As stated in Yusuke Fujimaki's patch, Ceph recently removed the
deprecated auth_supported option that is still used by libvirt, causing
errors when attempting to start a storage pool on a newer Ceph server:
https://lists.libvirt.org/archives/list/[email protected]/thread/RELDVG6A3LAA4IFA32EOFQ5OJPMI6OGR/
https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70

This patch addresses the issue by replacing the deprecated option with
all three new options (auth_cluster_required, auth_service_required and
auth_client_required), as was previously done in Ceph.

Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918

Signed-off-by: Janis Heims <[email protected]>
---
 src/libxl/libxl_conf.c                        | 11 ++++++----
 src/libxl/xen_xl.c                            |  4 +++-
 src/storage/storage_backend_rbd.c             | 22 +++++++++++++++++--
 .../test-rbd-multihost-noauth.cfg             |  2 +-
 4 files changed, 31 insertions(+), 8 deletions(-)

diff --git a/src/libxl/libxl_conf.c b/src/libxl/libxl_conf.c
index 3bb5c1e591..49f968a857 100644
--- a/src/libxl/libxl_conf.c
+++ b/src/libxl/libxl_conf.c
@@ -1087,11 +1087,14 @@ libxlMakeNetworkDiskSrcStr(virStorageSource *src,
 
         if (username) {
             virBufferEscape(&buf, '\\', ":", ":id=%s", username);
-            virBufferEscape(&buf, '\\', ":",
-                            ":key=%s:auth_supported=cephx\\;none",
-                            secret);
+            virBufferEscape(&buf, '\\', ":", ":key=%s", secret);
+            virBufferAddLit(&buf, ":auth_cluster_required=cephx");
+            virBufferAddLit(&buf, ":auth_service_required=cephx");
+            virBufferAddLit(&buf, ":auth_client_required=cephx\\;none");
         } else {
-            virBufferAddLit(&buf, ":auth_supported=none");
+            virBufferAddLit(&buf, ":auth_cluster_required=none");
+            virBufferAddLit(&buf, ":auth_service_required=none");
+            virBufferAddLit(&buf, ":auth_client_required=none");
         }
 
         if (src->nhosts > 0) {
diff --git a/src/libxl/xen_xl.c b/src/libxl/xen_xl.c
index d05972af5b..c1ddc7c071 100644
--- a/src/libxl/xen_xl.c
+++ b/src/libxl/xen_xl.c
@@ -1478,7 +1478,9 @@ xenFormatXLDiskSrcNet(virStorageSource *src)
 
         virBufferStrcat(&buf, "rbd:", src->path, NULL);
 
-        virBufferAddLit(&buf, ":auth_supported=none");
+        virBufferAddLit(&buf, ":auth_cluster_required=none");
+        virBufferAddLit(&buf, ":auth_service_required=none");
+        virBufferAddLit(&buf, ":auth_client_required=none");
 
         if (src->nhosts > 0) {
             virBufferAddLit(&buf, ":mon_host=");
diff --git a/src/storage/storage_backend_rbd.c 
b/src/storage/storage_backend_rbd.c
index 25cad4a28d..33e644d981 100644
--- a/src/storage/storage_backend_rbd.c
+++ b/src/storage/storage_backend_rbd.c
@@ -241,17 +241,35 @@ 
virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
             goto cleanup;
 
         if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
-                                             "auth_supported", "cephx") < 0)
+                                             "auth_cluster_required", "cephx") 
< 0)
+            goto cleanup;
+
+        if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
+                                             "auth_service_required", "cephx") 
< 0)
+            goto cleanup;
+
+        if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
+                                             "auth_client_required", "cephx") 
< 0)
             goto cleanup;
     } else {
         VIR_DEBUG("Not using cephx authorization");
+
         if (rados_create(&ptr->cluster, NULL) < 0) {
             virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
                            _("failed to create the RADOS cluster"));
             goto cleanup;
         }
+
         if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
-                                             "auth_supported", "none") < 0)
+                                             "auth_cluster_required", "none") 
< 0)
+            goto cleanup;
+
+        if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
+                                             "auth_service_required", "none") 
< 0)
+            goto cleanup;
+
+        if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
+                                             "auth_client_required", "none") < 
0)
             goto cleanup;
     }
 
diff --git a/tests/xlconfigdata/test-rbd-multihost-noauth.cfg 
b/tests/xlconfigdata/test-rbd-multihost-noauth.cfg
index 5906865047..b149be077c 100644
--- a/tests/xlconfigdata/test-rbd-multihost-noauth.cfg
+++ b/tests/xlconfigdata/test-rbd-multihost-noauth.cfg
@@ -22,4 +22,4 @@ parallel = "none"
 serial = "none"
 builder = "hvm"
 boot = "d"
-disk = [ 
"format=raw,vdev=hda,access=rw,backendtype=phy,target=/dev/HostVG/XenGuest2", 
"format=raw,vdev=hdb,access=rw,backendtype=qdisk,target=rbd:pool/image:auth_supported=none:mon_host=mon1.example.org\\:6321\\;mon2.example.org\\:6322\\;mon3.example.org\\:6322"
 ]
+disk = [ 
"format=raw,vdev=hda,access=rw,backendtype=phy,target=/dev/HostVG/XenGuest2", 
"format=raw,vdev=hdb,access=rw,backendtype=qdisk,target=rbd:pool/image:auth_cluster_required=none:auth_service_required=none:auth_client_required=none:mon_host=mon1.example.org\\:6321\\;mon2.example.org\\:6322\\;mon3.example.org\\:6322"
 ]

base-commit: 215fab8ab1d912f6b25e60ab4d2ad59000f2eaff
-- 
2.54.0

Reply via email to