Repository navigation
Conversation
Some networks may not provide IPv4 or IPv6 access based on hardware configuration. A user may want to restrict IPv4 network booting to verify an environment has moved to IPv6 only. While this restriction exists at a network layer; it creates complexities around determining which boot device (vif) should or shouldn't restrict a protocol. Instead we add the restriction to the VM (or template) itself in order to let users identify which VMs should be restricted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: Gerald Elder-Vass <gerald.elder-vass@citrix.com>
Some networks may not provide IPv4 or IPv6 access based on hardware configuration. If a user attempts to network boot it will prioritise IPv6 before falling back to IPv4 if the IPv6 DHCP request times out. This can create a long delay before booting successfully. While this restriction exists at a network layer; it creates complexities around determining which boot device (vif) should or shouldn't restrict a protocol. Instead we add the restriction to the VM (or template) itself in order to let users identify which VMs should be restricted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: Gerald Elder-Vass <gerald.elder-vass@citrix.com>
GeraldEV
marked this pull request as ready for review
October 6, 2026 15:56
Contributor
|
Everything looks good with the code, but I haven't been able to verify that writing those keys to xenstore will indeed disallow ipv4/ipv6 boot. Could you point me to where that is documented? |
Contributor
Author
The behaviour is enforced by the firmware of the VM, for XenServer that's edk2 (OVMF) |
cplaursen
approved these changes
Oct 8, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is an updated version of #7312 where the restriction was applied at the network level, it has been changed to apply at the VM/template level.
This improvement is from a customer request to avoid network boot using disabled internet protocols specifically on UEFI VMs.
It is expected the VM sits on a single network which holds the protocol limitation but this cannot be guaranteed, so we restrict the VM which can be easily templated to apply across many VMs with finer control.
The Toolstack will populate a XenStore entry before the VM boots which the virtual firmware will read to determine if a boot device/protocol is valid.
In XenServer, the firmware will assume the protocol is enabled unless it can; access XenStore, determine the XenStore entry for the protocol exists, read the entry, confirm the entry is exactly "false".
Along with populating the default value on create/upgrade; this will ensure there is no change in behaviour until a user opts into the feature.
The code in this PR was Co-authored by claude using the Sonnet 5 model
Fresh install/upgraded:
Changing the value:
XenStore is correctly populated: