RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 2135747 - Rebase sevctl for RHEL 8.8
Summary: Rebase sevctl for RHEL 8.8
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: sevctl
Version: 8.8
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: rc
: ---
Assignee: Tyler Fanelli
QA Contact: zixchen
URL:
Whiteboard:
Depends On: 2135744
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-10-18 10:59 UTC by John Ferlan
Modified: 2023-07-24 02:36 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of: 2135744
Environment:
Last Closed: 2023-05-16 08:36:31 UTC
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-136850 0 None None None 2022-10-18 11:05:09 UTC
Red Hat Product Errata RHBA-2023:2827 0 None None None 2023-05-16 08:36:32 UTC

Description John Ferlan 2022-10-18 10:59:50 UTC
+++ This bug was initially created as a clone of Bug #2135744 +++

Description of problem:

Let's be sure the latest sevctl release is rebased into RHEL 8.8

Comment 2 John Ferlan 2022-10-18 11:01:50 UTC
Setting ITR=8.8.0 and DTM=15 to align with 9.2 rebase. This needs to be completed before 15-Jan in order to be ready for Comprehensive Test Cycle 2

Comment 3 Tyler Fanelli 2022-12-01 02:07:35 UTC
@zixchen @coli Does qa_ack+ need to be submitted in order for me to submit a push? I'm running into the following problem when pushing via "rhpkg push":

remote: *** Checking commit fef2acf02533d41a6d555d59c4b20ecacabe26e2
remote: *** Related:
remote: ***   Unapproved:
remote: ***     rhbz#2135747 (qa_ack?, internal_target_release=8.8.0, devel_ack+, mirror+, release?, Rebase, Triaged)
remote: *** No approved issue IDs referenced in log message or changelog for fef2acf02533d41a6d555d59c4b20ecacabe26e2
remote: *** Unapproved issue IDs referenced in log message or changelog for fef2acf02533d41a6d555d59c4b20ecacabe26e2
remote: *** Commit fef2acf02533d41a6d555d59c4b20ecacabe26e2 denied
remote: *** Current checkin policy requires:
remote:     ((release == + and internal_target_release == 8.8.0) or (((jiraProject == RHELBLD) or (jiraProject == SPRHEL) or (jiraProject == RHELPLAN)) and ((jiraField(release) == +) or (jiraField(BZ release) == +)) 
            and (jiraField(fixVersions) == 8.8.0)))

Comment 4 zixchen 2022-12-01 02:24:14 UTC
(In reply to Tyler Fanelli from comment #3)
> @zixchen @coli Does qa_ack+ need to be submitted in order for me
> to submit a push? I'm running into the following problem when pushing via
> "rhpkg push":
> 
> remote: *** Checking commit fef2acf02533d41a6d555d59c4b20ecacabe26e2
> remote: *** Related:
> remote: ***   Unapproved:
> remote: ***     rhbz#2135747 (qa_ack?, internal_target_release=8.8.0,
> devel_ack+, mirror+, release?, Rebase, Triaged)
> remote: *** No approved issue IDs referenced in log message or changelog for
> fef2acf02533d41a6d555d59c4b20ecacabe26e2
> remote: *** Unapproved issue IDs referenced in log message or changelog for
> fef2acf02533d41a6d555d59c4b20ecacabe26e2
> remote: *** Commit fef2acf02533d41a6d555d59c4b20ecacabe26e2 denied
> remote: *** Current checkin policy requires:
> remote:     ((release == + and internal_target_release == 8.8.0) or
> (((jiraProject == RHELBLD) or (jiraProject == SPRHEL) or (jiraProject ==
> RHELPLAN)) and ((jiraField(release) == +) or (jiraField(BZ release) == +)) 
>             and (jiraField(fixVersions) == 8.8.0)))

Sorry, added qa_ack+

Comment 5 Tyler Fanelli 2022-12-01 20:00:24 UTC
Thanks!

Can you begin the manual gating for OSCI?

https://dashboard.osci.redhat.com/#/artifact/brew-build/aid/49336666?focus=id:7445a7773999-1

Comment 6 zixchen 2022-12-02 06:06:20 UTC
(In reply to Tyler Fanelli from comment #5)
> Thanks!
> 
> Can you begin the manual gating for OSCI?
> 
> https://dashboard.osci.redhat.com/#/artifact/brew-build/aid/
> 49336666?focus=id:7445a7773999-1

Thanks Tyler.Test with sevctl-0.3.2-1.el8, manual gating passes.

# cargo test --features=hw_tests,openssl
    Finished test [unoptimized + debuginfo] target(s) in 0.02s
     Running unittests src/lib.rs (target/debug/deps/sev-8752109774a03c4e)

running 7 tests
test firmware::host::types::test::snp_ext_config_get_config ... ok
test firmware::host::types::test::snp_ext_config_get_certs ... ok
test util::impl_const_id::tests::test_const_id_macro ... ok
test session::initialized::verify ... ok
test session::key::mac ... ok
test session::initialized::session ... ok
test session::key::derive ... ok

test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

     Running tests/api.rs (target/debug/deps/api-e9f7682bf5c7fef7)

running 13 tests
test pdh_generate ... ignored
test pek_cert_import ... ignored
test pek_generate ... ignored
test platform_reset ... ignored
test snp_get_ext_config_cert_only ... ignored
test snp_get_ext_config_cfg_only ... ignored
test snp_get_ext_config_std ... ignored
test snp_set_ext_config_std ... ignored
test get_identifier ... ok
test platform_status ... ok
test pek_csr ... ok
test snp_platform_status ... ok
test pdh_cert_export ... ok

test result: ok. 5 passed; 0 failed; 8 ignored; 0 measured; 0 filtered out; finished in 0.01s

     Running tests/certs.rs (target/debug/deps/certs-97e6c72cd766fbea)

running 58 tests
test milan::ark::decode ... ok
test milan::ask::encode ... ok
test milan::ark::encode ... ok
test milan::ask::decode ... ok
test milan::cek::decode ... ok
test milan::cek::encode ... ok
test milan::oca::encode ... ok
test milan::oca::decode ... ok
test milan::pdh::decode ... ok
test milan::pdh::encode ... ok
test milan::pek::decode ... ok
test milan::pek::encode ... ok
test naples::ark::decode ... ok
test naples::ark::encode ... ok
test naples::ask::decode ... ok
test milan::ark::verify ... ok
test naples::ark::verify ... ok
test milan::cek::verify ... ok
test milan::ask::verify ... ok
test naples::ask::encode ... ok
test naples::cek::decode ... ok
test naples::cek::encode ... ok
test naples::ask::verify ... ok
test naples::cek::verify ... ok
test naples::oca::decode ... ok
test naples::pdh::decode ... ok
test naples::oca::encode ... ok
test milan::oca::verify ... ok
test naples::pek::decode ... ok
test naples::pdh::encode ... ok
test naples::pek::encode ... ok
test rome::ark::decode ... ok
test milan::pdh::verify ... ok
test rome::ark::encode ... ok
test rome::ask::decode ... ok
test rome::ask::encode ... ok
test rome::ark::verify ... ok
test rome::cek::decode ... ok
test naples::oca::verify ... ok
test rome::ask::verify ... ok
test rome::cek::encode ... ok
test rome::oca::decode ... ok
test rome::cek::verify ... ok
test rome::oca::encode ... ok
test rome::pdh::decode ... ok
test naples::pdh::verify ... ok
test rome::pdh::encode ... ok
test milan::pek::verify ... ok
test rome::pek::decode ... ok
test rome::pek::encode ... ok
test test_for_verify_false_positive ... ok
test rome::oca::verify ... ok
test naples::pek::verify ... ok
test rome::pdh::verify ... ok
test rome::pek::verify ... ok
test milan::oca::create ... ok
test naples::oca::create ... ok
test rome::oca::create ... ok

test result: ok. 58 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s

     Running tests/launch.rs (target/debug/deps/launch-56627a459caf1de4)

running 1 test
test sev ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s

     Running tests/session.rs (target/debug/deps/session-d5543291739e20f5)

running 2 tests
test initialized::create ... ok
test initialized::start ... ok

test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s

     Running tests/snp_launch.rs (target/debug/deps/snp_launch-2529c440049cc086)

running 1 test
test snp ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s

   Doc-tests sev

running 1 test
test src/lib.rs - Generation (line 131) - compile ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s

Comment 9 zixchen 2022-12-05 07:58:21 UTC
Hi Tyler, could you please update the commits of the rebase?

Comment 10 zixchen 2022-12-05 08:41:56 UTC
Regression test passed on Rome and Milan, no issue found.

Version:
sevctl-0.3.2-1.el8.x86_64
qemu-kvm-6.2.0-26.module+el8.8.0+17341+68372c23.x86_64

Job log:
Rome: http://lab-04.rhts.eng.pek2.redhat.com/beaker/logs/tasks/153624+/153624765/taskout.log
Milan: http://lab-04.rhts.eng.pek2.redhat.com/beaker/logs/tasks/153626+/153626701/taskout.log

Comment 13 errata-xmlrpc 2023-05-16 08:36:31 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (sevctl bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:2827


Note You need to log in before you can comment on or make changes to this bug.