Bug 1142152 - bind hangs after reload/GSSAPI Error: The referenced context has expired (Success)
Summary: bind hangs after reload/GSSAPI Error: The referenced context has expired (Suc...
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: bind
Version: 6.6
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: Tomáš Hozza 🤓
QA Contact: Tereza Cerna
Depends On: 1142150 1142176
Blocks: 1153398 1159820
TreeView+ depends on / blocked
Reported: 2014-09-16 09:12 UTC by Arpit Tolani
Modified: 2019-07-11 08:11 UTC (History)
7 users (show)

Fixed In Version: bind-9.8.2-0.32.rc1.el6
Doc Type: Bug Fix
Doc Text:
BIND incorrectly handled errors returned by dynamic databases (from dyndbAPI). Consequently, BIND could enter a deadlock situation on shutdown under certain circumstances. The dyndb API has been fixed not to cause a deadlock during BIND shutdown after the dynamic database returns an error, and BIND now shuts down normally in the described situation.
Clone Of: 1142150
Last Closed: 2015-07-22 05:50:11 UTC

Attachments (Terms of Use)
SRPM with bind-dyndb-ldap plugin for testing of this bug (311.71 KB, application/x-rpm)
2014-12-09 08:35 UTC, Tomáš Hozza 🤓
no flags Details

System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2015:1250 normal SHIPPED_LIVE bind bug fix and enhancement update 2015-07-20 17:50:10 UTC

Description Arpit Tolani 2014-09-16 09:12:48 UTC
+++ This bug was initially created as a clone of Bug #1142150 +++

Description of problem:
bind hangs after reload/GSSAPI Error: The referenced context has expired (Success)

 After a while (about once in a week) the bind daemon is in the state hang/zombie. The bind daemon seems to be present and accept requests from the clients, but is not answering any dns requests. Only killing the process with kill -9 can stop the daemon. After starting bind again, it works fine, until the problem occurs again.

Version-Release number of selected component (if applicable):

How reproducible:
Everytime Logrotates runs. 

Steps to Reproduce:
1. Configure IPA server with DNS
2. Wait till logrotate starts rotating. 

Additional info:
It is related to https://fedorahosted.org/bind-dyndb-ldap/ticket/131

Comment 1 Tomáš Hozza 🤓 2014-09-16 09:51:30 UTC
It is too late for 6.6. Moving to 6.7.

Comment 2 Petr Spacek 2014-09-16 17:29:37 UTC
There is nothing private in this bug. Publicizing.

Comment 3 Tomáš Hozza 🤓 2014-09-17 18:31:57 UTC
patch added to Bug #1142150

reproducer added in Bug #1142150 comment #7

Comment 5 Tomáš Hozza 🤓 2014-12-09 08:35:52 UTC
Created attachment 966145 [details]
SRPM with bind-dyndb-ldap plugin for testing of this bug

Comment 6 Tomáš Hozza 🤓 2014-12-09 09:35:01 UTC
Steps to reproduce for QA:

1. install bind
2. build the attachment 966145 [details] for your architecture
3. install the bind-dyndb-ldap package built from attachment 966145 [details]
4. Add the following section to /etc/named.conf:

dynamic-db "my_db_name" {
	library "ldap.so";
	arg "uri ldap://ldap.example.com";
	arg "base cn=dns, dc=example, dc=com";
	arg "auth_method none";

5. export KRB5_KTNAME=/etc/named.keytab
6. run 'named -u named -fg' as root
7. named will start
8. run 'rndc reload' from another console and watch the error on output:

[root@localhost ~]# rndc reload
rndc: 'reload' failed: out of memory

9. press CTRL+C in the terminal you've started named or run 'rndc halt'

Actual result in 9.:
Named will freeze and the only way to stop it is to kill -9 it.

Expected result in 9. (and with attached patch):
Named will exit just normally.

Comment 9 Tereza Cerna 2015-03-04 10:36:08 UTC
Verified in version:

=== 1. console ===
# named -u named -fg
04-Mar-2015 11:25:15.231 running

=== 2. console ===
# rndc reload
server reload successful
# rndc halt

=== 1. console ===
04-Mar-2015 11:27:05.015 exiting
# echo $?

Named exited normally.

Reproduced in version:

=== 1. console ===
# named -u named -fg
04-Mar-2015 11:14:31.432 running

=== 2. console ===
# rndc reload
rndc: 'reload' failed: out of memory
# rndc halt

=== 1. console ===

Named freezed.

Comment 11 errata-xmlrpc 2015-07-22 05:50:11 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.