Bug 1165796
| Summary: | bind-dyndb-ldap crashes if server is shutting down and connection to LDAP is down | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Scott Poore <spoore> | ||||
| Component: | bind-dyndb-ldap | Assignee: | Tomas Krizek <tkrizek> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Scott Poore <spoore> | ||||
| Severity: | low | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | 7.0 | CC: | mkosek, pspacek | ||||
| Target Milestone: | rc | ||||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | bind-dyndb-ldap-11.1-1.el7 | Doc Type: | No Doc Update | ||||
| Doc Text: |
undefined
|
Story Points: | --- | ||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2017-08-01 19:27:49 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | |||||||
| Bug Blocks: | 1205796, 1298243 | ||||||
| Attachments: |
|
||||||
|
Description
Scott Poore
2014-11-19 17:52:57 UTC
Created attachment 959104 [details]
named abrt email
This is a harmless bug in bind-dyndb-ldap error handling. It can crash during shutdown if something is wrong with LDAP connection but the daemon is shutting down anyway so it should not cause any huge problem. It seems that it affects all versions from at least 2011. Most important part of the log is: Nov 25 10:20:56 kvm-guest-01 ns-slapd: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (No Kerberos credentials available) Nov 25 10:20:57 kvm-guest-01 systemd: Stopping Berkeley Internet Name Domain (DNS)... Nov 25 10:20:57 kvm-guest-01 named[4805]: received control channel command 'stop' Nov 25 10:20:57 kvm-guest-01 named[4805]: shutting down: flushing changes Nov 25 10:20:57 kvm-guest-01 named[4805]: stopping command channel on 127.0.0.1#953 Nov 25 10:20:57 kvm-guest-01 named[4805]: stopping command channel on ::1#953 Nov 25 10:20:57 kvm-guest-01 named[4805]: ldap_helper.c:644: REQUIRE(pthread_kill(ldap_inst->watcher, 10) == 0) failed, back trace Nov 25 10:20:57 kvm-guest-01 named[4805]: #0 0x7fba3d78e380 in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #1 0x7fba3b9801ca in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #2 0x7fba36f33cdd in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #3 0x7fba36f3c591 in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #4 0x7fba36f3c6aa in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #5 0x7fba3cfb1659 in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #6 0x7fba3d7a499b in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #7 0x7fba3b9a28a6 in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #8 0x7fba3b557df3 in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: #9 0x7fba3a8003dd in ?? Nov 25 10:20:57 kvm-guest-01 named[4805]: exiting (due to assertion failure) As far as I know, this is not currently causing a problem. I think we could certainly move this out to 7.2. Upstream ticket: https://fedorahosted.org/bind-dyndb-ldap/ticket/149 Fixed upstream master: https://git.fedorahosted.org/cgit/bind-dyndb-ldap.git/commit/?id=edd8c0552eb7e977a961c9492eb18c177685e438 bind-dyndb-ldap-11.1-1.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-56aa9caed6 bind-dyndb-ldap-11.1-1.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-56aa9caed6 bind-dyndb-ldap-11.1-2.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-f6f66523b8 bind-dyndb-ldap-11.1-2.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-f6f66523b8 I've removed this bug from Fedora Update System, since it's filed for RHEL. This appears to be fixed. Verified. Version :: Results :: Verified. Version :: ipa-server-4.5.0-13.el7.x86_64 Results :: On rhel7.4 server, with fresh install, I tried ipa shutdown with dirsrv already down. [root@rhel7-4 yum.repos.d]# systemctl stop dirsrv@EXAMPLE-COM [root@rhel7-4 yum.repos.d]# ipactl stop Stopping ipa-dnskeysyncd Service Stopping ipa-otpd Service Stopping pki-tomcatd Service Stopping ntpd Service Stopping ipa-custodia Service Stopping httpd Service Stopping named Service Stopping kadmin Service Stopping krb5kdc Service Stopping Directory Service ipa: INFO: The ipactl command was successful From /var/log/messages: May 25 11:30:54 rhel7-4 systemd: Stopping Berkeley Internet Name Domain (DNS) with native PKCS#11... May 25 11:30:54 rhel7-4 named-pkcs11[11179]: received control channel command 'stop' May 25 11:30:54 rhel7-4 named-pkcs11[11179]: shutting down: flushing changes May 25 11:30:54 rhel7-4 named-pkcs11[11179]: stopping command channel on 127.0.0.1#953 May 25 11:30:54 rhel7-4 named-pkcs11[11179]: stopping command channel on ::1#953 May 25 11:30:54 rhel7-4 named-pkcs11[11179]: unloading DynDB instance 'ipa' May 25 11:30:54 rhel7-4 named-pkcs11[11179]: zone example.com/IN: shutting down May 25 11:30:54 rhel7-4 named-pkcs11[11179]: no longer listening on ::#53 May 25 11:30:54 rhel7-4 named-pkcs11[11179]: no longer listening on 127.0.0.1#53 May 25 11:30:54 rhel7-4 named-pkcs11[11179]: no longer listening on 192.168.122.74#53 May 25 11:30:54 rhel7-4 named-pkcs11[11179]: exiting And I also ran an upgrade from 7.3 to 7.4 and did not see a named crash. From the log: May 25 12:11:54 master named-pkcs11[4161]: received control channel command 'stop' May 25 12:11:54 master named-pkcs11[4161]: shutting down: flushing changes May 25 12:11:54 master named-pkcs11[4161]: stopping command channel on 127.0.0.1#953 May 25 12:11:54 master named-pkcs11[4161]: stopping command channel on ::1#953 May 25 12:11:54 master named-pkcs11[4161]: unloading DynDB instance 'ipa' May 25 12:11:54 master named-pkcs11[4161]: zone testrelm.test/IN: shutting down May 25 12:11:54 master named-pkcs11[4161]: no longer listening on ::#53 May 25 12:11:54 master named-pkcs11[4161]: no longer listening on 127.0.0.1#53 May 25 12:11:54 master named-pkcs11[4161]: no longer listening on 192.168.122.71#53 May 25 12:11:54 master named-pkcs11[4161]: exiting May 25 12:11:54 master systemd: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11. May 25 12:11:54 master systemd: Stopped Berkeley Internet Name Domain (DNS) with native PKCS#11. May 25 12:11:54 master systemd: Stopping Kerberos 5 Password-changing and Administration... May 25 12:11:54 master systemd: kadmin.service: main process exited, code=exited, status=2/INVALIDARGUMENT May 25 12:11:54 master systemd: Stopped Kerberos 5 Password-changing and Administration. May 25 12:11:54 master systemd: Unit kadmin.service entered failed state. May 25 12:11:54 master systemd: kadmin.service failed. May 25 12:11:54 master systemd: Stopping Kerberos 5 KDC... May 25 12:11:54 master systemd: Stopped Kerberos 5 KDC. May 25 12:11:54 master systemd: Stopping 389 Directory Server TESTRELM-TEST.... It should be noted that it looked like DS stopped after named. So, this may not even be a typical possible issue during upgrade anymore due to other changes. Marking verified and as sanity only. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2120 |