Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-18498

gnutls rebuild fails because of the upstream `ktls.sh` test

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Minor Minor
    • rhel-9.4
    • rhel-9.4
    • gnutls
    • gnutls-3.8.3-1.el9
    • None
    • None
    • 1
    • rhel-sst-security-crypto
    • ssg_security
    • 23
    • 0.2
    • False
    • Hide

      None

      Show
      None
    • No
    • Crypto24Q1
    • Hide

      Acceptance Criteria: `ktls.sh` upstream test passes in and out of FIPS mode with ktls kernel module pre-loaded [/CoreOS/gnutls/Sanity/smoke-test]

      Show
      Acceptance Criteria: `ktls.sh` upstream test passes in and out of FIPS mode with ktls kernel module pre-loaded [/CoreOS/gnutls/Sanity/smoke-test]
    • Pass
    • None
    • None

      gnutls-3.8.2-1.el9 rebuild tests fail because of the upstream `ktls.sh` test failure, for different reasons:

      1. in non-FIPS mode, it fails as described in https://gitlab.com/gnutls/gnutls/-/issues/1443, (Error: Decryption has failed), kernel version is 5.14.0-395.el9
      2. in FIPS mode, it fails differently:

      /proc/modules:tls 151552 0 - Live 0xffffffffc0b61000
      running ktls test with NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+AES-128-GCM
      client: Peer has closed the TLS connection
      running ktls test with NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+AES-256-GCM
      client: Peer has closed the TLS connection
      running ktls test with NORMAL:-VERS-ALL:+VERS-TLS1.2:-CIPHER-ALL:+CHACHA20-POLY1305
      gnutls_ktls: gnutls_ktls.c:67: client: Assertion `gnutls_priority_set_direct(session, prio, NULL) >= 0' failed.
      gnutls_ktls: gnutls_ktls.c:185: server: Assertion `gnutls_priority_set_direct(session, prio, NULL) >= 0' failed.
      ./ktls.sh: line 47: 126378 Aborted (core dumped) GNUTLS_SYSTEM_PRIORITY_FAIL_ON_INVALID=1 GNUTLS_SYSTEM_PRIORITY_FILE="$cfg" "$builddir/gnutls_ktls" "$@"
      FAIL ktls.sh (exit status: 134)

      Please skip, xfail or patch this test.

              dueno@redhat.com Daiki Ueno
              asosedki@redhat.com Alexander Sosedkin
              Daiki Ueno Daiki Ueno
              Alexander Sosedkin Alexander Sosedkin
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: