Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 411837 - net-ftp/vsftpd: Does not run on IPv4 and IPv6
Summary: net-ftp/vsftpd: Does not run on IPv4 and IPv6
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Server (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's FTP Packages Maintainers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-04-13 10:57 UTC by Norman Rieß
Modified: 2012-04-15 14:36 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Norman Rieß 2012-04-13 10:57:52 UTC
=net-ftp/vsftpd-3.0.0 and latest stable does not run simultaniously on IPv4 and IPv6.

Config file suggests to run two copies of the daemon.

vsftpd # grep listen ipv4.conf | grep -v "#"
listen=YES
listen_ipv6=NO

vsftpd # grep listen ipv6.conf | grep -v "#"
listen=NO
listen_ipv6=YES

Starting one Daemon works.

/etc/init.d/vsftpd.ipv6 restart
 * Starting vsftpd.ipv6 ... [ ok ]

netstat -lp | grep vsf
tcp6       0      0 [::]:ftp       [::]:*    LISTEN      9734/vsftpd

Starting the second does not. Also the rc-script does not handle the error and responds with "ok".

/etc/init.d/vsftpd.ipv4 start
 * Starting vsftpd.ipv4 ...
500 OOPS: could not bind listening IPv4 socket         [ ok ]

And now vice versa:

/etc/init.d/vsftpd.ipv6 stop
 * Stopping vsftpd.ipv6 ...                           [ ok ]
/etc/init.d/vsftpd.ipv4 restart
 * Stopping vsftpd.ipv4 ...
 * start-stop-daemon: no matching processes found     [ ok ]
 * Starting vsftpd.ipv4 ...                           [ ok ]
netstat -lp | grep vsf
tcp        0      0 *:ftp      *:*        LISTEN      9789/vsftpd

IPv6 socket is not bound, but vsftpd can not bind to it.

/etc/init.d/vsftpd.ipv6 start
 * Starting vsftpd.ipv6 ...                           [ ok ]
500 OOPS: could not bind listening IPv6 socket

Commenting out as suggested in the config file is not valid either.
/etc/init.d/vsftpd.ipv6 start
 * Starting vsftpd.ipv6 ...              [ ok ]
500 OOPS: run two copies of vsftpd for IPv4 and IPv6



emerge --info
Portage 2.1.10.49 (default/linux/amd64/10.0/server, gcc-4.5.3, glibc-2.13-r4, 3.2.12-gentoo x86_64)
=================================================================
System uname: Linux-3.2.12-gentoo-x86_64-QEMU_Virtual_CPU_version_0.15.1-with-gentoo-2.0.3
Timestamp of tree: Fri, 13 Apr 2012 10:00:01 +0000
app-shells/bash:          4.2_p20
dev-java/java-config:     2.1.11-r3
dev-lang/python:          2.7.2-r3, 3.2.2
dev-util/cmake:           2.8.6-r4
dev-util/pkgconfig:       0.26
sys-apps/baselayout:      2.0.3
sys-apps/openrc:          0.9.8.4
sys-apps/sandbox:         2.5
sys-devel/autoconf:       2.13, 2.68
sys-devel/automake:       1.11.1
sys-devel/binutils:       2.21.1-r1
sys-devel/gcc:            4.5.3-r2
sys-devel/gcc-config:     1.5-r2
sys-devel/libtool:        2.4-r1
sys-devel/make:           3.82-r1
sys-kernel/linux-headers: 3.1 (virtual/os-headers)
sys-libs/glibc:           2.13-r4
Repositories: gentoo
ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="* -@EULA AdobeFlash-10.3"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="assume-digests binpkg-logs distlocks ebuild-locks fixlafiles news parallel-fetch protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch"
FFLAGS=""
GENTOO_MIRRORS="http://distfiles.gentoo.org"
LANG="de_DE.utf8"
LC_ALL="de_DE.utf8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
LINGUAS="de"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY=""
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="X acl amd64 audacious berkdb bzip2 cli cracklib crypt cups cxx dri firefox fortran gdbm gnome gnutls gpm gtk gtk2 gtk3 iconv ipv6 jpeg matroska mjpeg mmx modules mp3 mpeg mudflap multilib ncurses nls nptl nptlonly nsplugin ogg openmp pam pcre pdf png pppd python readline session snmp sse sse2 ssl sysfs tcpd theora threads truetype unicode vaapi vorbis vpx x264 xml xorg xvid zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="de" PHP_TARGETS="php5-3" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="cirrus" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
Comment 1 Markos Chandras (RETIRED) gentoo-dev 2012-04-13 11:01:00 UTC
I presume you need to run the two copies using xinetd and not using the normal init scripts.
Comment 2 Norman Rieß 2012-04-13 11:41:20 UTC
Thank you. I tried that and found me in a similar situation:


xinetd.d # cat vsftpd_ipv4 
service ftp
{
	disable			= no
	socket_type		= stream
	protocol		= tcp
	flags			= IPv4
	wait			= no
	user			= root
	server			= /usr/sbin/vsftpd
	server_args		= /etc/vsftpd/vsftpd.conf -olisten=NO -olisten_ipv6=NO
}
xinetd.d # cat vsftpd_ipv6 
service ftp
{
	disable			= no
	socket_type		= stream
	protocol		= tcp
	flags			= IPv6
	wait			= no
	user			= root
	server			= /usr/sbin/vsftpd
	server_args		= /etc/vsftpd/vsftpd.conf -olisten=NO -olisten_ipv6=NO
}

vsftpd # grep listen  vsftpd.conf | grep -v "#"
listen=NO
listen_ipv6=NO

Apr 13 13:33:39 [start-stop-daemon] pam_unix(start-stop-daemon:session): session opened for user nobody by root(uid=0)
Apr 13 13:33:39 [xinetd] bind failed (Address already in use (errno = 98)). service = ftp
Apr 13 13:33:39 [xinetd] Service ftp failed to start and is deactivated.
Apr 13 13:33:39 [xinetd] xinetd Version 2.3.14 started with libwrap loadavg options compiled in.
Apr 13 13:33:39 [xinetd] Started working: 1 available service

netstat -lp | grep xine
tcp        0      0 *:ftp        *:*                LISTEN      14436/xinetd

I hope i got the xinetd configs right.
Comment 3 Markos Chandras (RETIRED) gentoo-dev 2012-04-13 11:50:56 UTC
I've never tried this configuration before so lets see what others think. I don't believe this is a problem with the package though, so you may want to move this to forums as bugzilla is not the ideal place for this kind of discussion
Comment 4 Norman Rieß 2012-04-13 12:07:17 UTC
I did that:
http://forums.gentoo.org/viewtopic-p-7012190.html#7012190

Thank you.
Comment 5 Norman Rieß 2012-04-15 08:47:23 UTC
Hello Markos,

please close this bug.
Setting up the IPv6 listener only allows IPv4 connections via the IPv6 socket.

tcp6       0      0 :::21                   :::*                    LISTEN      2413/vsftpd           
tcp6       0      0 176.9.155.157:21        78.51.166.103:44529     VERBUNDEN   2417/vsftpd

I was mislead by the config files statement:

"#This directive enables listening on IPv6 sockets. To listen on IPv4 and IPv6
# sockets, you must run two copies of vsftpd with two configuration files.
# Make sure, that one of the listen options is commented !!"

So maybe a sentence like "This enables IPv6 and IPv4 connections would be clearer."

Regards
Norman
Comment 6 Markos Chandras (RETIRED) gentoo-dev 2012-04-15 14:36:11 UTC
Thanks. Please contact the upstream developer to request a change in the configuration file