Re: [Users] Certificates and PKI seem to be broken after yum update

2013-04-08 Thread Chris Smith
After setting the .keystore owner and group owner to ovirt, and
rebooting, I now have a new error in engine.log

2013-04-08 02:39:16,787 ERROR
[org.ovirt.engine.core.engineencryptutils.EncryptionUtils]
(QuartzScheduler_Worker-95) Failed to decryptData must start with zero
2013-04-08 02:39:16,845 ERROR
[org.ovirt.engine.core.vdsbroker.vdsbroker.VdsBrokerCommand]
(QuartzScheduler_Worker-95) XML RPC error in command
GetCapabilitiesVDS ( Vds: transporter ), the error was:
java.util.concurrent.ExecutionException:
java.lang.reflect.InvocationTargetException,
SunCertPathBuilderException: unable to find valid certification path
to requested target

Are there other files that may have been affected that I can also
correct ownership or permissions on?

On the host side, I get certificate unknown in vdsm.log

  File /usr/lib64/python2.7/ssl.py, line 305, in do_handshake
self._sslobj.do_handshake()
SSLError: [Errno 1] _ssl.c:504: error:14094416:SSL
routines:SSL3_READ_BYTES:sslv3 alert certificate unknown
Thread-757809::ERROR::2013-04-08
02:44:05,424::SecureXMLRPCServer::73::root::(handle_error) client
('172.16.23.8', 54489)
Traceback (most recent call last):
  File /usr/lib64/python2.7/SocketServer.py, line 582, in
process_request_thread
self.finish_request(request, client_address)
  File /usr/lib/python2.7/site-packages/vdsm/SecureXMLRPCServer.py,
line 66, in finish_request
request.do_handshake()
  File /usr/lib64/python2.7/ssl.py, line 305, in do_handshake
self._sslobj.do_handshake()
SSLError: [Errno 1] _ssl.c:504: error:14094416:SSL
routines:SSL3_READ_BYTES:sslv3 alert certificate unknown

Is there a procedure for just re-establishing PKI and certs for the
engine and hosts?

On Sun, Apr 7, 2013 at 4:58 AM, Alon Bar-Lev alo...@redhat.com wrote:

 OK... you are running a very old version of engine (3.1).

 The upgrade did not upgraded into 3.2, so nothing as far as I know should 
 have been changed.

 But the .keystore permissions is owned by root now, so some other package 
 (maybe selinux-policy) changed permissions...

 The simplest way to test is to:
 # cp -a /etc/pki/ovirt-engine /etc/pki/ovirt-engine.backup1
 # chown -R ovirt:ovirt /etc/pki/ovirt-engine

 But if that file permissions was changed, I can only assume other files were 
 also changes...

 Regards,
 Alon

 - Original Message -
 From: Chris Smith whitehat...@gmail.com
 To: Alon Bar-Lev alo...@redhat.com
 Cc: Users@ovirt.org
 Sent: Sunday, April 7, 2013 11:51:17 AM
 Subject: Re: [Users] Certificates and PKI seem to be broken after yum update

 I did a yum update and rebooted.

 engine-upgrade was run on 24-March

 When run now, it states that there are no updates available.

 [root@reliant ~]# engine-upgrade
 Loaded plugins: versionlock
 Checking for updates... (This may take several minutes)
 No updates available


 [root@reliant ovirt-engine]# cat ovirt-engine-upgrade_2013_03_24_12_04_06.log
 2013-03-24 12:04:06::DEBUG::common_utils::585::root:: found existing
 pgpass file, fetching DB host value
 2013-03-24 12:04:06::DEBUG::common_utils::585::root:: found existing
 pgpass file, fetching DB port value
 2013-03-24 12:04:06::DEBUG::common_utils::585::root:: found existing
 pgpass file, fetching DB admin value
 2013-03-24 12:04:07::DEBUG::engine-upgrade::302::root:: Yum list updates
 started
 2013-03-24 12:04:07::DEBUG::engine-upgrade::273::root:: Yum unlock started
 2013-03-24 12:04:07::DEBUG::engine-upgrade::285::root:: Yum unlock
 completed successfully
 2013-03-24 12:04:07::DEBUG::engine-upgrade::308::root:: Getting list
 of packages to upgrade
 2013-03-24 12:04:27::DEBUG::engine-upgrade::260::root:: Yum lock started
 2013-03-24 12:04:27::DEBUG::common_utils::309::root:: Executing
 command -- '/bin/rpm -q ovirt-engine'
 2013-03-24 12:04:27::DEBUG::common_utils::335::root:: output =
 ovirt-engine-3.1.0-4.fc17.noarch

 2013-03-24 12:04:27::DEBUG::common_utils::336::root:: stderr =
 2013-03-24 12:04:27::DEBUG::common_utils::337::root:: retcode = 0
 2013-03-24 12:04:27::DEBUG::common_utils::309::root:: Executing
 command -- '/bin/rpm -q ovirt-engine-backend'
 2013-03-24 12:04:27::DEBUG::common_utils::335::root:: output =
 ovirt-engine-backend-3.1.0-4.fc17.noarch

 2013-03-24 12:04:27::DEBUG::common_utils::336::root:: stderr =
 2013-03-24 12:04:27::DEBUG::common_utils::337::root:: retcode = 0
 2013-03-24 12:04:27::DEBUG::common_utils::309::root:: Executing
 command -- '/bin/rpm -q ovirt-engine-config'
 2013-03-24 12:04:27::DEBUG::common_utils::335::root:: output =
 ovirt-engine-config-3.1.0-4.fc17.noarch

 2013-03-24 12:04:27::DEBUG::common_utils::336::root:: stderr =
 2013-03-24 12:04:27::DEBUG::common_utils::337::root:: retcode = 0
 2013-03-24 12:04:27::DEBUG::common_utils::309::root:: Executing
 command -- '/bin/rpm -q ovirt-engine-genericapi'
 2013-03-24 12:04:27::DEBUG::common_utils::335::root:: output =
 ovirt-engine-genericapi-3.1.0-4.fc17.noarch

 2013-03-24 12:04:27::DEBUG::common_utils::336::root:: stderr =
 2013-03-24 

Re: [Users] Certificates and PKI seem to be broken after yum update

2013-04-08 Thread Alon Bar-Lev
This error means that the /etc/pki/ovirt-engine/.truststore is unreadable or 
does not contain the /etc/pki/ovirt-engine/ca.pem certificate.

Unfortunately, the pki administration is weak in current implementation, you 
can trace the installation script and checkout the calls to installCA.sh to how 
to reproduce, please note that password are encrypted in database using the 
private key locate in .keystore so if you are to re-generate anything remember 
to keep the engine private key.

However, if you succeed in login, the remaining problem you have is the 
.truststore permissions and/or content.

Regards,
Alon Bar-Lev.

- Original Message -
 From: Chris Smith whitehat...@gmail.com
 To: Alon Bar-Lev alo...@redhat.com
 Cc: Users@ovirt.org
 Sent: Monday, April 8, 2013 9:46:46 AM
 Subject: Re: [Users] Certificates and PKI seem to be broken after yum update
 
 After setting the .keystore owner and group owner to ovirt, and
 rebooting, I now have a new error in engine.log
 
 2013-04-08 02:39:16,787 ERROR
 [org.ovirt.engine.core.engineencryptutils.EncryptionUtils]
 (QuartzScheduler_Worker-95) Failed to decryptData must start with zero
 2013-04-08 02:39:16,845 ERROR
 [org.ovirt.engine.core.vdsbroker.vdsbroker.VdsBrokerCommand]
 (QuartzScheduler_Worker-95) XML RPC error in command
 GetCapabilitiesVDS ( Vds: transporter ), the error was:
 java.util.concurrent.ExecutionException:
 java.lang.reflect.InvocationTargetException,
 SunCertPathBuilderException: unable to find valid certification path
 to requested target
 
 Are there other files that may have been affected that I can also
 correct ownership or permissions on?
 
 On the host side, I get certificate unknown in vdsm.log
 
   File /usr/lib64/python2.7/ssl.py, line 305, in do_handshake
 self._sslobj.do_handshake()
 SSLError: [Errno 1] _ssl.c:504: error:14094416:SSL
 routines:SSL3_READ_BYTES:sslv3 alert certificate unknown
 Thread-757809::ERROR::2013-04-08
 02:44:05,424::SecureXMLRPCServer::73::root::(handle_error) client
 ('172.16.23.8', 54489)
 Traceback (most recent call last):
   File /usr/lib64/python2.7/SocketServer.py, line 582, in
 process_request_thread
 self.finish_request(request, client_address)
   File /usr/lib/python2.7/site-packages/vdsm/SecureXMLRPCServer.py,
 line 66, in finish_request
 request.do_handshake()
   File /usr/lib64/python2.7/ssl.py, line 305, in do_handshake
 self._sslobj.do_handshake()
 SSLError: [Errno 1] _ssl.c:504: error:14094416:SSL
 routines:SSL3_READ_BYTES:sslv3 alert certificate unknown
 
 Is there a procedure for just re-establishing PKI and certs for the
 engine and hosts?
 
 On Sun, Apr 7, 2013 at 4:58 AM, Alon Bar-Lev alo...@redhat.com wrote:
 
  OK... you are running a very old version of engine (3.1).
 
  The upgrade did not upgraded into 3.2, so nothing as far as I know should
  have been changed.
 
  But the .keystore permissions is owned by root now, so some other package
  (maybe selinux-policy) changed permissions...
 
  The simplest way to test is to:
  # cp -a /etc/pki/ovirt-engine /etc/pki/ovirt-engine.backup1
  # chown -R ovirt:ovirt /etc/pki/ovirt-engine
 
  But if that file permissions was changed, I can only assume other files
  were also changes...
 
  Regards,
  Alon
 
  - Original Message -
  From: Chris Smith whitehat...@gmail.com
  To: Alon Bar-Lev alo...@redhat.com
  Cc: Users@ovirt.org
  Sent: Sunday, April 7, 2013 11:51:17 AM
  Subject: Re: [Users] Certificates and PKI seem to be broken after yum
  update
 
  I did a yum update and rebooted.
 
  engine-upgrade was run on 24-March
 
  When run now, it states that there are no updates available.
 
  [root@reliant ~]# engine-upgrade
  Loaded plugins: versionlock
  Checking for updates... (This may take several minutes)
  No updates available
 
 
  [root@reliant ovirt-engine]# cat
  ovirt-engine-upgrade_2013_03_24_12_04_06.log
  2013-03-24 12:04:06::DEBUG::common_utils::585::root:: found existing
  pgpass file, fetching DB host value
  2013-03-24 12:04:06::DEBUG::common_utils::585::root:: found existing
  pgpass file, fetching DB port value
  2013-03-24 12:04:06::DEBUG::common_utils::585::root:: found existing
  pgpass file, fetching DB admin value
  2013-03-24 12:04:07::DEBUG::engine-upgrade::302::root:: Yum list updates
  started
  2013-03-24 12:04:07::DEBUG::engine-upgrade::273::root:: Yum unlock started
  2013-03-24 12:04:07::DEBUG::engine-upgrade::285::root:: Yum unlock
  completed successfully
  2013-03-24 12:04:07::DEBUG::engine-upgrade::308::root:: Getting list
  of packages to upgrade
  2013-03-24 12:04:27::DEBUG::engine-upgrade::260::root:: Yum lock started
  2013-03-24 12:04:27::DEBUG::common_utils::309::root:: Executing
  command -- '/bin/rpm -q ovirt-engine'
  2013-03-24 12:04:27::DEBUG::common_utils::335::root:: output =
  ovirt-engine-3.1.0-4.fc17.noarch
 
  2013-03-24 12:04:27::DEBUG::common_utils::336::root:: stderr =
  2013-03-24 12:04:27::DEBUG::common_utils::337::root:: retcode = 0
  2013-03-24 

[Users] Trouble in ovirt during install new host.

2013-04-08 Thread Kasen

Hi!

I update ovirt from 3.1 to 3.2 and now i have trouble. When I want 
install new host in ovirt, its install failed. In log i see next:


2013-04-08 11:09:55 DEBUG otopi.context context._executeMethod:127 
method exception

Traceback (most recent call last):
  File /tmp/ovirt-JvvRifwHtC/pythonlib/otopi/context.py, line 117, in 
_executeMethod

method['method']()
  File 
/tmp/ovirt-JvvRifwHtC/otopi-plugins/ovirt-host-deploy/vdsm/bridge.py, 
line 671, in _validation

addresses=addresses,
RuntimeError: Cannot connect engine host 'localhost.localdomain' at any 
of the addresses ['127.0.0.1', '127.0.0.1', '127.0.0.1', '::1', '::1', 
'::1']'
2013-04-08 11:09:55 ERROR otopi.context context._executeMethod:136 
Failed to execute stage 'Setup validation': Cannot connect engine host 
'localhost.localdomain' at any of the addresses ['127.0.0.1', 
'127.0.0.1', '127.0.0.1', '::1', '::1', '::1']'


and

2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine 
dialog.__logString:213 DIALOG:SEND   ***Q:VALUE VDSM/engineHost
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine 
dialog.__logString:213 DIALOG:SEND   ###
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine 
dialog.__logString:213 DIALOG:SEND   ### Please specify value for 
'VDSM/engineHost':
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine 
dialog.__logString:213 DIALOG:SEND   ### Response is VALUE 
VDSM/engineHost=type:value or ABORT VDSM/engineHost
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine 
dialog.__logString:213 DIALOG:RECEIVEVALUE 
VDSM/engineHost=str:localhost.localdomain


How and where i must specified VDSM/engineHost?

Best regards,
Kasen.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] Trouble in ovirt during install new host.

2013-04-08 Thread Alon Bar-Lev
Hi,

Is it all-in-one configuration?

If not, you probably have localhost value in ENGINE_FQDN at 
/etc/ovirt-engine/engine.conf, change it to name visible to vdsm host.

Alon

- Original Message -
 From: Kasen kas...@gmail.com
 To: users@ovirt.org
 Sent: Monday, April 8, 2013 10:40:27 AM
 Subject: [Users] Trouble in ovirt during install new host.
 
 Hi!
 
 I update ovirt from 3.1 to 3.2 and now i have trouble. When I want
 install new host in ovirt, its install failed. In log i see next:
 
 2013-04-08 11:09:55 DEBUG otopi.context context._executeMethod:127
 method exception
 Traceback (most recent call last):
File /tmp/ovirt-JvvRifwHtC/pythonlib/otopi/context.py, line 117, in
 _executeMethod
  method['method']()
File
 /tmp/ovirt-JvvRifwHtC/otopi-plugins/ovirt-host-deploy/vdsm/bridge.py,
 line 671, in _validation
  addresses=addresses,
 RuntimeError: Cannot connect engine host 'localhost.localdomain' at any
 of the addresses ['127.0.0.1', '127.0.0.1', '127.0.0.1', '::1', '::1',
 '::1']'
 2013-04-08 11:09:55 ERROR otopi.context context._executeMethod:136
 Failed to execute stage 'Setup validation': Cannot connect engine host
 'localhost.localdomain' at any of the addresses ['127.0.0.1',
 '127.0.0.1', '127.0.0.1', '::1', '::1', '::1']'
 
 and
 
 2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
 dialog.__logString:213 DIALOG:SEND   ***Q:VALUE VDSM/engineHost
 2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
 dialog.__logString:213 DIALOG:SEND   ###
 2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
 dialog.__logString:213 DIALOG:SEND   ### Please specify value for
 'VDSM/engineHost':
 2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
 dialog.__logString:213 DIALOG:SEND   ### Response is VALUE
 VDSM/engineHost=type:value or ABORT VDSM/engineHost
 2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
 dialog.__logString:213 DIALOG:RECEIVEVALUE
 VDSM/engineHost=str:localhost.localdomain
 
 How and where i must specified VDSM/engineHost?
 
 Best regards,
 Kasen.
 ___
 Users mailing list
 Users@ovirt.org
 http://lists.ovirt.org/mailman/listinfo/users
 
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] Trouble in ovirt during install new host.

2013-04-08 Thread Kasen
Thanks. I add ENGINE_FQDN in /etc/sysconfig/ovirt-engine and host 
install successfully.


08.04.13, 11:52, Alon Bar-Lev пишет:

Hi,

Is it all-in-one configuration?

If not, you probably have localhost value in ENGINE_FQDN at 
/etc/ovirt-engine/engine.conf, change it to name visible to vdsm host.

Alon

- Original Message -

From: Kasen kas...@gmail.com
To: users@ovirt.org
Sent: Monday, April 8, 2013 10:40:27 AM
Subject: [Users] Trouble in ovirt during install new host.

Hi!

I update ovirt from 3.1 to 3.2 and now i have trouble. When I want
install new host in ovirt, its install failed. In log i see next:

2013-04-08 11:09:55 DEBUG otopi.context context._executeMethod:127
method exception
Traceback (most recent call last):
File /tmp/ovirt-JvvRifwHtC/pythonlib/otopi/context.py, line 117, in
_executeMethod
  method['method']()
File
/tmp/ovirt-JvvRifwHtC/otopi-plugins/ovirt-host-deploy/vdsm/bridge.py,
line 671, in _validation
  addresses=addresses,
RuntimeError: Cannot connect engine host 'localhost.localdomain' at any
of the addresses ['127.0.0.1', '127.0.0.1', '127.0.0.1', '::1', '::1',
'::1']'
2013-04-08 11:09:55 ERROR otopi.context context._executeMethod:136
Failed to execute stage 'Setup validation': Cannot connect engine host
'localhost.localdomain' at any of the addresses ['127.0.0.1',
'127.0.0.1', '127.0.0.1', '::1', '::1', '::1']'

and

2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
dialog.__logString:213 DIALOG:SEND   ***Q:VALUE VDSM/engineHost
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
dialog.__logString:213 DIALOG:SEND   ###
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
dialog.__logString:213 DIALOG:SEND   ### Please specify value for
'VDSM/engineHost':
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
dialog.__logString:213 DIALOG:SEND   ### Response is VALUE
VDSM/engineHost=type:value or ABORT VDSM/engineHost
2013-04-08 11:09:55 DEBUG otopi.plugins.otopi.dialog.machine
dialog.__logString:213 DIALOG:RECEIVEVALUE
VDSM/engineHost=str:localhost.localdomain

How and where i must specified VDSM/engineHost?

Best regards,
Kasen.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] DNS for IPA in oVirt

2013-04-08 Thread Yair Zaslavsky
Hi,
When you add a new domain - let's say example.com what happens from DNS 
perspective is -


a. if useDnsLookup at engine-manage-domains conf is set to true then
dns_lookup_realm  = true
and dns_lookup_kdc = true

Will be placed at the krb5.conf that is being created.
This will cause the internal java kerberos implementation to issue DNS srv 
requests per realm (for example, if you want to add the domain example.com, the 
realm will be EXAMPLE.COM) 
for kerberos -
the srv record query will look like _kerberos._tcp.example.com and it will 
return a list of KDCs for the realm.

If useDnsLookup is not set to true, 
This will cause the manage-domains utility to issue kerberos DNS srv records, 
and fill the krb5.conf file with information on KDCs per realm.


In return you will get a list of corresponding hosts for the ldap servers.

b. If -ldapServers was not passed - a DNS srv record will be issues to get the 
ldap servers for the domain -
_ldap._tcp.example.com  after the manage-domains utility performs kerberos 
authentication.
This is done, in order to get a URL of an ldap server to be used, to send an 
ldap query and get the user id for the given user at the command line utility.

So, as long as your DNS is configured properly, and the SRV records are well 
defined, you will get SRV records for kerberos and ldap.





- Original Message -
 From: René Koch (ovido) r.k...@ovido.at
 To: ovirt-users users@ovirt.org
 Sent: Friday, April 5, 2013 3:47:07 PM
 Subject: [Users] DNS for IPA in oVirt
 
 Hi list,
 
 I don't want to ask my question in the mail thread of Eduardo to avoid
 mixing topics.
 
 Can you give me more detailed information on how oVirt is using DNS
 internally and how IPA users can work in the following scenario:
 
 # engine-manage-domains -action=list
 Domain: ovido.at
   User name: ad...@ovido.at
 Manage Domains completed successfully
 
 # cat /etc/hosts | grep engine
 10.0.100.195 ovirt-engine.lab.ovido.at
 
 # ip a
 2: eth0: BROADCAST,MULTICAST,UP,LOWER_UP mtu 1500 qdisc pfifo_fast
 state UP qlen 1000
 link/ether 00:1a:4a:00:64:14 brd ff:ff:ff:ff:ff:ff
 inet 10.0.100.195/24 brd 10.0.100.255 scope global eth0
 
 # host ovirt-engine.lab.ovido.at
 ovirt-engine.lab.ovido.at has address 10.0.100.24
 
 # host 10.0.100.24
 24.100.0.10.in-addr.arpa domain name pointer ovirt-engine.lab.ovido.at.
 
 So in my case I have correct DNS settings (forward and reverse), but my
 ovirt-engine host has a totally different IP address.
 
 I didn't test SSO with Kerberos in user portal (maybe this want work),
 but authentication with IPA user in user portal and admin portal is
 working fine even with these totally wrong DNS configuration.
 
 
 Regards,
 René
 
 
 ___
 Users mailing list
 Users@ovirt.org
 http://lists.ovirt.org/mailman/listinfo/users

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] [Spice-devel] 3.2 final and status of spice console in ie

2013-04-08 Thread David Jaša
Hi Juan,

Juan Jose píše v Po 08. 04. 2013 v 14:36 +0200:
 
 Hello evrybody,
 
 
 I'm testing open console in a Windows 7 client with IE 9 and when I
 try to click in console when I'm inside User Portal with wirt-viewer
 installad, it is launched but and virt-viewer give me the message
 Unable to connect to graphic server and It can't connect to my VM.
 Any suggest?

I've described the debugging steps on this list in the past, please look
them up and go through spicex.log. If that isn't sufficient, please use
debug-helper.exe (IIRC I described it in another mail here) to get
remote-viewer debug output.

HTH,

David

 
 
 Many thanks in avanced,
 
 
 Juanjo.
 
 
 On Thu, Mar 21, 2013 at 1:49 PM, Gianluca Cecchi
 gianluca.cec...@gmail.com wrote:
 On Wed, Mar 20, 2013 at 10:43 PM, Jeff Bailey wrote:
  On 3/20/2013 5:20 AM, Christophe Fergeau wrote:
 
  On Tue, Mar 19, 2013 at 05:11:56PM -0400, Jeff Bailey
 wrote:
 
 
  Heh, heh, maybe it's a secret. :)
 
  Actually, I believe I got it from
 http://elmarco.fedorapeople.org/spice.cab
  and it seems to be version 5.0.2.2.
 
 
 
 
 As already pointed in another mail of this same thread from
 Michal
 Skrivanek (about a month ago), the info is at
 http://wiki.ovirt.org/How_to_Connect_to_SPICE_Console_With_Portal
 and the page indeed contains the same link to spice.cab file
 you are referring
 so possibly difficult to find but not a secret... ;-)
 
 Gianluca
 ___
 Users mailing list
 Users@ovirt.org
 http://lists.ovirt.org/mailman/listinfo/users
 
 
 
 ___
 Users mailing list
 Users@ovirt.org
 http://lists.ovirt.org/mailman/listinfo/users

-- 

David Jaša, RHCE

SPICE QE based in Brno
GPG Key: 22C33E24 
Fingerprint: 513A 060B D1B4 2A72 7F0D 0278 B125 CD00 22C3 3E24



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] SPM is always contending

2013-04-08 Thread Yeela Kaplan
Hi Andy,
I saw in another thread that you have resolved the issue,
but I would like to further investigate the cause.
Can you please send an sos report as soon as possible?
Thanks,
Yeela

- Original Message -
 From: Andy Singleton andy.single...@brightprocess.com
 To: users@ovirt.org
 Sent: Friday, April 5, 2013 12:07:24 PM
 Subject: [Users] SPM is always contending
 
 After the node acting as spm was (accidentally) put into maintenance
 mode, the spm role is always contending. The original node doesnt take
 the role back either.
 About 10 instances were still running on the node when it was put into
 maintenance.
 
 I have ovirt 3.1.0-4 with a targetcli iscsi store.
 
 Here are the contents of the engine.log.
 
 Andy
 
 2013-04-04 15:25:23,979 INFO
 [org.ovirt.engine.core.vdsbroker.vdsbroker.SpmStartVDSCommand]
 (QuartzScheduler_Worker-96) [5449512a] spmStart polling ended. spm status:
 Free
 2013-04-04 15:25:23,993 INFO
 [org.ovirt.engine.core.vdsbroker.vdsbroker.HSMClearTaskVDSCommand]
 (QuartzScheduler_Worker-96) [5449512a] START, HSMClearTaskVDSCommand(vd
 sId = d265245e-3cc5-11e2-bce7-001018fc3b14,
 taskId=7c1cf7c6-21d4-4504-882d-3d465742b6ef), log id: d2da8ba
 2013-04-04 15:25:24,011 INFO
 [org.ovirt.engine.core.vdsbroker.vdsbroker.HSMClearTaskVDSCommand]
 (QuartzScheduler_Worker-96) [5449512a] FINISH, HSMClearTaskVDSCommand,
 log id: d2da8ba
 2013-04-04 15:25:24,012 INFO
 [org.ovirt.engine.core.vdsbroker.vdsbroker.SpmStartVDSCommand]
 (QuartzScheduler_Worker-96) [5449512a] FINISH, SpmStartVDSCommand, return:
 org.ovirt.engine.core.common.businessentities.SpmStatusResult@30a05218,
 log id: 5980d6f4
 2013-04-04 15:25:24,014 INFO
 [org.ovirt.engine.core.bll.storage.SetStoragePoolStatusCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] Running command: SetStoragePoolStat
 usCommand internal: true. Entities affected :  ID:
 0ba15357-9b3b-4a76-8dac-b2b66b922174 Type: StoragePool
 2013-04-04 15:25:24,843 ERROR
 [org.ovirt.engine.core.vdsbroker.irsbroker.IrsBrokerCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98]
 IrsBroker::Failed::GetStoragePoolInfoV
 DS due to: IrsSpmStartFailedException: IRSGenericException:
 IRSErrorException: SpmStart failed
 2013-04-04 15:25:24,900 INFO
 [org.ovirt.engine.core.vdsbroker.irsbroker.IrsBrokerCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] Irs placed on server null failed.
 Proc
 eed Failover
 2013-04-04 15:25:34,977 INFO
 [org.ovirt.engine.core.vdsbroker.irsbroker.IrsBrokerCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] hostFromVds::selectedVds -
 moon-palace
 , spmStatus Free, storage pool Primary
 2013-04-04 15:25:35,806 INFO
 [org.ovirt.engine.core.vdsbroker.irsbroker.IrsBrokerCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] starting spm on vds moon-palace,
 stora
 ge pool Primary, prevId -1, LVER 2520
 2013-04-04 15:25:35,851 INFO
 [org.ovirt.engine.core.vdsbroker.vdsbroker.SpmStartVDSCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] START, SpmStartVDSCommand(vdsId = 3d
 88c8b0-84bc-11e2-96b1-001018fc3b14, storagePoolId =
 0ba15357-9b3b-4a76-8dac-b2b66b922174, prevId=-1, prevLVER=2520,
 storagePoolFormatType=V2, recoveryMode=Manual, SCSIF
 encing=false), log id: 30f4f64e
 2013-04-04 15:25:45,901 INFO
 [org.ovirt.engine.core.vdsbroker.vdsbroker.SpmStartVDSCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] spmStart polling started: taskId = 6
 8002cff-478d-4c2c-8839-b935d8a858b1
 2013-04-04 15:26:11,903 INFO [org.ovirt.engine.core.bll.VdsLoadBalancer]
 (QuartzScheduler_Worker-81) [45db3aaa] VdsLoadBalancer: Starting load
 balance for cluster: BP_
 Primary, algorithm: EvenlyDistribute.
 2013-04-04 15:26:12,807 INFO [org.ovirt.engine.core.bll.VdsLoadBalancer]
 (QuartzScheduler_Worker-81) [45db3aaa] VdsLoadBalancer: high util: 51,
 low util: 0, duration:
 2, threashold: 80
 2013-04-04 15:26:12,845 INFO
 [org.ovirt.engine.core.bll.VdsLoadBalancingAlgorithm]
 (QuartzScheduler_Worker-81) [45db3aaa] VdsLoadBalancer: number of
 relevant vdss (no
 migration, no pending): 3.
 2013-04-04 15:26:12,846 INFO
 [org.ovirt.engine.core.bll.VdsCpuVdsLoadBalancingAlgorithm]
 (QuartzScheduler_Worker-81) [45db3aaa] VdsLoadBalancer: number of over
 utilize
 d vdss found: 0.
 2013-04-04 15:26:12,846 INFO
 [org.ovirt.engine.core.bll.VdsCpuVdsLoadBalancingAlgorithm]
 (QuartzScheduler_Worker-81) [45db3aaa] VdsLoadBalancer: max cpu limit:
 40, num
 ber of ready to migration vdss: 3
 2013-04-04 15:26:19,024 INFO
 [org.ovirt.engine.core.vdsbroker.vdsbroker.SpmStartVDSCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] spmStart polling ended: taskId = 680
 02cff-478d-4c2c-8839-b935d8a858b1 task status = finished
 2013-04-04 15:26:19,024 ERROR
 [org.ovirt.engine.core.vdsbroker.vdsbroker.SpmStartVDSCommand]
 (QuartzScheduler_Worker-96) [6d6dbe98] Start SPM Task failed - result: clea
 nSuccess, message: VDSGenericException: VDSErrorException: Failed in
 vdscommand to HSMGetTaskStatusVDS, error = BlockSD master file system
 FSCK error
 
 This log sequence repeats indefinitely