From fbd754c23469ff307d26f3ce3ab7511996c73812 Mon Sep 17 00:00:00 2001 From: Oyvind Albrigtsen Date: Fri, 31 Oct 2025 08:46:31 +0100 Subject: [PATCH] - nfsserver: add ability to set e.g. "pipefs-directory=/run/nfs/rpc_pipefs" in /etc/nfs.conf to avoid issues with non-clustered Kerberized mounts Resolves: RHEL-109485 --- ...port-non-clustered-kerberized-mounts.patch | 92 +++++++++++++++++++ resource-agents.spec | 10 +- 2 files changed, 101 insertions(+), 1 deletion(-) create mode 100644 RHEL-109485-nfsserver-support-non-clustered-kerberized-mounts.patch diff --git a/RHEL-109485-nfsserver-support-non-clustered-kerberized-mounts.patch b/RHEL-109485-nfsserver-support-non-clustered-kerberized-mounts.patch new file mode 100644 index 0000000..a88052d --- /dev/null +++ b/RHEL-109485-nfsserver-support-non-clustered-kerberized-mounts.patch @@ -0,0 +1,92 @@ +From a4fd26a37b20e86e7c188b45d40e31d240f3decf Mon Sep 17 00:00:00 2001 +From: Oyvind Albrigtsen +Date: Thu, 14 Aug 2025 09:33:17 +0200 +Subject: [PATCH] nfsserver: add ability to set e.g. + "pipefs-directory=/run/nfs/rpc_pipefs" in /etc/nfs.conf to avoid issues with + non-clustered Kerberized mounts + +--- + heartbeat/nfsserver | 28 +++++++++++++++++----------- + 1 file changed, 17 insertions(+), 11 deletions(-) + +diff --git a/heartbeat/nfsserver b/heartbeat/nfsserver +index 5b02924a9..83f4bac51 100755 +--- a/heartbeat/nfsserver ++++ b/heartbeat/nfsserver +@@ -264,7 +264,7 @@ set_exec_mode() + ## + # If the user defined an init script, It must exist for us to continue + ## +- if [ -n "$OCF_RESKEY_nfs_init_script" ]; then ++ if [ $systemd_running -ne 0 ] && [ -n "$OCF_RESKEY_nfs_init_script" ]; then + # check_binary will exit the process if init script does not exist + check_binary ${OCF_RESKEY_nfs_init_script} + EXEC_MODE=1 +@@ -274,7 +274,7 @@ set_exec_mode() + ## + # Check to see if the default init script exists, if so we'll use that. + ## +- if which $DEFAULT_INIT_SCRIPT > /dev/null 2>&1; then ++ if [ $systemd_running -ne 0 ] && which $DEFAULT_INIT_SCRIPT > /dev/null 2>&1; then + OCF_RESKEY_nfs_init_script=$DEFAULT_INIT_SCRIPT + EXEC_MODE=1 + return 0 +@@ -780,7 +780,7 @@ nfsserver_start () + # the uts namespace is useless in that case. + # If systemd is running, mangle the nfs-server.service unit, + # independent of the "EXEC_MODE" we detected. +- if $systemd_is_running ; then ++ if [ $systemd_running -eq 0 ]; then + if [ -z "$OCF_RESKEY_nfs_server_scope" ] ; then + remove_unshare_uts_dropins + else +@@ -789,7 +789,9 @@ nfsserver_start () + fi + + if ! `mount | grep -q " on $OCF_RESKEY_rpcpipefs_dir "`; then +- mount -t rpc_pipefs sunrpc $OCF_RESKEY_rpcpipefs_dir ++ if [ $systemd_running -ne 0 ] || { [ $systemd_running -eq 0 ] && systemctl -q is-enabled var-lib-nfs-rpc_pipefs.mount ;}; then ++ mount -t rpc_pipefs sunrpc $OCF_RESKEY_rpcpipefs_dir ++ fi + fi + + # remove the sm-notify pid so sm-notify will be allowed to run again without requiring a reboot. +@@ -1003,11 +1005,15 @@ nfsserver_stop () + fi + fi + +- # systemd +- case $EXEC_MODE in +- [23]) nfs_exec stop rpc-gssd > /dev/null 2>&1 +- ocf_log info "Stop: rpc-gssd" +- esac ++ ++ if mount | grep -q " on $OCF_RESKEY_rpcpipefs_dir "; then ++ # systemd ++ case $EXEC_MODE in ++ [23]) ++ nfs_exec stop rpc-gssd > /dev/null 2>&1 ++ ocf_log info "Stop: rpc-gssd" ++ esac ++ fi + + unbind_tree + rc=$? +@@ -1017,7 +1023,7 @@ nfsserver_stop () + ocf_log info "NFS server stopped" + fi + +- if $systemd_is_running; then ++ if [ $systemd_running -eq 0 ]; then + remove_unshare_uts_dropins + fi + +@@ -1057,7 +1063,7 @@ nfsserver_validate () + } + + nfsserver_validate +-systemd_is_running && systemd_is_running=true || systemd_is_running=false ++systemd_is_running; systemd_running=$? + + case $__OCF_ACTION in + start) nfsserver_start diff --git a/resource-agents.spec b/resource-agents.spec index 8623c30..65eb0c9 100644 --- a/resource-agents.spec +++ b/resource-agents.spec @@ -45,7 +45,7 @@ Name: resource-agents Summary: Open Source HA Reusable Cluster Resource Scripts Version: 4.10.0 -Release: 92%{?rcver:%{rcver}}%{?numcomm:.%{numcomm}}%{?alphatag:.%{alphatag}}%{?dirty:.%{dirty}}%{?dist} +Release: 93%{?rcver:%{rcver}}%{?numcomm:.%{numcomm}}%{?alphatag:.%{alphatag}}%{?dirty:.%{dirty}}%{?dist} License: GPLv2+ and LGPLv2+ URL: https://github.com/ClusterLabs/resource-agents Source0: %{upstream_prefix}-%{upstream_version}.tar.gz @@ -181,6 +181,7 @@ Patch128: RHEL-123906-podman-etcd-compute-dynamic-revision-bump-from-maxRaftInde Patch129: RHEL-115785-RHEL-115782-2-db2-fix-variable-name.patch Patch130: RHEL-118621-MailTo-add-s-nail-support-for-multiple-recipients.patch Patch131: RHEL-64949-oracle-improve-monpassword-description.patch +Patch132: RHEL-109485-nfsserver-support-non-clustered-kerberized-mounts.patch # bundled ha-cloud-support libs Patch500: ha-cloud-support-aliyun.patch @@ -457,6 +458,7 @@ exit 1 %patch -p1 -P 129 %patch -p1 -P 130 %patch -p1 -P 131 +%patch -p1 -P 132 # bundled ha-cloud-support libs %patch -p1 -P 500 @@ -789,6 +791,12 @@ rm -rf %{buildroot}/usr/share/doc/resource-agents %{_usr}/lib/ocf/lib/heartbeat/OCF_*.pm %changelog +* Fri Oct 31 2025 Oyvind Albrigtsen - 4.10.0-93 +- nfsserver: add ability to set e.g. "pipefs-directory=/run/nfs/rpc_pipefs" + in /etc/nfs.conf to avoid issues with non-clustered Kerberized mounts + + Resolves: RHEL-109485 + * Wed Oct 29 2025 Oyvind Albrigtsen - 4.10.0-92 - MailTo: add s-nail support for multiple recipients - oracle: improve monpassword description