#5571 [tracker] 389 segfault during ipa-backup
Closed: Fixed None Opened 8 years ago by webrat.

Hi,

I'm using FreeIPA (4.2.0) on CentOS 7.2. While running the daily Backup via {{{/sbin/ipa-backup -q}}} sometimes I see that it does not complete successfully

Preparing backup on auth.foobar.tv
Stopping IPA services
Backing up userRoot in FOOBAR-TV to LDIF
db2ldif failed: [05/Jan/2016:09:11:32 +0100] - userRoot: entry cache size: 10485760B; db size: 802816B
[05/Jan/2016:09:11:32 +0100] - WARNING: changelog: entry cache size 2097152B is less than db size 7856128B; We recommend to increase the entry cache size nsslapd-cachememsize.
[05/Jan/2016:09:11:32 +0100] - Total entry cache size: 12582912B; dbcache size: 10000000B; available memory size: 3930042368B
[05/Jan/2016:09:11:32 +0100] ldbm_usn_init - backend: changelog (global mode)
[05/Jan/2016:09:11:32 +0100] ldbm_usn_init - backend: userRoot (global mode)
[05/Jan/2016:09:11:32 +0100] schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=foobar,dc=tv
[05/Jan/2016:09:11:32 +0100] schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=foobar,dc=tv
[05/Jan/2016:09:11:32 +0100] schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=foobar,dc=tv
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=dns,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=dns,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=keys,cn=sec,cn=dns,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=dns,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=dns,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=groups,cn=compat,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=computers,cn=compat,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=ng,cn=compat,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target ou=sudoers,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=users,cn=compat,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=vaults,cn=kra,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=ad,cn=etc,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] NSACLPlugin - The ACL target cn=casigningcert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=foobar,dc=tv does not exist
[05/Jan/2016:09:11:32 +0100] - Skipping CoS Definition cn=Password Policy,cn=accounts,dc=foobar,dc=tv--no CoS Templates found, which should be added before the CoS Definition.
[05/Jan/2016:09:11:32 +0100] ldbm_back_add - conn=0 op=0 modify_term: old_entry=0x0, new_entry=0x0
ldiffile: /var/lib/dirsrv/slapd-FOOBAR-TV/ldif/FOOBAR-TV-userRoot.ldif
[05/Jan/2016:09:11:32 +0100] ldbm_back_delete - conn=0 op=0 modify_update_all: old_entry=0x7fe9f17fdee0, new_entry=0x7fe9cc003390, rc=0
[05/Jan/2016:09:11:32 +0100] - export userRoot: Processed 418 entries (100%).
[05/Jan/2016:09:11:32 +0100] ldbm_back_delete - conn=0 op=0 modify_switch_entries: old_entry=0x7fe9f17fdee0, new_entry=0x7fe9cc003390, rc=0
[05/Jan/2016:09:11:32 +0100] ldbm_back_delete - conn=0 op=0 modify_term: old_entry=0x7fe9f17fdee0, new_entry=0x7fe9cc003390, in_cache=1
/usr/sbin/db2ldif: line 157:  2196 Segmentation fault      /usr/sbin/ns-slapd db2ldif -D /etc/dirsrv/slapd-FOOBAR-TV -n userRoot -a "/var/lib/dirsrv/slapd-FOOBAR-TV/ldif/FOOBAR-TV-userRoot.ldif" -r

I can not reproduce this issue always, but it happens roughly every second time.
Any hints on how this could be fixed?


389-ds bug fixed https://fedorahosted.org/389/ticket/48388 (1.3.5). The bug was not backported to Fedora.

IPA should raise 389 requires when it happens. Changing to tracker ticket.

Fixed in 389-ds-base-1.3.4.8-1.fc23

Metadata Update from @webrat:
- Issue assigned to someone
- Issue set to the milestone: FreeIPA 4.3.1

7 years ago

Login to comment on this ticket.

Metadata