Bug 1577243
Summary: | nss-mdns modifies /etc/nsswitch.conf in scriptlets which conflicts with authselect on Fedora 28 | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Edgar Hoch <edgar.hoch> | ||||
Component: | nss-mdns | Assignee: | Adam Goode <adam> | ||||
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
Severity: | medium | Docs Contact: | |||||
Priority: | unspecified | ||||||
Version: | 31 | CC: | adam.farden, adam, akos.ladanyi, Bert.Deknuydt, bnocera, bog, fedora, gregoire, imgx64+bzrh, john.ellson, lantw44, lpoetter, meta, mwc, noloader, patdung100+redhat, pbrezina, redhat-bugzilla, thomas | ||||
Target Milestone: | --- | Keywords: | Reopened | ||||
Target Release: | --- | ||||||
Hardware: | Unspecified | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | nss-mdns-0.14.1-5.fc30 nss-mdns-0.14.1-5.fc31 nss-mdns-0.14.1-5.el7 nss-mdns-0.14.1-5.el8 | Doc Type: | If docs needed, set a value | ||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2020-03-19 13:54:40 UTC | Type: | Bug | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | |||||||
Bug Blocks: | 1471318 | ||||||
Attachments: |
|
Description
Edgar Hoch
2018-05-11 14:27:28 UTC
The nss-mdns scriptlet is the most brittle part of the package. If there is any way we can get rid of it forever, I would love to do it. I filed this upstream bug to investigate more: https://github.com/pbrezina/authselect/issues/51 I've encountered the inverse of this bug, where authselect clobbers the existing mdns modifications made to /etc/nsswitch.conf. I just recently did a clean install of Fedora 28 last Tuesday. nss-mdns and authselect are both installed. The contents of my nsswitch.conf file are: $ cat /etc/nsswitch.conf # Generated by authselect on Tue May 15 23:43:17 2018 # Do not modify this file manually. passwd: sss files systemd group: sss files systemd netgroup: sss files automount: sss files services: sss files sudoers: files sss shadow: files ethers: files netmasks: files networks: files protocols: files rpc: files hosts: files dns myhostname aliases: files nisplus bootparams: nisplus [NOTFOUND=return] files publickey: nisplus I am able to use avahi-resolve-host-name manually resolve local devices: $ avahi-resolve-host-name uwbts3.local uwbts3.local fe80::201:2eff:fe70:fabe But I am unable to ping local devices $ ping uwbts3.local ping: uwbts3.local: Name or service not known After manually reinstalling nss-mdns mdns resolution is restored, because of the modifications made to the /etc/nsswitch.conf file. (note the hosts: line) $ sudo dnf remove nss-mdns $ sudo dnf install nss-mdns $ cat /etc/nsswitch.conf # Generated by authselect on Tue May 15 23:43:17 2018 # Do not modify this file manually. passwd: sss files systemd group: sss files systemd netgroup: sss files automount: sss files services: sss files sudoers: files sss shadow: files ethers: files netmasks: files networks: files protocols: files rpc: files hosts: files mdns4_minimal [NOTFOUND=return] dns myhostname aliases: files nisplus bootparams: nisplus [NOTFOUND=return] files publickey: nisplus I, too, am here because Fedora 28 broke my existing nsswitch.conf. Furthermore, authselect doesn't seem to have any option to re-enable Avahi/Zeroconf. It seems from https://github.com/pbrezina/authselect/issues/51 that there's no easy fix, so for now I'm just patching nsswitch.conf because I need to be able to use my printer, etc. This is still broken on a clean net-install pulling in all the latest packages. I just had to do a 'sudo dnf reinstall nss-mdss' to get functionality working. Interestingly this only affected my Desktop PC. My IoT boards running a build of ARM minimal server do not have this problem and can ping each other normally. This message is a reminder that Fedora 28 is nearing its end of life. On 2019-May-28 Fedora will stop maintaining and issuing updates for Fedora 28. It is Fedora's policy to close all bug reports from releases that are no longer maintained. At that time this bug will be closed as EOL if it remains open with a Fedora 'version' of '28'. Package Maintainer: If you wish for this bug to remain open because you plan to fix it in a currently maintained version, simply change the 'version' to a later Fedora version. Thank you for reporting this issue and we are sorry that we were not able to fix it before Fedora 28 is end of life. If you would still like to see this bug fixed and are able to reproduce it against a later version of Fedora, you are encouraged change the 'version' to a later Fedora version prior this bug is closed as described in the policy above. Although we aim to fix as many bugs as possible during every release's lifetime, sometimes those efforts are overtaken by events. Often a more recent Fedora release includes newer upstream software that fixes bugs or makes them obsolete. The problem still exists on Fedora 30. The package version is still the same as in Fedora 28, it was only rebuild for the current release. In the meantime there was many improvements in authselect, and I think the maintainer of authselect will provide additional functionality if neccessary, so I think it should be possible to find a better solution for nss-mds than using sed in package scripts! Upstream source on github is unchanged since a year. Yes, I got stalled on trying to understand the authselect integration. Any contributions welcome. This bug appears to have been reported against 'rawhide' during the Fedora 31 development cycle. Changing version to '31'. This bug appears to have been reported against 'rawhide' during the Fedora 31 development cycle. Changing version to 31. Created attachment 1637614 [details]
proposed patch
Adam, I attached proposed spec file patch. It makes sure the changes are written for both authselect and non-authselect cases. It is the same as the one used by systemd. Thanks, I'll take a look! If it's easier, you can also try sending a pull request at https://src.fedoraproject.org/rpms/nss-mdns FEDORA-EPEL-2020-ea93165071 has been submitted as an update to Fedora EPEL 8. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ea93165071 FEDORA-EPEL-2020-b5e1d863a8 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-b5e1d863a8 FEDORA-2020-b2c8abab93 has been submitted as an update to Fedora 30. https://bodhi.fedoraproject.org/updates/FEDORA-2020-b2c8abab93 FEDORA-2020-01fb095a03 has been submitted as an update to Fedora 31. https://bodhi.fedoraproject.org/updates/FEDORA-2020-01fb095a03 nss-mdns-0.14.1-5.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-b5e1d863a8 nss-mdns-0.14.1-5.el8 has been pushed to the Fedora EPEL 8 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ea93165071 nss-mdns-0.14.1-5.fc30 has been pushed to the Fedora 30 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-b2c8abab93 nss-mdns-0.14.1-5.fc31 has been pushed to the Fedora 31 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-01fb095a03 nss-mdns-0.14.1-5.fc30 has been pushed to the Fedora 30 stable repository. If problems still persist, please make note of it in this bug report. nss-mdns-0.14.1-5.fc31 has been pushed to the Fedora 31 stable repository. If problems still persist, please make note of it in this bug report. nss-mdns-0.14.1-5.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report. nss-mdns-0.14.1-5.el8 has been pushed to the Fedora EPEL 8 stable repository. If problems still persist, please make note of it in this bug report. This is still broken, upgrades from Fedora 31 to Fedora 32 disabled the functionality on upgrade. Upgrade was done offline with PackageKit. $ dnf history info 267 | grep nss-mdns Upgrade nss-mdns-0.14.1-6.fc32.x86_64 @fedora Upgraded nss-mdns-0.14.1-5.fc31.x86_64 @@System The F31 -> F32 upgrade problems are tracked in bug #1811935. |