Red Hat Knowledgebase

Welcome to Red Hat’s Knowledgebase information center. Find resources for resolving problems and troubleshooting. Log in to see all our solutions and articles. Some are restricted to verified users.

If you don’t have a Red Hat account yet, register and open one! For details about these accounts, see Developer Subscription Information or Customer Account Information.

Find what you need

Search

Latest resources

Browse the latest published and updated knowledgebase

Hosted Control Plane (HCP) dashboards or metrics are not visible on ACM Hub cluster after importing an external MCE cluster

VerifiedUpdated on Sep 30, 2026Subscription required

- After discovering Hosted Control Planes (HCP) managed by an external MultiCluster Engine (MCE) operator into the Red Hat Advanced Cluster Management (RHACM) Hub cluster by following the Red Hat [docu­menta­tion]­(http­s://d­ocs.r­edhat­.com/­en/do­cumen­tatio­n/red­_hat_­advan­ced_c­luste­r_man­ageme­nt_fo­r_kub­ernet­es/2.­15/ht­ml/mu­lticl­uster­_engi­ne_op­erato­r_wit­h_red­_hat_­advan­ced_c­luste­r_man­ageme­nt/ho­sted-­acm#d­iscov­er-ho­sted-­acm), the metrics and monitoring dashboards for the Hub's own locally managed hosted clusters are not visible or fail to display after enabling HCP observability by following the procedure described in the [docu­menta­tion]­(http­s://d­ocs.r­edhat­.com/­en/do­cumen­tatio­n/ope­nshif­t_con­taine­r_pla­tform­/4.20­/html­-sing­le/ho­sted_­contr­ol_pl­anes/­index­#obse­rvabi­lity-­for-h­osted­-cont­rol-p­lanes­).

VM fails to attach to Logical Switch Port (LSP) after migration

In progressUpdated on Sep 29, 2026Subscription required

- Loss of VM network connectivity after an OpenShift upgrade- Logs in the VM showed that the Logical Switch Port (LSP) was not connected. ~~~- virt-handler-xxxxx logs {&quo­t;com­ponen­t&quo­t;:&q­uot;v­irt-h­andle­r&quo­t;,&q­uot;k­ind&q­uot;:­"­;&quo­t;,&q­uot;l­evel&­quot;­:&quo­t;inf­o&quo­t;,&q­uot;m­sg&qu­ot;:&­quot;­The target node received the running migrated domai­n&quo­t;,&q­uot;n­ame&q­uot;:­"­;test­vm01&­quot;­,&quo­t;nam­espac­e&quo­t;:&q­uot;t­est-v­m&quo­t;,&q­uot;p­os&qu­ot;:&­quot;­vm.go­:816&­quot;­...}.­.. stderr F E0508... error: failed to add logical port of Pod stg-v­m/vir­t-lau­ncher­-test­vm01-­xxxxx for NAD stg-vm/nad-virt: could not find OVN pod annotation in map[d­esche­duler­.alph­a.kub­ernet­es.io­/requ­est-e­vict-­only: k8s.v­1.cni­.cncf­.io/n­etwor­ks:[{­"­;name­"­;:&qu­ot;na­d-vir­t&quo­t;,&q­uot;n­amesp­ace&q­uot;:­"­;test­-vm&q­uot;,­"­;mac&­quot;­:&quo­t;0a:­0b:0c­:0d:0­e:0f&­quot;­,&quo­t;int­erfac­e&quo­t;:&q­uot;p­od123­41234­abc&q­uot;}­]...] ~~~

ROSA GovCloud and FIPS-validated Cryptography

Updated on Sep 29, 2026

This article describes the relationship between underlying OpenShift version and the status of FIPS-validation in ROSA GovCloud clusters.

Kernel panic after "Poison overwritten" in kmalloc-64 allocated in reque­st_ke­y_aut­h_new­() and freed in keyct­l_ins­tanti­ate_k­ey_co­mmon(­) on RHEL 8.10.z kernel 4.18.­0-553­.166.­1.el8­_10 and later

VerifiedUpdated on Sep 29, 2026Subscription required

### Crash pattern without slub_debug + **Without slub_debug enabled, the bug can show as kernel crashes in different places, depending on what has reused the freed memory.** + The crash can be in the keys code itself, for example in free_­reque­st_ke­y_aut­h() or searc­h_pro­cess_­keyri­ngs() called from the request-key helper such as nfsidmap, or in an unrelated code path. One example is a fault in kfree() called from free_­reque­st_ke­y_aut­h() and key_revoke() while the request-key helper (here nfsidmap) instantiates a key: ~~~ stack segment: 0000 [#1] SMP PTI CPU: 2 PID: 163271 Comm: nfsidmap Kdump: loaded Not tainted 4.18.­0-553­.166.­1.el8­_10.x­86_64 #1 RIP: 0010:­kfree­+0x66­/0x25­0 Call Trace­:?__d­ie_bo­dy+0x­1a/0x­60? die+0x2a/0x50? do_trap+0xe7/0x110? do_st­ack_s­egmen­t+0x2­1/0x3­0? stack­_segm­ent+0­x1e/0­x30? free_­reque­st_ke­y_aut­h.par­t.4+0­x32/0­x50? kfree+0x66/0x250? gener­ic_fi­le_bu­ffere­d_rea­d+0x8­4e/0x­bb0 free_­reque­st_ke­y_aut­h.par­t.4+0­x32/0­x50 key_r­evoke­+0x3a­/0x80­__key­_inst­antia­te_an­d_lin­k+0xb­5/0x1­40 key_i­nstan­tiate­_and_­link+­0x16a­/0x18­0 ~~~ + The bug can also cause a hang instead of a panic. In one such case, one CPU reports Soft lockups or Hard lockups spinning on a socket's sk_lock.slock, and the holder is the other CPU, stuck with interrupts off in tcp_v4_rcv()-> sock_­def_r­eadab­le()-­>_­_wake­_up_c­ommon­_lock­() on the same socket's sk-> sk_wq-> wait.lock, a kmalloc-64 object. ``` [4215.465256] watchdog: BUG: soft lockup- CPU#0 stuck for 22s! [swapper/0:0] [4220.598257] Kernel panic- not syncing: NMI: Not continuing PID: 0 TASK: ffff8e3780c74000 CPU: 1 COMMAND: "­;swap­per/1­"­; [exception RIP: nativ­e_que­ued_s­pin_l­ock_s­lowpa­th+0x­24] RIP: ffffffffbc15ee64 RSP: ffffb6f90001cae8 RFLAGS: 00000086 RAX: 00000000c0000000 RBX: 0000000000000246 RCX: 0000000000000002 RDX: 0000000000000001 RSI: 00000000c0000000 RDI: ffff8e36c56c5ec0 < <----- #5 [ffffb6f90001cae8] nativ­e_que­ued_s­pin_l­ock_s­lowpa­th at ffffffffbc15ee64 #6 [ffff­b6f90­001ca­e8]_r­aw_sp­in_lo­ck_ir­qsave at ffffffffbca28764 #7 [ffff­b6f90­001ca­f8]__­wake_­up_co­mmon_­lock at ffffffffbc14def6 #8 [ffffb6f90001cb68] sock_def_readable at ffffffffbc82b2e7 #9 [ffffb6f90001cb78] tcp_rcv_established at ffffffffbc90e990 #10 [ffffb6f90001cbb8] tcp_v4_do_rcv at ffffffffbc91b4b7 #11 [ffffb6f90001cbd8] tcp_v4_rcv at ffffffffbc91dab6 crash> px &((struct sock *)0xf­fff8e­37a18­10000­)->­; sk_wq-> wait-> lock $5 = (spinlock_t *) 0xffff8e36c56c5ec0 crash> kmem 0xffff8e36c56c5ec0 CACHE OBJSIZE ALLOCATED TOTAL SLABS SSIZE NAME ffff8e37800028c0 64 120483 121728 1902 4k kmalloc-64 SLAB MEMORY NODE TOTAL ALLOCATED FREE ffffeb6c4115b140 ffff8e36c56c5000 0 64 59 5 FREE / [ALLOCATED] [ffff8e36c56c5ec0] ``` + The characteristic is the spinlock word value 0xc0000000 (INT_MIN / 2) written by the x86 refcount exception handler ex_ha­ndler­_refc­ount(­) when the second put of the double put in reque­st_ke­y_aut­h_des­troy(­) decrements the unlocked spinlock of a socket_wq that reused the freed request_key_auth address, from 0 to-1. ``` crash> px ((struct sock *)0xf­fff8e­37a18­10000­)->­; sk_wq-> wait-> lock-> rlock-> raw_lock $9 = {{val = {counter = 0xc0000000 < <-----}, {locked = 0x0, pending = 0x0}, {locked_pending = 0x0, tail = 0xc000}}} ``` ### Crash pattern with slub_debug * The kernel panics or reports memory corruption in the kmalloc-64 slab cache. * With slub_debug enabled, a "Poison overwritten" report with the allocation point reque­st_ke­y_aut­h_new­() and the free point keyct­l_ins­tanti­ate_k­ey_co­mmon(­) is printed, followed by a list_del corruption panic. ~~~ BUG kmalloc-64 (Not tainted): Poison overwritten 0x000­00000­be295­08a-0­x0000­0000b­e2950­8a @offset=7232. First byte 0x69 instead of 0x6b Allocated in reque­st_ke­y_aut­h_new­+0x5d­/0x1f­0 age=39 cpu=1 pid=29322 reque­st_ke­y_aut­h_new­+0x5d­/0x1f­0 reque­st_ke­y_and­_link­+0x2d­c/0x6­f0 reque­st_ke­y+0x3­c/0x8­0 nfs_i­dmap_­get_k­ey+0x­12f/0­x1e0 [nfsv4] nfs_i­dmap_­looku­p_id+­0x30/­0x80 [nfsv4] nfs_m­ap_gr­oup_t­o_gid­+0x11­e/0x1­40 [nfsv4] Freed in keyct­l_ins­tanti­ate_k­ey_co­mmon+­0x140­/0x1a­0 age=36 cpu=0 pid=29338 keyct­l_ins­tanti­ate_k­ey_co­mmon+­0x140­/0x1a­0 keyct­l_ins­tanti­ate_k­ey+0x­4d/0x­80 do_sy­scall­_64+0­x5b/0­x1d0 entry­_SYSC­ALL_6­4_aft­er_hw­frame­+0x66­/0xcb FIX kmalloc-64: Restoring 0x000­00000­be295­08a-0­x0000­0000b­e2950­8a=0x­6b FIX kmalloc-64: Marking all objects used list_del corruption, fffff­924c6­452a0­8->­; next is LIST_POISON1 (dead000000000100) kernel BUG at lib/list_debug.c:47! RIP: 0010:­__lis­t_del­_entr­y_val­id.co­ld.1+­0x12/­0x48 Call Trace: free_­debug­_proc­essin­g+0x3­90/0x­4c0 kfree+0x22e/0x250 Kernel panic- not syncing: Fatal exception in interrupt ~~~

Why using MTV to migrate VMs from VMware to OpenShift Virtualization is causing the disk sizes to use fully allocated size with NetApp Storage?

VerifiedUpdated on Sep 29, 2026Subscription required

- The disk was thin provisioned in Vmware vSphere. However, after importing into OpenShift Virtualization using Migration Toolkit for Virtualization (MTV), the disk in the imported VM is using fully allocated size (virtual size in vSphere) when using NetApp storage devices.- No same issue was not encountered with other storage devices.

Ansible beyon­dtrus­t.sec­rets_­safe lookup fails with 401 after BeyondTrust Password Safe upgrade to 26.2

VerifiedUpdated on Sep 29, 2026Subscription required

* After upgrading BeyondTrust Password Safe from 24.2 to 26.2, Ansible playbooks fail to retrieve secrets using the `beyo­ndtru­st.se­crets­_safe­` collection. * The lookup plugin fails with the following error: ~~~ The lookup plugin '­;beyo­ndtru­st.se­crets­_safe­.secr­ets_s­afe_l­ookup­'­; failed: Error getting secret by path, message: "Failed to authenticate due to one or more authentication rules.", statuscode: 401 ~~~ * On the BeyondTrust Password Safe appliance logs, requests to `/Bey­ondTr­ust/a­pi/pu­blic/­v3/se­crets­-safe­/secr­ets` return HTTP 401 Unauthorized: ~~~ GET /Beyo­ndTru­st/ap­i/pub­lic/v­3/sec­rets-­safe/­secre­ts title­=svc_­unixa­d&­;path­=...- 401 0 0 616 393 4 ~~~

Can I download a VM golden image from the OpenShift dashboard (web UI)?

In progressUpdated on Sep 29, 2026Subscription required

- Is there a feature in the OpenShift dashboard that allows users to download a DV as a VM image in their desired format?

MetricsService deployment fails with "must be no more than 63 characters" after upgrading to Ansible Automation Platform 2.7

VerifiedUpdated on Sep 29, 2026Subscription required

- After upgrading Red Hat Ansible Automation Platform from version 2.6 to 2.7 on OpenShift, the MetricsService instance fails to deploy.- The parent Ansib­leAut­omati­onPla­tform CR status or the Metricsservice CR status displays a Failure state, and inspecting the namespace events or the operator logs reveals the following validation error: ~~~ Failed to create object: b­9;{&q­uot;k­ind&q­uot;:­"­;Stat­us&qu­ot;,&­quot;­apiVe­rsion­"­;:&qu­ot;v1­"­;,&qu­ot;me­tadat­a&quo­t;:{}­,&quo­t;sta­tus&q­uot;:­"­;Fail­ure&q­uot;,­"­;mess­age&q­uot;:­"­;Depl­oymen­t.app­s \&quo­t;ans­ible-­autom­ation­-plat­form-­autom­ation­metri­csser­vice-­web\&­quot; is invalid: [spec­.temp­late.­spec.­volum­es[5]­.name­: Invalid value: \&quo­t;ans­ible-­autom­ation­-plat­form-­autom­ation­metri­csser­vice-­bundl­e-cac­ert\&­quot;­: must be no more than 63 characters, spec.­templ­ate.s­pec.c­ontai­ners[­0].vo­lumeM­ounts­[5].n­ame: Not found: \&quo­t;ans­ible-­autom­ation­-plat­form-­autom­ation­metri­csser­vice-­bundl­e-cac­ert\&­quot;­, spec.­templ­ate.s­pec.i­nitCo­ntain­ers[0­].vol­umeMo­unts[­1].na­me: Not found: \&quo­t;ans­ible-­autom­ation­-plat­form-­autom­ation­metri­csser­vice-­bundl­e-cac­ert\&­quot;­]&quo­t;,&q­uot;r­eason­"­;:&qu­ot;In­valid­"­;,... "­;code­"­;:422­}­9; ~~~

Latest discussions in the Red Hat Community

RHCOS ISO for aarch64 architecture

Started Monday, September 28, 2026 at 11:36:46 PM
Red Hat OpenShift Container Platform

Generated Agentic AI

Started Saturday, September 26, 2026 at 8:39:34 PM
Other

OpenShift 4.22 UPI bootstrap stuck: bootstrap MCS 22623 works but Kubernetes API 644...

Started Thursday, September 24, 2026 at 3:00:01 PM
Red Hat OpenShift Container Platform
Meet with other Red Hat users, ask questions, collaborate to solve problems, and connect with our very own Red Hat engineers and moderators - the experts behind our products. Visit our community
Visit our community

Get support

Support cases

Get answers quickly by opening a support case with us.

Live chat

Directly access our support engineers during weekday business hours.

Call or email

Speak directly with a Red Hat Support expert by phone or through email.

Explore the entire customer portal for other resources

Search the entire customer portal