Bug 676733

Summary: crash while adding a new user to be synced to windows
Product: Red Hat Enterprise Linux 6 Reporter: Rich Megginson <rmeggins>
Component: 389-ds-baseAssignee: Rich Megginson <rmeggins>
Status: CLOSED ERRATA QA Contact: Chandrasekar Kannan <ckannan>
Severity: high Docs Contact:
Priority: high    
Version: 6.1CC: amsharma, benl, dpal, jgalipea
Target Milestone: rcKeywords: screened
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Fixed In Version: 389-ds-base-1.2.8-0.3.a3.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 676689 Environment:
Last Closed: 2011-05-19 08:41:34 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 676689    
Bug Blocks: 639035, 656390, 676871    

Description Rich Megginson 2011-02-10 18:37:29 EST
+++ This bug was initially created as a clone of Bug #676689 +++

Description of problem:

I set up windows sync (2008 R2).  Initial sync went ok.  I added an ntUser to the DS side - when it went to sync it crashed with an assertion abort in ldap_next_entry() in windows_search_entry_ext().  It seems that openldap ldap_next_entry(LDAP *, LDAPMessage *entry) does not like entry == NULL - it asserts and aborts, while mozldap ldap_next_entry will just return NULL in that case.

--- Additional comment from rmeggins@redhat.com on 2011-02-10 17:28:04 EST ---

Created attachment 478135 [details]
Comment 3 Rich Megginson 2011-05-02 11:36:40 EDT
to reproduce:
1) setup windows sync and a sync agreement
2) add a user to the DS side like this
dn: cn=testuser,ou=people,<your suffix>
objectclass: person
objectclass: ntUser
sn: User
givenName: Test
ntUserDomainId: testuser
ntUserCreateNewAccount: TRUE

3) verify that the user entry is created in AD
4) verify the directory server did not crash
Comment 4 Amita Sharma 2011-05-03 02:24:32 EDT
[root@rheltest etc]# ldapadd -x -D "cn=Directory Manager" -w abc -h localhost -p 389 << EOF
> dn: cn=testuser,ou=users,ou=unix,dc=corp,dc=example,dc=com
> objectclass: person
> objectClass: inetorgperson
> objectclass: ntUser
> sn: User
> givenName: Test
> ntUserDomainId: testuser
> ntUserCreateNewAccount: TRUE
adding new entry "cn=testuser,ou=users,ou=unix,dc=corp,dc=example,dc=com"

- Entry replicated to AD and no crash found.
hence verified.
Comment 5 errata-xmlrpc 2011-05-19 08:41:34 EDT
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.