XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    XCP-ng 8.3 updates announcements and testing

    Scheduled Pinned Locked Moved News
    431 Posts 47 Posters 172.4k Views 61 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • semarieS Offline
      semarie @semarie
      last edited by

      SHA`is SHA1. so I assume it is that.
      And it seems to be still accepted in authProtocol parameter.

      1 Reply Last reply Reply Quote 0
      • semarieS Offline
        semarie
        last edited by

        after testing (with net-snmp-utils 5.9.3), I have no problem with snmpv3 and SHA/AES.

        On my testing host, snmpd server (OpenBSD):

        • User: user1
        • auth: AES with password123
        • priv: AES with 321drowssap

        From XCP-ng 8.3, with net-snmp-utils 5.9.3:
        $ snmpbulkwalk -v3 -a SHA -A password123 -l authPriv -x AES -X 321drowssap -u user1 192.168.1.80

        so the net-snmp client itself seems fine with SHA/AES.

        could you share more elements ?

        Mitchel-APDM 1 Reply Last reply Reply Quote 1
        • Mitchel-APDM Offline
          Mitchel-APD @semarie
          last edited by Mitchel-APD

          @semarie Hi,

          Thanks for your help, I just created the user with the net-snmp-create-v3-user command, and definded SHA-256.

          SNMP now works like before.

          net-snmp-create-v3-user -ro -A verrysecureauthenticationpassword-a SHA-256 -X verrysecureprivacypassword--x AES snmpusername
          
          1 Reply Last reply Reply Quote 1
          • A Offline
            abudef
            last edited by

            Hi, it seems that shutting down the host is taking an extremely long time now. I tried it in two different environments; the shutdown process starts but gets stuck on the splash screen for several minutes before finally completing. There were no active virtual machines on the hosts being shut down.

            Does anyone have the possibility to test this in a lab? Thanks!

            gduperreyG R 2 Replies Last reply Reply Quote 1
            • gduperreyG Offline
              gduperrey Vates 🪐 XCP-ng Team @abudef
              last edited by

              @abudef I've updated and rebooted numerous hosts with these updates and haven't noticed any significant slowdowns.

              Do you have any additional information in the logs?

              A 1 Reply Last reply Reply Quote 0
              • M Offline
                MajorP93
                last edited by

                Can also confirm that I was able to apply this round of patches using rolling update method without any issues or slowdowns on a pool of 5 hosts.

                1 Reply Last reply Reply Quote 2
                • A Offline
                  abudef @gduperrey
                  last edited by abudef

                  @gduperrey Restart happens normally, without any noticeable delay, but shutdown takes a long time. Which logs should I specifically check?

                  (It's not a real issue, but I just needed to move servers in the lab and had to shut them down, so I noticed it.)

                  1 Reply Last reply Reply Quote 0
                  • R Offline
                    robertblissitt @abudef
                    last edited by

                    @abudef After the excitement from the last update cycle (see my post above from ~January 29), I kicked off a Rolling Pool Reboot this time before considering a Rolling Pool Update. During this RPR, the first host is currently hanging on its shut down right now after about 10 - 15 minutes as shown in the screenshot. I am running the previous most recent version of XCP-ng, again from January 29, 2026. I'll revisit installing these most recent updates once I get clean reboots. 🙂
                    1ce1d34e-2a48-42fc-943d-86b66c2fd596-image.jpeg

                    M G 2 Replies Last reply Reply Quote 0
                    • M Offline
                      manilx @robertblissitt
                      last edited by manilx

                      @robertblissitt Press ESC and you'll see what's happening

                      1 Reply Last reply Reply Quote 1
                      • G Offline
                        Greg_E @robertblissitt
                        last edited by

                        @robertblissitt

                        Normal for the pool master to take a bit longer but never seen 15 minutes before.

                        1 Reply Last reply Reply Quote 0
                        • gduperreyG Offline
                          gduperrey Vates 🪐 XCP-ng Team
                          last edited by

                          As explained, I haven't observed such a delay on our end during our testing.

                          As Maniix suggests, you can see what's happening by pressing "Esc" to see which step is taking longer.

                          From what I've heard internally, a common reason for this lengthy step is when a shared server was running on a VM and that VM was shut down. The host then takes a very long time to shut down or restart.

                          P 1 Reply Last reply Reply Quote 0
                          • P Offline
                            ph7 @gduperrey
                            last edited by

                            @gduperrey
                            In my homelab I've had the same problem for at least 18 month's
                            when shutting down the XO-VM it hangs for 2-3 minutes when it tries to umount the remotes

                            umount /run/xo-server/mounts/xxxxx (SMB and NFS)
                            umount /run/xo-server/mounts/yyyyy (SMB)
                            

                            I did report this in an earlier thread

                            M 1 Reply Last reply Reply Quote 0
                            • M Offline
                              manilx @ph7
                              last edited by

                              @ph7 This I can confirm, with XO VM.
                              But discussion was about the host....

                              1 Reply Last reply Reply Quote 0
                              • gduperreyG Offline
                                gduperrey Vates 🪐 XCP-ng Team
                                last edited by

                                For XO, I suggest you start a separate thread.

                                Regarding the host issue, without more details or information, it's difficult to say anything at the moment, especially since I haven't been able to reproduce it myself.

                                R 1 Reply Last reply Reply Quote 0
                                • R Offline
                                  robertblissitt @gduperrey
                                  last edited by

                                  @gduperrey Absolutely understand. 🙂 I didn't now about the Escape key as Manilx mentioned. Next time, I will press Esc to see if there is any useful information and report it here. This was just new behavior and wanted to report it informally.

                                  1 Reply Last reply Reply Quote 1
                                  • A Offline
                                    abudef
                                    last edited by abudef

                                    In my case, I gave the command to shut down all hosts, and the master "made it" first. The other hosts then got "stuck" at this point for a very long time:

                                    ad65b000-f778-4ce2-aba2-0ea120457691-image.jpeg

                                    EDIT: Apparently waiting for umount:

                                    2154dd7d-a1a4-4e82-a834-de4cd149041c-image.jpeg

                                    gduperreyG 1 Reply Last reply Reply Quote 1
                                    • gduperreyG Offline
                                      gduperrey Vates 🪐 XCP-ng Team @abudef
                                      last edited by

                                      @abudef In case of a shutdown, I turn off the secondary servers first. Once they are off, I shut down the primary server. This ensures that if the secondary servers have information to send to the primary, they can do so, whereas otherwise, they can wait to shut down.

                                      In case of a pool reboot, I reboot the primary server first, and once it is accessible, I reboot the secondary servers.

                                      A 1 Reply Last reply Reply Quote 1
                                      • A Offline
                                        abudef @gduperrey
                                        last edited by

                                        @gduperrey Of course, the order matters. Now everything seems to be clear.

                                        1 Reply Last reply Reply Quote 1
                                        • gduperreyG Offline
                                          gduperrey Vates 🪐 XCP-ng Team
                                          last edited by gduperrey

                                          New security and maintenance update candidate for you to test!

                                          A new security vulnerability, XSA-480, has been detected and fixed for xen.


                                          Security updates

                                          • xen: A vulnerability has been discovered on x86 Intel systems with EPT support, where unintended host or guest memory regions can be accessed from a VM's memory cache under any workload. This can lead to privilege escalation, denial of service (DoS) attacks affecting the entire host, or information leaks.
                                            On XCP-ng 8.3, x86 HVM/PVH VMs can leverage this vulnerability.
                                            There are no mitigations.

                                          A VSA was also published by our security team: https://docs.vates.tech/security/advisories/2026/vates-sa-2026-005/

                                          Maintenance updates

                                          We are taking this opportunity to release an update for ipmitool following some feedback from our users regarding the display of an error message in Xen-Orchestra, with certain models of DELL servers, in relation to the command ipmitool lan print.

                                          Test on XCP-ng 8.3

                                          yum clean metadata --enablerepo=xcp-ng-testing,xcp-ng-candidates
                                          yum update --enablerepo=xcp-ng-testing,xcp-ng-candidates
                                          reboot
                                          

                                          The usual update rules apply: pool coordinator first, etc.

                                          Versions:

                                          • ipmitool: 1.8.19-11.2.xcpng8.3
                                          • xen: 4.17.6-5.1.xcpng8.3

                                          What to test

                                          Normal use and anything else you want to test.

                                          Test window before official release of the updates

                                          ~2 days

                                          F A 2 Replies Last reply Reply Quote 3
                                          • F Offline
                                            flakpyro @gduperrey
                                            last edited by

                                            @gduperrey No issues to report on my test systems.

                                            1 Reply Last reply Reply Quote 3

                                            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                            With your input, this post could be even better 💗

                                            Register Login
                                            • First post
                                              Last post