Skip to content

Synchronise 2026.1 with upstream - #230

Merged
priteau merged 7 commits into
stackhpc/2026.1from
upstream/2026.1-2026-08-03
Aug 11, 2026
Merged

Synchronise 2026.1 with upstream#230
priteau merged 7 commits into
stackhpc/2026.1from
upstream/2026.1-2026-08-03

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

This PR contains a snapshot of 2026.1 from upstream stable/2026.1.

sbauza and others added 7 commits June 16, 2026 15:29
User-supplied scheduler hints can include internal keys like
"_nova_check_type" which cause the scheduler to bypass Placement
candidate selection, request pre-filters, and resource claims.
This can lead to instances being created without proper resource
accounting.

Rather than rejecting the request, silently strip any _nova-prefixed
hints before they reach the scheduler. This is consistent with the
existing hints behavior of ignoring unknown ones and ensures the
probe attempt still costs the attacker money.

Assisted-By: Cursor

Change-Id: Iac4fef93bef0bab3060d40a9ea3e0ebd69a38c37
Closes-Bug: #2151252
Signed-off-by: Sylvain Bauza <sbauza@redhat.com>
(cherry picked from commit 9666894)
During nova-compute startup, _validate_vtpm_configuration() accesses
instance.flavor and instance.image_meta for each instance. These
attributes were not pre-loaded, causing 2*N sequential database
queries (lazy-loading) and significantly slowing startup time.

Add 'flavor' and 'system_metadata' to expected_attrs when loading
instances in init_host() to batch-load them in a single query.

Assisted-By: claude-4.5-opus-high
Closes-Bug: 2141981
Change-Id: I84dc616ebd496b0049b8d828fb3ca80814e86d1d
Signed-off-by: Ilia Baikov <ilia.baikov@ib.systems>
(cherry picked from commit 2714c71)
The websockify lib behind novncproxy can log each time when some traffic
is forwarded back and forth. This can be pretty noisy in the logs.
So this patch changes the logic to only enable traffic logging if
[DEFAULT]debug=True is also set.

Closes-Bug: #2157885

Change-Id: I08d452110dd26a7ef6dfaf016cb0aa6438169a9f
Signed-off-by: Balazs Gibizer <gibi@redhat.com>
(cherry picked from commit c8fd6cd)
The websocket proxy mutates the CONF host list with the Host header
from the request, which would then poison future requests and/or
lead to a slow resource exhaustion attack. Simply making a copy before
mutation avoids the issue.

Conflicts:
  nova/console/websocketproxy.py

Generated-By: Claude Opus 4.6
Closes-Bug: #2158919
Change-Id: Ib13e479337f9b1c8b16952089d1d5f6979976b86
Signed-off-by: Dan Smith <dansmith@redhat.com>
(cherry picked from commit 0612fed)
Currently the CPU time and address space process limits for qemu-img
are hard-coded to 30 seconds and 1G respectively.

With more recent versions of Ceph in upstream CI, we have experienced
test failures that suggest 1G is no longer large enough for encrypted
RBD images. In the failures the following error is raised:

  nova.exception.InvalidDiskInfo: Disk info file is invalid: qemu-img
    failed to execute on
    rbd:volumes/volume-c83c9b7f-0f38-4bb8-a40a-300a66080d21:id=cinder :
    Unexpected error while running command.
  Command: /opt/stack/data/venv/bin/python3.12 -m
    oslo_concurrency.prlimit --as=1073741824 --cpu=30 -- env LC_ALL=C
    LANG=C qemu-img info
    rbd:volumes/volume-c83c9b7f-0f38-4bb8-a40a-300a66080d21:id=cinder
    --force-share --output=json
  Exit code: -6
  Stdout: ''
  Stderr: 'failed to allocate memory for stack: Cannot allocate memory\n'

This adds config options ``images_cpu_time_limit`` and
``images_address_space_limit`` to the ``[libvirt]`` section to allow
for tuning of the qemu-img process limits, similar to how Cinder and
Ironic make qemu-img process limits configurable.

Stable Only Changes
- the defautl value is updated to 1G to maintain stable
  branch behavior
- the ci jobs are updated to use 2G to match master
- the release note is updated to reflect this.

Closes-Bug: #2116852

Change-Id: I10e53de27b063b1e514e04066d0eb56a86188e9a
Signed-off-by: melanie witt <melwittt@gmail.com>
Signed-off-by: Sean Mooney <work@seanmooney.info>
(cherry picked from commit 7f43431)
@github-actions
github-actions Bot requested a review from a team as a code owner August 3, 2026 07:23
@github-actions github-actions Bot added automated Automated action performed by GitHub Actions synchronisation labels Aug 3, 2026
@priteau
priteau merged commit 7a4d0cb into stackhpc/2026.1 Aug 11, 2026
6 checks passed
@priteau
priteau deleted the upstream/2026.1-2026-08-03 branch August 11, 2026 10:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated action performed by GitHub Actions synchronisation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants