Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updated setup-sysvm-tmplt script, to run cmds accessing destdir with sudo #10263

Merged
merged 5 commits into from
Mar 27, 2025

Conversation

sureshanaparti
Copy link
Contributor

@sureshanaparti sureshanaparti commented Jan 24, 2025

Description

This PR updates setup-sysvm-tmplt script, to run cmds accessing destdir with sudo. These cmds in this script are are added to sudoers file, to allow for cloudstack service user 'cloud' to access destdir.

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • build/CI
  • test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

@sureshanaparti
Copy link
Contributor Author

@blueorangutan package

@blueorangutan
Copy link

@sureshanaparti a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@DaanHoogland DaanHoogland added this to the 4.19.2 milestone Jan 24, 2025
Copy link

codecov bot commented Jan 24, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 15.16%. Comparing base (0d5047b) to head (1c03f91).
Report is 54 commits behind head on 4.19.

Additional details and impacted files
@@            Coverage Diff             @@
##               4.19   #10263    +/-   ##
==========================================
  Coverage     15.16%   15.16%            
- Complexity    11300    11328    +28     
==========================================
  Files          5408     5414     +6     
  Lines        473912   474811   +899     
  Branches      57844    57911    +67     
==========================================
+ Hits          71855    72017   +162     
- Misses       394025   394742   +717     
- Partials       8032     8052    +20     
Flag Coverage Δ
uitests 4.28% <ø> (-0.01%) ⬇️
unittests 15.89% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@blueorangutan
Copy link

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ debian ✔️ suse15. SL-JID 12198

- The cmds in this script are allowed for normal (cloudstack service) user when destdir is created without sudo
@sureshanaparti sureshanaparti force-pushed the setup-sysvm-tmplt-script-update branch from 4a16185 to 0a4e462 Compare February 3, 2025 08:42
@sureshanaparti
Copy link
Contributor Author

@blueorangutan package

@blueorangutan
Copy link

@sureshanaparti a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan
Copy link

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ debian ✔️ suse15. SL-JID 12302

@sureshanaparti
Copy link
Contributor Author

@blueorangutan test

@blueorangutan
Copy link

@sureshanaparti a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@blueorangutan
Copy link

[SF] Trillian Build Failed (tid-12287)

@blueorangutan
Copy link

[SF] Trillian Build Failed (tid-12307)

@DaanHoogland DaanHoogland modified the milestones: 4.19.2, 4.19.3 Feb 7, 2025
@Pearl1594
Copy link
Contributor

@blueorangutan package

@blueorangutan
Copy link

@Pearl1594 a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan
Copy link

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ debian ✔️ suse15. SL-JID 12564

@Pearl1594
Copy link
Contributor

@blueorangutan test

@blueorangutan
Copy link

@Pearl1594 a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@blueorangutan
Copy link

[SF] Trillian Build Failed (tid-12492)

@Pearl1594
Copy link
Contributor

@sureshanaparti is this ready for review?

@sureshanaparti
Copy link
Contributor Author

@sureshanaparti is this ready for review?

not yet @Pearl1594 , still in progress.

@sureshanaparti sureshanaparti changed the title Updated setup-sysvm-tmplt script, to run cmds without sudo Updated setup-sysvm-tmplt script, to run cmds accessing destdir with sudo Mar 20, 2025
@sureshanaparti
Copy link
Contributor Author

@blueorangutan package

@blueorangutan
Copy link

@sureshanaparti a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan
Copy link

Packaging result [SF]: ✔️ el8 ✖️ el9 ✔️ debian ✖️ suse15. SL-JID 12838

@sureshanaparti
Copy link
Contributor Author

@blueorangutan package

@blueorangutan
Copy link

@sureshanaparti a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan
Copy link

Packaging result [SF]: ✔️ el8 ✖️ el9 ✔️ debian ✖️ suse15. SL-JID 12841

@rajujith
Copy link

@blueorangutan package

@blueorangutan
Copy link

@rajujith a [SL] Jenkins job has been kicked to build packages. It will be bundled with KVM, XenServer and VMware SystemVM templates. I'll keep you posted as I make progress.

@blueorangutan
Copy link

Packaging result [SF]: ✔️ el8 ✔️ el9 ✔️ debian ✔️ suse15. SL-JID 12890

Copy link

@rajujith rajujith left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.
Tested upgrade from 4.18.2. setup-sysvm-tmplt worked fine on a management server where umask is set to 0022.

@rajujith rajujith removed their assignment Mar 26, 2025
@sureshanaparti sureshanaparti marked this pull request as ready for review March 26, 2025 09:34
@sureshanaparti
Copy link
Contributor Author

@blueorangutan test

@blueorangutan
Copy link

@sureshanaparti a [SL] Trillian-Jenkins test job (ol8 mgmt + kvm-ol8) has been kicked to run smoke tests

@@ -146,9 +146,9 @@ fi


tmpltfile=$destdir/$localfile
tmpltsize=$(ls -l $tmpltfile | awk -F" " '{print $5}')
tmpltsize=$(sudo ls -l $tmpltfile | awk -F" " '{print $5}')
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as teh touch $tmplfile at line 111 is without sudo, does this need it?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@DaanHoogland needed it here, as tmpltfile is in destdir created with sudo in line 93.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok, than I don't understand why sudo is not needed on line 111, but if it tests alright then alright.

Copy link
Contributor

@Pearl1594 Pearl1594 Mar 27, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I just noticed it @DaanHoogland at L111 the variable is tmplfile and here it's tmpltfile - pointing to 2 different file paths.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@blueorangutan
Copy link

[SF] Trillian test result (tid-12822)
Environment: kvm-ol8 (x2), Advanced Networking with Mgmt server ol8
Total time taken: 47630 seconds
Marvin logs: https://github.com/blueorangutan/acs-prs/releases/download/trillian/pr10263-t12822-kvm-ol8.zip
Smoke tests completed. 132 look OK, 1 have errors, 0 did not run
Only failed and skipped tests results shown below:

Test Result Time (s) Test File
test_01_secure_vm_migration Error 134.70 test_vm_life_cycle.py
test_01_secure_vm_migration Error 134.71 test_vm_life_cycle.py

Copy link
Contributor

@DaanHoogland DaanHoogland left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clgtm

@DaanHoogland DaanHoogland merged commit 3afab9a into apache:4.19 Mar 27, 2025
26 checks passed
@DaanHoogland DaanHoogland deleted the setup-sysvm-tmplt-script-update branch March 27, 2025 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

SystemVM template upgrade fails on security hardened management servers
5 participants