You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
[1.2.5] - 2026-10-03
Fixed
Online snapshots failed at the filesystem freeze, and the agent claimed it had frozen.guestkitd runs as zyvor-agent with an empty capability set, but the QGA handlers guest-fsfreeze-freeze/-thaw ran fsfreeze themselves, so every freeze failed with Operation not permitted and KubeVirt failed the snapshot of any VM with PVC-backed disks (measured on Ubuntu 24.04 under KubeVirt 1.9: a freshly installed agent cannot freeze; with CAP_SYS_ADMIN it can). The unit file already says privileged operations run in guestkitd-exec; freeze and thaw now do: a new fsfreeze action in the helper (freeze/thaw only, always /) and executor_ipc::fsfreeze() for the agent, falling back to an in-process call only when no helper is running (agent run as root). Also, snapshot_hooks::freeze_filesystems/thaw_filesystems treated a successfully spawnedfsfreeze as success (status().is_ok()), so snapshot.prepare reported fs_frozen: true while nothing was frozen; they now use the same checked path. Covered by a test that starts the real guestkitd-exec with a fake fsfreeze. Requires the helper service (zyvor-guest-agent-exec.service, enabled by the packages) to be running.
Linux agent never connected to the hypervisor channel on stock distros. The virtio port (/dev/virtio-ports/org.qemu.guest_agent.0) is root:root 0600 but guestkit-agent.service runs as zyvor-agent, so the agent started, logged failed to open virtio channel, and KubeVirt reported no guest agent. The DEB, RPM and tarball now ship 60-zyvor-guest-agent.rules (group zyvor-agent, mode 0660 for org.qemu.guest_agent.0 and com.zyvor.guestkit.0) and reload/trigger udev on install. Verified on Ubuntu 24.04 under KubeVirt 1.9: with the rule the agent connects (agentConnected), without it it does not.
Concurrent NBD allocate+connect — NbdDevice::connect holds a cross-process flock (/run/lock/guestkit-nbd.lock, fallback /tmp) across free-device selection and qemu-nbd -c, and retries the next free index on failure. Fixes races where two mounts claimed the same /dev/nbdN (fluxvm#104: /dev/nbd0p1 already mounted, wrong guest-agent token). new() no longer claims a device index before connect.
Added
Offline inject on run_migrate_repair — optional inject_json appends hostname, network files, users, services, first-boot scripts, cloud-init user-data, Active Directory rejoin, Windows KMS reactivation, and RDP enable to the repair plan. Empty or "null" is a no-op. guestkit migrate-repair has no inject flag; h2kvm passes the JSON from Python.
Live guest fix helpers — live_fix_commands() returns shell lines (regenerate initramfs, update GRUB, optionally remove open-vm-tools). run_live_plan(commands, dry_run=False) runs those lines on the machine where Python is executing. It does not SSH.
Docs: README is now a landing page — the detailed sections moved into docs/ (quick-start, who-does-what, capabilities, oss-vs-enterprise, platform-layout, repository-layout, documentation-map, ...); every earlier README anchor still resolves.