RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 768084 - [RFE] Allow automember to work on entries that have already been added
Summary: [RFE] Allow automember to work on entries that have already been added
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: 389-ds-base
Version: 6.3
Hardware: Unspecified
OS: Unspecified
high
medium
Target Milestone: rc
: ---
Assignee: Rich Megginson
QA Contact: Sankar Ramalingam
URL:
Whiteboard:
Depends On: 747403
Blocks: 389_1.3.0 690319
TreeView+ depends on / blocked
 
Reported: 2011-12-15 17:36 UTC by Nathan Kinder
Modified: 2020-09-13 19:45 UTC (History)
3 users (show)

Fixed In Version: 389-ds-base-1.2.11.15-7.el6
Doc Type: Enhancement
Doc Text:
Added three new tasks: [1] Rebuild the automembership [2] Export the changes task [1] would perform to an ldif file [3] Map changes. Reads in an ldif of entries, and writes out an ldif of the changes that would occur if these entries were added.
Clone Of: 747403
Environment:
Last Closed: 2013-02-21 08:16:54 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github 389ds 389-ds-base issues 20 0 None None None 2020-09-13 19:45:32 UTC
Red Hat Product Errata RHSA-2013:0503 0 normal SHIPPED_LIVE Moderate: 389-ds-base security, bug fix, and enhancement update 2013-02-21 08:18:44 UTC

Comment 1 Rich Megginson 2012-01-06 23:48:38 UTC
Upstream ticket:
https://fedorahosted.org/389/ticket/20

Comment 3 RHEL Program Management 2012-07-10 08:07:18 UTC
This request was not resolved in time for the current release.
Red Hat invites you to ask your support representative to
propose this request, if still desired, for consideration in
the next release of Red Hat Enterprise Linux.

Comment 4 RHEL Program Management 2012-07-10 22:57:18 UTC
This request was erroneously removed from consideration in Red Hat Enterprise Linux 6.4, which is currently under development.  This request will be evaluated for inclusion in Red Hat Enterprise Linux 6.4.

Comment 6 Sankar Ramalingam 2012-11-20 06:42:04 UTC
I encountered a failure for test autoMemTask03. It throws Could not open ldif file error while running automembers mapping tasks.

[root@dell-pe2800-01 ~]# tail -f /var/log/dirsrv/slapd-dell-pe2800-01/errors [20/Nov/2012:00:07:41 -0500] auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:17:03 -0500] auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:21:42 -0500] auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:25:21 -0500] - slapd shutting down - signaling operation threads [20/Nov/2012:01:25:21 -0500] - slapd shutting down - closing down internal subsystems and plugins [20/Nov/2012:01:25:21 -0500] - Waiting for 4 database threads to stop [20/Nov/2012:01:25:21 -0500] - All database threads now stopped [20/Nov/2012:01:25:21 -0500] - slapd stopped. [20/Nov/2012:01:25:23 -0500] - 389-Directory/1.2.11.15 B2012.321.2026 starting up [20/Nov/2012:01:25:23 -0500] - slapd started. Listening on All Interfaces port 22518 for LDAP requests [20/Nov/2012:01:26:32 -0500] auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for reading 0


Hence reassigning this bug.

Comment 7 Nathan Kinder 2012-11-20 19:21:07 UTC
(In reply to comment #6)
> I encountered a failure for test autoMemTask03. It throws Could not open
> ldif file error while running automembers mapping tasks.
> 
> [root@dell-pe2800-01 ~]# tail -f /var/log/dirsrv/slapd-dell-pe2800-01/errors
> [20/Nov/2012:00:07:41 -0500] auto-membership-plugin - Could not open ldif
> file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:17:03 -0500]
> auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for
> reading 0 [20/Nov/2012:01:21:42 -0500] auto-membership-plugin - Could not
> open ldif file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:25:21
> -0500] - slapd shutting down - signaling operation threads
> [20/Nov/2012:01:25:21 -0500] - slapd shutting down - closing down internal
> subsystems and plugins [20/Nov/2012:01:25:21 -0500] - Waiting for 4 database
> threads to stop [20/Nov/2012:01:25:21 -0500] - All database threads now
> stopped [20/Nov/2012:01:25:21 -0500] - slapd stopped. [20/Nov/2012:01:25:23
> -0500] - 389-Directory/1.2.11.15 B2012.321.2026 starting up
> [20/Nov/2012:01:25:23 -0500] - slapd started. Listening on All Interfaces
> port 22518 for LDAP requests [20/Nov/2012:01:26:32 -0500]
> auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for
> reading 0
> 
> 
> Hence reassigning this bug.

Is this SELinux related?  Do you see any AVC messages in /var/log/audit/audit?

I'd like to see the output of 'ls -lZ /tmp/Output_03.ldif'.

Comment 8 Sankar Ramalingam 2012-11-21 12:37:27 UTC
(In reply to comment #7)
> (In reply to comment #6)
> > I encountered a failure for test autoMemTask03. It throws Could not open
> > ldif file error while running automembers mapping tasks.
> > 
> > [root@dell-pe2800-01 ~]# tail -f /var/log/dirsrv/slapd-dell-pe2800-01/errors
> > [20/Nov/2012:00:07:41 -0500] auto-membership-plugin - Could not open ldif
> > file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:17:03 -0500]
> > auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for
> > reading 0 [20/Nov/2012:01:21:42 -0500] auto-membership-plugin - Could not
> > open ldif file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:25:21
> > -0500] - slapd shutting down - signaling operation threads
> > [20/Nov/2012:01:25:21 -0500] - slapd shutting down - closing down internal
> > subsystems and plugins [20/Nov/2012:01:25:21 -0500] - Waiting for 4 database
> > threads to stop [20/Nov/2012:01:25:21 -0500] - All database threads now
> > stopped [20/Nov/2012:01:25:21 -0500] - slapd stopped. [20/Nov/2012:01:25:23
> > -0500] - 389-Directory/1.2.11.15 B2012.321.2026 starting up
> > [20/Nov/2012:01:25:23 -0500] - slapd started. Listening on All Interfaces
> > port 22518 for LDAP requests [20/Nov/2012:01:26:32 -0500]
> > auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for
> > reading 0
> > 
> > 
> > Hence reassigning this bug.
> 
> Is this SELinux related?  Do you see any AVC messages in
> /var/log/audit/audit?
> 
> I'd like to see the output of 'ls -lZ /tmp/Output_03.ldif'.
ls -lZ /tmp/Output_03.ldif
-rwxrwxrwx. sramling sramling unconfined_u:object_r:dirsrv_tmp_t:s0 /tmp/Output_03.ldif

Comment 9 Sankar Ramalingam 2012-11-26 09:00:09 UTC
(In reply to comment #8)
> (In reply to comment #7)
> > (In reply to comment #6)
> > > I encountered a failure for test autoMemTask03. It throws Could not open
> > > ldif file error while running automembers mapping tasks.
> > > 
> > > [root@dell-pe2800-01 ~]# tail -f /var/log/dirsrv/slapd-dell-pe2800-01/errors
> > > [20/Nov/2012:00:07:41 -0500] auto-membership-plugin - Could not open ldif
> > > file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:17:03 -0500]
> > > auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for
> > > reading 0 [20/Nov/2012:01:21:42 -0500] auto-membership-plugin - Could not
> > > open ldif file "/tmp/Output_03.ldif" for reading 0 [20/Nov/2012:01:25:21
> > > -0500] - slapd shutting down - signaling operation threads
> > > [20/Nov/2012:01:25:21 -0500] - slapd shutting down - closing down internal
> > > subsystems and plugins [20/Nov/2012:01:25:21 -0500] - Waiting for 4 database
> > > threads to stop [20/Nov/2012:01:25:21 -0500] - All database threads now
> > > stopped [20/Nov/2012:01:25:21 -0500] - slapd stopped. [20/Nov/2012:01:25:23
> > > -0500] - 389-Directory/1.2.11.15 B2012.321.2026 starting up
> > > [20/Nov/2012:01:25:23 -0500] - slapd started. Listening on All Interfaces
> > > port 22518 for LDAP requests [20/Nov/2012:01:26:32 -0500]
> > > auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for
> > > reading 0
> > > 
> > > 
> > > Hence reassigning this bug.
> > 
> > Is this SELinux related?  Do you see any AVC messages in

Audit log message...
==> /var/log/audit/audit.log <==
type=AVC msg=audit(1353920226.164:2214675): avc:  denied  { search } for  pid=1109 comm="ns-slapd" name="/" dev=dm-2 ino=2 scontext=unconfined_u:system_r:dirsrv_t:s0 tcontext=system_u:object_r:home_root_t:s0 tclass=dir
type=SYSCALL msg=audit(1353920226.164:2214675): arch=40000003 syscall=5 success=no exit=-13 a0=9ba02468 a1=0 a2=1b6 a3=1da3d8 items=0 ppid=1 pid=1109 auid=0 uid=501 gid=501 euid=501 suid=501 fsuid=501 egid=501 sgid=501 fsgid=501 tty=(none) ses=9546 comm="ns-slapd" exe="/usr/sbin/ns-slapd" subj=unconfined_u:system_r:dirsrv_t:s0 key=(null)

> > /var/log/audit/audit?
> > 
> > I'd like to see the output of 'ls -lZ /tmp/Output_03.ldif'.
> ls -lZ /tmp/Output_03.ldif
> -rwxrwxrwx. sramling sramling unconfined_u:object_r:dirsrv_tmp_t:s0
> /tmp/Output_03.ldif

Comment 10 mreynolds 2012-11-27 16:04:36 UTC
Ok, first the logging is displaying the wrong file.  It says it can't read /tmp/Output_03.ldif, but its really the input file it can not read. 

From tet:    $DATA_LDIF/Input.ldif

I was able to reproduce the error, and putting the input ldif in /var/lib/dirsrv solved the issue.

Note: I do have selinux disabled, and it still complains unless the input file is in /var/lib/dirsrv.  So this is an enviroment issue, not a DS issue.

Comment 11 mreynolds 2012-11-27 17:17:31 UTC
I just confirmed that having the input file in /tmp also works.

Comment 12 Sankar Ramalingam 2012-12-03 11:50:39 UTC
I will change the automation scripts as suggested and verify from the official acceptance execution.

Comment 13 Sankar Ramalingam 2012-12-06 04:56:36 UTC
[root@dell-pe2800-01 ~]# /usr/bin/ldapmodify -h dell-pe2800-01.rhts.eng.bos.redhat.com -p 8311 -D "cn=directory manager" -w Secret123 -avf /home/sramling/RHEL64/testcases/DS/6.0/tet_tmp_dir/Task_Mapping.ldif 
ldap_initialize( ldap://dell-pe2800-01.rhts.eng.bos.redhat.com:8311 )
add objectClass:
	top
	extensibleObject
add basedn:
	ou=TaskEmployees,dc=autoMembers,dc=com
add filter:
	(objectClass=posixAccount)
add scope:
	sub
add ldif_in:
	/tmp/Input.ldif
add ldif_out:
	/tmp/Output_03.ldif
adding new entry "cn=Mapping,cn=automember map updates,cn=tasks,cn=config"
modify complete

From error logs:

tail -f /var/log/dirsrv/slapd-dell-pe2800-01/errors
[05/Dec/2012:23:32:37 -0500] auto-membership-plugin - Could not open ldif file "/tmp/Output_03.ldif" for reading 0

/usr/bin/ldapmodify -h dell-pe2800-01.rhts.eng.bos.redhat.com -p 8311 -D "cn=directory manager" -w Secret123 -avf /home/sramling/RHEL64/testcases/DS/6.0/tet_tmp_dir/Task_Mapping.ldif 
ldap_initialize( ldap://dell-pe2800-01.rhts.eng.bos.redhat.com:8311 )
add objectClass:
	top
	extensibleObject
add basedn:
	ou=TaskEmployees,dc=autoMembers,dc=com
add filter:
	(objectClass=posixAccount)
add scope:
	sub
add ldif_in:
	/var/lib/dirsrv/slapd-dell-pe2800-01/ldif/Input.ldif
add ldif_out:
	/tmp/Output_03.ldif
adding new entry "cn=Mapping,cn=automember map updates,cn=tasks,cn=config"
modify complete

ls -al /tmp/Output_03.ldif 
-rw-------. 1 sramling sramling 1610 Dec  5 23:30 /tmp/Output_03.ldif


It works only when the input file is kept under /var/lib/dirsrv/slapd-$inst/ldif.

Comment 14 Sankar Ramalingam 2012-12-06 09:10:13 UTC
Marking the bug as Verified since Mapping tasks accepts the value for input file as - /var/lib/dirsrv/slapd-$inst/ldif/Input.ldif.

Comment 15 Noriko Hosoi 2012-12-07 21:40:46 UTC
Additional fix for this bug is provided.

https://fedorahosted.org/389/ticket/20
Attachment 0001 [details]-Ticket-20-Allow-automember-to-work-on-entries-that.patch​ added
Improved error codes, and made two error code functions available to the plugin API

Comment 16 Sankar Ramalingam 2013-01-21 07:40:44 UTC
No more error messages aobserved from autoMembers test reports. Hence marking the bug as Verified.

Comment 18 errata-xmlrpc 2013-02-21 08:16:54 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2013-0503.html


Note You need to log in before you can comment on or make changes to this bug.