[lustre-discuss] seclabel

Dilger, Andreas andreas.dilger at intel.com
Fri Mar 3 23:38:15 PST 2017


On Mar 2, 2017, at 05:55, Robin Humble <rjh+lustre at cita.utoronto.ca> wrote:
> 
> Hiya,
> 
> I'm updating an image for a root-on-lustre cluster from centos6 to 7
> and I've hit a little snag. I can't seem to mount lustre so that it
> understands seclabel. ie. setcap/getcap don't work. the upshot is that
> root can use ping (and a few other tools), but users can't.
> 
> any idea what I'm doing wrong?
> 
> from what little I understand about it I think seclabel is a form of
> xattr.

I try to stay away from that myself, but newer Lustre clients support SELinux
and similar things.  You probably need to strace and/or collect some kernel
debug logs (maybe with debug=-1 set) to see where the error is being generated.

Cheers, Andreas
--
Andreas Dilger
Lustre Principal Architect
Intel Corporation









More information about the lustre-discuss mailing list