Conversation
…amed Renaming a VM did two wrong things. A UEFI VM that had never been started raised CallError for a rename that had already been committed, because libvirt only creates the nvram file at first boot, so 'never booted' and 'nvram lost' look identical. And a VM with a TPM kept its TPM state directory under the old name while the re-defined domain pointed swtpm at the new one, so swtpm initialised blank state on the next boot and the guest saw a factory-reset TPM. Replace the try/except with a helper that moves the nvram file and the TPM state directory together, skipping either if it is absent. Log a warning when a UEFI VM had no nvram to move: that is normal for a VM that has never booted, but it also covers the case where one was lost, and such a VM comes up with a fresh nvram and no enrolled Secure Boot keys. Both halves are already fixed on 26.0 and master by NAS-140717 (8945d05). This keeps 25.10's plain os.rename, since truenas_os and renameat2 do not exist on this branch.
Contributor
|
This has been fixed in 26/27 and we have no plans to fix this in 25.10 train at this time. Going to close it out. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
NAS-143377 — against
stable/goldeye.Renaming a VM on 25.10 does two wrong things:
Both are already fixed on 26.0 and master by NAS-140717 (
8945d05571, "Move VM NVRAM and TPM atomically with VM rename"). This backports that decision.The error on a rename that worked
do_updateraises whenever the nvram file is missing and the bootloader is UEFI on both sides. A UEFI VM that has never booted has no nvram file — libvirt creates it from the<nvram template=...>attribute at first start — so "never booted" and "nvram was lost" are indistinguishable and the code treats both as the second, afterdatastore.updatehas committed. On 25.10.5:…while
vm.queryreturnsprobe_renamed.The TPM state left behind
get_vm_tpm_state_dir_namebuilds{id}_{name}_tpm_stateexactly the way the nvram file is built, and has one consumer — the swtpm backend insupervisor/domain_xml.py. Nothing renames it. Measured on 25.10.5 with a TPM VM booted once, then stopped and renamed:swtpm initialises blank state on the next boot. For a Windows guest the TPM looks factory reset: BitLocker asks for the recovery key and anything sealed to the TPM is gone.
Fix
A
_rename_vm_statehelper that moves both artefacts and logs when there was no nvram to move. Missing sources are skipped rather than raised — NAS-140717's wording: "Missing sources are silently skipped, a VM that has never booted has no on-disk state and libvirt/swtpm will initialise both on first start." The warning is kept because 26.0 keeps one too.Verified on 25.10.5
middlewared.loggetsRenamed VM 'f7a' to 'f7a_renamed' with no nvram file to move; libvirt will create one on next boot.UEFI_CSMVM renames with no warning — it legitimately has no nvram63_f7b_VARS.fd→63_f7b_renamed_VARS.fd,63_f7b_tpm_state→63_f7b_renamed_tpm_stateFound while testing, not patched
vm.deletedoes not remove the TPM state directory either —undefine_domainpassesVIR_DOMAIN_UNDEFINE_NVRAMso libvirt reaps the nvram file, butVIR_DOMAIN_UNDEFINE_TPMis never passed and nothing unlinks the directory. Not theoretical: the 25.10.5 box I tested on carries three orphans from VMs that no longer exist (7_,8_,9_Windows_11_Pro_tpm_state; ids 7/8/9 are not invm.query). NAS-140717 fixed this in the same commit withdelete_vm_state()— happy to fold it in.Scope
Keeps 25.10's plain
os.rename;truenas_os/renameat2/openat2do not exist on this branch, soAT_RENAME_NOREPLACEandRESOLVE_NO_SYMLINKScan't come across. Stale-destination reach is low —vm_vmusessqlite_autoincrement, so ids are not reused.Two further things NAS-140717 changed that this does not: it moved the filesystem work ahead of
datastore.updatewith rollback, and added unit tests for the helper. The ordering is the deeper fix and anything other thanFileNotFoundErrorstill surfaces after the commit here — I kept this to the two user-visible failures rather than restructuringdo_updateon a stable branch, but say the word.