-----============= acceptance-small: sanity-sec ============----- Sun Sep 6 20:41:55 EDT 2026 MGS_OS_ID_LIKE=rhel centos fedora rocky MGS_OS_VERSION_ID=8.10 MGS_OS_ID=rocky MGS_OS_VERSION_CODE=134873088 MDS1_OS_VERSION_ID=8.10 MDS1_OS_VERSION_CODE=134873088 MDS1_OS_ID_LIKE=rhel centos fedora rocky MDS1_OS_ID=rocky OST1_OS_VERSION_CODE=134873088 OST1_OS_ID_LIKE=rhel centos fedora rocky OST1_OS_VERSION_ID=8.10 OST1_OS_ID=rocky CLIENT_OS_ID=rocky CLIENT_OS_VERSION_CODE=134873088 CLIENT_OS_VERSION_ID=8.10 CLIENT_OS_ID_LIKE=rhel centos fedora rocky client=34683435 MDS=34683435 OSS=34683435 oleg113-server: /home/green/git/lustre-release/lustre/tests/except/sanity-sec.ex - see CLIENT_VERSION >= v2_16_57-13-g40cd140b85 (34683435 >= 34617613) for LU-18357, go 27a 27b excepting tests: skipping tests SLOW=no: 26 was USER0=sanityusr:x:500:500::/home/lustreuser:/bin/bash was USER1=sanityusr1:x:501:501::/home/sanityusr1:/bin/bash now USER0=sanityusr=500:500, USER1=sanityusr1=501:501 === sanity-sec: start setup 20:42:17 (1788741737) === oleg113-client.virtnet: executing check_config_client /mnt/lustre oleg113-client.virtnet: Checking config lustre mounted on /mnt/lustre Checking servers environments Checking clients oleg113-client.virtnet environments Using TIMEOUT=20 osc.lustre-OST0000-osc-ffff993912478800.idle_timeout=debug osc.lustre-OST0001-osc-ffff993912478800.idle_timeout=debug disable quota as required oleg113-server: oleg113-server.virtnet: executing set_default_debug vfstrace rpctrace dlmtrace neterror ha config ioctl super lfsck all osd-ldiskfs.track_declares_assert=1 === sanity-sec: finish setup 20:42:56 (1788741776) === oleg113-server: Warning: it is not recommended to have a squash value outside of the offset range [ 0, -3 ] as it will not be mapped properly. On MGS 192.168.201.113, default.squash_uid = nodemap.default.squash_uid=65534 oleg113-server: Warning: it is not recommended to have a squash value outside of the offset range [ 0, -3 ] as it will not be mapped properly. On MGS 192.168.201.113, default.squash_gid = nodemap.default.squash_gid=65534 oleg113-server: Warning: it is not recommended to have a squash value outside of the offset range [ 0, -3 ] as it will not be mapped properly. On MGS 192.168.201.113, default.squash_projid = nodemap.default.squash_projid=65534 == sanity-sec test 301: test GSSIAM security flavor with RW/RO ========================================================== 20:43:17 (1788741797) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Mount with user_principal=mock_gssiam_rw Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Mount with user_principal=mock_gssiam_ro sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (ro,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_ro,user_xattr,verbose) test_rw touch: cannot touch '/mnt/lustre/d301.sanity-sec/test_ro': Read-only file system Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Mount with user_principal=mock_gssiam_rw and subdir sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre/d301.sanity-sec /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre/d301.sanity-sec /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre/d301.sanity-sec on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) checking cli2mdt...found 1/1 gssiam connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Mount with user_principal=mock_gssiam_ro and subdir sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre/d301.sanity-sec /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre/d301.sanity-sec /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre/d301.sanity-sec on /mnt/lustre type lustre (ro,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_ro,user_xattr,verbose) checking cli2mdt...found 1/1 gssiam connections touch: cannot touch '/mnt/lustre/test_rw_subdir': Read-only file system test_rw test_rw_subdir_0 test_rw_subdir_1 test_rw_subdir_2 test_rw_subdir_3 test_rw_subdir_4 test_rw_subdir_5 test_rw_subdir_6 test_rw_subdir_7 test_rw_subdir_8 test_rw_subdir_9 touch: cannot touch '/mnt/lustre/test_ro_subdir': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_0/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_0': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_1/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_1': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_2/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_2': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_3/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_3': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_4/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_4': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_5/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_5': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_6/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_6': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_7/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_7': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_8/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_8': Read-only file system file touch: cannot touch '/mnt/lustre/test_rw_subdir_9/ro_file': Read-only file system mkdir: cannot create directory '/mnt/lustre/test_ro_subdir_9': Read-only file system Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/0 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 301 (116s) == sanity-sec test 302: test GSSIAM security flavor with mock deny principal ========================================================== 20:45:13 (1788741913) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-client: ssh exited with exit code 5 pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Mount with user_principal=mock_gssiam_deny Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: mount.lustre: mount 192.168.201.113@tcp:/lustre at /mnt/lustre failed: Operation not permitted Mount failed as expected with deny principal Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 302 (96s) == sanity-sec test 303: test GSSIAM flavor fileset inherit from default nm ========================================================== 20:46:49 (1788742009) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-client: ssh exited with exit code 5 pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Mount with user_principal=mock_gssiam_rw Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Mount with user_principal=mock_gssiam_rw and non-existent subdir Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 mount.lustre: mount 192.168.201.113@tcp:/lustre/d303.sanity-sec/nonexistent at /mnt/lustre failed: Operation not permitted Mount with user_principal=mock_gssiam_rw and subdir sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/0 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 303 (106s) == sanity-sec test 304: GSSIAM client properly retries when token is expired ========================================================== 20:48:35 (1788742115) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: fail_loc=0x80001206 Mount with fail_loc for expired token retry Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) /mnt/lustre/d304.sanity-sec/test_retry Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 1/1 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 304 (107s) == sanity-sec test 305: verify gssiam nodemap lifecycle == 20:50:22 (1788742222) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 On MGS 192.168.201.113, default.admin_nodemap = nodemap.default.admin_nodemap=1 On MGS 192.168.201.113, default.trusted_nodemap = nodemap.default.trusted_nodemap=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Iteration 1: enable gssiam rule Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam checking cli2mdt...found 1/1 gssiam connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Iteration 0: delete gssiam nodemap manually (should fail) oleg113-server: error: invalid ioctl: 000ce041 errno: 1: Operation not permitted oleg113-server: nodemap_del: Operation not permitted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Iteration 0: disable gssiam rule Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Iteration 3: check if gssiam nodemap is deleted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) Iteration 2: enable gssiam rule Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Iteration 4: delete gssiam nodemap manually (should fail) oleg113-server: error: invalid ioctl: 000ce041 errno: 1: Operation not permitted oleg113-server: nodemap_del: Operation not permitted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Iteration 4: disable gssiam rule Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Iteration 4: check if gssiam nodemap is deleted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) Iteration 3: enable gssiam rule Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Iteration 4: delete gssiam nodemap manually (should fail) oleg113-server: error: invalid ioctl: 000ce041 errno: 1: Operation not permitted oleg113-server: nodemap_del: Operation not permitted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Iteration 4: disable gssiam rule Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Iteration 3: check if gssiam nodemap is deleted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 1/1 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, default.admin_nodemap = nodemap.default.admin_nodemap=0 On MGS 192.168.201.113, default.trusted_nodemap = nodemap.default.trusted_nodemap=0 On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 305 (275s) == sanity-sec test 306: dynamic gssiam flavor transitions on live mount ========================================================== 20:54:57 (1788742497) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 On MGS 192.168.201.113, default.admin_nodemap = nodemap.default.admin_nodemap=1 On MGS 192.168.201.113, default.trusted_nodemap = nodemap.default.trusted_nodemap=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Iteration 1: change flavor to gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Iteration 3: change flavor back to null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections Iteration 3: check if gssiam nodemap is deleted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Iteration 2: change flavor to gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Iteration 4: change flavor back to null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections Iteration 3: check if gssiam nodemap is deleted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Iteration 3: change flavor to gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Iteration 4: change flavor back to null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections Iteration 3: check if gssiam nodemap is deleted pdsh@oleg113-client: oleg113-server: ssh exited with exit code 1 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/0 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, default.admin_nodemap = nodemap.default.admin_nodemap=0 On MGS 192.168.201.113, default.trusted_nodemap = nodemap.default.trusted_nodemap=0 On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 306 (242s) == sanity-sec test 307: GSSIAM read-only mount overrides server RW and vice-versa ========================================================== 20:58:59 (1788742739) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-client: ssh exited with exit code 5 pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Mount mock_gssiam_rw with ro Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw,ro 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw,ro 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (ro,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) mkdir: cannot create directory '/mnt/lustre/d307.sanity-sec': File exists Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Mount mock_gssiam_ro with default sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (ro,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_ro,user_xattr,verbose) mkdir: cannot create directory '/mnt/lustre/d307.sanity-sec': File exists Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/0 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 307 (78s) == sanity-sec test 308: verify GSSIAM disable_rootsquash and default rootsquash behavior ========================================================== 21:00:17 (1788742817) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 pdsh@oleg113-client: oleg113-client: ssh exited with exit code 5 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Mount with user_principal=mock_gssiam_rw,disable_rootsquash Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw,disable_rootsquash 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw,disable_rootsquash 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,disable_rootsquash,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw,disable_rootsquash 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw,disable_rootsquash 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,disable_rootsquash,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Mount with user_principal=mock_gssiam_rw (default rootsquash) sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/0 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 308 (75s) == sanity-sec test 309: verify stacked GSSIAM mount overrides previous mount policy ========================================================== 21:01:33 (1788742893) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections 1. Mount with user_principal=mock_gssiam_rw (writable) Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) 2. Stacked mount with disable_rootsquash,ro,device=192.168.201.113@tcp:/lustre force: 1 touch: cannot touch '/mnt/lustre/d309.sanity-sec/test_stacked_no_squash': Read-only file system 3. Unmount top layer Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/0 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 309 (80s) == sanity-sec test 310: verify single user with two mount points with different IAM ========================================================== 21:02:53 (1788742973) debug=+sec debug=+sec mdt.lustre-MDT0000.enable_remote_dir_gid=-1 fail_loc=0x1205 On MGS 192.168.201.113, active = nodemap.active=1 sptlrpc.gssiam.gssiam_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_upcall sptlrpc.gssiam_server.gssiam_auth_upcall=/home/green/git/lustre-release/lustre/utils/gss/l_gssiam_auth sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=gssiam Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=gssiam pdsh@oleg113-client: oleg113-server: ssh exited with exit code 2 checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 0/1 gssiam connections checking cli2mdt...found 1/1 gssiam connections Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: 1. Mount /mnt/lustre with user_principal=mock_gssiam_rw (writable) Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre/d310.sanity-sec /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_rw 192.168.201.113@tcp:/lustre/d310.sanity-sec /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre/d310.sanity-sec on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_rw,user_xattr,verbose) 2. Mount /mnt/lustre2 with user_principal=mock_gssiam_ro (read-only) Starting client oleg113-client.virtnet: -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre/d310.sanity-sec /mnt/lustre2 Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock,user_principal=mock_gssiam_ro 192.168.201.113@tcp:/lustre/d310.sanity-sec /mnt/lustre2 Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre/d310.sanity-sec on /mnt/lustre2 type lustre (ro,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_principal=mock_gssiam_ro,user_xattr,verbose) 3. Verify writable access on /mnt/lustre 4. Verify read access on /mnt/lustre2 5. Verify write access is denied on /mnt/lustre2 touch: cannot touch '/mnt/lustre2/test_ro_fail_file': Read-only file system 6. Verify /mnt/lustre remains writable Stopping clients: oleg113-client.virtnet /mnt/lustre2 (opts:) Stopping client oleg113-client.virtnet /mnt/lustre2 opts: Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) Stopping clients: oleg113-client.virtnet /mnt/lustre2 (opts:) Setting sptlrpc rule: lustre.srpc.flavor.default.cli2ost=null Setting sptlrpc rule: lustre.srpc.flavor.default.cli2mdt=null checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 0/1 null connections checking cli2mdt...found 1/1 null connections sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_flush=-1 sptlrpc.gssiam_server.gssiam_auth_upcall=/usr/sbin/l_gssiam_auth sptlrpc.gssiam.gssiam_upcall=/usr/sbin/l_gssiam_upcall On MGS 192.168.201.113, active = nodemap.active=0 Stopping clients: oleg113-client.virtnet /mnt/lustre (opts:) Stopping client oleg113-client.virtnet /mnt/lustre opts: Starting client oleg113-client.virtnet: -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Mount client oleg113-client.virtnet: mount -t lustre -o user_xattr,flock 192.168.201.113@tcp:/lustre /mnt/lustre Started clients oleg113-client.virtnet: 192.168.201.113@tcp:/lustre on /mnt/lustre type lustre (rw,flock,checksum,encrypt,lazystatfs,lruresize,nolock,statfs_project,nosync_on_close,nouser_fid2path,user_xattr,verbose) fail_loc=0 PASS 310 (94s) cleanup: ====================================================== running as uid/gid/euid/egid 500/500/500/500, groups: 500 [ls] [/mnt/lustre] d301.sanity-sec d303.sanity-sec d304.sanity-sec d306.sanity-sec d307.sanity-sec d308.sanity-sec d309.sanity-sec d310.sanity-sec running as uid/gid/euid/egid 501/501/501/501, groups: 501 [ls] [/mnt/lustre] d301.sanity-sec d303.sanity-sec d304.sanity-sec d306.sanity-sec d307.sanity-sec d308.sanity-sec d309.sanity-sec d310.sanity-sec == sanity-sec test complete, duration 1352 sec =========== 21:04:29 (1788743069) === sanity-sec: start cleanup 21:04:30 (1788743070) === === sanity-sec: finish cleanup 21:04:35 (1788743075) ===