Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 132550 - sys-auth/nss_ldap-249 can cause boot problems
Summary: sys-auth/nss_ldap-249 can cause boot problems
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High critical
Assignee: Gentoo LDAP project
URL:
Whiteboard:
Keywords:
: 139868 149935 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-05-07 04:49 UTC by Markus Ullmann (RETIRED)
Modified: 2006-10-05 07:36 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Markus Ullmann (RETIRED) gentoo-dev 2006-05-07 04:49:13 UTC
As this release fixes some bugs from previous stable version

http://bugs.gentoo.org/show_bug.cgi?id=125348
http://bugs.gentoo.org/show_bug.cgi?id=132006

please test and mark stable
Comment 1 Tobias Scherbaum (RETIRED) gentoo-dev 2006-05-11 05:55:47 UTC
ppc stable
Comment 2 Markus Rothe (RETIRED) gentoo-dev 2006-05-16 13:02:55 UTC
stable on ppc64
Comment 3 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2006-05-16 13:13:41 UTC
Stable on hppa, mips, sparc.
Comment 4 Chris Gianelloni (RETIRED) gentoo-dev 2006-05-25 13:12:22 UTC
x86 done
Comment 5 Christophe PEREZ 2006-05-25 19:09:44 UTC
not for me :
http://bugs.gentoo.org/show_bug.cgi?id=125348
Comment 6 Simon Stelling (RETIRED) gentoo-dev 2006-06-11 03:20:41 UTC
stable on amd64 not last and either least ;)
Comment 7 Paulo Ferreira 2006-08-20 05:02:31 UTC
This Bug Report from Debian:

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375077

happened with me?

I had a working installation with 239-r1, with 249 it failed with this problem.

Had to downgrade to 239-r1 (everything worked fine with no conf changes).
Comment 8 Peter Bienstman (RETIRED) gentoo-dev 2006-10-03 05:10:36 UTC
Just like the last reporter, I also got bitten by Debian bug 375077 (both on x86 and amd64), so I had to downgrade to 239-r1.

This is actually pretty serious, as it caused our systems to take half a day in order to boot up! Tracking down that ldap was the problem was far from trivial.
Comment 9 Peter Bienstman (RETIRED) gentoo-dev 2006-10-03 05:13:36 UTC
*** Bug 139868 has been marked as a duplicate of this bug. ***
Comment 10 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2006-10-03 13:37:58 UTC
pbienst: please test nss_ldap-253 instead for your boot problems.
it will be going stable in two weeks if there are no issues.
Comment 11 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2006-10-03 13:42:40 UTC
*** Bug 149935 has been marked as a duplicate of this bug. ***
Comment 12 Peter Bienstman (RETIRED) gentoo-dev 2006-10-04 04:28:43 UTC
The update to 253 did not solve the issue. Only 239-r1 works fine. The Debian bug report contains lots of background info, BTW.
Comment 13 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2006-10-04 13:25:15 UTC
pbienst: the 253 change and the changes it introduces to /etc/ldap.conf resolve the insanely long timeout issues on EVERY machine that I've tested it on. I did get some initial reports of it not working, but it was user error because they didn't apply the changes to /etc/ldap.conf with etc-update.

Also, make SURE you are using new enough baselayout (/etc/init.d/bootmisc has chown commented out)  and udev (the tpm/tss entries are removed) where our folks have removed all other lookups that would go to ldap because the entries weren't in files.


Yes, our solution path is different than debians, but that is because 'bind_policy soft' and changing ldap.conf/nsswitch.conf isn't a nice thing to do, and you won't find automatic config file changes in Gentoo init scripts last time I checked - we opted to fix the problem at it's source instead, rather than trying to avoid it.

If there are still lookups going to LDAP during early, you need to fix them on your system - the latest baselayout makes certain they don't happen, but you should check your system esp if you have other stuff that may do said lookups.
Comment 14 Peter Bienstman (RETIRED) gentoo-dev 2006-10-05 01:50:14 UTC
Thanks, that helped. udev-087-r1 did not have tpm commented out in udev-rules, so I did that manually. Which udev version has this fix?
Comment 15 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2006-10-05 07:36:46 UTC
pbienst: >=udev-99 is where it's removed.

i'm going to close this bug now, as the actual nss_ldap issues have been fixed for quite some while.