Bug 893121 - [abrt] samba-winbind-4.0.0-174.fc18: dump_core: Process /usr/sbin/winbindd was killed by signal 6 (SIGABRT)
Summary: [abrt] samba-winbind-4.0.0-174.fc18: dump_core: Process /usr/sbin/winbindd wa...
Keywords:
Status: CLOSED WORKSFORME
Alias: None
Product: Fedora
Classification: Fedora
Component: samba
Version: 18
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Guenther Deschner
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:417cbecd0f63150e4b4626afbe8...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-01-08 16:10 UTC by James MacLean
Modified: 2013-04-23 09:37 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 1051460 (view as bug list)
Environment:
Last Closed: 2013-01-10 14:10:52 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: backtrace (27.43 KB, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: cgroup (160 bytes, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: core_backtrace (3.38 KB, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: dso_list (10.75 KB, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: environ (147 bytes, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: limits (1.29 KB, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: maps (49.39 KB, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: open_fds (178 bytes, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: proc_pid_status (882 bytes, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
File: var_log_messages (11.40 KB, text/plain)
2013-01-08 16:10 UTC, James MacLean
no flags Details
ipa trustad install log (28.85 MB, text/plain)
2013-01-08 17:16 UTC, James MacLean
no flags Details

Description James MacLean 2013-01-08 16:10:03 UTC
Description of problem:
Trying to get ipa with smb support running. Finished running ipa-adtrust-install with smb bailing so tried ipactrl restart.

Version-Release number of selected component:
samba-winbind-4.0.0-174.fc18

Additional info:
backtrace_rating: 4
cmdline:        /usr/sbin/winbindd
crash_function: dump_core
executable:     /usr/sbin/winbindd
kernel:         3.7.1-2.fc18.x86_64
remote_result:  NOTFOUND
uid:            0

Truncated backtrace:
Thread no. 1 (10 frames)
 #2 dump_core at ../source3/lib/dumpcore.c:336
 #3 smb_panic_s3 at ../source3/lib/util.c:833
 #4 smb_panic at ../lib/util/fault.c:159
 #5 pdb_get_methods at ../source3/passdb/pdb_interface.c:225
 #7 pdb_capabilities at ../source3/passdb/pdb_interface.c:1225
 #8 _lsa_EnumTrustedDomainsEx at ../source3/rpc_server/lsa/srv_lsa_nt.c:3912
 #9 api_lsa_EnumTrustedDomainsEx at default/librpc/gen_ndr/srv_lsa.c:3912
 #10 rpcint_dispatch at ../source3/rpc_server/rpc_ncacn_np.c:133
 #11 rpcint_bh_raw_call_send at ../source3/rpc_server/rpc_ncacn_np.c:220
 #12 dcerpc_binding_handle_raw_call_send at ../librpc/rpc/binding_handle.c:133

Comment 1 James MacLean 2013-01-08 16:10:07 UTC
Created attachment 674922 [details]
File: backtrace

Comment 2 James MacLean 2013-01-08 16:10:09 UTC
Created attachment 674923 [details]
File: cgroup

Comment 3 James MacLean 2013-01-08 16:10:11 UTC
Created attachment 674924 [details]
File: core_backtrace

Comment 4 James MacLean 2013-01-08 16:10:14 UTC
Created attachment 674925 [details]
File: dso_list

Comment 5 James MacLean 2013-01-08 16:10:15 UTC
Created attachment 674926 [details]
File: environ

Comment 6 James MacLean 2013-01-08 16:10:17 UTC
Created attachment 674927 [details]
File: limits

Comment 7 James MacLean 2013-01-08 16:10:19 UTC
Created attachment 674928 [details]
File: maps

Comment 8 James MacLean 2013-01-08 16:10:21 UTC
Created attachment 674929 [details]
File: open_fds

Comment 9 James MacLean 2013-01-08 16:10:22 UTC
Created attachment 674930 [details]
File: proc_pid_status

Comment 10 James MacLean 2013-01-08 16:10:24 UTC
Created attachment 674931 [details]
File: var_log_messages

Comment 11 Alexander Bokovoy 2013-01-08 16:25:04 UTC
Please show your /var/log/ipaserver-install.log. The requirement to start smb.service in this setup is to have ipa-adtrust-install run successfully.

Comment 12 James MacLean 2013-01-08 17:16:12 UTC
Created attachment 674972 [details]
ipa trustad install log

Requested file.

Comment 13 Alexander Bokovoy 2013-01-08 17:37:57 UTC
In the log there is indicated success of ipa-adtrust-install run. Not sure what your original description of 'smb bailing' means then.

In /var/log/messages I can see that winbindd was not able to authenticate to LDAP server using kerberos keytab and therefore everything failed. We can start from here.

1. Please show 'klist -k /etc/smb/samba.keytab'
2. Please show 'klist -c /run/samba/krb5cc_samba'
3. Try to authenticate using the samba.keytab and connect to the LDAP server manually as root (and show output here, replace dc=example,dc=com by correct DN):
  OLDKRB5CCNAME=$KRB5CCNAME
  export KRB5CCNAME=/run/samba/krb5cc_samba
  klist
  ldapsearch -Y GSSAPI -b "dc=example,dc=com" uid=admin
  export KRB5CCNAME=/tmp/test.ccache
  kinit -kt /etc/smb/samba.keytab
  klist
  ldapsearch -Y GSSAPI -b "dc=example,dc=com" uid=admin
  kdestroy
  export KRB5CCNAME=$OLDKRB5CCNAME

One possible issue is that /run/samba/krb5cc_samba is from some old run and has a ticket obtained before re-install of FreeIPA (if any) so it is invalid and not accepted by the KDC.

Comment 14 James MacLean 2013-01-08 18:57:05 UTC
Hi Alexander,

I had been installing/uninstalling ipa and the adtrust parts since this was reported but was unable to get the winbind/smb piece to start. 

Then, as you suggested I removed the /run/samba/krb5cc_samba file and was able to carry on from "ipa-adtrust-install". 

Samba appears to be up and the testing shows it is ok. Sorry I have do not have it in a bad state to try the above. I will report back if it happens again.

JES

Comment 15 Alexander Bokovoy 2013-01-08 19:04:54 UTC
Thanks. I tried to guard against these invalid tickets in the latest releases but sometimes the code is not robust enough. The case of multiple re-installs is rather edge case for testing/development purposes though.

Feel free to close the bug.

Comment 16 James MacLean 2013-01-08 19:07:31 UTC
May I ask if you can confirm that currently you can not have an IPA-to-IPA 2 way trust and that you can only have a IPA-to-AD trust? I have been trying that without success and did not want to keep trying if it is a known limitation.

Thanks again,
JES

Comment 17 Alexander Bokovoy 2013-01-08 20:11:06 UTC
IPA-to-AD is two-way trust. IPA-to-IPA trusts are not implemented yet. Feel free to file an RFE ticket in FreeIPA's Trac instance at https://fedorahosted.org/freeipa/.

Comment 18 Alexander Bokovoy 2013-01-10 14:10:52 UTC
Closing.

Comment 19 Gergely Polonkai 2013-02-13 09:34:34 UTC
I have a Fedora 18 install on my company machine, set up to login using the Active Directory services. I got this same problem today, and I have nothing to do with IPA. However, abrt couldn't report the problem because it's the "duplicate" of this one...

Comment 20 Marek Marczykowski 2013-04-22 22:15:29 UTC
Same here.

Looking at backtrace it have something to do with printing. From logs:
"PANIC: assert failed at ../source3/printing/printing.c(481): pjob->jobid == jobid"

Comment 21 Andreas Schneider 2013-04-23 09:37:34 UTC
Sorry, but there is no printing support in winbind at all.


Note You need to log in before you can comment on or make changes to this bug.