[LU-381] CONFIG_SECURITY_DMESG_RESTRICT missing from config for RHEL6 Created: 31/May/11 Updated: 27/Jun/11 Resolved: 27/Jun/11 |
|
| Status: | Resolved |
| Project: | Lustre |
| Component/s: | None |
| Affects Version/s: | Lustre 2.1.0 |
| Fix Version/s: | Lustre 2.0.0 |
| Type: | Improvement | Priority: | Minor |
| Reporter: | Richard Henwood (Inactive) | Assignee: | Richard Henwood (Inactive) |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | None | ||
| Environment: |
RHEL6, git lustre-release, compiling from source |
||
| Epic: | papercut |
| Rank (Obsolete): | 4984 |
| Description |
|
Building Lustre from git/lustre-release on RHEL6, the .config file provided (lustre/kernel_patches/kernel_configs/kernel-2.6.32-2.6-rhel6-x86_64.config) does not contain a CONFIG_SECURITY_DMESG_RESTRICT directive. During make config a interactive prompt is provided: $ make oldconfig || make menuconfig scripts/kconfig/conf -o arch/x86/Kconfig * * Restart config... * * * Security options * Enable access key retention support (KEYS) [Y/n/?] y Enable the /proc/keys file by which keys may be viewed (KEYS_DEBUG_PROC_KEYS) [Y/n/?] y Restrict unprivileged access to the kernel syslog (SECURITY_DMESG_RESTRICT) [N/y/?] (NEW) This may be confusing to a user unfamiliar with SECURITY_DMESG_RESTRICT I suggest that this value be asserted as the default |
| Comments |
| Comment by Brian Murrell (Inactive) [ 31/May/11 ] |
|
In fact our policy with regard to kernel configuration options is to do what upstream does. We want to change the config (when compared to upstream) as little as we need to to make Lustre work. So the right thing to do here is investigate what RH set this value to for RHEL6 and do the same thing. |
| Comment by Richard Henwood (Inactive) [ 31/May/11 ] |
|
Thanks for the advice. RHEL6 set: CONFIG_SECURITY_DMESG_RESTRICT=n I'm preparing a patch to copy this assertion for Lustre .config. |
| Comment by Richard Henwood (Inactive) [ 02/Jun/11 ] |
|
The patch failed in Maloo. I've rebased and resubmitted. |
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Build Master (Inactive) [ 14/Jun/11 ] |
|
Integrated in Oleg Drokin : 60e6514a8280f90a97c00e18a3774b5e0212f7ff
|
| Comment by Richard Henwood (Inactive) [ 27/Jun/11 ] |
|
This fix has been merged. |