Bug 1473970 - dynazoom graph not working with munin-cgi-graph after recent security fix
dynazoom graph not working with munin-cgi-graph after recent security fix
Status: NEW
Product: Fedora
Classification: Fedora
Component: munin (Show other bugs)
Unspecified Linux
unspecified Severity medium
: ---
: ---
Assigned To: d. johnson
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2017-07-22 16:59 EDT by Peter "Pessoft" Kolínek
Modified: 2017-08-28 13:00 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Peter "Pessoft" Kolínek 2017-07-22 16:59:53 EDT
Description of problem:

When dynamic graph is being open via dynazoom it sends upper and lower limits to generate the graph images as empty values. This fails since the fix in parsing of input parameters of munin-cgi-graph. This has been however solved in the upstream stable-2.0 branch already.

Version-Release number of selected component (if applicable):

How reproducible:
Install munin-2.0.30-5.fc26.noarch and open some graph in detail view - via dynazoom.html.

Steps to Reproduce:
1. Open munin web interface
2. Select some host
3. Select some monitored service graph
4. Select some time range graph

Actual results:
dynazoom.html is opened, but munin-cgi-graph image is not rendered.

Expected results:
dynazoom.html is opened and munin-cgi-graph image is rendered and displayed.

Additional info:
Debug information shows that upper_limit received an empty value and has been passed to rrdtool. This is already fixed in upstream ( just few days after initial security fix ) so munin-cgi-graph checks whether it received numerical value in upper/lower_limit parameters.
Comment 1 Dan Alderman 2017-08-28 13:00:57 EDT
I have the same issue.  I think it's down to this:

2017/08/28 17:24:03 [RRD ERROR] Unable to graph @@CGITMPDIR@@/munin-cgi-graph/wobble.com/wibble.wobble.com/sensors_temp-pinpoint=1469376632,1503936632.png?&lower_limit=&upper_limit=&size_x=800&size_y=400 : option -l - Cannot convert '' to float

Which I think has been closed upstream by:


so we need a version bump?

Note You need to log in before you can comment on or make changes to this bug.