s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/56e216a0db1a4fcc8fd17745fac5739b : SUCCESS in 56m 30s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/474d574f6fb24387a45703c289bf22bd : SUCCESS in 37m 01s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"62b358317f859b08d025b0995bec52c1fb087b5c","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-03-05 20:55:19.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"8081e807cafd0790f61f9c1275695eef9ec090dc","author":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"date":"2022-03-05 22:40:20.000000000","message":"Patch Set 3:\n\nBuild succeeded. Test completed on IBM PowerKVM platform. For rechecking only on the IBM PowerKVM CI, add a review comment with pkvm- recheck. For contact and more information, see https://wiki.openstack.org/wiki/PowerKVM\n\n- tempest-dsvm-full-bionic https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic/8dc597b/ : SUCCESS in 1h 41m 21s\n- tempest-dsvm-full-bionic-py3 https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic-py3/7a95d5e/ : SUCCESS in 1h 36m 45s","accounts_in_message":[],"_revision_number":3},{"id":"10b7130fb90ebf7186410a741354481ea1a4cfce","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-03-05 22:55:34.000000000","message":"Patch Set 3:\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\n\n\n- tempest-integrated-compute https://zuul.opendev.org/t/openstack/build/cabefbcc442a419baa5dbfe767af321b : SUCCESS in 1h 13m 02s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/5645b0f77c0f4f28a4a02f7dbe351aa0 : SUCCESS in 37m 41s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/abe502353e874056846f508efee36936 : SUCCESS in 15m 14s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/cc9200ba5f074e519e3cc8cfc4875e83 : SUCCESS in 9m 08s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/9bcd5e416fda45b6ae09a5c030efdbde : SUCCESS in 14m 00s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/9f3d201dbd054f0a813b356118f34aef : SUCCESS in 15m 20s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/e84acde4f3ea401aab69d23a21764770 : SUCCESS in 13m 00s\n- ironic-tempest-ipa-wholedisk-bios-agent_ipmitool-tinyipa https://zuul.opendev.org/t/openstack/build/09a079f5b4324888a39297d54bdbbb35 : FAILURE in 56m 23s (non-voting)\n- devstack-plugin-ceph-tempest-py3 https://zuul.opendev.org/t/openstack/build/9c3301a92e2d4d95866bacc84febfb8b : SUCCESS in 1h 09m 52s (non-voting)\n- nova-live-migration https://zuul.opendev.org/t/openstack/build/131e52c8aef44e2084f0bfb8ce582022 : FAILURE in 33m 00s\n- nova-lvm https://zuul.opendev.org/t/openstack/build/9313628527604b369b994dcfa820e6e4 : SUCCESS in 53m 08s (non-voting)\n- nova-multi-cell https://zuul.opendev.org/t/openstack/build/ea3a271aaa784ec6bac35c30f8f7c195 : SUCCESS in 1h 16m 32s\n- nova-next https://zuul.opendev.org/t/openstack/build/ca4be421c8c54fa89713b6fdb27fbb17 : SUCCESS in 1h 51m 06s\n- nova-tox-functional-py36 https://zuul.opendev.org/t/openstack/build/216506a93a6b4430a560400b1ffa244e : SUCCESS in 18m 37s\n- nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/234cca8c0a8b4091b6657ec24c67e42e : SUCCESS in 7m 25s (non-voting)\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/97dd2984da0a4d3db5ed092089ffe271 : SUCCESS in 15m 47s (non-voting)\n- nova-grenade-multinode https://zuul.opendev.org/t/openstack/build/6380d90b82c54dde959aa9f36b4c6117 : FAILURE in 1h 28m 11s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/3b81966ed4a64a988d9b3bbbe02b18ba : SUCCESS in 51m 49s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/39664d1fff0444849ac4353085caa5b7 : SUCCESS in 28m 25s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"f7aab01f146f7e45fd007318b494b149d4c7c452","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-03-05 22:56:28.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"31979acc4db869012f459e23c8835c222b62ec07","author":{"_account_id":10118,"name":"IBM PowerKVM CI","email":"kvmpower@linux.vnet.ibm.com","username":"powerkvm","tags":["SERVICE_USER"]},"date":"2022-03-06 00:46:17.000000000","message":"Patch Set 3:\n\nBuild succeeded. Test completed on IBM PowerKVM platform. For rechecking only on the IBM PowerKVM CI, add a review comment with pkvm- recheck. For contact and more information, see https://wiki.openstack.org/wiki/PowerKVM\n\n- tempest-dsvm-full-bionic https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic/885880c/ : SUCCESS in 1h 46m 09s\n- tempest-dsvm-full-bionic-py3 https://oplab9.parqtec.unicamp.br/pub/ppc64el/openstack/nova/80/828980/3/check/tempest-dsvm-full-bionic-py3/fd212fc/ : SUCCESS in 1h 40m 55s","accounts_in_message":[],"_revision_number":3},{"id":"c92599c00bb63da35b70440f432a5942a82ab71a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2022-03-06 00:59:47.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- tempest-integrated-compute https://zuul.opendev.org/t/openstack/build/b0d3382b20c840e6a40ae68d2be667b3 : SUCCESS in 1h 13m 58s\n- openstacksdk-functional-devstack https://zuul.opendev.org/t/openstack/build/16126af8fef4412e8725d7ccc7ad4a61 : SUCCESS in 51m 53s\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/d8eaefd9312e41c49cb516b3740cba26 : SUCCESS in 22m 38s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/e72bb6b31a24462bb7e9e5608a033f28 : SUCCESS in 10m 16s\n- openstack-tox-py36 https://zuul.opendev.org/t/openstack/build/3536d247d79d4f75be0f6412b683ae44 : SUCCESS in 15m 36s\n- openstack-tox-py37 https://zuul.opendev.org/t/openstack/build/defd46b3385f40e59c2999f17ae14f97 : SUCCESS in 16m 38s\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/7842b5729d124b859a08bda1b2f02920 : SUCCESS in 12m 54s\n- ironic-tempest-ipa-wholedisk-bios-agent_ipmitool-tinyipa https://zuul.opendev.org/t/openstack/build/dfe2cc3f919a42a299ba60307a8a2107 : FAILURE in 1h 10m 12s (non-voting)\n- devstack-plugin-ceph-tempest-py3 https://zuul.opendev.org/t/openstack/build/e12559de26784af999e589335fcbda6a : SUCCESS in 1h 24m 26s (non-voting)\n- nova-live-migration https://zuul.opendev.org/t/openstack/build/75754a61aac149238a4770eff494f877 : SUCCESS in 50m 37s\n- nova-lvm https://zuul.opendev.org/t/openstack/build/8dbbbaeb318944e58d95fd4dccbe0584 : SUCCESS in 1h 03m 39s (non-voting)\n- nova-multi-cell https://zuul.opendev.org/t/openstack/build/0fbc96cf9aef49f4917ccd57cf3a3eb2 : SUCCESS in 1h 37m 20s\n- nova-next https://zuul.opendev.org/t/openstack/build/5a4db6220ff24dba8e963b70264f6679 : SUCCESS in 1h 56m 31s\n- nova-tox-functional-py36 https://zuul.opendev.org/t/openstack/build/557e8ff5925c440faa9b31331b966680 : SUCCESS in 21m 13s\n- nova-tox-validate-backport https://zuul.opendev.org/t/openstack/build/ccab484638a246838fe7930b79aee398 : SUCCESS in 6m 31s (non-voting)\n- openstack-tox-lower-constraints https://zuul.opendev.org/t/openstack/build/99f3e06f895f415fa03e49e575a33439 : SUCCESS in 15m 32s (non-voting)\n- nova-grenade-multinode https://zuul.opendev.org/t/openstack/build/a996ec4a5e1d47f688bcd2673d3dbdcc : SUCCESS in 1h 46m 52s\n- tempest-ipv6-only https://zuul.opendev.org/t/openstack/build/5460c0870b7e477ebee25983a7d07f07 : SUCCESS in 41m 21s\n- cyborg-tempest https://zuul.opendev.org/t/openstack/build/68d52509b26c4a76818c69d8ea2e1dca : SUCCESS in 33m 07s (non-voting)","accounts_in_message":[],"_revision_number":3},{"id":"84fdd0b08a597b6f7e4d38dbbdba70195430c027","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2022-04-12 10:04:04.000000000","message":"Patch Set 3: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"ef7b49d2eca68bcc726f00f454bc0e21559335da","tag":"autogenerated:gerrit:abandon","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-04-19 18:11:18.000000000","message":"Abandoned\n\nwill do cherry-pick from victoria if/once it\u0027s merged","accounts_in_message":[],"_revision_number":3},{"id":"d08e60686a03f4a2c588eb9f851280ad52f1ee62","author":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"date":"2022-04-19 20:10:39.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"b2dde80981b50d66c1aa459a8fadb1f547c35377","revisions":{"72f533a66dff14bd4bc290d6de5863ed44d8bd72":{"kind":"REWORK","_number":1,"created":"2022-02-13 22:28:23.000000000","uploader":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"ref":"refs/changes/80/828980/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova","ref":"refs/changes/80/828980/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova refs/changes/80/828980/1"}}},"commit":{"parents":[{"commit":"184a3c976faed38907af148a533bc6e9faa410f5","subject":"Ensure MAC addresses characters are in the same case","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/184a3c976faed38907af148a533bc6e9faa410f5"}]}],"author":{"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","date":"2022-01-20 14:37:19.000000000","tz":-180},"committer":{"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","date":"2022-02-13 22:28:01.000000000","tz":-180},"subject":"libvirt: disable secure boot on non-q35 or with os secure_boot options","message":"libvirt: disable secure boot on non-q35 or with os secure_boot options\n\nImpact:\n\u003d\u003d\u003d\n\nCurrently, setting hw_firwmare_type\u003duefi on Ubuntu 20.04\nmight create _unbootable_ servers on Ussuri and Victoria.\n\nWallaby and later are fixed with refactoring, as part of\nthe Secure Boot implementation, but that\u0027s risky; see\ncommit 9fff6893ce2e (\"libvirt: Use firmware metadata files\nto configure instance\") and others.\n\nIssue:\n\u003d\u003d\u003d\n\nThe issue is that if UEFI is enabled, SB can be enabled\nif loader OVMF_CODE.secboot.fd exists (eg, Ubuntu 20.04);\nsee commit 363710b65543 (\"libvirt: Handle alternative\nUEFI firmware binary paths\").\n\nThis is unintended and might prevent guest from booting\nbecause SB requires an q35 machine type, SMM feature in\nlibvirt XML, SB-ready image etc. (Neither is enabled by\ndefault nor guaranteed to be available or functional.)\n\nApproach:\n\u003d\u003d\u003d\n\nWell, SB support _isn\u0027t_ implemented in Ussuri/Victoria,\nonly later in Wallaby. The first commit above fixes the\nissue because it removes hardcoded firmware/loader path\nfrom second commit above.\n\nAs SB isn\u0027t supported, could we just ignore .secboot.fd?\n\nBut let\u0027s not change default behavior ~2 years into LTS.\n\nFix:\n\u003d\u003d\u003d\n\nSo, ignore .secboot.fd loader IF not q35. And since q35\nmay be set for AMD SEV, check `os.secure_boot` property/\nextra spec for `disabled` to ignore .secboot.fd as well\n(as listed in future `doc/source/admin/secure-boot.rst`),\nand users can explicitly disable it to boot UEFI on q35.\n\n(And as SB is not supported, do not check for both must\nmatch [`disabled`/`required`] as `required` isn\u0027t valid;\nthus if either image/flavor sets `disabled`, disable it).\n\nInfo:\n\u003d\u003d\u003d\n\n    [0] https://docs.openstack.org/nova/wallaby/admin/uefi.html\n    [1] https://docs.openstack.org/nova/wallaby/admin/secure-boot.html\n    [2] https://docs.openstack.org/nova/wallaby/user/flavors.html\n    [3] https://specs.openstack.org/openstack/nova-specs/specs/wallaby/implemented/allow-secure-boot-for-qemu-kvm-guests.html\n\nTests:\n\u003d\u003d\u003d\n\n    Original:\n\n    - Boots: BIOS / pc\n    - Boots: BIOS / q35\n\n    - Fails: UEFI / pc  / OVMF_CODE.secboot.fd\n    - Fails: UEFI / q35 / OVMF_CODE.secboot.fd\n\n    Patched:\n\n    - Boots: BIOS / pc\n    - Boots: BIOS / q35\n\n    - Boots: UEFI / pc  / OVMF_CODE.fd          # FIXED!\n    - Fails: UEFI / q35 / OVMF_CODE.secboot.fd  # No change by default.\n\n    - Boots: UEFI / q35 / OVMF_CODE.fd / os_secure_boot\u003ddisabled (image)\n    - Boots: UEFI / q35 / OVMF_CODE.fd / os:secure_boot\u003ddisabled (flavor)\n\nLogs: (included for PC with UEFI only; broken/fixed case)\n\u003d\u003d\u003d\n\n    $ openstack image set --property hw_firmware_type\u003duefi bionic\n    $ openstack server create --image bionic --flavor m1.small --network private srv\n\nBefore:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n          \u003cnova:name\u003esrv\u003c/nova:name\u003e\n        \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n        \u003cloader readonly\u003d\u0027yes\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.secboot.fd\u003c/loader\u003e\n\n    Guest doesn\u0027t boot; nothing in the console log:\n\n    $ openstack console log show srv | grep -i -e efi -e bios\n    $ openstack console log show srv | wc -l\n    0\n\n    QEMU looping / 100% CPU:\n\n    $ juju run --app nova-compute \u0027top -b -d1 -n5 | grep qemu\u0027\n      67205 libvirt+  ... 100.0   1.4   1:18.35\tqemu-sy+\n      67205 libvirt+  ... 100.0   1.4   1:19.36\tqemu-sy+\n      67205 libvirt+  ...  99.0   1.4   1:20.36\tqemu-sy+\n      67205 libvirt+  ... 101.0   1.4   1:21.37\tqemu-sy+\n      67205 libvirt+  ... 100.0   1.4   1:22.38\tqemu-sy+\n\nAfter:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n          \u003cnova:name\u003esrv\u003c/nova:name\u003e\n        \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n        \u003cloader readonly\u003d\u0027yes\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.fd\u003c/loader\u003e\n\n    Guest booted; details in the console log:\n\n    $ openstack console log show srv | grep -i -e efi -e bios\n    ...\n    Creating boot entry \"Boot0003\" with label \"ubuntu\" for file \"\\EFI\\ubuntu\\shimx64.efi\"\n    ...\n    [    0.000000] efi: EFI v2.70 by EDK II\n    [    0.000000] efi:  SMBIOS\u003d0x7fbcd000  ACPI\u003d0x7fbfa000  ACPI\n    2.0\u003d0x7fbfa014  MEMATTR\u003d0x7eb30018\n    [    0.000000] SMBIOS 2.8 present.\n    [    0.000000] DMI: OpenStack Foundation OpenStack Nova, BIOS 0.0.0 02/06/2015\n    ...\n\nNote that the XML snippet for the loader is aligned with Wallaby,\nin which just setting hw_firmware_type\u003duefi works out of the box:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n        \u003cnova:name\u003esrv\u003c/nova:name\u003e\n      \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n      \u003cloader readonly\u003d\u0027yes\u0027 secure\u003d\u0027no\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.fd\u003c/loader\u003e\n\nCloses-Bug: #1960758\nSigned-off-by: Mauricio Faria de Oliveira \u003cmfo@canonical.com\u003e\nChange-Id: I75408b4e8fbd0fd3e44ce2a3b417107b4cff3d38\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/72f533a66dff14bd4bc290d6de5863ed44d8bd72"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/72f533a66dff14bd4bc290d6de5863ed44d8bd72"}]},"branch":"refs/heads/stable/ussuri"},"e4e0b0298cad74e45296af9e86dc59243060a2a0":{"kind":"REWORK","_number":2,"created":"2022-02-14 12:45:25.000000000","uploader":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"ref":"refs/changes/80/828980/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova","ref":"refs/changes/80/828980/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova refs/changes/80/828980/2"}}},"commit":{"parents":[{"commit":"184a3c976faed38907af148a533bc6e9faa410f5","subject":"Ensure MAC addresses characters are in the same case","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/184a3c976faed38907af148a533bc6e9faa410f5"}]}],"author":{"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","date":"2022-01-20 14:37:19.000000000","tz":-180},"committer":{"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","date":"2022-02-14 12:44:52.000000000","tz":-180},"subject":"[stable-only] libvirt: disable secure boot on non-q35 or with os secure_boot options","message":"[stable-only] libvirt: disable secure boot on non-q35 or with os secure_boot options\n\nImpact:\n\u003d\u003d\u003d\n\nCurrently, setting hw_firwmare_type\u003duefi on Ubuntu 20.04\nmight create _unbootable_ servers on Ussuri and Victoria.\n\nWallaby and later are fixed with refactoring, as part of\nthe Secure Boot implementation, but that\u0027s risky; see\ncommit 9fff6893ce2e (\"libvirt: Use firmware metadata files\nto configure instance\") and others.\n\nIssue:\n\u003d\u003d\u003d\n\nThe issue is that if UEFI is enabled, SB can be enabled\nif loader OVMF_CODE.secboot.fd exists (eg, Ubuntu 20.04);\nsee commit 363710b65543 (\"libvirt: Handle alternative\nUEFI firmware binary paths\").\n\nThis is unintended and might prevent guest from booting\nbecause SB requires an q35 machine type, SMM feature in\nlibvirt XML, SB-ready image etc. (Neither is enabled by\ndefault nor guaranteed to be available or functional.)\n\nApproach:\n\u003d\u003d\u003d\n\nWell, SB support _isn\u0027t_ implemented in Ussuri/Victoria,\nonly later in Wallaby. The first commit above fixes the\nissue because it removes hardcoded firmware/loader path\nfrom second commit above.\n\nAs SB isn\u0027t supported should we just ignore .secboot.fd?\nMaybe not completely? Let\u0027s ignore it if not q35 (which\nit _needs_; note the behavior change but it\u0027s otherwise\nbroken anyway), and if q35 is used (for something else)\nand still broken with .secboot.fd, provide users with a\nway out of the latter using documented (future) options.\n\n[Or should we opinionatedly just ignore .secboot.fd, as\nSecure Boot is not yet supported anyway, and options to\nget it back are provided? (e.g. os secure_boot\u003drequired).\n\nFix:\n\u003d\u003d\u003d\n\nSo, ignore .secboot.fd loader IF not q35. And since q35\nmay be set for AMD SEV, check `os.secure_boot` property/\nextra spec for `disabled` to ignore .secboot.fd as well\n(as listed in future `doc/source/admin/secure-boot.rst`),\nand users can explicitly disable it to boot UEFI on q35.\n\n(And as SB is not supported, do not check for both must\nmatch [`disabled`/`required`] as `required` isn\u0027t valid;\nthus if either image/flavor sets `disabled`, disable it).\n\nInfo:\n\u003d\u003d\u003d\n\n    [0] https://docs.openstack.org/nova/wallaby/admin/uefi.html\n    [1] https://docs.openstack.org/nova/wallaby/admin/secure-boot.html\n    [2] https://docs.openstack.org/nova/wallaby/user/flavors.html\n    [3] https://specs.openstack.org/openstack/nova-specs/specs/wallaby/implemented/allow-secure-boot-for-qemu-kvm-guests.html\n\nTests:\n\u003d\u003d\u003d\n\n    Original:\n\n    - Boots: BIOS / pc\n    - Boots: BIOS / q35\n\n    - Fails: UEFI / pc  / OVMF_CODE.secboot.fd\n    - Fails: UEFI / q35 / OVMF_CODE.secboot.fd\n\n    Patched:\n\n    - Boots: BIOS / pc\n    - Boots: BIOS / q35\n\n    - Boots: UEFI / pc  / OVMF_CODE.fd          # FIXED!\n    - Fails: UEFI / q35 / OVMF_CODE.secboot.fd  # No change by default.\n\n    - Boots: UEFI / q35 / OVMF_CODE.fd / os_secure_boot\u003ddisabled (image)\n    - Boots: UEFI / q35 / OVMF_CODE.fd / os:secure_boot\u003ddisabled (flavor)\n\nLogs: (included for PC with UEFI only; broken/fixed case)\n\u003d\u003d\u003d\n\n    $ openstack image set --property hw_firmware_type\u003duefi bionic\n    $ openstack server create --image bionic --flavor m1.small --network private srv\n\nBefore:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n          \u003cnova:name\u003esrv\u003c/nova:name\u003e\n        \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n        \u003cloader readonly\u003d\u0027yes\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.secboot.fd\u003c/loader\u003e\n\n    Guest doesn\u0027t boot; nothing in the console log:\n\n    $ openstack console log show srv | grep -i -e efi -e bios\n    $ openstack console log show srv | wc -l\n    0\n\n    QEMU looping / 100% CPU:\n\n    $ juju run --app nova-compute \u0027top -b -d1 -n5 | grep qemu\u0027\n      67205 libvirt+  ... 100.0   1.4   1:18.35\tqemu-sy+\n      67205 libvirt+  ... 100.0   1.4   1:19.36\tqemu-sy+\n      67205 libvirt+  ...  99.0   1.4   1:20.36\tqemu-sy+\n      67205 libvirt+  ... 101.0   1.4   1:21.37\tqemu-sy+\n      67205 libvirt+  ... 100.0   1.4   1:22.38\tqemu-sy+\n\nAfter:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n          \u003cnova:name\u003esrv\u003c/nova:name\u003e\n        \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n        \u003cloader readonly\u003d\u0027yes\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.fd\u003c/loader\u003e\n\n    Guest booted; details in the console log:\n\n    $ openstack console log show srv | grep -i -e efi -e bios\n    ...\n    Creating boot entry \"Boot0003\" with label \"ubuntu\" for file \"\\EFI\\ubuntu\\shimx64.efi\"\n    ...\n    [    0.000000] efi: EFI v2.70 by EDK II\n    [    0.000000] efi:  SMBIOS\u003d0x7fbcd000  ACPI\u003d0x7fbfa000  ACPI\n    2.0\u003d0x7fbfa014  MEMATTR\u003d0x7eb30018\n    [    0.000000] SMBIOS 2.8 present.\n    [    0.000000] DMI: OpenStack Foundation OpenStack Nova, BIOS 0.0.0 02/06/2015\n    ...\n\nNote that the XML snippet for the loader is aligned with Wallaby,\nin which just setting hw_firmware_type\u003duefi works out of the box:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n        \u003cnova:name\u003esrv\u003c/nova:name\u003e\n      \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n      \u003cloader readonly\u003d\u0027yes\u0027 secure\u003d\u0027no\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.fd\u003c/loader\u003e\n\nCloses-Bug: #1960758\nSigned-off-by: Mauricio Faria de Oliveira \u003cmfo@canonical.com\u003e\nChange-Id: I75408b4e8fbd0fd3e44ce2a3b417107b4cff3d38\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/e4e0b0298cad74e45296af9e86dc59243060a2a0"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/e4e0b0298cad74e45296af9e86dc59243060a2a0"}]},"branch":"refs/heads/stable/ussuri"},"b2dde80981b50d66c1aa459a8fadb1f547c35377":{"kind":"REWORK","_number":3,"created":"2022-03-04 23:02:45.000000000","uploader":{"_account_id":28621,"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","username":"mfo"},"ref":"refs/changes/80/828980/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova","ref":"refs/changes/80/828980/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova refs/changes/80/828980/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova refs/changes/80/828980/3"}}},"commit":{"parents":[{"commit":"184a3c976faed38907af148a533bc6e9faa410f5","subject":"Ensure MAC addresses characters are in the same case","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/184a3c976faed38907af148a533bc6e9faa410f5"}]}],"author":{"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","date":"2022-01-20 14:37:19.000000000","tz":-180},"committer":{"name":"Mauricio Faria de Oliveira","email":"mfo@canonical.com","date":"2022-03-04 23:02:08.000000000","tz":-180},"subject":"[stable-only] libvirt: UEFI: skip OVMF_CODE.secboot.fd on pc if possible","message":"[stable-only] libvirt: UEFI: skip OVMF_CODE.secboot.fd on pc if possible\n\nCurrently, setting hw_firwmare_type\u003duefi on Ubuntu 20.04\nmight create _unbootable_ servers on Ussuri and Victoria,\nas OVMF_CODE.secboot.fd has SB+SMM features; SMM requires\nthe q35 machine type, thus fails to boot on pc (default).\n\nFix that by checking for q35 machine type, and other file\nis available. (We can\u0027t check files for SMM to confirm.)\n\nIf it\u0027s not q35 (ie, it\u0027s pc):\n- If other firmware is available, use that.\n- Else, well, let\u0027s at least try; log that, and good luck!\n  (Maybe we should error out? but this is stable-only..)\n\n[stable-only]:\n\nWallaby and later are fixed with refactoring, as part of\nthe Secure Boot implementation, but that\u0027s big/risky; see\ncommit 9fff6893ce2e (\"libvirt: Use firmware metadata files\nto configure instance\").\n\nThat removed the hardcoded paths from commit 363710b65543\n(\"libvirt: Handle alternative UEFI firmware binary paths\").\n\nInfo:\n\n    [0] https://docs.openstack.org/nova/wallaby/admin/uefi.html\n    [1] https://docs.openstack.org/nova/wallaby/admin/secure-boot.html\n    [2] https://docs.openstack.org/nova/wallaby/user/flavors.html\n    [3] https://specs.openstack.org/openstack/nova-specs/specs/wallaby/implemented/allow-secure-boot-for-qemu-kvm-guests.html\n\nTest:\n\n    $ openstack image set --property hw_firmware_type\u003duefi bionic\n    $ openstack server create --image bionic --flavor m1.small --network private srv\n\nBefore:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n          \u003cnova:name\u003esrv\u003c/nova:name\u003e\n        \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n        \u003cloader readonly\u003d\u0027yes\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.secboot.fd\u003c/loader\u003e\n\n    Guest doesn\u0027t boot; nothing in the console log:\n\n    $ openstack console log show srv | grep -i -e efi -e bios\n    $ openstack console log show srv | wc -l\n    0\n\n    QEMU looping / 100% CPU:\n\n    $ juju run --app nova-compute \u0027top -b -d1 -n5 | grep qemu\u0027\n      67205 libvirt+  ... 100.0   1.4   1:18.35\tqemu-sy+\n      67205 libvirt+  ... 100.0   1.4   1:19.36\tqemu-sy+\n      67205 libvirt+  ...  99.0   1.4   1:20.36\tqemu-sy+\n      67205 libvirt+  ... 101.0   1.4   1:21.37\tqemu-sy+\n      67205 libvirt+  ... 100.0   1.4   1:22.38\tqemu-sy+\n\nAfter:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n          \u003cnova:name\u003esrv\u003c/nova:name\u003e\n        \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n        \u003cloader readonly\u003d\u0027yes\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.fd\u003c/loader\u003e\n\n    Guest booted; details in the console log:\n\n    $ openstack console log show srv | grep -i -e efi -e bios\n    ...\n    Creating boot entry \"Boot0003\" with label \"ubuntu\" for file \"\\EFI\\ubuntu\\shimx64.efi\"\n    ...\n    [    0.000000] efi: EFI v2.70 by EDK II\n    [    0.000000] efi:  SMBIOS\u003d0x7fbcd000  ACPI\u003d0x7fbfa000  ACPI\n    2.0\u003d0x7fbfa014  MEMATTR\u003d0x7eb30018\n    [    0.000000] SMBIOS 2.8 present.\n    [    0.000000] DMI: OpenStack Foundation OpenStack Nova, BIOS 0.0.0 02/06/2015\n    ...\n\nNote that the XML snippet for the loader is aligned with Wallaby,\nin which just setting hw_firmware_type\u003duefi works out of the box:\n\n    $ juju run --app nova-compute \u0027for guest in $(virsh list --name); do \\\n      virsh dumpxml $guest; done | grep -e nova:name -e machine\u003d -e loader\u0027\n        \u003cnova:name\u003esrv\u003c/nova:name\u003e\n      \u003ctype arch\u003d\u0027x86_64\u0027 machine\u003d\u0027pc-i440fx-4.2\u0027\u003ehvm\u003c/type\u003e\n      \u003cloader readonly\u003d\u0027yes\u0027 secure\u003d\u0027no\u0027 type\u003d\u0027pflash\u0027\u003e/usr/share/OVMF/OVMF_CODE.fd\u003c/loader\u003e\n\nCloses-Bug: #1960758\nSigned-off-by: Mauricio Faria de Oliveira \u003cmfo@canonical.com\u003e\nChange-Id: I75408b4e8fbd0fd3e44ce2a3b417107b4cff3d38\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/b2dde80981b50d66c1aa459a8fadb1f547c35377"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova/commit/b2dde80981b50d66c1aa459a8fadb1f547c35377"}]},"branch":"refs/heads/stable/ussuri"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
