[LU-4291] Lustre 1.8.9 client on RHEL 6.4 does not play nice with SELINUX while mounting 2.4.1 filesystems Created: 22/Nov/13 Updated: 10/Feb/14 Resolved: 10/Feb/14 |
|
| Status: | Resolved |
| Project: | Lustre |
| Component/s: | None |
| Affects Version/s: | Lustre 1.8.9 |
| Fix Version/s: | None |
| Type: | Bug | Priority: | Major |
| Reporter: | Jason Hill (Inactive) | Assignee: | Oleg Drokin |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | None | ||
| Severity: | 3 |
| Rank (Obsolete): | 11774 |
| Description |
|
Lustre 1.8.9 client built locally from HPDD Git for kernel 2.6.32-358.23.2.el6.x86_64, using distribution OFED. Client successfully mounts all 1.8.9 filesystems, but when you ask it to mount a 2.4.1 filesystem it crashes with the following stack trace: ----------- Pid: 7454, comm: lsof Not tainted 2.6.32-358.23.2.el6.x86_64 #1 HP ProLiant DL385 G7 To get this trace, set SELINUX=permissive in /etc/selinux/config. We do have a kdump from this node in the permissive mode. Setting SELINUX=disabled and the behavior goes away. This is for an internet facing server (data transfer node), and our cyber policy strongly suggests running SELINUX on the web facing systems for the center. This isn't critical as there's a workaround, but it's serious and we do need to get the reason that Lustre is tickling SELINUX figured out and patched so we can move forward with putting the new Lustre filesystems on the data transfer nodes. |
| Comments |
| Comment by Oleg Drokin [ 22/Nov/13 ] |
|
Historically 1.8.9 with selinux in any state but off was not supported, so can you please turn it off completely? |
| Comment by Jason Hill (Inactive) [ 22/Nov/13 ] |
|
Oleg – thanks for the update. What is the stance for 2.4.X for our reference? |
| Comment by Oleg Drokin [ 26/Nov/13 ] |
|
There were some patches from Xyratex to allow operating a client and a server with SELinux enabled (no enforcement available, just to make it not crash), but to my knowledge we do not actively test this configuration. |
| Comment by James A Simmons [ 26/Nov/13 ] |
|
Lustre 2.4 is missing the patch from |
| Comment by James Nunez (Inactive) [ 10/Jan/14 ] |
|
Jason, As Oleg pointed out, there are patches in b2_5 and beyond that allow clients and servers to operate with SELinux enabled. Is there something else we need to do for this ticket or should we close it? Thanks, |
| Comment by Jason Hill (Inactive) [ 10/Feb/14 ] |
|
James, Go ahead and close this. My apologies for not responding sooner. 1 Month latencies are unacceptable. Thanks! – |
| Comment by James Nunez (Inactive) [ 10/Feb/14 ] |
|
Thank you for the update, Jason. |