Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-64660

RHCOS10: node-image-overlay.service failed on bootstrap when enabling fips

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 4.20
    • RHCOS
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Moderate
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      When installing with the RHCOS10 Prebuilt Release image - registry.ci.openshift.org/rhcos-devel/ocp-4.20-10.1:ocp-release-4.20.0-rc.3-x86_64, node-image-overlay.service failed on bootstrap
      
      [systemd]
      Failed Units: 1
        node-image-overlay.service
      [core@jimaash04b-sgsbh-bootstrap ~]$ sudo -i
      [systemd]
      Failed Units: 1
        node-image-overlay.service
      [root@jimaash04b-sgsbh-bootstrap ~]# grep -i fips /proc/cmdline
      BOOT_IMAGE=(hd0,gpt3)/boot/ostree/rhcos-b61c2c00bf688c0bdf042ed756359ecc7925581dba07ff47814d00bb3a6b978c/vmlinuz-6.12.0-124.7.1.el10_1.x86_64 rw ignition.firstboot ostree=/ostree/boot.1/rhcos/b61c2c00bf688c0bdf042ed756359ecc7925581dba07ff47814d00bb3a6b978c/0 ignition.platform.id=azurestack fips=1 boot=LABEL=boot
      
      [root@jimaash04b-sgsbh-bootstrap ~]# journalctl -u node-image-overlay.service 
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap systemd[1]: Starting node-image-overlay.service - Node Image Overlay...
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4058]: Overlaying node image content
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.bind.config.4062" -> "/usr/share/crypto-policies/DEFAULT/bind.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.gnutls.config.4062" -> "/usr/share/crypto-policies/DEFAULT/gnutls.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.java.config.4062" -> "/usr/share/crypto-policies/DEFAULT/java.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.krb5.config.4062" -> "/usr/share/crypto-policies/DEFAULT/krb5.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.libreswan.config.4062" -> "/usr/share/crypto-policies/DEFAULT/libreswan.txt" failed: Read-only file system>
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.libssh.config.4062" -> "/usr/share/crypto-policies/DEFAULT/libssh.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.nss.config.4062" -> "/usr/share/crypto-policies/DEFAULT/nss.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.openssh.config.4062" -> "/usr/share/crypto-policies/DEFAULT/openssh.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.opensshserver.config.4062" -> "/usr/share/crypto-policies/DEFAULT/opensshserver.txt" failed: Read-only fil>
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.openssl_fips.config.4062" -> "/usr/share/crypto-policies/DEFAULT/openssl_fips.txt" failed: Read-only file >
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.opensslcnf.config.4062" -> "/usr/share/crypto-policies/DEFAULT/opensslcnf.txt" failed: Read-only file syst>
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.rpm-sequoia.config.4062" -> "/usr/share/crypto-policies/DEFAULT/rpm-sequoia.txt" failed: Read-only file sy>
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [generator] symlink "/etc/crypto-policies/back-ends/.sequoia.config.4062" -> "/usr/share/crypto-policies/DEFAULT/sequoia.txt" failed: Read-only file system (30)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4062]: rsync: [receiver] rename "/etc/crypto-policies/.config.1N0Gvs" -> "crypto-policies/config": Device or resource busy (16)
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap node-image-overlay.sh[4061]: rsync error: some files/attrs were not transferred (see previous errors) (code 23) at main.c(1338) [sender=3.4.1]
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap systemd[1]: node-image-overlay.service: Main process exited, code=exited, status=23/n/a
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap systemd[1]: node-image-overlay.service: Failed with result 'exit-code'.
      Nov 04 11:31:27 jimaash04b-sgsbh-bootstrap systemd[1]: Failed to start node-image-overlay.service - Node Image Overlay.

      Version-Release number of selected component (if applicable):

      registry.ci.openshift.org/rhcos-devel/ocp-4.20-10.1:ocp-release-4.20.0-rc.3-x86_64

      How reproducible:

          Always

      Steps to Reproduce:

          1. Config install-config.yaml file, enable fips and set clusterOSImage rhcos-10.1.20251017-0-azurestack.x86_64.vhd
          2. Set ENV OPENSHIFT_INSTALL_RELEASE_IMAGE_OVERRIDE: registry.ci.openshift.org/rhcos-devel/ocp-4.20-10.1:ocp-release-4.20.0-rc.3-x86_64      
          3. Create cluster on Azure Stack Hub
          

      Actual results:

          Installation failed

      Expected results:

          Installation succeeded

      Additional info:

          

              Unassigned Unassigned
              jinyunma Jinyun Ma
              None
              None
              Michael Nguyen Michael Nguyen
              None
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: