Bug 1434028

Summary: zebra service fails to start: privs_init: user(quagga) is not part of vty group specified(quaggavt)
Product: [Fedora] Fedora Reporter: Richard W.M. Jones <rjones>
Component: quaggaAssignee: Michal Ruprich <mruprich>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 26CC: balajig81, mruprich, msekleta
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: quagga-1.2.1-1.fc26 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-08-01 16:22:34 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Richard W.M. Jones 2017-03-20 15:14:52 UTC
Description of problem:

After upgrading a machine from Fedora 25 to Fedora 26 yesterday,
quagga fails to start:

Mar 20 15:09:13 trick.home.annexia.org systemd[1]: Starting GNU Zebra routing manager...
Mar 20 15:09:13 trick.home.annexia.org zebra[13739]: privs_init: user(quagga) is not part of vty group specified(quaggavt)
Mar 20 15:09:13 trick.home.annexia.org systemd[1]: zebra.service: Control process exited, code=exited status=1
Mar 20 15:09:13 trick.home.annexia.org systemd[1]: Failed to start GNU Zebra routing manager.
Mar 20 15:09:13 trick.home.annexia.org systemd[1]: zebra.service: Unit entered failed state.
Mar 20 15:09:13 trick.home.annexia.org systemd[1]: zebra.service: Failed with result 'exit-code'.

The error message seems literally correct.  It is true that the
quagga user is not part of the quaggavt group:

$ grep quagga /etc/passwd
quagga:x:92:92:Quagga routing suite:/var/run/quagga:/sbin/nologin
$ grep quagga /etc/group
quaggavt:x:85:
quagga:x:92:

Should it be?  Should the RPM add the user to the group when
installing?

Version-Release number of selected component (if applicable):

quagga-1.1.1-2.fc26.x86_64

How reproducible:

100%

Steps to Reproduce:
1. systemctl start zebra

Comment 1 Richard W.M. Jones 2017-05-15 20:48:05 UTC
I upgraded another machine from F25 -> F26 today and same thing.

quagga-1.1.1-2.fc26.x86_64

Comment 2 Michal Ruprich 2017-05-16 17:53:24 UTC
The older version on F25 (0.99) has the same values in /etc/passwd and /etc/group but starts with no issues. Nothing changed in spec file that would indicate as to why this is happening.

Comment 3 Michal Ruprich 2017-05-17 09:59:44 UTC
This is most likely caused by changes in lib/privs.c in quagga. It uses getgrouplist function to retrieve groups of user quagga. But after quagga gets installed it becomes part of quagga group only and not quaggavt. I agree that quagga should be added to quaggavt during install. This needs to be addressed in the spec file when calling the configure script.

Comment 4 Michal Ruprich 2017-05-17 10:13:31 UTC
This is where the handling of groups changed in upstream:

https://github.com/Quagga/quagga/commit/80c9354835bb924983d12b0efad957e78f219287

Comment 5 Michal Ruprich 2017-05-17 10:18:45 UTC
The previous link is just a clone of the official upstream git. This is the commit in the official git:

http://git.savannah.gnu.org/cgit/quagga.git/commit/?id=80c9354835bb924983d12b0efad957e78f219287

Comment 6 Michal Ruprich 2017-05-29 10:23:21 UTC
I plan to rebase quagga in F26 and Rawhide to latest 1.2.1 version and I will fix the quagga group along with the update.

Comment 7 Fedora Update System 2017-05-30 17:13:16 UTC
quagga-1.2.1-1.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-92bbc9b619

Comment 8 Fedora Update System 2017-06-01 03:18:43 UTC
quagga-1.2.1-1.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-92bbc9b619

Comment 9 Fedora Update System 2017-08-01 16:22:34 UTC
quagga-1.2.1-1.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.