)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"71a93b076a54a61d358a0e38b770ea12b905f9c2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":8,"id":"30508f71_6625c317","updated":"2026-07-06 09:41:46.000000000","message":"lets fix the doc nit","commit_id":"dee22681339d6ddb92dc3484d584379f95745ae9"},{"author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"change_message_id":"9c3ca85d763564f86837fc5b3943503ab6dfa9f9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":15,"id":"e9c49165_4ca4fbd9","updated":"2026-07-08 11:09:09.000000000","message":"As discussed in the patchset for launching instances, I would like to see a bit more verbose documentation on the whole firmware descriptor JSON topic. See my code comment.","commit_id":"e91eaf38319f3feb5c0af58e11fcf6132c35ea5b"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"e0e9c100f612e41cd86acaef34fd826b163381a1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":17,"id":"d612beab_3256f833","updated":"2026-07-08 14:39:42.000000000","message":"recheck https://review.opendev.org/c/opendev/zuul-providers/+/996449","commit_id":"c855fa38950860d35d95eb58440cdaa977e6000b"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"7451cb56345b90fb82b0b8b7674e1b7686678d25","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":19,"id":"035c178c_6b875d4c","updated":"2026-07-17 22:30:33.000000000","message":"recheck","commit_id":"df4c464426a3b32073779c77c0d62633117993db"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"6a8a70dc89067c81f89bab70ffff0d8ac6f05b08","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":19,"id":"bf076eff_ce3e37b8","updated":"2026-07-17 16:46:19.000000000","message":"recheck","commit_id":"df4c464426a3b32073779c77c0d62633117993db"}],"doc/source/admin/sev.rst":[{"author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"change_message_id":"71a93b076a54a61d358a0e38b770ea12b905f9c2","unresolved":true,"context_lines":[{"line_number":248,"context_line":"- The operating system running in an encrypted virtual machine must"},{"line_number":249,"context_line":"  contain SEV support."},{"line_number":250,"context_line":""},{"line_number":251,"context_line":"- SEV-ES and SEV-SNP are explusive in a single host, due to firmware update"},{"line_number":252,"context_line":"  to resolve"},{"line_number":253,"context_line":"  `CVE-2025-48514 \u003chttps://nvd.nist.gov/vuln/detail/CVE-2025-48514\u003e`_ ."},{"line_number":254,"context_line":""}],"source_content_type":"text/x-rst","patch_set":8,"id":"79b5f919_9842f0fe","line":251,"range":{"start_line":251,"start_character":25,"end_line":251,"end_character":34},"updated":"2026-07-06 09:41:46.000000000","message":"nit: mutually-exclusive","commit_id":"dee22681339d6ddb92dc3484d584379f95745ae9"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"d06d8d18452a2fb9bb4157f6ba814e6daff0b6e7","unresolved":false,"context_lines":[{"line_number":248,"context_line":"- The operating system running in an encrypted virtual machine must"},{"line_number":249,"context_line":"  contain SEV support."},{"line_number":250,"context_line":""},{"line_number":251,"context_line":"- SEV-ES and SEV-SNP are explusive in a single host, due to firmware update"},{"line_number":252,"context_line":"  to resolve"},{"line_number":253,"context_line":"  `CVE-2025-48514 \u003chttps://nvd.nist.gov/vuln/detail/CVE-2025-48514\u003e`_ ."},{"line_number":254,"context_line":""}],"source_content_type":"text/x-rst","patch_set":8,"id":"415c2ea5_b3846728","line":251,"range":{"start_line":251,"start_character":25,"end_line":251,"end_character":34},"in_reply_to":"79b5f919_9842f0fe","updated":"2026-07-06 09:46:41.000000000","message":"Done","commit_id":"dee22681339d6ddb92dc3484d584379f95745ae9"},{"author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"change_message_id":"9c3ca85d763564f86837fc5b3943503ab6dfa9f9","unresolved":true,"context_lines":[{"line_number":163,"context_line":""},{"line_number":164,"context_line":"  .. note::"},{"line_number":165,"context_line":""},{"line_number":166,"context_line":"     It is also required that the appropriate QEMU firmware descriptor file is"},{"line_number":167,"context_line":"     present in the host operating system. These files are provided by"},{"line_number":168,"context_line":"     the qemu package from distributions in most cases, but it is known that"},{"line_number":169,"context_line":"     Ubuntu 26.04 does not yet provide the content required to launch SEV-SNP"}],"source_content_type":"text/x-rst","patch_set":15,"id":"74bd5819_2136da4a","line":166,"updated":"2026-07-08 11:09:09.000000000","message":"Given that official documentation is quite sparse on the whole QEMU firmware JSON topic and Ubuntu LTS releases are affected, I feel that this note does not properly explain the details.\n\nHere is a suggestion on how I would change this part:\n\n```\n- Ensure suitable QEMU firmware JSON files are present on the compute hosts.\n  Those are usually shipped by distribution packages at\n  ``/usr/share/qemu/firmware/``. They must contain the proper feature flag,\n  e.g., ``amd-sev-snp``, and specify a compatible firmware file.\n  Note that the lexicographical filename order of the JSON files matters\n  and the first matching JSON is selected for an instance.\n\n  .. note::\n      \n     For AMD SEV-SNP the firmware descriptor file should specify\n     ``mapping.device`` as ``memory``. Otherwise instances might\n     not launch properly and end up failing to start with an\n     ``pflash with kvm requires KVM readonly memory support``\n     error.\n     It is known that several Ubuntu releases (including 26.04)\n     provide faulty firmware descriptor files that trigger this\n     error.\n```","commit_id":"e91eaf38319f3feb5c0af58e11fcf6132c35ea5b"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"24af0e5c92c20e1587e85a0e736f113f219010eb","unresolved":true,"context_lines":[{"line_number":163,"context_line":""},{"line_number":164,"context_line":"  .. note::"},{"line_number":165,"context_line":""},{"line_number":166,"context_line":"     It is also required that the appropriate QEMU firmware descriptor file is"},{"line_number":167,"context_line":"     present in the host operating system. These files are provided by"},{"line_number":168,"context_line":"     the qemu package from distributions in most cases, but it is known that"},{"line_number":169,"context_line":"     Ubuntu 26.04 does not yet provide the content required to launch SEV-SNP"}],"source_content_type":"text/x-rst","patch_set":15,"id":"de6e908d_5703e60b","line":166,"in_reply_to":"64a7f8d0_82a8c0d6","updated":"2026-07-08 11:50:18.000000000","message":"I\u0027ve reported a bug against ubuntu because the issue is not really specific to nova and is a general packaging problem there. I\u0027ve added the required information in the bug added a link to the bug so that users can easily find whether the issue is still present or is already fixed. wdyt ?\n\nhttps://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2160129","commit_id":"e91eaf38319f3feb5c0af58e11fcf6132c35ea5b"},{"author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"change_message_id":"6dd015bb503bc78ffbd04b8494b6545c4ae5cec1","unresolved":true,"context_lines":[{"line_number":163,"context_line":""},{"line_number":164,"context_line":"  .. note::"},{"line_number":165,"context_line":""},{"line_number":166,"context_line":"     It is also required that the appropriate QEMU firmware descriptor file is"},{"line_number":167,"context_line":"     present in the host operating system. These files are provided by"},{"line_number":168,"context_line":"     the qemu package from distributions in most cases, but it is known that"},{"line_number":169,"context_line":"     Ubuntu 26.04 does not yet provide the content required to launch SEV-SNP"}],"source_content_type":"text/x-rst","patch_set":15,"id":"64a7f8d0_82a8c0d6","line":166,"in_reply_to":"74bd5819_2136da4a","updated":"2026-07-08 11:11:57.000000000","message":"I added the error message \"pflash with kvm requires ...\" on purpose because once you run into this problem, this is likely the only clue you can get out of the system. And searching online for this error message does not really turn up any helpful results (been there myself).\nThat\u0027s why I think including the error message somewhere would tremendously help whoever will run into this next.","commit_id":"e91eaf38319f3feb5c0af58e11fcf6132c35ea5b"},{"author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"change_message_id":"36a687437cfc9d6c7aa604ccce42753fd9994813","unresolved":false,"context_lines":[{"line_number":163,"context_line":""},{"line_number":164,"context_line":"  .. note::"},{"line_number":165,"context_line":""},{"line_number":166,"context_line":"     It is also required that the appropriate QEMU firmware descriptor file is"},{"line_number":167,"context_line":"     present in the host operating system. These files are provided by"},{"line_number":168,"context_line":"     the qemu package from distributions in most cases, but it is known that"},{"line_number":169,"context_line":"     Ubuntu 26.04 does not yet provide the content required to launch SEV-SNP"}],"source_content_type":"text/x-rst","patch_set":15,"id":"081c338a_435ca8b6","line":166,"in_reply_to":"de6e908d_5703e60b","updated":"2026-07-13 08:08:15.000000000","message":"Thank you for filing the bug report at Ubuntu\u0027s side and including the link here!","commit_id":"e91eaf38319f3feb5c0af58e11fcf6132c35ea5b"},{"author":{"_account_id":27665,"name":"Markus Hentsch","email":"markus.hentsch@cloudandheat.com","username":"mhen"},"change_message_id":"36a687437cfc9d6c7aa604ccce42753fd9994813","unresolved":true,"context_lines":[{"line_number":198,"context_line":"machine type is set to ``q35``.  This can be set per image by setting"},{"line_number":199,"context_line":"the image property ``hw_machine_type\u003dq35``, or per compute node by"},{"line_number":200,"context_line":"the operator via :oslo.config:option:`libvirt.hw_machine_type` as"},{"line_number":201,"context_line":"explained above. SEV-SNP instances also requires stateless firmware, which is"},{"line_number":202,"context_line":"enabled by the ``hw_firmware_stateless`` property set to ``true``."},{"line_number":203,"context_line":""},{"line_number":204,"context_line":""}],"source_content_type":"text/x-rst","patch_set":17,"id":"85d054ef_a8b26d60","line":201,"updated":"2026-07-13 08:08:15.000000000","message":"nit:\n\n```suggestion\nexplained above. SEV-SNP instances also require stateless firmware, which is\n```","commit_id":"c855fa38950860d35d95eb58440cdaa977e6000b"},{"author":{"_account_id":9816,"name":"Takashi Kajinami","email":"kajinamit@oss.nttdata.com","username":"kajinamit"},"change_message_id":"b963cf25777553a2309304bf129542abe0d9b55b","unresolved":false,"context_lines":[{"line_number":198,"context_line":"machine type is set to ``q35``.  This can be set per image by setting"},{"line_number":199,"context_line":"the image property ``hw_machine_type\u003dq35``, or per compute node by"},{"line_number":200,"context_line":"the operator via :oslo.config:option:`libvirt.hw_machine_type` as"},{"line_number":201,"context_line":"explained above. SEV-SNP instances also requires stateless firmware, which is"},{"line_number":202,"context_line":"enabled by the ``hw_firmware_stateless`` property set to ``true``."},{"line_number":203,"context_line":""},{"line_number":204,"context_line":""}],"source_content_type":"text/x-rst","patch_set":17,"id":"5af50558_07519eeb","line":201,"in_reply_to":"85d054ef_a8b26d60","updated":"2026-07-13 08:39:01.000000000","message":"Fix applied.","commit_id":"c855fa38950860d35d95eb58440cdaa977e6000b"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"fde7ca4f143f87fe04cfdc6af6bdadade103121a","unresolved":true,"context_lines":[{"line_number":118,"context_line":"     which operators can impose, for example if the smallest RAM"},{"line_number":119,"context_line":"     footprint of any flavor imposes a maximum number of simultaneously"},{"line_number":120,"context_line":"     running guests which is less than or equal to the SEV limit."},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"- Configure :oslo.config:option:`ram_allocation_ratio` on all SEV-capable"},{"line_number":123,"context_line":"  compute hosts to ``1.0``. Use of SEV requires that guest memory is not"},{"line_number":124,"context_line":"  swapped out to disks, meaning it is not possible to overcommit host memory."},{"line_number":125,"context_line":""},{"line_number":126,"context_line":"  Alternatively, you can explicitly configure small pages for instances using"},{"line_number":127,"context_line":"  the :nova:extra-spec:`hw:mem_page_size` flavor extra spec and equivalent"}],"source_content_type":"text/x-rst","patch_set":19,"id":"3fc40b4d_cb1eef16","line":124,"range":{"start_line":121,"start_character":1,"end_line":124,"end_character":77},"updated":"2026-07-16 10:59:54.000000000","message":"this could be a nova startup check possibel as a warning for a cycle or two then a hard error if we are not already doing this","commit_id":"df4c464426a3b32073779c77c0d62633117993db"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"fde7ca4f143f87fe04cfdc6af6bdadade103121a","unresolved":true,"context_lines":[{"line_number":241,"context_line":"  the second generation (Rome)."},{"line_number":242,"context_line":""},{"line_number":243,"context_line":"  __ https://www.redhat.com/archives/libvir-list/2019-January/msg00652.html"},{"line_number":244,"context_line":""},{"line_number":245,"context_line":"- The number of SEV-ES guests and SEV-SNP guests allowed to run concurrently"},{"line_number":246,"context_line":"  will always be limited. The total ASID slots are divided into the two pools"},{"line_number":247,"context_line":"  (one for SEV and the other for SEV-ES and SEV-SNP), according to"},{"line_number":248,"context_line":"  the ``Minimum ASID for SEV`` option in BIOS."},{"line_number":249,"context_line":""},{"line_number":250,"context_line":"- The operating system running in an encrypted virtual machine must"},{"line_number":251,"context_line":"  contain SEV support."}],"source_content_type":"text/x-rst","patch_set":19,"id":"d290e66e_66d38085","line":248,"range":{"start_line":244,"start_character":1,"end_line":248,"end_character":46},"updated":"2026-07-16 10:59:54.000000000","message":"nit: so i would put this after the \"SEV-ES and SEV-SNP are mutually-exclusive\" bullet","commit_id":"df4c464426a3b32073779c77c0d62633117993db"}],"releasenotes/notes/bp-amd-sev-snp-libvirt-support-5f8c306c1ef919d1.yaml":[{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"fde7ca4f143f87fe04cfdc6af6bdadade103121a","unresolved":true,"context_lines":[{"line_number":1,"context_line":"---"},{"line_number":2,"context_line":"features:"},{"line_number":3,"context_line":"  - |"},{"line_number":4,"context_line":"    The libvirt driver can now support requests for guest RAM to be encrypted"},{"line_number":5,"context_line":"    using the AMD SEV-SNP(Secure Nested Paging), in addition to AMD SEV and"}],"source_content_type":"text/x-yaml","patch_set":19,"id":"1715aa52_fb8796e4","line":2,"updated":"2026-07-16 10:59:54.000000000","message":"this should have been in the previous commit","commit_id":"df4c464426a3b32073779c77c0d62633117993db"}]}
