Bug 1007451 - schema-compat plugin should ignore slapi task entries to avoid possible DS deadlock
schema-compat plugin should ignore slapi task entries to avoid possible DS de...
Status: CLOSED CURRENTRELEASE
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: slapi-nis (Show other bugs)
7.0
Unspecified All
medium Severity high
: rc
: ---
Assigned To: Nalin Dahyabhai
Namita Soman
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2013-09-12 10:06 EDT by mreynolds
Modified: 2014-06-17 21:22 EDT (History)
4 users (show)

See Also:
Fixed In Version: slapi-nis-0.49-1.el7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-06-13 07:04:09 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description mreynolds 2013-09-12 10:06:38 EDT
Description of problem:

Potential deadlocks can occur when tasks are added to the Directory Server.  Where the task itself creates new thread and makes database updates, and the task add operation also triggers post plugins to fire off.

Version-Release number of selected component (if applicable):


How reproducible:

Sometimes

Steps to Reproduce:
1. Install FreeIPA server:
# ipa-server-install

2. Authenticate as admin:
# kinit admin

3. Add a hostgroup:
# ipa hostgroup-add --desc="Web Servers" webservers

4. Add a host:
# ipa host-add web1.example.com --force

5. Add an automember rule:
# ipa automember-add --type=hostgroup webservers
# ipa automember-add-condition --key=fqdn --type=hostgroup --inclusive-regex=^web[1-9]+\.example\.com webservers

6. Try to rebuild membership:
# cat rebuild.ldif 
dn: cn=rt,cn=automember rebuild membership,cn=tasks,cn=config
changetype: add
objectClass: top
objectClass: extensibleObject
cn: rt
basedn: cn=computers,cn=accounts,dc=idm,dc=lab,dc=eng,dc=brq,dc=redhat,dc=com
filter: (fqdn=*)
scope: sub

7. ldapmodify -x -D 'cn=directory manager' -w password -f rebuild.ldif
adding new entry "cn=rt,cn=automember rebuild membership,cn=tasks,cn=config"

Actual results:

The ldapmodify in step 7 hangs

Expected results:

ldapmodify does not hang the Directory Server
Comment 3 Martin Kosek 2013-09-17 07:31:21 EDT
Alexander or Nalin, will you be able to address this in slapi-nis?
Comment 4 Nalin Dahyabhai 2013-09-17 10:44:51 EDT
(In reply to Martin Kosek from comment #3)
> Alexander or Nalin, will you be able to address this in slapi-nis?

I'm working on it.
Comment 5 Nalin Dahyabhai 2013-09-19 15:13:17 EDT
I'm having trouble reproducing this bug in a VM with these packages:
389-ds-base-1.3.1.6-4.el7
ipa-server-3.3.1-3.el7
slapi-nis-0.48-1.el7

If you are still seeing this on your system with 0.48, can you check if 0.49 fixes it?  For now, this scratch build is all I can offer:
https://brewweb.devel.redhat.com//taskinfo?taskID=6305170
Comment 6 mreynolds 2013-09-19 15:22:02 EDT
I was never able to reproduce the issue.  Ana was able to reproduce this though(pretty consistently), maybe she still has a system setup that can be used?
Comment 7 Nalin Dahyabhai 2013-09-24 14:39:42 EDT
Alright, it looks like 0.49, which introduces additional run-time configuration options which default to excluding the cn=tasks,cn=config subtree from consideration by the plugins, avoids this for both Ana's and my testing.

Starting from Ana's notes, we've been able to trigger the bug, but only with a freshly-installed system (not just a fresh IPA installation on an existing system, which is weird) the first time an "automember rebuild membership" task is run.  That scenario seems to hit the locking problem fairly reliably.
Comment 9 Namita Soman 2014-01-28 10:39:21 EST
Verified using ipa-server-3.3.3-13.el7.x86_64, slapi-nis-0.52-2.el7.x86_64

Test automation output:
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: ipa-automember-bugzilla-003: bz1007451 schema-compat plugin should ignore slapi task entries to avoid possible DS deadlock
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

----------------------------
Added hostgroup "webservers"
----------------------------
  Host-group: webservers
  Description: Web Servers
:: [   PASS   ] :: Running 'ipa hostgroup-add --desc="Web Servers" webservers' (Expected 0, got 0)
------------------------------
Added host "web1.testrelm.com"
------------------------------
  Host name: web1.testrelm.com
  Principal name: host/web1.testrelm.com@TESTRELM.COM
  Password: False
  Keytab: False
  Managed by: web1.testrelm.com
:: [   PASS   ] :: Running 'ipa host-add web1.testrelm.com --force' (Expected 0, got 0)
----------------------------------
Added automember rule "webservers"
----------------------------------
  Automember Rule: webservers
:: [   PASS   ] :: Running 'ipa automember-add --type=hostgroup webservers' (Expected 0, got 0)
----------------------------------
Added condition(s) to "webservers"
----------------------------------
  Automember Rule: webservers
  Inclusive Regex: fqdn=^web[1-9]+.testrelm.com
----------------------------
Number of conditions added 1
----------------------------
:: [   PASS   ] :: Running 'ipa automember-add-condition --key=fqdn --type=hostgroup --inclusive-regex=^web[1-9]+\.testrelm\.com webservers' (Expected 0, got 0)
:: [   PASS   ] :: Running 'ipa host-show web1.testrelm.com --all > /tmp/tmpout.ipaautomember_bz_1007451.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmpout.ipaautomember_bz_1007451.out' should not contain 'Member of host-groups: webservers' 
adding new entry "cn=rt,cn=automember rebuild membership,cn=tasks,cn=config"

:: [   PASS   ] :: Running 'ldapmodify -x -D 'cn=directory manager' -w Secret123 -f /tmp/rebuild.ldif' (Expected 0, got 0)
:: [   PASS   ] :: Running 'ipa host-show web1.testrelm.com --all > /tmp/tmpout.ipaautomember_bz_1007451.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmpout.ipaautomember_bz_1007451.out' should contain 'Member of host-groups: webservers'
Comment 10 Ludek Smid 2014-06-13 07:04:09 EDT
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.

Note You need to log in before you can comment on or make changes to this bug.