October 2026 Updates #1 for XCP-ng 8.3 LTS
New updates are available for XCP-ng 8.3 LTS.
Host reboots are necessary after this update.
XCP-ng's updates are cumulative, so applying updates now will also apply any previous updates that weren't applied to your hosts. Update advisories: https://xcp-ng.org/blog/tag/update/.
Summary
This batch covers many areas, so here is an overview before the details.
Storage migration is much faster (2 to 2.5 times in some of our tests), and performance also improves for large virtual disks in the QCOW2 format.
The storage stack also receives reliability fixes. They cover virtual disk operations, the change tracking used by backups, shared storage over NFS and iSCSI, and XOSTOR, whose LINSTOR database is now backed up automatically.
For Windows VMs, new guest tools fix a data corruption issue that could occur during some snapshots and backups, and bring a new guest agent. We recommend updating the guest tools in your Windows VMs, and switching to these XCP-ng guest tools in VMs that use the compatible XenServer tools.
On the maintenance side, OpenSSL moves to its current long-term support version.
Other changes improve hardware support, for example for some Microsemi (Adaptec) RAID controllers, and XO Lite, the web interface embedded in each host, gets new necessary features such as creating networks.
Precautions before or after the update
As detailed below:
- The text identifiers of the Almalinux VM templates have changed. If you have automation assuming that they were stable, please take this into consideration.
- We invite you to verify some settings on Windows VMs which were created from the "Other Install Media" template, manually or during V2V migration. See further below.
Performance
Live storage migration accelerated
Live storage migration, which moves the virtual disks of a running VM to another storage repository, is much faster with this update. Data is now written to the destination several blocks at a time, instead of waiting for each write to complete before sending the next one.
How much faster depends on many factors, such as the speed of the source and destination storage, the network between them, and the load on the hosts. In some production-like setups, we measured migrations 2 to 2.5 times faster than before. One of the testers on our forum also described the acceleration as "really dramatic".
Enhanced performance for QCOW2 disks, in particular large ones
This update improves the performance of QCOW2-backed disks, especially big ones, by increasing the size of the QCOW2 metadata cache in tapdisk, the control domain process that handles the I/O of each virtual disk. QCOW2 disks rely on metadata tables to locate each block of data. When the cache is too small to hold the tables of a big disk, tapdisk has to read them from storage more often, which slows down I/O.
Windows Guest Tools 9.2.385
The guest tools ISO provided with XCP-ng now contains XCP-ng Windows Guest Tools 9.2.385, instead of version 9.1.200.
This release fixes a data corruption issue that could occur during in-memory snapshots and backups. For this reason, we recommend updating the guest tools in your Windows VMs, and also recommend to switch to these guest tools if still using XenServer's guest tools in VMs. If you have many of them, you can deploy the update with Group Policy, as explained in this guide.
Compared to 9.1.200, it also brings the overhauled Windows guest agent introduced with version 9.2.350.
Notable changes:
- Guest IP addresses can now be configured from the host, using
xe vif-configure-ipv4andxe vif-configure-ipv6. - The session agent gains a tray icon and an About dialog. It can be disabled if you prefer.
- Better network stability under high load, and storage driver fixes.
- Reliability and stability fixes for the drivers and the guest agent.
Storage
Fixes
This update also brings fixes across the storage stack.
Several of them concern QCOW2 disks and coalescing, the operation that merges a virtual disk with its parent, typically after a snapshot has been deleted. They address cases where tapdisk could crash or stop processing a VM's requests, and cases where a failed or interrupted coalesce could leave the disk chain or the SR in a bad state.
Two fixes concern Changed Block Tracking (CBT), which backups use to read only the blocks that changed. On shared file-based SRs, such as NFS, a disk running on a host other than the pool master could lose its CBT data. On shared LVM-based SRs (iSCSI, HBA), when a disk was activated on a host other than the pool master and its CBT log had to be deleted, the SR's LVM metadata could be damaged.
For hosts using NFS SRs, this update also fixes potential deadlocks in the NFS client of the control domain's kernel.
iSCSI operations are more reliable, especially with many LUNs and multipath connections. Concurrent operations could fail when creating or updating disks on iSCSI SRs, and in some cases block the iSCSI operations that followed.
A few smaller fixes improve error handling and reduce log noise.
XOSTOR
This update adds automatic backups of the LINSTOR database and fixes a few issues.
- To help recover from a possible LINSTOR database corruption, the database is now backed up regularly and after every major operation. Backups are stored locally on the pool master and on the DRBD volume that holds the LINSTOR database.
- Fix SR creation when a volume group is missing on one of the hosts. An update of the LINSTOR packages had changed their behaviour and broken this case. We're expanding our test suite to catch this kind of issue in the future.
- Fix the creation of RAW volumes.
- A missing LINSTOR resource definition is now reported with an explicit message instead of an unreadable trace.
Control plane (XAPI)
XAPI is XCP-ng's control plane. Here's what changed in this update.
Aside from the storage migration improvements mentioned above, xapi now offers a VM option that can help avoid a specific class of issues when passing through some AMD GPUs. Please follow this documentation guide for details. We are working on automatically toggling this option for VMs in the safe cases in a future update.
Virtualization & System
VM templates
- Viridian is now disabled by default in the "Other install media" template. As a reminder, Windows VMs must be created from Windows templates, which enable Viridian along with the other settings Windows needs. This change only affects VMs created from this templates from now on, and existing VMs are not modified.
However: if some of your Windows VMs were created with "Other install media" in the past (for example, when importing them from another hypervisor), check that Viridian is enabled on them. Without it, you may run into poor performance or odd Windows issues. Our documentation explains how to check and fix this. Note that some important Viridian settings can't be set from Xen Orchestra yet, so we recommend usingxe. - Our own AlmaLinux 8, 9 and 10 templates were replaced by the ones XenServer now provides.
- Their names don't change, but their UUIDs and reference labels do (
almalinux-8becomesalma-8, and so on). If some of your automation refers to these templates by UUID or reference label, please update it. - New AlmaLinux 8 and 9 VMs now use UEFI firmware by default, instead of BIOS.
- Their names don't change, but their UUIDs and reference labels do (
- Existing VMs are not affected. You may have to restart Xen Orchestra for it to show the updated list of templates.
- The Kylin Linux 7 template was removed, in sync with XenServer.
OpenSSL 3.5
OpenSSL, the cryptography library used by XAPI, stunnel, SSH and many other components of the control domain, was updated from 3.0.9 to 3.5.5, the current long-term support branch of OpenSSL. It includes the bug and security fixes released by OpenSSL since version 3.0.9 (see its changelog), and we added patches for CVE-2026-7383 and CVE-2026-34180.
Other changes
- On NVMe controllers exposing multiple namespaces, the
/dev/disk/by-id/nvme-<model>_<serial>symlinks could point to any of the namespaces. They now always point to namespace 1, and new symlinks that include the namespace number (nvme-<model>_<serial>_<namespace>) are created for each namespace. Most NVMe drives expose a single namespace and are not affected. If you split NVMe drives into several namespaces and refer to one by itsnvme-<model>_<serial>name (for example, to pass a disk through to a VM), check what it points to after the update, and prefer the new per-namespace names. - The
openvswitchpackage no longer installs the unusedopenvswitch-cfg-updateXAPI plugin, which was superseded long ago byopenvswitch-config-update. It's only meant to avoid confusion, and there's no functional change.
Drivers
Microsemi (Adaptec) RAID controllers
The out-of-tree aacraid driver we provided has issues with some controllers, which the in-tree driver handles better. It was also missing patches from upstream and hadn't been updated for a while. We tried to patch it, but that didn't solve all of its issues. So we're making the in-tree driver, which XCP-ng 8.2 was using, the default again.
Where the out-of-tree driver works fine, there's no reason to change anything. This update doesn't remove it from hosts where it is installed, so they keep using it, and no action is required. The in-tree driver will be the default on the next installation ISOs.
If you run into issues with your controller, you can switch a host to the in-tree driver: remove the out-of-tree driver with yum remove microsemi-aacraid, then reboot the host. Some controllers may require the aacraid.numacb=1000 kernel parameter with the in-tree driver. We don't have these controllers in our labs, so feedback from their users is welcome on the forum.
User interface
XO Lite 0.25.0
XO Lite, the management interface embedded in every XCP-ng host, was updated to version 0.25.0:
- Create networks, bonded networks and internal networks from the pool's network view.
- Rescan a host's physical network interfaces (PIFs).
- A new VDIs page for VMs, with a table and a side panel.
- VM actions are now available from the tree view.
- Various visual fixes.
See you in the next update announcement!