<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:07:42 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-14199] sanity-selinux test 21a  fails with &apos;client mount without sending sepol should be refused&apos;</title>
                <link>https://jira.whamcloud.com/browse/LU-14199</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;sanity-selinux test_21a  fails for RHEL 8.3 client/server testing in review-dne-selinux. &lt;/p&gt;

&lt;p&gt;Looking at the logs for the failure at &lt;a href=&quot;https://testing.whamcloud.com/test_sets/75526e78-6eda-4900-995c-b361935c3e9f&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://testing.whamcloud.com/test_sets/75526e78-6eda-4900-995c-b361935c3e9f&lt;/a&gt; , the suite_log shows the test output&lt;/p&gt;
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;CMD: trevis-200vm4 /usr/sbin/lctl set_param -P nodemap.c0.sepol=
On mds4, c0.sepol = 
On mds3, c0.sepol = 
On mds2, c0.sepol = 
On mds1, c0.sepol = 
Starting client: trevis-200vm1.trevis.whamcloud.com:  -o user_xattr,flock trevis-200vm4@tcp:/lustre /mnt/lustre
CMD: trevis-200vm1.trevis.whamcloud.com mkdir -p /mnt/lustre
CMD: trevis-200vm1.trevis.whamcloud.com mount -t lustre -o user_xattr,flock trevis-200vm4@tcp:/lustre /mnt/lustre
 sanity-selinux test_21a: @@@@@@ FAIL: client mount without sending sepol should be refused 
  Trace dump:
  = /usr/lib64/lustre/tests/test-framework.sh:6257:error()
  = /usr/lib64/lustre/tests/sanity-selinux.sh:604:test_21a()
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Sebastien took a look at this and had the following comments:&lt;br/&gt;
It comes from the following command in the test script:&lt;/p&gt;
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;do_facet mgs $LCTL set_param -P nodemap.$nm.sepol=&quot;$sepol&quot;
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;and the sepol variable is obtained from:&lt;/p&gt;
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;sepol=$(l_getsepol | cut -d&apos;:&apos; -f2- | xargs)
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;On my RHEL 8.2 test system it goes like this:&lt;/p&gt;
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;# l_getsepol | cut -d&apos;:&apos; -f2- | xargs
1:targeted:31:309ea33f4ea67b3baf7354d797d41a5330eb7c7653e66bcc928ea62268b7aa08
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;so the test is expected to set a non empty value for the sepol parameter on the nodemap, and the fact that it fails breaks the rest of the test. So it seems there is a problem with this command in RHEL 8.3 &lt;/p&gt;

&lt;p&gt;In addition, we see sanity-selinux test 21b fail in the same way with&lt;/p&gt;
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;CMD: trevis-200vm4 /usr/sbin/lctl set_param -P nodemap.c0.sepol=
On mds4, c0.sepol = 
On mds3, c0.sepol = 
On mds2, c0.sepol = 
On mds1, c0.sepol = 
 sanity-selinux test_21b: @@@@@@ FAIL: touch (1) 
  Trace dump:
  = /usr/lib64/lustre/tests/test-framework.sh:6257:error()
  = /usr/lib64/lustre/tests/sanity-selinux.sh:688:test_21b()
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;</description>
                <environment>RHEL8.3 client/server</environment>
        <key id="61909">LU-14199</key>
            <summary>sanity-selinux test 21a  fails with &apos;client mount without sending sepol should be refused&apos;</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="sebastien">Sebastien Buisson</assignee>
                                    <reporter username="jamesanunez">James Nunez</reporter>
                        <labels>
                            <label>rhel8.3</label>
                            <label>security</label>
                    </labels>
                <created>Tue, 8 Dec 2020 16:56:49 +0000</created>
                <updated>Fri, 24 Mar 2023 08:29:06 +0000</updated>
                            <resolved>Mon, 14 Dec 2020 04:52:34 +0000</resolved>
                                    <version>Lustre 2.14.0</version>
                                    <fixVersion>Lustre 2.14.0</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>3</watches>
                                                                            <comments>
                            <comment id="286998" author="sebastien" created="Tue, 8 Dec 2020 17:07:59 +0000"  >&lt;p&gt;I will look into this, thanks for documenting this issue James.&lt;/p&gt;</comment>
                            <comment id="287075" author="gerrit" created="Wed, 9 Dec 2020 12:42:10 +0000"  >&lt;p&gt;Sebastien Buisson (sbuisson@ddn.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/40918&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/40918&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-14199&quot; title=&quot;sanity-selinux test 21a  fails with &amp;#39;client mount without sending sepol should be refused&amp;#39;&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-14199&quot;&gt;&lt;del&gt;LU-14199&lt;/del&gt;&lt;/a&gt; sec: find policy version in use for sepol&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: e6e8034c05503773274ababc0b2399b9dd80f5f5&lt;/p&gt;</comment>
                            <comment id="287181" author="sebastien" created="Thu, 10 Dec 2020 08:11:47 +0000"  >&lt;p&gt;James,&lt;/p&gt;

&lt;p&gt;I managed to have review-dne-selinux passing on RHEL 8.3 clients with patch #40918:&lt;br/&gt;
&lt;a href=&quot;https://testing.whamcloud.com/test_sessions/31d8395b-3a26-49b2-92c9-52efdded3733&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://testing.whamcloud.com/test_sessions/31d8395b-3a26-49b2-92c9-52efdded3733&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So it should be fixed now.&lt;/p&gt;</comment>
                            <comment id="287451" author="gerrit" created="Mon, 14 Dec 2020 02:40:44 +0000"  >&lt;p&gt;Oleg Drokin (green@whamcloud.com) merged in patch &lt;a href=&quot;https://review.whamcloud.com/40918/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/40918/&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-14199&quot; title=&quot;sanity-selinux test 21a  fails with &amp;#39;client mount without sending sepol should be refused&amp;#39;&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-14199&quot;&gt;&lt;del&gt;LU-14199&lt;/del&gt;&lt;/a&gt; sec: find policy version in use for sepol&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: &lt;br/&gt;
Commit: e39d6451efb1d05ce7bb62eb0a91aebe7af302d9&lt;/p&gt;</comment>
                            <comment id="287454" author="pjones" created="Mon, 14 Dec 2020 04:52:34 +0000"  >&lt;p&gt;Landed for 2.14&lt;/p&gt;</comment>
                            <comment id="367172" author="gerrit" created="Fri, 24 Mar 2023 08:29:06 +0000"  >&lt;p&gt;&quot;Etienne AUJAMES &amp;lt;eaujames@ddn.com&amp;gt;&quot; uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/c/fs/lustre-release/+/50402&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/c/fs/lustre-release/+/50402&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-14199&quot; title=&quot;sanity-selinux test 21a  fails with &amp;#39;client mount without sending sepol should be refused&amp;#39;&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-14199&quot;&gt;&lt;del&gt;LU-14199&lt;/del&gt;&lt;/a&gt; sec: find policy version in use for sepol&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: b2_12&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 543051b621826ee118fb678a33bfe9b14c59a002&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i01gnj:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>