Skip to content

[devscripts] Patch OpenSSL FIPS package conflict for RHEL 9.4 - #4212

Open
dsariel wants to merge 1 commit into
openstack-k8s-operators:mainfrom
dsariel:devscripts_openssl_patch
Open

dsariel wants to merge 1 commit into
openstack-k8s-operators:mainfrom
dsariel:devscripts_openssl_patch

Conversation

@dsariel

@dsariel dsariel commented Sep 29, 2026 •

Copy link
Copy Markdown

Dev-scripts commit openshift-metal3/dev-scripts@cda6a0f ("Revert openssl version hacks") removed OpenSSL workarounds assuming fixes were available in CentOS Stream 9. However, RHEL 9.4 repositories still contain openssl-fips-provider-so which conflicts with openssl-libs during package operations.

This causes failures in 01_install_requirements.sh:

file /usr/lib64/ossl-modules/fips.so from install of
openssl-libs-1:3.0.7-6.el9_2.x86_64 conflicts with file from
package openssl-fips-provider-so-3.0.7-11.el9_0.x86_64

Affected jobs: uni04delta-ipv6-rhel9-rhoso18.0 and similar RHEL 9-based jobs.

Re-add the OpenSSL workaround via ci-framework patching of dev-scripts 01_install_requirements.sh. The patch removes openssl-fips-provider-so before dev-scripts attempts package installations.

This patch should be removed when any of the following occurs:

  1. Dev-scripts adds RHEL-specific handling for this conflict upstream
  2. RHEL 9.5+ repositories no longer ship the conflicting package
  3. The dev-scripts version pinned in cifmw_devscripts_repo_branch includes a fix for this issue

openshift-metal3/dev-scripts#1973

OSPCIX-1520

@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@openshift-ci

openshift-ci Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign yorabl for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/0c3d112415ef43db926d6d4fbb91900c

✔️ openstack-k8s-operators-content-provider SUCCESS in 3h 18m 59s
❌ podified-multinode-edpm-deployment-crc FAILURE in 19m 31s
✔️ podified-multinode-edpm-deployment-crc-centos-10 SUCCESS in 1h 28m 03s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 35m 06s
✔️ cifmw-pod-zuul-files SUCCESS in 4m 18s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 19s
✔️ cifmw-pod-pre-commit SUCCESS in 7m 53s
✔️ cifmw-molecule-devscripts SUCCESS in 12m 57s

@dsariel
dsariel force-pushed the devscripts_openssl_patch branch 2 times, most recently from 41693ca to b2f0400 Compare September 29, 2026 13:41
Dev-scripts commit openshift-metal3/dev-scripts@cda6a0f
("Revert openssl version hacks") removed OpenSSL workarounds assuming fixes
were available in CentOS Stream 9. However, RHEL 9.4 repositories still contain
`openssl-fips-provider-so` which conflicts with `openssl-libs` during package
operations.

This causes failures in `01_install_requirements.sh`:
```
file /usr/lib64/ossl-modules/fips.so from install of
openssl-libs-1:3.0.7-6.el9_2.x86_64 conflicts with file from
package openssl-fips-provider-so-3.0.7-11.el9_0.x86_64
```

Affected jobs: uni04delta-ipv6-rhel9-rhoso18.0 and similar RHEL 9-based jobs.

Re-add the OpenSSL workaround via ci-framework patching of dev-scripts
`01_install_requirements.sh`. The patch removes `openssl-fips-provider-so`
before dev-scripts attempts package installations.

This patch should be removed when **any** of the following occurs:

1. Dev-scripts adds RHEL-specific handling for this conflict upstream
2. RHEL 9.5+ repositories no longer ship the conflicting package
3. The dev-scripts version pinned in `cifmw_devscripts_repo_branch` includes
   a fix for this issue

openshift-metal3/dev-scripts#1973

OSPCIX-1520

Signed-off-by: David Sariel <dsariel@redhat.com>
@dsariel
dsariel force-pushed the devscripts_openssl_patch branch from b2f0400 to cc7128e Compare September 29, 2026 15:51
@tosky

tosky commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Wasn't this workaround not needed anymore with the recent version of ci-framework?

@centosinfra-prod-github-app

Copy link
Copy Markdown

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://gateway-cloud-softwarefactory.apps.ocp.cloud.ci.centos.org/zuul/t/rdoproject.org/buildset/073ac859958a44449aa6deb1f9ab98f3

❌ openstack-k8s-operators-content-provider FAILURE in 5m 51s
⚠️ podified-multinode-edpm-deployment-crc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ podified-multinode-edpm-deployment-crc-centos-10 SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
✔️ cifmw-pod-zuul-files SUCCESS in 4m 23s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 18s
✔️ cifmw-pod-pre-commit SUCCESS in 8m 01s
✔️ cifmw-molecule-devscripts SUCCESS in 10m 24s

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants