Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1157751

Summary: Pass REST session expiration time to the engine
Product: Red Hat Enterprise Virtualization Manager Reporter: Raz Tamir <ratamir>
Component: ovirt-engineAssignee: Ori Liel <oliel>
Status: CLOSED CURRENTRELEASE QA Contact: Karolína Hajná <khajna>
Severity: high Docs Contact:
Priority: unspecified    
Version: 3.4.3CC: gklein, juan.hernandez, lpeer, lsurette, oourfali, pstehlik, rbalakri, Rhev-m-bugs, srevivo, ykaul
Target Milestone: ovirt-3.6.0-rc   
Target Release: 3.6.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: 3.6.0-4 alpha3 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-04-20 01:10:12 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Infra RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1148514    
Bug Blocks:    

Description Raz Tamir 2014-10-27 15:46:49 UTC
Description of problem:
Comment from https://projects.engineering.redhat.com/browse/RHEVM-1808:

Python SDK has session timeout - this is a known issue from July. Juans comment:
"Backend sessions expire every 30 minutes, so if you request Python SDK
sessions longer than 30 minutes, say 1 hour, but then don't use it for
more than 30 minutes, then the backend session will expire, but the
RESTAPI session will still be alive. Please open a bug."


Version-Release number of selected component (if applicable):


How reproducible:
100%

Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:
Act like REST api

Additional info:

Comment 1 Juan Hernández 2014-10-27 16:00:20 UTC
This isn't exactly the same, but closely related to bug 1148514. The solution for both issues should be to keep the engine session alive while it is in use.

Comment 2 Yair Zaslavsky 2014-11-17 07:35:17 UTC
How do you define "in use"? 
The session does not "hang up" on you in the middle of a command.
Why should keep it alive after more than 30  (or any other constant we can think of) minutes ?
Whys is the rest-api session kept alive?

Comment 3 Juan Hernández 2014-11-17 07:44:10 UTC
From the RESTAPI point of view I define "in use" as follows:

* The backend session is in use if there is an unfinished async task or job started from that session.

* The backend session is in use if there is a live HTTP session that contains a reference to it.

* The backend session is in use if there is a pending runnable (in the queue managed by the ThreadPoolUtils class) containing a reference to it.

The backend session must be kept alive at lest as long as the RESTAPI considers it in use, otherwise RESTAPI operations may fail, like in this bug.

The RESTAPI is stateless. The only reason the HTTP session is kept alive is for the authentication framework, to avoid authenticating the user with each request.

Comment 5 Alon Bar-Lev 2015-06-24 07:33:33 UTC
I think we discussed that, when issuing a background/async job the engine session should be duplicated for that task, this session should also be cleaned up once this task is finished.

Comment 6 Oved Ourfali 2015-06-24 08:04:54 UTC
The contents should be:
1. Pass the expiration from the API to the engine, so that the engine session will expire once the that time has come.
2. Make sure no "keep-alive" or "activity" monitoring for the REST session. Only expire once the time to expiration has come.

Comment 7 Ori Liel 2015-07-08 13:46:23 UTC
patch submitted: 

  https://gerrit.ovirt.org/#/c/43140/

Comment 8 Juan Hernández 2016-02-25 11:38:57 UTC
To verify this bug I suggest the following approach:

1. Reduce the session timeout of the engine, just to avoid having to wait a long time to verify. For example, to set it to 1 minutes instead of the default 30 minutes:

  # engine-config -s UserSessionTimeOutInterval=5
  # service ovirt-engine restart

2. Reduce also the web application session timeout, for the same reason. In the /usr/share/ovirt-engine/restapi.war/WEB-INF/web.xml replace the value of the "session-timeout" paramter with 1.

3. Run a script that creates a session with TTL longer than the server session timeout, using the "session_timeout" parameter of the constructor of the API object. For example:

---8<---
#!/usr/bin/python

import time

from ovirtsdk.api import API
from ovirtsdk.xml import params

# Connect to the server, this will start the session:
api = API(
  url="https://engine36.example.com/ovirt-engine/api",
  username="admin@internal",
  password="redhat123",
  ca_file="/etc/pki/ovirt-engine/ca.pem",
  session_timeout=10,
  debug=True
)


# Wait longer than the engine session:
time.sleep(2 * 60)

# Do a request, this should succeed:
vms = api.vms.list()

# Close the connection:
api.disconnect()
--->8---

The script should succeed.

Remember to revert the changes to the configuration of the engine when done.

Comment 9 Karolína Hajná 2016-02-26 07:24:13 UTC
Verified in build 3.6.3-4 (3.6.3.3-0.1.el6)