As stated in Yusuke Fujimaki's patch, Ceph recently removed the deprecated auth_supported option that is still used by libvirt, causing errors when attempting to start a storage pool on a newer Ceph server: https://lists.libvirt.org/archives/list/[email protected]/thread/RELDVG6A3LAA4IFA32EOFQ5OJPMI6OGR/ https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
This patch addresses the issue by replacing the deprecated option with all three new options (auth_cluster_required, auth_service_required and auth_client_required), as was previously done in Ceph. Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918 Signed-off-by: Janis Heims <[email protected]> --- src/libxl/libxl_conf.c | 11 ++++++---- src/libxl/xen_xl.c | 4 +++- src/storage/storage_backend_rbd.c | 22 +++++++++++++++++-- .../test-rbd-multihost-noauth.cfg | 2 +- 4 files changed, 31 insertions(+), 8 deletions(-) diff --git a/src/libxl/libxl_conf.c b/src/libxl/libxl_conf.c index 3bb5c1e591..49f968a857 100644 --- a/src/libxl/libxl_conf.c +++ b/src/libxl/libxl_conf.c @@ -1087,11 +1087,14 @@ libxlMakeNetworkDiskSrcStr(virStorageSource *src, if (username) { virBufferEscape(&buf, '\\', ":", ":id=%s", username); - virBufferEscape(&buf, '\\', ":", - ":key=%s:auth_supported=cephx\\;none", - secret); + virBufferEscape(&buf, '\\', ":", ":key=%s", secret); + virBufferAddLit(&buf, ":auth_cluster_required=cephx"); + virBufferAddLit(&buf, ":auth_service_required=cephx"); + virBufferAddLit(&buf, ":auth_client_required=cephx\\;none"); } else { - virBufferAddLit(&buf, ":auth_supported=none"); + virBufferAddLit(&buf, ":auth_cluster_required=none"); + virBufferAddLit(&buf, ":auth_service_required=none"); + virBufferAddLit(&buf, ":auth_client_required=none"); } if (src->nhosts > 0) { diff --git a/src/libxl/xen_xl.c b/src/libxl/xen_xl.c index d05972af5b..c1ddc7c071 100644 --- a/src/libxl/xen_xl.c +++ b/src/libxl/xen_xl.c @@ -1478,7 +1478,9 @@ xenFormatXLDiskSrcNet(virStorageSource *src) virBufferStrcat(&buf, "rbd:", src->path, NULL); - virBufferAddLit(&buf, ":auth_supported=none"); + virBufferAddLit(&buf, ":auth_cluster_required=none"); + virBufferAddLit(&buf, ":auth_service_required=none"); + virBufferAddLit(&buf, ":auth_client_required=none"); if (src->nhosts > 0) { virBufferAddLit(&buf, ":mon_host="); diff --git a/src/storage/storage_backend_rbd.c b/src/storage/storage_backend_rbd.c index 25cad4a28d..33e644d981 100644 --- a/src/storage/storage_backend_rbd.c +++ b/src/storage/storage_backend_rbd.c @@ -241,17 +241,35 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr, goto cleanup; if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "cephx") < 0) + "auth_cluster_required", "cephx") < 0) + goto cleanup; + + if (virStorageBackendRBDRADOSConfSet(ptr->cluster, + "auth_service_required", "cephx") < 0) + goto cleanup; + + if (virStorageBackendRBDRADOSConfSet(ptr->cluster, + "auth_client_required", "cephx") < 0) goto cleanup; } else { VIR_DEBUG("Not using cephx authorization"); + if (rados_create(&ptr->cluster, NULL) < 0) { virReportError(VIR_ERR_INTERNAL_ERROR, "%s", _("failed to create the RADOS cluster")); goto cleanup; } + if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "none") < 0) + "auth_cluster_required", "none") < 0) + goto cleanup; + + if (virStorageBackendRBDRADOSConfSet(ptr->cluster, + "auth_service_required", "none") < 0) + goto cleanup; + + if (virStorageBackendRBDRADOSConfSet(ptr->cluster, + "auth_client_required", "none") < 0) goto cleanup; } diff --git a/tests/xlconfigdata/test-rbd-multihost-noauth.cfg b/tests/xlconfigdata/test-rbd-multihost-noauth.cfg index 5906865047..b149be077c 100644 --- a/tests/xlconfigdata/test-rbd-multihost-noauth.cfg +++ b/tests/xlconfigdata/test-rbd-multihost-noauth.cfg @@ -22,4 +22,4 @@ parallel = "none" serial = "none" builder = "hvm" boot = "d" -disk = [ "format=raw,vdev=hda,access=rw,backendtype=phy,target=/dev/HostVG/XenGuest2", "format=raw,vdev=hdb,access=rw,backendtype=qdisk,target=rbd:pool/image:auth_supported=none:mon_host=mon1.example.org\\:6321\\;mon2.example.org\\:6322\\;mon3.example.org\\:6322" ] +disk = [ "format=raw,vdev=hda,access=rw,backendtype=phy,target=/dev/HostVG/XenGuest2", "format=raw,vdev=hdb,access=rw,backendtype=qdisk,target=rbd:pool/image:auth_cluster_required=none:auth_service_required=none:auth_client_required=none:mon_host=mon1.example.org\\:6321\\;mon2.example.org\\:6322\\;mon3.example.org\\:6322" ] base-commit: 215fab8ab1d912f6b25e60ab4d2ad59000f2eaff -- 2.54.0
