https://bugzilla.redhat.com/show_bug.cgi?id=868386 (Red Hat Enterprise Linux 7)
Description of problem: Creating simultaneous instances of directory server fails when selinux is in enforcing mode. It returns "libsemanage.semanage_get_lock: Could not get direct transaction lock at /etc/selinux/targeted/modules/semanage.trans.LOCK" error. How reproducible: Consistently Steps to Reproduce: 1. Install latest 389-ds-base. 2. Set selinux to "Enforcing" mode. 3. Run setup-ds.pl script on two terminals simultaneously. 4. setup-ds.pl script fails to create ds instance and returns semanage error. Actual results: semanage port -a -t ldap_port_t -p tcp 13989 libsemanage.semanage_get_lock: Could not get direct transaction lock at /etc/selinux/targeted/modules/semanage.trans.LOCK. (Resource temporarily unavailable). /usr/sbin/semanage: Could not start semanage transaction Expected results: setup-ds.pl script should be able to handle multiple instance creation simultaneously. The script should till the other one is completed. Additional info: This change might be needed for setup-ds-admin.pl, remove-ds.pl and remove-ds-admin.pl scripts. Please refer to - https://bugzilla.redhat.com/show_bug.cgi?id=865236
Bug description: If multiple DSCreate or removeDSInstance run simultaneously, semanage port fails because only one semanage transaction is allowed to start.
Fix description: This patch puts "semanage port" in the while loop and it retries until it succeeds or reaches the max retry count (in total 5 minutes).
git patch file (master) 0001-Ticket-502-setup-ds.pl-script-should-wait-if-semanag.patch
ack
Reviewed by Mark (Thank you!!)
Pushed to master: commit 4999849d428c5564546467101483faa63999dc32
Metadata Update from @nhosoi: - Issue assigned to nhosoi - Issue set to the milestone: 1.3.1
389-ds-base is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in 389-ds-base's github repository.
This issue has been cloned to Github and is available here: - https://github.com/389ds/389-ds-base/issues/502
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.
Metadata Update from @spichugi: - Issue close_status updated to: wontfix (was: Fixed)