Repository navigation
Conversation
Adds a 4.23.0 to 24.0.0 upgrade path (squashed from sb/upgradepath-424: engine-schema: upgrade path for 24.0.0, fix CS version, fix upgrade unit tests for cutover, fix imports).
|
This pull request has merge conflicts. Dear author, please fix the conflicts and sync your branch with the base branch. |
711eb46 to
219f9cb
Compare
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #14166 +/- ##
============================================
+ Coverage 19.91% 19.99% +0.08%
- Complexity 20199 20424 +225
============================================
Files 6373 6385 +12
Lines 577230 579197 +1967
Branches 70696 71037 +341
============================================
+ Hits 114950 115810 +860
- Misses 449713 450718 +1005
- Partials 12567 12669 +102
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
🔴 Test Coverage Grade:
|
| Metric | Value |
|---|---|
| Line coverage | 24.94% |
| Branch coverage | 19.23% |
Grade Scale
| Grade | Line Coverage | Meaning |
|---|---|---|
| 🟢 A | ≥ 80% | Excellent - this code sleeps well at night 😴 |
| 🟡 B | 60-79% | Good - almost there, don't stop now 😉 |
| 🟠 C | 40-59% | Acceptable - your code is wearing a seatbelt, but no airbags 😬 |
| 🔴 D | 20-39% | Marginal - boldly shipping where no test has gone before 🖖 |
| ⛔ F | < 20% | Failing - tests? what tests? 🔥 |
Branch coverage is shown as a secondary signal. Grade is determined by line coverage.
View full Actions run
|
This pull request has merge conflicts. Dear author, please fix the conflicts and sync your branch with the base branch. |
The (nic_id, network_id) unique key rejected re-associating a network after a prior disassociate, since the old row's uniqueness survives as a soft-deleted (removed) row. Switch to a plain index so re-association after disassociation works, relying on application-level checks (not the DB) to reject a true duplicate live association.
…fallback Trunk NIC VLAN membership is delivered by reusing the existing guest bridge with vlan_filtering=1: the primary VLAN gets native/untagged membership, associated VLANs get tagged-only membership, via libvirt's <vlan trunk='yes'> element where supported, or manual `bridge vlan add` on older libvirt. Adds a live membership update path (UpdateNicVlanMembershipCommand/Answer + its KVM wrapper) so an association change on a running VM is pushed to the host without a restart, and a non-blocking diagnostic warning when the physical uplink is missing a VLAN a trunk NIC needs (CloudStack no longer manages the uplink's own VLAN membership - that is the operator's responsibility).
- New UsageEventUtils.publishNicNetworkOfferingUsageEvents() emits one usage event per network a nic bills against (primary + any trunk associations), replacing the old single-event publishUsageEvent at every NIC-billing call site - Ordinary non-trunk nics still produce exactly one event, unchanged - New nullable usage_network_offering.network_id column disambiguates rows when a trunk nic's networks share one network offering - Backfills network_id on a nic's own still-open usage row(s) the moment it first converts to a trunk nic; historic rows otherwise left alone
- New NicNetworkMapResponse + trunked/associatednetworks fields on NicResponse - Populated in listNics, listVirtualMachines, and the associate/disassociate/change-primary command responses - Trunk status derived from nic_network_map rows rather than a new column on the wide UserVmJoinVO view
- ASSOCIATED_NETWORKS/TRUNKED, needed by the previous commit's NicResponse fields
Core capability: - New associateNetworkToNic/disassociateNetworkFromNic/changeNicPrimaryNetwork admin APIs and associateNetworksToNic (programmatic, used by deploy) - A nic keeps one primary network plus any number of additional associated networks (nic_network_map), delivered as a VLAN trunk - changeNicPrimaryNetwork only allowed while the Instance is stopped - Rejects associating a network already reachable via another of the VM's nics, or with an overlapping CIDR to an existing association - Disassociating a network is blocked while an active PF/Static NAT/LB rule targets its allocated IP PF/Static NAT/LB support for associated networks: - NetworkModel.getNicAndIpInNetwork resolves a nic/guest-ip pair via the nic's primary match or a trunk association, reused by RulesManagerImpl and LoadBalancingRulesManagerImpl so these rules can target a trunk nic's associated networks, not just its primary Deployment planning: - Hosts without VLAN filtering enabled are excluded up front for any VM with a multi-VLAN trunk nic, with a reactive fallback exclusion during start as a backstop - Removing a nic cleans up any trunk associations it held as primary; deleting a network is blocked while still associated as a secondary Metadata: - A trunk nic's associated-network VLAN tags are exposed to the guest via the metadata service (nic-vlan-mapping file), gated by a new account-scoped config key, off by default
- EVENT_NIC_NETWORK_ASSOCIATE/DISASSOCIATE/PRIMARY_NETWORK_CHANGE, needed by the previous commit's @actionevent annotations
- New nicnetworkslist deploy param (nicnetworkslist[N].networkids, first id primary) lets a VM be deployed with trunk nics directly, mutually exclusive with networkids/iptonetworklist/vApp nicnetworklist - Also carries per-entry ip4address/ip6address for the primary and ip4addresses/ip6addresses (comma-separated) for its associated networks - a network with no requested IP auto-allocates - VNF: rejects a management-device nic from being requested as a trunk, both at deploy time and via the live associate API
- checkNoActiveRulesOnAssociation used findByIpAndNetworkId, which matches on a public IP's own address - the association's IP is a guest IP, so this never matched and the guard silently let disassociation through even with an active static NAT rule - Use findByAssociatedVmIdAndVmIp instead, which matches the actual static NAT target mapping
- validateVnfApplianceTrunkNics only ran at deploy time (nicnetworkslist) - the live associateNetworkToNic/associateNetworksToNic path had no equivalent check, so a VNF's management nic could be trunked after deploy - New single-nic validateVnfApplianceTrunkNic, called from associateNetworksInternal so both entry points are covered - No-op for any non-VNF template
- changeNicPrimaryNetwork updated networkId and the IPv4/IPv6 address but left gateway, netmask, broadcast/isolation uri, and IPv6 gateway/cidr pointing at the old primary network - wrong indefinitely, since nothing else ever recomputes them - New applyNetworkAddressingToNic refreshes them from the new primary network, mirroring the field derivation used when a nic is first created
- disassociateNetworkFromNic now clears nics.multi_network once nic_network_map has no remaining rows for that nic - Without this, listNics/listVirtualMachines kept reporting trunked=true and the deployment planner kept restricting the VM to VLAN-filtering- capable hosts even after all associations were removed
- New CommandSetupHelper.createDhcpEntryCommand overload takes addressing explicitly instead of reading it off a NicVO, since a nic's own DB row only ever carries its primary network's IP/gateway - NetworkServiceImpl sends the entry directly to the associated network's router(s) on live associate/disassociate, bypassing the DhcpServiceProvider pipeline (which re-resolves the nic from the DB and so can never see anything but the primary IP) - UserVmManagerImpl.finalizeStart converges a nic's associated-network DHCP entries with its current nic_network_map rows on every VM start, covering associations made while the VM was stopped and cleaning up entries for associations removed while stopped - New NicNetworkMapDao.listRemovedByNicId to support that cleanup
- Add missing VlanTrunkMigrationHelper import in VirtualMachineManagerImpl - Fix AssignLoadBalancerTest's NetworkModelImpl spy to stub the new getNicAndIpInNetwork method used by LoadBalancingRulesManagerImpl, matching the existing getNics() stub it replaced
…ommand replaceVlanTrunkInterfaces iterates VirtualMachineTO.getNics(), which the test's bare mock returned null for (unstubbed), unlike every real VirtualMachineTO built via toVmTO, which always sets nics. Stub it the same way getDisks() already was.
…ion rule/listing support - VM deploy/VNF UI: nicnetworkslist grouping in DeployVM/DeployVnfAppliance, zone-flag gating in NicsTab/NicsTable/host list, MigrateWizard unsuitable- reason tooltip - Migration: expose getMultiNetworkNicUnsuitableReason via findHostsForMigration/HostForMigrationResponse; destination-capability- driven bridge/VLAN-XML rewrite in LibvirtMigrateCommandWrapper now also covers a destination-only vlan_filtering boundary, not just the source's - DHCP: VR full-rebuild (createDhcpEntryCommandsForVMs) now includes a nic's trunk associations, not just its primary network - Billing: live associate/disassociate on a Running Instance now bills immediately instead of waiting for the next VM start - Association API hardening: admin-only authorization on associate/change- primary/disassociate, access check on requested networks, CIDR-overlap error includes network names - listNics/listVirtualMachines now also match a nic via its trunk associations, not just its primary network, so Static NAT/Port Forwarding/ Load Balancing pickers can target an associated network's IP, labeled distinctly from primary/secondary IPs
|
@blueorangutan package |
|
@weizhouapache a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
… when paging in deploy UI
|
Packaging result [SF]: ✖️ el8 ✖️ el9 ✖️ debian ✖️ suse15. SL-JID 19456 |
|
@blueorangutan package |
|
@Pearl1594 a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19457 |
|
@blueorangutan package |
|
|
@blueorangutan package |
|
@Pearl1594 a [SL] Jenkins job has been kicked to build packages. It will be bundled with no SystemVM templates. I'll keep you posted as I make progress. |
|
Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ el10 ✔️ debian ✔️ suse15. SL-JID 19458 |
|
@blueorangutan test |
|
@Pearl1594 a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests |
|
This pull request has merge conflicts. Dear author, please fix the conflicts and sync your branch with the base branch. |




Description
This PR adds support for multi-vlan trunk NICs
doc PR: apache/cloudstack-documentation#689
https://cwiki.apache.org/confluence/spaces/CLOUDSTACK/pages/451972290/Multi+VLAN+trunk+NICs+support+in+KVM
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Screenshots (if appropriate):
How Has This Been Tested?
Core trunk mechanism (KVM delivery)
Association lifecycle
Cross-VPC trunk associations
VM deploy and VNF
Network type coverage
DHCP correctness
Usage and billing
Migration
AssignVirtualMachine to another account
UI
How did you try to break this feature and the system with this change?