Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1511462 - scope one searches give incorrect results
scope one searches give incorrect results
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: 389-ds-base (Show other bugs)
7.5
Unspecified Unspecified
unspecified Severity high
: rc
: ---
Assigned To: Ludwig
Viktor Ashirov
Marc Muehlfeld
: Regression
: 1514051 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-11-09 07:15 EST by Ludwig
Modified: 2018-04-10 10:22 EDT (History)
7 users (show)

See Also:
Fixed In Version: 389-ds-base-1.3.7.5-10.el7
Doc Type: Bug Fix
Doc Text:
Directory Server searches with a scope set to "one" have been fixed Due to a bug in Directory Server, searches with a scope set to "one" returned all child entries instead of only the ones that matched the filter. This update fixes the problem. As a result, searches with scope "one" only return entries which are matching the filter.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-04-10 10:21:13 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:0811 None None None 2018-04-10 10:22 EDT

  None (edit)
Description Ludwig 2017-11-09 07:15:11 EST
if a onelevel search is done for an unidexed attribute, the filter test is skipped and all children of the search base are returned

see upstream ticket #49443
Comment 4 Amita Sharma 2017-12-05 06:37:13 EST
[root@qeos-38 upstream]# rpm -qa | grep 389
389-ds-base-snmp-1.3.7.5-10.el7.x86_64
389-ds-base-libs-1.3.7.5-10.el7.x86_64
389-ds-base-1.3.7.5-10.el7.x86_64

ldapadd -x -h localhost -p 389 -D "cn=Directory Manager" -w Secret123  << EOF
> dn: uid=amita2,ou=Special Users,dc=example,dc=com
> cn: amita2
> sn: amita2
> objectclass: top
> objectclass: organizationalPerson
> objectclass: inetOrgPerson
> objectclass: person
> uid: amita2
> description: anything
> mail: amita@example.com
> userpassword: Secret123
> EOF
adding new entry "uid=amita2,ou=Special Users,dc=example,dc=com"

[root@qeos-38 upstream]# ldapsearch -LLL -o ldif-wrap=no -h localhost  -p 389 -x -D "cn=directory manager" -w Secret123 -b "ou=Special Users,dc=example,dc=com" -s sub  description="Special Administrative Accounts" description
dn: ou=Special Users,dc=example,dc=com
description: Special Administrative Accounts

[root@qeos-38 upstream]# ldapsearch -LLL -o ldif-wrap=no -h localhost  -p 389 -x -D "cn=directory manager" -w Secret123 -b "ou=Special Users,dc=example,dc=com" -s one  description="anything" description
dn: uid=amita2,ou=Special Users,dc=example,dc=com
description: anything

Hence VERIFIED.
Comment 5 Viktor Ashirov 2018-01-05 10:37:30 EST
*** Bug 1514051 has been marked as a duplicate of this bug. ***
Comment 9 errata-xmlrpc 2018-04-10 10:21:13 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0811

Note You need to log in before you can comment on or make changes to this bug.