XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    XCP-ng 8.3 updates announcements and testing

    Scheduled Pinned Locked Moved News
    636 Posts 55 Posters 503.3k Views 75 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      andersonalipio
      last edited by andersonalipio

      Ran into some issues with sdncontroller.py (XCP-ng 8.3 and xcp-ng-xapi-plugins-1.16.0-1) when creating traffic rules on VLAN VIFs (and networks) in XOA — same error on both Premium and Community. The problem turned out to be a line feed sent by XOA.

      On line 236 of sdncontroller.py, I added a fix that solved the problem, and it now works perfectly managing traffic rules in XO on VLAN networks:

      def update_args_from_ovs(args):
          # FIX: strip line feed (\n \X0a) sent by Xen Orchestra
          args["bridge"] = str(args["bridge"]).strip()
          # get parent...
      

      I had another problem when adding rules on networks that weren't connected on all hosts, because those hosts didn't have VMs running on that network (default). Manually connecting them worked fine.

      I think it's more of an XO error than xapi plugin, but worked ok in my case.

      Thanks for the great work!

      bleaderB 1 Reply Last reply Reply Quote 0
      • olivierlambertO Offline
        olivierlambert Vates 🪐 Co-Founder CEO
        last edited by

        Ah good catch @andersonalipio ! We'll check that 🙂

        Ping @Team-XAPI-Network

        1 Reply Last reply Reply Quote 0
        • semarieS Offline
          semarie Vates 🪐 XCP-ng Team XAPI & Network Team @marcoi
          last edited by

          @andersonalipio I would be interested to get some elements from your installation.

          • your /var/log/sdn-controller-plugin.log file (on the host) in order to check the parameter passed by XO.
          • output of xe network-param-list uuid=$UUID (for the network concerned) or xe network-list params=all (if uuid is unknown)
          • output of xe pool-list params=other-config (for xo:sdn-controller:* elements)
          • output of xe vif-list params=uuid,network-uuid,other-config (for xo:sdn-controller:* elements)

          Feel free to share it privately via PM if you prefer, possibly using https://paste.vates.tech/ .

          Cc @Team-XO-Backend too (as it could be from XO side)

          A 2 Replies Last reply Reply Quote 0
          • bleaderB Offline
            bleader Vates 🪐 XCP-ng Team @andersonalipio
            last edited by

            @andersonalipio can you also share the XOA version you're running? @semarie did a bunch of improvement on lifecycle of hosts and VM at some point XO side.

            A 1 Reply Last reply Reply Quote 0
            • A Offline
              andersonalipio @semarie
              last edited by

              @semarie I'll do it as soon as I get access to the server, hopefully tomorrow.

              1 Reply Last reply Reply Quote 0
              • A Offline
                andersonalipio @bleader
                last edited by

                @bleader XOA 6.7 premium (updated last friday - latest channel), as all updates on XCP-ng 8.3 from latests available updates on same day (not testing, ci or other repos)

                1 Reply Last reply Reply Quote 0
                • A Offline
                  andersonalipio @semarie
                  last edited by

                  @semarie sorry for the delay.

                  @semarie said:

                  your /var/log/sdn-controller-plugin.log file (on the host) in order to check the parameter passed by XO.
                  MASTER_sdn-controller-plugin.txt

                  @semarie said:

                  output of xe network-param-list uuid=$UUID (for the network concerned) or xe network-list params=all (if uuid is unknown)
                  uuid ( RO) : 250cec4e-d7af-23c5-be1c-391186bde2f4
                  name-label ( RW): VLAN VDI INT - 102
                  name-description ( RW): VLAN Rede VDI Interna VMs
                  VIF-uuids (SRO): 9f23be5a-a6f5-f64d-e004-4a432aded733; b9f85e54-cfd0-6546-edac-ba1573f00bc5; 16bfa5e3-4022-7c9e-ef43-735599b9b5f2; 418fc7cb-ab9c-23db-8bad-7854cb16cbcb; b9dfc5b9-560e-38ac-941a-f744b0d741d8; af16b830-1d31-c664-d70c-a6d1c7ce3056; 3596ec8a-d0ee-2468-d6ae-16b66c745d03; 181808cf-1c42-ddcb-13b5-3bf5f4483a3f; 0c576952-b1f1-95db-1a7e-fc8f581a46e3; b2b8da93-f07f-32a4-1ae1-ae2eac13da08; 9c96d442-e782-774a-ac98-858fcce36607; f512706b-f1a3-767d-6941-ed0f6c926291; c5f2e0b1-a8d2-4846-521a-54b790d6d849; 82b9789c-cf69-6382-e6cc-95ef67b0ba2e; 967ecb88-a141-cd17-c45f-9f5a779efbca; 7445be42-7b30-7a61-f3a1-6aadb725be6a; aa2e03aa-dc9c-aff3-d8cb-5c652af62958; dd596564-a3b4-e15f-69cf-2af5d128a8c2; 767a2bae-8ff0-45fd-339f-56a955ed1ada; e5c85ad8-4bc1-f8b6-6c31-ca6f48604920; d30dfed6-ba5c-04f8-bbc6-ddc18414737e; cddb92fd-da90-cce1-620c-c31469dccada; da4421fa-0bb5-525b-544e-f03e6fbce04b; 947932f8-4bf6-204f-d112-0b251ac4abae; b5bdddd6-2908-ec1f-4a2d-a2b12cf36ee8; 0601ff52-51c9-72de-7dba-071d016473fd; 49739db0-2055-9a4b-fe22-027f5b7ceac0; e0e7fa88-1d3c-05f3-1cc9-cf6e08aa8294; 82b7a17e-2164-caec-90ba-2640a737897b; bda96371-0222-2919-d128-94f1e118a411; ca3e3dee-40da-b1c3-77ce-9b4640511151; 8241bab2-ab2a-228e-24ca-914a80d1cacc
                  PIF-uuids (SRO): fef83dfe-5a02-50b6-12a3-0fed1189acaf; de48ed20-e0d2-ab4d-c2b3-7857110e0f6a; 4014506f-75ff-800b-3bde-d49196f39bf7; 29d6c11e-d149-b54a-6cf5-d41af778cd50; c064f9cb-018d-d5a3-12d1-29a6050118d8; 4dffbd1d-2bcb-1d85-b029-1bc4366ef4ad; f81b260a-88ed-2c7f-b87d-ea1bcb830e69; 5deeb719-799b-2752-a1dd-5788b94c0f21; 5d7761a3-8ebd-fb60-8568-6a7129bef180; 74943f3a-bacc-bfb3-3efa-b66423fa0604; c4b64326-3c78-c7ac-0535-22aa0e2b0e62; d2f68f7a-a32a-f84d-9162-71f18d7b35ec
                  MTU ( RW): 1500
                  bridge ( RO): xapi3
                  managed ( RO): true
                  other-config (MRW): xo:sdn-controller:of-rules: ["{"allow":true,"protocol":"IP","ipRange":"172.22.146.126/32","direction":"from/to","cookie":"0xd3d2533ed26a8151"}","{"allow":true,"protocol":"IP","ipRange":"172.22.146.119/32","direction":"from/to","cookie":"0xa9b47fab93762ad1"}","{"allow":true,"protocol":"IP","ipRange":"172.22.146.120/30","direction":"from/to","cookie":"0x20b7928056a3e208"}","{"allow":true,"protocol":"IP","ipRange":"172.22.146.124/32","direction":"from/to","cookie":"0x67d0c4dc2d9fd8a9"}","{"allow":false,"protocol":"IP","ipRange":"0.0.0.0/0","direction":"from/to","cookie":"0xd191b1374733bc1a"}"]; automatic: false
                  blobs ( RO):
                  tags (SRW):
                  default-locking-mode ( RW): unlocked
                  purpose (SRW):

                  @semarie said:

                  output of xe pool-list params=other-config (for xo:sdn-controller:* elements)
                  xo:sdn-controller:of-method: xapi-plugin; xo:sdn-controller:of-format: xapi-plugin; auto_poweron: true;

                  @semarie said:

                  output of xe vif-list params=uuid,network-uuid,other-config (for xo:sdn-controller:* elements)

                  this output is pointless because our current rules are on network, not on VIF anymore.

                  bleaderB 1 Reply Last reply Reply Quote 0
                  • bleaderB Offline
                    bleader Vates 🪐 XCP-ng Team @andersonalipio
                    last edited by

                    @andersonalipio Let's continue the discussion with @semarie in a separate thread

                    1 Reply Last reply Reply Quote 0
                    • gduperreyG Online
                      gduperrey Vates 🪐 XCP-ng Team
                      last edited by

                      Hello,

                      We have just made "refreshed" XCP-ng installation ISOs available for everyone; these include all updates released over the past year, up to the present day.

                      You can read the blog post here: https://xcp-ng.org/blog/2026/08/14/xcp-ng-8-3-lts-refreshed-installation-isos/

                      1 Reply Last reply Reply Quote 0
                      • glehG Offline
                        gleh Vates 🪐 XCP-ng Team @rzr
                        last edited by gleh

                        New maintenance update candidates for XCP-ng 8.3 LTS

                        This release batch contains mostly fixes, tool version updates, and some improvements.

                        What changed

                        Virtualization & System

                        • kernel:

                          • Reliability fixes for CVE-2026-45840 and CVE-2026-53227.
                          • On some systems, PCIe expansion cards connected to a hotplug-capable PCI bus might not be seen at boot time. This release fixes such systems.
                          • Fixed CVE-2026-64600, also known as RefluXFS. By default, XCP-ng doesn’t use XFS; when an XFS SR is used, we consider the LPE risk low, but fixed it anyway as a defence-in-depth measure.
                        • xen:

                          • Synchronization with XenServer release 4.17.6-12:
                            • Various XSA fixes that were already included in XCP-ng previous releases are now part of this XS release.
                            • It also brings fixes for possible bugs and crashes.
                          • Fix bug causing UEFI logic to set inappropriate screen resolutions.
                        • edk2: Add XCP-ng branding to the UEFI VM boot logo

                        • varstored and xcp-efivar-utils:

                          • Sync with XenServer 1.3.4-2.
                          • Group existing EFI helper scripts into a shared package xcp-efivar-utils.
                          • Update dbx hashes from secureboot_objects v1.6.5.
                        • xcp-emu-manager: Stability fixes for aborting live migration and pausing a migrated VM to finalize the migration.

                        • xcp-ng-generic-lib: Fix build that was failing because of cmake3 update

                        Control Plane

                        • xapi:

                          • Improve error reporting when pool join fails on TLS verification
                          • Disallow PCI passthrough for boot devices, which would break dom0 boot
                          • Add DHCP setting for VIF IP configuration, currently only supported by the Windows guest agent
                          • Allow selecting image format (VHD, QCOW2) for VDIs during migration
                          • Ensure the xapi database is flushed when shutting down
                          • Add VLAN filtering support in XAPI.
                          • Reuse sessions of storage backends, reducing the load on the database
                          • Fixed cross-pool migration being blocked for VMs that couldn't be booted on the sender pool
                          • Fixed wrong task timeout calculation for VMs with a large number of VBDs (and similar multi-part tasks)
                        • xcp-ng-xapi-plugins:

                          • in sdncontroller.py plugin, fix dump-flows command when calling it against VLAN interface.
                          • in sdncontroller.py plugin, fix add-rule command in edge case (error out instead of cleanly quit).
                        • xsconsole:

                          • Retry the xapi connection instead of latching it broken forever
                          • Add the option not to rename the management interface when performing an emergency network reset
                          • Reset the old management interface IP configuration when switching to a new interface with the same IP address

                        Storage

                        • blktap: Fixes and log improvement

                          • Stabilization fixes on qcow2 release:
                            • Fix a potential deadlock on VDI export.
                            • Fix a potential crash that could be invisible to the user because it could happen on the VDI close.
                            • Fix a wrong VDI statistics computation.
                          • tap-ctl commands now displays clear and parsable error messages.
                        • sm: Storage driver performance and stability have been significantly improved (QCOW2),

                          • Drivers improvements + perf:
                            - Add live leaf coalesce support for QCOW2 to avoid bump in size error.
                            - Improve performance of scan on LVMSR with QCOW2 VDIs.
                            - Reduce read cost of FileSR VDI allocated size during scan. Speed improvement for QCOW2: x10.
                          • Drivers misc:
                            • Robustify drivers: they have now an internal supported image format list.
                            • Preserve image-format field during resize on FileSR.
                            • Fix wrong data in LVMSR MGT: always store snapshot UUID instead of OpaqueRef.
                            • Fixed a wrongful termination of the GC when having multiple openers of chain of VHD.
                          • LINSTOR:
                            • Improve LINSTOR perf: don't load VDIs during VDI.deactivate call.
                            • Fix a bad LINSTOR snap rollback caused by a journaler race condition.
                            • Improve performance of the LINSTOR Journaler by using the existing connection to the controller to avoid re-parsing the URI.
                            • Fix a race condition in LINSTOR SR when trying to perform a snapshot while the same VDI is currently coalescing
                          • To help recovering from a LINSTOR database corruption, it is now backed up regularly and after every major operation, locally on the master, and on the replicated LINSTOR database device.
                          • Upstream changes:
                            • Ignore LVM VDI missing from VGs and XAPI: prevent abort during scan.
                            • SCSI volumes: resolve device names correctly using canonical device path(s). Some volumes were not resolved correctly.
                            • Explain errors when a LUN cannot be resized.
                            • Code optimization and cleanup.
                            • Ignore LVM VDI missing from VGs and XAPI: prevent abort during scan.
                            • SCSI volumes: resolve device names correctly using canonical device path(s). Some volumes were not resolved correctly.
                            • Explain errors when a LUN cannot be resized.
                            • Code optimization and cleanup.
                            • Improved handling of wrongful metadata stored on VDI following an error.
                            • Robustified tapdisk pause mechanism.

                        Regarding this sm update, please check whether the SM logs show any crashes related to the GC, particularly on NFS SRs, and send us these logs if there are any issues.

                        Network

                        • ca-certificates: Refresh root certificates to connect to third parties depending on Certificate Authorities.

                        • krb5: The Kerberos 5 library has been updated to improve GSSAPI compatibility to prepare upcoming packages upgrade (and to satisfy XS-8.4 migration).

                        • libreswan: Addressed DoS vulnerabilities (CVE-2026-12413, CVE-2026-50721, CVE-2026-50722) in encrypted Global Private Networks. Exposure appears minimal for XCP-ng environments, as OVS handles the underlying Libreswan orchestration directly.

                        • openssh: Fix regression and apply security patches.

                          • Custom OpenSSH configurations will now be applied (custom rules are placed in /etc/ssh/sshd_config.d/. The files must end with .conf suffix)
                          • Five minor security flaws have been fixed in OpenSSH:
                            • CVE-2025-32728: A logic error was fixed regarding cases where x11_forwarding is disabled.
                            • CVE-2025-61984: Checks for forbidden characters have been tightened.
                            • CVE-2025-61985: A specific character has been disallowed in URL-encoded strings.
                            • CVE-2026-35385: The behavior when using scp with -O (without -p) has been corrected to prevent privilege escalation.
                            • CVE-2026-35388: The behavior regarding "ask/autoask" or ssh -O proxy ... has been corrected.
                        • p11-kit: - Updated library to prepare upcoming packages upgrade.

                        UI

                        • xo-lite: Update to 0.24.0-1
                          • [System] Update system pages layout (user feedback) (PR #9746)

                          • Introduce robots.txt for avoid browser indexing (PR #9858)

                          • Update the UiTitle component to use the one from web-core (PR #9869)

                          • [Pool/System] Add Reboot VM on internal shutdown in pool's system tab (PR #9962)

                          • Update the UiCard component to use the one from web-core (PR #9980)

                          • Update the UiCardTitle component to use the one from web-core (PR #9982)

                          • Replacement of the UiSeparator component with VtsDivider from web-core (PR #10017)

                          • Update side panels (PR #9836)

                          • [XOA deploy] Update log visualization component (PR #9995)

                          • [SidePanels] Add and use new VtsCardObjectTitle component to display object title and ID in side panels (PR #9755)

                          • Replacement of the UiSpinner component with UiLoader from web-core (PR #10023)

                          • [Pool,Host/Storage] Add Storage tabs (PR #10005)

                          • [Host/dashboard] Switch CPU and RAM panels order to match Pool dashboard layout (PR #10059)

                          • Remove all "coming soon" disabled button placeholders from network, VM, and pool components (PR #10068)

                          • [VM/Network] add possibility to “connect/disconnect” a VIF on a VM (PR #10080)

                          • [Pool/networks] Add the possibility to copy information from one or more networks in JSON format (PR #10083)

                          • Fix some design inconsistency between pages (PR #10109)
                            Update of the xo-lite RPM to version 0.23.0 at the request of the XO team.

                          • [System] Update system pages layout (user feedback) (PR #9746)

                          • Introduce robots.txt for avoid browser indexing (PR #9858)

                          • Update the UiTitle component to use the one from web-core (PR #9869)

                          • [Pool/System] Add Reboot VM on internal shutdown in pool's system tab (PR #9962)

                          • Update the UiCard component to use the one from web-core (PR #9980)

                          • Update the UiCardTitle component to use the one from web-core (PR #9982)

                          • Replacement of the UiSeparator component with VtsDivider from web-core (PR #10017)

                          • Update side panels (PR #9836)

                          • [XOA deploy] Update log visualization component (PR #9995)

                          • [SidePanels] Add and use new VtsCardObjectTitle component to display object title and ID in side panels (PR #9755)

                          • Replacement of the UiSpinner component with UiLoader from web-core (PR #10023)

                          • [Pool,Host/Storage] Add Storage tabs (PR #10005)

                        Drivers and Middleware

                        • amd-microcode: Update to 2026-05-19 drop as redistributed by XenServer. Updated CPUs:

                          • BRH-C1 00b00f21: 2025-10-17, rev 0b002161 -> 2025-10-17, rev 0b002162
                          • BRHD-B0 00b10f10: 2025-10-17, rev 0b101058 -> 2025-10-17, rev 0b101059
                        • qlogic-fastlinq-alt_8_42: If encountering issue with the current driver versions (main or alt ones) on some older hardware, this alt_8_42 package is based on an older source version can be tested for better results.

                        Others

                        • bash: No impact on usability, just for packaging facilities
                        • gmp: Updated library to prepare upcoming packages upgrade.
                        • redhat-lsb: Align to XS: Drop unused sub packages
                        • zlib: No impact on usability, just for packaging facilities

                        Versions

                        • amd-microcode: 20251203-1.1.xcpng8.3 -> 20260519-1.1.xcpng8.3
                        • bash: 4.2.46-30.el7 -> 4.2.46-30.1.xcpng8.3
                        • blktap: 3.55.5-9.1.xcpng8.3 -> 3.55.5-9.3.xcpng8.3
                        • ca-certificates: 2021.2.50-72.el7_9 -> 2021.2.50-73.1.xcpng8.3
                        • edk2: 20220801-1.7.11.1.xcpng8.3 -> 20220801-1.7.11.2.xcpng8.3
                        • gmp: 6.0.0-15.el7 -> 6.2.1-8.1.xcpng8.3
                        • gpumon: 24.1.0-91.1.xcpng8.3 -> 24.1.0-96.1.xcpng8.3
                        • kernel: 4.19.19-8.0.46.6.xcpng8.3 -> 4.19.19-8.0.46.10.xcpng8.3
                        • krb5: 1.15.1-22.1.xcpng8.3 -> 1.21.3-4.1.xcpng8.3
                        • libreswan: 4.12-2.3.2.xcpng8.3 -> 4.12-2.3.3.xcpng8.3
                        • ocaml: 4.14.2-1.xcpng8.3 -> 4.14.4-1.xcpng8.3
                        • ocaml-findlib: 1.9.8-1.xcpng8.3 -> 1.9.8-1.1.xcpng8.3
                        • opam: 2.4.1-1.1.xcpng8.3 -> 2.5.2-1.1.xcpng8.3
                        • openssh: 9.8p1-1.2.4.xcpng8.3 -> 9.8p1-1.2.6.xcpng8.3
                        • p11-kit: 0.23.5-3.el7 -> 0.24.1-4.xcpng8.3
                        • perl-Archive-Tar: 1.92-3.el7
                        • qlogic-fastlinq-alt_8_42: 8.42.10.0-2.xcpng8.3
                        • redhat-lsb: 4.1-27.el7.centos.1 -> 4.1-28.2.1.xcpng8.3
                        • sm: 3.2.12-17.9.xcpng8.3 -> 3.2.12-23.4.xcpng8.3
                        • varstored: 1.3.2-2.1.xcpng8.3 -> 1.3.4-2.1.xcpng8.3
                        • xapi: 26.1.11-1.3.xcpng8.3 -> 26.1.16-1.1.xcpng8.3
                        • xcp-efivar-utils: 1.0.0-1.xcpng8.3
                        • xcp-emu-manager: 1.2.0-2.xcpng8.3 -> 1.2.1-2.xcpng8.3
                        • xcp-featured: 1.2.1-2.xcpng8.3 -> 1.2.1-4.xcpng8.3
                        • xcp-ng-generic-lib: 1.1.1-4.xcpng8.3 -> 1.1.1-5.xcpng8.3
                        • xcp-ng-xapi-plugins: 1.16.0-1.xcpng8.3 -> 1.17.0-1.xcpng8.3
                        • xen: 4.17.6-9.3.1.xcpng8.3 -> 4.17.6-12.2.xcpng8.3
                        • xo-lite: 0.21.0-1.xcpng8.3 -> 0.24.0-1.xcpng8.3
                        • xs-opam-repo: 6.99.0-1.4.xcpng8.3 -> 6.99.0-1.5.xcpng8.3
                        • xsconsole: 11.0.9.1-1.1.xcpng8.3 -> 11.0.9.1-1.3.xcpng8.3
                        • zlib: 1.2.7-17.el7 -> 1.2.7-17.1.xcpng8.3

                        Test on XCP-ng 8.3

                        yum clean metadata --enablerepo=xcp-ng-testing,xcp-ng-candidates
                        yum update --enablerepo=xcp-ng-testing,xcp-ng-candidates
                        reboot
                        

                        The usual update rules apply: pool coordinator first, etc.

                        What to test

                        As usual, normal use and anything else you want to test.

                        Regarding this sm update, please check whether the SM logs show any crashes related to the GC, particularly on NFS SRs, and send us these logs if there are any issues.

                        Test window before official release of the updates

                        ~ 4 days

                        We would like to thank users who shared feedback since our last call for testing:

                        @Andrew, @JeffBerntsen, @MajorP93, @TrapoSAMA, @acebmxer, @andersonalipio, @flakpyro, @marcoi

                        M 1 Reply Last reply Reply Quote 6
                        • M Online
                          MajorP93 @gleh
                          last edited by

                          @gleh Wow! This sounds like a big release especially in the QCOW2 / storage department.
                          A huge thanks to the whole XCP-ng team!
                          The platform keeps improving and improving which is awesome to see.

                          I will test this batch of packages next week when my test environment is available again.

                          Best regards

                          1 Reply Last reply Reply Quote 1

                          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                          With your input, this post could be even better 💗

                          Register Login
                          • First post
                            Last post