XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    XCP-ng 8.2 updates announcements and testing

    Scheduled Pinned Locked Moved News
    703 Posts 67 Posters 1.1m Views 86 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      ravenet @gduperrey
      last edited by

      So far fine on an epyc 7002 and a xeon e5 v3

      1 Reply Last reply Reply Quote 3
      • A Offline
        Andrew Top contributor @gduperrey
        last edited by

        @gduperrey Installed on several old and new Intel machines. Working as expected.

        1 Reply Last reply Reply Quote 3
        • gskgerG Offline
          gskger Top contributor @gduperrey
          last edited by

          Updated my playlab and nothing to report. Looks good.

          1 Reply Last reply Reply Quote 3
          • stormiS Offline
            stormi Vates 🪐 XCP-ng Team
            last edited by

            New security update candidate (kernel)

            The linux kernel in XCP-ng's domain control is being updated to fix vulnerabilities which may allow a guest to crash to host or make it unresponsive. Even without a malicious attacker, users had reported such issues triggered by the Qlogic/Broadcom netxtreme 2 and the Cisco enic drivers.

            It also contains two fixes for issues that were debugged by the XCP-ng developers and the user community, and reported to XenServer developers at the time:

            • Samba shares failing to reconnect after an unexpected disconnection.
            • Display issue with Intel NUCs and other hardware, due to a bug in EFI Framebuffer support.

            Test on XCP-ng 8.2

            From an up to date host:

            yum clean metadata --enablerepo=xcp-ng-testing
            yum update kernel --enablerepo=xcp-ng-testing
            reboot
            

            Versions:

            • kernel: 4.19.19-7.0.15.1.xcpng8.2

            What to test

            Normal use and anything else you want to test. The closer to your actual use of XCP-ng, the better.

            Test window before official release of the updates

            ~2 days.

            gskgerG A 3 Replies Last reply Reply Quote 1
            • olivierlambertO Offline
              olivierlambert Vates 🪐 Co-Founder CEO
              last edited by

              Tested and working it on my local EPYC box 🙂

              1 Reply Last reply Reply Quote 1
              • gskgerG Offline
                gskger Top contributor @stormi
                last edited by

                Same on my playlab. Updated both hosts and no issues so far.

                1 Reply Last reply Reply Quote 1
                • J Offline
                  JeffBerntsen Top contributor
                  last edited by

                  Both sets of updates installed and tested in my lab with no problems so far.

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    Andrew Top contributor @stormi
                    last edited by

                    @stormi Running both updates on everything. The 64 bit EFI console on the NUCs works for me with this kernel update.

                    If you (anyone) is using one of my NUC Test ISO install images then the EFI console will work with the update but the i225/r8125 network may not. To fix that issue, make sure you have installed the network PACKAGE and not just the ISO install. My test ISO installer may not have fully installed the needed package. Download and install the network driver BEFORE the kernel update. If it's too late then you can use a USB stick to just copy the RPM files and install them after the update.

                    It does not hurt to reinstall the r8125 or the IGC drivers anyway. login to XCP, download driver, install (remove very old driver if there is an error):

                    wget http://users.ntplx.net/~andrew/xcp/r8125-module-9.009.02-2.xcpng8.2.x86_64.rpm
                    yum install ./r8125-module-9.009.02-2.xcpng8.2.x86_64.rpm
                    
                    wget http://users.ntplx.net/~andrew/xcp/igc-module-5.10.146-2.xcpng8.2.x86_64.rpm
                    yum remove intel-igc-5.10.108-1.xcpng8.2.x86_64
                    yum install ./igc-module-5.10.146-2.xcpng8.2.x86_64.rpm
                    
                    1 Reply Last reply Reply Quote 1
                    • A Offline
                      Andrew Top contributor @stormi
                      last edited by

                      @stormi I do see this now at boot (related to netdata):

                      [   49.028835] xenstat.plugin[1818]: segfault at 80 ip 000000000040378a sp 00007ffc4f4278a0 error 4 in xenstat.plugin[400000+8000]
                      [   49.028842] Code: f4 ff ff 41 b8 68 5d 40 00 b9 d4 00 00 00 ba 30 5f 40 00 be d8 52 40 00 bf 8b 4f 40 00 31 c0 45 31 e4 e8 a9 04 00 00 4c 89 e3 <48> 8b 9b 80 00 00 00 48 85 db 0f 85 be f4 ff ff
                      e9 b7 f7 ff ff 8b
                      
                      stormiS 2 Replies Last reply Reply Quote 0
                      • stormiS Offline
                        stormi Vates 🪐 XCP-ng Team @Andrew
                        last edited by stormi

                        @Andrew It never happened before?

                        1 Reply Last reply Reply Quote 0
                        • stormiS Offline
                          stormi Vates 🪐 XCP-ng Team @Andrew
                          last edited by stormi

                          @Andrew said in Updates announcements and testing:

                          @stormi I do see this now at boot (related to netdata):

                          [   49.028835] xenstat.plugin[1818]: segfault at 80 ip 000000000040378a sp 00007ffc4f4278a0 error 4 in xenstat.plugin[400000+8000]
                          [   49.028842] Code: f4 ff ff 41 b8 68 5d 40 00 b9 d4 00 00 00 ba 30 5f 40 00 be d8 52 40 00 bf 8b 4f 40 00 31 c0 45 31 e4 e8 a9 04 00 00 4c 89 e3 <48> 8b 9b 80 00 00 00 48 85 db 0f 85 be f4 ff ff
                          e9 b7 f7 ff ff 8b
                          

                          So, I reproduced, but also with the previous kernel, so it's not related to this kernel update.

                          Update: same regarding the Xen update candidate. Reverting it does not fix the segfault.

                          A 1 Reply Last reply Reply Quote 0
                          • A Offline
                            Andrew Top contributor @stormi
                            last edited by

                            @stormi I have just not seen that error before and it was not in the old logs. I guess it's just netdata getting old and cranky (grincheux). Otherwise things are good in normal operation.

                            1 Reply Last reply Reply Quote 1
                            • stormiS Offline
                              stormi Vates 🪐 XCP-ng Team
                              last edited by

                              Update published. Thanks for the tests!

                              https://xcp-ng.org/blog/2022/12/21/december-2022-security-update/

                              1 Reply Last reply Reply Quote 1
                              • gduperreyG Offline
                                gduperrey Vates 🪐 XCP-ng Team
                                last edited by

                                New Update Candidates (xen, xapi, templates)

                                • Xen: Enable AVX-512 by default for EPYC Zen4 (Genoa)
                                • Xapi: Redirect http requests on the host webpage to https by default.
                                • Guest templates:
                                  • Add the following templates: RHEL 9, AlmaLinux 9, Rocky Linux 9, CentOS Stream 8 & 9, Oracle Linux 9

                                Test on XCP-ng 8.2

                                From an up to date host:

                                For Xen, Xapi and Guest templates:

                                yum clean metadata --enablerepo=xcp-ng-testing
                                yum update xen-dom0-libs xen-dom0-tools xen-hypervisor xen-libs xen-tools xapi-core xapi-tests xapi-xe guest-templates-json guest-templates-json-data-linux guest-templates-json-data-other guest-templates-json-data-windows --enablerepo=xcp-ng-testing
                                reboot
                                

                                Versions:

                                • xen-*: 4.13.4-9.29.1.xcpng8.2
                                • xapi-*: 1.249.26-2.2.xcpng8.2
                                • guest-templates-json-*: 1.9.6-1.2.xcpng8.2

                                What to test

                                Normal use and anything else you want to test. The closer to your actual use of XCP-ng, the better.

                                Test window before official release of the updates

                                No precise ETA, but the sooner the feedback the better.

                                A N 3 Replies Last reply Reply Quote 0
                                • A Offline
                                  Andrew Top contributor @gduperrey
                                  last edited by

                                  @gduperrey Mirror error

                                  failure: repodata/6b271e84b07dced2015bb0d835fb0ec1be1d308d92010993d44a1af0c130aa9f-primary.sqlite.bz2 from xcp-ng-testing: [Errno 256] No more mirrors to try.
                                  http://mirrors.xcp-ng.org/8/8.2/testing/x86_64/repodata/6b271e84b07dced2015bb0d835fb0ec1be1d308d92010993d44a1af0c130aa9f-primary.sqlite.bz2: [Errno 14] HTTP Error 404 - Not Found
                                  
                                  Name:   mirrors.xcp-ng.org
                                  Address: 37.26.189.194
                                  
                                  1 Reply Last reply Reply Quote 0
                                  • A Offline
                                    Andrew Top contributor @gduperrey
                                    last edited by

                                    @gduperrey The repository seems to work now....

                                    1 Reply Last reply Reply Quote 1
                                    • gduperreyG gduperrey referenced this topic on
                                    • stormiS Offline
                                      stormi Vates 🪐 XCP-ng Team
                                      last edited by

                                      Unrelated to the above: a security update for sudo was published. I don't think it's very likely to be an actual threat in the context of your use of XCP-ng, but it might be in specific contexts.

                                      https://xcp-ng.org/blog/2023/01/31/january-2023-security-update/

                                      brezlordB 1 Reply Last reply Reply Quote 0
                                      • brezlordB Offline
                                        brezlord @stormi
                                        last edited by brezlord

                                        @stormi Applied the update through XO and now XO can not login to the host with the below error.

                                        connect ECONNREFUSED 192.168.40.201:443
                                        

                                        I rebooted the host and I can no longer login as root.

                                        ssh: connect to host 192.168.40.201 port 22: Connection refused
                                        

                                        Any ideas?

                                        1 Reply Last reply Reply Quote 0
                                        • stormiS Offline
                                          stormi Vates 🪐 XCP-ng Team
                                          last edited by stormi

                                          Was it the only update applied? Is the stunnel service running?

                                          Oh, I also read that you can't connect as root.

                                          brezlordB 1 Reply Last reply Reply Quote 0
                                          • brezlordB Offline
                                            brezlord @stormi
                                            last edited by

                                            @stormi Yes only update.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post