XenServer 6.2 (clearwater) と XenServer 6.5 (Creedence) を中心に雑な感じで書いていきます。といいながら、すでにXenServer8がリリースされている・・・
2016年7月27日水曜日
New Windows PV Drivers
新しいWindows PVドライバがリリースされました。
Windows PV Drivers
http://www.xenproject.org/developers/teams/windows-pv-drivers.html
しかもちゃんとReleased Sign。
みんなが待ち望んでいたので、MLでは賞賛の嵐です。Thank you Paul!
プレゼンの説明
http://wiki.xenproject.org/wiki/Windows_PV_Drivers_Presentation
2015年6月4日木曜日
Hotfix XS62ESP1024 - for XenServer 6.2.0 Service Pack 1
Hotfix XS62ESP1024 - for XenServer 6.2.0 Service Pack 1
http://support.citrix.com/article/CTX142496
Kernelを含むアップデート。
Hotfix XS62ESP1009 の件もあるからちょっと様子見したいところ。
http://support.citrix.com/article/CTX142496
Kernelを含むアップデート。
Hotfix XS62ESP1009 の件もあるからちょっと様子見したいところ。
2015年5月14日木曜日
VENOM
VENOM(Virtualized Environment Neglected Operations Manipulation)の件
◆詳細
http://lists.xen.org/archives/html/xen-users/2015-05/msg00109.html
http://support.citrix.com/article/CTX201078
◆詳細
Crowdstrike.com
Q+A: Learn More About VENOMhttp://venom.crowdstrike.com/◆Xen
[Xen-users] Xen Security Advisory 133 (CVE-2015-3456) - Privilege escalation via emulated floppy disk drivehttp://lists.xen.org/archives/html/xen-users/2015-05/msg00109.html
ISSUE DESCRIPTION
=================
The code in qemu which emulates a floppy disk controller did not
correctly bounds check accesses to an array and therefore was
vulnerable to a buffer overflow attack.
◆XenServer
Citrix Security Advisory for CVE-2015-3456http://support.citrix.com/article/CTX201078
Description of Problem
Citrix is aware of the recent vulnerability that has been reported against the Xen hypervisor. This issue is known as the 'VENOM' vulnerability and has been assigned the following CVE number:
CVE-2015-3456: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456
The following sections will provide guidance to customers on the potential impact of this issue. Citrix is actively analysing the impact of this vulnerability on supported versions of Citrix XenServer. Additional details and guidance will be added to this document as soon as they are available.
<追記 2015/5/19>
https://securityblog.redhat.com/2015/05/13/venom-dont-get-bitten/
VENOMでは、VM上で特定コマンドを実施することで、ハイパーバイザ上で任意のコマンドを実施できるというもの。
ただし、Redhatとしては、特定コマンドは実施できるが、ハイパーバイザ上での実効は確認できていないとのこと。
ちなみに、影響をうけるのは、HVM(完全仮想化)なVMだけだよ。XenTools入った準仮想化VMは影響受けないらしいよ。
まぁ、RootとられてXenTools抜かれたらやられちゃうけど。
https://securityblog.redhat.com/2015/05/13/venom-dont-get-bitten/
ただし、Redhatとしては、特定コマンドは実施できるが、ハイパーバイザ上での実効は確認できていないとのこと。
We believe that code execution is possible but we have not yet seen any working reproducers that would allow this.なお、既存のExploitは、QEMUをCrashさせるので、Segfault LOGをみてれば、その攻撃を判定できそうとのこと。
ちなみに、影響をうけるのは、HVM(完全仮想化)なVMだけだよ。XenTools入った準仮想化VMは影響受けないらしいよ。
まぁ、RootとられてXenTools抜かれたらやられちゃうけど。
2015年5月1日金曜日
Docker with XenServer6.5
Preview of XenServer support for Docker and Container Management
http://xenserver.org/blog/entry/preview-of-xenserver-support-for-docker-and-container-management.html
3月10日に公開されてた・・・
PRE-RELEASE COMPONENTS - DOCKER INTEGRATION
http://xenserver.org/overview-xenserver-open-source-virtualization/prerelease.html
XenServer6.5用のDocker。
Supplemental Packとして提供されている。
PRE-RELEASE版なので、遊ぶにはちょうどいいけど、それ以外にはちょっと怖い。
Dundeeまで待ちたいね。
http://xenserver.org/blog/entry/preview-of-xenserver-support-for-docker-and-container-management.html
3月10日に公開されてた・・・
PRE-RELEASE COMPONENTS - DOCKER INTEGRATION
http://xenserver.org/overview-xenserver-open-source-virtualization/prerelease.html
XenServer6.5用のDocker。
Supplemental Packとして提供されている。
PRE-RELEASE版なので、遊ぶにはちょうどいいけど、それ以外にはちょっと怖い。
Dundeeまで待ちたいね。
XenServer Dundee
Introducing XenServer Dundee
CentOS7ベースの次期XenServer 「Dundee」
Versionとかは見てないけど、多分XenServer 7?
DOWNLOAD - PRE-RELEASE XENSERVER
XenServer Dundee Alpha1 がDownloadできます。
2014年12月22日月曜日
Hotfix XS62ESP1012 - For XenServer 6.2.0 Service Pack 1
Hotfix XS62ESP1012 - For XenServer 6.2.0 Service Pack 1
http://support.citrix.com/article/CTX141845
XenToolsのUpdateです。
パッチ番号は滅茶苦茶ですが、XenToolsだけの更新なので、適当な順番であてれば問題無いと思います。
修正内容は主にWindows系のPVドライバ関係です。
下記も更新しました。
XenServer6.2 SP1 のパッチリスト (2014/12/3時点)
http://mada0833.blogspot.jp/2014/04/XenServer62SP1PatchList.html
http://support.citrix.com/article/CTX141845
XenToolsのUpdateです。
パッチ番号は滅茶苦茶ですが、XenToolsだけの更新なので、適当な順番であてれば問題無いと思います。
修正内容は主にWindows系のPVドライバ関係です。
下記も更新しました。
XenServer6.2 SP1 のパッチリスト (2014/12/3時点)
http://mada0833.blogspot.jp/2014/04/XenServer62SP1PatchList.html
2014年12月3日水曜日
Hotfix XS62ESP1015 - For XenServer 6.2.0 Service Pack 1
Hotfix XS62ESP1015 - For XenServer 6.2.0 Service Pack 1
https://support.citrix.com/article/CTX141717
含まれるFix
あて方は、XS62ESP015には、Kernelが含まれていないため、
Recommended Updates for XenServer 6.x Hotfixes
のXS62ESP1013の置き換えと考えてよさそうだ。
XS62ESP1009は最後かぁ・・・
https://support.citrix.com/article/CTX141717
含まれるFix
This hotfix also includes the following previously released hotfixes:
CTX140052 - Hotfix XS62E014 - For XenServer 6.2.0
CTX140051 - Hotfix XS62ESP1002 - For XenServer 6.2.0 Service Pack 1
CTX140417 - Hotfix XS62ESP1004 - For XenServer 6.2.0 Service Pack 1
CTX141036 - Hotfix XS62ESP1008 - For XenServer 6.2.0 Service Pack 1
CTX141472 - Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1
CTX141480 - Hotfix XS62ESP1013 - For XenServer 6.2.0 Service Pack 1
あて方は、XS62ESP015には、Kernelが含まれていないため、
Recommended Updates for XenServer 6.x Hotfixes
のXS62ESP1013の置き換えと考えてよさそうだ。
XS62ESP1009は最後かぁ・・・
2014年11月26日水曜日
What are the top Citrix XenServer Issues/Workarounds/Best Practices for NFSv3
NetAppに情報があったので。
What are the top Citrix XenServer Issues/Workarounds/Best Practices for NFSv3
https://kb.netapp.com/support/index?id=3014326&page=content
あと、折角のリンクが壊れてたので、ここに書いておきます。
XenServer and NetApp Storage Best Prictices
https://www.netapp.com/us/media/tr-3732.pdf
What are the top Citrix XenServer Issues/Workarounds/Best Practices for NFSv3
https://kb.netapp.com/support/index?id=3014326&page=content
あと、折角のリンクが壊れてたので、ここに書いておきます。
XenServer and NetApp Storage Best Prictices
https://www.netapp.com/us/media/tr-3732.pdf
2014年11月12日水曜日
Windows10 on XenServer6.2 SP1
今更ながら Win10 Techical Preview を XenServer 6.2 SP1 (PatchはXS62ESP1014まで) にINSTALLしてみた。
Win10は基本的にWin8.1らしいのでやってみた。
(内部の仕組みは、今度詳しい人が来日したタイミングで聞いてみる)
Win8.1と同じならテンプレートからNew VMできんじゃね? と思って
NewVM でWindows 8 64bitのテンプレートを選択。
何の問題なくインストール完了
ちょっと物足らない・・・
xentoolsも入れた。
問題なく動作。
ちょっとDom0のログでも見てみるかな。
Win10は基本的にWin8.1らしいのでやってみた。
(内部の仕組みは、今度詳しい人が来日したタイミングで聞いてみる)
Win8.1と同じならテンプレートからNew VMできんじゃね? と思って
NewVM でWindows 8 64bitのテンプレートを選択。
何の問題なくインストール完了
ちょっと物足らない・・・
xentoolsも入れた。
問題なく動作。
ちょっとDom0のログでも見てみるかな。
2014年10月2日木曜日
XenServer Shellshock と XSA-108
Citrix Security Advisory for GNU Bash Shellshock Vulnerabilities
http://support.citrix.com/article/CTX200217
XenServerは影響を継続調査中とのこと。
XSA-108
http://xenbits.xen.org/xsa/advisory-108.html
http://xenbits.xen.org/xsa/
公表をもったいつけてた?XSA-108の件、
XSA-100の延長って印象。HVMで運用してなきゃ、まぁ影響はなさそう。
http://support.citrix.com/article/CTX200217
XenServerは影響を継続調査中とのこと。
XSA-108
http://xenbits.xen.org/xsa/advisory-108.html
http://xenbits.xen.org/xsa/
公表をもったいつけてた?XSA-108の件、
XSA-100の延長って印象。HVMで運用してなきゃ、まぁ影響はなさそう。
2014年10月1日水曜日
Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1
Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1
The option Restore Virtual Machine Metadata in xsconsole fails to restore VDIs on the storage repositories (SRs). VDIs are restored if the SRs contain the backup of the pool metadata.
When Linux bridge is used as the network stack, generic receive offload (GRO) does not always work on VLANs.
なお、XS62ESP1002 / XS62ESP1004 / XS62ESP1008 が含まれる。
最近Blogの更新ができません。
だれかうちでXenServerの技術者しませんか?
2014年7月23日水曜日
Memory usage alert mail など
xapi
Add Dom0 mem_usage alert
https://github.com/xapi-project/xen-api/pull/1836
+def get_percent_mem_usage(ignored):
+ "Get the percent usage of Dom0 memory/swap. Input list is ignored and should be empty"
Swapの状況もDom0でとれて、Alertメールも出せるようになる。
CP-9019: Automatically log the Xen console
https://github.com/andyhhp/xen-api/commit/9c5c623df0fbe477d3aa1e0c5cdf5054bd9ebe33
/usr/sbin/xenconsoled --log=hv --timestamp=hv --log-dir=/var/log/xen
CP-8987: Use Sexp for Xenops header serialisation
https://github.com/simonjbeaumont/xenopsd/commit/42b0c6061408e08ff8b2c9880344e294c5865a2a
We want to be able to extend the Xenops record in the suspend image in future
versions
sexp_lib
2014年7月16日水曜日
XenServer関連の修正メモ
あまり目に着く情報がなかったので、Blog自体を更新してなかったが、
この辺で更新しておきます。
XenServer
CA-139739: encode NFS shares
self.remotepath = self.dconf['serverpath'].encode('utf-8')
え?encode? そういう書き方もできるのか。
CP-8636: Change gpumon build to use new NVIDIA GDK
-Source1: tdk_5.319.43.tar.gz
+Source1: gdk_331_62_release.tgz
-tar zxvf /obj/SOURCES/tdk_5.319.43.tar.gz
-cp $RPM_BUILD_DIR/tdk_5.319.43/nvml/include/nvml.h /usr/include
+tar zxvf /obj/SOURCES/gdk_331_62_release.tgz
+cp $RPM_BUILD_DIR/gdk_linux_amd64_release/nvml/include/nvml.h /usr/include
GDKのVersion情報が必要になった時のMEMO
CP-8285: Remove maxcpus=1 workaround (only SLES 11 SP0 needs this)
linux-guest-loaderのeliloader.py
2014年7月9日水曜日
XenServer Tech Preview Releas / Alpha4
XenServer Tech Preview Release Date: Jul 8, 2014
https://www.citrix.com/downloads/xenserver/product-software/xenserver-tech-preview
Citrix XenServer 6.4.93
XenServer Creedence Alpha 4
http://xenserver.org/open-source-virtualization-download/11-product/142-download-pre-release.html
2014-07-02 nightly build
https://www.citrix.com/downloads/xenserver/product-software/xenserver-tech-preview
Citrix XenServer 6.4.93
XenServer Creedence Alpha 4
http://xenserver.org/open-source-virtualization-download/11-product/142-download-pre-release.html
2014-07-02 nightly build
多分 TechPreviewはAlpha4と同じと思われる。
なお、最新Nightly Buildは 2014-07-07 だ。次は07-12?
2014年6月17日火曜日
xapi daemon のRRDの説明、 MPP-RDAC 他
RE: [xs-devel] Gluster FS with libgfapi
https://lists.xenserver.org/sympa/arc/xs-devel/2014-06/msg00052.html
Creedenceでは、libgfapiはサポートしてない模様。
The problem with xapi daemon metrics in monitoring XenServer performance
http://discussions.citrix.com/topic/346909-the-problem-with-xapi-daemon-metrics-in-monitoring-xenserver-performance/
xapi DaemonのRRD関連の
xapi_allocation_kib
xapi_free_memory_kib
xapi_live_memory_kib
xapi_memory_usage_kib
の説明。
MultiPath XenServer MPP-RDAC - IBM DS3512/24 - 1746
http://discussions.citrix.com/topic/352656-multipath-xenserver-mpp-rdac-ibm-ds351224-1746/
iSCSIで組む人は、MPP-RDACがおすすめらしいけど。使ったことない。
LSIのチップ積んだストレージなら可能とManualで読んだ記憶が。
また、MPP-RDACで使えば、XenMotionでPacket Loss無しにSeemlessにMigration可能だという話もどこかで見た記憶がある。
https://lists.xenserver.org/sympa/arc/xs-devel/2014-06/msg00052.html
Creedenceでは、libgfapiはサポートしてない模様。
The problem with xapi daemon metrics in monitoring XenServer performance
http://discussions.citrix.com/topic/346909-the-problem-with-xapi-daemon-metrics-in-monitoring-xenserver-performance/
xapi DaemonのRRD関連の
xapi_allocation_kib
xapi_free_memory_kib
xapi_live_memory_kib
xapi_memory_usage_kib
の説明。
MultiPath XenServer MPP-RDAC - IBM DS3512/24 - 1746
http://discussions.citrix.com/topic/352656-multipath-xenserver-mpp-rdac-ibm-ds351224-1746/
iSCSIで組む人は、MPP-RDACがおすすめらしいけど。使ったことない。
LSIのチップ積んだストレージなら可能とManualで読んだ記憶が。
また、MPP-RDACで使えば、XenMotionでPacket Loss無しにSeemlessにMigration可能だという話もどこかで見た記憶がある。
2014年5月30日金曜日
XenServer 6.2 で ftp コマンド を利用する方法
通常、ftpは過去の遺物なので使う機会が少ないのだが、
運用で全く使わないということではないのが現実。
XenServer6.2では、telnetとかtcpdumpとか基本的なツールが入っているが、ftp client だけない。
そこで、ftp をどうしても使いたい時のTIPS。
XenServer6.2 は CentOS 5.7 ベースなので、そのパッケージを利用すればいい。
なお、XenServer6.2 は 32bit だよ。
なので、まぁこんな感じで ftp client のRPMを取得すればいい。
ダウンロードは例としてMazのところの公開サーバを利用させてもらう
http://ftp.iij.ad.jp/pub/linux/centos/5.10/os/i386/CentOS/ftp-0.17-38.el5.i386.rpm
なお、この方法で他のRPMの多少いけるが、
ftp client くらいの単純なRPMならいいけど、
それ以外は、ちゃんとDDKでコンパイルして適用することをお勧めする。
運用で全く使わないということではないのが現実。
XenServer6.2では、telnetとかtcpdumpとか基本的なツールが入っているが、ftp client だけない。
そこで、ftp をどうしても使いたい時のTIPS。
XenServer6.2 は CentOS 5.7 ベースなので、そのパッケージを利用すればいい。
[root@cw01 ~]# rpm -qif /etc/redhat-release
Name : centos-release Relocations: (not relocatable)
Version : 5 Vendor: CentOS
Release : 7.el5.centos Build Date: Mon 29 Aug 2011 08:00:09 PM JST
なお、XenServer6.2 は 32bit だよ。
[root@cw01 ~]# uname -a
Linux cw01 2.6.32.43-0.4.1.xs1.8.0.853.170791xen #1 SMP Mon Mar 3 06:36:39 EST 2014 i686 i686 i386 GNU/Linux
なので、まぁこんな感じで ftp client のRPMを取得すればいい。
ダウンロードは例としてMazのところの公開サーバを利用させてもらう
http://ftp.iij.ad.jp/pub/linux/centos/5.10/os/i386/CentOS/ftp-0.17-38.el5.i386.rpm
取得
[root@cw01 ~]# wget http://ftp.iij.ad.jp/pub/linux/centos/5.10/os/i386/CentOS/ftp-0.17-38.el5.i386.rpm
--2014-05-30 08:41:39-- http://ftp.iij.ad.jp/pub/linux/centos/5.10/os/i386/CentOS/ftp-0.17-38.el5.i386.rpm
Resolving ftp.iij.ad.jp... 202.232.140.170, 2001:240:bb8f:200::1:170
Connecting to ftp.iij.ad.jp|202.232.140.170|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 56209 (55K) [application/x-rpm]
Saving to: `ftp-0.17-38.el5.i386.rpm'
100%[==========================================================>] 56,209 --.-K/s in 0.04s
2014-05-30 08:41:39 (1.43 MB/s) - `ftp-0.17-38.el5.i386.rpm' saved [56209/56209]
インストール
[root@cw01 ~]# rpm -Uvh ftp-0.17-38.el5.i386.rpm
Preparing... ########################################### [100%]
1:ftp ########################################### [100%]
テスト
[root@cw01 ~]# ftp ftp.iij.ad.jp
Trying 202.232.140.170...
Connected to ftp.iij.ad.jp (202.232.140.170).
220 IIJ FTP server ready (IPv4 client).
Name (ftp.iij.ad.jp:root): anonymous
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> quit
221 Goodbye.
なお、この方法で他のRPMの多少いけるが、
ftp client くらいの単純なRPMならいいけど、
それ以外は、ちゃんとDDKでコンパイルして適用することをお勧めする。
2014年5月21日水曜日
2014/05/21 のMEMO
NIC driver for Windows PE
http://discussions.citrix.com/topic/284196-nic-driver-for-windows-pe/
2011年3月から続くThread。
Clearwaterで認識させる基本的なStepや、下記のような強引にNICを認識させるPatchなどで紹介されている。
CA-99235: Keep trying to remove the tag forever
https://github.com/xapi-project/sm/commit/7ca2d42adc17cfde8ec7f37c07a24293741af274
これってClearwaterでも発生するんだよね、多分。
http://discussions.citrix.com/topic/284196-nic-driver-for-windows-pe/
2011年3月から続くThread。
Clearwaterで認識させる基本的なStepや、下記のような強引にNICを認識させるPatchなどで紹介されている。
qemu_args[i] = qemu_args[i].replace('rtl8139', 'e1000')
CA-99235: Keep trying to remove the tag forever
https://github.com/xapi-project/sm/commit/7ca2d42adc17cfde8ec7f37c07a24293741af274
In the error handling path of VDI.activate, if the connection with the
master is lost, the slave cannot remove the tag from sm-config. When the
connection is restored, the VDI is left in undefined state. To avoid
this we keep trying to remove the tag until we succeed (the connection
with the host has been restored).
これってClearwaterでも発生するんだよね、多分。
2014年5月20日火曜日
XenServer.next Alpha Available for Download
http://www.xenserver.org/discuss-virtualization/virtualization-blog/entry/xenserver-next-alpha-available-for-download.htmlThe XenServer engineering team is pleased to announce the availability an alpha of the next release of XenServer, code named “Creedence”.
ちなみに、
Creedence versionってなに?っと検索すると、http://ja.wikipedia.org/wiki/%E3%82%AF%E3%83%AA%E3%83%BC%E3%83%87%E3%83%B3%E3%82%B9%E3%83%BB%E3%82%AF%E3%83%AA%E3%82%A2%E3%82%A6%E3%82%A9%E3%83%BC%E3%82%BF%E3%83%BC%E3%83%BB%E3%83%AA%E3%83%90%E3%82%A4%E3%83%90%E3%83%ABこれは、完全に別のものだと思ってた。
そうきたかw。最適な名前ですね。
絶対sarasotaだと思ってた。だってSourceに・・・
https://github.com/Zhengchai/xenadmin/blob/4100f506ca2b832ff0c207bbaaeca93a68b7e0af/XenAdminTests/XenModelTests/TestAPICallVersions.cs
って、このSource、2013年6月のものだった・・・orz
古かったのね。
Creedence Clearwater Revival (CCR)からますます目が離せないですねぇ。(意外とどっちでもよくなってる)
XenServer 6.2.50
と表示されてたんだよ。4月のBuildまでは。5月は見てない。
5/19以降のBuildでどう表示されるか試してみるか。
2014年5月16日金曜日
XenServer6.2) VIFのLocking-modeで遊んでみた
VIFのLocking-modeで遊んでみた。
VIFのlocking-modeに関してはマニュアルに書いてある通り。
端的にいうと、VIF側で利用できるIPアドレスを制限しちゃおうという機能。
試験環境
Dom0:XS62SP1(patch:-5)
PM:CentOS6.4からVM:CentOSのApache上の1MBファイルをabで取得する。
VIF状態
1GbpsNIC環境ならこんなもんですね。
外部(PM)からPINGが飛ばなくなった。
次に、IPを設定してやる。
PINGが飛ぶようになった。
レスポンスは
locking-modeを利用しても、1GbpsNICの環境では特に劣化は見られなかった。
なお、複数IPを許可したい場合には、単純に複数記述してやればよい。
参考)
vif-param-add
http://discussions.citrix.com/topic/351462-vif-param-add/
VIFのlocking-modeに関してはマニュアルに書いてある通り。
端的にいうと、VIF側で利用できるIPアドレスを制限しちゃおうという機能。
試験環境
Dom0:XS62SP1(patch:-5)
PM:CentOS6.4からVM:CentOSのApache上の1MBファイルをabで取得する。
VIF状態
[root@txs01 ~]# xe vif-param-list uuid=61694e93-42d6-465e-3fc0-2f214b973884abの結果(設定前)
uuid ( RO) : 61694e93-42d6-465e-3fc0-2f214b973884
vm-uuid ( RO): 7aa322f7-b272-c936-f4e4-55b522c7eec1
vm-name-label ( RO): CentOS-130-Apache
allowed-operations (SRO): attach; unplug
current-operations (SRO):
device ( RO): 1
MAC ( RO): 06:06:3e:45:cb:70
MAC-autogenerated ( RO): true
MTU ( RO): 1500
currently-attached ( RO): true
qos_algorithm_type ( RW):
qos_algorithm_params (MRW): kbps: 1000
qos_supported_algorithms (SRO):
other-config (MRW):
network-uuid ( RO): 1deba6e0-7167-8287-b428-0f142baa8a85
network-name-label ( RO): VLAN901
io_read_kbs ( RO): 0.000
io_write_kbs ( RO): 0.000
locking-mode ( RW): network_default
ipv4-allowed (SRW):
ipv6-allowed (SRW):
Server Software: Apache/2.2.3
Server Hostname: 10.0.1.130
Server Port: 80
Document Path: /index.html
Document Length: 1024000 bytes
Concurrency Level: 100
Time taken for tests: 8.759 seconds
Complete requests: 1000
Failed requests: 0
Write errors: 0
Total transferred: 1026769248 bytes
HTML transferred: 1026498438 bytes
Requests per second: 114.16 [#/sec] (mean)
Time per request: 875.935 [ms] (mean)
Time per request: 8.759 [ms] (mean, across all concurrent requests)
Transfer rate: 114472.43 [Kbytes/sec] received
<SNAP>
Total transferred: 1026800112 bytes
HTML transferred: 1026529302 bytes
Requests per second: 113.86 [#/sec] (mean)
Time per request: 878.284 [ms] (mean)
Time per request: 8.783 [ms] (mean, across all concurrent requests)
Transfer rate: 114169.77 [Kbytes/sec] received
<SNAP>
Total transferred: 1024270000 bytes
HTML transferred: 1024000000 bytes
Requests per second: 114.43 [#/sec] (mean)
Time per request: 873.907 [ms] (mean)
Time per request: 8.739 [ms] (mean, across all concurrent requests)
Transfer rate: 114458.81 [Kbytes/sec] received
DEVTYPE=bridge: Rx=0.948 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif12.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.948 Gbit/s, Tx=0.006 Gbit/s
| |- vif12.1: Rx=0.948 Gbit/s, Tx=0.006 Gbit/s
DEVTYPE=bridge: Rx=0.949 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif12.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.949 Gbit/s, Tx=0.006 Gbit/s
| |- vif12.1: Rx=0.949 Gbit/s, Tx=0.006 Gbit/s
DEVTYPE=bridge: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif12.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
| |- vif12.1: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
1GbpsNIC環境ならこんなもんですね。
設定変更
まず、ipvX-allowedを指定せずに locking-mode を locked に変更[root@xs01 ~]# xe vif-param-set uuid=61694e93-42d6-465e-3fc0-2f214b973884 locking-mode=locked
[root@xs01 ~]# xe vif-param-list uuid=61694e93-42d6-465e-3fc0-2f214b973884
uuid ( RO) : 61694e93-42d6-465e-3fc0-2f214b973884
vm-uuid ( RO): 7aa322f7-b272-c936-f4e4-55b522c7eec1
vm-name-label ( RO): CentOS
allowed-operations (SRO): attach; unplug
current-operations (SRO):
device ( RO): 1
MAC ( RO): 06:06:3e:45:cb:70
MAC-autogenerated ( RO): true
MTU ( RO): 1500
currently-attached ( RO): true
qos_algorithm_type ( RW):
qos_algorithm_params (MRW): kbps: 1000
qos_supported_algorithms (SRO):
other-config (MRW):
network-uuid ( RO): 1deba6e0-7167-8287-b428-0f142baa8a85
network-name-label ( RO): VLAN01
io_read_kbs ( RO): 0.000
io_write_kbs ( RO): 0.000
locking-mode ( RW): locked
ipv4-allowed (SRW):
ipv6-allowed (SRW):
外部(PM)からPINGが飛ばなくなった。
次に、IPを設定してやる。
[root@xs01 ~]# xe vif-param-set uuid=61694e93-42d6-465e-3fc0-2f214b973884 ipv4-allowed=10.0.1.130 ipv6-allowed=fe80::406:3eff:fe45:cb70
[root@xs01 ~]# xe vif-param-list uuid=61694e93-42d6-465e-3fc0-2f214b973884
uuid ( RO) : 61694e93-42d6-465e-3fc0-2f214b973884
vm-uuid ( RO): 7aa322f7-b272-c936-f4e4-55b522c7eec1
vm-name-label ( RO): CentOS
allowed-operations (SRO): attach; unplug
current-operations (SRO):
device ( RO): 1
MAC ( RO): 06:06:3e:45:cb:70
MAC-autogenerated ( RO): true
MTU ( RO): 1500
currently-attached ( RO): true
qos_algorithm_type ( RW):
qos_algorithm_params (MRW): kbps: 1000
qos_supported_algorithms (SRO):
other-config (MRW):
network-uuid ( RO): 1deba6e0-7167-8287-b428-0f142baa8a85
network-name-label ( RO): VLAN01
io_read_kbs ( RO): 0.084
io_write_kbs ( RO): 0.056
locking-mode ( RW): locked
ipv4-allowed (SRW): 10.0.1.130
ipv6-allowed (SRW): fe80::406:3eff:fe45:cb70
PINGが飛ぶようになった。
レスポンスは
DEVTYPE=bridge: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif16.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
| |- vif16.1: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
DEVTYPE=bridge: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
| |- vif16.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
| |- vif16.1: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
Total transferred: 1026134032 bytes
HTML transferred: 1025863492 bytes
Requests per second: 114.22 [#/sec] (mean)
Time per request: 875.518 [ms] (mean)
Time per request: 8.755 [ms] (mean, across all concurrent requests)
Transfer rate: 114456.18 [Kbytes/sec] received
locking-modeを利用しても、1GbpsNICの環境では特に劣化は見られなかった。
なお、複数IPを許可したい場合には、単純に複数記述してやればよい。
参考)
vif-param-add
http://discussions.citrix.com/topic/351462-vif-param-add/
2014年5月15日木曜日
XenServer6.2 ) interface-rename COMMAND
How to Change Order of NICs in XenServer 6.x
http://support.citrix.com/article/CTX135809interface-renameってコマンドを使ってみた。
[root@xs01 ~]# interface-rename --help
usage: interface-rename --rename|--list|--update <args>|--reset-to-install [-v] [-d]
Utility for managing the naming of physical network interfaces. It is used to
undo the damage of race condition for device drivers grabbing eth names on
boot, taking into account naming policies provided at install time. In
addition, it implements sensible policies when network hardware changes, and
the ability for manual alteration of the policies after install.
options:
--version show program's version number and exit
-h, --help show this help message and exit
-v, --verbose increase logging
-d, --dry-run dry run - don't write any state back to disk
Actions:
Exactly one action is expected
-r, --rename rename physical interfaces. It is not safe to rename
interfaces which have traffic passing, or higher level
networking constructs on them (bonds/bridges/etc).
Use at your own risk after boot
-l, --list list current physical device information in a concise
manner as a reference for --update
-u, --update manually update the order of devices. <args> should
be one or more <target eth name>=MAC|PCI|Phys|"SMBios"
--reset-to-install reset configuration to install state
renameとupdateはCLIから利用することはないだろうね・・・
listはNICのドライバ一覧を取得するのに便利だね。
[root@xs01 ~]# interface-rename --list
ERROR [2014-05-13 19:17:46] Can't generate current state for interface '{'Driver': '802.1Q VLAN Support', 'Bus Info': '', 'BIOS device': {'all_ethN': 'eth6', 'physical': ''}, 'Assigned MAC': '00:1B:21:79:BB:9B', 'Firmware version': 'N/A', 'Driver version': '1.8', 'Kernel name': 'bond1.901'}' - Unrecognised PCI address ''
ERROR [2014-05-13 19:17:46] Can't generate current state for interface '{'Driver': '802.1Q VLAN Support', 'Bus Info': '', 'BIOS device': {'all_ethN': 'eth7', 'physical': ''}, 'Assigned MAC': '00:1B:21:79:BB:9B', 'Firmware version': 'N/A', 'Driver version': '1.8', 'Kernel name': 'bond1.902'}' - Unrecognised PCI address ''
ERROR [2014-05-13 19:17:46] Can't generate current state for interface '{'Driver': '802.1Q VLAN Support', 'Bus Info': '', 'BIOS device': {'all_ethN': 'eth8', 'physical': ''}, 'Assigned MAC': '00:1B:21:79:BB:9B', 'Firmware version': 'N/A', 'Driver version': '1.8', 'Kernel name': 'bond1.903'}' - Unrecognised PCI address ''
Name MAC PCI ethN Phys SMBios Driver Version Firmware
eth0 00:26:2d:08:12:78 0000:01:00.0 eth0 em1 igb 4.1.2 2.5, 0xf1300000
eth1 00:26:2d:08:12:79 0000:01:00.1 eth1 em2 igb 4.1.2 2.5, 0xf1300000
eth2 00:1b:21:79:bb:9a 0000:03:00.0 eth2 p2p1 e1000e 2.3.2-NAPI 5.11-2
eth3 00:1b:21:79:bb:9b 0000:03:00.1 eth3 p2p2 e1000e 2.3.2-NAPI 5.11-2
eth4 00:1b:21:79:ba:94 0000:04:00.0 eth4 p1p1 e1000e 2.3.2-NAPI 5.11-2
eth5 00:1b:21:79:ba:95 0000:04:00.1 eth5 p1p2 e1000e 2.3.2-NAPI 5.11-2
インストール時の状態にリセットも可能っぽい(今回は、Dry-Run)
[root@xs01 ~]# interface-rename --dry-run --reset-to-install
INFO [2014-05-13 19:20:31] Dry Run - logging to stdout instead of '/var/log/interface-rename.log'
INFO [2014-05-13 19:20:31] Would copy '/etc/sysconfig/network-scripts/interface-rename-data/.from_install/static-rules.conf' to '/etc/sysconfig/network-scripts/interface-rename-data/static-rules.conf' if not dry run
INFO [2014-05-13 19:20:31] Would copy '/etc/sysconfig/network-scripts/interface-rename-data/.from_install/dynamic-rules.json' to '/etc/sysconfig/network-scripts/interface-rename-data/dynamic-rules.json' if not dry run
INFO [2014-05-13 19:20:31] Would write:
# Automatically generated file from /etc/sysconfig/network-scripts/interface-rename.py
ACTION!="add" GOTO="network-done"
# Rules generated from static configuration and last boot data
# Rename unrecognised devices sideways to deal with them later
SUBSYSTEM=="net" KERNEL=="eth*" PROGRAM="/etc/udev/scripts/net-rename-sideways.sh %k" NAME="%c"
LABEL="network-done"
to '/etc/udev/rules.d/60-net.rules' if not dry run
INFO [2014-05-13 19:20:31] All Done
こんなところにInstall時の設定が退避されるんだね。
見てみよう
[root@xs01 ~]# cd /etc/sysconfig/network-scripts/interface-rename-data/.from_install/JSONだって。
[root@xs01 .from_install]# ls
dynamic-rules.json static-rules.conf
MACとPCI BUSとETHで構成されるだけだった。
なお、ファイルの見方は static-rules.confに書いてある。
[root@xs01 .from_install]# more dynamic-rules.jsonlistくらいしか用途を見いだせなかった。
# Automatically adjusted file. Do not edit unless you are certain you know how to
{
"lastboot": [
[
"00:1B:21:79:BB:9B",
"0000:03:00.1",
"eth3"
],
[
"00:1B:21:79:BA:95",
"0000:04:00.1",
"eth5"
],
[
"00:26:2D:08:12:78",
"0000:01:00.0",
"eth0"
],
[
"00:1B:21:79:BA:94",
"0000:04:00.0",
"eth4"
],
[
"00:26:2D:08:12:79",
"0000:01:00.1",
"eth1"
],
[
"00:1B:21:79:BB:9A",
"0000:03:00.0",
"eth2"
]
],
"old": []
}
登録:
投稿 (Atom)
