Bug 1903654 - ipa-server-install --uninstall fails on Fedora 33, returned non-zero exit status 2: Unable to disable feature: No such file or directory
Summary: ipa-server-install --uninstall fails on Fedora 33, returned non-zero exit sta...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: 35
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Florence Blanc-Renaud
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-12-02 15:13 UTC by RobbieTheK
Modified: 2022-07-06 08:41 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2022-07-06 08:41:45 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Fedora Pagure freeipa issue 9147 0 None None None 2022-05-02 16:29:07 UTC
Red Hat Issue Tracker FREEIPA-7233 0 None Waiting on Customer use different ssh user by remote execution tasks 2022-06-07 08:54:23 UTC

Description RobbieTheK 2020-12-02 15:13:07 UTC
Running ipa-server-install --uninstall -U -v --forceom  5.8.18-300.fc33.x86_64 results in the following. Note we did change the hostname and IP address since the original installation.

Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'
Removing IPA client configuration
Starting external process
args=['/usr/sbin/ipa-client-install', '--on-master', '--unattended', '--uninstall']
Unconfigured automount client failed: CalledProcessError(Command ['/usr/sbin/ipa-client-automount', '--uninstall', '--debug'] 
returned non-zero exit status 1: 'Loading StateFile from 
'/var/lib/ipa-client/sysrestore/sysrestore.state\'
Loading StateFile from \'/var/lib/ipa-client/sysrestore/sysrestore.state\'
Loading StateFile from \'/var/lib/ipa-client/sysrestore/sysrestore.state\
Starting external process
args=[\'/usr/bin/authselect\', \'disable-feature\', \'with-custom-automount\']
Process finished, return code=2
stdout=
stderr=Unable to disable feature [2]: No such file or directory
Traceback (most recent call last):
File "/usr/sbin/ipa-client-automount", line 27, in <module>
    main()
  File "/usr/lib/python3.9/site-packages/ipaclient/install/ipa_client_automount.py", line 600, in main
    configure_automount()\n  File "/usr/lib/python3.9/site-packages/ipaclient/install/ipa_client_automount.py", line 473, in configure_automount
    return uninstall(fstore, statestore)
  File "/usr/lib/python3.9/site-packages/ipaclient/install/ipa_client_automount.py", line 322, in uninstall
    tasks.disable_ldap_automount(statestore)\n  File "/usr/lib/python3.9/site-packages/ipaplatform/redhat/tasks.py", line 776, in disable_ldap_automount
    ipautil.run(authselect_cmd)
  File "/usr/lib/python3.9/site-packages/ipapython/ipautil.py", line 594, in run
    raise CalledProcessError(ipapython.ipautil.CalledProcessError: CalledProcessError(Command [\'/usr/bin/authselect\', \'disable-feature\', \'with-custom-automount\'] returned non-zero exit status 2: \'Unable to disable feature [2]: No such file or directory\
\')
')
NSS is built without support of the legacy database(DBM)
The ipa-client-install command failed. See /var/log/ipaclient-uninstall.log for more information
Process finished, return code=1
Uninstall of client side components failed!
  File "/usr/lib/python3.9/site-packages/ipapython/admintool.py", line 180, in execute
    return_value = self.run()
  File "/usr/lib/python3.9/site-packages/ipapython/install/cli.py", line 340, in run
    return cfgr.run()
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 360, in run
    return self.execute()
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 386, in execute
    for rval in self._executor():
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 431, in __runner
    exc_handler(exc_info)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception
    self._handle_exception(exc_info)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception
    six.reraise(*exc_info)
  File "/usr/lib/python3.9/site-packages/six.py", line 703, in reraise
    raise value
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 421, in __runner
    step()
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 418, in <lambda>
    step = lambda: next(self.__gen)
  File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from
    six.reraise(*exc_info)
  File "/usr/lib/python3.9/site-packages/six.py", line 703, in reraise
    raise value
  File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from
    value = gen.send(prev_value)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 655, in _configure
    next(executor)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 431, in __runner
    exc_handler(exc_info)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 460, in _handle_execute_exception
    self._handle_exception(exc_info)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 518, in _handle_exception
    self.__parent._handle_exception(exc_info)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception
    six.reraise(*exc_info)
  File "/usr/lib/python3.9/site-packages/six.py", line 703, in reraise
    raise value
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 515, in _handle_exception
    super(ComponentBase, self)._handle_exception(exc_info)
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 450, in _handle_exception
    six.reraise(*exc_info)
  File "/usr/lib/python3.9/site-packages/six.py", line 703, in reraise
    raise value
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 421, in __runner
    step()
  File "/usr/lib/python3.9/site-packages/ipapython/install/core.py", line 418, in <lambda>
    step = lambda: next(self.__gen)
  File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 81, in run_generator_with_yield_from
    six.reraise(*exc_info)
  File "/usr/lib/python3.9/site-packages/six.py", line 703, in reraise
    raise value
  File "/usr/lib/python3.9/site-packages/ipapython/install/util.py", line 59, in run_generator_with_yield_from
    value = gen.send(prev_value)
  File "/usr/lib/python3.9/site-packages/ipapython/install/common.py", line 73, in _uninstall
    for unused in self._uninstaller(self.parent):
  File "/usr/lib/python3.9/site-packages/ipaserver/install/server/__init__.py", line 581, in main
    uninstall(self)
  File "/usr/lib/python3.9/site-packages/ipaserver/install/server/install.py", line 272, in decorated
    func(installer)
  File "/usr/lib/python3.9/site-packages/ipaserver/install/server/install.py", line 1261, in uninstall
    sys.exit(rv)
DEBUG The ipa-server-install command failed, exception: SystemExit: 1

Comment 1 Rob Crittenden 2020-12-02 15:43:45 UTC
Pavel, any tips on what to investigate regarding this authselect error?

Comment 2 Pavel Březina 2020-12-08 11:39:55 UTC
It looks like with-custom-automount is not supported by the authselect version.

Please, provide output of 'authselect current' and 'cat /usr/share/authselect/default/sssd/nsswitch.conf'.

Comment 3 RobbieTheK 2020-12-08 12:30:50 UTC
(In reply to Pavel Březina from comment #2)
> It looks like with-custom-automount is not supported by the authselect
> version.
> 
> Please, provide output of 'authselect current' and 'cat
> /usr/share/authselect/default/sssd/nsswitch.conf'.

authselect current
Profile ID: sssd
Enabled features:
- with-sudo

 cat /usr/share/authselect/default/sssd/nsswitch.conf
passwd:     sss files systemd   {exclude if "with-custom-passwd"}
group:      sss files systemd   {exclude if "with-custom-group"}
netgroup:   sss files           {exclude if "with-custom-netgroup"}
automount:  sss files           {exclude if "with-custom-automount"}
services:   sss files           {exclude if "with-custom-services"}
sudoers:    files sss           {include if "with-sudo"}

Comment 4 Pavel Březina 2020-12-08 12:45:07 UTC
So with-custom-automount is clearly there. Can you also provide output of "sudo authselect --debug --trace --warn disable-feature with-custom-automount"?

Comment 5 RobbieTheK 2020-12-08 13:13:40 UTC
Apologies Pavel, wrong server here are the command results from the correct server

authselect --debug --trace --warn disable-feature with-custom-automount
Unable to disable feature [2]: No such file or directory

 authselect current
No existing configuration detected.
 cat /usr/share/authselect/default/sssd/nsswitch.conf
passwd:     sss files systemd   {exclude if "with-custom-passwd"}
group:      sss files systemd   {exclude if "with-custom-group"}
netgroup:   sss files           {exclude if "with-custom-netgroup"}
automount:  sss files           {exclude if "with-custom-automount"}
services:   sss files           {exclude if "with-custom-services"}
sudoers:    files sss           {include if "with-sudo"}

sudo authselect --debug --trace --warn disable-feature with-custom-automount
Unable to disable feature [2]: No such file or directory

Comment 6 Pavel Březina 2020-12-08 14:32:03 UTC
authselect current
No existing configuration detected.

Authselect was not used to create the configuration. Is it possible that IPA was installed before F28 in which the authselect was introduced?

IPA should probably ignore the error (RC 2: Profile or configuration was not found or the system was not configured with authselect).

Comment 7 RobbieTheK 2020-12-08 14:52:54 UTC
> Authselect was not used to create the configuration. Is it possible that IPA
> was installed before F28 in which the authselect was introduced?

Absolutely possible, yes, right around that time.

> IPA should probably ignore the error (RC 2: Profile or configuration was not
> found or the system was not configured with authselect).

That, or couldn't some other error checking be added?

Comment 8 Ben Cotton 2021-11-04 16:50:10 UTC
This message is a reminder that Fedora 33 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora 33 on 2021-11-30.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
Fedora 'version' of '33'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora 33 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora, you are encouraged  change the 'version' to a later Fedora 
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

Comment 9 Rob Crittenden 2021-11-10 15:36:57 UTC
It may be possible to detect that authconfig was used originally to configure things. We'll need to fire up an older release and compare sysrestore states and files. Ignoring the error may catch other failures as well and mask real issues.

Comment 10 Florence Blanc-Renaud 2022-05-02 16:28:32 UTC
Upstream ticket:
https://pagure.io/freeipa/issue/9147

Comment 11 Ben Cotton 2022-05-12 15:31:00 UTC
This message is a reminder that Fedora Linux 34 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 34 on 2022-06-07.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '34'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'version' 
to a later Fedora Linux version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora Linux 34 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora Linux, you are encouraged to change the 'version' to a later version
prior to this bug being closed.

Comment 12 Rob Crittenden 2022-05-13 20:18:46 UTC
PR https://github.com/freeipa/freeipa/pull/6256

Comment 13 Rob Crittenden 2022-05-13 20:19:11 UTC
master:

* ce0592bd478c184b1c0c2a75f675c5a361f4a9a4 client uninstall: handle uninstall with authconfig

Comment 14 Florence Blanc-Renaud 2022-05-14 10:45:52 UTC
Fixed upstream
ipa-4-9:
https://pagure.io/freeipa/c/d39e232e9ee28da5d4488135d264d2d1b9e671ba

Comment 15 Florence Blanc-Renaud 2022-07-06 08:41:45 UTC
Fix included in FreeIPA 4.9.10:

$ git tag --contains d39e232e9ee28da5d4488135d264d2d1b9e671ba
release-4-9-10

https://bodhi.fedoraproject.org/updates/FEDORA-2022-43d4facf0e provides freeipa-4.9.10-1.fc35 - pushed to stable
https://bodhi.fedoraproject.org/updates/FEDORA-2022-effec46c2d provides freeipa-4.9.10-1.fc36 - pushed to stable 
https://bodhi.fedoraproject.org/updates/FEDORA-2022-72757a649e provides freeipa-4.9.10-1.fc37 - pushed to stable

Marking as closed, CURRENTRELEASE


Note You need to log in before you can comment on or make changes to this bug.