<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 02:23:38 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-9145] When Shared Key feature is active, Nodemap admin property allows more access</title>
                <link>https://jira.whamcloud.com/browse/LU-9145</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;When the Shared Key feature of Lustre is active, and the Nodemap &quot;admin&quot; property for a nodemap is set to 0, Lustre does not restrict access to that nodemap as it normally would without Shared Key. Examples of this issue occurring can be found in tests 17, 18, and 20-23 of sanity-sec in the testing framework of the following run:&lt;br/&gt;
&lt;a href=&quot;https://testing.hpdd.intel.com/test_sets/36d7440a-f84f-11e6-887f-5254006e85c2&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://testing.hpdd.intel.com/test_sets/36d7440a-f84f-11e6-887f-5254006e85c2&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This may be replicated on a system with Shared Key and Nodemap features enabled, by setting all nodemap admin and trusted properties to 0.  Under these conditions, the system does not fully limit root access.&lt;/p&gt;

&lt;p&gt;The error returned by the test framework is:&lt;br/&gt;
sanity-sec test_17: @@@@@@ FAIL: test trusted_noadmin:0:c0:0:000, wanted 0 0, got 1 1&lt;/p&gt;

&lt;p&gt;The &quot;0 0&quot; desired by this test is the output of do_create_delete() from the sanity-sec.sh suite in the testing framework. This function attempts to touch, and then remove, a file. Since it should not be able to do either, the test fails since both operations are permitted.  Other tests of the same nature fail for similar reasons.&lt;/p&gt;</description>
                <environment></environment>
        <key id="44037">LU-9145</key>
            <summary>When Shared Key feature is active, Nodemap admin property allows more access</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="kit.westneat">Kit Westneat</assignee>
                                    <reporter username="hannac">Chris Hanna</reporter>
                        <labels>
                            <label>patch</label>
                    </labels>
                <created>Wed, 22 Feb 2017 19:39:15 +0000</created>
                <updated>Wed, 15 Dec 2021 02:35:29 +0000</updated>
                            <resolved>Tue, 9 Jan 2018 15:50:45 +0000</resolved>
                                    <version>Lustre 2.9.0</version>
                                    <fixVersion>Lustre 2.11.0</fixVersion>
                    <fixVersion>Lustre 2.10.4</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>8</watches>
                                                                            <comments>
                            <comment id="186650" author="adilger" created="Wed, 1 Mar 2017 18:25:58 +0000"  >&lt;p&gt;Chris, are Kit or Jeremy still available to work on this?&lt;/p&gt;</comment>
                            <comment id="187788" author="hannac" created="Fri, 10 Mar 2017 13:43:48 +0000"  >&lt;p&gt;Hi Andreas,&lt;/p&gt;

&lt;p&gt;Kit mentioned he may take a look at this next week. Kerberos is affected in the same manner as SSK.&lt;/p&gt;</comment>
                            <comment id="192112" author="gerrit" created="Fri, 14 Apr 2017 16:12:25 +0000"  >&lt;p&gt;Kit Westneat (kit.westneat@gmail.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/26624&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/26624&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-9145&quot; title=&quot;When Shared Key feature is active, Nodemap admin property allows more access&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-9145&quot;&gt;&lt;del&gt;LU-9145&lt;/del&gt;&lt;/a&gt; nodemap: new_init_ucred doesn&apos;t do nodemapping&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: a17498dfd8a618964215974c028944d29c95f8be&lt;/p&gt;</comment>
                            <comment id="217765" author="gerrit" created="Tue, 9 Jan 2018 05:35:31 +0000"  >&lt;p&gt;Oleg Drokin (oleg.drokin@intel.com) merged in patch &lt;a href=&quot;https://review.whamcloud.com/26624/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/26624/&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-9145&quot; title=&quot;When Shared Key feature is active, Nodemap admin property allows more access&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-9145&quot;&gt;&lt;del&gt;LU-9145&lt;/del&gt;&lt;/a&gt; nodemap: new_init_ucred doesn&apos;t do nodemapping&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: &lt;br/&gt;
Commit: 37db778f48f952747575e323cb341ed663852fff&lt;/p&gt;</comment>
                            <comment id="217807" author="mdiep" created="Tue, 9 Jan 2018 15:50:45 +0000"  >&lt;p&gt;Landed for 2.11&lt;/p&gt;</comment>
                            <comment id="217847" author="gerrit" created="Tue, 9 Jan 2018 20:42:58 +0000"  >&lt;p&gt;Minh Diep (minh.diep@intel.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/30812&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/30812&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-9145&quot; title=&quot;When Shared Key feature is active, Nodemap admin property allows more access&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-9145&quot;&gt;&lt;del&gt;LU-9145&lt;/del&gt;&lt;/a&gt; nodemap: new_init_ucred doesn&apos;t do nodemapping&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: b2_10&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 5e5a69890e27963c2e2556e59b2984df254c3e2c&lt;/p&gt;</comment>
                            <comment id="221691" author="gerrit" created="Mon, 26 Feb 2018 18:43:43 +0000"  >&lt;p&gt;John L. Hammond (john.hammond@intel.com) merged in patch &lt;a href=&quot;https://review.whamcloud.com/30812/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/30812/&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-9145&quot; title=&quot;When Shared Key feature is active, Nodemap admin property allows more access&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-9145&quot;&gt;&lt;del&gt;LU-9145&lt;/del&gt;&lt;/a&gt; nodemap: new_init_ucred doesn&apos;t do nodemapping&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: b2_10&lt;br/&gt;
Current Patch Set: &lt;br/&gt;
Commit: 51eaf0d07e84cc86a1d4469f293060da53c351d5&lt;/p&gt;</comment>
                            <comment id="253635" author="adilger" created="Tue, 27 Aug 2019 00:00:52 +0000"  >&lt;p&gt;No tests are currently reported as skipped because of this ticket.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="47492">LU-9795</issuekey>
        </issuelink>
                            </outwardlinks>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="57891">LU-13172</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzz4nz:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10023"><![CDATA[4]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>