Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #265695 > unrolled thread
| Started by | Jan Ingvoldstad <frettled@gmail.com> |
|---|---|
| First post | 2024-01-09 07:50 +0100 |
| Last post | 2024-01-13 09:10 +0100 |
| Articles | 9 — 5 participants |
Back to article view | Back to linux.debian.user
Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug Jan Ingvoldstad <frettled@gmail.com> - 2024-01-09 07:50 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug "Gareth Evans" <donotspam@fastmail.fm> - 2024-01-10 18:50 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug Xiyue Deng <manphiz@gmail.com> - 2024-01-10 20:30 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug Махно <mindaugasceliesius@gmail.com> - 2024-01-11 14:30 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug Jan Ingvoldstad <frettled@gmail.com> - 2024-01-12 08:00 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug Махно <mindaugasceliesius@gmail.com> - 2024-01-12 14:10 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug "Gareth Evans" <donotspam@fastmail.fm> - 2024-01-13 03:40 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug "Gareth Evans" <donotspam@fastmail.fm> - 2024-01-13 03:50 +0100
Re: Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug Jeffrey Walton <noloader@gmail.com> - 2024-01-13 09:10 +0100
| From | Jan Ingvoldstad <frettled@gmail.com> |
|---|---|
| Date | 2024-01-09 07:50 +0100 |
| Subject | Bookworm and ZFS (zfs-dkms 2.1.11) data corruption bug |
| Message-ID | <HUe5Y-1QaH-3@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Hi, It seems that Bookworm's zfs-dkms package (from contrib) has the data corruption bug that was fixed with OpenZFS 2.1.14 (and 2.2.2) on 2023-11-30. https://github.com/openzfs/zfs/releases/tag/zfs-2.1.14 However, I see no relevant bug report in the bug tracker - have my searching skills failed? -- Jan
[toc] | [next] | [standalone]
| From | "Gareth Evans" <donotspam@fastmail.fm> |
|---|---|
| Date | 2024-01-10 18:50 +0100 |
| Message-ID | <HUKSd-2aIZ-11@gated-at.bofh.it> |
| In reply to | #265695 |
> On 9 Jan 2024, at 06:41, Jan Ingvoldstad <frettled@gmail.com> wrote: > > Hi, > > It seems that Bookworm's zfs-dkms package (from contrib) has the data corruption bug that was fixed with OpenZFS 2.1.14 (and 2.2.2) on 2023-11-30. > > https://github.com/openzfs/zfs/releases/tag/zfs-2.1.14 > > However, I see no relevant bug report in the bug tracker - have my searching skills failed? > > -- > Jan This prompted me to look for updates. 2.2.2-3 is available in bookworm-backports. Is this, or a later version, likely to be made available in bookworm-updates? Does anyone have experience with the backports version? Thanks Gareth
[toc] | [prev] | [next] | [standalone]
| From | Xiyue Deng <manphiz@gmail.com> |
|---|---|
| Date | 2024-01-10 20:30 +0100 |
| Message-ID | <HUMr0-2bLR-5@gated-at.bofh.it> |
| In reply to | #265695 |
Jan Ingvoldstad <frettled@gmail.com> writes: > Hi, > > It seems that Bookworm's zfs-dkms package (from contrib) has the data > corruption bug that was fixed with OpenZFS 2.1.14 (and 2.2.2) on 2023-11-30. > > https://github.com/openzfs/zfs/releases/tag/zfs-2.1.14 > > However, I see no relevant bug report in the bug tracker - have my > searching skills failed? You can check the developer page of zfs-linux[1] on which the "action needed" section has information about security issues (along with version info as Gareth posted). The one you mentioned was being tracked in [2] and the corresponding Debian bug is [3]. My guess is that as zfs-linux is not in "main" but "contrib", and the issue is marked "no-dsa" (see [4]), there may be no urgency to provide a stable update. But you may send a follow up in the tracking bug and ask for clarification from the maintainers on whether an (old)stable-update is desired. [1] https://tracker.debian.org/pkg/zfs-linux [2] https://security-tracker.debian.org/tracker/CVE-2023-49298 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056752 [4] https://security-team.debian.org/security_tracker.html#issues-not-warranting-a-security-advisory -- Xiyue Deng
[toc] | [prev] | [next] | [standalone]
| From | Махно <mindaugasceliesius@gmail.com> |
|---|---|
| Date | 2024-01-11 14:30 +0100 |
| Message-ID | <HV3i9-2mFz-1@gated-at.bofh.it> |
| In reply to | #265754 |
It is recommended by Debian ZFS on Linux Team to install ZFS related packages from Backports archive. Upstream stable patches will be tracked and compatibility is always maintained. 2024-01-11, kt, 02:08 Xiyue Deng <manphiz@gmail.com> rašė: > > Jan Ingvoldstad <frettled@gmail.com> writes: > > > Hi, > > > > It seems that Bookworm's zfs-dkms package (from contrib) has the data > > corruption bug that was fixed with OpenZFS 2.1.14 (and 2.2.2) on 2023-11-30. > > > > https://github.com/openzfs/zfs/releases/tag/zfs-2.1.14 > > > > However, I see no relevant bug report in the bug tracker - have my > > searching skills failed? > > You can check the developer page of zfs-linux[1] on which the "action > needed" section has information about security issues (along with > version info as Gareth posted). The one you mentioned was being tracked > in [2] and the corresponding Debian bug is [3]. My guess is that as > zfs-linux is not in "main" but "contrib", and the issue is marked > "no-dsa" (see [4]), there may be no urgency to provide a stable update. > But you may send a follow up in the tracking bug and ask for > clarification from the maintainers on whether an (old)stable-update is > desired. > > [1] https://tracker.debian.org/pkg/zfs-linux > [2] https://security-tracker.debian.org/tracker/CVE-2023-49298 > [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1056752 > [4] https://security-team.debian.org/security_tracker.html#issues-not-warranting-a-security-advisory > > -- > Xiyue Deng >
[toc] | [prev] | [next] | [standalone]
| From | Jan Ingvoldstad <frettled@gmail.com> |
|---|---|
| Date | 2024-01-12 08:00 +0100 |
| Message-ID | <HVjGh-2wzY-1@gated-at.bofh.it> |
| In reply to | #265754 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Jan 10, 2024 at 10:48 PM Xiyue Deng <manphiz@gmail.com> wrote: > > You can check the developer page of zfs-linux[1] on which the "action > needed" section has information about security issues (along with > version info as Gareth posted). The one you mentioned was being tracked > in [2] and the corresponding Debian bug is [3]. My guess is that as > zfs-linux is not in "main" but "contrib", and the issue is marked > "no-dsa" (see [4]), there may be no urgency to provide a stable update. > But you may send a follow up in the tracking bug and ask for > clarification from the maintainers on whether an (old)stable-update is > desired. > Thanks, so it *was* my searching skills that failed me: "The fix will land in bookworm-backports and bullseye-backports-sloppy shortly after 2.1.14-1 migrates to testing, which will take about 2 days hopefully. Fixes to 2.0.3-9+deb11u1 (bullseye) and 2.1.11-1 (bookworm) are planned but will likely take more time." I think the bug is mislabeled as "security" and "important", as this is primarily a severe data corruption bug, but with *possible* security implications. It is far more concerning that one cannot trust that cp actually copies a file, and this is a blocker for installing the ZFS packages in Debian. -- Jan
[toc] | [prev] | [next] | [standalone]
| From | Махно <mindaugasceliesius@gmail.com> |
|---|---|
| Date | 2024-01-12 14:10 +0100 |
| Message-ID | <HVpsl-2Aou-3@gated-at.bofh.it> |
| In reply to | #265815 |
>I have not seen this recommendation, do you have a link? It is from Debian wiki https://wiki.debian.org/ZFS 2024-01-12, pn, 14:08 Jan Ingvoldstad <frettled@gmail.com> rašė: > > > On Wed, Jan 10, 2024 at 10:48 PM Xiyue Deng <manphiz@gmail.com> wrote: >> >> >> You can check the developer page of zfs-linux[1] on which the "action >> needed" section has information about security issues (along with >> version info as Gareth posted). The one you mentioned was being tracked >> in [2] and the corresponding Debian bug is [3]. My guess is that as >> zfs-linux is not in "main" but "contrib", and the issue is marked >> "no-dsa" (see [4]), there may be no urgency to provide a stable update. >> But you may send a follow up in the tracking bug and ask for >> clarification from the maintainers on whether an (old)stable-update is >> desired. > > > Thanks, so it *was* my searching skills that failed me: > > "The fix will land in bookworm-backports and bullseye-backports-sloppy > shortly after 2.1.14-1 migrates to testing, which will take about 2 > days hopefully. Fixes to 2.0.3-9+deb11u1 (bullseye) and 2.1.11-1 > (bookworm) are planned but will likely take more time." > > I think the bug is mislabeled as "security" and "important", as this is primarily a severe data corruption bug, but with *possible* security implications. > > It is far more concerning that one cannot trust that cp actually copies a file, and this is a blocker for installing the ZFS packages in Debian. > > -- > Jan
[toc] | [prev] | [next] | [standalone]
| From | "Gareth Evans" <donotspam@fastmail.fm> |
|---|---|
| Date | 2024-01-13 03:40 +0100 |
| Message-ID | <HVC6d-2HPr-1@gated-at.bofh.it> |
| In reply to | #265815 |
On Fri 12/01/2024 at 06:49, Jan Ingvoldstad <frettled@gmail.com> wrote:
> ...
> It is far more concerning that one cannot trust that cp actually copies a file, and this is a blocker for installing the ZFS packages in Debian.
The update in bookworm-backports to 2.2.2-3 allegedly fixes this issue.
I have installed it and at least rebooted :)
I have had ZFS on root since Buster, and have upgraded to each new stable release since then.
I had wondered recently if the Debian wiki's recommendation [1] of installing from "stable-backports", and the statement that
"Upstream stable patches will be tracked and compatibility is always maintained"
was to suggest use of the actual "stable-backports" repo, and that the compatibility guarantee meant that they cater for any potential ZFS issues arising for non-upgraded systems after new release time. On closer inspection, the line the wiki provides to add this to sources.list actually adds the codename-backports repo (currently "bookworm-backports"). "stable-backports" also appears to be an alias that apt understands as referring to {codename}-backports for whatever current stable is, and use of the actual "stable-backports" repo is not recommended or implied.
Is the Debian wiki advice re installing ZFS from backports applicable in all circumstances? What would be the suggested approach for installing with ZFS on root or re-pointing apt at backports for ZFS immediately after [upgrading to] a new stable release? Do backports even exist at that point? If so, after a release upgrade, can you install the same version of eg. zfs-dkms from backports as a sort of special case for the purposes of changing the repo? Or do you just have to watch and wait for new ZFS backports?
OpenZFS instructions [2] for root on ZFS suggest using bookworm not bookworm-backports, so I wondered if an initial lack of backports might be the reason.
Thanks,
Gareth
[1] https://wiki.debian.org/ZFS#Status
[2] https://openzfs.github.io/openzfs-docs/Getting%20Started/Debian/Debian%20Bookworm%20Root%20on%20ZFS.html#step-1-prepare-the-install-environment
[toc] | [prev] | [next] | [standalone]
| From | "Gareth Evans" <donotspam@fastmail.fm> |
|---|---|
| Date | 2024-01-13 03:50 +0100 |
| Message-ID | <HVCfT-2HSR-3@gated-at.bofh.it> |
| In reply to | #265861 |
On Sat 13/01/2024 at 02:32, Gareth Evans <donotspam@fastmail.fm> wrote: > use of the actual "stable-backports" repo is not > recommended or implied. "implied" might be debatable given that was indeed my first thought, but not intended to be implied, it seems. Certainly not necessary.
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-01-13 09:10 +0100 |
| Message-ID | <HVHfz-2LfM-5@gated-at.bofh.it> |
| In reply to | #265815 |
On Fri, Jan 12, 2024 at 8:18 AM Jan Ingvoldstad <frettled@gmail.com> wrote: > > On Wed, Jan 10, 2024 at 10:48 PM Xiyue Deng <manphiz@gmail.com> wrote: >> >> You can check the developer page of zfs-linux[1] on which the "action >> needed" section has information about security issues (along with >> version info as Gareth posted). The one you mentioned was being tracked >> in [2] and the corresponding Debian bug is [3]. My guess is that as >> zfs-linux is not in "main" but "contrib", and the issue is marked >> "no-dsa" (see [4]), there may be no urgency to provide a stable update. >> But you may send a follow up in the tracking bug and ask for >> clarification from the maintainers on whether an (old)stable-update is >> desired. > > Thanks, so it *was* my searching skills that failed me: > > "The fix will land in bookworm-backports and bullseye-backports-sloppy > shortly after 2.1.14-1 migrates to testing, which will take about 2 > days hopefully. Fixes to 2.0.3-9+deb11u1 (bullseye) and 2.1.11-1 > (bookworm) are planned but will likely take more time." > > I think the bug is mislabeled as "security" and "important", as this is primarily a severe data corruption bug, but with *possible* security implications. > > It is far more concerning that one cannot trust that cp actually copies a file, and this is a blocker for installing the ZFS packages in Debian. Using cp with sparse files has a long history of problems. Recently this showed up: bug#61386: [PATCH] cp,mv,install: Disable sparse copy on macOS, <https://lists.nongnu.org/archive/html/bug-coreutils/2023-02/msg00010.html>. I seem to recall the problem was a little bigger than just macOS. It affected other OSes, too. While it was propagated through coreutils, I believe the underlying problem was Gnulib. The ZFS issue looks to be similar, if I am parsing things correctly: GH #11900: SEEK_DATA fails randomly, <https://github.com/openzfs/zfs/issues/11900>. Jeff
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web