Skip to content

v1.2.5

Latest

Choose a tag to compare

@github-actions github-actions released this 02 Oct 19:38
· 8 commits to main since this release
387b992

[1.2.5] - 2026-10-03

Fixed

  • Online snapshots failed at the filesystem freeze, and the agent claimed it had frozen. guestkitd runs as zyvor-agent with an empty capability set, but the QGA handlers guest-fsfreeze-freeze/-thaw ran fsfreeze themselves, so every freeze failed with Operation not permitted and KubeVirt failed the snapshot of any VM with PVC-backed disks (measured on Ubuntu 24.04 under KubeVirt 1.9: a freshly installed agent cannot freeze; with CAP_SYS_ADMIN it can). The unit file already says privileged operations run in guestkitd-exec; freeze and thaw now do: a new fsfreeze action in the helper (freeze/thaw only, always /) and executor_ipc::fsfreeze() for the agent, falling back to an in-process call only when no helper is running (agent run as root). Also, snapshot_hooks::freeze_filesystems/thaw_filesystems treated a successfully spawned fsfreeze as success (status().is_ok()), so snapshot.prepare reported fs_frozen: true while nothing was frozen; they now use the same checked path. Covered by a test that starts the real guestkitd-exec with a fake fsfreeze. Requires the helper service (zyvor-guest-agent-exec.service, enabled by the packages) to be running.
  • Linux agent never connected to the hypervisor channel on stock distros. The virtio port (/dev/virtio-ports/org.qemu.guest_agent.0) is root:root 0600 but guestkit-agent.service runs as zyvor-agent, so the agent started, logged failed to open virtio channel, and KubeVirt reported no guest agent. The DEB, RPM and tarball now ship 60-zyvor-guest-agent.rules (group zyvor-agent, mode 0660 for org.qemu.guest_agent.0 and com.zyvor.guestkit.0) and reload/trigger udev on install. Verified on Ubuntu 24.04 under KubeVirt 1.9: with the rule the agent connects (agentConnected), without it it does not.
  • Concurrent NBD allocate+connect — NbdDevice::connect holds a cross-process flock (/run/lock/guestkit-nbd.lock, fallback /tmp) across free-device selection and qemu-nbd -c, and retries the next free index on failure. Fixes races where two mounts claimed the same /dev/nbdN (fluxvm#104: /dev/nbd0p1 already mounted, wrong guest-agent token). new() no longer claims a device index before connect.

Added

  • Offline inject on run_migrate_repair — optional inject_json appends hostname, network files, users, services, first-boot scripts, cloud-init user-data, Active Directory rejoin, Windows KMS reactivation, and RDP enable to the repair plan. Empty or "null" is a no-op. guestkit migrate-repair has no inject flag; h2kvm passes the JSON from Python.
  • Live guest fix helpers — live_fix_commands() returns shell lines (regenerate initramfs, update GRUB, optionally remove open-vm-tools). run_live_plan(commands, dry_run=False) runs those lines on the machine where Python is executing. It does not SSH.
  • Docs: README is now a landing page — the detailed sections moved into docs/ (quick-start, who-does-what, capabilities, oss-vs-enterprise, platform-layout, repository-layout, documentation-map, ...); every earlier README anchor still resolves.