Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2022-01-12 Thread Rich Sudlow
Thank you Jeffrey!

Rich

On Tue, Jan 11, 2022 at 12:52 PM Jeffrey E Altman  wrote:
>
> On 11/24/2021 10:41 PM, Jeffrey E Altman (jalt...@auristor.com) wrote:
> > On 11/11/2021 9:01 AM, Jeffrey E Altman (jalt...@auristor.com) wrote:
> >> Any version of OpenAFS cache manager configured with a disk cache
> >> running on an impacted el7 kernel is affected.   All kernels from
> >> 3.10.0_861.el7 through 3.10.0_1160.42.2.el7 are impacted.   When a new
> >> el7 kernel containing the AuriStor provided fix is available and
> >> deployed, then OpenAFS will no longer be vulnerable.
> > AuriStor expects the bug fix to be included in
> > kernel-3.10.0-1160.51.1.el7 which we hope will ship by the middle of
> > December.  The kernel released yesterday kernel-3.10.0-1160.49.2.el7
> > does not include the fix.
>
> The kernel containing the fix is kernel-3.10.0-1160.53.1.el7
>
> Red Hat customers can read the announcement at
> https://access.redhat.com/errata/RHSA-2022:0063
>
> Jeffrey Altman
>
>


-- 
Rich Sudlow
University of Notre Dame
Center for Research Computing - Union Station
506 W. South St
South Bend, In 46601

(574) 631-7258 (office)
(574) 807-1046 (cell)
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info


Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2022-01-11 Thread Jeffrey E Altman
On 11/24/2021 10:41 PM, Jeffrey E Altman (jalt...@auristor.com) wrote:
> On 11/11/2021 9:01 AM, Jeffrey E Altman (jalt...@auristor.com) wrote:
>> Any version of OpenAFS cache manager configured with a disk cache
>> running on an impacted el7 kernel is affected.   All kernels from
>> 3.10.0_861.el7 through 3.10.0_1160.42.2.el7 are impacted.   When a new
>> el7 kernel containing the AuriStor provided fix is available and
>> deployed, then OpenAFS will no longer be vulnerable.
> AuriStor expects the bug fix to be included in
> kernel-3.10.0-1160.51.1.el7 which we hope will ship by the middle of
> December.  The kernel released yesterday kernel-3.10.0-1160.49.2.el7
> does not include the fix.

The kernel containing the fix is kernel-3.10.0-1160.53.1.el7

Red Hat customers can read the announcement at
https://access.redhat.com/errata/RHSA-2022:0063

Jeffrey Altman




smime.p7s
Description: S/MIME Cryptographic Signature


Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2021-11-25 Thread Gerry Seidman

Hi Rich,

Thanks so much for the holiday wishes.

Hopefully this finds you and everyone in your circle healthy and thriving.

Happy Thanksgiving,
Gerry

On 11/25/2021 9:55 AM, Rich Sudlow (r...@nd.edu) wrote:
Thanks Jeffrey-wishing you and the Auristor folks and all on this list 
a Happy Thanksgiving!!


Rich

On Wed, Nov 24, 2021 at 10:41 PM Jeffrey E Altman 
 wrote:


On 11/11/2021 9:01 AM, Jeffrey E Altman (jalt...@auristor.com) wrote:
> Any version of OpenAFS cache manager configured with a disk cache
> running on an impacted el7 kernel is affected.   All kernels from
> 3.10.0_861.el7 through 3.10.0_1160.42.2.el7 are impacted.   When
a new
> el7 kernel containing the AuriStor provided fix is available and
> deployed, then OpenAFS will no longer be vulnerable.

AuriStor expects the bug fix to be included in
kernel-3.10.0-1160.51.1.el7 which we hope will ship by the middle of
December.  The kernel released yesterday kernel-3.10.0-1160.49.2.el7
does not include the fix.

Jeffrey Altman

--
Rich Sudlow
University of Notre Dame
Center for Research Computing - Union Station
506 W. South St
South Bend, In 46601

(574) 631-7258 (office)
(574) 807-1046 (cell)


Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2021-11-25 Thread Rich Sudlow
Thanks Jeffrey-wishing you and the Auristor folks and all on this list a
Happy Thanksgiving!!

Rich

On Wed, Nov 24, 2021 at 10:41 PM Jeffrey E Altman 
wrote:

> On 11/11/2021 9:01 AM, Jeffrey E Altman (jalt...@auristor.com) wrote:
> > Any version of OpenAFS cache manager configured with a disk cache
> > running on an impacted el7 kernel is affected.   All kernels from
> > 3.10.0_861.el7 through 3.10.0_1160.42.2.el7 are impacted.   When a new
> > el7 kernel containing the AuriStor provided fix is available and
> > deployed, then OpenAFS will no longer be vulnerable.
>
> AuriStor expects the bug fix to be included in
> kernel-3.10.0-1160.51.1.el7 which we hope will ship by the middle of
> December.  The kernel released yesterday kernel-3.10.0-1160.49.2.el7
> does not include the fix.
>
> Jeffrey Altman
>
> --
Rich Sudlow
University of Notre Dame
Center for Research Computing - Union Station
506 W. South St
South Bend, In 46601

(574) 631-7258 (office)
(574) 807-1046 (cell)


Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2021-11-24 Thread Jeffrey E Altman
On 11/11/2021 9:01 AM, Jeffrey E Altman (jalt...@auristor.com) wrote:
> Any version of OpenAFS cache manager configured with a disk cache
> running on an impacted el7 kernel is affected.   All kernels from
> 3.10.0_861.el7 through 3.10.0_1160.42.2.el7 are impacted.   When a new
> el7 kernel containing the AuriStor provided fix is available and
> deployed, then OpenAFS will no longer be vulnerable.

AuriStor expects the bug fix to be included in
kernel-3.10.0-1160.51.1.el7 which we hope will ship by the middle of
December.  The kernel released yesterday kernel-3.10.0-1160.49.2.el7
does not include the fix.

Jeffrey Altman



smime.p7s
Description: S/MIME Cryptographic Signature


Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2021-11-12 Thread Harald Barth


> Any version of OpenAFS cache manager configured with a disk cache ...

But mem cache OK?

Regards,
Harald.
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info


Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2021-11-11 Thread Giovanni Bracco
You say "disk cache":   is that true also in the case when the cache is 
a directory in /dev/shm ?


Giovanni

On 11/11/21 15:01, Jeffrey E Altman wrote:

On 11/11/2021 7:12 AM, Giovanni Bracco (giovanni.bra...@enea.it) wrote:

Are all OpenAFS versions 1.6.x and 1.8.x affected by the bug described
in the enclosed mail?


Any version of OpenAFS cache manager configured with a disk cache
running on an impacted el7 kernel is affected.   All kernels from
3.10.0_861.el7 through 3.10.0_1160.42.2.el7 are impacted.   When a new
el7 kernel containing the AuriStor provided fix is available and
deployed, then OpenAFS will no longer be vulnerable.

Jeffrey Altman




--
Giovanni Bracco
phone  +39 351 8804788
E-mail  giovanni.bra...@enea.it
WWW http://www.afs.enea.it/bracco
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info


Re: [OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2021-11-11 Thread Jeffrey E Altman
On 11/11/2021 7:12 AM, Giovanni Bracco (giovanni.bra...@enea.it) wrote:
> Are all OpenAFS versions 1.6.x and 1.8.x affected by the bug described
> in the enclosed mail?
>
Any version of OpenAFS cache manager configured with a disk cache
running on an impacted el7 kernel is affected.   All kernels from
3.10.0_861.el7 through 3.10.0_1160.42.2.el7 are impacted.   When a new
el7 kernel containing the AuriStor provided fix is available and
deployed, then OpenAFS will no longer be vulnerable.

Jeffrey Altman




smime.p7s
Description: S/MIME Cryptographic Signature


[OpenAFS] Fwd: CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS v2021.05-10 released > OpenAFS versions?

2021-11-11 Thread Giovanni Bracco
Are all OpenAFS versions 1.6.x and 1.8.x affected by the bug described 
in the enclosed mail?


Giovanni

 Forwarded Message 
Subject: 	CRITICAL: RHEL7/CentOS7/SL7 client systems - AuriStorFS 
v2021.05-10 released

Date:   Wed, 10 Nov 2021 12:14:22 -0500
From:   Jeffrey E Altman 
Reply-To:   i...@auristor.com
Organization:   AuriStor, Inc.
To: Giovanni Bracco 



Dear community,

This morning AuriStorFS v2010.05-10 was published to workaround a 
CRITICAL kernel bug present in all RHEL7/CentOS7/SL7 releases beginning 
with RHEL 7.5.   All kernels from 3.10.0_861.el7 through 
3.10.0_1160.42.2.el7 are impacted.


The bug was introduced into upstream Linux kernels from 3.2 through 3.15 
by automated patch back-porting tools.  The broken back-port was then 
cherry-picked from the torvalds/linux repository into the rhel7 repository.


RHEL7 is the only Linux distribution for which AuriStor builds kernel 
modules that is impacted by the bug.   AuriStor has submitted to Red Hat 
and Red Hat has accepted a patch which is expected to be included in a 
soon to be released RHEL 7.9 kernel update.


The bug is triggered when the afs disk cache is being read and the 
process that issued the syscall has a pending fatal signal. In this 
case, an EINTR error state results in a file system read failure but the 
file system read returns success.   This bug has minimal impact on a 
userspace process directly issuing a file read because the process will 
be terminated as soon as the syscall completes.  However, the bug can 
corrupt the state of the AuriStorFS cache or the Linux page cache which 
might negatively impact subsequent attempts to perform directory lookups 
or file access.


When this bug is triggered messages similar to those that follow might 
be written to the system message log:


  * yfs: Disk cache read error in CacheItems slot 59151 off
5205308/19148204 code 0/88
  * yfs: Unexpected directory iteration error (2.822.23.8382
[your-cell-name.com] @ad57888e2424, pos 0, error 22)

Not all code paths impacted by the bug will generate an error. In 
particular, corrupted page cache contents will not log an error.


AuriStor recommends that end users update any RHEL7/CentOS7/SL7 systems 
running AuriStorFS or OpenAFS clients to AuriStorFS v2021.05-10 as soon 
as possible.  AuriStorFS v2021.05-10 contains a workaround for the 
kernel bug.


Please submit any support questions to 
auristorfs-enterprise-supp...@auristor.com


Sincerely,

Jeffrey Altman
on behalf of the AuriStor team


--
Giovanni Bracco
phone  +39 351 8804788
E-mail  giovanni.bra...@enea.it
WWW http://www.afs.enea.it/bracco
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info