Bug 2331728

Summary: LDAP initialization does unnecessary resolution of hostname
Product: [Fedora] Fedora Reporter: Petr Menšík <pemensik>
Component: openldapAssignee: Simon Pichugin <spichugi>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: rawhideCC: spichugi, vashirov
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: openldap-2.6.10-4.fc44 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2025-08-30 02:47:03 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Petr Menšík 2024-12-11 19:04:30 UTC
curl --version does try to resolve local hostname, which is usually stored in $HOSTNAME variable. It seems it does that for no good reason. It does not matter whether machine hostname is already FQDN or not, it always try it unconditionally by calling getaddrinfo(3).

Every usage of dnf tries to resolve hostname. That is then supressed by myhostname on Fedora, which returns non-helping response. I think hostname should be fetched from actual network responses.

Seen with:
openldap-2.6.8-5.fc41.x86_64

Reproducible: Always

Steps to Reproduce:
1. dnf install gdb curl
2. gdb --args curl --version
3. (gdb) break getaddrinfo
4. (gdb) run
Actual Results:  
getaddrinfo is called with current hostname, stored into ldap_int_hostname variable. That is used only when ldap client has not configured target server. But this hostname seems fetched always.

Expected Results:  
No network activity happens, unless something is actually requested. This is not the case.

I think it should be made lazy initialized. It should be tried only when necessary. This seems to be useful when tlso_session_chkhost in libraries/libldap/tls_o.c is used. I think should initialize hostname only once conditions to use it happens. There is a fallback anyway. It should query FQDN only when name_in contains unusable response.

Related: https://github.com/systemd/systemd/issues/34897
Related: https://issues.redhat.com/browse/RHEL-70922

Comment 1 Aoife Moloney 2025-02-26 13:19:47 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 42 development cycle.
Changing version to 42.

Comment 2 Petr Menšík 2025-06-20 19:38:53 UTC
This seems to be fixed in 2.7 at upstream, but still an issue with current openldap 2.6.10. Thank you for reporting it upstream!

Comment 3 Fedora Update System 2025-08-30 01:56:00 UTC
FEDORA-2025-42a9a20e92 (openldap-2.6.10-4.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-42a9a20e92

Comment 4 Fedora Update System 2025-08-30 02:47:03 UTC
FEDORA-2025-42a9a20e92 (openldap-2.6.10-4.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.