RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1044205 - [RFE] Allow memberOf to use an alternate config area
Summary: [RFE] Allow memberOf to use an alternate config area
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: 389-ds-base
Version: 7.0
Hardware: Unspecified
OS: Unspecified
high
unspecified
Target Milestone: rc
: ---
Assignee: mreynolds
QA Contact: Viktor Ashirov
URL:
Whiteboard:
Depends On: 1172597
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-12-17 22:05 UTC by Nathan Kinder
Modified: 2020-09-13 20:46 UTC (History)
9 users (show)

Fixed In Version: 389-ds-base-1.3.3.1-1.el7
Doc Type: Release Note
Doc Text:
Alternative Configuration Storage for the MemberOf Plug-In The configuration of the MemberOf plug-in for the 389 Directory Server can now be stored in a suffix mapped to a back-end database. This allows the MemberOf plug-in configuration to be replicated, which makes it easier for the user to maintain a consistent MemberOf plug-in configuration in a replicated environment.
Clone Of:
Environment:
Last Closed: 2015-03-05 09:33:08 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
Valgrind output (257.46 KB, text/plain)
2014-11-25 20:30 UTC, Nathan Kinder
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github 389ds 389-ds-base issues 862 0 None None None 2020-09-13 20:46:35 UTC
Red Hat Product Errata RHSA-2015:0416 0 normal SHIPPED_LIVE Important: 389-ds-base security, bug fix, and enhancement update 2015-03-05 14:26:33 UTC

Description Nathan Kinder 2013-12-17 22:05:30 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/389/ticket/47525

The memberOf plug-in currently uses it's main plug-in config entry in cn=config for the memberOf configuration.  This doesn't allow the memberOf configuration to be replicated across all masters in a replicated environment.

We should add support for using an alternate config area that is in a normal backend.  We already do this for other plug-ins by using nsslapd-pluginConfigArea in the main plug-in config entry.

Comment 5 Sankar Ramalingam 2014-11-25 07:36:30 UTC
Memberof plugin configuration with alternate configArea is failing. Hence, flipping the status back to Assigned.
Refer - https://bugzilla.redhat.com/show_bug.cgi?id=1044170#c2

Comment 6 Sankar Ramalingam 2014-11-25 09:02:37 UTC
Build tested:
[root@vm-idm-035 ~]# rpm -qa 389-ds-base
389-ds-base-1.3.3.1-9.el7.x86_64

Comment 8 Sankar Ramalingam 2014-11-25 19:04:50 UTC
As per the comment from Nathan for Bug #1044170, I configured memberOf plugin with alternate config area in a single ldapmodify command. Then, restarted the server.

[root@vm-idm-042 ~]# ldapsearch -x -p 1989 -h localhost -D "cn=Directory Manager" -w Secret123 -b "cn=MemberOf Plugin,cn=plugins,cn=config"

dn: cn=MemberOf Plugin,cn=plugins,cn=config
nsslapd-pluginEnabled: off

[root@vm-idm-042 ~]# ldapmodify -ax -p 1989 -h localhost -D "cn=Directory Manager" -w Secret123 << EOF
dn: cn=MemberOf Plugin,cn=plugins,cn=config
changetype: modify
replace: nsslapd-pluginEnabled
nsslapd-pluginEnabled: on
> -
> replace: nsslapd-pluginConfigArea
> nsslapd-pluginConfigArea: ou=groups,dc=newmemof,dc=com
> -
> EOF
modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config"

[root@vm-idm-042 ~]# ldapsearch -x -p 1989 -h localhost -D "cn=Directory Manager" -w Secret123 -b "cn=MemberOf Plugin,cn=plugins,cn=config"

# MemberOf Plugin, plugins, config
dn: cn=MemberOf Plugin,cn=plugins,cn=config
nsslapd-pluginPath: libmemberof-plugin
nsslapd-pluginInitfunc: memberof_postop_init
nsslapd-pluginType: betxnpostoperation
nsslapd-pluginEnabled: on
nsslapd-plugin-depends-on-type: database
memberofgroupattr: member
memberofattr: memberOf
nsslapd-pluginId: none
nsslapd-pluginVersion: none
nsslapd-pluginVendor: none
nsslapd-pluginDescription: none
nsslapd-pluginConfigArea: ou=groups,dc=newmemof,dc=com

[root@vm-idm-042 ~]# /usr/lib64/dirsrv/slapd-testinst1/restart-slapd 
Server failed to start !!! Please check errors log for problems


Few lines from DS error logs...
[26/Nov/2014:00:28:46 +051800] memberof-plugin - Error 53: The memberOfGroupAttr and memberOfAttr configuration attributes must be provided
[26/Nov/2014:00:28:47 +051800] memberof-plugin - configuration failed (Server is unwilling to perform)
[26/Nov/2014:00:28:47 +051800] - Failed to start betxnpostoperation plugin MemberOf Plugin
[26/Nov/2014:00:28:48 +051800] memberof-plugin - only one memberOf plugin instance can be used
[26/Nov/2014:00:28:48 +051800] memberof-plugin - configuration failed (Bad parameter to an ldap routine)
[26/Nov/2014:00:28:48 +051800] - Failed to start betxnpostoperation plugin MemberOf Plugin
[26/Nov/2014:00:28:48 +051800] memberof-plugin - only one memberOf plugin instance can be used
[26/Nov/2014:00:28:48 +051800] memberof-plugin - configuration failed (Bad parameter to an ldap routine)
[26/Nov/2014:00:28:49 +051800] - Failed to start betxnpostoperation plugin MemberOf Plugin
[26/Nov/2014:00:28:49 +051800] memberof-plugin - only one memberOf plugin instance can be used
[26/Nov/2014:00:28:49 +051800] memberof-plugin - configuration failed (Bad parameter to an ldap routine)
[26/Nov/2014:00:28:49 +051800] - Failed to start betxnpostoperation plugin MemberOf Plugin
[26/Nov/2014:00:28:49 +051800] - Error: Failed to resolve plugin dependencies
[26/Nov/2014:00:28:49 +051800] - Error: betxnpostoperation plugin MemberOf Plugin is not started

Comment 9 Nathan Kinder 2014-11-25 19:17:54 UTC
The first problem I see is that the following crashes ns-slapd:

---------------------------------------------------------------------
[ipauser@ipa ~]$ ldapmodify -x -D "cn=directory manager" -w Secret12
dn: cn=MemberOf Plugin,cn=plugins,cn=config
changetype: modify
replace:nsslapd-pluginEnabled
nsslapd-pluginEnabled: on

modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config"

[ipauser@ipa ~]$ sudo systemctl restart dirsrv.target
[ipauser@ipa ~]$ ps -ef | grep slapd
nobody   21735     1  1 14:01 ?        00:00:00 /usr/sbin/ns-slapd -D /etc/dirsrv/slapd-ipa -i /var/run/dirsrv/slapd-ipa.pid -w /var/run/dirsrv/slapd-ipa.startpid
ipauser  21777 10356  0 14:02 pts/0    00:00:00 grep --color=auto slapd
[ipauser@ipa ~]$ ldapmodify -x -D "cn=directory manager" -w Secret12
dn: cn=MemberOf Plugin,cn=plugins,cn=config
changetype: modify
replace: nsslapd-pluginConfigArea
nsslapd-pluginConfigArea:ou=People,dc=example,dc=com

modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config"
---------------------------------------------------------------------

The stack shows an abort and indicates a possible memory error:

---------------------------------------------------------------------------
#0  0x00007fdc3d0105c9 in raise () from /lib64/libc.so.6
#1  0x00007fdc3d011cd8 in abort () from /lib64/libc.so.6
#2  0x00007fdc3d050dd7 in __libc_message () from /lib64/libc.so.6
#3  0x00007fdc3d0577dc in malloc_consolidate () from /lib64/libc.so.6
#4  0x00007fdc3d059069 in _int_malloc () from /lib64/libc.so.6
#5  0x00007fdc3d05b12c in malloc () from /lib64/libc.so.6
#6  0x00007fdc3e7902e5 in ber_memalloc_x () from /lib64/liblber-2.4.so.2
#7  0x00007fdc3e78e94b in ber_realloc () from /lib64/liblber-2.4.so.2
#8  0x00007fdc3e78d88b in ber_start_seqorset () from /lib64/liblber-2.4.so.2
#9  0x00007fdc3e78e3fc in ber_printf () from /lib64/liblber-2.4.so.2
#10 0x00007fdc3f61ef7f in send_ldap_result_ext () from /usr/lib64/dirsrv/libslapd.so.0
#11 0x00007fdc3f61f321 in send_ldap_result () from /usr/lib64/dirsrv/libslapd.so.0
#12 0x00007fdc3f609423 in slapi_send_ldap_result () from /usr/lib64/dirsrv/libslapd.so.0
#13 0x00007fdc3f5c852a in dse_modify () from /usr/lib64/dirsrv/libslapd.so.0
#14 0x00007fdc3f5f9061 in op_shared_modify () from /usr/lib64/dirsrv/libslapd.so.0
#15 0x00007fdc3f5fa39f in do_modify () from /usr/lib64/dirsrv/libslapd.so.0
#16 0x00007fdc3fad83f1 in connection_threadmain ()
#17 0x00007fdc3da029eb in _pt_root () from /lib64/libnspr4.so
#18 0x00007fdc3d3a3df3 in start_thread () from /lib64/libpthread.so.0
#19 0x00007fdc3d0d101d in clone () from /lib64/libc.so.6
---------------------------------------------------------------------------

Valgrind will hopefully show more information.

Comment 10 Nathan Kinder 2014-11-25 20:13:37 UTC
This crash problem only seems to occur if the following conditions are met:

- memberOf is already enabled and loaded (enable + restart)
- nsslapd-pluginConfigArea is added for memberOf on a running server
- nsslapd-pluginConfigArea points to an entry that exists, but is an invalid config entry (doesn't contain the required configuration attributes)

We validate that the entry pointed to by nsslapd-pluginConfigArea exists at the preop modify phase in memberof_validate_config(), but we don't actually validate that is contains the required configuration attributes.  We then attempt to actually apply the config in memberof_apply_config(), which fails with an error 53.  We attempt to return this error 53 to the client, but encounter some sort of memory error when returning the response.

Comment 11 Nathan Kinder 2014-11-25 20:30:24 UTC
Created attachment 961376 [details]
Valgrind output

Comment 12 mreynolds 2014-12-04 21:49:10 UTC
Fixed upstream

Veriification steps list above (comment 8):

https://bugzilla.redhat.com/show_bug.cgi?id=1044205#c8

Comment 13 Sankar Ramalingam 2014-12-10 12:57:34 UTC
Marking it as verified since there is a new bugzilla opened for the partial configuration of memberof plugin.
https://bugzilla.redhat.com/show_bug.cgi?id=1172597

Comment 14 Jiri Herrmann 2014-12-12 15:31:28 UTC
If this Feature should be included in the 7.1 Release Notes, could you please change the Doc Type from Enhancement to "Release Note"?

Note that the Release Notes are intended to list the most prominent and customer-relevant new features rather than every single enhancement.

Cheers,
Jirka

Comment 15 Sankar Ramalingam 2014-12-24 15:39:13 UTC
Configuring memberof plugin with alternate plugin config area works fine. I configured the plugin with the LDIF file as follows.

[root@mgmt9 MMR_WINSYNC]# cat /tmp/MemOfNew.ldif 
dn: cn=memofGroup3,dc=newmemof,dc=com
changetype: add
objectClass: top
objectClass: extensibleObject
cn: memofGroup3
memberofgroupattr: member
memberofattr: memberOf
memberOfEntryScope: ou=groups,dc=newmemof,dc=com
memberOfSkipNested: on
memberOfEntryScopeExcludeSubtree: ou=people,dc=newmemof,dc=com
memberOfAllBackends: off

dn: cn=MemberOf Plugin,cn=plugins,cn=config
changetype: modify
replace: nsslapd-pluginEnabled
nsslapd-pluginEnabled: on
-
replace: nsslapd-pluginConfigArea
nsslapd-pluginConfigArea: cn=memofGroup3,dc=newmemof,dc=com


Build tested:
[root@mgmt9 MMR_WINSYNC]# rpm -qa 389-ds-base
389-ds-base-1.3.3.1-10.el7.x86_64

Comment 21 errata-xmlrpc 2015-03-05 09:33:08 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-0416.html


Note You need to log in before you can comment on or make changes to this bug.