Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 2005219

Summary: Deployment fails if LVMFilterEnabled is true but LVMFilterAllowList is empty
Product: Red Hat OpenStack Reporter: Takashi Kajinami <tkajinam>
Component: tripleo-ansibleAssignee: Giulio Fidente <gfidente>
Status: CLOSED ERRATA QA Contact: Tzach Shefi <tshefi>
Severity: low Docs Contact:
Priority: low    
Version: 16.1 (Train)CC: cylopez, gfidente, ltoscano, tshefi
Target Milestone: z8Keywords: Triaged
Target Release: 16.1 (Train on RHEL 8.2)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: tripleo-ansible-0.5.1-1.20220114163452.902c3c8.el8ost Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-03-24 11:01:35 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Takashi Kajinami 2021-09-17 07:29:14 UTC
Description of problem:

# This feature is TP in RHOSP16.1 and RHOSP16.2 but I'm reporting this bug
# because its implementation is available in RHOSP16.y and stable/train.

When LVMFilterEnabled: true is set in a template file, overcloud deployment always fails at the following task.

~~~
TASK [tripleo_lvmfilter : collect in-use lvm2 devices list] ******************** 
~~~

It seems the tripleo_lvmfilter role doesn't handle an empty list properly
and put an invalid filter definition

[heat-admin@compute-0 ~]$ sudo cat /etc/lvm/lvm.conf
...

devices {
        ...
        global_filter=["","r|.*|"]
        ...
}

...
~~~


Version-Release number of selected component (if applicable):
RHOSP16.1.6

How reproducible:
Always

Steps to Reproduce:
1. Deploy overcloud with LVMFilterEnabled: true

Actual results:
Deployment fails at the tripleo_lvmfilter role

Expected results:
Deployment succeeds without any error

Additional info:

Comment 1 Giulio Fidente 2021-09-23 14:41:55 UTC
hello, I think [1] is only setting in the lvm global_filter any a|| item if at least one item is in the allowed_devices list; our best option is probably to default LVMFilterAllowlist parameter to ['.*'] instead

can you confirm the above to be working for you when set in a custom env file? as a result the lvm conf should look like:

  global_filter=["a|.*|","r|.*|"]

1. https://github.com/openstack/tripleo-ansible/blob/master/tripleo_ansible/roles/tripleo_lvmfilter/tasks/main.yml#L47

Comment 4 Takashi Kajinami 2021-10-07 15:47:12 UTC
Hi Giulio,

Unfortunately I don't have a handy deployment to test the whole deployment so could not yet test usage of the template parameter

I have tested the minimum steps implemented in tripleo_lvmfilter but it seems that deny rule is ignored when LVMFilterAllowlist: ['.*'] is set
and we need to get rid of that allow expression.

[heat-admin@controller-0 ~]$ sudo vi /etc/lvm/lvm.conf
...
devices {
        global_filter=["","r|.*|"]                             <==== This is what is set by default now
}
...
[heat-admin@controller-0 ~]$ sudo vgscan
  Configuration setting "devices/global_filter" invalid. It cannot be set to an empty value.
  Pattern must begin with 'a' or 'r'.
  Invalid filter pattern "".
  Failed to create global regex device filter                  <==== The vgscan command fails
[heat-admin@controller-0 ~]$ sudo vi /etc/lvm/lvm.conf
...
devices {
        global_filter=["a|.*|","r|.*|"]                        <==== Add both rules
}
...
[heat-admin@controller-0 ~]$ sudo vgscan
  Found volume group "cinder-volumes" using metadata type lvm2 <==== LVM is still detected
[heat-admin@controller-0 ~]$ sudo lvs
  LV                  VG             Attr       LSize  Pool Origin Data%  Meta%  Move Log Cpy%Sync Convert
  cinder-volumes-pool cinder-volumes twi-a-tz-- 15.20g             0.00   10.57                           
[heat-admin@controller-0 ~]$ sudo vgs
  VG             #PV #LV #SN Attr   VSize   VFree  
  cinder-volumes   1   1   0 wz--n- <16.00g 780.00m

[heat-admin@controller-0 ~]$ sudo vi /etc/lvm/lvm.conf
...
devices {
        global_filter=["r|.*|"]                                <==== define only deny rule
}
...
[heat-admin@controller-0 ~]$ sudo vgscan
[heat-admin@controller-0 ~]$                                   <==== LVM is no longer detected
[heat-admin@controller-0 ~]$ sudo lvs
[heat-admin@controller-0 ~]$

Comment 5 Giulio Fidente 2021-10-07 15:59:52 UTC
hi, thanks for pinging back; I think I have a working patch in https://review.opendev.org/812568

Comment 15 errata-xmlrpc 2022-03-24 11:01:35 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Red Hat OpenStack Platform 16.1.8 bug fix and enhancement advisory), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:0986