Bug 1370512

Summary: Received ACIError instead of DuplicatedError in stageuser_tests
Product: Red Hat Enterprise Linux 7 Reporter: Petr Vobornik <pvoborni>
Component: ipaAssignee: IPA Maintainers <ipa-maint>
Status: CLOSED ERRATA QA Contact: Kaleem <ksiddiqu>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.3CC: akasurde, jcholast, mbasti, pvoborni, rcritten
Target Milestone: rcKeywords: Regression
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ipa-4.4.0-9.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-11-04 06:02:17 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
console.log none

Description Petr Vobornik 2016-08-26 14:12:36 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/6199

We do not have right to write to users delete_container. In case that
user already exists in that container and we tried to add entry, we
receive ACIError. This must be checked and DuplicationEntry error must
be raised before.


Several similar errors in ipa.test_xmlrpc.test_stageuser_plugin:
{{{
        except errors.PublicError as got_exception:
>           assert type(expected_exception) is type(got_exception)
E           assert <class 'ipalib.errors.DuplicateEntry'> is <class 'ipalib.errors.ACIError'>
E            +  where <class 'ipalib.errors.DuplicateEntry'> = type(DuplicateEntry(u'user with name "tuser" already exists',))
E            +  and   <class 'ipalib.errors.ACIError'> = type(ACIError(u"Insufficient access: Insufficient 'add' privilege to add the entry ...ts,cn=provisioning,dc=dom-150,dc=idm,dc=lab,dc=eng,dc=brq,dc=redhat,dc=com'.",))
}}}

Version of DS: 389-ds-base-1.3.5.12-1.fc24.x86_64

In the latest provided build of DS, there were some changes in ACI enforcing, thus this is probbably the root cause

Comment 2 Jan Cholasta 2016-08-30 06:22:51 UTC
Fixed upstream
master:
https://fedorahosted.org/freeipa/changeset/5c50b265e6b5a0d06f213b5eb581c96e3392aeea

Comment 5 Martin Bašti 2016-09-19 11:18:24 UTC
Steps to reproduce:

$ ipa user-add test
$ ipa user-del test --preserve
$ ipa user-add test

Comment 6 Abhijeet Kasurde 2016-09-19 11:45:13 UTC
Verified using IPA version ::
ipa-server-4.4.0-12.el7.x86_64


Marking BZ as verified.

Comment 7 Abhijeet Kasurde 2016-09-19 11:45:32 UTC
Created attachment 1202455 [details]
console.log

Comment 9 errata-xmlrpc 2016-11-04 06:02:17 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2404.html