Description of problem:
Adding users to user group throws Internal server error.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Login as admin.
2. Navigate to User page
3. Add 10 users (say user00, user01,.....user09, user10)
4. Navigate to User Group page
5. Add a group (say group01) then click "Add and Edit"
6. In Users tab click "ADD"
IPA Error 907 :: cannot connect to u'ldapi://%2fvar%2frun%2fslapd-TESTRELM-COM.socket': LDAP Server Down (ScreenShot-1)
Internal Server Error pops up (ScreenShot-2)
when I tried on CLI but I did not see the error.
Created attachment 926405 [details]
IPA Error 907
Created attachment 926406 [details]
Internal Server Error
Please provide httpd error_log so that we can check the real errors.
Created attachment 926445 [details]
Netgroups :: Ldapi connection issue
Same error found in Netgroups page as well. After adding 10th netgroup "IPA Error 907" pops up (ScreenShot-3).
Created attachment 926446 [details]
Thanks. This looks as intermittent errors, I could not reproduce them on my set up. I suspect that this may also be an Directory Server issue. Is there anything interesting /var/log/dirsrv/.../errors log?
I did not see anything interesting in /var/log/dirsrv/.../errors log. Also I have reproduced this bug on multiple machines.I have pasted the details of one of my machines in Comment 9 for your reference.
let me know if you need any further information.
I see DS crashed, this is why it was not responding:
# grep ns-slapd /var/log/messages
Aug 18 01:07:46 server66ad ns-slapd: Failed to rename errors log file, Netscape Portable Runtime error -5950 (File not found.). Exiting...
Aug 18 04:32:54 server66ad kernel: ns-slapd: segfault at 0 ip 00007ffddd190ab2 sp 00007ffdba3e15c8 error 4 in libback-ldbm.so[7ffddd15d000+9b000]
I see it also was not able to touch it's log files, did you manipulate with them or the directory they are stored in? It may be related to the crash.
Could you please enable the VM to generate the core for DS so that we can report proper bug to 389-ds-base component? See HOWTO below:
Created attachment 928759 [details]
I have reproduced the crash and attached the stacktrace.
Cool! Re-assigning to DS team so that they can fix the crash. Once that is fixed, Web UI should run smoothly again.
Thank you Martin.
The search filter is (&(objectClass=posixaccount)(!(memberOf=cn=group1,cn=groups,cn=accounts,dc=testrelm,dc=com)))"
and the crash is in idl_is_allids() called with a NULL list.
Looks like this was fixed as a side effect of ticket #47313 (bz1044133), which was not backported to 1.2.11
The code was introduce to 188.8.131.52-30 by another backport for a VLV fix, but the check in idl_is_allids is missing
Request Varun to mark qe_test_coverage+ flag if its automated in IPA.
Created attachment 929355 [details]
git patch file (389-ds-base-1.2.11) -- backporting just the NULL idl checking in idl_common.c from the commit a71633d56951dd6c4d0368c790b85628f1598968
The search filter:
Entries that satisfy "objectClass=posixaccount" need to exist, while
entries that satisfy "memberOf=cn=group1,cn=groups,cn=accounts,dc=testrelm,dc=com" should not exist.
If the search does not crash the server, the fix is verified.
Thanks to Nathan for reviewing the patch.
Pusehd to 389-ds-base-1.2.11:
4a16332..488fa12 389-ds-base-1.2.11 -> 389-ds-base-1.2.11
I have upgraded my setup to latest 389-ds-base-184.108.40.206-42.el6.
And I tested manually by adding 10 users,100 users and more than 10 netgroups in IPA-WebUI, no crash observed. Hence marking bug as verified.
tested ipa-server version :: ipa-server-3.0.0-42.el6.x86_64
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.