Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
204 commits
Select commit Hold shift + click to select a range
74fa3df
CP-309972: Configurable between ldap and ldaps during join domain
Jan 9, 2026
e300f70
CP-309972: Configurable between ldap and ldaps during join domain
Mar 9, 2026
3afd88a
CP-309972: Configurable between ldap and ldaps during join domain (#6…
liulinC Mar 11, 2026
63addaf
Merge master to feature/ldaps (#6944)
liulinC Mar 12, 2026
cf6575b
Sync master to feature branch (#6948)
liulinC Mar 16, 2026
a8d4ce6
CP-311021: Add API external_auth_set_ldaps
Jan 28, 2026
928e0b2
CP-311021: Refine for comments
liulinC Mar 16, 2026
f383999
CP-311021: Add API external_auth_set_ldaps (#6946)
liulinC Mar 19, 2026
25fe631
CP-311257: Add try_map_any to listext
Mar 19, 2026
da6c8bf
CP-311257: Raise proper error code
Mar 17, 2026
e17315c
CP-311257: Raise proper error code (#6963)
liulinC Mar 23, 2026
0bcc46e
CP-311293: Add sync between set ldaps and other query ops
Mar 23, 2026
596b991
CP-311293: Add sync between set ldaps and other query ops (#6966)
liulinC Mar 24, 2026
0e1394a
CP-309846: Select proper AD certificate
Mar 23, 2026
794844f
CP-309846: Select proper AD certificate (#6975)
liulinC Mar 26, 2026
5b60d41
Sync master to feature branch (#6984)
liulinC Mar 27, 2026
5a62181
Sync master to feature branch (#6985)
liulinC Mar 30, 2026
5f08edd
CP-311259: Use Tls_policy to configure cipher suites
Mar 24, 2026
63e8b94
CP-311259: Use Tls_policy to configure cipher suites (#6976)
liulinC Mar 31, 2026
c830695
CP-311860: pool.join: sync ldaps status with pool coordinator
Mar 31, 2026
a74ef93
CP-311860: register auth_no_certs error message
Mar 31, 2026
8253466
CP-311860: pool.join: sync ldaps status with pool coordinator (#6986)
liulinC Apr 2, 2026
5df4794
CP-312077: Set winbind_keep_configuration to true by default
Apr 3, 2026
8f846bb
CP-312077: Set winbind_keep_configuration to true by default (#6990)
liulinC Apr 9, 2026
15ec9dc
Merge branch 'master' into private/linl/sync
Apr 28, 2026
e7f51b6
sync master to feature branch (#7040)
liulinC Apr 29, 2026
7ca7274
Merge branch 'master' into private/linl/sync
May 6, 2026
ad94af6
sync master to feature branch (#7053)
liulinC May 7, 2026
dc4b03a
CP-311896: ldaps feature sync with trusted certs
Apr 22, 2026
b1eeff8
CP-311896: ldaps feature sync with trusted certs (#7054)
liulinC May 7, 2026
684685b
Update document for pool.sync_trusted_certificates_from
minglumlu May 7, 2026
91596ab
CP-311981: Add pool.sync_trusted_certificates_from API
minglumlu Apr 27, 2026
fed0b33
fixup! CP-311981: Add pool.sync_trusted_certificates_from API
minglumlu May 12, 2026
651b8ba
Add pool.sync_trusted_certificates_from API (#7056)
minglumlu May 13, 2026
aa28513
sync master to feature branch (#7065)
liulinC May 13, 2026
dea642b
sync master to feature branch due to xen update merge (#7076)
liulinC May 15, 2026
d77241a
CP-311213: Provides more detailed error message
May 15, 2026
51b3030
storage: Add tags to vdi_info struct
last-genius May 18, 2026
42cb9bd
storage: Add VDI.{add_tags,remove_tags} methods
last-genius May 18, 2026
e13b4b9
CP-311213: Provides more detailed error message (#7075)
liulinC May 19, 2026
508e3f6
CA-427607: Report no_support_encrypt_type error
May 20, 2026
9baedba
CA-427607: Report no_support_encrypt_type error (#7082)
liulinC May 21, 2026
7d249ae
Merge branch 'master' into private/linl/sync
May 21, 2026
0f19f31
Sync master to feature branch (#7087)
liulinC May 21, 2026
76a4fcf
CA-427727: Failed to join host to pool due to ldaps sync failed
May 21, 2026
2ba80ee
CA-427727: Failed to join host to pool due to ldaps sync failed (#7089)
liulinC May 22, 2026
6d1f091
Merge branch 'master' into private/linl/dev
Jun 2, 2026
0e59597
feature branch sync (#7110)
liulinC Jun 2, 2026
7c02362
CA-428177: clarify ldaps trusted certificate error messages
Jun 3, 2026
37f6e7e
CA-428177: clarify ldaps trusted certificate error messages (#7111)
liulinC Jun 5, 2026
76c7e26
storage: Preserve VDI tags on SMAPIv1 migrate
last-genius May 18, 2026
fb69250
CA-428436: validate DC LDAPS certificate before joining domain
Jun 9, 2026
fb2e37c
CA-428436: validate DC LDAPS certificate before joining domain (#7121)
liulinC Jun 12, 2026
45b356f
Merge branch 'master' into private/linl/sync
liulinC Jun 12, 2026
c4886eb
Sync master to feature branch (#7128)
liulinC Jun 12, 2026
d57c84d
CA-428461: make trusted-domain attribute enrichment best-effort
liulinC Jun 11, 2026
1a4b39f
CA-428461: make trusted-domain attribute enrichment best-effort (#7126)
liulinC Jun 15, 2026
e68fa90
CA-403379: pre-flight cluster_host state before pool-ha-enable
LunfanZhang Jun 15, 2026
0f6edc1
README: Add instructions for installing developer tools
last-genius Jun 22, 2026
74bdf42
README: Add instructions for installing developer tools (#7136)
last-genius Jun 23, 2026
ea81df8
CP-310955: Update friendly error messages (#7108)
xueqingz Jun 23, 2026
8109f32
networkd: make Dhclient.stop to stop the DHCP client managing the int…
semarie Jun 19, 2026
0d3b9a6
networkd: make Dhclient.ensure_running to discard previously assigned…
semarie Jun 19, 2026
2ea48ef
dhclient: add comments on functions
semarie Jun 19, 2026
83e7241
networkd: refactor set_ipv{4,6}_conf functions
semarie Jun 19, 2026
79135d0
CA-417915: stunnel proxy process is not reaped during stop
minglumlu Jun 24, 2026
593360e
CA-417915: stunnel proxy process is not reaped during stop (#7140)
minglumlu Jun 25, 2026
616b58c
dhclient: add `set_stale` (and remove `remove_conf_file`) in public i…
semarie Jun 19, 2026
a0fc1d1
xe: Fix bash completion for 'xe vlan-create pif-uuid='
last-genius Jun 25, 2026
385fba2
xcp-networkd: dhclient cleanup (#7138)
last-genius Jun 25, 2026
3e43f1f
xe: Fix bash completion for 'xe vlan-create pif-uuid=' (#7142)
last-genius Jun 26, 2026
71a2576
Remove image format from deprecated receive start
gthvn1 Jun 26, 2026
d5dacc6
Merge branch 'master' into private/linl/sync
Jun 29, 2026
67dad04
sync master to feature branch (#7148)
liulinC Jun 29, 2026
242f6db
Remove image format from deprecated receive start (#7144)
changlei-li Jun 29, 2026
ccf0368
CP-312131: set LDAPS datamodel lifecycle version to 26.15.0-next
liulinC Jun 29, 2026
cfa60cc
CP-312131: regenerate datamodel_lifecycle.ml for sync_trusted_certifi…
liulinC Jun 29, 2026
fce3436
Update release version to 26.15.0-next (#7152)
minglumlu Jun 29, 2026
9913e47
CA-403379: pre-flight cluster_host state before pool-ha-enable (#7130)
LunfanZhang Jun 30, 2026
b6a72e4
Merge feature branch to master (#7149)
changlei-li Jun 30, 2026
3bc7574
build(deps): bump com.fasterxml.jackson.core:jackson-databind
dependabot[bot] Jun 30, 2026
3a1d714
CA-429144: Do not leak new vbds after snapshot
changlei-li Jul 1, 2026
d7e6fc2
CA-429144: Do not leak new vbds after snapshot (#7156)
changlei-li Jul 1, 2026
f5bd7c8
build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.…
psafont Jul 1, 2026
2a68366
Revert "dhclient: add `set_stale` (and remove `remove_conf_file`) in …
semarie Jul 2, 2026
d1dfc57
Revert "networkd: refactor set_ipv{4,6}_conf functions"
semarie Jul 2, 2026
7658162
Revert "dhclient: add comments on functions"
semarie Jul 2, 2026
6b21257
Revert "networkd: make Dhclient.ensure_running to discard previously …
semarie Jul 2, 2026
3fda4fa
Revert "networkd: make Dhclient.stop to stop the DHCP client managing…
semarie Jul 2, 2026
2f29f5e
Revert xcp-networkd: dhclient cleanup (#7138) (#7159)
changlei-li Jul 2, 2026
3b63bc0
xapi: report a clear error when host evacuation is blocked by unprote…
olivierlambert Jun 28, 2026
19c4386
quicktest: Verify non-snapshotted VBDs are not leaked on VM.revert
last-genius Jul 3, 2026
331227c
CA-428532: Ensure db flush is executed in shutdown_agent
changlei-li Jul 6, 2026
c6bf6cf
Update lifecycle
changlei-li Jul 6, 2026
ad4e6bb
quicktest: Verify non-snapshotted VBDs are not leaked on VM.revert (#…
last-genius Jul 6, 2026
7c3b3eb
CA-428532: Ensure db flush is executed in shutdown_agent (#7164)
changlei-li Jul 6, 2026
22bfccb
auto-mark new VMs for Secure Boot certificate update on boot
Jun 30, 2026
d862fad
change schema hash
Jun 30, 2026
4c1acbd
always record VM secureboot_certificates_state at creation
Jul 3, 2026
651d067
change release version
Jul 6, 2026
7c02d20
auto-mark new VMs for Secure Boot certificate update on boot (#7155)
stephenchengCloud Jul 7, 2026
f9b42e6
xapi: report a clear error when host evacuation is blocked by unprote…
last-genius Jul 8, 2026
85724ce
doc: Update snapshot revert design to follow the implementation
last-genius Jul 9, 2026
406574e
Drop redundant secureboot_certificates_state recompute
Jul 8, 2026
c518d66
Drop redundant secureboot_certificates_state recompute (#7167)
stephenchengCloud Jul 10, 2026
7dffaf0
doc: Update snapshot revert design to follow the implementation (#7170)
last-genius Jul 10, 2026
9e49a3b
XCPNG-3545: Clear tunnels with corrupted PIFs
contificate Jul 13, 2026
8d0ef64
CP-312949: xenopsd: optional kTLS sender for VM live migration
mg12ctx May 26, 2026
a7917d8
CP-313264: xenopsd: migration-tls.md: add design document
mg12ctx Jun 29, 2026
94abfa9
CP-313264: xenopsd: log the negotiated kTLS version and cipher
mg12ctx Jul 9, 2026
ea79766
CA-422619: Skip xapi-clusterd start when already active
Jul 14, 2026
9fe1935
CA-422619: Add a timeout to the xapi-clusterd start
Jul 14, 2026
481997f
CP-313264: introduce faster migration datapath using kernel TLS (kTLS…
mg12 Jul 14, 2026
6138869
Corrected certificate validation for HTTP calls
kc284 Jul 3, 2026
00cb2ac
[SDK] Corrected certificate validation for HTTP calls (#7176)
minglumlu Jul 15, 2026
5d5bcc0
XCPNG-3545: Clear tunnels with corrupted PIFs (#7172)
contificate Jul 15, 2026
246390b
Start SM service after dbsync to avoid startup deadlock
gthvn1 Jul 10, 2026
48db100
vlan_tag_invalid: change the documentation string
semarie Mar 25, 2026
68c50c3
VLAN filtering on VIF
semarie Mar 25, 2026
d8fcd26
xenopsd: Device.Vif.add: add trunks attribute in debug string
semarie Jul 6, 2026
887d6ac
xenopsd: update xenstore while updating xapi db
semarie Jul 6, 2026
1f50380
test_vif_trunks: cover more coherence checks
semarie Jul 7, 2026
473877a
Rename README.markdown to README.md
shindere Jul 10, 2026
4999805
Update the URL of the OCaml web site
shindere Jul 10, 2026
9e2c7e5
Add explanations re:Storage Repositories to the Xen-API overview
shindere Jul 17, 2026
1a2cfbb
Cosmetic changes to README (#7181)
last-genius Jul 17, 2026
2de2f25
VLAN filtering on VIF (#7123)
changlei-li Jul 21, 2026
f13f3c9
Following action for README.markdown to README.md
changlei-li Jul 21, 2026
b08a580
Following action for README.markdown to README.md (#7183)
last-genius Jul 21, 2026
1f6c257
Rate limit: Implement token buckets
cplaursen Apr 2, 2026
5f89004
Rate limit: Implement queueing mechanism
cplaursen Apr 2, 2026
568d12b
Add tests for rate limits and token buckets
cplaursen May 21, 2026
b5d7809
Add LRU cache to rate limiting library
cplaursen May 21, 2026
ed0a4ef
Add caller table to rate limit library
cplaursen May 21, 2026
614c601
Add caller statistics tracker to rate limit library
cplaursen May 21, 2026
cb516bf
Update rate limit library name to avoid name clashes
cplaursen Jun 3, 2026
89d5b6e
Add Caller and Rate_limit datamodels
cplaursen Jun 3, 2026
b7e85ee
Instrument RPC calls with usage logging and rate limiting
cplaursen Jun 3, 2026
d4e0a8e
Add rate limit and caller to xapi CLI
cplaursen Jun 3, 2026
161986a
Add quicktest for rate limiting
cplaursen Jun 3, 2026
864b939
Update rate limit design document with correct caller API
cplaursen Jun 4, 2026
c23768a
xapi-caller: Load call costs from external file at startup
cplaursen Jun 30, 2026
ed9f84b
rate-limit: Remove fairness bug in worker thread
cplaursen Jul 3, 2026
6981f80
rate-limit: Allow tokens to go negative on big requests
cplaursen Jul 7, 2026
492edf4
xapi_caller: Initialise caller table on module load
cplaursen Jul 9, 2026
7e5baf2
quicktest: Use more realistic bounds in rate limit test
cplaursen Jul 9, 2026
e19c9a4
http-lib: Canonicalise IPv4-mapped IPv6 client addresses
cplaursen Jul 13, 2026
f08fc10
xapi_caller: Serialise all caller_table mutations
cplaursen Jul 13, 2026
4e27cb0
rate-limit: Skip redundant caller refreshes
cplaursen Jul 13, 2026
53dd81a
CA-422619: Skip xapi-clusterd start when already active (#7178)
BengangY Jul 22, 2026
eb746b7
CA-430005: Should not check non-trusted certificates for duplication
minglumlu Jul 22, 2026
cc456ac
Add rate limiting to xapi (#7186)
cplaursen Jul 22, 2026
7c9db2c
rate-limit: Fix deadlock in rate limit deletion
cplaursen Jul 22, 2026
8b58237
opam: Fix rate limit package dependencies
cplaursen Jul 23, 2026
ba83ef6
xe: print debug info for all connection attempts
shindere Jul 23, 2026
aade641
Add debug messages for all connection methods in the `xe= CLI client …
last-genius Jul 23, 2026
bc3dd17
opam: Fix rate limit package dependencies (#7193)
cplaursen Jul 23, 2026
4b9b9aa
CA-430005: Should not check non-trusted certificates for duplication …
minglumlu Jul 24, 2026
b59864f
rate-limit: Fix deadlock in rate limit deletion (#7189)
cplaursen Jul 24, 2026
e730da0
CA-430085: Fix vncsnapshot 500 error
cplaursen Jul 28, 2026
115bd59
[ci] Don't use timedatectl to set timezone in actions
changlei-li Jul 31, 2026
8cf7f83
[ci] Don't use timedatectl to set timezone in actions (#7203)
BengangY Jul 31, 2026
4eb841c
CA-430085: Fix vncsnapshot 500 error (#7202)
cplaursen Jul 31, 2026
cc62cb3
xapi-rate-limit: Add auto-registered caller limit
cplaursen Jul 28, 2026
b3929f3
rate-limit: Only show caller groups in the RRDs
cplaursen Jul 29, 2026
11eeeb6
rate-limit: Improve debug messages when rate limit applied
cplaursen Jul 30, 2026
c1ea186
CA-430018: Fix mismatch between VGPU and PCI cards
freddy77 Jul 28, 2026
ae4d3ec
scripts/attach-static-vdis: Toggle nullglob to fix behavior on empty dir
last-genius Aug 3, 2026
b8779e0
Fix memory issues with caller rrd (#7201)
cplaursen Aug 3, 2026
b9114fd
xapi_globs: Remove unused code
last-genius Jul 21, 2026
d09606d
rate-limit: Add observers to rate limited calls
cplaursen Jul 14, 2026
f5c75e0
rate-limit: Add observers to rate limited calls (#7190)
cplaursen Aug 3, 2026
1100233
pygrub-wrapper: Drop the script, move logic into xenopsd
last-genius Aug 3, 2026
ac93801
CA-430018: Fix mismatch between VGPU and PCI cards (#7198)
cplaursen Aug 4, 2026
a4dcbfe
CA-426637: Drain the remaining bytes in metadata_handler
changlei-li Aug 5, 2026
64be2ce
CP-314075: restore VDI.resize_online for online VDI resize
MarkSymsCtx Aug 4, 2026
4aaa358
CP-314075: allow reintroduction of removed lifecycle features
MarkSymsCtx Aug 6, 2026
610b848
pygrub misc cleanup (#7206)
minglumlu Aug 10, 2026
b6d3a8d
CA-429051: Sync original bond slave network MTU
changlei-li Aug 7, 2026
461ab30
CP-314075: restore VDI.resize_online for online VDI resize (#7211)
MarkSymsCtx Aug 10, 2026
cd53b06
Add explanations re:Storage Repositories to the Xen-API overview (#7101)
gthvn1 Aug 10, 2026
259c4cd
Update datamodel_lifecycle.ml after release v26.17.0
minglumlu Aug 11, 2026
72073f9
Update datamodel_lifecycle.ml after release v26.17.0 (#7215)
minglumlu Aug 11, 2026
b56692c
scripts/attach-static-vdis: Toggle nullglob to fix behavior on empty …
last-genius Aug 11, 2026
f484dd5
CA-430002: Clean up sysprep SR when the SR directory doesn't exist
minglumlu Aug 10, 2026
2415721
Remove unnecessary guard on sysprep cleanup
minglumlu Aug 11, 2026
382c16b
Start SM service after dbsync to avoid startup deadlock (#7179)
last-genius Aug 12, 2026
ddceacd
CA-429051: Sync original bond slave network MTU (#7213)
changlei-li Aug 14, 2026
b638834
CP-314125: Fetch only required fields in gc_connector
cplaursen Aug 14, 2026
f78797a
CA-430002: Clean up sysprep SR when the SR directory doesn't exist (…
minglumlu Aug 17, 2026
ded956f
CA-426637: Drain the remaining bytes in metadata_handler (#7209)
changlei-li Aug 17, 2026
d124cef
CP-314125: Fetch only required fields in gc_connector (#7225)
cplaursen Aug 18, 2026
9d8a3fa
Preserve VDI tags on migration (#7080)
last-genius Aug 18, 2026
3906bf2
xenopsd/xc: mirror CDF_TRAP_UNMAPPED_ACCESSES from Xenctrl
d3athjest3r Jul 24, 2026
eeeddbc
xenopsd/xc: mirror altp2m_count from Xenctrl.domctl_create_config
d3athjest3r Jul 24, 2026
efe0a80
Explain how to work with several branches
shindere Aug 18, 2026
4f73f9e
CA-375277: xenctrlext_stubs.c: add missing enter/leave blocking section
edwintorok Aug 18, 2026
5ebdd97
CA-375277: unixpwd_stubs.c: factor out common code and release the ru…
edwintorok Aug 18, 2026
5af66e6
Explain how to work with several branches (#7222)
changlei-li Aug 20, 2026
3dfce15
xenopsd/xc: set CDF_TRAP_UNMAPPED_ACCESSES for ARM domains
d3athjest3r Aug 20, 2026
e2ee48d
CA-375277: OCaml C stubs: release the runtime lock around blocking ca…
minglumlu Aug 21, 2026
416046f
Fix format: xenopsd/xc: set CDF_TRAP_UNMAPPED_ACCESSES for ARM domains
minglumlu Aug 24, 2026
33a55da
xenopsd/xc: sync domain.ml with Xen 4.21's Xenctrl ABI additions (#7197)
minglumlu Aug 24, 2026
4339842
Merge master branch to the feature/sxm-v3
LunfanZhang Aug 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/generate-and-build-sdks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ jobs:
# isn't using UTC
- name: Set Timezone to Tokyo for datetime tests
run: |
sudo timedatectl set-timezone Asia/Tokyo
sudo ln -sf /usr/share/zoneinfo/Asia/Tokyo /etc/localtime

- name: Run CI for SDKs
uses: ./.github/workflows/sdk-ci
Expand Down Expand Up @@ -139,7 +139,7 @@ jobs:
# isn't using UTC
- name: Set Timezone to Tokyo for datetime tests
run: |
sudo timedatectl set-timezone Asia/Tokyo
sudo ln -sf /usr/share/zoneinfo/Asia/Tokyo /etc/localtime

- name: Build Java SDK
shell: bash
Expand Down
3 changes: 1 addition & 2 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -138,7 +138,6 @@ install-extra:
install -D ./ocaml/xenopsd/scripts/xen-backend.rules $(DESTDIR)/$(ETCDIR)/udev/rules.d/xen-backend.rules
install -D ./ocaml/xenopsd/scripts/qemu-wrapper $(DESTDIR)/$(QEMU_WRAPPER_DIR)/qemu-wrapper
install -D ./ocaml/xenopsd/scripts/swtpm-wrapper $(DESTDIR)/$(QEMU_WRAPPER_DIR)/swtpm-wrapper
install -D ./ocaml/xenopsd/scripts/pygrub-wrapper $(DESTDIR)/$(QEMU_WRAPPER_DIR)/pygrub-wrapper
DESTDIR=$(DESTDIR) SBINDIR=$(SBINDIR) QEMU_WRAPPER_DIR=$(QEMU_WRAPPER_DIR) XENOPSD_LIBEXECDIR=$(XENOPSD_LIBEXECDIR) ETCDIR=$(ETCDIR) ./ocaml/xenopsd/scripts/make-custom-xenopsd.conf

# common flags and packages for 'dune install' and 'dune uninstall'
Expand Down Expand Up @@ -182,7 +181,7 @@ install:
chmod +x $(DESTDIR)$(DOCDIR)/doc-convert.sh
# backward compat with existing specfile, to be removed after it is updated
find $(DESTDIR) -name '*.cmxs' -delete
for pkg in xapi-debug xapi xe xapi-tools xapi-sdk vhd-tool qcow-stream-tool; do for f in CHANGELOG LICENSE README.markdown; do rm $(DESTDIR)$(OPTDIR)/doc/$$pkg/$$f $(DESTDIR)$(PREFIX)/doc/$$pkg/$$f -f; done; for f in META dune-package opam; do rm $(DESTDIR)$(LIBDIR)/$$pkg/$$f -f; done; done;
for pkg in xapi-debug xapi xe xapi-tools xapi-sdk vhd-tool qcow-stream-tool; do for f in CHANGELOG LICENSE README.md; do rm $(DESTDIR)$(OPTDIR)/doc/$$pkg/$$f $(DESTDIR)$(PREFIX)/doc/$$pkg/$$f -f; done; for f in META dune-package opam; do rm $(DESTDIR)$(LIBDIR)/$$pkg/$$f -f; done; done;


uninstall:
Expand Down
46 changes: 45 additions & 1 deletion README.markdown → README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ Xen API (or xapi) is a management stack that configures and controls
Xen-enabled hosts and resource pools, and coordinates resources
within the pool. Xapi exposes the Xen API interface for many
languages and is a component of the XenServer project.
Xen API is written mostly in [OCaml](http://caml.inria.fr/ocaml/)
Xen API is written mostly in [OCaml](https://ocaml.org)
4.07.

Xapi is the main component produced by the Linux Foundation's
Expand Down Expand Up @@ -59,6 +59,10 @@ To build xen-api from source, we recommend using [opam](https://opam.ocaml.org/d

```bash
opam install xs-toolstack

# Install developer tools (utop, ocamlformat, ocaml-lsp-server, etc.)
opam install dev-tools

# Update the current switch. (You're already on the correct one, just refresh it).
eval $(opam env)
```
Expand All @@ -73,6 +77,46 @@ To build xen-api from source, we recommend using [opam](https://opam.ocaml.org/d

The binaries should now be in `./_build/install/default/bin`!

Working With Several Branches
-----------------------------

When working on this repository as a regular contributor, one generally
has to work with several branches: the master branch and
lifecycle-management (LCM) branches. The following two recommendations
make such workflows easier:

- Create one Opam switch per branch you work on. This is because
different branches of this repository may have different dependencies.
In particular, this means that different branches may have to get
their dependencies from different branches of the xs-opam repository.
As repository definitions are global to Opam rather than local to a
given switch, if a branch of this repository needs to get its
dependencies from a branch other than master in xs-opam, then that
other branch will have to be added with a different repository name
(see example below).

- Use `git worktree` to make sure that different branches are checked
out at different locations on your file system. This is because
pinning makes it so that Opam expects certain dependencies to be
available at certain paths. When not using work trees, the same path
can refer to different versions of a same file as the checked out
branch changes.

For instance, assuming the `26.1-lcm` branch, which takes its
dependencies from the 6.99-lcm branch of the xs-opam repository, has
been checked out in a Git work tree somewhere on your file system, here
is how to proceed to create an Opam switch that will work for this
branch:

```
export OCAML_VERSION_FULL="4.14.2"
opam switch create xen-api-26.1-lcm ocaml-base-compiler.$OCAML_VERSION_FULL
eval $(opam env --switch=xen-api-26.1-lcm --set-switch)
opam repo add xs-opam-6.99-lcm "https://github.com/xapi-project/xs-opam.git#6.99-lcm"
opam repo remove default
opam install xs-toolstack
```

Working From a Fork
-------------------
If you are working from within a clone of a fork of this repository, you will
Expand Down
39 changes: 19 additions & 20 deletions doc/content/design/external-auth-ldaps.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,9 +91,11 @@ Given `ldaps` default to `false`, this feature is **NOT** enabled until explicit

#### 3.1.2 Error code
Following new error codes added to indicate ldaps enable related error
- POOL_AUTH_ENABLE_FAILED_NO_CERTS, no certs can be used for ldaps, refer to 4.1.2 for certs finding.
- POOL_AUTH_ENABLE_FAILED_INVALID_CERTS, found certs, but none of the certs can be used to connect to DC
**Note**: Current error code handing infrustrucure requires the error code prefix with POOL_AUTH_ENABLE_FAILED
- `POOL_AUTH_ENABLE_FAILED_NO_TRUSTED_CERTS`: no trusted certs can be used for ldaps, refer to 4.1.2 for trusted certs finding.
- `POOL_AUTH_ENABLE_FAILED_INVALID_TRUSTED_CERTS`: found trusted certs, but none of the trusted certs can be used to connect to DC.
- `POOL_AUTH_ENABLE_FAILED_SETUP_TLS_CONNECTION`: failed to set up TLS connection to DC (e.g. GnuTLS handshake failure such as `tstream_tls_sync_setup: GNUTLS ERROR`). The error message contains the underlying details reported by winbind.

**Note**: Current error code handling infrastructure requires the error code prefix with `POOL_AUTH_ENABLE_FAILED`.

### 3.2 Set/Get Pool LDAPS Status

Expand Down Expand Up @@ -135,10 +137,11 @@ xe pool-external-auth-set-ldaps uuid=<uuid> ldaps=<true|false>

#### 3.2.1.2 Error code
This API may raise following errors
- AUTH_NO_CERTS, no certs found to enable ldaps, refer to 4.1.2 for certs finding
- AUTH_INVALID_CERTS, found certs, but none of the certs can be used to connect to DC
- AUTH_IS_DISABLED, AD is not enabled
- AUTH_SET_LDAPS_FAILED, Failed to set ldaps, the error message contains the details like ldap query on domain failed
- `AUTH_NO_TRUSTED_CERTS`: no trusted certs found to enable ldaps, refer to 4.1.2 for trusted certs finding.
- `AUTH_INVALID_TRUSTED_CERTS`: found trusted certs, but none of the trusted certs can be used to connect to DC.
- `AUTH_SETUP_TLS_CONNECTION`: failed to set up TLS CONNECTION to DC (e.g. GnuTLS handshake failure such as `tstream_tls_sync_setup: GNUTLS ERROR`). The error message contains the underlying details reported by winbind.
- `AUTH_IS_DISABLED`: AD is not enabled.
- `AUTH_SET_LDAPS_FAILED`: Failed to set ldaps, the error message contains the details like ldap query on domain failed.

#### 3.2.2 Get Pool LDAPS Status

Expand Down Expand Up @@ -268,10 +271,10 @@ alt precheck failed
client-->>user: precheck failed
end

Note over client,coor: sync all ldaps certs
client->>coor: pool.download_trusted_certificate
coor-->>client:
client->>join: pool.install_trusted_certificate
Note over client,coor: sync trusted CA certs from coordinator to joining host
client->>join: pool.sync_trusted_certificates_from
join->>coor: pool.exchange_trusted_certificates_on_join
coor-->>join:
join-->>client:

user->>client: join domain username/password
Expand All @@ -289,15 +292,11 @@ client-->>user: pool.join succeed

**Detailed Steps:**

1. Client find proper `ldaps certs` from pool coordinator as `certs_pool`
- a. find all certs `ldaps in purpose`
- b. if no LDAPS certs, find all `general` certs
2. Client find all certs in joining host as `certs_joining_host`
3. Client identify the certs needs to be synced to joining host as `certs_to_sync = certs_pool - certs_joining_host` (certs in `certs_pool`, but not in `certs_joining_host`), the certs fingerprint should be used to identify the certs
4. Client download all `certs_to_sync`, `pool.download_trusted_certificate` from coordinator
5. Client upload all certs to joining pool, `pool.install_trusted_certificate` to joining pool, with the same purpose
6. Client trigger `pool.join` again with domain username and password
7. After pool.join:
1. Client calls `pool.sync_trusted_certificates_from` to joiner host. The call will
- a. download all trusted certificates from the pool, and
- b. install the trusted certificates into the joiner host.
2. Client trigger `pool.join` again with domain username and password
3. After pool.join:
- If pool.join failed, Client call `pool.uninstall_trusted_certificate` on joining host to revert the certs
- If pool.join succeed, do nothing as pool.join would sync the certs anyway

Expand Down
Loading
Loading