)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"076e4ec79a0a1c1328d8abed4f2e1388c78cd597","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"db846d88_8955dea1","updated":"2026-06-24 16:23:59.000000000","message":"Couple of small things inline. But overall direction looks good","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"0c77092633394ebebeb5b0571a51fd8791f18065","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"098334be_b38b9254","updated":"2026-07-20 14:21:45.000000000","message":"Note that we expect conflict caused by https://review.opendev.org/c/openstack/nova/+/996316 which is being merged now.\n\nI also wonder if we can add a few functional tests scenario for RP report by nova-compute. Once https://review.opendev.org/c/openstack/nova/+/997635 is merged you can follow the existing implementation for SEV to add these.","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"a41191f94a198c68b6cf97551187fbd1ca45c387","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"450e23e7_aefbf85e","in_reply_to":"098334be_b38b9254","updated":"2026-07-23 12:53:14.000000000","message":"The conflict is resolved. For the functional tests I am thinking it could be another patch. We shouldn\u0027t need as many as for SEV since it TDX doesn\u0027t have different versions.","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"f0f873a563951b3302d7ccde350805aec20a1b89","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"d6a017fb_87e32976","in_reply_to":"450e23e7_aefbf85e","updated":"2026-07-23 16:33:29.000000000","message":"In case you haven\u0027t yet wrote functional tests then use https://review.opendev.org/c/openstack/nova/+/998525 .","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"e6a159135f9ca348318b96de4d159c33688781a1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"1cb124ab_fc5a04a6","in_reply_to":"d6a017fb_87e32976","updated":"2026-07-27 12:17:33.000000000","message":"Done","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"13f88f9d2925936a3b61aa36e117f25935c0f900","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"813e83ee_e5f346ce","updated":"2026-07-22 08:53:05.000000000","message":"I have only small things. The overall direction looks good. Let continue building up the series. :)\n\nI haven\u0027t got my hands on a TDX capable hardware yet. As soon as I got it I will post test results and printouts.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"45a76601_28856963","updated":"2026-07-21 12:50:14.000000000","message":"Thanks for rebasing the change. I\u0027m adding a few more comments so please check these. Also please check my previous comment about functional tests for PR creation by nova-compute.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"90a19a10bf4ae97ab7602f8facf3a814c170e84b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"d2d8e9a6_28452abe","in_reply_to":"688a2a76_1d467861","updated":"2026-08-07 12:48:32.000000000","message":"I got HW and able to boot a VM with TDX using this patch series. https://paste.openstack.org/show/brAOgxu5mrp5Orjfy96J/","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"a41191f94a198c68b6cf97551187fbd1ca45c387","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"a822c0df_a8113f9d","in_reply_to":"813e83ee_e5f346ce","updated":"2026-07-23 12:53:14.000000000","message":"I have been testing on Ubuntu 26.04 for a newer libvirt version. Let me know if you need some guidance in the setup.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"367c45d013649a6e02525b38dae0bed03e733cb2","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":3,"id":"688a2a76_1d467861","in_reply_to":"a822c0df_a8113f9d","updated":"2026-07-23 14:36:18.000000000","message":"thanks. we discussed it on IRC, I need better HW due to DIMM setup requirements of TDX. I will get back to you if a have further questions. \n\nIt has a non zero chance that I will not get a compatible HW in time. So I will ask you to run at least some devstack based manual tests with the complete patch series and publish the results. That should be enough for me from testing perspective to eventually approve the series. We can get back to this testing later when we have the complete series.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"367c45d013649a6e02525b38dae0bed03e733cb2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"6ae8bce2_d3653ce0","updated":"2026-07-23 14:36:18.000000000","message":"My comments were fixed so this looks good to me now. I hold my +2 while looking at the rest of the series and potentially do some local testing.","commit_id":"462e89e40c76139169c8f3e553ec84207d55cbcd"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"68997c8c750bd59f10578044e7e407cc85c92310","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"4d35f0b2_131086d5","updated":"2026-08-10 10:07:54.000000000","message":"I don\u0027t want to hold the series but I have some concerns by the fragile host interface we define for TDX. I\u0027m not asking for alternative approaches but I would surely appreciate some follow-up in the series that would later strengthen that host interface, particularly when upgrading nova-compute or the kernel.\n\n+1 for now as I want to review the whole series.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"90a19a10bf4ae97ab7602f8facf3a814c170e84b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"e8886c92_54e9358f","updated":"2026-08-07 12:48:32.000000000","message":"Looks good to me. Also I saw this working locally (see manual test result inline)","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"307ec143e13b4fbb9381b2e953e51fa243b8ff20","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"f389ad57_044f3656","updated":"2026-08-21 01:36:52.000000000","message":"apart from config approach, its missing the _validate_mem_encryption_configuration part also, my -1 is for that only. If you want to add that in separate change I am ok with that too but commented here as we discussed about it this change.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"e631e58c4b4eb9e2e98279ece15d170a5795a640","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"e9472383_db46b5b6","updated":"2026-08-19 08:38:33.000000000","message":"lets add a config","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"6f71261a4645c4b5f88944e88a312eb30e8abbac","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"44e04389_5a9fc271","updated":"2026-08-18 07:52:35.000000000","message":"recheck\n\nrsync: [sender] link_stat \"/var/lib/zuul/builds/d1824ce079aa4c0d94e56c8daa1e3ce1/work/ca-bundle.pem\" failed: No such file or directory (2)\n\n\n(the functional-threading instability is known and being fixed)","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"1ad93ae45f81083f1052de5a251aa4a1814d7be5","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"edfcc325_ea245227","updated":"2026-08-18 11:46:35.000000000","message":"recheck https://bugs.launchpad.net/nova/+bug/2163552","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"820b30eafca6665c9430419ed6bd236acff8400a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"ba003e5b_56f520e5","updated":"2026-08-17 09:14:55.000000000","message":"recheck multiple job failure","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a1436bb02c3590cb450fd0c9a080737482574aeb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"bebe3a3b_97be4455","updated":"2026-08-21 19:26:40.000000000","message":"Thanks for the updates. this lgtm now","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"36c7cd73ccbc75c635d8edc6d15f33e360cfc21d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"b2599e1a_1ccd99fd","updated":"2026-08-22 09:19:22.000000000","message":"The requested conf is added. This looks good to land now.","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"edc44bc1_198f89dd","updated":"2026-08-21 18:21:30.000000000","message":"im a bit too tired to finish reviewing this today so ill re review the series on monday\n\nmy primary concerns has been adresssed adn the blocker resovled.\nim not sure the cgroup parsing is required or shoudl remain but ill leave that up to others to weigh in on but orginally i was suggesting replacign it with a config option not addign a config opiton as a fallback.","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"ebea6df1cbb6e64f1cabe869f1b14fad43ba5e3d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"1a8a8c1d_3d68e901","updated":"2026-08-22 18:04:00.000000000","message":"recheck bug https://bugs.launchpad.net/nova/+bug/2163552","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"55172b3e21e9a0136abeb8fdbe2aa7d1b58c81c3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"23a25bb3_dbbd393b","updated":"2026-08-24 09:33:35.000000000","message":"recheck https://bugs.launchpad.net/nova/+bug/2164880","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"abfe7e03dd3d20ffd617f3b74f755ecca29f13a8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"2d4323ac_7e5ec1ff","updated":"2026-08-24 12:47:47.000000000","message":"with a fresh brain i dont see any other blocker so upgrding to +2\n\ni still would prefer to not depend on cgroups but the current approch is workable as is so that not a blocker","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"}],"nova/conf/libvirt.py":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":true,"context_lines":[{"line_number":964,"context_line":"hierarchy. If the cgroup value cannot be read, this option becomes the only"},{"line_number":965,"context_line":"source of the limit and **must** be set, or Nova will assume the host does not"},{"line_number":966,"context_line":"support Intel TDX."},{"line_number":967,"context_line":""},{"line_number":968,"context_line":"If the cgroup value *can* be read and this option is also set, the lower"},{"line_number":969,"context_line":"of the two values is used."},{"line_number":970,"context_line":"\"\"\"),"},{"line_number":971,"context_line":"]"},{"line_number":972,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"60b0c9c7_f1b82d8e","line":969,"range":{"start_line":967,"start_character":1,"end_line":969,"end_character":26},"updated":"2026-08-21 18:21:30.000000000","message":"ok i proably would have kept it simple and use this a a full overriede but that logic is fine","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a1436bb02c3590cb450fd0c9a080737482574aeb","unresolved":true,"context_lines":[{"line_number":964,"context_line":"hierarchy. If the cgroup value cannot be read, this option becomes the only"},{"line_number":965,"context_line":"source of the limit and **must** be set, or Nova will assume the host does not"},{"line_number":966,"context_line":"support Intel TDX."},{"line_number":967,"context_line":""},{"line_number":968,"context_line":"If the cgroup value *can* be read and this option is also set, the lower"},{"line_number":969,"context_line":"of the two values is used."},{"line_number":970,"context_line":"\"\"\"),"},{"line_number":971,"context_line":"]"},{"line_number":972,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"adc5d5eb_649a26b7","line":969,"range":{"start_line":967,"start_character":1,"end_line":969,"end_character":26},"in_reply_to":"60b0c9c7_f1b82d8e","updated":"2026-08-21 19:26:40.000000000","message":"i feel this is much better if someone want to limit TDX VMs even host allows.","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"36c7cd73ccbc75c635d8edc6d15f33e360cfc21d","unresolved":false,"context_lines":[{"line_number":964,"context_line":"hierarchy. If the cgroup value cannot be read, this option becomes the only"},{"line_number":965,"context_line":"source of the limit and **must** be set, or Nova will assume the host does not"},{"line_number":966,"context_line":"support Intel TDX."},{"line_number":967,"context_line":""},{"line_number":968,"context_line":"If the cgroup value *can* be read and this option is also set, the lower"},{"line_number":969,"context_line":"of the two values is used."},{"line_number":970,"context_line":"\"\"\"),"},{"line_number":971,"context_line":"]"},{"line_number":972,"context_line":""}],"source_content_type":"text/x-python","patch_set":7,"id":"89235324_0f2e584f","line":969,"range":{"start_line":967,"start_character":1,"end_line":969,"end_character":26},"in_reply_to":"adc5d5eb_649a26b7","updated":"2026-08-22 09:19:22.000000000","message":"This is OK to me.","commit_id":"a69768e478d7a08355b11fba5a814b08e495ce09"}],"nova/objects/fields.py":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"e9f4ed455414ae83f80ce4125d4131686f0e744f","unresolved":true,"context_lines":[{"line_number":566,"context_line":"    AMD_SEV_ES \u003d \"amd-sev-es\""},{"line_number":567,"context_line":"    INTEL_TDX \u003d \"intel-tdx\""},{"line_number":568,"context_line":""},{"line_number":569,"context_line":"    ALL \u003d (AMD_SEV, AMD_SEV_ES, INTEL_TDX)"},{"line_number":570,"context_line":""},{"line_number":571,"context_line":""},{"line_number":572,"context_line":"class MaxPhyAddrMode(BaseNovaEnum):"}],"source_content_type":"text/x-python","patch_set":2,"id":"199531f6_a08f60b7","line":569,"updated":"2026-06-26 09:36:18.000000000","message":"Heads up. This will be a merge conflict point with https://review.opendev.org/q/topic:%22bp/amd-sev-snp-libvirt-support%22 as that also adds a new field value. Give that the SNP series is a bit further ahead and therefore more like to land first I suggest you to try to rebase on top of it (at least top of the commit that causes the merge conflict)","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"70f5ddc18628b63921353c6a606b35ba9a1fb9e3","unresolved":true,"context_lines":[{"line_number":566,"context_line":"    AMD_SEV_ES \u003d \"amd-sev-es\""},{"line_number":567,"context_line":"    INTEL_TDX \u003d \"intel-tdx\""},{"line_number":568,"context_line":""},{"line_number":569,"context_line":"    ALL \u003d (AMD_SEV, AMD_SEV_ES, INTEL_TDX)"},{"line_number":570,"context_line":""},{"line_number":571,"context_line":""},{"line_number":572,"context_line":"class MaxPhyAddrMode(BaseNovaEnum):"}],"source_content_type":"text/x-python","patch_set":2,"id":"24822300_d1ee81cf","line":569,"in_reply_to":"199531f6_a08f60b7","updated":"2026-06-26 09:46:24.000000000","message":"Yes thanks for the heads up, will do that before moving to the next parts.\n\nThis patch looks very similar and complete https://review.opendev.org/c/openstack/nova/+/994764, so will start there.","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"263f9e4abce8ff0deb9c2697c4d35cbf05a852ca","unresolved":true,"context_lines":[{"line_number":566,"context_line":"    AMD_SEV_ES \u003d \"amd-sev-es\""},{"line_number":567,"context_line":"    INTEL_TDX \u003d \"intel-tdx\""},{"line_number":568,"context_line":""},{"line_number":569,"context_line":"    ALL \u003d (AMD_SEV, AMD_SEV_ES, INTEL_TDX)"},{"line_number":570,"context_line":""},{"line_number":571,"context_line":""},{"line_number":572,"context_line":"class MaxPhyAddrMode(BaseNovaEnum):"}],"source_content_type":"text/x-python","patch_set":2,"id":"375d5207_8112e21e","line":569,"in_reply_to":"24822300_d1ee81cf","updated":"2026-07-20 13:42:54.000000000","message":"I\u0027m wondering if we are allowed to squash these two updates into a single version bump because it sounds a bit redundant to make two bumps for the same field within a single cycle ?","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"28cc245a851ab305665099dbd01ca18c43503cea","unresolved":false,"context_lines":[{"line_number":566,"context_line":"    AMD_SEV_ES \u003d \"amd-sev-es\""},{"line_number":567,"context_line":"    INTEL_TDX \u003d \"intel-tdx\""},{"line_number":568,"context_line":""},{"line_number":569,"context_line":"    ALL \u003d (AMD_SEV, AMD_SEV_ES, INTEL_TDX)"},{"line_number":570,"context_line":""},{"line_number":571,"context_line":""},{"line_number":572,"context_line":"class MaxPhyAddrMode(BaseNovaEnum):"}],"source_content_type":"text/x-python","patch_set":2,"id":"f64e7c85_44071afa","line":569,"in_reply_to":"375d5207_8112e21e","updated":"2026-07-21 12:15:48.000000000","message":"We agreed in IRC to just bump the versions because it is cheap","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"}],"nova/tests/fixtures/libvirt.py":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"c194d9f50110de9910600cb276e80b975a9d8f78","unresolved":true,"context_lines":[{"line_number":2427,"context_line":"      \u003c/enum\u003e"},{"line_number":2428,"context_line":"    \u003c/launchSecurity\u003e\u0027\u0027\u0027"},{"line_number":2429,"context_line":""},{"line_number":2430,"context_line":"    _domain_capability_features_with_TDX \u003d \u0027\u0027\u0027  \u003cfeatures\u003e"},{"line_number":2431,"context_line":"      \u003cgic supported\u003d\u0027no\u0027/\u003e"},{"line_number":2432,"context_line":"      \u003ctdx supported\u003d\u0027yes\u0027/\u003e"},{"line_number":2433,"context_line":"    \u003c/features\u003e\u0027\u0027\u0027"},{"line_number":2434,"context_line":""},{"line_number":2435,"context_line":"    _domain_capability_features_with_TDX_unsupported \u003d \\"},{"line_number":2436,"context_line":"        _domain_capability_features_with_TDX.replace(\u0027yes\u0027, \u0027no\u0027)"},{"line_number":2437,"context_line":""},{"line_number":2438,"context_line":"    def getCapabilities(self):"},{"line_number":2439,"context_line":"        \"\"\"Return spoofed capabilities.\"\"\""},{"line_number":2440,"context_line":"        numa_topology \u003d self.host_info.numa_topology"}],"source_content_type":"text/x-python","patch_set":5,"id":"82c36958_133b3224","line":2437,"range":{"start_line":2430,"start_character":3,"end_line":2437,"end_character":1},"updated":"2026-08-18 20:31:48.000000000","message":"nit: this woudl b ea litte cleaner IMO\n\n```suggestion\n    _domain_capability_features_with_TDX \u003d \u0027\u0027\u0027\\\n    \u003cfeatures\u003e\n      \u003cgic supported\u003d\u0027no\u0027/\u003e\n      \u003ctdx supported\u003d\u0027yes\u0027/\u003e\n    \u003c/features\u003e\u0027\u0027\u0027\n\n    _domain_capability_features_with_TDX_unsupported \u003d \u0027\u0027\u0027\\\n    \u003cfeatures\u003e\n      \u003cgic supported\u003d\u0027no\u0027/\u003e\n      \u003ctdx supported\u003d\u0027no\u0027/\u003e\n    \u003c/features\u003e\u0027\u0027\u0027\n```","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":false,"context_lines":[{"line_number":2427,"context_line":"      \u003c/enum\u003e"},{"line_number":2428,"context_line":"    \u003c/launchSecurity\u003e\u0027\u0027\u0027"},{"line_number":2429,"context_line":""},{"line_number":2430,"context_line":"    _domain_capability_features_with_TDX \u003d \u0027\u0027\u0027  \u003cfeatures\u003e"},{"line_number":2431,"context_line":"      \u003cgic supported\u003d\u0027no\u0027/\u003e"},{"line_number":2432,"context_line":"      \u003ctdx supported\u003d\u0027yes\u0027/\u003e"},{"line_number":2433,"context_line":"    \u003c/features\u003e\u0027\u0027\u0027"},{"line_number":2434,"context_line":""},{"line_number":2435,"context_line":"    _domain_capability_features_with_TDX_unsupported \u003d \\"},{"line_number":2436,"context_line":"        _domain_capability_features_with_TDX.replace(\u0027yes\u0027, \u0027no\u0027)"},{"line_number":2437,"context_line":""},{"line_number":2438,"context_line":"    def getCapabilities(self):"},{"line_number":2439,"context_line":"        \"\"\"Return spoofed capabilities.\"\"\""},{"line_number":2440,"context_line":"        numa_topology \u003d self.host_info.numa_topology"}],"source_content_type":"text/x-python","patch_set":5,"id":"7af93002_332a619c","line":2437,"range":{"start_line":2430,"start_character":3,"end_line":2437,"end_character":1},"in_reply_to":"2ce30697_f42ab090","updated":"2026-08-21 18:21:30.000000000","message":"Done","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"34120baec93a35607f5cb8afa12b7f57ec3e06d6","unresolved":true,"context_lines":[{"line_number":2427,"context_line":"      \u003c/enum\u003e"},{"line_number":2428,"context_line":"    \u003c/launchSecurity\u003e\u0027\u0027\u0027"},{"line_number":2429,"context_line":""},{"line_number":2430,"context_line":"    _domain_capability_features_with_TDX \u003d \u0027\u0027\u0027  \u003cfeatures\u003e"},{"line_number":2431,"context_line":"      \u003cgic supported\u003d\u0027no\u0027/\u003e"},{"line_number":2432,"context_line":"      \u003ctdx supported\u003d\u0027yes\u0027/\u003e"},{"line_number":2433,"context_line":"    \u003c/features\u003e\u0027\u0027\u0027"},{"line_number":2434,"context_line":""},{"line_number":2435,"context_line":"    _domain_capability_features_with_TDX_unsupported \u003d \\"},{"line_number":2436,"context_line":"        _domain_capability_features_with_TDX.replace(\u0027yes\u0027, \u0027no\u0027)"},{"line_number":2437,"context_line":""},{"line_number":2438,"context_line":"    def getCapabilities(self):"},{"line_number":2439,"context_line":"        \"\"\"Return spoofed capabilities.\"\"\""},{"line_number":2440,"context_line":"        numa_topology \u003d self.host_info.numa_topology"}],"source_content_type":"text/x-python","patch_set":5,"id":"2ce30697_f42ab090","line":2437,"range":{"start_line":2430,"start_character":3,"end_line":2437,"end_character":1},"in_reply_to":"82c36958_133b3224","updated":"2026-08-21 13:46:13.000000000","message":"Fixed","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"}],"nova/tests/unit/virt/libvirt/test_driver.py":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"c194d9f50110de9910600cb276e80b975a9d8f78","unresolved":true,"context_lines":[{"line_number":3378,"context_line":"    # the getDomainCapabilities test stub is called by memory encryption config"},{"line_number":3379,"context_line":"    # but it doesn\u0027t support the faked machine type used in this test"},{"line_number":3380,"context_line":"    @mock.patch.object(libvirt_driver.LibvirtDriver,"},{"line_number":3381,"context_line":"                \u0027_get_mem_encryption_config\u0027, new\u003dmock.Mock(return_value\u003dNone))"},{"line_number":3382,"context_line":"    def test_get_guest_config_records_machine_type_in_instance(self):"},{"line_number":3383,"context_line":"        # Assert that the config derived machine type is used when it"},{"line_number":3384,"context_line":"        # isn\u0027t present in the image_meta of an instance."}],"source_content_type":"text/x-python","patch_set":5,"id":"f9ae4934_e0fab8f9","line":3381,"range":{"start_line":3381,"start_character":60,"end_line":3381,"end_character":77},"updated":"2026-08-18 20:31:48.000000000","message":"nit: that is the default if you dont set it","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":false,"context_lines":[{"line_number":3378,"context_line":"    # the getDomainCapabilities test stub is called by memory encryption config"},{"line_number":3379,"context_line":"    # but it doesn\u0027t support the faked machine type used in this test"},{"line_number":3380,"context_line":"    @mock.patch.object(libvirt_driver.LibvirtDriver,"},{"line_number":3381,"context_line":"                \u0027_get_mem_encryption_config\u0027, new\u003dmock.Mock(return_value\u003dNone))"},{"line_number":3382,"context_line":"    def test_get_guest_config_records_machine_type_in_instance(self):"},{"line_number":3383,"context_line":"        # Assert that the config derived machine type is used when it"},{"line_number":3384,"context_line":"        # isn\u0027t present in the image_meta of an instance."}],"source_content_type":"text/x-python","patch_set":5,"id":"7226def3_6e4e1e0b","line":3381,"range":{"start_line":3381,"start_character":60,"end_line":3381,"end_character":77},"in_reply_to":"dea5dcea_3ceb89a9","updated":"2026-08-21 18:21:30.000000000","message":"oh your irght it returns a mock obejct by defualt not None","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"5a0eaca406f3fb1d8b357ce1d861746c51370fb8","unresolved":true,"context_lines":[{"line_number":3378,"context_line":"    # the getDomainCapabilities test stub is called by memory encryption config"},{"line_number":3379,"context_line":"    # but it doesn\u0027t support the faked machine type used in this test"},{"line_number":3380,"context_line":"    @mock.patch.object(libvirt_driver.LibvirtDriver,"},{"line_number":3381,"context_line":"                \u0027_get_mem_encryption_config\u0027, new\u003dmock.Mock(return_value\u003dNone))"},{"line_number":3382,"context_line":"    def test_get_guest_config_records_machine_type_in_instance(self):"},{"line_number":3383,"context_line":"        # Assert that the config derived machine type is used when it"},{"line_number":3384,"context_line":"        # isn\u0027t present in the image_meta of an instance."}],"source_content_type":"text/x-python","patch_set":5,"id":"dea5dcea_3ceb89a9","line":3381,"range":{"start_line":3381,"start_character":60,"end_line":3381,"end_character":77},"in_reply_to":"f9ae4934_e0fab8f9","updated":"2026-08-21 07:29:49.000000000","message":"I tried to not set it but it did not behave the same\n\nError:\n```\nnova.tests.unit.virt.libvirt.test_driver.LibvirtConnTestCase.test_get_guest_config_records_machine_type_in_instance\n-------------------------------------------------------------------------------------------------------------------\n\nCaptured traceback:\n~~~~~~~~~~~~~~~~~~~\n    Traceback (most recent call last):\n\n      File \"/usr/lib/python3.14/unittest/mock.py\", line 1439, in patched\n    return func(*newargs, **newkeywargs)\n\n      File \"/opt/stack/nova/nova/tests/unit/virt/libvirt/test_driver.py\", line 3394, in test_get_guest_config_records_machine_type_in_instance\n    cfg \u003d drvr._get_guest_config(\n        instance,\n    ...\u003c2 lines\u003e...\n        disk_info\n    )\n\n      File \"/opt/stack/nova/nova/virt/libvirt/driver.py\", line 7867, in _get_guest_config\n    self._guest_configure_mem_encryption(instance, guest,\n    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^\n                                         me_config.model)\n                                         ^^^^^^^^^^^^^^^^\n\n      File \"/opt/stack/nova/nova/virt/libvirt/driver.py\", line 7943, in _guest_configure_mem_encryption\n    raise exception.Invalid(\n    ...\u003c4 lines\u003e...\n        })\n\n    nova.exception.Invalid: Unknown MemEncryptionModel: \u003cMock name\u003d\u0027mock().model\u0027 id\u003d\u0027132031258857824\u0027\u003e. Supported models: amd-sev, amd-sev-es, amd-sev-snp, intel-tdx\n```","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"307ec143e13b4fbb9381b2e953e51fa243b8ff20","unresolved":true,"context_lines":[{"line_number":30911,"context_line":"        \"\"\"Test that the entire check pass if the driver supports all models"},{"line_number":30912,"context_line":"        instances request"},{"line_number":30913,"context_line":"        \"\"\""},{"line_number":30914,"context_line":"        self._test__validate_mem_encryption_configuration(True, True, True)"},{"line_number":30915,"context_line":""},{"line_number":30916,"context_line":"    @mock.patch(\u0027nova.objects.instance.Instance.save\u0027)"},{"line_number":30917,"context_line":"    def test_register_machine_type_already_registered_image_metadata("}],"source_content_type":"text/x-python","patch_set":5,"id":"cff9a086_8f051949","line":30914,"range":{"start_line":30914,"start_character":70,"end_line":30914,"end_character":74},"updated":"2026-08-21 01:36:52.000000000","message":"here you can add tests if instances requested the TDX support and host does not have. To pass that check, you need to add TDX part in (i commented in driver file about it) _validate_mem_encryption_configuration","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a1436bb02c3590cb450fd0c9a080737482574aeb","unresolved":false,"context_lines":[{"line_number":30911,"context_line":"        \"\"\"Test that the entire check pass if the driver supports all models"},{"line_number":30912,"context_line":"        instances request"},{"line_number":30913,"context_line":"        \"\"\""},{"line_number":30914,"context_line":"        self._test__validate_mem_encryption_configuration(True, True, True)"},{"line_number":30915,"context_line":""},{"line_number":30916,"context_line":"    @mock.patch(\u0027nova.objects.instance.Instance.save\u0027)"},{"line_number":30917,"context_line":"    def test_register_machine_type_already_registered_image_metadata("}],"source_content_type":"text/x-python","patch_set":5,"id":"fdaf01cf_b33ea516","line":30914,"range":{"start_line":30914,"start_character":70,"end_line":30914,"end_character":74},"in_reply_to":"526ecd41_20078af4","updated":"2026-08-21 19:26:40.000000000","message":"thanks","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"5a0eaca406f3fb1d8b357ce1d861746c51370fb8","unresolved":true,"context_lines":[{"line_number":30911,"context_line":"        \"\"\"Test that the entire check pass if the driver supports all models"},{"line_number":30912,"context_line":"        instances request"},{"line_number":30913,"context_line":"        \"\"\""},{"line_number":30914,"context_line":"        self._test__validate_mem_encryption_configuration(True, True, True)"},{"line_number":30915,"context_line":""},{"line_number":30916,"context_line":"    @mock.patch(\u0027nova.objects.instance.Instance.save\u0027)"},{"line_number":30917,"context_line":"    def test_register_machine_type_already_registered_image_metadata("}],"source_content_type":"text/x-python","patch_set":5,"id":"526ecd41_20078af4","line":30914,"range":{"start_line":30914,"start_character":70,"end_line":30914,"end_character":74},"in_reply_to":"cff9a086_8f051949","updated":"2026-08-21 07:29:49.000000000","message":"This gets added in a later patch:\nhttps://review.opendev.org/c/openstack/nova/+/999249/3/nova/tests/unit/virt/libvirt/test_driver.py","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"}],"nova/tests/unit/virt/libvirt/test_host.py":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"076e4ec79a0a1c1328d8abed4f2e1388c78cd597","unresolved":true,"context_lines":[{"line_number":2495,"context_line":"            return_value\u003d63):"},{"line_number":2496,"context_line":"            self.assertTrue(self.host.supports_intel_tdx)"},{"line_number":2497,"context_line":"            self.assertEqual("},{"line_number":2498,"context_line":"    63, self.host._get_mem_encryption_slots_intel_tdx())"},{"line_number":2499,"context_line":""},{"line_number":2500,"context_line":"    @mock.patch.object(os.path, \u0027exists\u0027, return_value\u003dTrue)"},{"line_number":2501,"context_line":"    @mock.patch(\u0027builtins.open\u0027, mock.mock_open(read_data\u003d\u00271\\n\u0027))"}],"source_content_type":"text/x-python","patch_set":2,"id":"d5beedbb_9d83490c","line":2498,"updated":"2026-06-24 16:23:59.000000000","message":"nit: it is strangely indented","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"70f5ddc18628b63921353c6a606b35ba9a1fb9e3","unresolved":false,"context_lines":[{"line_number":2495,"context_line":"            return_value\u003d63):"},{"line_number":2496,"context_line":"            self.assertTrue(self.host.supports_intel_tdx)"},{"line_number":2497,"context_line":"            self.assertEqual("},{"line_number":2498,"context_line":"    63, self.host._get_mem_encryption_slots_intel_tdx())"},{"line_number":2499,"context_line":""},{"line_number":2500,"context_line":"    @mock.patch.object(os.path, \u0027exists\u0027, return_value\u003dTrue)"},{"line_number":2501,"context_line":"    @mock.patch(\u0027builtins.open\u0027, mock.mock_open(read_data\u003d\u00271\\n\u0027))"}],"source_content_type":"text/x-python","patch_set":2,"id":"8efe27a7_4b794874","line":2498,"in_reply_to":"d5beedbb_9d83490c","updated":"2026-06-26 09:46:24.000000000","message":"Acknowledged","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"076e4ec79a0a1c1328d8abed4f2e1388c78cd597","unresolved":true,"context_lines":[{"line_number":2506,"context_line":"                            return_value\u003dNone):"},{"line_number":2507,"context_line":"            self.assertTrue(self.host.supports_intel_tdx)"},{"line_number":2508,"context_line":"            self.assertEqual("},{"line_number":2509,"context_line":"    0, self.host._get_mem_encryption_slots_intel_tdx())"},{"line_number":2510,"context_line":""},{"line_number":2511,"context_line":"    @mock.patch.object(os.path, \u0027exists\u0027, return_value\u003dTrue)"},{"line_number":2512,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"}],"source_content_type":"text/x-python","patch_set":2,"id":"8a1aa658_1c36ed89","line":2509,"updated":"2026-06-24 16:23:59.000000000","message":"ditto","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"70f5ddc18628b63921353c6a606b35ba9a1fb9e3","unresolved":false,"context_lines":[{"line_number":2506,"context_line":"                            return_value\u003dNone):"},{"line_number":2507,"context_line":"            self.assertTrue(self.host.supports_intel_tdx)"},{"line_number":2508,"context_line":"            self.assertEqual("},{"line_number":2509,"context_line":"    0, self.host._get_mem_encryption_slots_intel_tdx())"},{"line_number":2510,"context_line":""},{"line_number":2511,"context_line":"    @mock.patch.object(os.path, \u0027exists\u0027, return_value\u003dTrue)"},{"line_number":2512,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"}],"source_content_type":"text/x-python","patch_set":2,"id":"1daf953b_22b20555","line":2509,"in_reply_to":"8a1aa658_1c36ed89","updated":"2026-06-26 09:46:24.000000000","message":"Acknowledged","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":true,"context_lines":[{"line_number":2569,"context_line":""},{"line_number":2570,"context_line":"        def _exists(path):"},{"line_number":2571,"context_line":"            if path \u003d\u003d \u0027/sys/fs/cgroup/misc.capacity\u0027:"},{"line_number":2572,"context_line":"                return self.misc_capacity is not None"},{"line_number":2573,"context_line":"            # if path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_snp\u0027:"},{"line_number":2574,"context_line":"            #     return self.kernel_sev_snp is not None"},{"line_number":2575,"context_line":"            # elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_es\u0027:"},{"line_number":2576,"context_line":"            #     return self.kernel_sev_es is not None"},{"line_number":2577,"context_line":"            elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev\u0027:"},{"line_number":2578,"context_line":"                return None"},{"line_number":2579,"context_line":"            self.fail(\u0027Unexpected path is accessed by os.path: %s\u0027 % path)"}],"source_content_type":"text/x-python","patch_set":3,"id":"7fa24781_03ab47cf","line":2576,"range":{"start_line":2572,"start_character":53,"end_line":2576,"end_character":55},"updated":"2026-07-21 12:50:14.000000000","message":"Can we remove these ?","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"b8ddd5d25bcbbc1db555886ced8088e93538d0cd","unresolved":true,"context_lines":[{"line_number":2569,"context_line":""},{"line_number":2570,"context_line":"        def _exists(path):"},{"line_number":2571,"context_line":"            if path \u003d\u003d \u0027/sys/fs/cgroup/misc.capacity\u0027:"},{"line_number":2572,"context_line":"                return self.misc_capacity is not None"},{"line_number":2573,"context_line":"            # if path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_snp\u0027:"},{"line_number":2574,"context_line":"            #     return self.kernel_sev_snp is not None"},{"line_number":2575,"context_line":"            # elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_es\u0027:"},{"line_number":2576,"context_line":"            #     return self.kernel_sev_es is not None"},{"line_number":2577,"context_line":"            elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev\u0027:"},{"line_number":2578,"context_line":"                return None"},{"line_number":2579,"context_line":"            self.fail(\u0027Unexpected path is accessed by os.path: %s\u0027 % path)"}],"source_content_type":"text/x-python","patch_set":3,"id":"c957c906_df68e6d1","line":2576,"range":{"start_line":2572,"start_character":53,"end_line":2576,"end_character":55},"in_reply_to":"7fa24781_03ab47cf","updated":"2026-07-21 12:57:50.000000000","message":"ops, yes will do!","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"e6a159135f9ca348318b96de4d159c33688781a1","unresolved":false,"context_lines":[{"line_number":2569,"context_line":""},{"line_number":2570,"context_line":"        def _exists(path):"},{"line_number":2571,"context_line":"            if path \u003d\u003d \u0027/sys/fs/cgroup/misc.capacity\u0027:"},{"line_number":2572,"context_line":"                return self.misc_capacity is not None"},{"line_number":2573,"context_line":"            # if path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_snp\u0027:"},{"line_number":2574,"context_line":"            #     return self.kernel_sev_snp is not None"},{"line_number":2575,"context_line":"            # elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_es\u0027:"},{"line_number":2576,"context_line":"            #     return self.kernel_sev_es is not None"},{"line_number":2577,"context_line":"            elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev\u0027:"},{"line_number":2578,"context_line":"                return None"},{"line_number":2579,"context_line":"            self.fail(\u0027Unexpected path is accessed by os.path: %s\u0027 % path)"}],"source_content_type":"text/x-python","patch_set":3,"id":"08c62077_9f283570","line":2576,"range":{"start_line":2572,"start_character":53,"end_line":2576,"end_character":55},"in_reply_to":"c957c906_df68e6d1","updated":"2026-07-27 12:17:33.000000000","message":"Done","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":true,"context_lines":[{"line_number":2574,"context_line":"            #     return self.kernel_sev_snp is not None"},{"line_number":2575,"context_line":"            # elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_es\u0027:"},{"line_number":2576,"context_line":"            #     return self.kernel_sev_es is not None"},{"line_number":2577,"context_line":"            elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev\u0027:"},{"line_number":2578,"context_line":"                return None"},{"line_number":2579,"context_line":"            self.fail(\u0027Unexpected path is accessed by os.path: %s\u0027 % path)"},{"line_number":2580,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"abb71667_75c66f9f","line":2577,"range":{"start_line":2577,"start_character":25,"end_line":2577,"end_character":61},"updated":"2026-07-21 12:50:14.000000000","message":"adding a note hear to record context of this patching (I assume this is needed due to supports_mem_encryption flag, right ?)","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"e6a159135f9ca348318b96de4d159c33688781a1","unresolved":false,"context_lines":[{"line_number":2574,"context_line":"            #     return self.kernel_sev_snp is not None"},{"line_number":2575,"context_line":"            # elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_es\u0027:"},{"line_number":2576,"context_line":"            #     return self.kernel_sev_es is not None"},{"line_number":2577,"context_line":"            elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev\u0027:"},{"line_number":2578,"context_line":"                return None"},{"line_number":2579,"context_line":"            self.fail(\u0027Unexpected path is accessed by os.path: %s\u0027 % path)"},{"line_number":2580,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"33c55dd0_6aadd95c","line":2577,"range":{"start_line":2577,"start_character":25,"end_line":2577,"end_character":61},"in_reply_to":"50b87e2c_c012fbaa","updated":"2026-07-27 12:17:33.000000000","message":"Done","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"b8ddd5d25bcbbc1db555886ced8088e93538d0cd","unresolved":true,"context_lines":[{"line_number":2574,"context_line":"            #     return self.kernel_sev_snp is not None"},{"line_number":2575,"context_line":"            # elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev_es\u0027:"},{"line_number":2576,"context_line":"            #     return self.kernel_sev_es is not None"},{"line_number":2577,"context_line":"            elif path \u003d\u003d \u0027/sys/module/kvm_amd/parameters/sev\u0027:"},{"line_number":2578,"context_line":"                return None"},{"line_number":2579,"context_line":"            self.fail(\u0027Unexpected path is accessed by os.path: %s\u0027 % path)"},{"line_number":2580,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"50b87e2c_c012fbaa","line":2577,"range":{"start_line":2577,"start_character":25,"end_line":2577,"end_character":61},"in_reply_to":"abb71667_75c66f9f","updated":"2026-07-21 12:57:50.000000000","message":"Yes correct will add a note","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":true,"context_lines":[{"line_number":2590,"context_line":"            \u0027builtins.open\u0027, side_effect\u003d_open)).mock"},{"line_number":2591,"context_line":""},{"line_number":2592,"context_line":""},{"line_number":2593,"context_line":"@ddt.ddt"},{"line_number":2594,"context_line":"class TestLibvirtTDXUnsupported(TestLibvirtTDX):"},{"line_number":2595,"context_line":"    def test_unsupported_without_feature(self):"},{"line_number":2596,"context_line":"        self.assertFalse(self.host.supports_intel_tdx)"}],"source_content_type":"text/x-python","patch_set":3,"id":"97e8e2d0_4b3d265f","line":2593,"range":{"start_line":2593,"start_character":0,"end_line":2593,"end_character":8},"updated":"2026-07-21 12:50:14.000000000","message":"ddt isn\u0027t used in this class so this can be removed.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"b8ddd5d25bcbbc1db555886ced8088e93538d0cd","unresolved":false,"context_lines":[{"line_number":2590,"context_line":"            \u0027builtins.open\u0027, side_effect\u003d_open)).mock"},{"line_number":2591,"context_line":""},{"line_number":2592,"context_line":""},{"line_number":2593,"context_line":"@ddt.ddt"},{"line_number":2594,"context_line":"class TestLibvirtTDXUnsupported(TestLibvirtTDX):"},{"line_number":2595,"context_line":"    def test_unsupported_without_feature(self):"},{"line_number":2596,"context_line":"        self.assertFalse(self.host.supports_intel_tdx)"}],"source_content_type":"text/x-python","patch_set":3,"id":"a209b9d8_dfde9041","line":2593,"range":{"start_line":2593,"start_character":0,"end_line":2593,"end_character":8},"in_reply_to":"97e8e2d0_4b3d265f","updated":"2026-07-21 12:57:50.000000000","message":"Acknowledged","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":true,"context_lines":[{"line_number":2593,"context_line":"@ddt.ddt"},{"line_number":2594,"context_line":"class TestLibvirtTDXUnsupported(TestLibvirtTDX):"},{"line_number":2595,"context_line":"    def test_unsupported_without_feature(self):"},{"line_number":2596,"context_line":"        self.assertFalse(self.host.supports_intel_tdx)"},{"line_number":2597,"context_line":""},{"line_number":2598,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"},{"line_number":2599,"context_line":"        new\u003dvc._domain_capability_features_with_TDX_unsupported)"}],"source_content_type":"text/x-python","patch_set":3,"id":"4dd0f3d4_7dcd8570","line":2596,"range":{"start_line":2596,"start_character":13,"end_line":2596,"end_character":24},"updated":"2026-07-21 12:50:14.000000000","message":"Can we add asssert for supports_mem_encryption ? We probably want to add the same to the existing sev cases...","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"3cd6719183487d3f575a6122837108a0f3b93daa","unresolved":true,"context_lines":[{"line_number":2593,"context_line":"@ddt.ddt"},{"line_number":2594,"context_line":"class TestLibvirtTDXUnsupported(TestLibvirtTDX):"},{"line_number":2595,"context_line":"    def test_unsupported_without_feature(self):"},{"line_number":2596,"context_line":"        self.assertFalse(self.host.supports_intel_tdx)"},{"line_number":2597,"context_line":""},{"line_number":2598,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"},{"line_number":2599,"context_line":"        new\u003dvc._domain_capability_features_with_TDX_unsupported)"}],"source_content_type":"text/x-python","patch_set":3,"id":"684e6d04_5899784a","line":2596,"range":{"start_line":2596,"start_character":13,"end_line":2596,"end_character":24},"in_reply_to":"26cbe1b6_9f0eb99e","updated":"2026-07-21 13:42:41.000000000","message":"Looking at the current sev test codes, we consistently assert supports_amd_sev and supports_mem_encryption, while we don\u0027t check the generic flag in es and snp.\n\nI think we can leave es and snp now but add supports_mem_encryption assetion the tdx test cases where supports_intel_tdx is asserted .","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"b8ddd5d25bcbbc1db555886ced8088e93538d0cd","unresolved":true,"context_lines":[{"line_number":2593,"context_line":"@ddt.ddt"},{"line_number":2594,"context_line":"class TestLibvirtTDXUnsupported(TestLibvirtTDX):"},{"line_number":2595,"context_line":"    def test_unsupported_without_feature(self):"},{"line_number":2596,"context_line":"        self.assertFalse(self.host.supports_intel_tdx)"},{"line_number":2597,"context_line":""},{"line_number":2598,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"},{"line_number":2599,"context_line":"        new\u003dvc._domain_capability_features_with_TDX_unsupported)"}],"source_content_type":"text/x-python","patch_set":3,"id":"26cbe1b6_9f0eb99e","line":2596,"range":{"start_line":2596,"start_character":13,"end_line":2596,"end_character":24},"in_reply_to":"4dd0f3d4_7dcd8570","updated":"2026-07-21 12:57:50.000000000","message":"I know there were some before in sev as well and I mostly updated to match with the new style. Should I add them back for sev?","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"a41191f94a198c68b6cf97551187fbd1ca45c387","unresolved":false,"context_lines":[{"line_number":2593,"context_line":"@ddt.ddt"},{"line_number":2594,"context_line":"class TestLibvirtTDXUnsupported(TestLibvirtTDX):"},{"line_number":2595,"context_line":"    def test_unsupported_without_feature(self):"},{"line_number":2596,"context_line":"        self.assertFalse(self.host.supports_intel_tdx)"},{"line_number":2597,"context_line":""},{"line_number":2598,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"},{"line_number":2599,"context_line":"        new\u003dvc._domain_capability_features_with_TDX_unsupported)"}],"source_content_type":"text/x-python","patch_set":3,"id":"54b94a5d_a200093f","line":2596,"range":{"start_line":2596,"start_character":13,"end_line":2596,"end_character":24},"in_reply_to":"684e6d04_5899784a","updated":"2026-07-23 12:53:14.000000000","message":"Acknowledged","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":true,"context_lines":[{"line_number":2635,"context_line":"    def test_supported_with_feature(self):"},{"line_number":2636,"context_line":"        self.misc_capacity \u003d \"tdx 0\\n\""},{"line_number":2637,"context_line":"        self.assertTrue(self.host.supports_intel_tdx)"},{"line_number":2638,"context_line":"        # self.assertTrue(self.host.supports_mem_encryption)"},{"line_number":2639,"context_line":""},{"line_number":2640,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"},{"line_number":2641,"context_line":"                       new\u003dvc._domain_capability_features_with_TDX)"}],"source_content_type":"text/x-python","patch_set":3,"id":"9c481c9c_7f3a8fcb","line":2638,"range":{"start_line":2638,"start_character":8,"end_line":2638,"end_character":60},"updated":"2026-07-21 12:50:14.000000000","message":"Uncomment this and add this consistently to the other checks","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"b8ddd5d25bcbbc1db555886ced8088e93538d0cd","unresolved":false,"context_lines":[{"line_number":2635,"context_line":"    def test_supported_with_feature(self):"},{"line_number":2636,"context_line":"        self.misc_capacity \u003d \"tdx 0\\n\""},{"line_number":2637,"context_line":"        self.assertTrue(self.host.supports_intel_tdx)"},{"line_number":2638,"context_line":"        # self.assertTrue(self.host.supports_mem_encryption)"},{"line_number":2639,"context_line":""},{"line_number":2640,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"},{"line_number":2641,"context_line":"                       new\u003dvc._domain_capability_features_with_TDX)"}],"source_content_type":"text/x-python","patch_set":3,"id":"f6502cd7_5f6cf494","line":2638,"range":{"start_line":2638,"start_character":8,"end_line":2638,"end_character":60},"in_reply_to":"9c481c9c_7f3a8fcb","updated":"2026-07-21 12:57:50.000000000","message":"Acknowledged","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"68997c8c750bd59f10578044e7e407cc85c92310","unresolved":true,"context_lines":[{"line_number":2595,"context_line":"        self.assertFalse(self.host.supports_mem_encryption)"},{"line_number":2596,"context_line":""},{"line_number":2597,"context_line":"    @mock.patch.object(vc, \u0027_domain_capability_features\u0027,"},{"line_number":2598,"context_line":"    new\u003dvc._domain_capability_features_with_TDX)"},{"line_number":2599,"context_line":"    def test_unsupported_without_host_passthrough(self):"},{"line_number":2600,"context_line":"        self.flags(cpu_mode\u003d\u0027host-model\u0027, group\u003d\u0027libvirt\u0027)"},{"line_number":2601,"context_line":"        self.assertFalse(self.host.supports_intel_tdx)"}],"source_content_type":"text/x-python","patch_set":5,"id":"8a266c24_4f661192","line":2598,"updated":"2026-08-10 10:07:54.000000000","message":"minor indentation problem","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"}],"nova/virt/libvirt/config.py":[{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":true,"context_lines":[{"line_number":339,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureSev()"},{"line_number":340,"context_line":"            if c.tag \u003d\u003d \"launchSecurity\":"},{"line_number":341,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureLaunchSecurity()"},{"line_number":342,"context_line":"            if c.tag \u003d\u003d \"tdx\":"},{"line_number":343,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureTDX()"},{"line_number":344,"context_line":"            if feature:"},{"line_number":345,"context_line":"                feature.parse_dom(c)"},{"line_number":346,"context_line":"                self.features.append(feature)"}],"source_content_type":"text/x-python","patch_set":3,"id":"701ec0cd_ec9cdd5b","line":343,"range":{"start_line":342,"start_character":12,"end_line":343,"end_character":61},"updated":"2026-07-21 12:50:14.000000000","message":"I personally prefer having this before launchSecurity, so that we have individual model elements before the common launchSecurity element","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"367c45d013649a6e02525b38dae0bed03e733cb2","unresolved":false,"context_lines":[{"line_number":339,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureSev()"},{"line_number":340,"context_line":"            if c.tag \u003d\u003d \"launchSecurity\":"},{"line_number":341,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureLaunchSecurity()"},{"line_number":342,"context_line":"            if c.tag \u003d\u003d \"tdx\":"},{"line_number":343,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureTDX()"},{"line_number":344,"context_line":"            if feature:"},{"line_number":345,"context_line":"                feature.parse_dom(c)"},{"line_number":346,"context_line":"                self.features.append(feature)"}],"source_content_type":"text/x-python","patch_set":3,"id":"c508ee1a_78f16214","line":343,"range":{"start_line":342,"start_character":12,"end_line":343,"end_character":61},"in_reply_to":"07d3612b_293306b2","updated":"2026-07-23 14:36:18.000000000","message":"Done","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"b8ddd5d25bcbbc1db555886ced8088e93538d0cd","unresolved":true,"context_lines":[{"line_number":339,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureSev()"},{"line_number":340,"context_line":"            if c.tag \u003d\u003d \"launchSecurity\":"},{"line_number":341,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureLaunchSecurity()"},{"line_number":342,"context_line":"            if c.tag \u003d\u003d \"tdx\":"},{"line_number":343,"context_line":"                feature \u003d LibvirtConfigDomainCapsFeatureTDX()"},{"line_number":344,"context_line":"            if feature:"},{"line_number":345,"context_line":"                feature.parse_dom(c)"},{"line_number":346,"context_line":"                self.features.append(feature)"}],"source_content_type":"text/x-python","patch_set":3,"id":"07d3612b_293306b2","line":343,"range":{"start_line":342,"start_character":12,"end_line":343,"end_character":61},"in_reply_to":"701ec0cd_ec9cdd5b","updated":"2026-07-21 12:57:50.000000000","message":"Yes I agree, will do","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"}],"nova/virt/libvirt/host.py":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"076e4ec79a0a1c1328d8abed4f2e1388c78cd597","unresolved":true,"context_lines":[{"line_number":2180,"context_line":"                    feature_is_tdx \u003d isinstance("},{"line_number":2181,"context_line":"                        feature, vconfig.LibvirtConfigDomainCapsFeatureTDX"},{"line_number":2182,"context_line":"                    )"},{"line_number":2183,"context_line":"                    if feature_is_tdx and feature.supported:"},{"line_number":2184,"context_line":"                        LOG.info(\"Intel TDX support detected\")"},{"line_number":2185,"context_line":"                        self._supports_intel_tdx \u003d True"},{"line_number":2186,"context_line":"                        return self._supports_intel_tdx"}],"source_content_type":"text/x-python","patch_set":2,"id":"c605d41a_4b503014","line":2183,"updated":"2026-06-24 16:23:59.000000000","message":"Am I correct that this is wants to cover the libvirt and qemu version dependencies as well?\nDoes an older libvirt report the capability if the host support it? I guess not. But: Does a new libvirt with old qemu report this capability if the host support it?","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"263f9e4abce8ff0deb9c2697c4d35cbf05a852ca","unresolved":false,"context_lines":[{"line_number":2180,"context_line":"                    feature_is_tdx \u003d isinstance("},{"line_number":2181,"context_line":"                        feature, vconfig.LibvirtConfigDomainCapsFeatureTDX"},{"line_number":2182,"context_line":"                    )"},{"line_number":2183,"context_line":"                    if feature_is_tdx and feature.supported:"},{"line_number":2184,"context_line":"                        LOG.info(\"Intel TDX support detected\")"},{"line_number":2185,"context_line":"                        self._supports_intel_tdx \u003d True"},{"line_number":2186,"context_line":"                        return self._supports_intel_tdx"}],"source_content_type":"text/x-python","patch_set":2,"id":"ca586009_1aa1a8eb","line":2183,"in_reply_to":"5cabead5_e20c72ef","updated":"2026-07-20 13:42:54.000000000","message":"Yeah it seems that internal logic in libvirt to expose tdx feature seems already checks the sysfs parameter so we can drop it.","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"21846c337e6a354f0c775e1799dceefaafdfb094","unresolved":false,"context_lines":[{"line_number":2180,"context_line":"                    feature_is_tdx \u003d isinstance("},{"line_number":2181,"context_line":"                        feature, vconfig.LibvirtConfigDomainCapsFeatureTDX"},{"line_number":2182,"context_line":"                    )"},{"line_number":2183,"context_line":"                    if feature_is_tdx and feature.supported:"},{"line_number":2184,"context_line":"                        LOG.info(\"Intel TDX support detected\")"},{"line_number":2185,"context_line":"                        self._supports_intel_tdx \u003d True"},{"line_number":2186,"context_line":"                        return self._supports_intel_tdx"}],"source_content_type":"text/x-python","patch_set":2,"id":"5cabead5_e20c72ef","line":2183,"in_reply_to":"91464a4a_e997ea90","updated":"2026-06-30 16:05:23.000000000","message":"OK thanks for the explanation. If we can dorp the sysfs check that is good to.","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"70f5ddc18628b63921353c6a606b35ba9a1fb9e3","unresolved":true,"context_lines":[{"line_number":2180,"context_line":"                    feature_is_tdx \u003d isinstance("},{"line_number":2181,"context_line":"                        feature, vconfig.LibvirtConfigDomainCapsFeatureTDX"},{"line_number":2182,"context_line":"                    )"},{"line_number":2183,"context_line":"                    if feature_is_tdx and feature.supported:"},{"line_number":2184,"context_line":"                        LOG.info(\"Intel TDX support detected\")"},{"line_number":2185,"context_line":"                        self._supports_intel_tdx \u003d True"},{"line_number":2186,"context_line":"                        return self._supports_intel_tdx"}],"source_content_type":"text/x-python","patch_set":2,"id":"91464a4a_e997ea90","line":2183,"in_reply_to":"c605d41a_4b503014","updated":"2026-06-26 09:46:24.000000000","message":"Yes libvirt queries qemu to see if it has the tdx-guest object, essentially asking if it was compiled with TDX support. A new libvirt with an old qemu (without TDX support) would therefore not report tdx capable, even if the host has the support.\n\nI also found that the kernel sysfs parameter is actually directly checked by Libvirt already [1]. The separate check by Nova is therefore unnecessary and can be dropped from this patch.\n\n[1] https://gitlab.com/libvirt/libvirt/-/blob/v11.6.0/src/qemu/qemu_capabilities.c?ref_type\u003dtags#L5335","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"28cc245a851ab305665099dbd01ca18c43503cea","unresolved":false,"context_lines":[{"line_number":2180,"context_line":"                    feature_is_tdx \u003d isinstance("},{"line_number":2181,"context_line":"                        feature, vconfig.LibvirtConfigDomainCapsFeatureTDX"},{"line_number":2182,"context_line":"                    )"},{"line_number":2183,"context_line":"                    if feature_is_tdx and feature.supported:"},{"line_number":2184,"context_line":"                        LOG.info(\"Intel TDX support detected\")"},{"line_number":2185,"context_line":"                        self._supports_intel_tdx \u003d True"},{"line_number":2186,"context_line":"                        return self._supports_intel_tdx"}],"source_content_type":"text/x-python","patch_set":2,"id":"c43511bd_123b6168","line":2183,"in_reply_to":"ca586009_1aa1a8eb","updated":"2026-07-21 12:15:48.000000000","message":"Dropped in latest version","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"076e4ec79a0a1c1328d8abed4f2e1388c78cd597","unresolved":true,"context_lines":[{"line_number":2224,"context_line":"        \"\"\""},{"line_number":2225,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2226,"context_line":"            return None"},{"line_number":2227,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2228,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity()"},{"line_number":2229,"context_line":"        return self._max_intel_tdx_guests"},{"line_number":2230,"context_line":""},{"line_number":2231,"context_line":"    @property"}],"source_content_type":"text/x-python","patch_set":2,"id":"f07afe35_2622aabc","line":2228,"range":{"start_line":2227,"start_character":0,"end_line":2228,"end_character":65},"updated":"2026-06-24 16:23:59.000000000","message":"In case there is an error parsing the file nova will retry parsing it at every call and log a warning repeatedly. Would it be better saving 0 here if None is returned from _get_tdx_capacity? That would mean we only retry parsing if the compute service is restarted.","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"28cc245a851ab305665099dbd01ca18c43503cea","unresolved":false,"context_lines":[{"line_number":2224,"context_line":"        \"\"\""},{"line_number":2225,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2226,"context_line":"            return None"},{"line_number":2227,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2228,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity()"},{"line_number":2229,"context_line":"        return self._max_intel_tdx_guests"},{"line_number":2230,"context_line":""},{"line_number":2231,"context_line":"    @property"}],"source_content_type":"text/x-python","patch_set":2,"id":"31d93781_9ccf7392","line":2228,"range":{"start_line":2227,"start_character":0,"end_line":2228,"end_character":65},"in_reply_to":"ec8a940e_e48a8714","updated":"2026-07-21 12:15:48.000000000","message":"Done in latest version","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"70f5ddc18628b63921353c6a606b35ba9a1fb9e3","unresolved":true,"context_lines":[{"line_number":2224,"context_line":"        \"\"\""},{"line_number":2225,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2226,"context_line":"            return None"},{"line_number":2227,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2228,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity()"},{"line_number":2229,"context_line":"        return self._max_intel_tdx_guests"},{"line_number":2230,"context_line":""},{"line_number":2231,"context_line":"    @property"}],"source_content_type":"text/x-python","patch_set":2,"id":"ec8a940e_e48a8714","line":2228,"range":{"start_line":2227,"start_character":0,"end_line":2228,"end_character":65},"in_reply_to":"f07afe35_2622aabc","updated":"2026-06-26 09:46:24.000000000","message":"Yes that sounds reasonable","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"13f88f9d2925936a3b61aa36e117f25935c0f900","unresolved":true,"context_lines":[{"line_number":330,"context_line":"        self._max_sev_guests: int \u003d 0"},{"line_number":331,"context_line":"        self._max_sev_es_guests: int \u003d 0"},{"line_number":332,"context_line":"        self._supports_intel_tdx: bool | None \u003d None"},{"line_number":333,"context_line":"        self._max_intel_tdx_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"},{"line_number":335,"context_line":"        self._supports_secure_boot: bool | None \u003d None"},{"line_number":336,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"67ab0de4_409530d2","line":333,"updated":"2026-07-22 08:53:05.000000000","message":"just to double check, there is no way to get the max guests from libvirt yet? If so  it might worth to let the libvirt developers know that such a thing would be useful :)","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a1436bb02c3590cb450fd0c9a080737482574aeb","unresolved":true,"context_lines":[{"line_number":330,"context_line":"        self._max_sev_guests: int \u003d 0"},{"line_number":331,"context_line":"        self._max_sev_es_guests: int \u003d 0"},{"line_number":332,"context_line":"        self._supports_intel_tdx: bool | None \u003d None"},{"line_number":333,"context_line":"        self._max_intel_tdx_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"},{"line_number":335,"context_line":"        self._supports_secure_boot: bool | None \u003d None"},{"line_number":336,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"9e3d9ac3_3fe66a63","line":333,"in_reply_to":"01a2b15c_5d8033f0","updated":"2026-08-21 19:26:40.000000000","message":"ok, that\u0027s better then","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":true,"context_lines":[{"line_number":330,"context_line":"        self._max_sev_guests: int \u003d 0"},{"line_number":331,"context_line":"        self._max_sev_es_guests: int \u003d 0"},{"line_number":332,"context_line":"        self._supports_intel_tdx: bool | None \u003d None"},{"line_number":333,"context_line":"        self._max_intel_tdx_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"},{"line_number":335,"context_line":"        self._supports_secure_boot: bool | None \u003d None"},{"line_number":336,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"01a2b15c_5d8033f0","line":333,"in_reply_to":"4a1d47d5_be52f255","updated":"2026-08-21 18:21:30.000000000","message":"well we asked them to add the ablity to read the same for sev and they did\nthey generally condier providing an interface to counts of this type in scope.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"307ec143e13b4fbb9381b2e953e51fa243b8ff20","unresolved":true,"context_lines":[{"line_number":330,"context_line":"        self._max_sev_guests: int \u003d 0"},{"line_number":331,"context_line":"        self._max_sev_es_guests: int \u003d 0"},{"line_number":332,"context_line":"        self._supports_intel_tdx: bool | None \u003d None"},{"line_number":333,"context_line":"        self._max_intel_tdx_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"},{"line_number":335,"context_line":"        self._supports_secure_boot: bool | None \u003d None"},{"line_number":336,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"4a1d47d5_be52f255","line":333,"in_reply_to":"59b5033c_b285dc12","updated":"2026-08-21 01:36:52.000000000","message":"not sure if libvirt will provide, most probably answer will be no. reading cgroup and fethcing value is mostly out of scope of libvirt or any deployment specific things. but yes, good to check with them","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"a41191f94a198c68b6cf97551187fbd1ca45c387","unresolved":true,"context_lines":[{"line_number":330,"context_line":"        self._max_sev_guests: int \u003d 0"},{"line_number":331,"context_line":"        self._max_sev_es_guests: int \u003d 0"},{"line_number":332,"context_line":"        self._supports_intel_tdx: bool | None \u003d None"},{"line_number":333,"context_line":"        self._max_intel_tdx_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"},{"line_number":335,"context_line":"        self._supports_secure_boot: bool | None \u003d None"},{"line_number":336,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"a5acd206_a893f2f5","line":333,"in_reply_to":"67ab0de4_409530d2","updated":"2026-07-23 12:53:14.000000000","message":"Not sure about ongoing work but there is no way currently to get max guests from libvirt. Can look into it a bit deeper :)","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"abfe7e03dd3d20ffd617f3b74f755ecca29f13a8","unresolved":false,"context_lines":[{"line_number":330,"context_line":"        self._max_sev_guests: int \u003d 0"},{"line_number":331,"context_line":"        self._max_sev_es_guests: int \u003d 0"},{"line_number":332,"context_line":"        self._supports_intel_tdx: bool | None \u003d None"},{"line_number":333,"context_line":"        self._max_intel_tdx_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"},{"line_number":335,"context_line":"        self._supports_secure_boot: bool | None \u003d None"},{"line_number":336,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"21f93250_7cfaefbd","line":333,"in_reply_to":"9e3d9ac3_3fe66a63","updated":"2026-08-24 12:47:47.000000000","message":"lets resolve this for now and ask the libivrt folks if they coudl add this to there backlog, if they add it in the future great if not then we have a workable solution in this change anyway","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"367c45d013649a6e02525b38dae0bed03e733cb2","unresolved":true,"context_lines":[{"line_number":330,"context_line":"        self._max_sev_guests: int \u003d 0"},{"line_number":331,"context_line":"        self._max_sev_es_guests: int \u003d 0"},{"line_number":332,"context_line":"        self._supports_intel_tdx: bool | None \u003d None"},{"line_number":333,"context_line":"        self._max_intel_tdx_guests: int | None \u003d None"},{"line_number":334,"context_line":"        self._supports_uefi: bool | None \u003d None"},{"line_number":335,"context_line":"        self._supports_secure_boot: bool | None \u003d None"},{"line_number":336,"context_line":""}],"source_content_type":"text/x-python","patch_set":3,"id":"59b5033c_b285dc12","line":333,"in_reply_to":"a5acd206_a893f2f5","updated":"2026-07-23 14:36:18.000000000","message":"Not a blocker of this work. But if you have time ping the libvirt folks upstream about the need. Let\u0027s see how they feel about it.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"13f88f9d2925936a3b61aa36e117f25935c0f900","unresolved":true,"context_lines":[{"line_number":2213,"context_line":""},{"line_number":2214,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2215,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2216,"context_line":"            return None"},{"line_number":2217,"context_line":""},{"line_number":2218,"context_line":"        with open(capacity_file) as f:"},{"line_number":2219,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":3,"id":"d2201a76_de867731","line":2216,"updated":"2026-07-22 08:53:05.000000000","message":"return 0","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"a41191f94a198c68b6cf97551187fbd1ca45c387","unresolved":false,"context_lines":[{"line_number":2213,"context_line":""},{"line_number":2214,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2215,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2216,"context_line":"            return None"},{"line_number":2217,"context_line":""},{"line_number":2218,"context_line":"        with open(capacity_file) as f:"},{"line_number":2219,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":3,"id":"8f17999a_4013e002","line":2216,"in_reply_to":"d2201a76_de867731","updated":"2026-07-23 12:53:14.000000000","message":"Acknowledged","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"13f88f9d2925936a3b61aa36e117f25935c0f900","unresolved":false,"context_lines":[{"line_number":2211,"context_line":"        \"\"\""},{"line_number":2212,"context_line":"        capacity_file \u003d MISC_CONTROL_GROUP_CAPACITY_FILE"},{"line_number":2213,"context_line":""},{"line_number":2214,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2215,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2216,"context_line":"            return None"},{"line_number":2217,"context_line":""},{"line_number":2218,"context_line":"        with open(capacity_file) as f:"},{"line_number":2219,"context_line":"            content \u003d f.read()"},{"line_number":2220,"context_line":"            LOG.debug(\"%s contains [%s]\", capacity_file, content)"},{"line_number":2221,"context_line":"            for line in content.splitlines():"}],"source_content_type":"text/x-python","patch_set":3,"id":"fbc78325_cff53266","line":2218,"range":{"start_line":2214,"start_character":0,"end_line":2218,"end_character":38},"updated":"2026-07-22 08:53:05.000000000","message":"nit: the general pattern of check existence and then open is prone to race condition. If the file existed at L2214 nothing guarantees that it still exists at L2218. Of course in this specific case the file being part of the kernel interface we are fine. So I\u0027m just nothing it for the future.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"13f88f9d2925936a3b61aa36e117f25935c0f900","unresolved":true,"context_lines":[{"line_number":2236,"context_line":"        \"\"\"Determine maximum number of guests with Intel TDX."},{"line_number":2237,"context_line":"        \"\"\""},{"line_number":2238,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2239,"context_line":"            return None"},{"line_number":2240,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2241,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity() or 0"},{"line_number":2242,"context_line":"        return self._max_intel_tdx_guests"}],"source_content_type":"text/x-python","patch_set":3,"id":"f04e0903_32d10f2e","line":2239,"updated":"2026-07-22 08:53:05.000000000","message":"return 0","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"a41191f94a198c68b6cf97551187fbd1ca45c387","unresolved":false,"context_lines":[{"line_number":2236,"context_line":"        \"\"\"Determine maximum number of guests with Intel TDX."},{"line_number":2237,"context_line":"        \"\"\""},{"line_number":2238,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2239,"context_line":"            return None"},{"line_number":2240,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2241,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity() or 0"},{"line_number":2242,"context_line":"        return self._max_intel_tdx_guests"}],"source_content_type":"text/x-python","patch_set":3,"id":"b7eb74f7_a98b1f69","line":2239,"in_reply_to":"f04e0903_32d10f2e","updated":"2026-07-23 12:53:14.000000000","message":"Acknowledged","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"427dfae14008cefb0bdf9c8d76a42678618c92f5","unresolved":true,"context_lines":[{"line_number":2238,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2239,"context_line":"            return None"},{"line_number":2240,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2241,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity() or 0"},{"line_number":2242,"context_line":"        return self._max_intel_tdx_guests"},{"line_number":2243,"context_line":""},{"line_number":2244,"context_line":"    @property"}],"source_content_type":"text/x-python","patch_set":3,"id":"6b06c80c_2d5892c8","line":2241,"range":{"start_line":2241,"start_character":46,"end_line":2241,"end_character":70},"updated":"2026-07-21 12:50:14.000000000","message":"This looks redundant and _get_tdx_capacity can return 0 directly instead of None","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"b8ddd5d25bcbbc1db555886ced8088e93538d0cd","unresolved":false,"context_lines":[{"line_number":2238,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2239,"context_line":"            return None"},{"line_number":2240,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2241,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity() or 0"},{"line_number":2242,"context_line":"        return self._max_intel_tdx_guests"},{"line_number":2243,"context_line":""},{"line_number":2244,"context_line":"    @property"}],"source_content_type":"text/x-python","patch_set":3,"id":"2a53b3b2_3e656c2a","line":2241,"range":{"start_line":2241,"start_character":46,"end_line":2241,"end_character":70},"in_reply_to":"6b06c80c_2d5892c8","updated":"2026-07-21 12:57:50.000000000","message":"Acknowledged","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"13f88f9d2925936a3b61aa36e117f25935c0f900","unresolved":true,"context_lines":[{"line_number":2311,"context_line":"        return [ot.HW_CPU_X86_AMD_SEV_SNP]"},{"line_number":2312,"context_line":""},{"line_number":2313,"context_line":"    def _get_mem_encryption_slots_intel_tdx(self) -\u003e int:"},{"line_number":2314,"context_line":"        if self.supports_intel_tdx and self.max_intel_tdx_guests is not None:"},{"line_number":2315,"context_line":"            return self.max_intel_tdx_guests"},{"line_number":2316,"context_line":"        else:"},{"line_number":2317,"context_line":"            return 0"},{"line_number":2318,"context_line":""},{"line_number":2319,"context_line":"    def _get_mem_encryption_traits_intel_tdx(self) -\u003e list[str]:"},{"line_number":2320,"context_line":"        return [ot.HW_CPU_X86_INTEL_TDX]"}],"source_content_type":"text/x-python","patch_set":3,"id":"fa887d72_d78fd110","line":2317,"range":{"start_line":2314,"start_character":0,"end_line":2317,"end_character":20},"updated":"2026-07-22 08:53:05.000000000","message":"I think this is as simple as\n```\nreturn self.max_intel_tdx_guests\n```\nas the None value is already handled there. As well as the case when the feature is not available","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"a41191f94a198c68b6cf97551187fbd1ca45c387","unresolved":false,"context_lines":[{"line_number":2311,"context_line":"        return [ot.HW_CPU_X86_AMD_SEV_SNP]"},{"line_number":2312,"context_line":""},{"line_number":2313,"context_line":"    def _get_mem_encryption_slots_intel_tdx(self) -\u003e int:"},{"line_number":2314,"context_line":"        if self.supports_intel_tdx and self.max_intel_tdx_guests is not None:"},{"line_number":2315,"context_line":"            return self.max_intel_tdx_guests"},{"line_number":2316,"context_line":"        else:"},{"line_number":2317,"context_line":"            return 0"},{"line_number":2318,"context_line":""},{"line_number":2319,"context_line":"    def _get_mem_encryption_traits_intel_tdx(self) -\u003e list[str]:"},{"line_number":2320,"context_line":"        return [ot.HW_CPU_X86_INTEL_TDX]"}],"source_content_type":"text/x-python","patch_set":3,"id":"ee217f95_3d41d985","line":2317,"range":{"start_line":2314,"start_character":0,"end_line":2317,"end_character":20},"in_reply_to":"fa887d72_d78fd110","updated":"2026-07-23 12:53:14.000000000","message":"yup that works!","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"68997c8c750bd59f10578044e7e407cc85c92310","unresolved":true,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"0794d2fc_7ceac00b","line":84,"updated":"2026-08-10 10:07:54.000000000","message":"Glad this is quite unrelated to TDX and rather a quite large kernel API, but I\u0027m still afraid of the potential differences it could have during kernel upgrades.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"4245b54fb73e29285817131e36c5859a55ca9fca","unresolved":true,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"b7ffa5ed_7b49ad8f","line":84,"in_reply_to":"0794d2fc_7ceac00b","updated":"2026-08-10 12:04:26.000000000","message":"It seems libvirt does not provide more data at the moment in the domcapabilities. I asked @anton.iacobaeus@canarybit.eu already to ping the libvirt folks to eventually get one","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"307ec143e13b4fbb9381b2e953e51fa243b8ff20","unresolved":true,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"aabc64b5_05f75e48","line":84,"in_reply_to":"2557a00a_2a84b258","updated":"2026-08-21 01:36:52.000000000","message":"++ on config approach.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"c194d9f50110de9910600cb276e80b975a9d8f78","unresolved":true,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"67efba50_f6270dc1","line":84,"in_reply_to":"5ce154e6_c77789af","updated":"2026-08-18 20:31:48.000000000","message":"thats problematic.\n\nwe cant generally assume that nova view of cgroups matches libvirts/qemus\n\nso this can break if nova-compute is runing in a contianer.\nredhats new installer\n\nhttps://github.com/openstack-k8s-operators/edpm-ansible/blob/main/roles/edpm_nova/templates/quadlet/nova_compute.container.j2\nand kolla-ansibel for exmapel will not work\n\nhttps://github.com/openstack/kolla-ansible/blob/master/ansible/roles/nova-cell/handlers/main.yml#L144-L159\nhttps://github.com/openstack/kolla-ansible/blob/master/ansible/roles/service-check-containers/tasks/main.yml#L2-L29\n\nthis will return the cgroup view form ninside the contianer whic is not the saem as where libvirt is running.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"bc09fe14bc35b79a6e380eebd3425c83a032af48","unresolved":true,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"e6167346_d8402a94","line":84,"in_reply_to":"67efba50_f6270dc1","updated":"2026-08-19 08:20:59.000000000","message":"That indeed seems like a problem, I was not aware of this type of deployment for Nova. Unfortunately I don\u0027t have an environment to test this easily.\n\nThis use case strengthens the case to have libvirt report this as part of the capabilities, and I will report it to upstream.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":false,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"045427a9_d3d7b12d","line":84,"in_reply_to":"aabc64b5_05f75e48","updated":"2026-08-21 18:21:30.000000000","message":"Done","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"77f625d85f030559e84f28a73ddd31aefdaab05e","unresolved":true,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"5ce154e6_c77789af","line":84,"in_reply_to":"b7ffa5ed_7b49ad8f","updated":"2026-08-10 12:55:12.000000000","message":"sure, just keeping it as a tracker","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"e631e58c4b4eb9e2e98279ece15d170a5795a640","unresolved":true,"context_lines":[{"line_number":81,"context_line":""},{"line_number":82,"context_line":"MIN_QEMU_SEV_ES_VERSION \u003d (8, 0, 0)"},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"MISC_CONTROL_GROUP_CAPACITY_FILE \u003d \u0027/sys/fs/cgroup/misc.capacity\u0027"},{"line_number":85,"context_line":""},{"line_number":86,"context_line":""},{"line_number":87,"context_line":"class LibvirtEventHandler:"}],"source_content_type":"text/x-python","patch_set":5,"id":"2557a00a_2a84b258","line":84,"in_reply_to":"e6167346_d8402a94","updated":"2026-08-19 08:38:33.000000000","message":"good catch Sean!\n\nwe can fall back now to have a config option in nova defining / overriding the capacity. That way out of the box in a non containerized env the current code will work and in a containerized env we can define a config value to override. \n\nThen when libvirt starts reporting the value in domcaps then we can deprecate the config.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"68997c8c750bd59f10578044e7e407cc85c92310","unresolved":false,"context_lines":[{"line_number":2161,"context_line":"        return self._supports_amd_sev_snp"},{"line_number":2162,"context_line":""},{"line_number":2163,"context_line":"    @property"},{"line_number":2164,"context_line":"    def supports_intel_tdx(self) -\u003e bool:"},{"line_number":2165,"context_line":"        \"\"\"Determine if the host supports Intel TDX for guests."},{"line_number":2166,"context_line":""},{"line_number":2167,"context_line":"        Returns a boolean indicating whether Intel Trust Domain Extensions"}],"source_content_type":"text/x-python","patch_set":5,"id":"c6f65083_2b106d3f","line":2164,"updated":"2026-08-10 10:07:54.000000000","message":"fwiw, it reuses the same pattern than SNP, so cool with me.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"e5e261fea73c164b20bd6d67d85bf92ff9d0f13c","unresolved":true,"context_lines":[{"line_number":2197,"context_line":"            return self._supports_intel_tdx"},{"line_number":2198,"context_line":""},{"line_number":2199,"context_line":"        domain_caps \u003d self.get_domain_capabilities()"},{"line_number":2200,"context_line":"        for arch in domain_caps:"},{"line_number":2201,"context_line":"            for machine_type in domain_caps[arch]:"},{"line_number":2202,"context_line":"                LOG.debug("},{"line_number":2203,"context_line":"                    \"Checking TDX support for arch %s and machine type %s\","}],"source_content_type":"text/x-python","patch_set":5,"id":"6d8fdb7d_bfee9bce","line":2200,"range":{"start_line":2200,"start_character":8,"end_line":2200,"end_character":32},"updated":"2026-08-10 16:10:58.000000000","message":"just fyi\n\nI\u0027ve proposed the change to make snp detection logic check only x86_64 arch because the other architectures do not make sense at all. we could probably update this later.\n\nhttps://review.opendev.org/c/openstack/nova/+/998285","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"dd7261ffc9c0b38312137aa6cb67efaa6837240d","unresolved":true,"context_lines":[{"line_number":2197,"context_line":"            return self._supports_intel_tdx"},{"line_number":2198,"context_line":""},{"line_number":2199,"context_line":"        domain_caps \u003d self.get_domain_capabilities()"},{"line_number":2200,"context_line":"        for arch in domain_caps:"},{"line_number":2201,"context_line":"            for machine_type in domain_caps[arch]:"},{"line_number":2202,"context_line":"                LOG.debug("},{"line_number":2203,"context_line":"                    \"Checking TDX support for arch %s and machine type %s\","}],"source_content_type":"text/x-python","patch_set":5,"id":"7dd4fa2a_94b22d76","line":2200,"range":{"start_line":2200,"start_character":8,"end_line":2200,"end_character":32},"in_reply_to":"6d8fdb7d_bfee9bce","updated":"2026-08-10 16:13:56.000000000","message":"Yup that makes sense!","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"5a3a47edc528edfe2bf3a93ee9c465232f2143dc","unresolved":true,"context_lines":[{"line_number":2197,"context_line":"            return self._supports_intel_tdx"},{"line_number":2198,"context_line":""},{"line_number":2199,"context_line":"        domain_caps \u003d self.get_domain_capabilities()"},{"line_number":2200,"context_line":"        for arch in domain_caps:"},{"line_number":2201,"context_line":"            for machine_type in domain_caps[arch]:"},{"line_number":2202,"context_line":"                LOG.debug("},{"line_number":2203,"context_line":"                    \"Checking TDX support for arch %s and machine type %s\","}],"source_content_type":"text/x-python","patch_set":5,"id":"f7513276_46978d09","line":2200,"range":{"start_line":2200,"start_character":8,"end_line":2200,"end_character":32},"in_reply_to":"7dd4fa2a_94b22d76","updated":"2026-08-13 13:14:36.000000000","message":"addressed by https://review.opendev.org/c/openstack/nova/+/1000805/1","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":false,"context_lines":[{"line_number":2197,"context_line":"            return self._supports_intel_tdx"},{"line_number":2198,"context_line":""},{"line_number":2199,"context_line":"        domain_caps \u003d self.get_domain_capabilities()"},{"line_number":2200,"context_line":"        for arch in domain_caps:"},{"line_number":2201,"context_line":"            for machine_type in domain_caps[arch]:"},{"line_number":2202,"context_line":"                LOG.debug("},{"line_number":2203,"context_line":"                    \"Checking TDX support for arch %s and machine type %s\","}],"source_content_type":"text/x-python","patch_set":5,"id":"dbf24daf_1751b5c6","line":2200,"range":{"start_line":2200,"start_character":8,"end_line":2200,"end_character":32},"in_reply_to":"f7513276_46978d09","updated":"2026-08-21 18:21:30.000000000","message":"Acknowledged","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"c194d9f50110de9910600cb276e80b975a9d8f78","unresolved":true,"context_lines":[{"line_number":2216,"context_line":"        LOG.debug(\"No Intel TDX support detected for any (arch, machine_type)\")"},{"line_number":2217,"context_line":"        return self._supports_intel_tdx"},{"line_number":2218,"context_line":""},{"line_number":2219,"context_line":"    def _get_tdx_capacity(self) -\u003e int:"},{"line_number":2220,"context_line":"        \"\"\"Read kernel misc control group for maximum Intel TDX guests."},{"line_number":2221,"context_line":""},{"line_number":2222,"context_line":"        The misc control group is a generic interface for any resource that may"}],"source_content_type":"text/x-python","patch_set":5,"id":"cf4ce56c_c6f57006","line":2219,"range":{"start_line":2219,"start_character":4,"end_line":2219,"end_character":39},"updated":"2026-08-18 20:31:48.000000000","message":"so this wont work\n\nas we did for sev before libvirt gained a way to report the capascity via the domain cap api we need a nova config option for the capacity.\n\nwe rejected a similar apporch to this for the inital sev enablment because reading the cgroups api does not work properly in contaienrs.\n\nso -1 until this is updated to add a config options like \n\nhttps://docs.openstack.org/nova/2023.1/configuration/config.html#libvirt.num_memory_encrypted_guests\n\n\nnote that was called num_memory_encrypted_guests because it wqas intend to be used with Intel MKTME  before TDX was created as a common config option for both\n\nwe may want to call this libvirt.num_tdx not that we ahve remvoed num_memory_encrypted_guests or reintoduce it but use it exclsively for TDX now.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":false,"context_lines":[{"line_number":2216,"context_line":"        LOG.debug(\"No Intel TDX support detected for any (arch, machine_type)\")"},{"line_number":2217,"context_line":"        return self._supports_intel_tdx"},{"line_number":2218,"context_line":""},{"line_number":2219,"context_line":"    def _get_tdx_capacity(self) -\u003e int:"},{"line_number":2220,"context_line":"        \"\"\"Read kernel misc control group for maximum Intel TDX guests."},{"line_number":2221,"context_line":""},{"line_number":2222,"context_line":"        The misc control group is a generic interface for any resource that may"}],"source_content_type":"text/x-python","patch_set":5,"id":"8a0556f8_6042be5d","line":2219,"range":{"start_line":2219,"start_character":4,"end_line":2219,"end_character":39},"in_reply_to":"36068470_03142aaf","updated":"2026-08-21 18:21:30.000000000","message":"Done","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"e631e58c4b4eb9e2e98279ece15d170a5795a640","unresolved":true,"context_lines":[{"line_number":2216,"context_line":"        LOG.debug(\"No Intel TDX support detected for any (arch, machine_type)\")"},{"line_number":2217,"context_line":"        return self._supports_intel_tdx"},{"line_number":2218,"context_line":""},{"line_number":2219,"context_line":"    def _get_tdx_capacity(self) -\u003e int:"},{"line_number":2220,"context_line":"        \"\"\"Read kernel misc control group for maximum Intel TDX guests."},{"line_number":2221,"context_line":""},{"line_number":2222,"context_line":"        The misc control group is a generic interface for any resource that may"}],"source_content_type":"text/x-python","patch_set":5,"id":"827649c5_7a81a953","line":2219,"range":{"start_line":2219,"start_character":4,"end_line":2219,"end_character":39},"in_reply_to":"655711ff_f58dbf96","updated":"2026-08-19 08:38:33.000000000","message":"I agree","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"34120baec93a35607f5cb8afa12b7f57ec3e06d6","unresolved":true,"context_lines":[{"line_number":2216,"context_line":"        LOG.debug(\"No Intel TDX support detected for any (arch, machine_type)\")"},{"line_number":2217,"context_line":"        return self._supports_intel_tdx"},{"line_number":2218,"context_line":""},{"line_number":2219,"context_line":"    def _get_tdx_capacity(self) -\u003e int:"},{"line_number":2220,"context_line":"        \"\"\"Read kernel misc control group for maximum Intel TDX guests."},{"line_number":2221,"context_line":""},{"line_number":2222,"context_line":"        The misc control group is a generic interface for any resource that may"}],"source_content_type":"text/x-python","patch_set":5,"id":"36068470_03142aaf","line":2219,"range":{"start_line":2219,"start_character":4,"end_line":2219,"end_character":39},"in_reply_to":"827649c5_7a81a953","updated":"2026-08-21 13:46:13.000000000","message":"Config option has now been added","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"bc09fe14bc35b79a6e380eebd3425c83a032af48","unresolved":true,"context_lines":[{"line_number":2216,"context_line":"        LOG.debug(\"No Intel TDX support detected for any (arch, machine_type)\")"},{"line_number":2217,"context_line":"        return self._supports_intel_tdx"},{"line_number":2218,"context_line":""},{"line_number":2219,"context_line":"    def _get_tdx_capacity(self) -\u003e int:"},{"line_number":2220,"context_line":"        \"\"\"Read kernel misc control group for maximum Intel TDX guests."},{"line_number":2221,"context_line":""},{"line_number":2222,"context_line":"        The misc control group is a generic interface for any resource that may"}],"source_content_type":"text/x-python","patch_set":5,"id":"655711ff_f58dbf96","line":2219,"range":{"start_line":2219,"start_character":4,"end_line":2219,"end_character":39},"in_reply_to":"cf4ce56c_c6f57006","updated":"2026-08-19 08:20:59.000000000","message":"Yes that makes sense, I can add a variable which would effectively be an override for the current behavior (cgroup resource) and a hard requirement in case that fails.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"68997c8c750bd59f10578044e7e407cc85c92310","unresolved":true,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"bbc59bf2_2c94943e","line":2231,"updated":"2026-08-10 10:07:54.000000000","message":"really, do we just say \"meh, we no longer have TDX capacity\" if a kernel upgrade arrives with a behavioural change for TDX ?\nI can understand why we log it this way for non-TDX resources but I\u0027m afraid our operators could miss a behavioural change during a kernel upgrade.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"77f625d85f030559e84f28a73ddd31aefdaab05e","unresolved":true,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"5d09ce9d_dbb7097f","line":2231,"in_reply_to":"0510b5ba_8144eafe","updated":"2026-08-10 12:55:12.000000000","message":"can then we add this for TDX too  ?","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":38744,"name":"Anton Iacobaeus","display_name":"antia","email":"anton.iacobaeus@canarybit.eu","username":"antia","status":"Canary Bit"},"change_message_id":"5a0eaca406f3fb1d8b357ce1d861746c51370fb8","unresolved":true,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"c2853e3e_a3302bee","line":2231,"in_reply_to":"1dea3e9d_ddf50b20","updated":"2026-08-21 07:29:49.000000000","message":"This was added in a later patch:\nhttps://review.opendev.org/c/openstack/nova/+/999249/3/nova/virt/libvirt/driver.py","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"ba1627addc936bcf6b5d5089e4a6d5372bd8f30f","unresolved":true,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"ddfec175_f53baf18","line":2231,"in_reply_to":"5d09ce9d_dbb7097f","updated":"2026-08-10 13:31:27.000000000","message":"It is working for TDX out of the box as it is generic for an mem encryption config.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"a1436bb02c3590cb450fd0c9a080737482574aeb","unresolved":false,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"e78b070e_22265764","line":2231,"in_reply_to":"badd1fb9_32eeacf0","updated":"2026-08-21 19:26:40.000000000","message":"yeah, ditto but ok with it to be added later.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"4245b54fb73e29285817131e36c5859a55ca9fca","unresolved":true,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"0510b5ba_8144eafe","line":2231,"in_reply_to":"bbc59bf2_2c94943e","updated":"2026-08-10 12:04:26.000000000","message":"I think we have some generic code that stops the nova-compute startup if we have a VM with some CC feature but don\u0027t have that CC support any more.\n//later\nyes it is added by @kajinamit@oss.nttdata.com in https://review.opendev.org/c/openstack/nova/+/994342/14/nova/virt/libvirt/driver.py","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":true,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"badd1fb9_32eeacf0","line":2231,"in_reply_to":"c2853e3e_a3302bee","updated":"2026-08-21 18:21:30.000000000","message":"it would have been preferable to have that in this patch but i can accept ti later\n\nthis is a correctness issue rather then an optimsiation like the architecture check","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"307ec143e13b4fbb9381b2e953e51fa243b8ff20","unresolved":true,"context_lines":[{"line_number":2228,"context_line":""},{"line_number":2229,"context_line":"        if not os.path.exists(capacity_file):"},{"line_number":2230,"context_line":"            LOG.debug(\"%s does not exist\", capacity_file)"},{"line_number":2231,"context_line":"            return 0"},{"line_number":2232,"context_line":""},{"line_number":2233,"context_line":"        with open(capacity_file) as f:"},{"line_number":2234,"context_line":"            content \u003d f.read()"}],"source_content_type":"text/x-python","patch_set":5,"id":"1dea3e9d_ddf50b20","line":2231,"in_reply_to":"ddfec175_f53baf18","updated":"2026-08-21 01:36:52.000000000","message":"not sure how that works for TDX because it does not only check mem encryption but the encryption model also. If instance has TDX model then _is_supported_mem_encryption_model will raise Invalid exception and block compute to start. I think this can be easily reproduced in functional test?\n\n- https://github.com/openstack/nova/blob/master/nova/virt/libvirt/driver.py#L13588\n\nwe need to add the check for TDX model in _is_supported_mem_encryption_model and then check host if it has support or not.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"68997c8c750bd59f10578044e7e407cc85c92310","unresolved":true,"context_lines":[{"line_number":2237,"context_line":"                parts \u003d line.split()"},{"line_number":2238,"context_line":"                if len(parts) \u003d\u003d 2 and parts[0] \u003d\u003d \u0027tdx\u0027:"},{"line_number":2239,"context_line":"                    try:"},{"line_number":2240,"context_line":"                        return int(parts[1])"},{"line_number":2241,"context_line":"                    except ValueError:"},{"line_number":2242,"context_line":"                        LOG.warning("},{"line_number":2243,"context_line":"                            \"Failed to parse TDX capacity from %s: \""}],"source_content_type":"text/x-python","patch_set":5,"id":"cff929a4_d538d339","line":2240,"updated":"2026-08-10 10:07:54.000000000","message":"this sounds horribly hacky but I assume there is no other way but to sparse that file ? What a terrible and fragile API.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"abfe7e03dd3d20ffd617f3b74f755ecca29f13a8","unresolved":false,"context_lines":[{"line_number":2237,"context_line":"                parts \u003d line.split()"},{"line_number":2238,"context_line":"                if len(parts) \u003d\u003d 2 and parts[0] \u003d\u003d \u0027tdx\u0027:"},{"line_number":2239,"context_line":"                    try:"},{"line_number":2240,"context_line":"                        return int(parts[1])"},{"line_number":2241,"context_line":"                    except ValueError:"},{"line_number":2242,"context_line":"                        LOG.warning("},{"line_number":2243,"context_line":"                            \"Failed to parse TDX capacity from %s: \""}],"source_content_type":"text/x-python","patch_set":5,"id":"59cb71e6_7def5def","line":2240,"in_reply_to":"2ffdf0c6_276517a6","updated":"2026-08-24 12:47:47.000000000","message":"Acknowledged","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"581f7be7a5afdce87622cfc93768bf19a199315a","unresolved":true,"context_lines":[{"line_number":2237,"context_line":"                parts \u003d line.split()"},{"line_number":2238,"context_line":"                if len(parts) \u003d\u003d 2 and parts[0] \u003d\u003d \u0027tdx\u0027:"},{"line_number":2239,"context_line":"                    try:"},{"line_number":2240,"context_line":"                        return int(parts[1])"},{"line_number":2241,"context_line":"                    except ValueError:"},{"line_number":2242,"context_line":"                        LOG.warning("},{"line_number":2243,"context_line":"                            \"Failed to parse TDX capacity from %s: \""}],"source_content_type":"text/x-python","patch_set":5,"id":"2ffdf0c6_276517a6","line":2240,"in_reply_to":"b5c7af5f_09bd346c","updated":"2026-08-21 18:21:30.000000000","message":"the only slight diffents is that libvirt does have some compatiblity contract in general for there intefaces but i dont that is really as ture for this cgroups interface.\n\ni would prsonally prefer to remove the cgroups part entrile and only use the config option until libivirt provdies and interface for this but i wont block on that point.\n\nthat is what we did for sev however so it woudl be more consitnet to do that for TDX supprot","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"19a1a05c52192abc849b41480ff5e459d8ccbe45","unresolved":true,"context_lines":[{"line_number":2237,"context_line":"                parts \u003d line.split()"},{"line_number":2238,"context_line":"                if len(parts) \u003d\u003d 2 and parts[0] \u003d\u003d \u0027tdx\u0027:"},{"line_number":2239,"context_line":"                    try:"},{"line_number":2240,"context_line":"                        return int(parts[1])"},{"line_number":2241,"context_line":"                    except ValueError:"},{"line_number":2242,"context_line":"                        LOG.warning("},{"line_number":2243,"context_line":"                            \"Failed to parse TDX capacity from %s: \""}],"source_content_type":"text/x-python","patch_set":5,"id":"b5c7af5f_09bd346c","line":2240,"in_reply_to":"ba3eb9ea_54a8ecb8","updated":"2026-08-10 13:32:37.000000000","message":"The same way if the libvirt xml structure changes :)\nWe all depend on the providers to keep the interface stable regardless if this is a kernel interface here or a libvirt interface in case of SNP","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"4245b54fb73e29285817131e36c5859a55ca9fca","unresolved":true,"context_lines":[{"line_number":2237,"context_line":"                parts \u003d line.split()"},{"line_number":2238,"context_line":"                if len(parts) \u003d\u003d 2 and parts[0] \u003d\u003d \u0027tdx\u0027:"},{"line_number":2239,"context_line":"                    try:"},{"line_number":2240,"context_line":"                        return int(parts[1])"},{"line_number":2241,"context_line":"                    except ValueError:"},{"line_number":2242,"context_line":"                        LOG.warning("},{"line_number":2243,"context_line":"                            \"Failed to parse TDX capacity from %s: \""}],"source_content_type":"text/x-python","patch_set":5,"id":"f46a38d6_a7b568b2","line":2240,"in_reply_to":"cff929a4_d538d339","updated":"2026-08-10 12:04:26.000000000","message":"I don\u0027t think this is too hackish of a parser or a file that has either emptylines or a key value pair per line. Either is has tdx in it with the number of lost the host supports or it does not have it in the file.\n\n(as I wote above libvirt does not provide us the data and I asked Antia to ask them for a future improvement)\n\nThis is how it looks like on my machine I used to test this.\n```\n[root@beast01 ~]# cat /sys/fs/cgroup/misc.capacity\ntdx 47\n```","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":7166,"name":"Sylvain Bauza","email":"sbauza@redhat.com","username":"sbauza"},"change_message_id":"77f625d85f030559e84f28a73ddd31aefdaab05e","unresolved":true,"context_lines":[{"line_number":2237,"context_line":"                parts \u003d line.split()"},{"line_number":2238,"context_line":"                if len(parts) \u003d\u003d 2 and parts[0] \u003d\u003d \u0027tdx\u0027:"},{"line_number":2239,"context_line":"                    try:"},{"line_number":2240,"context_line":"                        return int(parts[1])"},{"line_number":2241,"context_line":"                    except ValueError:"},{"line_number":2242,"context_line":"                        LOG.warning("},{"line_number":2243,"context_line":"                            \"Failed to parse TDX capacity from %s: \""}],"source_content_type":"text/x-python","patch_set":5,"id":"ba3eb9ea_54a8ecb8","line":2240,"in_reply_to":"f46a38d6_a7b568b2","updated":"2026-08-10 12:55:12.000000000","message":"for sure, this is just something like key/value but in case it changes, we could have a regression, that\u0027s it","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"},{"author":{"_account_id":8556,"name":"Ghanshyam Maan","display_name":"Ghanshyam Maan","email":"gmaan.os14@gmail.com","username":"ghanshyam"},"change_message_id":"307ec143e13b4fbb9381b2e953e51fa243b8ff20","unresolved":false,"context_lines":[{"line_number":2252,"context_line":"        \"\"\""},{"line_number":2253,"context_line":"        if not self.supports_intel_tdx:"},{"line_number":2254,"context_line":"            return 0"},{"line_number":2255,"context_line":"        if self._max_intel_tdx_guests is None:"},{"line_number":2256,"context_line":"            self._max_intel_tdx_guests \u003d self._get_tdx_capacity()"},{"line_number":2257,"context_line":"        return self._max_intel_tdx_guests"},{"line_number":2258,"context_line":""}],"source_content_type":"text/x-python","patch_set":5,"id":"83dce6e9_3d4793f9","line":2255,"range":{"start_line":2255,"start_character":0,"end_line":2255,"end_character":46},"updated":"2026-08-21 01:36:52.000000000","message":"++. From the kernel documentation, I learnt that tdx capacity is not a static value instead it is dynamically calculated based on a few factors (shared hw resource pool/keys) so calculating it here once can be stale but thats not the case. It is calculated at bios partiyioning time and if anyone change it then we have to resart the host and compute service so it will be recalculated as per new setting.","commit_id":"8dfb7d5943563a998f91d1a4a9a15f391bd72a93"}],"requirements.txt":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"076e4ec79a0a1c1328d8abed4f2e1388c78cd597","unresolved":false,"context_lines":[{"line_number":50,"context_line":"oslo.versionedobjects\u003e\u003d1.35.0 # Apache-2.0"},{"line_number":51,"context_line":"os-brick\u003e\u003d6.10.0 # Apache-2.0"},{"line_number":52,"context_line":"os-resource-classes\u003e\u003d1.1.0 # Apache-2.0"},{"line_number":53,"context_line":"os-traits\u003e\u003d3.8.0 # Apache-2.0"},{"line_number":54,"context_line":"os-vif\u003e\u003d3.1.0 # Apache-2.0"},{"line_number":55,"context_line":"castellan\u003e\u003d0.16.0 # Apache-2.0"},{"line_number":56,"context_line":"microversion-parse\u003e\u003d0.2.1 # Apache-2.0"}],"source_content_type":"text/plain","patch_set":2,"id":"6be7d1bd_88959a96","line":53,"updated":"2026-06-24 16:23:59.000000000","message":"yepp this is needed to have the TDX trait","commit_id":"025ee8a335a952101a7f350edd1683bac711341d"},{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"13f88f9d2925936a3b61aa36e117f25935c0f900","unresolved":false,"context_lines":[{"line_number":50,"context_line":"oslo.versionedobjects\u003e\u003d1.35.0 # Apache-2.0"},{"line_number":51,"context_line":"os-brick\u003e\u003d6.10.0 # Apache-2.0"},{"line_number":52,"context_line":"os-resource-classes\u003e\u003d1.1.0 # Apache-2.0"},{"line_number":53,"context_line":"os-traits\u003e\u003d3.8.0 # Apache-2.0"},{"line_number":54,"context_line":"os-vif\u003e\u003d3.1.0 # Apache-2.0"},{"line_number":55,"context_line":"castellan\u003e\u003d0.16.0 # Apache-2.0"},{"line_number":56,"context_line":"microversion-parse\u003e\u003d0.2.1 # Apache-2.0"}],"source_content_type":"text/plain","patch_set":3,"id":"cc25577b_e80691f9","line":53,"updated":"2026-07-22 08:53:05.000000000","message":"yepp that adds the TDX trait.","commit_id":"7ed58c05098e80366d860788d65589d268e36d05"}]}
