[lustre-discuss] RHEL 9.8 and 10.2 support

Fokke Dijkstra f.dijkstra at rug.nl
Thu Jun 4 14:39:07 UTC 2026


Thanks for the information. It would be really helpful if there was a
clearly described way of how to construct lustre client rpms with the
patches for a newer RHEL version. That would indeed allow us to switch to a
more recent kernel if security issues require this.
Is that documentation available somewhere? As far as I can see the RHEL 9.8
patches have not been merged into the b2_15 branch. Does a 2.15.9 RC branch
exist somewhere?

Fokke

Op do 4 jun 2026 om 14:41 schreef Peter Jones <
pjones at thelustrecollective.com>:

> I acknowledge that there is a window between a new Red Hat minor version
> releasing and a fully-qualified of Lustre supporting that version being
> released.
>
> Efforts are made to keep this window as small as possible (work is done
> with beta versions when available for example), but there are usually other
> factors involved than purely RHEL updates to consider and time needs to be
> allocated for testing.
>
> Given that the work for the client support of the new RHEL version is
> publicly available ahead of the formal release being available, I would
> have thought that this would provide a suitable stopgap in the event of
> something urgent coming up.
>
> Is there something which makes this unworkable or is there just a lack of
> documentation for people to feel confident enough to attempt this?
>
> *From: *lustre-discuss <lustre-discuss-bounces at lists.lustre.org> on
> behalf of Fokke Dijkstra via lustre-discuss <
> lustre-discuss at lists.lustre.org>
> *Date: *Thursday, June 4, 2026 at 12:36 AM
> *To: *
> *Cc: *lustre-discuss at lists.lustre.org <lustre-discuss at lists.lustre.org>
> *Subject: *Re: [lustre-discuss] RHEL 9.8 and 10.2 support
>
> I would also like to stress the importance of having Lustre supporting the
> latest RedHat kernels as soon as possible. We have seen several privilege
> escalation exploits in the last month, for which we had to temporarily
> limit or disable access to our cluster to prevent somebody from using the
> exploits.
> If we would also have had to wait for a Lustre client update, before we
> could patch our services that would have been disastrous. Since the fixes
> were still released for Alma Linux 9.7 we managed to patch within a few
> days.
> If a new vulnerability were to be published now we would be in great
> trouble, as we currently cannot run Alma Linux 9.8 kernels with a working
> Lustre client. And given the frequency with which critical vulnerabilities
> have appeared I don't think we have seen the end of this.
>
> Kind regards,
>
> Fokke Dijkstra
>
>
> Op di 2 jun 2026 om 16:08 schreef Peter Jones via lustre-discuss <
> lustre-discuss at lists.lustre.org>:
>
> Georgios
>
> The plan is to finalize which the next LTS release will be - 2.17 vs 2.18
> - by the end of this month. Whatever the outcome, there will be support for
> RHEL 10.x clients.
>
> Peter
>
> *From: *lustre-discuss <lustre-discuss-bounces at lists.lustre.org> on
> behalf of Georgios Magklaras via lustre-discuss <
> lustre-discuss at lists.lustre.org>
> *Date: *Tuesday, June 2, 2026 at 4:32 AM
> *To: *lustre-discuss at lists.lustre.org <lustre-discuss at lists.lustre.org>
> *Subject: *Re: [lustre-discuss] RHEL 9.8 and 10.2 support
>
> For David: For RHEL 10.2, there are patches (including one suggestion from
> me) as part of LU 20312: https://jira.whamcloud.com/browse/LU-20312
>
> We are of course in the process of testing this.
>
> For Peter: We also echo the LTS issue. We are using primarily 2.15.x, with
> 2.16.1 at a smaller part of our production. 2.17.x is used as part of our
> test environment, because we are encountering issues with 2.16.1 . For RHEL
> 10.x, we would like to know what would be the LTS Lustre release.
>
> Best regards,
> GM
> --
> --
> --
>
> *Georgios Magklaras PhD*
> Chief Engineer
> IT Infrastructure/HPC
> The Norwegian Meteorological Institute
>
> https://www.met.no/
> https://www.steelcyber.com/georgioshome/
>
> On Tue, 2 Jun 2026 at 11:45, Hans Henrik Happe via lustre-discuss <
> lustre-discuss at lists.lustre.org> wrote:
>
> The work is tracked in LU-20071
> <https://jira.whamcloud.com/browse/LU-20071> for the RHEL 9.8 and there
> is a patch. Haven't tested it myself.
>
> You need RHEL 9.8 to get a kernel that fixes all the known root escalation
> security issues. So I agree that we are in a bit of a limbo until an RHEL
> 9.8 LTS version of Lustre is ready. However, I think Alma did a special
> security kernel for RHEL 9.7. I know Rocky did.
>
> On 01/06/2026 19.16, Peter Jones via lustre-discuss wrote:
>
> So do I understand correctly that your concern is that:
>
>
>    1. there are vulnerabilities in RHEL 10.2 that also affect RHEL 10.1
>    but there are no updates for RHEL 10.1 once RHEL 10.2 is GA
>    2. RHEL 10.x is not supported by the current Lustre LTS branch
>    (2.15.x)
>
>
> If so, the good news is that we expect to have a newly designated LTS
> branch in the near future that will support RHEL 10.x clients.
>
> Longer term, there are efforts to get Lustre into the upstream kernel,
> which would completely eliminate any of these issues.
>
> In the meantime, if you are ever in the position of wanting to move to
> kernel versions ahead of formal support being available, my recommendation
> would be to experiment with a limited number of clients (perhaps even just
> one) before rolling out across all the clients.
>
> *From: *David Cohen <cdavid at physics.technion.ac.il>
> <cdavid at physics.technion.ac.il>
> *Date: *Monday, June 1, 2026 at 8:41 AM
> *To: *Peter Jones <pjones at thelustrecollective.com>
> <pjones at thelustrecollective.com>
> *Cc: *lustre-discuss <lustre-discuss at lists.lustre.org>
> <lustre-discuss at lists.lustre.org>
> *Subject: *Re: [lustre-discuss] RHEL 9.8 and 10.2 support
>
> Hi Peter,
> For the EL 10.1 client I was using version 17.0 which was the only version
> to support EL 10. After upgrading to EL 10.2 the client lost the storage
> mount.
> I'm not updating the EL9.7 clients, not to risk losing the storage mount.
> They are running the 2.15 LTS Lustre.
> On the servers I am still using the 2.15 version on EL 8.10 as I prefer to
> use the LTS version, and there is no LTS server support beyond EL 8.10.
> This complex matrix just emphasizes how much Lustre is a
> restrictive factor for upgrades.
>
> David
>
>
> On Mon, Jun 1, 2026 at 4:48 PM Peter Jones <pjones at thelustrecollective.com>
> wrote:
>
> David
>
> Could you please clarify what version of Lustre you are using today for
> both servers and clients? Also, are you using ldiskfs or ZFS as the backend
> filesystem?
>
> Peter
>
> *From: *David Cohen <cdavid at physics.technion.ac.il>
> *Date: *Sunday, May 31, 2026 at 8:25 PM
> *To: *Peter Jones <pjones at thelustrecollective.com>
> *Cc: *lustre-discuss <lustre-discuss at lists.lustre.org>
> *Subject: *Re: [lustre-discuss] RHEL 9.8 and 10.2 support
>
> Hi Peter,
> The new kernel presented with EL 10.2 presents changes preventing DKMS
> from recompiling Lustre modules.
> There is even a Jira ticket following the issue since the beta,
> highlighting the security fixes in the new kernels.
> https://jira.whamcloud.com/browse/LU-20070
>
> David
>
>
>
> On Mon, Jun 1, 2026 at 12:19 AM Peter Jones <
> pjones at thelustrecollective.com> wrote:
>
> David
>
> Could you please elaborate as to what you feel is missing today? Lustre
> clients are patchless, so I would expect that if a security update is
> issued for a given supported release of RHEL that users would just apply
> the kernel update and weak updates would take care of the rest with no need
> to get any updates to Lustre...
>
> Peter
>
> *From: *lustre-discuss <lustre-discuss-bounces at lists.lustre.org> on
> behalf of David Cohen via lustre-discuss <lustre-discuss at lists.lustre.org>
> *Date: *Sunday, May 31, 2026 at 5:31 AM
> *To: *lustre-discuss <lustre-discuss at lists.lustre.org>
> *Subject: *[lustre-discuss] RHEL 9.8 and 10.2 support
>
> Hi,
> With the latest critical kernel vulnerabilities, updates are no longer
> optional.
> This puts Lustre on the critical path for cluster security.
> Is there a plan to address this necessity by releasing Lustre client
> versions outside of the half a year cycle to support the new kernels?
>
> David
>
>
> _______________________________________________
> lustre-discuss mailing listlustre-discuss at lists.lustre.orghttp://lists.lustre.org/listinfo.cgi/lustre-discuss-lustre.org
>
>
> _______________________________________________
> lustre-discuss mailing list
> lustre-discuss at lists.lustre.org
> http://lists.lustre.org/listinfo.cgi/lustre-discuss-lustre.org
>
>
>
>
>
> _______________________________________________
> lustre-discuss mailing list
> lustre-discuss at lists.lustre.org
> http://lists.lustre.org/listinfo.cgi/lustre-discuss-lustre.org
>
>
>
> --
> Fokke Dijkstra <f.dijkstra at rug.nl> <f.dijkstra at rug.nl>
> Team High Performance Computing
> Center for Information Technology, University of Groningen
> Postbus 11044, 9700 CA  Groningen, The Netherlands
>
>

-- 
Fokke Dijkstra <f.dijkstra at rug.nl> <f.dijkstra at rug.nl>
Team High Performance Computing
Center for Information Technology, University of Groningen
Postbus 11044, 9700 CA  Groningen, The Netherlands
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.lustre.org/pipermail/lustre-discuss_lists.lustre.org/attachments/20260604/7631ca15/attachment.html>


More information about the lustre-discuss mailing list