Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 2121914

Summary: PasswordDialog breaks Anaconda Rescue when an empty passphrase is entered
Product: Red Hat Enterprise Linux 8 Reporter: Renaud Métrich <rmetrich>
Component: python-simplelineAssignee: Radek Vykydal <rvykydal>
Status: CLOSED ERRATA QA Contact: Release Test Team <release-test-team-automation>
Severity: high Docs Contact:
Priority: high    
Version: 8.7CC: jstodola, lmiksik, rvykydal
Target Milestone: rcKeywords: Triaged
Target Release: ---Flags: pm-rhel: mirror+
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: python-simpleline-1.1.1-3.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 2125272 (view as bug list) Environment:
Last Closed: 2022-11-08 10:04:35 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2121915, 2125272    

Description Renaud Métrich 2022-08-27 09:41:33 UTC
Description of problem:

When booting a system in rescue mode and having "user data" LUKS devices on the system, it's mandatory for the user to unlock those even though this should just be optional because these are not useful to troubleshoot system boot related to some issue with the system filesystems (/, /boot, /usr, etc.).
This is because of a bug in the python-simpleline implementation available on RHEL8: not entering a passphrase (through just typing "Enter" key) leads to the modal dialog to remain alive and hang Anaconda Rescue module.

This bug is critical because in some cases, the admin can just NOT unlock the LUKS devices, typically if there is no passphrase associated to the LUKS device and Clevis is used instead.

The bug is in file `/usr/lib/python3.6/site-packages/simpleline/render/adv_widgets.py`:
-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------
 60 class PasswordDialog(UIScreen):
 61     """Dialog screen for password input."""
 :
 78     def prompt(self, args=None):
 :
 89         self._password = handler.value
 90         if not self._password:
 91             return None
 92         else:
 93             # this may seem innocuous, but it's really a giant hack; we should
 94             # not be calling close() from prompt(), but the input handling code
 95             # in the TUI is such that without this very simple workaround, we
 96             # would be forever pelting users with a prompt to enter their pw
 97             self.close()
-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------

Here above, a test is made is password is empty on line 90, leading to just returning None and never closing the dialog.
The patch, which is already implemented in a more recent release of `python-simpleline` (found for example on Fedora 36 through `python3-simpleline-1.9.0-2.fc36.noarch` package) consists in unconditionally closing the dialog (and returning "None" as well):
-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------
 62 class PasswordDialog(UIScreen):
 :
 80     def prompt(self, args=None):
 :
 91         self._password = handler.value
 92 
 93         # this may seem innocuous, but it's really a giant hack; we should
 94         # not be calling close() from prompt(), but the input handling code
 95         # in the TUI is such that without this very simple workaround, we
 96         # would be forever pelting users with a prompt to enter their pw
 97         self.close()
 98         return None
-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------

Version-Release number of selected component (if applicable):

All python-simpleline including python-simpleline-1.1.1-2.el8.noarch

How reproducible:

Always

Steps to Reproduce:
1. Add a second disk to a VM on which a LVM LV will be encrypted and boot the VM
2. Create the encrypted disk

   # vgcreate data /dev/vdb
   # lvcreate -n luksdata -L 2G data
   # cryptsetup luksFormat /dev/data/luksdata --force-password
   --> "redhat"
   # UUID=$(cryptsetup luksUUID /dev/data/luksdata)
   # echo "luks-$UUID UUID=$UUID none discard" >> /etc/crypttab
   # cryptsetup luksOpen /dev/data/luksdata luks-$UUID
   # mkfs.xfs -L "LUKS XFS" /dev/mapper/luks-$UUID
   # echo "/dev/mapper/luks-$UUID /luksdata xfs defaults,x-systemd.device-timeout=0 0 0" >> /etc/fstab

3. Boot with RHEL DVD in Troubleshooting mode and select "1) Continue"

4. Enter no passphrase by just typing "Enter" key

Actual results:

-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------
================================================================================
Password

                                 data-luksdata

Passphrase: <CR>
--> hangs there forever
-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------

Expected results: continues to /mnt/sysroot prompt without unlocking

-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------
================================================================================
Password

                                 data-luksdata

Passphrase: <CR>
================================================================================
================================================================================
Rescue Shell

Your system has been mounted under /mnt/sysroot.
-------- 8< ---------------- 8< ---------------- 8< ---------------- 8< --------

Comment 4 Radek Vykydal 2022-09-01 13:33:19 UTC
(In reply to Jan Stodola from comment #1)
> Missing commit:
> https://github.com/rhinstaller/python-simpleline/commit/
> b24fd679ae7aefb7d845b1ed1418fba603894f5c

Port to RHEL8: https://src.osci.redhat.com/rpms/python-simpleline/pull-request/6#

I am going to prepare updates image with scratch build of the python-simpleline package.

Comment 5 Radek Vykydal 2022-09-01 14:21:10 UTC
(In reply to Radek Vykydal from comment #4)

> I am going to prepare updates image with scratch build of the
> python-simpleline package.

http://file.emea.redhat.com/rvykydal/rhbz2121914/updates.simpleline.2121914.img

Comment 9 Jan Stodola 2022-09-09 14:11:11 UTC
Confirmed that the problem is fixed in python3-simpleline-1.1.1-3.el8, when no LUKS passphrase is provided, the rescue mode continues and doesn't get stuck. Also tested that the correct passphrase unlocks the encrypted device and anaconda mounts it. In case of an incorrect passphrase, the installer (or rescuer?) asks for the passphrase again.

Marking as Verified:Tested

Comment 10 Jan Stodola 2022-09-09 14:13:52 UTC
*** Bug 2121915 has been marked as a duplicate of this bug. ***

Comment 13 Jan Stodola 2022-09-12 07:30:26 UTC
Checked that python-simpleline-1.1.1-3.el8 is in nightly compose RHEL-8.7.0-20220911.2

Moving to VERIFIED

Comment 15 errata-xmlrpc 2022-11-08 10:04:35 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (python-simpleline bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:7671