Bug 672711

Summary: ipa role-mod: attr "description" removal is possible (and it should not)
Product: [Retired] freeIPA Reporter: Yi Zhang <yzhang>
Component: ipa-serverAssignee: Rob Crittenden <rcritten>
Status: CLOSED ERRATA QA Contact: Chandrasekar Kannan <ckannan>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 2.0CC: benl, dpal, jgalipea, jhrozek
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: freeipa-2.1.0-1.fc15 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-03-28 09:26:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Yi Zhang 2011-01-25 23:43:42 UTC
Description of problem:
I just found a tricky way to remove attribute with role-mod. Please check the test below


Version-Release number of selected component (if applicable): ipa-server-2.0-0.2011011115gitc778919.fc14.i686


How reproducible:


Steps to Reproduce:
1. [before]
[yi@dhcp-137 ipa-delegation]$ ipa role-find testRole01
--------------
1 role matched
--------------
  Role name: testrole01
  Description: 4_role_mod_1004
----------------------------
Number of entries returned 1
----------------------------


2. [a tricky way to remove "description" ]

[yi@dhcp-137 ipa-delegation]$ ipa role-mod testRole01 --desc= --rename=NewTestRole01
--------------------------
Modified role "testrole01"
--------------------------
  Role name: newtestrole01


3. [ after ]

[yi@dhcp-137 ipa-delegation]$ ipa role-find newtestrole01
--------------
1 role matched
--------------
  Role name: newtestrole01
----------------------------
Number of entries returned 1
----------------------------


[yi@dhcp-137 ipa-delegation]$ ipa role-find newtestrole01 --all
--------------
1 role matched
--------------
  dn: cn=newtestrole01,cn=roles,cn=accounts,dc=sjc,dc=redhat,dc=com
  Role name: newtestrole01
  objectclass: groupofnames, nestedgroup, top
----------------------------
Number of entries returned 1
----------------------------
[yi@dhcp-137 ipa-delegation]$ ipa role-find newtestrole01 --all --raw
--------------
1 role matched
--------------
  dn: cn=newtestrole01,cn=roles,cn=accounts,dc=sjc,dc=redhat,dc=com
  cn: newtestrole01
  objectclass: groupofnames
  objectclass: nestedgroup
  objectclass: top
----------------------------
Number of entries returned 1
----------------------------

Comment 1 Jakub Hrozek 2011-01-26 09:38:37 UTC
This looks like a bug to me, if an attribute is required we probably shouldn't allow renaming it to an empty string (except for setattr). CLI doesn't allow entering it empty when calling -add anyway.

https://fedorahosted.org/freeipa/ticket/852

Comment 2 Rob Crittenden 2011-01-26 14:03:28 UTC
Setting to an empty value will delete the attribute. What is surprising to me is I think description is required by the schema, so it is unclear why it is allowed at all.

Comment 3 Dmitri Pal 2011-02-23 20:12:22 UTC
master: 81020a2ffaa13edbdaa4ff377b748fb623fe0c09