<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:41:24 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-4291] Lustre 1.8.9 client on RHEL 6.4 does not play nice with SELINUX while mounting 2.4.1 filesystems</title>
                <link>https://jira.whamcloud.com/browse/LU-4291</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;Lustre 1.8.9 client built locally from HPDD Git for kernel 2.6.32-358.23.2.el6.x86_64, using distribution OFED. Client successfully mounts all 1.8.9 filesystems, but when you ask it to mount a 2.4.1 filesystem it crashes with the following stack trace:&lt;/p&gt;

&lt;p&gt;-----------&lt;del&gt;[ cut here ]&lt;/del&gt;-----------&lt;br/&gt;
kernel BUG at security/selinux/ss/services.c:625!&lt;br/&gt;
invalid opcode: 0000 &lt;a href=&quot;#1&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;1&lt;/a&gt; SMP&lt;br/&gt;
last sysfs file: /sys/devices/pci0000:00/0000:00:0a.0/0000:02:00.4/usb7/7-1/speed&lt;br/&gt;
CPU 11&lt;br/&gt;
Modules linked in: mgc(U) lustre(U) lov(U) mdc(U) lquota(U) osc(U) ptlrpc(U) obdclass(U) lvfs(U) ko2iblnd(U) lnet(U) libcfs(U) nfs lockd fscache auth_rpcgss nfs_acl mptctl mptbase autofs4 sunrpc nf_conntrack_netbios_ns nf_conntrack_broadcast ipt_REJECT xt_comment nf_conntrack_ipv4 nf_defrag_ipv4 xt_state nf_conntrack iptable_filter ip_tables ib_ipoib rdma_ucm ib_ucm ib_uverbs ib_umad rdma_cm ib_cm iw_cm ib_addr ipv6 tcp_bic power_meter sg mlx4_ib ib_sa ib_mad ib_core mlx4_en mlx4_core hpilo hpwdt bnx2 myri10ge(U) dca microcode serio_raw k10temp amd64_edac_mod edac_core edac_mce_amd i2c_piix4 shpchp ext4 jbd2 mbcache sd_mod crc_t10dif hpsa pata_acpi ata_generic pata_atiixp ahci radeon ttm drm_kms_helper drm i2c_algo_bit i2c_core dm_mirror dm_region_hash dm_log dm_mod &lt;span class=&quot;error&quot;&gt;&amp;#91;last unloaded: scsi_wait_scan&amp;#93;&lt;/span&gt; &lt;/p&gt;

&lt;p&gt;Pid: 7454, comm: lsof Not tainted 2.6.32-358.23.2.el6.x86_64 #1 HP ProLiant DL385 G7&lt;br/&gt;
RIP: 0010:&lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff8123982b&amp;gt;&amp;#93;&lt;/span&gt;  &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff8123982b&amp;gt;&amp;#93;&lt;/span&gt; context_struct_compute_av+0x40b/0x420&lt;br/&gt;
RSP: 0018:ffff88083854db18  EFLAGS: 00010246&lt;br/&gt;
RAX: 0000000000000000 RBX: ffff88083854dca8 RCX: 0000000000000100&lt;br/&gt;
RDX: 0000000000000f3c RSI: 00000000ffffffff RDI: 0000000000000010&lt;br/&gt;
RBP: ffff88083854db98 R08: 00000000000135f0 R09: ffff88083854dca8&lt;br/&gt;
R10: 0000000000000010 R11: 0000000000000000 R12: 0000000000000007&lt;br/&gt;
R13: ffff880c3a556248 R14: 0000000000000796 R15: 000000000000079e&lt;br/&gt;
FS:  00007f9638d787a0(0000) GS:ffff88084e480000(0000) knlGS:0000000000000000&lt;br/&gt;
CS:  0010 DS: 0000 ES: 0000 CR0: 000000008005003b&lt;br/&gt;
CR2: 0000003a4dadaf50 CR3: 00000008391ac000 CR4: 00000000000007e0&lt;br/&gt;
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000&lt;br/&gt;
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400&lt;br/&gt;
Process lsof (pid: 7454, threadinfo ffff88083854c000, task ffff8808395e0040)&lt;br/&gt;
Stack:&lt;br/&gt;
 ffff880839c1bc80 0007880800000007 ffff88041cc613c8 ffff880c3a556248&lt;br/&gt;
&amp;lt;d&amp;gt; ffff88083a6825f0 00000000b4bb9d11 0000000000000007 0000000000000000&lt;br/&gt;
&amp;lt;d&amp;gt; 000700073854dbd8 ffffffff81223621 ffff88083854dbe8 ffff88083854dca8&lt;br/&gt;
Call Trace:&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff81223621&amp;gt;&amp;#93;&lt;/span&gt; ? avc_has_perm+0x71/0x90&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff81239d05&amp;gt;&amp;#93;&lt;/span&gt; security_compute_av+0xf5/0x2c0&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff8122328e&amp;gt;&amp;#93;&lt;/span&gt; avc_has_perm_noaudit+0x14e/0x470&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff812235fb&amp;gt;&amp;#93;&lt;/span&gt; avc_has_perm+0x4b/0x90&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff812253c4&amp;gt;&amp;#93;&lt;/span&gt; inode_has_perm+0x54/0xa0&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff811a2100&amp;gt;&amp;#93;&lt;/span&gt; ? mntput_no_expire+0x30/0x110&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff8122599b&amp;gt;&amp;#93;&lt;/span&gt; dentry_has_perm+0x5b/0x80&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff81225a4c&amp;gt;&amp;#93;&lt;/span&gt; selinux_inode_getattr+0x2c/0x30&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff8121d033&amp;gt;&amp;#93;&lt;/span&gt; security_inode_getattr+0x23/0x30&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff81186d2f&amp;gt;&amp;#93;&lt;/span&gt; vfs_getattr+0x2f/0x80&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff81186de0&amp;gt;&amp;#93;&lt;/span&gt; vfs_fstatat+0x60/0x80&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff81186f2b&amp;gt;&amp;#93;&lt;/span&gt; vfs_stat+0x1b/0x20&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff81186f54&amp;gt;&amp;#93;&lt;/span&gt; sys_newstat+0x24/0x50&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff810dc937&amp;gt;&amp;#93;&lt;/span&gt; ? audit_syscall_entry+0x1d7/0x200&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff810dc685&amp;gt;&amp;#93;&lt;/span&gt; ? __audit_syscall_exit+0x265/0x290&lt;br/&gt;
 &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff8100b072&amp;gt;&amp;#93;&lt;/span&gt; system_call_fastpath+0x16/0x1b&lt;br/&gt;
Code: ff ff ff e8 08 53 e3 ff 85 c0 0f 84 34 ff ff ff 0f b7 75 8e 48 c7 c7 28 22 7c 81 31 c0 e8 52 43 2d 00 e9 1d ff ff ff 0f 0b eb fe &amp;lt;0f&amp;gt; 0b 0f 1f 00 eb fb 66 66 66 66 66 2e 0f 1f 84 00 00 00 00 00&lt;br/&gt;
RIP  &lt;span class=&quot;error&quot;&gt;&amp;#91;&amp;lt;ffffffff8123982b&amp;gt;&amp;#93;&lt;/span&gt; context_struct_compute_av+0x40b/0x420&lt;br/&gt;
 RSP &amp;lt;ffff88083854db18&amp;gt;&lt;/p&gt;

&lt;p&gt;To get this trace, set SELINUX=permissive in /etc/selinux/config.&lt;/p&gt;

&lt;p&gt;We do have a kdump from this node in the permissive mode.&lt;/p&gt;

&lt;p&gt;Setting SELINUX=disabled and the behavior goes away. &lt;/p&gt;

&lt;p&gt;This is for an internet facing server (data transfer node), and our cyber policy strongly suggests running SELINUX on the web facing systems for the center. &lt;/p&gt;

&lt;p&gt;This isn&apos;t critical as there&apos;s a workaround, but it&apos;s serious and we do need to get the reason that Lustre is tickling SELINUX figured out and patched so we can move forward with putting the new Lustre filesystems on the data transfer nodes.&lt;/p&gt;</description>
                <environment></environment>
        <key id="22205">LU-4291</key>
            <summary>Lustre 1.8.9 client on RHEL 6.4 does not play nice with SELINUX while mounting 2.4.1 filesystems</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="3" iconUrl="https://jira.whamcloud.com/images/icons/priorities/major.svg">Major</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="green">Oleg Drokin</assignee>
                                    <reporter username="hilljjornl">Jason Hill</reporter>
                        <labels>
                    </labels>
                <created>Fri, 22 Nov 2013 05:05:42 +0000</created>
                <updated>Mon, 10 Feb 2014 17:19:05 +0000</updated>
                            <resolved>Mon, 10 Feb 2014 17:19:05 +0000</resolved>
                                    <version>Lustre 1.8.9</version>
                                                        <due></due>
                            <votes>0</votes>
                                    <watches>5</watches>
                                                                            <comments>
                            <comment id="72094" author="green" created="Fri, 22 Nov 2013 05:39:39 +0000"  >&lt;p&gt;Historically 1.8.9 with selinux in any state but off was not supported, so can you please turn it off completely?&lt;br/&gt;
Even if it worked before for you, the code path was not verified, so now at the slight change broken things revealed itself.&lt;/p&gt;</comment>
                            <comment id="72157" author="hilljjornl" created="Fri, 22 Nov 2013 18:23:26 +0000"  >&lt;p&gt;Oleg &amp;#8211; thanks for the update. What is the stance for 2.4.X for our reference?&lt;/p&gt;</comment>
                            <comment id="72312" author="green" created="Tue, 26 Nov 2013 15:26:28 +0000"  >&lt;p&gt;There were some patches from Xyratex to allow operating a client and a server with SELinux enabled (no enforcement available, just to make it not crash), but to my knowledge we do not actively test this configuration.&lt;/p&gt;</comment>
                            <comment id="72317" author="simmonsja" created="Tue, 26 Nov 2013 15:46:08 +0000"  >&lt;p&gt;Lustre 2.4 is missing the patch from &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-2655&quot; title=&quot;Make ability to mount lustre server target on selinux enabled servers.&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-2655&quot;&gt;&lt;del&gt;LU-2655&lt;/del&gt;&lt;/a&gt;. Lustre 1.8 would need to back port that and a bunch of patches from &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-589&quot; title=&quot;test-packages launched by auster.sh read the wrong configuration file when auster.sh is invoked with the &amp;#39;-c&amp;#39; option&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-589&quot;&gt;&lt;del&gt;LU-589&lt;/del&gt;&lt;/a&gt;. Is SELinux a hard requirement?&lt;/p&gt;</comment>
                            <comment id="74764" author="jamesanunez" created="Fri, 10 Jan 2014 23:51:34 +0000"  >&lt;p&gt;Jason, &lt;/p&gt;

&lt;p&gt;As Oleg pointed out, there are patches in b2_5 and beyond that allow clients and servers to operate with SELinux enabled. &lt;/p&gt;

&lt;p&gt;Is there something else we need to do for this ticket or should we close it?&lt;/p&gt;

&lt;p&gt;Thanks, &lt;br/&gt;
James&lt;/p&gt;</comment>
                            <comment id="76608" author="hilljjornl" created="Mon, 10 Feb 2014 16:42:32 +0000"  >&lt;p&gt;James,&lt;/p&gt;

&lt;p&gt;Go ahead and close this. My apologies for not responding sooner. 1 Month latencies are unacceptable.&lt;/p&gt;

&lt;p&gt;Thanks!&lt;/p&gt;

&lt;p&gt;&amp;#8211;&lt;br/&gt;
-Jason&lt;/p&gt;</comment>
                            <comment id="76614" author="jamesanunez" created="Mon, 10 Feb 2014 17:19:05 +0000"  >&lt;p&gt;Thank you for the update, Jason.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzw9wf:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>11774</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>