Bug 1469246 - Replica install fails to configure IPA-specific temporary files/directories
Replica install fails to configure IPA-specific temporary files/directories
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
Unspecified Unspecified
high Severity unspecified
: rc
: ---
Assigned To: Petr Vobornik
: Regression, ZStream
Depends On: 1467675
Blocks: 1470125
  Show dependency treegraph
Reported: 2017-07-10 13:37 EDT by Martin Babinsky
Modified: 2018-02-28 03:52 EST (History)
13 users (show)

See Also:
Fixed In Version: ipa-4.5.0-21.el7
Doc Type: If docs needed, set a value
Doc Text:
Previously, when installing IdM replica, the installer incorrectly set the location and permissions of temporary directories. The IdM management framework requires these temporary directories to operate correctly. As a consequence, after rebooting the newly configured replica, the services tied to the management framework did not work and displayed non-specific error messages. To fix this bug, the installer now additionally adds a drop-in configuration file that re-creates the directory structure after rebooting. As a result, the IdM replica continues to work correctly after reboot.
Story Points: ---
Clone Of: 1467675
: 1470125 (view as bug list)
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
RHEL75-Replica-Plain install-after-reboot (40.33 KB, image/png)
2018-01-05 08:28 EST, Nikhil Dehadrai
no flags Details
RHEL74z_to_RHEL75_Replica_upgrade (41.54 KB, image/png)
2018-01-05 08:29 EST, Nikhil Dehadrai
no flags Details

  None (edit)
Comment 3 Martin Babinsky 2017-07-10 13:59:48 EDT
This issue can be reproduced also on RPM based installs (no containers):

1.) install a master
2.) install a replica
3.) reboot a replica
4.) try to login to WebUI on the replica

Actual outcome:

login fails due to missing /var/run/ipa directory

Expected outcome:

login works and WebUI is fully functional.

Moreover, upon replica VM restart only directory server is running, all other services are stopped. When running `ipactl restart` I see the following error:

ipactl restart
Failed to get service list from file: Unknown error when retrieving list of services from file: [Errno 2] No such file or directory: '/var/run/ipa/services.list'

This is also caused by the missing configuration in /etc/tmpfiles.d. A proper solution would be to ship a ipa-specific configuration to /usr/lib/tmpfiles.d/ (where vendor-provided configuration should be placed anyway) via spec file instead of runtime shenanigans. We are adding ipaapi user in spec anyway so we should not encounter issues with missing directory owners anymore.
Comment 6 Alexander Bokovoy 2017-07-10 16:10:49 EDT
Note that the code in 38c66896de1769077cd5b057133606ec5eeaf62b first creates the temporary directory, then runs client installation, and then configures systemd-tmpfiles to re-create temporary directories on reboot.

However, in the case of replica, we do not configure systemd-tmpfiles to re-create temporary directories. Instead, we expect upgrade code to handle this.

It looks like in the case of a replica installation we never run upgrade routine at all.

So a potential workaround would be to explicitly run ipa-server-upgrade before rebooting a replica, with or without containers.
Comment 7 Martin Babinsky 2017-07-11 06:50:50 EDT
Upstream ticket:
Comment 12 Pavel Vomacka 2017-07-12 08:17:36 EDT
Fixed upstream
Comment 14 Stanislav Laznicka 2017-08-30 07:07:12 EDT
Fixed upstream
Comment 16 Nikhil Dehadrai 2018-01-05 08:25:14 EST
ipa-server version: ipa-server-4.5.4-7.el7.x86_64

Verified the bug on the basis of following observations:
1) Log in to webui of replica is successful after reboot when REPLICA is setup on RHEL 75 as fresh install.
2) Log in to webui of replica is successful after reboot when REPLICA is setup as upgraded from RHEL74z to RHEL75.
3) Verified that '/var/run/ipa' directory exists on Replica.
4) Similar behavior is observed with IPA-master after reboot.

[root@ibm-x3650m4-01-vm-01 ~]# tail -1 /var/log/ipareplica-install.log 
2018-01-05T11:57:21Z INFO The ipa-replica-install command was successful
[root@ibm-x3650m4-01-vm-01 ~]# rpm -q ipa-server nss
[root@ibm-x3650m4-01-vm-01 ~]# ls -l /var/run/ipa/
total 8
drwxrwx---. 2 ipaapi ipaapi  60 Jan  5 08:13 ccaches
-rw-------. 1 root   root    19 Jan  5 07:58 renewal.lock
-rw-r--r--. 1 root   root   104 Jan  5 08:04 services.list
[root@ibm-x3650m4-01-vm-01 ~]# 

Thus on the basis of above observations , marking the status of bug to "VERIFIED".
Comment 17 Nikhil Dehadrai 2018-01-05 08:28 EST
Created attachment 1377493 [details]
RHEL75-Replica-Plain install-after-reboot

RHEL75-Replica-Plain install-after-reboot
Comment 18 Nikhil Dehadrai 2018-01-05 08:29 EST
Created attachment 1377496 [details]


Note You need to log in before you can comment on or make changes to this bug.