On a Thursday in 2026, Daniel P. Berrangé wrote:
On Thu, Oct 01, 2026 at 01:27:42PM +0200, Ján Tomko via Devel wrote:
On a Monday in 2026, Yusuke Fujimaki wrote:
> Ceph removed auth_supported option in commit 350cc71d,
> https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
>
> auth_supported has long been an optional parameter, and has been
> replaced by auth_*_required.
> The error occurs because libvirt always uses the auth_supported option when
> authenticating to rbd storage.Therefore, remove the code that uses this
> option.
>
> Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918
>
> Signed-off-by: Yusuke Fujimaki <[email protected]>
> ---
> src/libxl/libxl_conf.c                           | 6 +-----
> src/libxl/xen_xl.c                               | 2 --
> src/storage/storage_backend_rbd.c                | 7 -------
> tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +-
> 4 files changed, 2 insertions(+), 15 deletions(-)
>
> diff --git a/src/storage/storage_backend_rbd.c 
b/src/storage/storage_backend_rbd.c
> index 25cad4a28d..3981f81a79 100644
> --- a/src/storage/storage_backend_rbd.c
> +++ b/src/storage/storage_backend_rbd.c
> @@ -239,10 +239,6 @@ 
virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
>
>         if (rc < 0)
>             goto cleanup;
> -
> -        if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
> -                                             "auth_supported", "cephx") < 0)

This does not look right - if we've been requesting the auth method
before, shouldn't we request it via a new option?

IIUC, the suggestion seems to be let the client+server auth-negotiate
the auth to make it "do the right thing".

If we wanted to still force it though, it appears we could use
auth_client_required instead.  IIUC,  auth_supported has been
a no-op for a while, so  just removing it is functionally the
same as we've been using for a while.


Looking at the referenced commit:
https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
it seemed all three options - auth_{cluster,service,client}_required -
were filled up until its removal.

Jano


Jano

> -            goto cleanup;
>     } else {
>         VIR_DEBUG("Not using cephx authorization");
>         if (rados_create(&ptr->cluster, NULL) < 0) {


With regards,
Daniel
--
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|


Reply via email to