Bug 1402371

Summary: "Insufficient privileges" messages observed in pcs status for nfs_unblock resource agent.
Product: Red Hat Enterprise Linux 6 Reporter: Soumya Koduri <skoduri>
Component: resource-agentsAssignee: Oyvind Albrigtsen <oalbrigt>
Status: CLOSED WONTFIX QA Contact: cluster-qe <cluster-qe>
Severity: high Docs Contact:
Priority: unspecified    
Version: 6.8CC: agk, aloganat, amukherj, cfeist, cluster-maint, cluster-qe, dang, fdinitto, ffilz, jthottan, mbenjamin, mnovacek, msaini, oalbrigt, rcyriac, rhs-bugs, sbhaloth, skoduri, storage-qa-internal, tlavigne
Target Milestone: rc   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1402370 Environment:
Last Closed: 2017-11-07 21:02:20 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1402370    
Bug Blocks: 1403654    

Comment 3 Oyvind Albrigtsen 2016-12-08 10:26:45 UTC
https://github.com/ClusterLabs/resource-agents/pull/898

Comment 5 Soumya Koduri 2016-12-08 12:25:28 UTC
Manisha/Arthy,

Could you please verify and confirm the same. Thanks!

Comment 6 Manisha Saini 2016-12-08 13:35:32 UTC
Arthy,

This Issue is observed in rhel 6 also.

[root@dhcp37-156 gluster]# cat /etc/redhat-release 
Red Hat Enterprise Linux Server release 6.8 (Santiago)


[root@dhcp37-156 gluster]# pcs status
Cluster name: G1481202576.08
Last updated: Thu Dec  8 18:59:39 2016		Last change: Thu Dec  8 18:41:09 2016 by root via cibadmin on dhcp37-156.lab.eng.blr.redhat.com
Stack: cman
Current DC: dhcp37-156.lab.eng.blr.redhat.com (version 1.1.14-8.el6_8.2-70404b0) - partition WITHOUT quorum
4 nodes and 24 resources configured

Online: [ dhcp37-156.lab.eng.blr.redhat.com dhcp37-63.lab.eng.blr.redhat.com ]
OFFLINE: [ dhcp37-169.lab.eng.blr.redhat.com dhcp37-196.lab.eng.blr.redhat.com ]

Full list of resources:

 Clone Set: nfs_setup-clone [nfs_setup]
     Stopped: [ dhcp37-156.lab.eng.blr.redhat.com dhcp37-169.lab.eng.blr.redhat.com dhcp37-196.lab.eng.blr.redhat.com dhcp37-63.lab.eng.blr.redhat.com ]
 Clone Set: nfs-mon-clone [nfs-mon]
     Stopped: [ dhcp37-156.lab.eng.blr.redhat.com dhcp37-169.lab.eng.blr.redhat.com dhcp37-196.lab.eng.blr.redhat.com dhcp37-63.lab.eng.blr.redhat.com ]
 Clone Set: nfs-grace-clone [nfs-grace]
     Started: [ dhcp37-156.lab.eng.blr.redhat.com dhcp37-63.lab.eng.blr.redhat.com ]
     Stopped: [ dhcp37-169.lab.eng.blr.redhat.com dhcp37-196.lab.eng.blr.redhat.com ]
 Resource Group: dhcp37-156.lab.eng.blr.redhat.com-group
     dhcp37-156.lab.eng.blr.redhat.com-nfs_block	(ocf::heartbeat:portblock):	Started dhcp37-156.lab.eng.blr.redhat.com
     dhcp37-156.lab.eng.blr.redhat.com-cluster_ip-1	(ocf::heartbeat:IPaddr):	Started dhcp37-156.lab.eng.blr.redhat.com
     dhcp37-156.lab.eng.blr.redhat.com-nfs_unblock	(ocf::heartbeat:portblock):	FAILED dhcp37-156.lab.eng.blr.redhat.com (unmanaged)
 Resource Group: dhcp37-196.lab.eng.blr.redhat.com-group
     dhcp37-196.lab.eng.blr.redhat.com-nfs_block	(ocf::heartbeat:portblock):	Stopped
     dhcp37-196.lab.eng.blr.redhat.com-cluster_ip-1	(ocf::heartbeat:IPaddr):	Stopped
     dhcp37-196.lab.eng.blr.redhat.com-nfs_unblock	(ocf::heartbeat:portblock):	Stopped
 Resource Group: dhcp37-63.lab.eng.blr.redhat.com-group
     dhcp37-63.lab.eng.blr.redhat.com-nfs_block	(ocf::heartbeat:portblock):	Stopped
     dhcp37-63.lab.eng.blr.redhat.com-cluster_ip-1	(ocf::heartbeat:IPaddr):	Stopped
     dhcp37-63.lab.eng.blr.redhat.com-nfs_unblock	(ocf::heartbeat:portblock):	Stopped
 Resource Group: dhcp37-169.lab.eng.blr.redhat.com-group
     dhcp37-169.lab.eng.blr.redhat.com-nfs_block	(ocf::heartbeat:portblock):	Stopped
     dhcp37-169.lab.eng.blr.redhat.com-cluster_ip-1	(ocf::heartbeat:IPaddr):	Stopped
     dhcp37-169.lab.eng.blr.redhat.com-nfs_unblock	(ocf::heartbeat:portblock):	Stopped

Failed Actions:
* dhcp37-156.lab.eng.blr.redhat.com-nfs_unblock_stop_0 on dhcp37-156.lab.eng.blr.redhat.com 'insufficient privileges' (4): call=85, status=complete, exitreason='none',
    last-rc-change='Thu Dec  8 18:56:35 2016', queued=0ms, exec=297ms


PCSD Status:
  dhcp37-156.lab.eng.blr.redhat.com: Online
  dhcp37-196.lab.eng.blr.redhat.com: Online
  dhcp37-63.lab.eng.blr.redhat.com: Online
  dhcp37-169.lab.eng.blr.redhat.com: Online

Comment 7 Oyvind Albrigtsen 2016-12-08 13:55:50 UTC
Thanks for the feedback.

I had a look, and it seems like we need an updated version of iptables to come around the issue on RHEL6 (it doesnt have any locking, so we cant make it wait with -w):
 Dec  8 18:56:35 dhcp37-156 crmd[6281]:   notice: Operation dhcp37-156.lab.eng.blr.redhat.com-nfs_unblock_stop_0: insufficient privileges (node=dhcp37-156.lab.eng.blr.redhat.com, call=85, rc=4, cib-update=175, confirmed=true)
Dec  8 18:56:35 dhcp37-156 crmd[6281]:   notice: dhcp37-156.lab.eng.blr.redhat.com-dhcp37-156.lab.eng.blr.redhat.com-nfs_unblock_stop_0:85 [ 0+0 records in\n0+0 records out\n0 bytes (0 B) copied, 0.14356 s, 0.0 kB/s\niptables: Resource temporarily unavailable.\n ]

Comment 8 Oyvind Albrigtsen 2016-12-09 12:07:21 UTC
iptables v1.4.20 or newer is required for the wait feature. The current available for RHEL6 is v. 1.4.7.

Comment 14 Chris Feist 2017-11-07 21:02:20 UTC
Red Hat Enterprise Linux 6 is in the Production 3 Phase. During the Production 3 Phase, Critical impact Security Advisories (RHSAs) and selected Urgent Priority Bug Fix Advisories (RHBAs) may be released as they become available.

The official life cycle policy can be reviewed here:

http://redhat.com/rhel/lifecycle

This issue does not meet the inclusion criteria for the Production 3 Phase and will be marked as CLOSED/WONTFIX. If this remains a critical requirement, please contact Red Hat Customer Support to request a re-evaluation of the issue, citing a clear business justification. Note that a strong business justification will be required for re-evaluation. Red Hat Customer Support can be contacted via the Red Hat Customer Portal at the following URL:

https://access.redhat.com/