Re: [PATCH v3] powerpc/audit: Convert powerpc to AUDIT_ARCH_COMPAT_GENERIC
Venkat Rao Bagalkote <[email protected]> Thu, 2 Jul 2026 18:19:52 +0530
| Newsgroups | org.kernel.vger.audit,org.kernel.vger.linux-kernel,org.ozlabs.lists.linuxppc-dev |
|---|---|
| Message-ID | <[email protected]> |
On 01/07/26 2:23 pm, Christophe Leroy (CS GROUP) wrote: > > > Le 01/07/2026 à 10:09, Venkat Rao Bagalkote a écrit : >> >> On 01/07/26 10:26 am, Christophe Leroy (CS GROUP) wrote: >>> >>> >>> Le 01/07/2026 à 06:32, Venkat Rao Bagalkote a écrit : >>>> >>>> On 01/07/26 7:44 am, Madhavan Srinivasan wrote: >>>>> >>>>> On 7/1/26 12:41 AM, Paul Moore wrote: >>>>>> On Wed, May 13, 2026 at 1:42 AM Madhavan Srinivasan >>>>>> <[email protected]> wrote: >>>>>>> On 5/13/26 10:05 AM, Harsh Prateek Bora wrote: >>>>>>>> On 11/03/26 12:49 am, Paul Moore wrote: >>>>>>>>> On Tue, Mar 10, 2026 at 11:08 AM Christophe Leroy (CS GROUP) >>>>>>>>> <[email protected]> wrote: >>>>>>>>>> From: Christophe Leroy <[email protected]> >>>>>>>>>> >>>>>>>>>> Commit e65e1fc2d24b ("[PATCH] syscall class hookup for all >>>>>>>>>> normal >>>>>>>>>> targets") added generic support for AUDIT but that didn't >>>>>>>>>> include >>>>>>>>>> support for bi-arch like powerpc. >>>>>>>>>> >>>>>>>>>> Commit 4b58841149dc ("audit: Add generic compat syscall >>>>>>>>>> support") >>>>>>>>>> added generic support for bi-arch. >>>>>>>>>> >>>>>>>>>> Convert powerpc to that bi-arch generic audit support. >>>>>>>>>> >>>>>>>>>> With this change generated text is similar. >>>>>>>>>> >>>>>>>>>> Thomas has confirmed that the previously failing >>>>>>>>>> filter_exclude/test >>>>>>>>>> is now successful both without and with this patch, see [1] >>>>>>>>>> >>>>>>>>>> [1] >>>>>>>>>> https://eur01.safelinks.protection.outlook.com/? >>>>>>>>>> url=https%3A%2F%2Flore.kernel.org%2Fall%2F20260306115350- >>>>>>>>>> ef265661-6d6b-4043-9bd0-8e6b437d0d67%40linutronix.de%2F&data=05%7C02%7Cchristophe.leroy%40csgroup.eu%7C81e1e4e3bae245103d3308ded729bb47%7C8b87af7d86474dc78df45f69a2011bb5%7C0%7C0%7C639184771399964577%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=%2FtCHXFR5np67gntCnXqv7Eemo5WuwaIEcywxZQzDADA%3D&reserved=0 >>>>>>>>>> >>>>>>>>>> Link: https://eur01.safelinks.protection.outlook.com/? >>>>>>>>>> url=https%3A%2F%2Fgithub.com%2Flinuxppc%2Fissues%2Fissues%2F412&data=05%7C02%7Cchristophe.leroy%40csgroup.eu%7C81e1e4e3bae245103d3308ded729bb47%7C8b87af7d86474dc78df45f69a2011bb5%7C0%7C0%7C639184771400190794%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=4fPEX7HuGBcxOcXlcJVQvDdP7Y9InhDpbz3z%2BS9lkCQ%3D&reserved=0 >>>>>>>>>> >>>>>>>>>> Signed-off-by: Christophe Leroy <[email protected]> >>>>>>>>>> Reviewed-by: Cédric Le Goater <[email protected]> >>>>>>>>>> --- >>>>>>>>>> Venkat, a test result with >>>>>>>>>> https://eur01.safelinks.protection.outlook.com/? >>>>>>>>>> url=https%3A%2F%2Fgithub.com%2Flinux-audit%2Faudit- >>>>>>>>>> testsuite&data=05%7C02%7Cchristophe.leroy%40csgroup.eu%7C81e1e4e3bae245103d3308ded729bb47%7C8b87af7d86474dc78df45f69a2011bb5%7C0%7C0%7C639184771400214912%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yHp3p5zNx%2BqQg2cKBsKJADWcUcKVtZstzNScBfWzF%2FQ%3D&reserved=0 >>>>>>>>>> would be appreciated. >>>>>>>>> Yes, I'd like to see confirmation that the audit test suite >>>>>>>>> runs clean >>>>>>>>> on ppc systems with this patch applied, and unfortunately >>>>>>>>> without a >>>>>>>>> ppc system I have no way to test this myself. >>>>>>> My bad, this is a miss from my end. >>>>>>> Venkat is already on this and will update the results here. >>>>>> Do we have an update on this? Maybe I missed it, but I don't recall >>>>>> seeing any test results. >>>>> Venkat, did run the test but I guess he missed to respond here, >>>>> Details of his test run that he shared me in the internal chat >>>>> from May 13. >>>> >>>> >>>> Sorry, My bad. I missed updating here. Yes, this was tested in May. >>>> Please let me know, if a re-run is required? >>> >>> It looks like netcat >>> (https://eur01.safelinks.protection.outlook.com/? >>> url=https%3A%2F%2Flinux.die.net%2Fman%2F1%2Fnc&data=05%7C02%7Cchristophe.leroy%40csgroup.eu%7C97ac234e82884f729d1508ded7480f62%7C8b87af7d86474dc78df45f69a2011bb5%7C0%7C0%7C639184901648983046%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=18PJTLp9ozMqSkWWvBZmtjzjTI355Oq%2F5aqmU6zCiZE%3D&reserved=0) >>> is not installed in you setup. Are you able to install it and rerun >>> the test ? >> >> >> I investigated the failure on the RHEL 10 ppc64le test system. >> >> >> The netfilter_pkt failure is due to missing userspace dependencies: >> >> Can't exec "nc": No such file or directory >> Can't exec "iptables": No such file or directory >> Can't exec "ip6tables": No such file or directory >> >> I checked the system and confirmed that nc, ncat, iptables, and >> ip6tables are not installed: >> >> >> which nc >> which ncat >> which iptables >> which ip6tables >> >> >> all return "not found". >> >> The system has nftables installed (/usr/sbin/nft), but I was unable >> to locate packages providing nc/ncat or iptables/ip6tables in the >> currently enabled repositories (epel, rh10_base, rh10_app, rh10_crb). > > Found: > - > https://dl.fedoraproject.org/pub/epel/10/Everything/ppc64le/Packages/n/netcat-1.238-1.el10_3.ppc64le.rpm > - > https://rpmfind.net/linux/RPM/almalinux-kitten/10/baseos/ppc64le/iptables-nft-1.8.11-6.el10.ppc64le.html > - > https://www.rpmfind.net/linux/RPM/centos-stream/10/appstream/ppc64le/iptables-devel-1.8.11-14.el10.ppc64le.html > > Does it help ? > > Christophe Hi Christophe, Thanks for sharing the RPMs,they were very helpful. I reran the audit-testsuite after installing the missing userspace dependencies that were identified earlier. I installed: - netcat (nc) - iptables - ip6tables Following this, the previously failing netfilter_pkt test is now passing: netfilter_pkt/test ................... ok Current remaining issue: 1. amcast_joinpart ------------------ Still fails due to a missing Perl dependency: Can't locate Socket/Netlink.pm in @INC I searched the configured repositories and could not find a package providing Socket::Netlink / Socket/Netlink.pm on this EL10 ppc64le system. Latest run summary: amcast_joinpart/test ................. Can't locate Socket/Netlink.pm in @INC (you may need to install the Socket::Netlink module) (@INC entries checked: /usr/local/lib64/perl5/5.40 /usr/local/share/perl5/5.40 /usr/lib64/perl5/vendor_perl /usr/share/perl5/vendor_perl /usr/lib64/perl5 /usr/share/perl5 .) at amcast_joinpart/test line 10. BEGIN failed--compilation aborted at amcast_joinpart/test line 10. amcast_joinpart/test ................. Dubious, test returned 2 (wstat 512, 0x200) Failed 7/7 subtests backlog_wait_time_actual_reset/test .. ok bpf/test ............................. ok exec_execve/test ..................... ok exec_name/test ....................... ok fanotify/test ........................ ok field_compare/test ................... ok file_create/test ..................... ok file_delete/test ..................... ok file_permission/test ................. ok file_rename/test ..................... ok filter_exclude/test .................. ok filter_exit/test ..................... ok filter_saddr_fam/test ................ ok filter_sessionid/test ................ ok io_uring/test ........................ ok login_tty/test ....................... ok lost_reset/test ...................... ok netfilter_pkt/test ................... ok signal/test .......................... ok syscalls_file/test ................... ok syscall_module/test .................. ok time_change/test ..................... ok user_msg/test ........................ ok All tests now pass except amcast_joinpart, which is blocked by the missing Socket::Netlink Perl module. Please let me know if there is a recommended package source for Socket::Netlink on EL10 ppc64le. Regards, Venkat. > >> >> >> At this point, the remaining failure appears to be an environmental >> dependency issue rather than a test failure. Please let me know if >> there is a recommended package/repository for EL10 ppc64le that >> provides netcat and iptables compatibility tools, and I can re-run >> the test. >> >> >> Regards, >> >> Venkat. >> >>> >>> Thanks >>> Christophe >>> >>>> >>>> Regards, >>>> >>>> Venkat. >>>> >>>>> >>>>> backlog_wait_time_actual_reset/test .. ok >>>>> bpf/test ............................. ok >>>>> exec_execve/test ..................... ok >>>>> exec_name/test ....................... ok >>>>> fanotify/test ........................ ok >>>>> field_compare/test ................... ok >>>>> file_create/test ..................... ok >>>>> file_delete/test ..................... ok >>>>> file_permission/test ................. ok >>>>> file_rename/test ..................... ok >>>>> filter_exclude/test .................. ok >>>>> filter_exit/test ..................... ok >>>>> filter_saddr_fam/test ................ ok >>>>> filter_sessionid/test ................ ok >>>>> io_uring/test ........................ ok >>>>> login_tty/test ....................... ok >>>>> lost_reset/test ...................... ok >>>>> netfilter_pkt/test ................... Can't exec "nc": No such >>>>> file or directory at netfilter_pkt/test line 83. >>>>> >>>>> Venkat, can you please re-run if possible and paste the log here. >>>>> >>>>> Thanks >>>>> Maddy >>>>> >>>>> >>> > >