Visitar URL original
Comparing main...4.20 · apache/cloudstack · GitHub
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: apache/cloudstack
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: main
Choose a base ref
...
head repository: apache/cloudstack
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 4.20
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 8 commits
  • 24 files changed
  • 10 contributors

Commits on Sep 11, 2026

  1. KVM: assign the hot-plugged NIC the next PCI slot above existing NICs…

    … (monotonic interface naming) (#12826)
    
    * KVM: assign explicit PCI slot when hot-plugging NIC to ensure sequential naming
    
    When hot-plugging a NIC to a running VM, libvirt auto-assigns the next
    free PCI slot. Since non-NIC devices (virtio-serial, disk, balloon,
    watchdog) occupy slots immediately after existing NICs, the hot-plugged
    NIC gets a much higher slot number (e.g. 0x09 instead of 0x05), causing
    the guest to see non-sequential interface names (ens9 instead of ens5).
    
    This fix queries the domain XML to find all used PCI slots and assigns
    the next free slot after the highest existing NIC slot. This matches
    the approach already used by LibvirtReplugNicCommandWrapper which
    preserves PCI slots during re-plug operations.
    
    Fixes #12825
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * fix(kvm): NPE in PlugNic when libvirt domain XML is unavailable
    
    LibvirtPlugNicCommandWrapper.findNextAvailablePciSlot calls
    vm.getXMLDesc(0) and pipes the result straight into Pattern.matcher,
    which NPEs if libvirt returned null (or, in the
    LibvirtComputingResourceTest.testPlugNicCommandNoMatchMack unit test,
    when the Domain mock isn't stubbed for getXMLDesc). Reported by
    @DaanHoogland after the SL packaging run on #12826.
    
    Defensive null check returns null from findNextAvailablePciSlot when
    the domain XML can't be parsed, which falls through to libvirt's
    auto-assignment of the PCI slot — same behaviour as before this PR
    when nextSlot is null.
    
    Also stubs Domain.getXMLDesc(0) in testPlugNicCommandNoMatchMack with
    a minimal <domain> XML that exercises the parser path (rather than
    just relying on the null-fallback), so the test continues to cover
    the happy path of the new logic.
    
    * address review (#12826): parse PCI addresses with an XML parser, split slot selection into helpers, add unit tests
    
    - getUsedPciSlots() parses the domain XML with the safer DocumentBuilderFactory
      and only considers <address type='pci'> elements, replacing the regex.
    - getHighestNicSlot() and getFirstFreeSlotAbove() are separate methods.
    - The javadoc now states the guarantee precisely: deterministic and monotonic
      after the last NIC, not contiguous when other devices sit in between.
    - LibvirtPlugNicCommandWrapperTest covers parsing, selection and the fallbacks.
    
    Signed-off-by: James Peru <jmsperu@gmail.com>
    
    ---------
    
    Signed-off-by: James Peru <jmsperu@gmail.com>
    Co-authored-by: James Peru <jamesperu@Jamess-Mac-mini.local>
    Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
    Co-authored-by: jmsperu <jmsperu@users.noreply.github.com>
    4 people authored Sep 11, 2026
    Configuration menu
    Copy the full SHA
    a4d3c66 View commit details
    Browse the repository at this point in the history
  2. ui: fix info card showing invalid template, iso link (#13199)

    Template/ISO for a VM could be in deleted state therefore links should not be shown for them in the VM info-card.
    
    Signed-off-by: Abhishek Kumar <abhishek.mrt22@gmail.com>
    shwstppr authored Sep 11, 2026
    Configuration menu
    Copy the full SHA
    8261bec View commit details
    Browse the repository at this point in the history

Commits on Sep 14, 2026

  1. Configuration menu
    Copy the full SHA
    8eeccdb View commit details
    Browse the repository at this point in the history

Commits on Sep 30, 2026

  1. Improve date/timestamp handling performance in GenericDaoBase and Dat…

    …eUtil (#13809)
    
    * Improve date/timestamp handling performance in GenericDaoBase and DateUtil
    
    * address review comment
    sudo87 authored Sep 30, 2026
    Configuration menu
    Copy the full SHA
    5deb6a9 View commit details
    Browse the repository at this point in the history

Commits on Oct 1, 2026

  1. Configuration menu
    Copy the full SHA
    4b2d387 View commit details
    Browse the repository at this point in the history

Commits on Oct 6, 2026

  1. lock only domains that have finite limits for checked reservation (#1…

    …4169)
    
    * lock on only domains that have finite limits for checked reservation
    
    * fix domain lock set to reflect tag->untagged fallback and limit inheritance
    
    listRowsToLockForLimitCheck previously only locked ancestor domains that
    owned an explicit finite resource_limit row for the exact tag, so it
    missed domains that inherit a finite limit from an ancestor's row, and
    domains that fall back to the untagged limit when no tag-specific limit
    is configured (per findCorrectResourceLimitForDomain). Either gap let
    concurrent reservations bypass domain-level serialization.
    
    Replace the set-based approximation with an in-memory walk of the
    account's domain chain that replicates findCorrectResourceLimitForDomain's
    nearest-row-with-fallback semantics, using bulk queries (covered by
    existing indexes) to fetch the chain's resource_limit rows and to resolve
    the final resource_count rows to lock.
    
    ---------
    
    Co-authored-by: Mark Armstrong <marms@apple.com>
    sb-abhish3k and Mark Armstrong authored Oct 6, 2026
    Configuration menu
    Copy the full SHA
    b8a44e9 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    5dfe75f View commit details
    Browse the repository at this point in the history

Commits on Oct 7, 2026

  1. server: scope IPv6 security group member rules to the exact host (#14037

    )
    
    * server: scope IPv6 security group member rules to the exact host
    
    When a security group rule references another security group, each member VM
    should be authorized as an exact host. The IPv4 address is correctly pinned to
    a /32, but the IPv6 address was expanded to /64, opening the whole subnet the
    member sits in rather than just that member. Pin the IPv6 member to /128 to
    match the IPv4 behaviour.
    
    * server: scope the Impl2 IPv6 security group member rule to the exact host
    rootnomad authored Oct 7, 2026
    Configuration menu
    Copy the full SHA
    376c1b4 View commit details
    Browse the repository at this point in the history
Loading