[PATCH] Remove rbd's auth_supported option
Ceph removed auth_supported option in commit 350cc71d, https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70 auth_supported has long been an optional parameter, and has been replaced by auth_*_required. The error occurs because libvirt always uses the auth_supported option when authenticating to rbd storage.Therefore, remove the code that uses this option. Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918 Signed-off-by: Yusuke Fujimaki <usk.fujimaki@gmail.com> --- src/libxl/libxl_conf.c | 6 +----- src/libxl/xen_xl.c | 2 -- src/storage/storage_backend_rbd.c | 7 ------- tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +- 4 files changed, 2 insertions(+), 15 deletions(-) diff --git a/src/libxl/libxl_conf.c b/src/libxl/libxl_conf.c index 3bb5c1e591..184a143712 100644 --- a/src/libxl/libxl_conf.c +++ b/src/libxl/libxl_conf.c @@ -1087,11 +1087,7 @@ libxlMakeNetworkDiskSrcStr(virStorageSource *src, if (username) { virBufferEscape(&buf, '\\', ":", ":id=%s", username); - virBufferEscape(&buf, '\\', ":", - ":key=%s:auth_supported=cephx\\;none", - secret); - } else { - virBufferAddLit(&buf, ":auth_supported=none"); + virBufferEscape(&buf, '\\', ":", ":key=%s", secret); } if (src->nhosts > 0) { diff --git a/src/libxl/xen_xl.c b/src/libxl/xen_xl.c index d05972af5b..952dd73c1a 100644 --- a/src/libxl/xen_xl.c +++ b/src/libxl/xen_xl.c @@ -1478,8 +1478,6 @@ xenFormatXLDiskSrcNet(virStorageSource *src) virBufferStrcat(&buf, "rbd:", src->path, NULL); - virBufferAddLit(&buf, ":auth_supported=none"); - if (src->nhosts > 0) { virBufferAddLit(&buf, ":mon_host="); for (i = 0; i < src->nhosts; i++) { diff --git a/src/storage/storage_backend_rbd.c b/src/storage/storage_backend_rbd.c index 25cad4a28d..3981f81a79 100644 --- a/src/storage/storage_backend_rbd.c +++ b/src/storage/storage_backend_rbd.c @@ -239,10 +239,6 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr, if (rc < 0) goto cleanup; - - if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "cephx") < 0) - goto cleanup; } else { VIR_DEBUG("Not using cephx authorization"); if (rados_create(&ptr->cluster, NULL) < 0) { @@ -250,9 +246,6 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr, _("failed to create the RADOS cluster")); goto cleanup; } - if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "none") < 0) - goto cleanup; } VIR_DEBUG("Found %zu RADOS cluster monitors in the pool configuration", diff --git a/tests/xlconfigdata/test-rbd-multihost-noauth.cfg b/tests/xlconfigdata/test-rbd-multihost-noauth.cfg index 5906865047..933e5af75a 100644 --- a/tests/xlconfigdata/test-rbd-multihost-noauth.cfg +++ b/tests/xlconfigdata/test-rbd-multihost-noauth.cfg @@ -22,4 +22,4 @@ parallel = "none" serial = "none" builder = "hvm" boot = "d" -disk = [ "format=raw,vdev=hda,access=rw,backendtype=phy,target=/dev/HostVG/XenGuest2", "format=raw,vdev=hdb,access=rw,backendtype=qdisk,target=rbd:pool/image:auth_supported=none:mon_host=mon1.example.org\\:6321\\;mon2.example.org\\:6322\\;mon3.example.org\\:6322" ] +disk = [ "format=raw,vdev=hda,access=rw,backendtype=phy,target=/dev/HostVG/XenGuest2", "format=raw,vdev=hdb,access=rw,backendtype=qdisk,target=rbd:pool/image:mon_host=mon1.example.org\\:6321\\;mon2.example.org\\:6322\\;mon3.example.org\\:6322" ] -- 2.47.3
On a Monday in 2026, Yusuke Fujimaki wrote:
Ceph removed auth_supported option in commit 350cc71d, https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
auth_supported has long been an optional parameter, and has been replaced by auth_*_required. The error occurs because libvirt always uses the auth_supported option when authenticating to rbd storage.Therefore, remove the code that uses this option.
Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918
Signed-off-by: Yusuke Fujimaki <usk.fujimaki@gmail.com> --- src/libxl/libxl_conf.c | 6 +----- src/libxl/xen_xl.c | 2 -- src/storage/storage_backend_rbd.c | 7 ------- tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +- 4 files changed, 2 insertions(+), 15 deletions(-)
diff --git a/src/storage/storage_backend_rbd.c b/src/storage/storage_backend_rbd.c index 25cad4a28d..3981f81a79 100644 --- a/src/storage/storage_backend_rbd.c +++ b/src/storage/storage_backend_rbd.c @@ -239,10 +239,6 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
if (rc < 0) goto cleanup; - - if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "cephx") < 0)
This does not look right - if we've been requesting the auth method before, shouldn't we request it via a new option? Jano
- goto cleanup; } else { VIR_DEBUG("Not using cephx authorization"); if (rados_create(&ptr->cluster, NULL) < 0) {
On Thu, Oct 01, 2026 at 01:27:42PM +0200, Ján Tomko via Devel wrote:
On a Monday in 2026, Yusuke Fujimaki wrote:
Ceph removed auth_supported option in commit 350cc71d, https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
auth_supported has long been an optional parameter, and has been replaced by auth_*_required. The error occurs because libvirt always uses the auth_supported option when authenticating to rbd storage.Therefore, remove the code that uses this option.
Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918
Signed-off-by: Yusuke Fujimaki <usk.fujimaki@gmail.com> --- src/libxl/libxl_conf.c | 6 +----- src/libxl/xen_xl.c | 2 -- src/storage/storage_backend_rbd.c | 7 ------- tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +- 4 files changed, 2 insertions(+), 15 deletions(-)
diff --git a/src/storage/storage_backend_rbd.c b/src/storage/storage_backend_rbd.c index 25cad4a28d..3981f81a79 100644 --- a/src/storage/storage_backend_rbd.c +++ b/src/storage/storage_backend_rbd.c @@ -239,10 +239,6 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
if (rc < 0) goto cleanup; - - if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "cephx") < 0)
This does not look right - if we've been requesting the auth method before, shouldn't we request it via a new option?
IIUC, the suggestion seems to be let the client+server auth-negotiate the auth to make it "do the right thing". If we wanted to still force it though, it appears we could use auth_client_required instead. IIUC, auth_supported has been a no-op for a while, so just removing it is functionally the same as we've been using for a while.
Jano
- goto cleanup; } else { VIR_DEBUG("Not using cephx authorization"); if (rados_create(&ptr->cluster, NULL) < 0) {
With regards, Daniel -- |: https://berrange.com ~~ https://hachyderm.io/@berrange :| |: https://libvirt.org ~~ https://entangle-photo.org :| |: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
On a Thursday in 2026, Daniel P. Berrangé wrote:
On Thu, Oct 01, 2026 at 01:27:42PM +0200, Ján Tomko via Devel wrote:
On a Monday in 2026, Yusuke Fujimaki wrote:
Ceph removed auth_supported option in commit 350cc71d, https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
auth_supported has long been an optional parameter, and has been replaced by auth_*_required. The error occurs because libvirt always uses the auth_supported option when authenticating to rbd storage.Therefore, remove the code that uses this option.
Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918
Signed-off-by: Yusuke Fujimaki <usk.fujimaki@gmail.com> --- src/libxl/libxl_conf.c | 6 +----- src/libxl/xen_xl.c | 2 -- src/storage/storage_backend_rbd.c | 7 ------- tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +- 4 files changed, 2 insertions(+), 15 deletions(-)
diff --git a/src/storage/storage_backend_rbd.c b/src/storage/storage_backend_rbd.c index 25cad4a28d..3981f81a79 100644 --- a/src/storage/storage_backend_rbd.c +++ b/src/storage/storage_backend_rbd.c @@ -239,10 +239,6 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
if (rc < 0) goto cleanup; - - if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "cephx") < 0)
This does not look right - if we've been requesting the auth method before, shouldn't we request it via a new option?
IIUC, the suggestion seems to be let the client+server auth-negotiate the auth to make it "do the right thing".
If we wanted to still force it though, it appears we could use auth_client_required instead. IIUC, auth_supported has been a no-op for a while, so just removing it is functionally the same as we've been using for a while.
Looking at the referenced commit: https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70 it seemed all three options - auth_{cluster,service,client}_required - were filled up until its removal. Jano
Jano
- goto cleanup; } else { VIR_DEBUG("Not using cephx authorization"); if (rados_create(&ptr->cluster, NULL) < 0) {
With regards, Daniel -- |: https://berrange.com ~~ https://hachyderm.io/@berrange :| |: https://libvirt.org ~~ https://entangle-photo.org :| |: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
On Thu, Oct 01, 2026 at 02:02:33PM +0200, Ján Tomko wrote:
On a Thursday in 2026, Daniel P. Berrangé wrote:
On Thu, Oct 01, 2026 at 01:27:42PM +0200, Ján Tomko via Devel wrote:
On a Monday in 2026, Yusuke Fujimaki wrote:
Ceph removed auth_supported option in commit 350cc71d, https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
auth_supported has long been an optional parameter, and has been replaced by auth_*_required. The error occurs because libvirt always uses the auth_supported option when authenticating to rbd storage.Therefore, remove the code that uses this option.
Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918
Signed-off-by: Yusuke Fujimaki <usk.fujimaki@gmail.com> --- src/libxl/libxl_conf.c | 6 +----- src/libxl/xen_xl.c | 2 -- src/storage/storage_backend_rbd.c | 7 ------- tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +- 4 files changed, 2 insertions(+), 15 deletions(-)
diff --git a/src/storage/storage_backend_rbd.c b/src/storage/storage_backend_rbd.c index 25cad4a28d..3981f81a79 100644 --- a/src/storage/storage_backend_rbd.c +++ b/src/storage/storage_backend_rbd.c @@ -239,10 +239,6 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
if (rc < 0) goto cleanup; - - if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "cephx") < 0)
This does not look right - if we've been requesting the auth method before, shouldn't we request it via a new option?
IIUC, the suggestion seems to be let the client+server auth-negotiate the auth to make it "do the right thing".
If we wanted to still force it though, it appears we could use auth_client_required instead. IIUC, auth_supported has been a no-op for a while, so just removing it is functionally the same as we've been using for a while.
Looking at the referenced commit: https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70 it seemed all three options - auth_{cluster,service,client}_required - were filled up until its removal.
Hmmm, so we should be setting all three options in this new patch then for compatibility. With regards, Daniel -- |: https://berrange.com ~~ https://hachyderm.io/@berrange :| |: https://libvirt.org ~~ https://entangle-photo.org :| |: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
2026年10月1日(木) 21:17 Daniel P. Berrangé <berrange@redhat.com>:
On Thu, Oct 01, 2026 at 02:02:33PM +0200, Ján Tomko wrote:
On a Thursday in 2026, Daniel P. Berrangé wrote:
On Thu, Oct 01, 2026 at 01:27:42PM +0200, Ján Tomko via Devel wrote:
On a Monday in 2026, Yusuke Fujimaki wrote:
Ceph removed auth_supported option in commit 350cc71d, https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70
auth_supported has long been an optional parameter, and has been replaced by auth_*_required. The error occurs because libvirt always uses the auth_supported option when authenticating to rbd storage.Therefore, remove the code that uses this option.
Resolves: https://gitlab.com/libvirt/libvirt/-/work_items/918
Signed-off-by: Yusuke Fujimaki <usk.fujimaki@gmail.com> --- src/libxl/libxl_conf.c | 6 +----- src/libxl/xen_xl.c | 2 -- src/storage/storage_backend_rbd.c | 7 ------- tests/xlconfigdata/test-rbd-multihost-noauth.cfg | 2 +- 4 files changed, 2 insertions(+), 15 deletions(-)
diff --git a/src/storage/storage_backend_rbd.c b/src/storage/storage_backend_rbd.c index 25cad4a28d..3981f81a79 100644 --- a/src/storage/storage_backend_rbd.c +++ b/src/storage/storage_backend_rbd.c @@ -239,10 +239,6 @@ virStorageBackendRBDOpenRADOSConn(virStorageBackendRBDState *ptr,
if (rc < 0) goto cleanup; - - if (virStorageBackendRBDRADOSConfSet(ptr->cluster, - "auth_supported", "cephx") < 0)
This does not look right - if we've been requesting the auth method before, shouldn't we request it via a new option?
IIUC, the suggestion seems to be let the client+server auth-negotiate the auth to make it "do the right thing".
If we wanted to still force it though, it appears we could use auth_client_required instead. IIUC, auth_supported has been a no-op for a while, so just removing it is functionally the same as we've been using for a while.
Looking at the referenced commit: https://github.com/ceph/ceph/commit/350cc71d7d9e9cd6239d24080082de7ac9bf8b70 it seemed all three options - auth_{cluster,service,client}_required - were filled up until its removal.
Hmmm, so we should be setting all three options in this new patch then for compatibility.
Since auth_cluster_required configures authentication between Ceph daemons (ceph-mon, ceph-osd, ceph-mds and ceph-mgr), wouldn't auth_client_required and auth_service_required be sufficient for the connection from libvirt to rbd?
With regards, Daniel -- |: https://berrange.com ~~ https://hachyderm.io/@berrange :| |: https://libvirt.org ~~ https://entangle-photo.org :| |: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
-- Yusuke FUJIMAKI
participants (4)
-
Daniel P. Berrangé -
Ján Tomko -
Yusuke FUJIMAKI -
Yusuke Fujimaki