Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
DescriptionJan Pazdziora (Red Hat)
2021-10-11 09:22:55 UTC
Description of problem:
Running annocheck on libbpf now started to report that it was compiled without the BIND_NOW and LTO.
Version-Release number of selected component (if applicable):
libbpf-0.5.0-1.el9.x86_64
annobin-annocheck-10.10-1.el9.x86_64
How reproducible:
Deterministic.
Steps to Reproduce:
1. annocheck --verbose /usr/lib64/libbpf.so.0.*.0
Actual results:
annocheck: Version 10.10.
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: pie test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: cf-protection test because correct flags found in .note.gnu.property note
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: property-note test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: writable-got test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: dynamic-segment test
Hardened: /usr/lib64/libbpf.so.0.5.0: FAIL: bind-now test because not linked with -Wl,-z,now
Hardened: /usr/lib64/libbpf.so.0.5.0: info: For more information visit: https://sourceware.org/annobin/annobin.html/Test-bind-now.html
Hardened: /usr/lib64/libbpf.so.0.5.0: info: set binary producer to Gas version 2.
Hardened: /usr/lib64/libbpf.so.0.5.0: info: notes produced by assembler plugin version 1
Hardened: /usr/lib64/libbpf.so.0.5.0: info: set binary producer to GCC version 10.
Hardened: /usr/lib64/libbpf.so.0.5.0: info: notes produced by gcc plugin version 1010
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: stack-prot test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: pic test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: fortify test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: glibcxx-assertions test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: optimization test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: warnings test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: stack-clash test
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: entry test because shared libraries do not use entry points
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: gnu-stack test because stack segment exists with the correct permissions
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: gnu-relro test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: notes test because no gaps found
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: not-branch-protection test because not an AArch64 binary
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: not-dynamic-tags test because AArch64 specific
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: go-revision test because no GO compiled code found
Hardened: /usr/lib64/libbpf.so.0.5.0: MAYB: test: lto because no indication that LTO was used
Hardened: /usr/lib64/libbpf.so.0.5.0: info: For more information visit: https://sourceware.org/annobin/annobin.html/Test-lto.html
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: only-go test because no GO compiled code found
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: production test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: run-path test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: rwx-seg test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: short-enums test
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: stack-realign test because not an x86 executable
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: textrel test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: threads test
Hardened: libbpf.so.0.5.0: Overall: FAIL.
Expected results:
No FAIL.
Additional info:
This is a regression against libbpr 0.4.0:
# annocheck /usr/lib64/libbpf.so.0.4.0
annocheck: Version 10.10.
Hardened: libbpf.so.0.4.0: PASS.
Comment 1Jan Pazdziora (Red Hat)
2021-10-11 09:23:31 UTC
Comment 13Jean-Tsung Hsiao
2021-11-17 15:03:16 UTC
Still not completely passed with libbpf-0.5.0-3.el9. REset the status to Modified.
See logs below:
[root@netqe10 ~]# uname -r
5.14.0-15.el9.x86_64
[root@netqe10 ~]# rpm -q libbpf
libbpf-0.5.0-3.el9.x86_64
[root@netqe10 ~]#
annocheck: Version 10.23.
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: pie test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: cf-protection test because correct flags found in .note.gnu.property note
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: property-note test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: writable-got test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: dynamic-segment test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: bind-now test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: stack-prot test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: pic test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: fortify test because fortify note found
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: glibcxx-assertions test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: optimization test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: warnings test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: stack-clash test
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: entry test because shared libraries do not use entry points
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: gnu-stack test because stack segment exists with the correct permissions
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: gnu-relro test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: notes test because no gaps found
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: not-branch-protection test because not an AArch64 binary
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: not-dynamic-tags test because AArch64 specific
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: go-revision test because no GO compiled code found
Hardened: /usr/lib64/libbpf.so.0.5.0: MAYB: test: lto because no indication that LTO was used
Hardened: /usr/lib64/libbpf.so.0.5.0: info: For more information visit: https://sourceware.org/annobin/annobin.html/Test-lto.html
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: only-go test because no GO compiled code found
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: production test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: run-path test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: rwx-seg test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: short-enums test
Hardened: /usr/lib64/libbpf.so.0.5.0: skip: stack-realign test because not an x86 executable
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: textrel test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: threads test
Hardened: /usr/lib64/libbpf.so.0.5.0: PASS: unicode test
Hardened: libbpf.so.0.5.0: Overall: FAIL (due to MAYB results).
[root@netqe10 ~]#
it failed with: FAIL (due to MAYB results).
and the maybe results is:
Hardened: /usr/lib64/libbpf.so.0.5.0: MAYB: test: lto because no indication that LTO was used
and lto is not supported in libbpf
Comment 15Jean-Tsung Hsiao
2021-12-03 01:11:45 UTC
Per comment #13 the bin-now has passed.Thus, the bug has been verified.
Comment 16Jean-Tsung Hsiao
2021-12-10 02:42:51 UTC
Hi Jiri,
Is there a newer libbpf than libbpf-0.5.0-3.el9.x86_64 to be tested ?
NOTE: Compose RHEL-9.0.0-20211208.3 is still using this libbpf.
Please let me know.
Thanks!
Jean
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory (new packages: libbpf), and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHBA-2022:3930