Bug 2135747

Summary: Rebase sevctl for RHEL 8.8
Product: Red Hat Enterprise Linux 8 Reporter: John Ferlan <jferlan>
Component: sevctlAssignee: Tyler Fanelli <tfanelli>
Status: CLOSED ERRATA QA Contact: zixchen
Severity: high Docs Contact:
Priority: unspecified    
Version: 8.8CC: coli, jinzhao, juzhang, tfanelli, virt-bugs, yfu, zixchen
Target Milestone: rcKeywords: Rebase, Triaged
Target Release: ---Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 2135744 Environment:
Last Closed: 2023-05-16 08:36:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2135744    
Bug Blocks:    

Description John Ferlan 2022-10-18 10:59:50 UTC
+++ This bug was initially created as a clone of Bug #2135744 +++

Description of problem:

Let's be sure the latest sevctl release is rebased into RHEL 8.8

Comment 2 John Ferlan 2022-10-18 11:01:50 UTC
Setting ITR=8.8.0 and DTM=15 to align with 9.2 rebase. This needs to be completed before 15-Jan in order to be ready for Comprehensive Test Cycle 2

Comment 3 Tyler Fanelli 2022-12-01 02:07:35 UTC
@zixchen @coli Does qa_ack+ need to be submitted in order for me to submit a push? I'm running into the following problem when pushing via "rhpkg push":

remote: *** Checking commit fef2acf02533d41a6d555d59c4b20ecacabe26e2
remote: *** Related:
remote: ***   Unapproved:
remote: ***     rhbz#2135747 (qa_ack?, internal_target_release=8.8.0, devel_ack+, mirror+, release?, Rebase, Triaged)
remote: *** No approved issue IDs referenced in log message or changelog for fef2acf02533d41a6d555d59c4b20ecacabe26e2
remote: *** Unapproved issue IDs referenced in log message or changelog for fef2acf02533d41a6d555d59c4b20ecacabe26e2
remote: *** Commit fef2acf02533d41a6d555d59c4b20ecacabe26e2 denied
remote: *** Current checkin policy requires:
remote:     ((release == + and internal_target_release == 8.8.0) or (((jiraProject == RHELBLD) or (jiraProject == SPRHEL) or (jiraProject == RHELPLAN)) and ((jiraField(release) == +) or (jiraField(BZ release) == +)) 
            and (jiraField(fixVersions) == 8.8.0)))

Comment 4 zixchen 2022-12-01 02:24:14 UTC
(In reply to Tyler Fanelli from comment #3)
> @zixchen @coli Does qa_ack+ need to be submitted in order for me
> to submit a push? I'm running into the following problem when pushing via
> "rhpkg push":
> 
> remote: *** Checking commit fef2acf02533d41a6d555d59c4b20ecacabe26e2
> remote: *** Related:
> remote: ***   Unapproved:
> remote: ***     rhbz#2135747 (qa_ack?, internal_target_release=8.8.0,
> devel_ack+, mirror+, release?, Rebase, Triaged)
> remote: *** No approved issue IDs referenced in log message or changelog for
> fef2acf02533d41a6d555d59c4b20ecacabe26e2
> remote: *** Unapproved issue IDs referenced in log message or changelog for
> fef2acf02533d41a6d555d59c4b20ecacabe26e2
> remote: *** Commit fef2acf02533d41a6d555d59c4b20ecacabe26e2 denied
> remote: *** Current checkin policy requires:
> remote:     ((release == + and internal_target_release == 8.8.0) or
> (((jiraProject == RHELBLD) or (jiraProject == SPRHEL) or (jiraProject ==
> RHELPLAN)) and ((jiraField(release) == +) or (jiraField(BZ release) == +)) 
>             and (jiraField(fixVersions) == 8.8.0)))

Sorry, added qa_ack+

Comment 5 Tyler Fanelli 2022-12-01 20:00:24 UTC
Thanks!

Can you begin the manual gating for OSCI?

https://dashboard.osci.redhat.com/#/artifact/brew-build/aid/49336666?focus=id:7445a7773999-1

Comment 6 zixchen 2022-12-02 06:06:20 UTC
(In reply to Tyler Fanelli from comment #5)
> Thanks!
> 
> Can you begin the manual gating for OSCI?
> 
> https://dashboard.osci.redhat.com/#/artifact/brew-build/aid/
> 49336666?focus=id:7445a7773999-1

Thanks Tyler.Test with sevctl-0.3.2-1.el8, manual gating passes.

# cargo test --features=hw_tests,openssl
    Finished test [unoptimized + debuginfo] target(s) in 0.02s
     Running unittests src/lib.rs (target/debug/deps/sev-8752109774a03c4e)

running 7 tests
test firmware::host::types::test::snp_ext_config_get_config ... ok
test firmware::host::types::test::snp_ext_config_get_certs ... ok
test util::impl_const_id::tests::test_const_id_macro ... ok
test session::initialized::verify ... ok
test session::key::mac ... ok
test session::initialized::session ... ok
test session::key::derive ... ok

test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

     Running tests/api.rs (target/debug/deps/api-e9f7682bf5c7fef7)

running 13 tests
test pdh_generate ... ignored
test pek_cert_import ... ignored
test pek_generate ... ignored
test platform_reset ... ignored
test snp_get_ext_config_cert_only ... ignored
test snp_get_ext_config_cfg_only ... ignored
test snp_get_ext_config_std ... ignored
test snp_set_ext_config_std ... ignored
test get_identifier ... ok
test platform_status ... ok
test pek_csr ... ok
test snp_platform_status ... ok
test pdh_cert_export ... ok

test result: ok. 5 passed; 0 failed; 8 ignored; 0 measured; 0 filtered out; finished in 0.01s

     Running tests/certs.rs (target/debug/deps/certs-97e6c72cd766fbea)

running 58 tests
test milan::ark::decode ... ok
test milan::ask::encode ... ok
test milan::ark::encode ... ok
test milan::ask::decode ... ok
test milan::cek::decode ... ok
test milan::cek::encode ... ok
test milan::oca::encode ... ok
test milan::oca::decode ... ok
test milan::pdh::decode ... ok
test milan::pdh::encode ... ok
test milan::pek::decode ... ok
test milan::pek::encode ... ok
test naples::ark::decode ... ok
test naples::ark::encode ... ok
test naples::ask::decode ... ok
test milan::ark::verify ... ok
test naples::ark::verify ... ok
test milan::cek::verify ... ok
test milan::ask::verify ... ok
test naples::ask::encode ... ok
test naples::cek::decode ... ok
test naples::cek::encode ... ok
test naples::ask::verify ... ok
test naples::cek::verify ... ok
test naples::oca::decode ... ok
test naples::pdh::decode ... ok
test naples::oca::encode ... ok
test milan::oca::verify ... ok
test naples::pek::decode ... ok
test naples::pdh::encode ... ok
test naples::pek::encode ... ok
test rome::ark::decode ... ok
test milan::pdh::verify ... ok
test rome::ark::encode ... ok
test rome::ask::decode ... ok
test rome::ask::encode ... ok
test rome::ark::verify ... ok
test rome::cek::decode ... ok
test naples::oca::verify ... ok
test rome::ask::verify ... ok
test rome::cek::encode ... ok
test rome::oca::decode ... ok
test rome::cek::verify ... ok
test rome::oca::encode ... ok
test rome::pdh::decode ... ok
test naples::pdh::verify ... ok
test rome::pdh::encode ... ok
test milan::pek::verify ... ok
test rome::pek::decode ... ok
test rome::pek::encode ... ok
test test_for_verify_false_positive ... ok
test rome::oca::verify ... ok
test naples::pek::verify ... ok
test rome::pdh::verify ... ok
test rome::pek::verify ... ok
test milan::oca::create ... ok
test naples::oca::create ... ok
test rome::oca::create ... ok

test result: ok. 58 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s

     Running tests/launch.rs (target/debug/deps/launch-56627a459caf1de4)

running 1 test
test sev ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s

     Running tests/session.rs (target/debug/deps/session-d5543291739e20f5)

running 2 tests
test initialized::create ... ok
test initialized::start ... ok

test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s

     Running tests/snp_launch.rs (target/debug/deps/snp_launch-2529c440049cc086)

running 1 test
test snp ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s

   Doc-tests sev

running 1 test
test src/lib.rs - Generation (line 131) - compile ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s

Comment 9 zixchen 2022-12-05 07:58:21 UTC
Hi Tyler, could you please update the commits of the rebase?

Comment 10 zixchen 2022-12-05 08:41:56 UTC
Regression test passed on Rome and Milan, no issue found.

Version:
sevctl-0.3.2-1.el8.x86_64
qemu-kvm-6.2.0-26.module+el8.8.0+17341+68372c23.x86_64

Job log:
Rome: http://lab-04.rhts.eng.pek2.redhat.com/beaker/logs/tasks/153624+/153624765/taskout.log
Milan: http://lab-04.rhts.eng.pek2.redhat.com/beaker/logs/tasks/153626+/153626701/taskout.log

Comment 13 errata-xmlrpc 2023-05-16 08:36:31 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (sevctl bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:2827