)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"722bbeb12d134a4b8bfa407976647c2a9b5ec74a","unresolved":true,"context_lines":[{"line_number":35,"context_line":"This process shares the same libpod-xxx cgroup, but also uses other"},{"line_number":36,"context_line":"ones (this is expected libvirt behaviour):"},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"[heat-admin@compute-1 ~]$ cat /proc/402633/cgroup"},{"line_number":39,"context_line":"12:cpuset:/machine/qemu-1-instance-00000003.libvirt-qemu/emulator"},{"line_number":40,"context_line":"11:cpu,cpuacct:/machine/qemu-1-instance-00000003.libvirt-qemu/emulator"},{"line_number":41,"context_line":"10:rdma:/"},{"line_number":42,"context_line":"9:pids:/machine.slice/libpod-xxx.scope"},{"line_number":43,"context_line":"8:freezer:/machine/qemu-1-instance-00000003.libvirt-qemu"},{"line_number":44,"context_line":"7:memory:/machine/qemu-1-instance-00000003.libvirt-qemu"},{"line_number":45,"context_line":"6:devices:/machine/qemu-1-instance-00000003.libvirt-qemu"},{"line_number":46,"context_line":"5:perf_event:/machine/qemu-1-instance-00000003.libvirt-qemu"},{"line_number":47,"context_line":"4:blkio:/machine/qemu-1-instance-00000003.libvirt-qemu"},{"line_number":48,"context_line":"3:hugetlb:/machine.slice/libpod-xxx.scope"},{"line_number":49,"context_line":"2:net_cls,net_prio:/machine/qemu-1-instance-00000003.libvirt-qemu"},{"line_number":50,"context_line":"1:name\u003dsystemd:/machine.slice/libpod-xxx.scope"},{"line_number":51,"context_line":""},{"line_number":52,"context_line":"This cgroups placement shows libvirt using the direct cgroups apis and"},{"line_number":53,"context_line":"not sytstemd. This is sufficient to let this process run even after we"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"e8863e12_fea84ee8","line":50,"range":{"start_line":38,"start_character":0,"end_line":50,"end_character":46},"updated":"2021-10-19 09:41:45.000000000","message":"with this change, it looks now:\n\n[root@standalone zuul]# cat /proc/330365/cgroup \n12:blkio:/system.slice\n11:perf_event:/machine.slice/libpod-1d1c42a73d1aa0122aed29617b292969d12a58dbdf555df91e1616bad8451633.scope\n10:freezer:/machine.slice/libpod-1d1c42a73d1aa0122aed29617b292969d12a58dbdf555df91e1616bad8451633.scope\n9:memory:/system.slice/run-r641290aa7af649588b844261515999d8.scope\n8:pids:/system.slice/run-r641290aa7af649588b844261515999d8.scope\n7:hugetlb:/tripleo-libvirt\n6:devices:/system.slice\n5:cpu,cpuacct:/system.slice\n4:net_cls,net_prio:/machine.slice/libpod-1d1c42a73d1aa0122aed29617b292969d12a58dbdf555df91e1616bad8451633.scope\n3:cpuset:/machine.slice/libpod-1d1c42a73d1aa0122aed29617b292969d12a58dbdf555df91e1616bad8451633.scope\n2:rdma:/tripleo-libvirt\n1:name\u003dsystemd:/system.slice/run-r641290aa7af649588b844261515999d8.scope\n\nwhich is much better I suppose, but still I can see some libpod-xxx.scope in use. Shall I escape all of them...","commit_id":"cfbe1487420026c8e8f3822d3596d462412296c2"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"0f3aedda568b6f59cf6ecafbfc582b176a2ba438","unresolved":true,"context_lines":[{"line_number":69,"context_line":"working in the nova_libvirt contaienr, nor systemd machine, libvirt"},{"line_number":70,"context_line":"is falling back to its legacy cgroup support."},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"To mitigate that, run libvirtd as a transient unit on the host with the"},{"line_number":73,"context_line":"custom tripleo-libvirt cgroups applied. This also requires"},{"line_number":74,"context_line":"KillMode\u003dprocess. As we change the cgroup for libvirtd, that ensures"},{"line_number":75,"context_line":"that termination signals would be routed by dumb-init in a container to"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"c01966ac_3ffb1fc1","line":72,"range":{"start_line":72,"start_character":50,"end_line":72,"end_character":62},"updated":"2021-10-19 11:49:26.000000000","message":"its running as a transient unit within the contaienr not on the host right.\n\nlibvirtd should not eb installed on the host, it was deliberitly removed as part of its containerisation.","commit_id":"5d8266db46b71eee5a42eff7c1c2750306b4c637"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":17216,"name":"Martin Schuppert","email":"mschuppert@redhat.com","username":"mcschupp"},"change_message_id":"4cd3b84c9faf5d3ec1dbe7e2bc39e7a84c121c17","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"35611e4d_9aa9b097","updated":"2021-10-19 09:55:00.000000000","message":"fyi, libcgroup is planned to be removed in rhel9. since cnosp got stopped re removed the package from the list via https://review.opendev.org/c/openstack/tripleo-common/+/793976 . it seems it gets still pulled in as a dependency, but that might change. danpb mentioned at that time that we might be able to use systemd-run as a replacement. But haven\u0027t checked it","commit_id":"5d8266db46b71eee5a42eff7c1c2750306b4c637"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"40231b3c46f753c4a4c352339350d6bc896eaa2f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"c7500ee7_699eddbc","updated":"2021-10-19 13:42:46.000000000","message":"please ignore the dnsmasq processes left behind - that\u0027s because we install libvirt on standalone nodes, and have its default network in autostart. On a normal OSP compute there would be no such a problem.","commit_id":"5d8266db46b71eee5a42eff7c1c2750306b4c637"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"b60bec68cf509b2dbf411f90febce185be11b65a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"c9950b41_fe76a09e","updated":"2021-10-19 10:35:19.000000000","message":"unfortunately, this approach also lefts dnsmasq processes behind with the transient run-rXXX cgroup scopes that used to hold it before libvirt restarted","commit_id":"5d8266db46b71eee5a42eff7c1c2750306b4c637"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"7f2a111484a42bc018c8cd02e15a328b90f2a91f","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"eb8837a8_ed6c3bf4","in_reply_to":"c9950b41_fe76a09e","updated":"2021-10-19 12:23:46.000000000","message":"So those dnsmasq processes lifecycle is managed by neutron via the side car wrappers. I suppose we could leave them around? Or how could we check if neutron would reap it off eventually?","commit_id":"5d8266db46b71eee5a42eff7c1c2750306b4c637"},{"author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"change_message_id":"6191dcaabcbbadf4e668bf8f5e2fb2ee18ea57e1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"beed4715_558173cd","in_reply_to":"eb8837a8_ed6c3bf4","updated":"2021-10-19 12:27:45.000000000","message":"we should not be spawning any dnsmas process in the nova_libvirt container\nwe are not using libvirts networking capablity for dhcp or dns.\n\nthere shoudl be no libvirt networks defiend.\nhow were they created?","commit_id":"5d8266db46b71eee5a42eff7c1c2750306b4c637"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"610af393b37356ddb3748ba2567a091f84fbc504","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":3,"id":"cda60115_3d3f4e30","updated":"2021-10-19 15:57:41.000000000","message":"recheck","commit_id":"f7b61a6aabfb42fc025d94d21e9ef4ad3b3d6ada"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"8047a6ccfdedefec39c1e2f8dd54ee252bb1bbe1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"f8cf8147_c9c85852","updated":"2021-10-26 16:05:55.000000000","message":"TODO: the same for modular libvirt","commit_id":"f3e5d596f369c5b8f8ceb7ce7efc1da889a17752"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"6a134c5bf7dcbb285874723dab52464dc2c1bc91","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"32ab42c2_34174c66","updated":"2021-11-10 11:41:33.000000000","message":"PTAL","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"2f5c034b60bfe406f42e3cfe17a1bbddc36f74af","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"e572ac69_b2b9f599","updated":"2021-11-09 09:12:36.000000000","message":"PTAL","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"c873c983d01eea8d55a410061d3ddd707964e3bf","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"6e0fe5a4_12e62381","updated":"2021-11-10 11:41:39.000000000","message":"check-rdo","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"477b7a5d46261e6c7657e13978bffd77a614aa6b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"ff85d09a_fdbffdb5","updated":"2021-11-09 09:12:49.000000000","message":"check-rdo","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"6c0c0af16177fdca97bfc56ad8f495bea51adae9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"ce577581_0b396e1f","updated":"2021-11-10 15:55:16.000000000","message":"if I freeze libvirt (kill -STOP), that changes nothing. Qemu-kvm survives, libvirt container/service gets restarted OK.\n\nif I freeze the conmon that runs theirs libpod-XXX.scope, then both libvirtd and qemu-processes in that scope get wiped.\n\nI don\u0027t think we should expect conmon becomes totally unresponsive under \"norma\" failure scenarios though?","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"57d7884355b973cf7834d9b43c4c757638e6c651","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"584ac126_ba0650ec","updated":"2021-11-10 15:03:02.000000000","message":"let\u0027s hold for a while, need more testing","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"438265aa59ba3c763a799fab3e87cdffa0e6805e","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"fbe5a3ec_03a6b504","updated":"2021-11-05 08:47:00.000000000","message":"recheck","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"},{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"d6db952957532ad11ef272b38630fb3f1af2d990","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"af32347f_d0b281e2","in_reply_to":"ce577581_0b396e1f","updated":"2021-11-10 16:14:14.000000000","message":"that failure mode looks like:\n\nqemu-kvm: terminating on signal 15 from pid 1 (\u003cunknown process\u003e)\nshutting down, reason\u003dcrashed\n\nlogged. But I think we can assume that freezing conmon is not a real case. If it happens in real, that means container runtime engine is borked, and we can expect no dataplane available for instances, so there would be no value to keep it up.","commit_id":"dd8c89ea23d032228748c7dd8f6c8ca16be9c77a"}],"deployment/deprecated/nova/nova-libvirt-container-puppet.yaml":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"18c413bf02d3741fac5d2666ea445d61cd5908ce","unresolved":true,"context_lines":[{"line_number":512,"context_line":"                  /usr/lib/systemd/kvm-setup"},{"line_number":513,"context_line":"                fi"},{"line_number":514,"context_line":"                #NOTE(bogdando): run libvirtd as a transient unit in the container"},{"line_number":515,"context_line":"                exec systemd-run --unit\u003dtransient-libvirtd --scope --slice\u003dsystem /usr/sbin/libvirtd /usr/sbin/libvirtd LIBVIRTD_ARGS"},{"line_number":516,"context_line":"              params:"},{"line_number":517,"context_line":"                LIBVIRTD_ARGS:"},{"line_number":518,"context_line":"                  if:"}],"source_content_type":"text/x-yaml","patch_set":4,"id":"697a7ce1_513b92c8","line":515,"range":{"start_line":515,"start_character":33,"end_line":515,"end_character":58},"updated":"2021-10-26 16:06:39.000000000","message":"note: not needed","commit_id":"f3e5d596f369c5b8f8ceb7ce7efc1da889a17752"}],"deployment/nova/nova-modular-libvirt-container-puppet.yaml":[{"author":{"_account_id":6926,"name":"Bogdan Dobrelya","email":"bdobreli@redhat.com","username":"bogdando"},"change_message_id":"acaa5ba3158cfad0d40c85181ac28598cd115888","unresolved":true,"context_lines":[{"line_number":673,"context_line":"                start_order: 5"},{"line_number":674,"context_line":"                image: {get_param: ContainerNovaLibvirtImage}"},{"line_number":675,"context_line":"                ulimit: {get_param: ContainerNovaLibvirtUlimit}"},{"line_number":676,"context_line":"                kill_mode: process"},{"line_number":677,"context_line":"                cgroupns: host"},{"line_number":678,"context_line":"                net: host"},{"line_number":679,"context_line":"                pid: host"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"91cf7dfe_74beeecc","line":676,"updated":"2021-10-26 17:07:52.000000000","message":"unsure for what else containers should we use the same kill_mode?","commit_id":"55ce0eef080404177296935e2e50d406210d9a5c"},{"author":{"_account_id":17216,"name":"Martin Schuppert","email":"mschuppert@redhat.com","username":"mcschupp"},"change_message_id":"2b434746104115d5c7f753e45e0049b72e955cf5","unresolved":true,"context_lines":[{"line_number":673,"context_line":"                start_order: 5"},{"line_number":674,"context_line":"                image: {get_param: ContainerNovaLibvirtImage}"},{"line_number":675,"context_line":"                ulimit: {get_param: ContainerNovaLibvirtUlimit}"},{"line_number":676,"context_line":"                kill_mode: process"},{"line_number":677,"context_line":"                cgroupns: host"},{"line_number":678,"context_line":"                net: host"},{"line_number":679,"context_line":"                pid: host"}],"source_content_type":"text/x-yaml","patch_set":5,"id":"cccfc218_a76bd3d1","line":676,"in_reply_to":"91cf7dfe_74beeecc","updated":"2021-10-27 06:51:31.000000000","message":"probable virtqemud","commit_id":"55ce0eef080404177296935e2e50d406210d9a5c"}]}
