--On Thursday, November 09, 2006 2:20 AM +0000 lsherida(a)nccs.nasa.gov wrote:
> Full_Name: Lee Sheridan
> Version: 2.3.27
> OS: Debian GNU/Linux (etch)
> URL: ftp://ftp.openldap.org/incoming/
> Submission from: (NULL) (69.168.13.7)
>
>
> In servers/slapd/overlays/ppolicy.c, check_password_quality function, at
> line 530, the value of the 'ok' variable is discarded by unconditionally
> assigning it the value LDAP_SUCCESS.
>
> The variable is the return code of the user-defined check_password()
> function, which is assigned at line 522. The next if-then-else block is
> checking to see if the module reported an error, at which point 'ok'
> would be assigned LDAP_OTHER regardless of what check_password()
> returned. A superfluous else block appears after this check, assigning
> 'ok' to LDAP_SUCCESS.
>
> It works fine for me if I remove the else block.
Howard checked in a fix to HEAD for this last night, please test.
--Quanah
--
Quanah Gibson-Mount
Principal Software Developer
ITS/Shared Application Services
Stanford University
GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html
--On Thursday, November 09, 2006 5:08 PM +0000 hardimankevin(a)yahoo.com
wrote:
> --0-1753053770-1163092074=:90949
> Content-Type: text/plain; charset=ascii
> Content-Transfer-Encoding: quoted-printable
>
> Buchan,=0A=0ANot sure what to say - I can reproduce this error with the
> Man= driva packages and from source (which leads me to believe it has
> nothing to= do with the packaging) with a 100% rate. I had sent Howard
> Chu an email l= ast night with much more detail; if you'd like me to
> forward that I will.= =0A=0A -kph=0A=0A=0A----- Original Message
>
You should send responses with more detail to the ITS, not to individual
people. This allows all developers and other involved to have the full
information.
--Quanah
--
Quanah Gibson-Mount
Principal Software Developer
ITS/Shared Application Services
Stanford University
GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html
--0-1753053770-1163092074=:90949
Content-Type: text/plain; charset=ascii
Content-Transfer-Encoding: quoted-printable
Buchan,=0A=0ANot sure what to say - I can reproduce this error with the Man=
driva packages and from source (which leads me to believe it has nothing to=
do with the packaging) with a 100% rate. I had sent Howard Chu an email l=
ast night with much more detail; if you'd like me to forward that I will.=
=0A=0A -kph=0A=0A=0A----- Original Message ----=0AFrom: Buchan Milne <bg=
milne(a)staff.telkomsa.net>=0ATo: hardimankevin(a)yahoo.com=0ACc: openldap-its@=
openldap.org=0ASent: Thursday, November 9, 2006 11:07:10 AM=0ASubject: Re: =
(ITS#4739) Server crashes every time alias is dereferenced=0A=0AOn Wednesda=
y 08 November 2006 21:18, hardimankevin(a)yahoo.com wrote:=0A> Full_Name: Kev=
in Hardiman=0A> Version: 2.3.27=0A> OS: Linux (Mandriva 2007)=0A> URL: ftp:=
//ftp.openldap.org/incoming/=0A> Submission from: (NULL) (24.90.130.182)=0A=
>=0A>=0A> Using the very simple alias below, OpenLDAP will crash every time=
it is=0A> dereferenced:=0A>=0A> dn: uid=3Dtest,ou=3DUsers,ou=3Dbladiant,ou=
=3Dsmb,ou=3DCore Services,dc=3Dexample,dc=3Dcom=0A> objectClass: alias=0A> =
objectclass: extensibleObject=0A> uid: test=0A> aliasedObjectName: uid=3Dte=
st,ou=3DUsers,dc=3Dexample,dc=3Dcom=0A>=0A> This error has been experience =
with OpenLDAP releases 2.3.6 and 2.3.27,=0A> both in the form of provided M=
andriva packages. I also have seen a number=0A> of references to this erro=
r in previous releases, with no explicit fix. =0A> Please advise.=0A=0A=0AC=
an't reproduce:=0A=0A$ ldapsearch -h localhost -LLL -s children -a never -=
x -b "ou=3DTest =0AAliases,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom"=0Adn: uid=3D=
bgmilne,ou=3DTest Aliases,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom=0AobjectClass:=
alias=0AobjectClass: extensibleObject=0Auid: bgmilne=0AaliasedObjectName: =
uid=3Dbgmilne,ou=3DPeople,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom=0A=0A$ ldapsea=
rch -h localhost -LLL -s children -a always -x -b "ou=3DTest =0AAliases,dc=
=3Dranger,dc=3Ddnsalias,dc=3Dcom" objectclass=0Adn: uid=3Dbgmilne,ou=3DPeop=
le,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom=0AobjectClass: mailRecipient=0Aobject=
Class: person=0AobjectClass: organizationalPerson=0AobjectClass: inetOrgPer=
son=0AobjectClass: posixAccount=0AobjectClass: top=0AobjectClass: kerberosS=
ecurityObject=0AobjectClass: shadowAccount=0AobjectClass: sambaSamAccount=
=0A=0A$ rpm -q openldap-servers=0Aopenldap-servers-2.3.27-1mdv2007.0=0A=0A$=
rpm -q openldap-servers --qf "%{PACKAGER}\n"=0ABuchan Milne <bgmilne@mandr=
iva.org>=0A=0A=0ARegards,=0ABuchan=0A=0A-- =0ABuchan Milne=0AISP Systems Sp=
ecialist - Monitoring/Authentication Team Leader=0AB.Eng,RHCE(8030047890107=
97),LPIC-2(LPI000074592)=0A=0A=0A=0A=0A=0A=0A=0A =0A_______________________=
_____________________________________________________________=0ADo you Yaho=
o!?=0AEveryone is raving about the all-new Yahoo! Mail beta.=0Ahttp://new.m=
ail.yahoo.com
--0-1753053770-1163092074=:90949
Content-Type: text/html; charset=ascii
Content-Transfer-Encoding: quoted-printable
<html><head><style type=3D"text/css"><!-- DIV {margin:0px;} --></style></he=
ad><body><div style=3D"font-family:arial, helvetica, sans-serif;font-size:1=
0pt"><div style=3D"font-family: arial,helvetica,sans-serif; font-size: 10pt=
;">Buchan,<br><br>Not sure what to say - I can reproduce this error with th=
e Mandriva packages and from source (which leads me to believe it has nothi=
ng to do with the packaging) with a 100% rate. I had sent Howard Chu =
an email last night with much more detail; if you'd like me to forward that=
I will.<br><br> -kph<br><br><br><div style=3D"font-famil=
y: times new roman,new york,times,serif; font-size: 12pt;">----- Original M=
essage ----<br>From: Buchan Milne <bgmilne(a)staff.telkomsa.net><br>To:=
hardimankevin(a)yahoo.com<br>Cc: openldap-its(a)openldap.org<br>Sent: Thursday=
, November 9, 2006 11:07:10 AM<br>Subject: Re: (ITS#4739) Server crashes ev=
ery time alias is dereferenced<br><br><div>On Wednesday 08 November 2006 21=
:18,
hardimankevin(a)yahoo.com wrote:<br>> Full_Name: Kevin Hardiman<br>> V=
ersion: 2.3.27<br>> OS: Linux (Mandriva 2007)<br>> URL: ftp://ftp.ope=
nldap.org/incoming/<br>> Submission from: (NULL) (24.90.130.182)<br>>=
<br>><br>> Using the very simple alias below, OpenLDAP will crash eve=
ry time it is<br>> dereferenced:<br>><br>> dn: uid=3Dtest,ou=3DUse=
rs,ou=3Dbladiant,ou=3Dsmb,ou=3DCore Services,dc=3Dexample,dc=3Dcom<br>> =
objectClass: alias<br>> objectclass: extensibleObject<br>> uid: test<=
br>> aliasedObjectName: uid=3Dtest,ou=3DUsers,dc=3Dexample,dc=3Dcom<br>&=
gt;<br>> This error has been experience with OpenLDAP releases 2.3.6 and=
2.3.27,<br>> both in the form of provided Mandriva packages.  =
;I also have seen a number<br>> of references to this error in previous =
releases, with no explicit fix. <br>> Please advise.<br><br><br>Can't re=
produce:<br><br>$ ldapsearch -h localhost -LLL -s children -a never &n=
bsp;-x -b "ou=3DTest
<br>Aliases,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom"<br>dn: uid=3Dbgmilne,ou=3D=
Test Aliases,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom<br>objectClass: alias<br>ob=
jectClass: extensibleObject<br>uid: bgmilne<br>aliasedObjectName: uid=3Dbgm=
ilne,ou=3DPeople,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom<br><br>$ ldapsearch -h =
localhost -LLL -s children -a always -x -b "ou=3DTest <br>Aliase=
s,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom" objectclass<br>dn: uid=3Dbgmilne,ou=
=3DPeople,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom<br>objectClass: mailRecipient<=
br>objectClass: person<br>objectClass: organizationalPerson<br>objectClass:=
inetOrgPerson<br>objectClass: posixAccount<br>objectClass: top<br>objectCl=
ass: kerberosSecurityObject<br>objectClass: shadowAccount<br>objectClass: s=
ambaSamAccount<br><br>$ rpm -q openldap-servers<br>openldap-servers-2.3.27-=
1mdv2007.0<br><br>$ rpm -q openldap-servers --qf "%{PACKAGER}\n"<br>Buchan =
Milne <bgmilne(a)mandriva.org><br><br><br>Regards,<br>Buchan<br><br>-- =
<br>Buchan Milne<br>ISP Systems Specialist -
Monitoring/Authentication Team Leader<br>B.Eng,RHCE(803004789010797),LPIC-=
2(LPI000074592)<br></div></div><br></div></div><br>=0A=0A<hr size=3D1>Every=
one is raving about <a href=3D"http://us.rd.yahoo.com/evt=3D45083/*http://a=dvision.webevents.yahoo.com/mailbeta">the all-new Yahoo! Mail beta.</a></bo=
dy></html>
--0-1753053770-1163092074=:90949--
--nextPart2681002.ZbxIqWnAlZ
Content-Type: text/plain;
charset="iso-8859-6"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline
On Wednesday 08 November 2006 21:18, hardimankevin(a)yahoo.com wrote:
> Full_Name: Kevin Hardiman
> Version: 2.3.27
> OS: Linux (Mandriva 2007)
> URL: ftp://ftp.openldap.org/incoming/
> Submission from: (NULL) (24.90.130.182)
>
>
> Using the very simple alias below, OpenLDAP will crash every time it is
> dereferenced:
>
> dn: uid=3Dtest,ou=3DUsers,ou=3Dbladiant,ou=3Dsmb,ou=3DCore Services,dc=3D=
example,dc=3Dcom
> objectClass: alias
> objectclass: extensibleObject
> uid: test
> aliasedObjectName: uid=3Dtest,ou=3DUsers,dc=3Dexample,dc=3Dcom
>
> This error has been experience with OpenLDAP releases 2.3.6 and 2.3.27,
> both in the form of provided Mandriva packages. I also have seen a number
> of references to this error in previous releases, with no explicit fix.=20
> Please advise.
Can't reproduce:
$ ldapsearch -h localhost -LLL -s children -a never -x -b "ou=3DTest=20
Aliases,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom"
dn: uid=3Dbgmilne,ou=3DTest Aliases,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom
objectClass: alias
objectClass: extensibleObject
uid: bgmilne
aliasedObjectName: uid=3Dbgmilne,ou=3DPeople,dc=3Dranger,dc=3Ddnsalias,dc=
=3Dcom
$ ldapsearch -h localhost -LLL -s children -a always -x -b "ou=3DTest=20
Aliases,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom" objectclass
dn: uid=3Dbgmilne,ou=3DPeople,dc=3Dranger,dc=3Ddnsalias,dc=3Dcom
objectClass: mailRecipient
objectClass: person
objectClass: organizationalPerson
objectClass: inetOrgPerson
objectClass: posixAccount
objectClass: top
objectClass: kerberosSecurityObject
objectClass: shadowAccount
objectClass: sambaSamAccount
$ rpm -q openldap-servers
openldap-servers-2.3.27-1mdv2007.0
$ rpm -q openldap-servers --qf "%{PACKAGER}\n"
Buchan Milne <bgmilne(a)mandriva.org>
Regards,
Buchan
=2D-=20
Buchan Milne
ISP Systems Specialist - Monitoring/Authentication Team Leader
B.Eng,RHCE(803004789010797),LPIC-2(LPI000074592)
--nextPart2681002.ZbxIqWnAlZ
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
iD8DBQBFU1IvrJK6UGDSBKcRAhkQAKDCpV5W+plszHrf/GIqkx2yMcTtwQCePs67
JaAwrB9eaYnzEcK7uS41ZEo=
=4WpH
-----END PGP SIGNATURE-----
--nextPart2681002.ZbxIqWnAlZ--
hardimankevin(a)yahoo.com wrote:
> Full_Name: Kevin Hardiman
> Version: 2.3.27
> OS: Linux (Mandriva 2007)
> URL: ftp://ftp.openldap.org/incoming/
> Submission from: (NULL) (24.90.130.182)
>
>
> Using the very simple alias below, OpenLDAP will crash every time it is
> dereferenced:
>
> dn: uid=test,ou=Users,ou=bladiant,ou=smb,ou=Core Services,dc=example,dc=com
> objectClass: alias
> objectclass: extensibleObject
> uid: test
> aliasedObjectName: uid=test,ou=Users,dc=example,dc=com
>
> This error has been experience with OpenLDAP releases 2.3.6 and 2.3.27, both in
> the form of provided Mandriva packages. I also have seen a number of references
> to this error in previous releases, with no explicit fix. Please advise.
Well, considering that no one has reported any such problem during the
whole time releases 2.3.6-2.3.27 were published, it's no surprise that
there has been no fix yet.
There's not enough information here to reproduce the bug. What backend
are you using, what other entries are in the database? In particular,
does "uid=test,ou=Users,dc=example,dc=com" exist? You should provide a
sample slapd.conf and minimal LDIF needed to reproduce the error.
--
-- Howard Chu
Chief Architect, Symas Corp. http://www.symas.com
Director, Highland Sun http://highlandsun.com/hyc
OpenLDAP Core Team http://www.openldap.org/project/
Full_Name: Lee Sheridan
Version: 2.3.27
OS: Debian GNU/Linux (etch)
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (69.168.13.7)
In servers/slapd/overlays/ppolicy.c, check_password_quality function, at
line 530, the value of the 'ok' variable is discarded by unconditionally
assigning it the value LDAP_SUCCESS.
The variable is the return code of the user-defined check_password() function,
which is assigned at line 522. The next if-then-else block is checking to
see if the module reported an error, at which point 'ok' would be assigned
LDAP_OTHER regardless of what check_password() returned. A superfluous else
block appears after this check, assigning 'ok' to LDAP_SUCCESS.
It works fine for me if I remove the else block.
Thanks,
Full_Name: Howard Chu
Version: all < 2.3.29
OS:
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (76.168.84.21)
Submitted by: hyc
Apparently this bug was discovered by Evgeny Legerov but was not previously
reported to anyone on the Project. The bug is now fixed in HEAD and RE23.
Performing a SASL Bind with an authcid longer than 255 characters, with a space
as the 255th character, will cause the length of the normalized name to be
computed incorrectly, failing to take into account the escaping of the space
character. (The SASL Bind code truncates all incoming names longer than 255 to
exactly 255 characters.) This triggers an assert in libldap because the
resulting string length doesn't match what we expected it to be.
The fix is in libldap/getdn.c rev 1.134.
The MITRE CVE record for this bug is
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5779
Full_Name: Kevin Hardiman
Version: 2.3.27
OS: Linux (Mandriva 2007)
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (24.90.130.182)
Using the very simple alias below, OpenLDAP will crash every time it is
dereferenced:
dn: uid=test,ou=Users,ou=bladiant,ou=smb,ou=Core Services,dc=example,dc=com
objectClass: alias
objectclass: extensibleObject
uid: test
aliasedObjectName: uid=test,ou=Users,dc=example,dc=com
This error has been experience with OpenLDAP releases 2.3.6 and 2.3.27, both in
the form of provided Mandriva packages. I also have seen a number of references
to this error in previous releases, with no explicit fix. Please advise.
Kevin Hardiman
richton(a)nbcs.rutgers.edu wrote:
> Please visit
> https://www.nbcs.rutgers.edu/~richton/richton-20061107-livelock_2.txt for
> an updated backtrace. This one almost looks like it has lock contention,
> and a writewaiter assert is notably missing...
The trace shows several threads backing off because they think some
other thread is about to read the entry from the database. At a guess,
none of them is actually going to perform the database read. Most likely
a lock is missing here.
--
-- Howard Chu
Chief Architect, Symas Corp. http://www.symas.com
Director, Highland Sun http://highlandsun.com/hyc
OpenLDAP Core Team http://www.openldap.org/project/
Please visit
https://www.nbcs.rutgers.edu/~richton/richton-20061107-livelock_2.txt for
an updated backtrace. This one almost looks like it has lock contention,
and a writewaiter assert is notably missing...
I'm going to rm the bad link, it can only hurt people.
On Tue, 7 Nov 2006, Aaron Richton wrote:
> Sigh. As may be obvious to anybody unfortunate enough to look at the link, I
> seem to have gotten my core files confused. I have a bunch of db_stat -CA
> done properly, but the backtrace for this may be lost to the bit bucket. I'll
> poke around my systems and see what I can find, but I think it might be
> nothing. A syslog of "waiting for 1027 threads to terminate" might be the
> only other durable evidence.
>