Bug 1247556 - Insufficient rights to stop service failed with errno 1 "Interactive authentication required"
Insufficient rights to stop service failed with errno 1 "Interactive authenti...
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: systemd (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: systemd-maint
Depends On:
  Show dependency treegraph
Reported: 2015-07-28 06:14 EDT by Yongcheng Yang
Modified: 2016-06-02 04:56 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2016-06-02 04:56:57 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Yongcheng Yang 2015-07-28 06:14:39 EDT
Description of problem:
Test the "Insufficient rights" in current RHEL-7.2, the return status has changed from "4" to "1", and the warning messages also changed.

As the LSB said, the non-zero status code has different meanings:
"1	generic or unspecified error (current practice)"
"4	user had insufficient privilege"

So maybe we should still use the errno "4" for insufficient rights error.

And RHEL-7.1 does not has this issue.

Version-Release number of selected component (if applicable):
RHEL-7.2 with kernel-3.10.0-295.el7.x86_64

How reproducible:

Steps to Reproduce:
1. useradd test
2. su test -c "service nfs stop"

Actual results:
[root@hp-dl385pg8-03 ~]#  su test -c "service nfs stop"
Redirecting to /bin/systemctl stop  nfs.service
Error creating textual authentication agent: Error opening current controlling terminal for the process (`/dev/tty'): No such device or address (polkit-error-quark, 0)
Failed to stop nfs.service: Interactive authentication required.
[root@hp-dl385pg8-03 ~]# echo $?
^^<<<<<<<<<<<<<<<<<<<<<<<<<<<<< RHEL-7.2 kernel-3.10.0-295.el7.x86_64
[root@hp-dl385pg8-03 ~]# 

Expected results:
[root@hp-dl580g7-04 ~]# id testuserqa
uid=1001(testuserqa) gid=1001(testuserqa) groups=1001(testuserqa)
[root@hp-dl580g7-04 ~]# su testuserqa -c "service nfs-idmapd stop"
Redirecting to /bin/systemctl stop  nfs-idmapd.service
Failed to issue method call: Access denied
[root@hp-dl580g7-04 ~]# echo $?
^^<<<<<<<<<<<<<<<<<<<<<<<<<<<<< RHEL-7.1 kernel-3.10.0-229.el7.x86_64
[root@hp-dl580g7-04 ~]# 

Additional info:
Comment 2 Lukáš Nykrýn 2015-07-30 10:04:58 EDT
Yes this behavior has changed because now we support polkit authentication.
Comment 3 Yongcheng Yang 2016-06-02 04:56:57 EDT
According to comment 2, this is the expected result.

So close this bug as NOTABUG, please correct me if there's any concern.

Note You need to log in before you can comment on or make changes to this bug.