[lustre-discuss] seclabel
Dilger, Andreas
andreas.dilger at intel.com
Fri Mar 3 23:38:15 PST 2017
On Mar 2, 2017, at 05:55, Robin Humble <rjh+lustre at cita.utoronto.ca> wrote:
>
> Hiya,
>
> I'm updating an image for a root-on-lustre cluster from centos6 to 7
> and I've hit a little snag. I can't seem to mount lustre so that it
> understands seclabel. ie. setcap/getcap don't work. the upshot is that
> root can use ping (and a few other tools), but users can't.
>
> any idea what I'm doing wrong?
>
> from what little I understand about it I think seclabel is a form of
> xattr.
I try to stay away from that myself, but newer Lustre clients support SELinux
and similar things. You probably need to strace and/or collect some kernel
debug logs (maybe with debug=-1 set) to see where the error is being generated.
Cheers, Andreas
--
Andreas Dilger
Lustre Principal Architect
Intel Corporation
More information about the lustre-discuss
mailing list