IDS Crashes with LDAP on Solaris 10
Posted in 2006
Tom Girsch reported IDS 10.00/9.40 on Solaris 10 crashing (MSC VP) whenever an LDAP-authenticated user connected, via shared memory or TCP/IP; it was reproducible on multiple boxes but IBM support couldn't reproduce it and a PMR was open. Suggestions included trussing the MSC VP, supplying a shared-memory dump/af stack trace and sqlhosts, and noting IDS authenticates LDAP only through PAM, so a mismatched PAM/LDAP library version could be at fault. A Spanish poster hit the same crash on Red Hat, where PAM_STACKSIZE tweaks didn't help but an interim build (10.00.UC4W2) from IBM fixed it. Girsch's own Solaris case shows no recorded resolution.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Installation, Setup & Upgrades, Storage & Space Management, Networking & sqlhosts Configuration, Platform-Specific Issues, Versions, Editions & End-of-Life
Hello all, I'm running IDS 10.00.FC4 on Solaris 10, and am having a frustrating problem. Any time an LDAP user attempts to connect to the database, the server crashes, implicating the MSC VP. Local (non-LDAP) users seem to work fine. It doesn't matter whether the LDAP user connects locally via shared memory or remotely via TCP/IP. Either crashes the engine. I've been able to replicate this regularly on two different Solaris 10 boxes (at various patch levels, all the way up to current), with IDS 10.00.FC4, 10.00.FC4W1, 10.00.UC4, 9.40.UC6, and 9.40.FC6. The behavior is virtually identical with all of these versions. And I can do it with a minimally configured instance (512 MB single cooked chunk, single CPU VP, etc.). IBM is stumped, and has proven unable to replicate the problem on either of the two Solaris 10 boxes they've tried. I've tested these identical scenarios on Solaris 8, and haven't been able to replicate there. I don't have a Solaris 9 box available to me, so I can't test on that platform. Has anyone else encountered anything similar on Solaris 10? Is anyone else running IDS successfully on Solaris 10? Any help is appreciated. - Tom Girsch Hilton Hotels
"Has anyone else encountered anything similar on Solaris 10? Is anyone else running IDS successfully on Solaris 10? " truss the MSC VP whilst this is happening. I think on Solaris 10 you can even truss -u to see what library calls the MSC VP is making!
Buenos dias, me ocurrio lo mismo con sistema operativo linux RED-HAT e informix 10.00 UC4. En las conexiones por ODBC, los usuarios LDAP que no eran locales, no conseguian conectar con informix. Ademas, si se equivocaban en la contraseña Informix hacia crash. Es un bug de la version 10.00 UC4 que se arregla con una version intermedia, 10.00 UC4W2. Esta version no está disponible por internet, hay que pedirla a IBM y me la enviaron de EEUU. Sin embargo por Shared Memory funiona perfectamente, tanto en la 9x como en las 10.00, y tampoco sucede con las conexiones por JDBC. Saludos. Thomas J. Girsch wrote: > Hello all, > > I'm running IDS 10.00.FC4 on Solaris 10, and am having a frustrating > problem. Any time an LDAP user attempts to connect to the database, the > server crashes, implicating the MSC VP. Local (non-LDAP) users seem to > work fine. It doesn't matter whether the LDAP user connects locally via > shared memory or remotely via TCP/IP. Either crashes the engine. > > I've been able to replicate this regularly on two different Solaris 10 > boxes (at various patch levels, all the way up to current), with IDS > 10.00.FC4, 10.00.FC4W1, 10.00.UC4, 9.40.UC6, and 9.40.FC6. The behavior > is virtually identical with all of these versions. And I can do it with > a minimally configured instance (512 MB single cooked chunk, single CPU > VP, etc.). > > IBM is stumped, and has proven unable to replicate the problem on either > of the two Solaris 10 boxes they've tried. > > I've tested these identical scenarios on Solaris 8, and haven't been > able to replicate there. I don't have a Solaris 9 box available to me, > so I can't test on that platform. > > Has anyone else encountered anything similar on Solaris 10? Is anyone > else running IDS successfully on Solaris 10? > > Any help is appreciated. > > - Tom Girsch > Hilton Hotels
Has IBM looked at a shared memory dump for this crash? Thomas J. Girsch wrote: > Hello all, > > I'm running IDS 10.00.FC4 on Solaris 10, and am having a frustrating > problem. Any time an LDAP user attempts to connect to the database, the > server crashes, implicating the MSC VP. Local (non-LDAP) users seem to > work fine. It doesn't matter whether the LDAP user connects locally via > shared memory or remotely via TCP/IP. Either crashes the engine. > > I've been able to replicate this regularly on two different Solaris 10 > boxes (at various patch levels, all the way up to current), with IDS > 10.00.FC4, 10.00.FC4W1, 10.00.UC4, 9.40.UC6, and 9.40.FC6. The behavior > is virtually identical with all of these versions. And I can do it with > a minimally configured instance (512 MB single cooked chunk, single CPU > VP, etc.). > > IBM is stumped, and has proven unable to replicate the problem on either > of the two Solaris 10 boxes they've tried. > > I've tested these identical scenarios on Solaris 8, and haven't been > able to replicate there. I don't have a Solaris 9 box available to me, > so I can't test on that platform. > > Has anyone else encountered anything similar on Solaris 10? Is anyone > else running IDS successfully on Solaris 10? > > Any help is appreciated. > > - Tom Girsch > Hilton Hotels
do you have a PMR number?
Hi, voy a escribir en ingles porque esta es una lista en ingles y escribir en ingles es muy facil para mi. I think you (both) should get (more) help from Tech Support. Tracing (e.g. using truss/strace) can certainly be helpful in determining the cause of the problem. One thing you probably should clarify (also when talking to Tech Support) is this: From your descriptions, I'm not clear as to how you actually do (or intend to do) the authentication via LDAP. IDS does not support LDAP authentication natively. Are you utilizing PAM? Or are you utilizing some means of the OS (without PAM)? There may be a problem with the library that either PAM or the OS is using to do the authentication. I think I heard that at least one such customer case is known where on Linux the library doing the LDAP stuff in the PAM stack was of a newer version than "expected by IDS" and this caused a problem. As far as I know this particular problem has been fixed by now (though I don't know the version, Tech Support should be able to find out that). If the problem is in this area, it can also easily explain, why Tech Support so far has not been able to reproduce the problem on their machines ... Regards, Martin -- Martin Fuerderer IBM Informix Development Munich, Germany Information Management Visit one of the upcoming Infobahn events in Germany to get up-to-date information on Informix products: - June 20, 2006 at the IBM Forum Muenchen - June 21, 2006 at the IBM Forum Frankfurt - June 22, 2006 at the IBM Forum Berlin For more please see: http://www.ibm.com/de/events/infobahn/ informix-list-bounces@iiug.org wrote on 28.05.2006 09:17:51: > Buenos dias, > me ocurrio lo mismo con sistema operativo linux RED-HAT e informix > 10.00 UC4. En las conexiones por ODBC, los usuarios LDAP que no eran > locales, no conseguian conectar con informix. Ademas, si se equivocaban > en la contraseña Informix hacia crash. Es un bug de la version 10.00 > UC4 que se arregla con una version intermedia, 10.00 UC4W2. Esta > version no está disponible por internet, hay que pedirla a IBM y me la > enviaron de EEUU. > Sin embargo por Shared Memory funiona perfectamente, tanto en la 9x > como en las 10.00, y tampoco sucede con las conexiones por JDBC. > > Saludos. > > Thomas J. Girsch wrote: > > Hello all, > > > > I'm running IDS 10.00.FC4 on Solaris 10, and am having a frustrating > > problem. Any time an LDAP user attempts to connect to the database, the > > server crashes, implicating the MSC VP. Local (non-LDAP) users seem to > > work fine. It doesn't matter whether the LDAP user connects locally via > > shared memory or remotely via TCP/IP. Either crashes the engine. > > > > I've been able to replicate this regularly on two different Solaris 10 > > boxes (at various patch levels, all the way up to current), with IDS > > 10.00.FC4, 10.00.FC4W1, 10.00.UC4, 9.40.UC6, and 9.40.FC6. The behavior > > is virtually identical with all of these versions. And I can do it with > > a minimally configured instance (512 MB single cooked chunk, single CPU > > VP, etc.). > > > > IBM is stumped, and has proven unable to replicate the problem on either > > of the two Solaris 10 boxes they've tried. > > > > I've tested these identical scenarios on Solaris 8, and haven't been > > able to replicate there. I don't have a Solaris 9 box available to me, > > so I can't test on that platform. > > > > Has anyone else encountered anything similar on Solaris 10? Is anyone > > else running IDS successfully on Solaris 10? > > > > Any help is appreciated. > > > > - Tom Girsch > > Hilton Hotels > > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list
> informix-list-bounces@iiug.org wrote on 28.05.2006 09:17:51: > >> Buenos dias, >> me ocurrio lo mismo con sistema operativo linux RED-HAT e informix >> 10.00 UC4. En las conexiones por ODBC, los usuarios LDAP que no eran >> locales, no conseguian conectar con informix. Ademas, si se equivocaban >> en la contrase'a Informix hacia crash. Es un bug de la version 10.00 >> UC4 que se arregla con una version intermedia, 10.00 UC4W2. Esta >> version no est' disponible por internet, hay que pedirla a IBM y me la >> enviaron de EEUU. >> Sin embargo por Shared Memory funiona perfectamente, tanto en la 9x >> como en las 10.00, y tampoco sucede con las conexiones por JDBC. >> >> Saludos. >> >> Thomas J. Girsch wrote: >>> Hello all, >>> >>> I'm running IDS 10.00.FC4 on Solaris 10, and am having a frustrating >>> problem. Any time an LDAP user attempts to connect to the database, > the >>> server crashes, implicating the MSC VP. Local (non-LDAP) users seem > to >>> work fine. It doesn't matter whether the LDAP user connects locally > via >>> shared memory or remotely via TCP/IP. Either crashes the engine. >>> >>> I've been able to replicate this regularly on two different Solaris 10 >>> boxes (at various patch levels, all the way up to current), with IDS >>> 10.00.FC4, 10.00.FC4W1, 10.00.UC4, 9.40.UC6, and 9.40.FC6. The > behavior >>> is virtually identical with all of these versions. And I can do it > with >>> a minimally configured instance (512 MB single cooked chunk, single > CPU >>> VP, etc.). >>> >>> IBM is stumped, and has proven unable to replicate the problem on > either >>> of the two Solaris 10 boxes they've tried. >>> >>> I've tested these identical scenarios on Solaris 8, and haven't been >>> able to replicate there. I don't have a Solaris 9 box available to > me, >>> so I can't test on that platform. >>> >>> Has anyone else encountered anything similar on Solaris 10? Is anyone >>> else running IDS successfully on Solaris 10? >>> >>> Any help is appreciated. >>> >>> - Tom Girsch >>> Hilton Hotels >> _______________________________________________ >> Informix-list mailing list >> Informix-list@iiug.org >> http://www.iiug.org/mailman/listinfo/informix-list > Well, clarity (for both of these) would come from posting the sqlhosts file in use. Also, an extract of the stack trace(s) from the af file(s).
scottishpoet wrote: > do you have a PMR number? > Yep. 62346,227,000 As to others' questions about sqlhosts files and stack traces, they're pretty vanilla, but I'll try to get something up tomorrow. And yes, under the covers, there's PAM involved, too.
Guy Bowerman wrote: > Has IBM looked at a shared memory dump for this crash? > No, but they haven't asked for one, either. And I'd say I'm on about my fifth engineer for this PMR.
tarod35 wrote: > Buenos dias, > me ocurrio lo mismo con sistema operativo linux RED-HAT e informix > 10.00 UC4. En las conexiones por ODBC, los usuarios LDAP que no eran > locales, no conseguian conectar con informix. Ademas, si se equivocaban > en la contrase'a Informix hacia crash. Es un bug de la version 10.00 > UC4 que se arregla con una version intermedia, 10.00 UC4W2. Esta > version no est' disponible por internet, hay que pedirla a IBM y me la > enviaron de EEUU. > Sin embargo por Shared Memory funiona perfectamente, tanto en la 9x > como en las 10.00, y tampoco sucede con las conexiones por JDBC. > > Saludos. > You might try setting PAM_STACKSIZE to something like 64 or 128 in your onconfig, to see if this helps. This helped us with some ODBC crash issues on a couple of our platforms.
Thomas J. Girsch wrote: > tarod35 wrote: > > Buenos dias, > > me ocurrio lo mismo con sistema operativo linux RED-HAT e informix > > 10.00 UC4. En las conexiones por ODBC, los usuarios LDAP que no eran > > locales, no conseguian conectar con informix. Ademas, si se equivocaban > > en la contraseña Informix hacia crash. Es un bug de la version 10.00 > > UC4 que se arregla con una version intermedia, 10.00 UC4W2. Esta > > version no está disponible por internet, hay que pedirla a IBM y me la > > enviaron de EEUU. > > Sin embargo por Shared Memory funiona perfectamente, tanto en la 9x > > como en las 10.00, y tampoco sucede con las conexiones por JDBC. > > > > Saludos. > > > You might try setting PAM_STACKSIZE to something like 64 or 128 in your > onconfig, to see if this helps. This helped us with some ODBC crash > issues on a couple of our platforms. Ya probé con PAM_STACKSIZE =128 y con PAM_STACKSIZE =1024 pero siempre hacia crash. Abrimos una incidencia con IBM y despues de varios meses nos mandaron la verion nueva de IDS 10.00 UC4W2. SAludos.