2026年10月1日(木) 21:17 Daniel P. Berrangé <[email protected]>:
>
> On Thu, Oct 01, 2026 at 02:02:33PM +0200, Ján Tomko wrote:
> > On a Thursday in 2026, Daniel P. Berrangé wrote:
> > > On Thu, Oct 01, 2026 at 01:27:42PM +0200, Ján Tomko via Devel wrote:
> > > > On a Monday in 2026, Yusuke Fujimaki wrote:
> > > > > Ceph removed auth_supported option in commit 350cc71d,
> > > > > https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
> > > > >
> > > > > auth_supported has long been an optional parameter, and has been
> > > > > replaced by auth_*_required.
> > > > > The error occurs because libvirt always uses the auth_supported 
> > > > > option when
> > > > > authenticating to rbd storage.Therefore, remove the code that uses 
> > > > > this
> > > > > option.
> > > > >
> > > > > Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918
> > > > >
> > > > > Signed-off-by: Yusuke Fujimaki <[email protected]>
> > > > > ---
> > > > > src/libxl/libxl_conf.c                           | 6 +-----
> > > > > src/libxl/xen_xl.c                               | 2 --
> > > > > src/storage/storage_backend_rbd.c                | 7 -------
> > > > > tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +-
> > > > > 4 files changed, 2 insertions(+), 15 deletions(-)
> > > > >
> > > > > diff --git a/src/storage/storage_backend_rbd.c 
> > > > > b/src/storage/storage_backend_rbd.c
> > > > > index 25cad4a28d..3981f81a79 100644
> > > > > --- a/src/storage/storage_backend_rbd.c
> > > > > +++ b/src/storage/storage_backend_rbd.c
> > > > > @@ -239,10 +239,6 @@ 
> > > > > virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
> > > > >
> > > > >         if (rc < 0)
> > > > >             goto cleanup;
> > > > > -
> > > > > -        if (virStorageBackendRBDRADOSConfSet(ptr->cluster,
> > > > > -                                             "auth_supported", 
> > > > > "cephx") < 0)
> > > >
> > > > This does not look right - if we've been requesting the auth method
> > > > before, shouldn't we request it via a new option?
> > >
> > > IIUC, the suggestion seems to be let the client+server auth-negotiate
> > > the auth to make it "do the right thing".
> > >
> > > If we wanted to still force it though, it appears we could use
> > > auth_client_required instead.  IIUC,  auth_supported has been
> > > a no-op for a while, so  just removing it is functionally the
> > > same as we've been using for a while.
> > >
> >
> > Looking at the referenced commit:
> > https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
> > it seemed all three options - auth_{cluster,service,client}_required -
> > were filled up until its removal.
>
> Hmmm, so we should be setting all three options in this new
> patch then for compatibility.

Since auth_cluster_required configures authentication between Ceph daemons
(ceph-mon, ceph-osd, ceph-mds and ceph-mgr), wouldn't auth_client_required and
auth_service_required be sufficient for the connection from libvirt to rbd?
>
> With regards,
> Daniel
> --
> |: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
> |: https://libvirt.org          ~~          https://entangle-photo.org :|
> |: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|
>

-- 
Yusuke FUJIMAKI

Reply via email to