)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"b1de90ba5e278fac63ebc1a5ad688b14291590e4","unresolved":true,"context_lines":[{"line_number":13,"context_line":""},{"line_number":14,"context_line":"With this change now nova-compute fails to start up if SEV-SNP is"},{"line_number":15,"context_line":"enabled in the hosts with SEV-ES guests."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Closes-Bug: #2157891"},{"line_number":18,"context_line":"Change-Id: I96df149b1f3c63a73696534d75d1cac45fe4add8"},{"line_number":19,"context_line":"Signed-off-by: Takashi Kajinami \u003ckajinamit@oss.nttdata.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"4b29dbd9_76a53eb6","line":16,"updated":"2026-06-24 14:29:17.000000000","message":"please add a release notes to this patch. It might worth calling this out in the upgrade section","commit_id":"c27e0d68ecda8ac0ab6579b30c4bc43ce2eda3aa"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"52975fec2671cf99bee22b9d2baa9df55d278a70","unresolved":false,"context_lines":[{"line_number":13,"context_line":""},{"line_number":14,"context_line":"With this change now nova-compute fails to start up if SEV-SNP is"},{"line_number":15,"context_line":"enabled in the hosts with SEV-ES guests."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"Closes-Bug: #2157891"},{"line_number":18,"context_line":"Change-Id: I96df149b1f3c63a73696534d75d1cac45fe4add8"},{"line_number":19,"context_line":"Signed-off-by: Takashi Kajinami \u003ckajinamit@oss.nttdata.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"3703cb46_7b6ca370","line":16,"in_reply_to":"4b29dbd9_76a53eb6","updated":"2026-06-25 12:43:01.000000000","message":"Done","commit_id":"c27e0d68ecda8ac0ab6579b30c4bc43ce2eda3aa"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"b1de90ba5e278fac63ebc1a5ad688b14291590e4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"532b81fb_4bbb9b2a","updated":"2026-06-24 14:29:17.000000000","message":"-1 to have a release notes","commit_id":"c27e0d68ecda8ac0ab6579b30c4bc43ce2eda3aa"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"848905e4cba4d17879564e2e0d0f62df656f57a8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"0736c9d2_ae8fe3ea","updated":"2026-06-24 15:19:46.000000000","message":"Will address the comments by gibi. Had to update this to submit the following change.","commit_id":"dffa3cf140f404a19996d0deb1d1e0ebd22b8574"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"0ffdb03c0e04e8bc8f795a746aa4c41c5bf8959f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"37aaa4dd_de713e1f","updated":"2026-07-06 09:10:15.000000000","message":"I\u0027m OK to fix the last remaining comment in a follow up as it is just about a comment in the code","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"e9e5c5c008e8277982f5b46c6b9da195f99f784a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":16,"id":"5753e3b6_5de320ce","updated":"2026-07-13 15:45:01.000000000","message":"look good to me","commit_id":"3341d69bb294454b773f1942e681a1da95ed1a8d"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"0888bd0f40bd9d54223f797acec5c4d0c5982e06","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"299108e5_0214f712","updated":"2026-07-16 09:41:41.000000000","message":"recheck bug 2160901","commit_id":"7dd0d6106bdcf9babb81d7b55fd775b543a6e9ad"}],"nova/tests/fixtures/libvirt.py":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3bb5dde1d7ab892926259074cf11cda583e49652","unresolved":false,"context_lines":[{"line_number":2734,"context_line":"                return False"},{"line_number":2735,"context_line":"            return real_exists(path)"},{"line_number":2736,"context_line":""},{"line_number":2737,"context_line":"        self.useFixture(fixtures.MonkeyPatch(\u0027os.path.exists\u0027, fake_exists))"},{"line_number":2738,"context_line":""},{"line_number":2739,"context_line":"        disable_event_thread(self)"},{"line_number":2740,"context_line":""}],"source_content_type":"text/x-python","patch_set":13,"id":"31a97182_8fb6effb","side":"PARENT","line":2737,"range":{"start_line":2737,"start_character":13,"end_line":2737,"end_character":23},"updated":"2026-07-07 16:05:51.000000000","message":"I\u0027ve decided to drop this mock now because this doesn\u0027t allow me to mocking os.path.exists in tests using LibvirtFixture.","commit_id":"64da9109a5149da798ee5bb4fd55fac7567aa4a0"}],"nova/tests/functional/libvirt/test_amd_sev.py":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"3f04a129f4b8b32a6cccd30e94bb1a0384643cd3","unresolved":true,"context_lines":[{"line_number":64,"context_line":""},{"line_number":65,"context_line":"        self.mock_cpu_flag \u003d mock.patch("},{"line_number":66,"context_line":"            \u0027nova.virt.libvirt.host.Host._is_supported_cpu_flag\u0027,"},{"line_number":67,"context_line":"            return_value\u003dFalse).start()"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"    @mock.patch.object("},{"line_number":70,"context_line":"        fakelibvirt.virConnect, \u0027_domain_capability_features\u0027,"}],"source_content_type":"text/x-python","patch_set":10,"id":"fe85cbb7_ecf4576c","line":67,"updated":"2026-07-03 13:10:51.000000000","message":"self.addCleanup(patcher.stop)\n\nmaybe we need a hacking rule as well to catch these in the future.","commit_id":"b16850634af40a06b00465e15a003ffd19a78bef"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d7f11f791e5099b19732c108d797f34c99eb1ed9","unresolved":false,"context_lines":[{"line_number":64,"context_line":""},{"line_number":65,"context_line":"        self.mock_cpu_flag \u003d mock.patch("},{"line_number":66,"context_line":"            \u0027nova.virt.libvirt.host.Host._is_supported_cpu_flag\u0027,"},{"line_number":67,"context_line":"            return_value\u003dFalse).start()"},{"line_number":68,"context_line":""},{"line_number":69,"context_line":"    @mock.patch.object("},{"line_number":70,"context_line":"        fakelibvirt.virConnect, \u0027_domain_capability_features\u0027,"}],"source_content_type":"text/x-python","patch_set":10,"id":"158e4bad_4709126b","line":67,"in_reply_to":"fe85cbb7_ecf4576c","updated":"2026-07-03 14:15:02.000000000","message":"Done","commit_id":"b16850634af40a06b00465e15a003ffd19a78bef"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"3f04a129f4b8b32a6cccd30e94bb1a0384643cd3","unresolved":true,"context_lines":[{"line_number":139,"context_line":"            networks\u003d\u0027none\u0027"},{"line_number":140,"context_line":"        )"},{"line_number":141,"context_line":""},{"line_number":142,"context_line":"        # now sev-snp is detectedlost, so compute should fail"},{"line_number":143,"context_line":"        self.mock_cpu_flag.reset_mock()"},{"line_number":144,"context_line":"        self.mock_cpu_flag.return_value \u003d True"},{"line_number":145,"context_line":"        ex \u003d self.assertRaises("}],"source_content_type":"text/x-python","patch_set":10,"id":"e922982f_a4c54642","line":142,"range":{"start_line":142,"start_character":25,"end_line":142,"end_character":37},"updated":"2026-07-03 13:10:51.000000000","message":"nit: typo?","commit_id":"b16850634af40a06b00465e15a003ffd19a78bef"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d7f11f791e5099b19732c108d797f34c99eb1ed9","unresolved":false,"context_lines":[{"line_number":139,"context_line":"            networks\u003d\u0027none\u0027"},{"line_number":140,"context_line":"        )"},{"line_number":141,"context_line":""},{"line_number":142,"context_line":"        # now sev-snp is detectedlost, so compute should fail"},{"line_number":143,"context_line":"        self.mock_cpu_flag.reset_mock()"},{"line_number":144,"context_line":"        self.mock_cpu_flag.return_value \u003d True"},{"line_number":145,"context_line":"        ex \u003d self.assertRaises("}],"source_content_type":"text/x-python","patch_set":10,"id":"990e8208_0ef42147","line":142,"range":{"start_line":142,"start_character":25,"end_line":142,"end_character":37},"in_reply_to":"e922982f_a4c54642","updated":"2026-07-03 14:15:02.000000000","message":"Done","commit_id":"b16850634af40a06b00465e15a003ffd19a78bef"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"77a21eece3859a5440c69e0a58c3c16f6f61129d","unresolved":true,"context_lines":[{"line_number":61,"context_line":""},{"line_number":62,"context_line":"        self.qemu_version \u003d versionutils.convert_version_to_int("},{"line_number":63,"context_line":"            host.MIN_QEMU_SEV_ES_VERSION)"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"        cpu_flag_patcher \u003d mock.patch("},{"line_number":66,"context_line":"            \u0027nova.virt.libvirt.host.Host._is_supported_cpu_flag\u0027,"},{"line_number":67,"context_line":"            return_value\u003dFalse)"},{"line_number":68,"context_line":"        self.mock_cpu_flag \u003d cpu_flag_patcher.start()"},{"line_number":69,"context_line":"        self.addCleanup(cpu_flag_patcher.stop)"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"    @mock.patch.object("},{"line_number":72,"context_line":"        fakelibvirt.virConnect, \u0027_domain_capability_features\u0027,"}],"source_content_type":"text/x-python","patch_set":11,"id":"f6d8ceaa_b1d1a343","line":69,"range":{"start_line":64,"start_character":1,"end_line":69,"end_character":46},"updated":"2026-07-06 13:45:21.000000000","message":"instead of doing it like this you should use self.useFixure and the fixture package\n```suggestion\n\n        self.mock_cpu_flag \u003d self.useFixture(\n            fixtures.MockPatch(\n                \u0027nova.virt.libvirt.host.Host._is_supported_cpu_flag\u0027,\n                return_value\u003dFalse)).mock)\n```","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":61,"context_line":""},{"line_number":62,"context_line":"        self.qemu_version \u003d versionutils.convert_version_to_int("},{"line_number":63,"context_line":"            host.MIN_QEMU_SEV_ES_VERSION)"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"        cpu_flag_patcher \u003d mock.patch("},{"line_number":66,"context_line":"            \u0027nova.virt.libvirt.host.Host._is_supported_cpu_flag\u0027,"},{"line_number":67,"context_line":"            return_value\u003dFalse)"},{"line_number":68,"context_line":"        self.mock_cpu_flag \u003d cpu_flag_patcher.start()"},{"line_number":69,"context_line":"        self.addCleanup(cpu_flag_patcher.stop)"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"    @mock.patch.object("},{"line_number":72,"context_line":"        fakelibvirt.virConnect, \u0027_domain_capability_features\u0027,"}],"source_content_type":"text/x-python","patch_set":11,"id":"66904aa6_a183cdac","line":69,"range":{"start_line":64,"start_character":1,"end_line":69,"end_character":46},"in_reply_to":"f6d8ceaa_b1d1a343","updated":"2026-07-07 15:47:46.000000000","message":"Done","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":61,"context_line":""},{"line_number":62,"context_line":"        self.qemu_version \u003d versionutils.convert_version_to_int("},{"line_number":63,"context_line":"            host.MIN_QEMU_SEV_ES_VERSION)"},{"line_number":64,"context_line":""},{"line_number":65,"context_line":"        cpu_flag_patcher \u003d mock.patch("},{"line_number":66,"context_line":"            \u0027nova.virt.libvirt.host.Host._is_supported_cpu_flag\u0027,"},{"line_number":67,"context_line":"            return_value\u003dFalse)"},{"line_number":68,"context_line":"        self.mock_cpu_flag \u003d cpu_flag_patcher.start()"},{"line_number":69,"context_line":"        self.addCleanup(cpu_flag_patcher.stop)"},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"    @mock.patch.object("},{"line_number":72,"context_line":"        fakelibvirt.virConnect, \u0027_domain_capability_features\u0027,"}],"source_content_type":"text/x-python","patch_set":11,"id":"07cd92d8_ed65fc5f","line":69,"range":{"start_line":64,"start_character":1,"end_line":69,"end_character":46},"in_reply_to":"f6d8ceaa_b1d1a343","updated":"2026-07-07 15:47:46.000000000","message":"Done. I\u0027ve also updated the existing patch in L56.","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"0ffdb03c0e04e8bc8f795a746aa4c41c5bf8959f","unresolved":true,"context_lines":[{"line_number":141,"context_line":"            networks\u003d\u0027none\u0027"},{"line_number":142,"context_line":"        )"},{"line_number":143,"context_line":""},{"line_number":144,"context_line":"        # now sev-snp is lost, so compute should fail"},{"line_number":145,"context_line":"        self.mock_cpu_flag.reset_mock()"},{"line_number":146,"context_line":"        self.mock_cpu_flag.return_value \u003d True"},{"line_number":147,"context_line":"        ex \u003d self.assertRaises("}],"source_content_type":"text/x-python","patch_set":11,"id":"7de016c1_c3f51a68","line":144,"updated":"2026-07-06 09:10:15.000000000","message":"hm. isn\u0027t it `sev-es is lost because sev-snp is detected`?","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"666272be23f010f16a264afb192deb0268e2794e","unresolved":true,"context_lines":[{"line_number":141,"context_line":"            networks\u003d\u0027none\u0027"},{"line_number":142,"context_line":"        )"},{"line_number":143,"context_line":""},{"line_number":144,"context_line":"        # now sev-snp is lost, so compute should fail"},{"line_number":145,"context_line":"        self.mock_cpu_flag.reset_mock()"},{"line_number":146,"context_line":"        self.mock_cpu_flag.return_value \u003d True"},{"line_number":147,"context_line":"        ex \u003d self.assertRaises("}],"source_content_type":"text/x-python","patch_set":11,"id":"b5da10be_4ff5da2c","line":144,"in_reply_to":"7de016c1_c3f51a68","updated":"2026-07-06 09:49:35.000000000","message":"Oh yes. I\u0027ll fix this by https://review.opendev.org/c/openstack/nova/+/996070 .","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":141,"context_line":"            networks\u003d\u0027none\u0027"},{"line_number":142,"context_line":"        )"},{"line_number":143,"context_line":""},{"line_number":144,"context_line":"        # now sev-snp is lost, so compute should fail"},{"line_number":145,"context_line":"        self.mock_cpu_flag.reset_mock()"},{"line_number":146,"context_line":"        self.mock_cpu_flag.return_value \u003d True"},{"line_number":147,"context_line":"        ex \u003d self.assertRaises("}],"source_content_type":"text/x-python","patch_set":11,"id":"dcec6961_10236340","line":144,"in_reply_to":"b5da10be_4ff5da2c","updated":"2026-07-07 15:47:46.000000000","message":"I\u0027ve squashed the follow-up into this.","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"}],"nova/tests/unit/virt/libvirt/test_host.py":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"77a21eece3859a5440c69e0a58c3c16f6f61129d","unresolved":true,"context_lines":[{"line_number":2078,"context_line":"        mock_libversion.return_value \u003d 7008000"},{"line_number":2079,"context_line":"        self.assertFalse(self.host.supports_remote_managed_ports)"},{"line_number":2080,"context_line":""},{"line_number":2081,"context_line":"    def test__is_supported_cpu_flag(self):"},{"line_number":2082,"context_line":"        cpuinfo \u003d \"\"\""},{"line_number":2083,"context_line":"processor       : 0"},{"line_number":2084,"context_line":"vendor_id       : AuthenticAMD"},{"line_number":2085,"context_line":"model name      : AMD EPYC 7763 64-Core Processor"},{"line_number":2086,"context_line":"cpu cores       : 64"},{"line_number":2087,"context_line":"siblings        : 128 (SMT enabled)"},{"line_number":2088,"context_line":"flags           : svm sev sev_es"},{"line_number":2089,"context_line":"\"\"\""},{"line_number":2090,"context_line":"        with mock.patch("},{"line_number":2091,"context_line":"            \u0027builtins.open\u0027, mock.mock_open(read_data\u003dcpuinfo)"},{"line_number":2092,"context_line":"        ) as mock_open:"},{"line_number":2093,"context_line":"            self.assertTrue(self.host._is_supported_cpu_flag(\u0027sev\u0027))"},{"line_number":2094,"context_line":"            self.assertEqual({\u0027svm\u0027, \u0027sev\u0027, \u0027sev_es\u0027}, self.host._cpu_flags)"},{"line_number":2095,"context_line":"            mock_open.assert_called_once_with(\u0027/proc/cpuinfo\u0027)"},{"line_number":2096,"context_line":""},{"line_number":2097,"context_line":"        with mock.patch("},{"line_number":2098,"context_line":"            \u0027builtins.open\u0027, mock.mock_open(read_data\u003dcpuinfo)"},{"line_number":2099,"context_line":"        ) as mock_open:"},{"line_number":2100,"context_line":"            self.assertTrue(self.host._is_supported_cpu_flag(\u0027sev_es\u0027))"},{"line_number":2101,"context_line":"            self.assertFalse(self.host._is_supported_cpu_flag(\u0027sev_snp\u0027))"},{"line_number":2102,"context_line":"            mock_open.assert_not_called()"},{"line_number":2103,"context_line":""},{"line_number":2104,"context_line":""},{"line_number":2105,"context_line":"vc \u003d fakelibvirt.virConnect"}],"source_content_type":"text/x-python","patch_set":11,"id":"638377f4_bc1be3bb","line":2102,"range":{"start_line":2081,"start_character":3,"end_line":2102,"end_character":41},"updated":"2026-07-06 13:45:21.000000000","message":"we use libvirt ot get the cpu flags so you shoudl not be emulating /proc/cpuinfo","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":2078,"context_line":"        mock_libversion.return_value \u003d 7008000"},{"line_number":2079,"context_line":"        self.assertFalse(self.host.supports_remote_managed_ports)"},{"line_number":2080,"context_line":""},{"line_number":2081,"context_line":"    def test__is_supported_cpu_flag(self):"},{"line_number":2082,"context_line":"        cpuinfo \u003d \"\"\""},{"line_number":2083,"context_line":"processor       : 0"},{"line_number":2084,"context_line":"vendor_id       : AuthenticAMD"},{"line_number":2085,"context_line":"model name      : AMD EPYC 7763 64-Core Processor"},{"line_number":2086,"context_line":"cpu cores       : 64"},{"line_number":2087,"context_line":"siblings        : 128 (SMT enabled)"},{"line_number":2088,"context_line":"flags           : svm sev sev_es"},{"line_number":2089,"context_line":"\"\"\""},{"line_number":2090,"context_line":"        with mock.patch("},{"line_number":2091,"context_line":"            \u0027builtins.open\u0027, mock.mock_open(read_data\u003dcpuinfo)"},{"line_number":2092,"context_line":"        ) as mock_open:"},{"line_number":2093,"context_line":"            self.assertTrue(self.host._is_supported_cpu_flag(\u0027sev\u0027))"},{"line_number":2094,"context_line":"            self.assertEqual({\u0027svm\u0027, \u0027sev\u0027, \u0027sev_es\u0027}, self.host._cpu_flags)"},{"line_number":2095,"context_line":"            mock_open.assert_called_once_with(\u0027/proc/cpuinfo\u0027)"},{"line_number":2096,"context_line":""},{"line_number":2097,"context_line":"        with mock.patch("},{"line_number":2098,"context_line":"            \u0027builtins.open\u0027, mock.mock_open(read_data\u003dcpuinfo)"},{"line_number":2099,"context_line":"        ) as mock_open:"},{"line_number":2100,"context_line":"            self.assertTrue(self.host._is_supported_cpu_flag(\u0027sev_es\u0027))"},{"line_number":2101,"context_line":"            self.assertFalse(self.host._is_supported_cpu_flag(\u0027sev_snp\u0027))"},{"line_number":2102,"context_line":"            mock_open.assert_not_called()"},{"line_number":2103,"context_line":""},{"line_number":2104,"context_line":""},{"line_number":2105,"context_line":"vc \u003d fakelibvirt.virConnect"}],"source_content_type":"text/x-python","patch_set":11,"id":"5b26108b_bd2d291b","line":2102,"range":{"start_line":2081,"start_character":3,"end_line":2102,"end_character":41},"in_reply_to":"638377f4_bc1be3bb","updated":"2026-07-07 15:47:46.000000000","message":"Done","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"}],"nova/virt/libvirt/host.py":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"b1de90ba5e278fac63ebc1a5ad688b14291590e4","unresolved":true,"context_lines":[{"line_number":2129,"context_line":"            return self._supports_amd_sev_es"},{"line_number":2130,"context_line":""},{"line_number":2131,"context_line":"        if self._is_supported_cpu_flag(\u0027sev_snp\u0027):"},{"line_number":2132,"context_line":"            LOG.info(\"AMD SEV-ES support is detected, but ignored because \""},{"line_number":2133,"context_line":"                     \"AMD SEV-SNP support is detected\")"},{"line_number":2134,"context_line":"            return False"},{"line_number":2135,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"ef9a63c3_37f4b70d","line":2132,"updated":"2026-06-24 14:29:17.000000000","message":"I would put this as a warning even. At least for a cycle or two","commit_id":"c27e0d68ecda8ac0ab6579b30c4bc43ce2eda3aa"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"086f612b634c6fda83b2f2bc767833d14ab94787","unresolved":false,"context_lines":[{"line_number":2129,"context_line":"            return self._supports_amd_sev_es"},{"line_number":2130,"context_line":""},{"line_number":2131,"context_line":"        if self._is_supported_cpu_flag(\u0027sev_snp\u0027):"},{"line_number":2132,"context_line":"            LOG.info(\"AMD SEV-ES support is detected, but ignored because \""},{"line_number":2133,"context_line":"                     \"AMD SEV-SNP support is detected\")"},{"line_number":2134,"context_line":"            return False"},{"line_number":2135,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"73ed8fd1_64fb2537","line":2132,"in_reply_to":"9d6b69b8_0ba3175f","updated":"2026-06-26 09:09:46.000000000","message":"OK","commit_id":"c27e0d68ecda8ac0ab6579b30c4bc43ce2eda3aa"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"bcbae70c90d1c8cbce700dfee36b8ff5bdcd8f92","unresolved":false,"context_lines":[{"line_number":2129,"context_line":"            return self._supports_amd_sev_es"},{"line_number":2130,"context_line":""},{"line_number":2131,"context_line":"        if self._is_supported_cpu_flag(\u0027sev_snp\u0027):"},{"line_number":2132,"context_line":"            LOG.info(\"AMD SEV-ES support is detected, but ignored because \""},{"line_number":2133,"context_line":"                     \"AMD SEV-SNP support is detected\")"},{"line_number":2134,"context_line":"            return False"},{"line_number":2135,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"7df7b92f_91c371dc","line":2132,"in_reply_to":"ef9a63c3_37f4b70d","updated":"2026-06-25 12:17:55.000000000","message":"Done","commit_id":"c27e0d68ecda8ac0ab6579b30c4bc43ce2eda3aa"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"aece2aa7cfd1f2db2dfd597acaa2ec68e066edbd","unresolved":false,"context_lines":[{"line_number":2129,"context_line":"            return self._supports_amd_sev_es"},{"line_number":2130,"context_line":""},{"line_number":2131,"context_line":"        if self._is_supported_cpu_flag(\u0027sev_snp\u0027):"},{"line_number":2132,"context_line":"            LOG.info(\"AMD SEV-ES support is detected, but ignored because \""},{"line_number":2133,"context_line":"                     \"AMD SEV-SNP support is detected\")"},{"line_number":2134,"context_line":"            return False"},{"line_number":2135,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"9d6b69b8_0ba3175f","line":2132,"in_reply_to":"ef9a63c3_37f4b70d","updated":"2026-06-25 12:42:49.000000000","message":"I decided to use info initially because it\u0027s a normal log for deployments with SEV-SNP support (once it\u0027s formally supported) but we can discuss the log level later at that point.","commit_id":"c27e0d68ecda8ac0ab6579b30c4bc43ce2eda3aa"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"77a21eece3859a5440c69e0a58c3c16f6f61129d","unresolved":true,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"5ce90e08_58043ade","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"updated":"2026-07-06 13:45:21.000000000","message":"no you shoudl not be reading this you shoudl be geting it form libvirt","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2c2485971067b9dd6c83ac1af598368828def9eb","unresolved":true,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"8ff4a9bb_046437a5","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"in_reply_to":"26313349_ee1bd3ce","updated":"2026-07-06 17:11:38.000000000","message":"they are not but its is in domain caps\n```\n    \u003claunchSecurity supported\u003d\u0027yes\u0027\u003e\n      \u003cenum name\u003d\u0027sectype\u0027\u003e\n        \u003cvalue\u003esev\u003c/value\u003e\n        \u003cvalue\u003esev-snp\u003c/value\u003e\n      \u003c/enum\u003e\n    \u003c/launchSecurity\u003e\n```\n\nmy expection is if we disable snp in the bios it would also remove it form that\nlist\n\nso if snp is listed there then we shoudl knwo that sev-es is not supproted on this host.\n\nif we add this i woudl prefer if if you extened the filesystem moduel for proc supprot and used that instead of directly opening the file like this.\n\nhttps://github.com/openstack/nova/blob/master/nova/filesystem.py\n\nand instead of storign the full set of raw cpu flags let have a dedicated bool and set that to true/fales so we can evauntlly just replace it wiht asking libvirt","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"14f596cc3b47c9b3bdafcd21f8d503e128f0f058","unresolved":true,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"b7ecc47d_d7f8cd96","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"in_reply_to":"51a4e667_e68b9548","updated":"2026-07-06 15:57:01.000000000","message":"The main problem is that we need a different level of check here.\n\nTo determine whether the host supports full stack capability to use SEV-SNP, we can use the existing items such as kernel module parameters, qemu version and libvirt version.\n\nHowever here we have to detect SEV-SNP enabled in firmware level. This might still mean incomplete setup to get SEV-SNP functional, but is enough to disable SEV-ES functionality ( I mean, SEV-ES might be disabled even when an older libvirt is still used, for example). I\u0027m unsure if it\u0027s libvirt\u0027s responsibility to detect that incomplete status.","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"9e4ea0a760cc6618960464d3e7c1e874e926af98","unresolved":true,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"6cd99708_98371614","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"in_reply_to":"5ce90e08_58043ade","updated":"2026-07-06 15:24:41.000000000","message":"I initially tried that approach but I eventually failed to find an appropriate libvirt API to get raw cpu flags. The features returned by domainCapabilities API are based on cpu_map, which does not include sev/sev-es/sev-snp. I\u0027d appreciate it if you can help me find the suitable API for this purpose ...","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"af15a95de7b842d4f794ca7febc21bb352ced385","unresolved":true,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"51a4e667_e68b9548","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"in_reply_to":"6cd99708_98371614","updated":"2026-07-06 15:46:54.000000000","message":"that sound like you need to first update libvirt before we proceed with this feature because thy shoudl be included in the capability output or domain caps\n@gibi can you dump both form the test system you were using or takashi if you have access to a system it woudl be good to review them.\n\nthis is effectivly a blocker to detectic supprot and we would need to have a config option or simialr instead until the libvirt supprot is fixed.","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"fc00309636c47dc9d6db2b9f093206eb2e861ad6","unresolved":true,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"9238d69b_463ebddf","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"in_reply_to":"8ff4a9bb_046437a5","updated":"2026-07-06 17:26:26.000000000","message":"Unfortunately libvirt determines these fields according to qemu\u0027s capabilities. It means that sev-snp might be reported even when sev-snp is not enabled in kernel or firmware.\n\nWe can technically fix that, though fixing it does not allow us to detect several cases. For example the host has old qemu without snp support but its hardware gets SNP enabled then domain capabilities show sev-snp is not enabled. However sev-es is no longer available in this set up.","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"504f832a_89305676","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"in_reply_to":"9238d69b_463ebddf","updated":"2026-07-07 15:47:46.000000000","message":"I\u0027m closing this because we agreed using sysfs path to determine SEV-SNP support status.","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d5a1c89eb0c0c1d8d2c6ab9bd061d70afb821be3","unresolved":true,"context_lines":[{"line_number":2027,"context_line":"        # safe guard"},{"line_number":2028,"context_line":"        return []"},{"line_number":2029,"context_line":""},{"line_number":2030,"context_line":"    def _is_supported_cpu_flag(self, flag) -\u003e bool:"},{"line_number":2031,"context_line":"        \"\"\"Determine if the flag is supported by CPU"},{"line_number":2032,"context_line":"        \"\"\""},{"line_number":2033,"context_line":"        if self._cpu_flags is None:"},{"line_number":2034,"context_line":"            with open(CPUINFO_FILE) as cpuinfo_file:"},{"line_number":2035,"context_line":"                for line in cpuinfo_file:"},{"line_number":2036,"context_line":"                    line \u003d line.strip()"},{"line_number":2037,"context_line":"                    if not line or \u0027:\u0027 not in line:"},{"line_number":2038,"context_line":"                        continue"},{"line_number":2039,"context_line":"                    key, value \u003d line.split(\u0027:\u0027, 1)"},{"line_number":2040,"context_line":"                    key \u003d key.strip()"},{"line_number":2041,"context_line":"                    if key in (\u0027flags\u0027, \u0027Features\u0027):"},{"line_number":2042,"context_line":"                        self._cpu_flags \u003d set(value.strip().split())"},{"line_number":2043,"context_line":"                        break"},{"line_number":2044,"context_line":"                else:"},{"line_number":2045,"context_line":"                    LOG.warning(\u0027CPU features could not be detected\u0027)"},{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""}],"source_content_type":"text/x-python","patch_set":11,"id":"26313349_ee1bd3ce","line":2048,"range":{"start_line":2030,"start_character":0,"end_line":2048,"end_character":1},"in_reply_to":"b7ecc47d_d7f8cd96","updated":"2026-07-06 16:12:39.000000000","message":"I rechecked https://github.com/libvirt/libvirt/blob/master/src/cpu_map/x86_features.xml and confirmed that sev related flags are not there. So at least capabilities API does not reflect the sev related cpu flags now (yet).","commit_id":"294114d645026fd23c09b3c46efd1f900ec6de54"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2c2485971067b9dd6c83ac1af598368828def9eb","unresolved":true,"context_lines":[{"line_number":78,"context_line":"# This is *not* the complete list of supported hypervisor drivers."},{"line_number":79,"context_line":"HV_DRIVER_QEMU \u003d \"QEMU\""},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"SEV_KERNEL_PARAM_FILE \u003d \u0027/sys/module/kvm_amd/parameters/%s\u0027"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"CPUINFO_FILE \u003d \u0027/proc/cpuinfo\u0027"},{"line_number":84,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"049e7bbb_6b1023f5","line":81,"range":{"start_line":81,"start_character":1,"end_line":81,"end_character":59},"updated":"2026-07-06 17:11:38.000000000","message":"by the way we really should tno be checkign this either.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"290bb5f0f904d846c5a386454f0902d8ca2a935a","unresolved":true,"context_lines":[{"line_number":78,"context_line":"# This is *not* the complete list of supported hypervisor drivers."},{"line_number":79,"context_line":"HV_DRIVER_QEMU \u003d \"QEMU\""},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"SEV_KERNEL_PARAM_FILE \u003d \u0027/sys/module/kvm_amd/parameters/%s\u0027"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"CPUINFO_FILE \u003d \u0027/proc/cpuinfo\u0027"},{"line_number":84,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"9e44c1d2_e2b54f6a","line":81,"range":{"start_line":81,"start_character":1,"end_line":81,"end_character":59},"in_reply_to":"049e7bbb_6b1023f5","updated":"2026-07-06 18:29:14.000000000","message":"I tend to agree but this libvirt is not checking the sev_es parameter and the sev_snp parameter yet. I proposed adding a logic to check sev_es a while ago but it was eventually ignored. I can probably push it again to ask for feedback.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"4153985f3673d7500ebd06456e07ea6b6da665ac","unresolved":true,"context_lines":[{"line_number":78,"context_line":"# This is *not* the complete list of supported hypervisor drivers."},{"line_number":79,"context_line":"HV_DRIVER_QEMU \u003d \"QEMU\""},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"SEV_KERNEL_PARAM_FILE \u003d \u0027/sys/module/kvm_amd/parameters/%s\u0027"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"CPUINFO_FILE \u003d \u0027/proc/cpuinfo\u0027"},{"line_number":84,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"b5a0c664_04afe669","line":81,"range":{"start_line":81,"start_character":1,"end_line":81,"end_character":59},"in_reply_to":"9e44c1d2_e2b54f6a","updated":"2026-07-06 18:52:21.000000000","message":"so we do not check kernel parameter or firmware setting for sriov \n\nfor example the iommu setting required for sriov to work or the intel vt-d bios configuration. so it seam out of scope for us to be doing ti here for sev.\n\ni get that we are trying to fail fast but there are a lot of other things that\nwe dont validate to have feature to work amd moduel options historically ahve been not a stable interface over the long term\n\nhttps://github.com/openstack/nova/commit/ab51a5dd25b8d4c66562148b43b1022eb5ceed7e\n\nanyway this is what it is chaning this is out os scope fo this patch but it is more or less tech debt and im not sure if this is really godo to keep long term","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":78,"context_line":"# This is *not* the complete list of supported hypervisor drivers."},{"line_number":79,"context_line":"HV_DRIVER_QEMU \u003d \"QEMU\""},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"SEV_KERNEL_PARAM_FILE \u003d \u0027/sys/module/kvm_amd/parameters/%s\u0027"},{"line_number":82,"context_line":""},{"line_number":83,"context_line":"CPUINFO_FILE \u003d \u0027/proc/cpuinfo\u0027"},{"line_number":84,"context_line":""}],"source_content_type":"text/x-python","patch_set":12,"id":"e070ba6a_856d5583","line":81,"range":{"start_line":81,"start_character":1,"end_line":81,"end_character":59},"in_reply_to":"b5a0c664_04afe669","updated":"2026-07-07 15:47:46.000000000","message":"I\u0027m closing this because we agreed using sysfs path to determine SEV-SNP support status.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2c2485971067b9dd6c83ac1af598368828def9eb","unresolved":true,"context_lines":[{"line_number":322,"context_line":"        self._libvirt_proxy_classes \u003d self._get_libvirt_proxy_classes(libvirt)"},{"line_number":323,"context_line":"        self._libvirt_proxy \u003d self._wrap_libvirt_proxy(libvirt)"},{"line_number":324,"context_line":""},{"line_number":325,"context_line":"        self._cpu_flags: set[str] | None \u003d None"},{"line_number":326,"context_line":""},{"line_number":327,"context_line":"        # A number of features are conditional on support in the hardware,"},{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"}],"source_content_type":"text/x-python","patch_set":12,"id":"3e7879c8_98835ff6","line":325,"range":{"start_line":325,"start_character":7,"end_line":325,"end_character":47},"updated":"2026-07-06 17:11:38.000000000","message":"i am not a fan of saving this in the host object\nas it will be confusing which cpu flags are used for vms this or the ones in \nin  \n```\nself._caps \u003d None\nself._domain_caps \u003d None\n```","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":322,"context_line":"        self._libvirt_proxy_classes \u003d self._get_libvirt_proxy_classes(libvirt)"},{"line_number":323,"context_line":"        self._libvirt_proxy \u003d self._wrap_libvirt_proxy(libvirt)"},{"line_number":324,"context_line":""},{"line_number":325,"context_line":"        self._cpu_flags: set[str] | None \u003d None"},{"line_number":326,"context_line":""},{"line_number":327,"context_line":"        # A number of features are conditional on support in the hardware,"},{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"}],"source_content_type":"text/x-python","patch_set":12,"id":"6742df54_c138f6a0","line":325,"range":{"start_line":325,"start_character":7,"end_line":325,"end_character":47},"in_reply_to":"3e7879c8_98835ff6","updated":"2026-07-07 15:47:46.000000000","message":"We no longer need this now, so I\u0027m closing this comment.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"290bb5f0f904d846c5a386454f0902d8ca2a935a","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"d14d5fd6_bffcaa45","line":331,"range":{"start_line":331,"start_character":8,"end_line":331,"end_character":53},"updated":"2026-07-06 18:29:14.000000000","message":"(creating a new thread to avoid mixing multiple topics)\n\nDetection of sev-snp support can be found in https://review.opendev.org/c/openstack/nova/+/994764/8/nova/virt/libvirt/host.py#2161 . This is meant to be used to determine whether libvirt is capable to use sev-snp while the detection implemented in this change is limited to the firmware setting.\n\nI can probably replace the version checks by the launchSecurity elements as suggested, though we likely have to check sev_snp parameter of kvm_amd now because libvirt does not honor it yet.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2c2485971067b9dd6c83ac1af598368828def9eb","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"1b932038_7c9af0e0","line":331,"updated":"2026-07-06 17:11:38.000000000","message":"instead if we do this lets have a new \n\n self._supports_amd_sev_snp bool and set that directly","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"75a09047_35a52489","line":331,"range":{"start_line":331,"start_character":8,"end_line":331,"end_character":53},"in_reply_to":"034f4281_4bdd419b","updated":"2026-07-07 15:47:46.000000000","message":"Thanks for these results. The result revealed that cpuinfo is useless in that case and the sysfs path is the appropriate approach. I\u0027ve updated the change to use it.\n\nNote that there might be a few corner cases which might not be detected properly, but we don\u0027t have a good detection method for these so I\u0027ll leave these now.\n\n* SEV-SNP is enabled in BIOS but kernel is too old to expose /sys/module/kvm_amd/parameters/sev_snp\n* SEV-SNP is enabled in BIOS but it\u0027s not enabled in kvm_amd kernel module, due to lack of sev_snp\u003d1 in the module setting.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"fc00309636c47dc9d6db2b9f093206eb2e861ad6","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"79d77f8e_b2c3c4dc","line":331,"in_reply_to":"1b932038_7c9af0e0","updated":"2026-07-06 17:26:26.000000000","message":"I intentionally avoided using that flag in this change. _supports_amd_sev_* tells whether that sev feature is actually available in libvirt and qemu. However what we should determine here is only whether SNP is enabled in firmware. For example it\u0027s possible that SNP is not yet enabled in kernel but is enabled in firmware, and SEV-ES is no longer functional at that stage.\n\nIf we don\u0027t care such partial configuration of SNP, and only check whether SEV-SNP is fully configured, then we can use _supports_amd_sev_snp flag (which I\u0027m implementing in the subsequent changes).","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"e9e5c5c008e8277982f5b46c6b9da195f99f784a","unresolved":false,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"9bd32335_115ca59a","line":331,"range":{"start_line":331,"start_character":8,"end_line":331,"end_character":53},"in_reply_to":"75a09047_35a52489","updated":"2026-07-13 15:45:01.000000000","message":"\u003e SEV-SNP is enabled in BIOS but it\u0027s not enabled in kvm_amd kernel module, due to lack of sev_snp\u003d1 in the module setting.\n\nStrangely I only needed to set kvm_amd.sev\u003d1 in the kernel command line to enable the whole sev, es, snp feature set.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"a4d22d8b236067551b2b37185731237fc43431d3","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"846b4bf3_d9fb39af","line":331,"in_reply_to":"79d77f8e_b2c3c4dc","updated":"2026-07-06 17:36:24.000000000","message":"that is not the api contract of domain caps\n\nthe api corntract is that if a featre is reported there then we must be able to create a intantce usign that functionality on this host.\n\nso that woudl be a libvirt bug if it reports it can create a vm with sev-snp in \n\n```\n    \u003claunchSecurity supported\u003d\u0027yes\u0027\u003e\n      \u003cenum name\u003d\u0027sectype\u0027\u003e\n        \u003cvalue\u003esev\u003c/value\u003e\n        \u003cvalue\u003esev-snp\u003c/value\u003e\n      \u003c/enum\u003e\n    \u003c/launchSecurity\u003e\n```\n\nand that is not possibel to do.\n\nso im suggesting if sev-snp is listed there we set _supports_amd_sev_es\u003dfalse\n\n```\n    \u003csev supported\u003d\u0027yes\u0027\u003e\n      \u003ccbitpos\u003e51\u003c/cbitpos\u003e\n      \u003creducedPhysBits\u003e1\u003c/reducedPhysBits\u003e\n      \u003cmaxGuests\u003e500\u003c/maxGuests\u003e\n      \u003cmaxESGuests\u003e9\u003c/maxESGuests\u003e\n    \u003c/sev\u003e\n```\nregardles of the value of maxESGuests","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"9170beddd941b277cc35cd55781bf4548adee1a7","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"dcaed7b3_fc5307a8","line":331,"in_reply_to":"7a17519e_a8a21d98","updated":"2026-07-06 18:39:45.000000000","message":"so i didn\u0027t review the spec before it was approved, for me any checks that require kernel or proc parsing would have been a blocker.\n\ni would have argued for no startup check beyond the libvirt detection before i was happy with the spec proceeding.\n\nsince the spec was approved with this startup check im trying to minimise the impact of it.\n\ni think we all agree if sev-snp is not in launchSecurity then snp shoudl not be reproted as supproted.\n\nso these triats \n\nhttps://github.com/openstack/os-traits/blob/master/os_traits/hw/cpu/x86/amd.py#L18-L20\n\nshoudl only be reported if the host can boot a vm with that capablity.\n\nso if  sev-snp is not in launchSecurity then HW_CPU_X86_AMD_SEV_SNP shoudl not be reproed\n\nthe quesion is if sev-snp is reported in launchSecurity\nwaht to do about HW_CPU_X86_AMD_SEV_ES and what to do if an instiance currently uses sev-es on this host.\n\nin that case i would have expected the HW_CPU_X86_AMD_SEV_ES trait to be removed\nand if vms were using sev-es then the agent shoudl refuse to start.\n\n\nthat is only correct if sev-snp is only reported in launchSecurity by libvirt if its possisble to boot an snp on this host which depend on the bios config.\n\nif that is not the case and its alwasy reproted if libvirt/qemu supprot it and the cpu support it that is a libvirt bug and i would prefer to have a workaround config option to force ES supprot until that bug can be fixed in libvirt.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"9dca99e3d9b05e070e882395e2bac0609b4ea321","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"034f4281_4bdd419b","line":331,"range":{"start_line":331,"start_character":8,"end_line":331,"end_character":53},"in_reply_to":"7b37b7a0_e2b75af1","updated":"2026-07-07 10:57:05.000000000","message":"+1 yes it does\n\nso to do that we wouldl remove   self._cpu_flags and _is_supported_cpu_flag\n\nand just add a simple _kernel_supports_amd_sev_snp that checks  /sys/module/kvm_amd/parameters/sev_snp\n\nand we would use taht as part of supports_amd_sev_es in this patch and in the patch that adds snp supprot we can add a new supports_amd_sev_snp property","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"e9ca4437406e1a61bb9d950ec292e9ba70b262ab","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"7a17519e_a8a21d98","line":331,"in_reply_to":"846b4bf3_d9fb39af","updated":"2026-07-06 18:24:08.000000000","message":"So what you are basically suggesting for this change specifically is that we should enable this validation logic only when host is fully configured and we know that at least libvirt is confident that it can support SEV-SNP fully, and we don\u0027t care partial configuration (for example in case sev-snp is enabled in firmware). Is that correct understanding ?\n\nIf that can unblock the whole work then I\u0027m ok with taking that direction, though I think we agreed that we prefer strict validation to help operators avoid unexpected situations during spec reviews.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"438b8730_170bffb0","line":331,"in_reply_to":"9d28be65_7eeebbd8","updated":"2026-07-07 15:47:46.000000000","message":"I\u0027m closing this because we agreed using sysfs path to determine SEV-SNP support status.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"58d4e2f443634207d5a35a5cefce1fbd31ede5b8","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"7b37b7a0_e2b75af1","line":331,"range":{"start_line":331,"start_character":8,"end_line":331,"end_character":53},"in_reply_to":"d14d5fd6_bffcaa45","updated":"2026-07-07 09:28:08.000000000","message":"Collected data from my HW https://drive.google.com/drive/folders/1U_wK6DRiPxKm98LJx3_BGH3VTEsPtFSU?usp\u003ddrive_link\n\nIt has new enough firmware that contains the CVE fix.\n\nIRC discussion is starting at https://meetings.opendev.org/irclogs/%23openstack-nova/%23openstack-nova.2026-07-07.log.html#openstack-nova.2026-07-07.log.html#t2026-07-07T08:32:19\n\nI think /sys/module/kvm_amd/parameters/sev_snp is enough as a backportable bugfix.\n\n1) Existing deployment with pre Hibiscus on SNP capable HW, new firmware, SNP disabled in BIOS, ES VMs exists the host. This is a stable state as nova will report ES available and the host supports ES as SNP is disabled in BIOS. Based on my trial /sys/module/kvm_amd/parameters/sev_snp is reported N in this case (as of kernel 6.12)\n\n1.1) Now SNP is enabled in BIOS. Nova should detect it with a backportable bugfix on stable branches and tell the user to either disable SNP in BIOS or delete / move the ES VMs away. In my trials /sys/module/kvm_amd/parameters/sev_snp is reported Y so it is enough to detect the situation (with kernel 6.12) (note that both sev_es and sev_snp are reported Y in this case). The bugfix does not need new libvirt version or cpuinfo parsing\n\n2) At Hibiscus we can add a new libvirt version / capability check top of the bugfix to see if SNP is not just enabled (as in 1.1.) but also supported by libvirt. If so we can report the resource inventory and trait.\n\nDoes it make sense for all of you?","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"ae6c475a546b2818a2debaaef72c68629d0b3b2b","unresolved":true,"context_lines":[{"line_number":328,"context_line":"        # kernel, QEMU, and/or libvirt. These are determined on demand and"},{"line_number":329,"context_line":"        # memoized by various properties below"},{"line_number":330,"context_line":"        self._supports_amd_sev: bool | None \u003d None"},{"line_number":331,"context_line":"        self._supports_amd_sev_es: bool | None \u003d None"},{"line_number":332,"context_line":"        self._max_sev_guests: int | None \u003d None"},{"line_number":333,"context_line":"        self._max_sev_es_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"}],"source_content_type":"text/x-python","patch_set":12,"id":"9d28be65_7eeebbd8","line":331,"in_reply_to":"dcaed7b3_fc5307a8","updated":"2026-07-07 03:59:09.000000000","message":"Reading the logic to detect SNP support in libvirt, we can check\n 1. /sys/module/kvm_amd/parameters/sev_snp\n 2. sev-snp field in launchSecurity element in domain capabilities\n \nto determine whether sev-snp is available in libvirt.\nWhile 1 is still required because libvirt doesn\u0027t check it yet, 2 would be replace the current libvirt/qemu version check, and I agree this would be better and more robust.\nI\u0027ll update the spec and implementation accordingly.\n\n- https://github.com/qemu/qemu/commit/7b34df44260 available since 9.1.0\n- https://github.com/libvirt/libvirt/commit/66df7992d8efd6462148d2ddf39323dc552eb92a available since libvirt 10.5.0\n\nI think the remaining question is still whether we can use that SNP detection logic in libvirt layer to determine whether ES should be ignored, or we should consider a bit wider cases (SEV-ES can be disabled by only enabling SEV-SNP in firmware, regardless of libvirt version, qemu version or kernel option. So it might be enabled in firmware layer even when libvirt doesn\u0027t report snp capability, but sev-es is already disabled at that point).\nThe current implementation uses cpu flags to catch such cases, but if we agree that we can reduce the scope then I\u0027ll update the logic to just rely on libvirt level check. I probably need some thoughts from @gibizer@gmail.com and @sbauza@redhat.com regarding this so that we find the balcned point we all can agree with.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2c2485971067b9dd6c83ac1af598368828def9eb","unresolved":true,"context_lines":[{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""},{"line_number":2052,"context_line":"        kernel_param_file \u003d SEV_KERNEL_PARAM_FILE % model.replace(\u0027-\u0027, \u0027_\u0027)"},{"line_number":2053,"context_line":""},{"line_number":2054,"context_line":"        if not os.path.exists(kernel_param_file):"},{"line_number":2055,"context_line":"            LOG.debug(\"%s does not exist\", kernel_param_file)"},{"line_number":2056,"context_line":"            return False"},{"line_number":2057,"context_line":""},{"line_number":2058,"context_line":"        with open(kernel_param_file) as f:"},{"line_number":2059,"context_line":"            content \u003d f.read()"},{"line_number":2060,"context_line":"            LOG.debug(\"%s contains [%s]\", kernel_param_file, content)"},{"line_number":2061,"context_line":"            return strutils.bool_from_string(content)"},{"line_number":2062,"context_line":""},{"line_number":2063,"context_line":"    @property"},{"line_number":2064,"context_line":"    def supports_amd_sev(self) -\u003e bool:"}],"source_content_type":"text/x-python","patch_set":12,"id":"8c5839ca_d088fafb","line":2061,"range":{"start_line":2049,"start_character":4,"end_line":2061,"end_character":53},"updated":"2026-07-06 17:11:38.000000000","message":"but at the very lease if we do check this which i dotn think we shoud be doing\nit shoudl be using read_sys\n\nhttps://github.com/openstack/nova/blob/master/nova/filesystem.py#L62","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""},{"line_number":2052,"context_line":"        kernel_param_file \u003d SEV_KERNEL_PARAM_FILE % model.replace(\u0027-\u0027, \u0027_\u0027)"},{"line_number":2053,"context_line":""},{"line_number":2054,"context_line":"        if not os.path.exists(kernel_param_file):"},{"line_number":2055,"context_line":"            LOG.debug(\"%s does not exist\", kernel_param_file)"},{"line_number":2056,"context_line":"            return False"},{"line_number":2057,"context_line":""},{"line_number":2058,"context_line":"        with open(kernel_param_file) as f:"},{"line_number":2059,"context_line":"            content \u003d f.read()"},{"line_number":2060,"context_line":"            LOG.debug(\"%s contains [%s]\", kernel_param_file, content)"},{"line_number":2061,"context_line":"            return strutils.bool_from_string(content)"},{"line_number":2062,"context_line":""},{"line_number":2063,"context_line":"    @property"},{"line_number":2064,"context_line":"    def supports_amd_sev(self) -\u003e bool:"}],"source_content_type":"text/x-python","patch_set":12,"id":"a0ba606b_de8c93db","line":2061,"range":{"start_line":2049,"start_character":4,"end_line":2061,"end_character":53},"in_reply_to":"4a276097_1fbccbd0","updated":"2026-07-07 15:47:46.000000000","message":"I\u0027m closing this because we agreed using sysfs path to determine SEV-SNP support status.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"fc00309636c47dc9d6db2b9f093206eb2e861ad6","unresolved":true,"context_lines":[{"line_number":2046,"context_line":"                    self._cpu_flags \u003d set()"},{"line_number":2047,"context_line":"        return flag in self._cpu_flags"},{"line_number":2048,"context_line":""},{"line_number":2049,"context_line":"    def _kernel_supports_amd_sev(self, model\u003d\u0027sev\u0027) -\u003e bool:"},{"line_number":2050,"context_line":"        \"\"\"Determine if the kernel supports AMD SEV for guests."},{"line_number":2051,"context_line":"        \"\"\""},{"line_number":2052,"context_line":"        kernel_param_file \u003d SEV_KERNEL_PARAM_FILE % model.replace(\u0027-\u0027, \u0027_\u0027)"},{"line_number":2053,"context_line":""},{"line_number":2054,"context_line":"        if not os.path.exists(kernel_param_file):"},{"line_number":2055,"context_line":"            LOG.debug(\"%s does not exist\", kernel_param_file)"},{"line_number":2056,"context_line":"            return False"},{"line_number":2057,"context_line":""},{"line_number":2058,"context_line":"        with open(kernel_param_file) as f:"},{"line_number":2059,"context_line":"            content \u003d f.read()"},{"line_number":2060,"context_line":"            LOG.debug(\"%s contains [%s]\", kernel_param_file, content)"},{"line_number":2061,"context_line":"            return strutils.bool_from_string(content)"},{"line_number":2062,"context_line":""},{"line_number":2063,"context_line":"    @property"},{"line_number":2064,"context_line":"    def supports_amd_sev(self) -\u003e bool:"}],"source_content_type":"text/x-python","patch_set":12,"id":"4a276097_1fbccbd0","line":2061,"range":{"start_line":2049,"start_character":4,"end_line":2061,"end_character":53},"in_reply_to":"8c5839ca_d088fafb","updated":"2026-07-06 17:26:26.000000000","message":"I can use it, though we likely need a different version(like read_proc). Also read_sys implements specific needs for sysfs, and I\u0027m unsure if we really need these handlings for procfs.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"2c2485971067b9dd6c83ac1af598368828def9eb","unresolved":true,"context_lines":[{"line_number":2128,"context_line":"            LOG.info(\"QEMU doesn\u0027t support AMD SEV-ES\")"},{"line_number":2129,"context_line":"            return self._supports_amd_sev_es"},{"line_number":2130,"context_line":""},{"line_number":2131,"context_line":"        if self._is_supported_cpu_flag(\u0027sev_snp\u0027):"},{"line_number":2132,"context_line":"            LOG.warning(\"AMD SEV-ES support is detected, but ignored because \""},{"line_number":2133,"context_line":"                        \"AMD SEV-SNP support is detected\")"},{"line_number":2134,"context_line":"            return False"}],"source_content_type":"text/x-python","patch_set":12,"id":"46f14a91_c04f222b","line":2131,"range":{"start_line":2131,"start_character":11,"end_line":2131,"end_character":49},"updated":"2026-07-06 17:11:38.000000000","message":"so we woudl replace this with \n\n\n```suggestion\n        if self.supports_amd_sev_snp():\n```","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"2db045ad43f847fbc113119f1ca2a39b96f9c5f0","unresolved":false,"context_lines":[{"line_number":2128,"context_line":"            LOG.info(\"QEMU doesn\u0027t support AMD SEV-ES\")"},{"line_number":2129,"context_line":"            return self._supports_amd_sev_es"},{"line_number":2130,"context_line":""},{"line_number":2131,"context_line":"        if self._is_supported_cpu_flag(\u0027sev_snp\u0027):"},{"line_number":2132,"context_line":"            LOG.warning(\"AMD SEV-ES support is detected, but ignored because \""},{"line_number":2133,"context_line":"                        \"AMD SEV-SNP support is detected\")"},{"line_number":2134,"context_line":"            return False"}],"source_content_type":"text/x-python","patch_set":12,"id":"3a642893_dedb4dd8","line":2131,"range":{"start_line":2131,"start_character":11,"end_line":2131,"end_character":49},"in_reply_to":"46f14a91_c04f222b","updated":"2026-07-07 15:47:46.000000000","message":"I\u0027ve updated this to read sysfs path, based on the agreement.","commit_id":"2c27ea0e55f650c8962ed928b9ed1a95b848dedd"}]}
