Unable to use vTPM on Ceph when min-compat-client too new for krbd even when krbd disabled

davidsg

New Member
Dec 21, 2025
11
4
3
With a Ceph cluster that has minimum client compatibility too new for krbd:
Code:
root@pve01:~# ceph osd get-require-min-compat-client
squid

Booting a VM with a vTPM whose state is stored on rbd fails, even though PVE is configured to use librbd:
Code:
Oct 06 17:23:47 pve03 kernel: libceph: mon2 (2)10.188.0.3:3300 session established
Oct 06 17:23:47 pve03 kernel: libceph: RADOS feature set mismatch: server's required > my supported 0x2f018fb87aa4aafe, missing 0x4000000000
Oct 06 17:23:47 pve03 kernel: libceph: mon2 (2)10.188.0.3:3300 missing required protocol features
Oct 06 17:23:47 pve03 kernel: libceph: mon2 (2)10.188.0.3:3300 session lost, hunting for new mon

Shouldn't the TPM state be accessed through a userspace ceph client if krbd is disabled? swtpm doesn't have native librbd support but I'd think rbd-fuse would be the right way to go?
 
Fixed with the patch below. I'll try to submit this officially once I figure out how to sign the CLA, it looks like I'm meant to print it, sign and scan back in? I have neither a printer nor a scanner, so that's difficult. I sent an email to ask about it. I thought eIDAS was supposed to enable electronic contract signatures between parties in EEA countries, so hopefully that's a possibility.

Code:
From 0087b58f9de2a800a99b24dd750cdd8717fddb73 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Dav=C3=AD=C3=B0=20Steinn=20Geirsson?= <david@dsg.is>
Date: Tue, 6 Oct 2026 18:11:00 +0000
Subject: [PATCH] drive: use the storage daemon for a tpmstate on rbd with krbd
 disabled
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

With a Ceph cluster where min-compat-client is too new for krbd, vTPM
fails if its image is stored on rbd with:

  rbd: sysfs write failed
  libceph: RADOS feature set mismatch: server's required > my supported

Fix by using the FUSE path when krbd is disabled for the storage.

Signed-off-by: Davíð Steinn Geirsson <david@dsg.is>
---
 src/PVE/QemuServer/Drive.pm | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/src/PVE/QemuServer/Drive.pm b/src/PVE/QemuServer/Drive.pm
index 0b57371..d6e4b3e 100644
--- a/src/PVE/QemuServer/Drive.pm
+++ b/src/PVE/QemuServer/Drive.pm
@@ -1227,6 +1227,12 @@ sub drive_uses_qsd_fuse {
         my $path = PVE::Storage::path($storecfg, $drive->{file});
         return 1 if $path =~ m!^iscsi://!;
 
+        # The RBD plugin maps a volume with the kernel client, which may not
+        # speak the cluster's feature set; with krbd disabled, reach the
+        # volume through librbd like every other drive.
+        my $scfg = PVE::Storage::storage_config($storecfg, $storeid);
+        return 1 if $scfg->{type} eq 'rbd' && !$scfg->{krbd};
+
         my $format = checked_volume_format($storecfg, $drive->{file});
         return $format ne 'raw';
     }
--
2.55.0