It seems like setting the ganeti backend parameter "cpu_type" is beneficial for a number reasons:
1. Performance -- Certain flags enable processor-specific performance features.
2. Security -- Certain flags enable fixes to hardware vulnerabilities, like Spectre and Meltdown.
3. Compatibility -- Rocky Linux 9.0, running kernel v5.14, panics at boot time unless a specific processor model is set. The default "QEMU Virtual CPU" is no longer sufficient.
QUESTION: How do I select the optimal processor model and flags from the dozens that are available with KVM?
EXAMPLE:
Here's the /proc/cpuinfo from my test cluster, where all nodes are Dell PowerEdge R610:
processor : 0
vendor_id : GenuineIntel
cpu family : 6
model : 44
model name : Intel(R) Xeon(R) CPU E5620 @ 2.40GHz
stepping : 2
microcode : 0x1f
cpu MHz : 2393.795
cache size : 12288 KB
physical id : 1
siblings : 8
core id : 0
cpu cores : 4
apicid : 32
initial apicid : 32
fpu : yes
fpu_exception : yes
cpuid level : 11
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ht tm pbe syscall nx pdpe1gb rdtscp lm constant_tsc arch_perfmon pebs bts rep_good nopl xtopology nonstop_tsc cpuid aperfmperf pni pclmulqdq dtes64 monitor ds_cpl vmx smx est tm2 ssse3 cx16 xtpr pdcm pcid dca sse4_1 sse4_2 popcnt aes lahf_lm pti ssbd ibrs ibpb stibp tpr_shadow vnmi flexpriority ept vpid dtherm ida arat flush_l1d
bugs : cpu_meltdown spectre_v1 spectre_v2 spec_store_bypass l1tf mds swapgs itlb_multihit
bogomips : 4787.59
clflush size : 64
cache_alignment : 64
address sizes : 40 bits physical, 48 bits virtual
power management:
Ganeti accepts this command...
# gnt-cluster modify -H kvm:cpu_type=Westmere\\,+pcid\\,+invpcid\\,+spec-ctrl\\,+ssbd\\,+md-clear
.. and the processor model and flags show up accordingly in the hypervisor command line...
# ps aux | grep qemu-kvm
root 526448 88.6 1.1 9912048 975664 ? Sl 14:10 0:37 /usr/libexec/qemu-kvm -name foremantest3a.dmz.psfc.coop -m 8192 -smp 4 -pidfile /var/run/ganeti/kvm-hypervisor/pid/foremantest3a.dmz.psfc.coop -device virtio-balloon -daemonize -D /var/log/ganeti/kvm/foremantest3a.dmz.psfc.coop.log -machine pc-i440fx-rhel7.6.0 -monitor unix:/var/run/ganeti/kvm-hypervisor/ctrl/foremantest3a.dmz.psfc.coop.monitor,server,nowait -serial unix:/var/run/ganeti/kvm-hypervisor/ctrl/foremantest3a.dmz.psfc.coop.serial,server,nowait -usb -usbdevice tablet -vnc 127.0.0.1:5100 -cpu Westmere,+pcid,+invpcid,+spec-ctrl,+ssbd,+md-clear -uuid 050e7e64-9901-492a-8342-b2a226c636d1 -netdev type=tap,id=nic-cf467569-0418-4eca,fd=12 -device virtio-net-pci,id=nic-cf467569-0418-4eca,bus=pci.0,addr=0xd,netdev=nic-cf467569-0418-4eca,mac=aa:00:00:ff:cc:37 -qmp unix:/var/run/ganeti/kvm-hypervisor/ctrl/foremantest3a.dmz.psfc.coop.qmp,server,nowait -qmp unix:/var/run/ganeti/kvm-hypervisor/ctrl/foremantest3a.dmz.psfc.coop.kvmd,server,nowait -boot c -device virtio-blk-pci,id=disk-e3949a28-9948-41af,bus=pci.0,addr=0xc,drive=disk-e3949a28-9948-41af -drive file=/var/run/ganeti/instance-disks/foremantest3a.dmz.psfc.coop:0,format=raw,if=none,aio=threads,id=disk-e3949a28-9948-41af,auto-read-only=off -S
...but, is this complete, or even sufficient?
Any advice would be greatly appreciated.
-jm