Chunk must have owner-id informix
Posted in 2017
After a power failure and server restart, Informix refused to come up, complaining that a chunk must have owner-id and group-id informix, even though the chunk path itself appeared to be owned by informix:informix. Paul Watson asked whether the symlink or its underlying device/file was the problem; the poster found the link's target was owned by root:root, and changing it to informix fixed the startup. Art Kagel confirmed both the link and the device/file it points to must be informix-owned, and Jonathan Leffler described the onsecurity utility (-v, -r options) for diagnosing and generating fixes for such permission problems.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Storage & Space Management
Hi, After a fail electricity power, we restar the server, then got this error: The chunk must have owner-id and group-id informix I list the chunk and see that it has owner and group informix. Any ideas? Thanks in advance.
Underpinning device or target of the link ? Cheers Paul -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of jorge valenzuela Sent: Monday, August 28, 2017 2:01 PM To: ids@iiug.org Subject: Chunk must have owner-id informix [39770] Hi, After a fail electricity power, we restar the server, then got this error: The chunk must have owner-id and group-id informix I list the chunk and see that it has owner and group informix. Any ideas? Thanks in advance. **************************************************************************** *** Forum Note: Use "Reply" to post a response in the discussion forum.
The link was root system (owner and group), I changen and it work. Thanks. > El 28/08/2017, a las 12:07, Paul Watson <paul@oninit.com> escribió: > > Underpinning device or target of the link ? > > Cheers > Paul > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of jorge > valenzuela > Sent: Monday, August 28, 2017 2:01 PM > To: ids@iiug.org > Subject: Chunk must have owner-id informix [39770] > > Hi, > > After a fail electricity power, we restar the server, then got this error: > The chunk must have owner-id and group-id informix > > I list the chunk and see that it has owner and group informix. > > Any ideas? > > Thanks in advance. > > **************************************************************************** > *** > Forum Note: Use "Reply" to post a response in the discussion forum. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Make sure that not only the link you use for the chunk but the file or device that it points to are also owned by informix & group informix! Art Art S. Kagel, President and Principal Consultant ASK Database Management www.askdbmgt.com Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Mon, Aug 28, 2017 at 3:01 PM, jorge valenzuela <jorgervt@gmail.com> wrote: > Hi, > > After a fail electricity power, we restar the server, then got this error: > The chunk must have owner-id and group-id informix > > I list the chunk and see that it has owner and group informix. > > Any ideas? > > Thanks in advance. > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > >
I will do. Thanks. On 28 August 2017 at 15:10, Art Kagel <art.kagel@gmail.com> wrote: > Make sure that not only the link you use for the chunk but the file or > device that it points to are also owned by informix & group informix! > > Art > > Art S. Kagel, President and Principal Consultant > ASK Database Management > www.askdbmgt.com > > Blog: http://informix-myview.blogspot.com/ > > Disclaimer: Please keep in mind that my own opinions are my own opinions > and do not reflect on the IIUG, nor any other organization with which I am > associated either explicitly, implicitly, or by inference. Neither do > those opinions reflect those of other individuals affiliated with any > entity with which I am affiliated nor those of the entities themselves. > > On Mon, Aug 28, 2017 at 3:01 PM, jorge valenzuela <jorgervt@gmail.com> > wrote: > > > Hi, > > > > After a fail electricity power, we restar the server, then got this > error: > > The chunk must have owner-id and group-id informix > > > > I list the chunk and see that it has owner and group informix. > > > > Any ideas? > > > > Thanks in advance. > > > > > > ************************************************************ > > ******************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > >
If you're not sure why a chunk name or other file or directory is regarded
as insecure, then you can use the 'onsecurity' program (from
$INFORMIXDIR/bin) to check. It uses the same code as the server uses â it
is just packaged as a standalone (and fairly small) program.
onsecurity -h
gives you help about how to use it. onsecurity -v tells you why it thinks
something is secure; it tells you anyway if it thinks it is insecure.
For example, on a Mac running 12.10.FC6:
$ onsecurity -v $INFORMIXDIR
# /opt/informix/12.10.FC6 (path is trusted)
# Analysis:# User Group Mode Type Secure Name
# 0 root 0 wheel 0755 DIR YES /
# 0 root 0 wheel 0755 DIR YES /opt
# 503 informix 704 informix 0755 DIR YES /opt/informix
# 503 informix 704 informix 0755 DIR YES /opt/informix/12.10.FC6
$
You can specify a chunk path or a directory or other file. It tracks
symlinks and reports if there are components of the paths through those
symlinks that it thinks are not secure, etc. It is paranoid, but it
explains its paranoia. For example, there isn't a file 'interloper' in my
$TMPDIR (and that is a peculiar location set by the system on a Mac):
$ onsecurity $TMPDIR/interloper# !!! SECURITY PROBLEM !!!
# /var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T//interloper (path is not
trusted)
# Analysis:
# User Group Mode Type Secure Name
# 0 root 0 wheel 0755 DIR YES /
# 0 root 0 wheel 0755 LINK YES /var
# --> private/var
# 0 root 0 wheel 0755 DIR YES /private
# 0 root 0 wheel 0755 DIR YES /private/var
# 0 root 0 wheel 0755 DIR YES /private/var/folders
# 0 root 0 wheel 0755 DIR YES /private/var/folders/77
# 501 jleffler 20 staff 0755 DIR NO
/private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
# 501 jleffler 20 staff 0700 DIR NO
/private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
# Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
# Problem: owner jleffler (uid 501) is not trusted
# Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
# Problem: owner jleffler (uid 501) is not trusted
# lstat() failed on
/private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T/interloper
# errno = 2: No such file or directory
$
There is also a '-r' option to recommend changes:
$ onsecurity -r $TMPDIR/interloper
#!/bin/sh# Script to fix permissions on specified files or directories
# Should be run by user root
# !!! SECURITY PROBLEM !!!
# /var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T//interloper (path is not
trusted)
# Analysis:
# User Group Mode Type Secure Name
# 0 root 0 wheel 0755 DIR YES /
# 0 root 0 wheel 0755 LINK YES /var
# --> private/var
# 0 root 0 wheel 0755 DIR YES /private
# 0 root 0 wheel 0755 DIR YES /private/var
# 0 root 0 wheel 0755 DIR YES /private/var/folders
# 0 root 0 wheel 0755 DIR YES /private/var/folders/77
# 501 jleffler 20 staff 0755 DIR NO
/private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
# 501 jleffler 20 staff 0700 DIR NO
/private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
# Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
# Problem: owner jleffler (uid 501) is not trusted
# Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
# Problem: owner jleffler (uid 501) is not trusted
# lstat() failed on
/private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T/interloper
# errno = 2: No such file or directory
chown root /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn \\\\
/private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
# End of script
$
This does not run any shell commands. It generates on standard output a
set of commands that could be run by an appropriately privileged user
(think 'root') to fix the problem. There are a bunch of options to tune
the recommendations:
$ onsecurity -h
Usage: onsecurity [-dehinpqrtvV][-u user][-g group] [-G action] [-O action]
[-U action] file-or-directory [...]
Option summary:
-d Print diagnostic output
-e Do not read files from /etc/informix
-g group Treat group as trusted
-h Print this help message and exit
-i Do not trust user informix or group informix
-n Do not trust system users (bin, sys) or groups (bin, sys,
...)
-p Perform analysis, assuming PRIVATE mode installation
-q Quiet: suppress analysis regardless of failure or success
-r Recommend changes to fix security problems
-t Terse: print minimal analysis on failure
-u user Treat user as trusted
-v Verbose: print analysis regardless of failure or success
-G action How to fix directories with flawed group permissions
-O action How to fix directories with flawed other permissions
-U action How to fix directories with flawed user permissions
-V Print version and exit
-version Print extended version information and exit
Actions (for -G, -O, -U):
chgrp[=group] (-G) Change group to nominated group
chown[=user] (-U) Change user to nominated user
chmod (-G, -O) Change mode to remove write access
add (-G, -O, -U) Add user, group or directory to trusted list
Default actions are:
-G chmod
-O chmod
-U chown
Do not use the add option unless there is no acceptable alternative.
Do NOT use the add option for -O (it leaves your system very insecure).
Save and execute the script generated, possibly after editing it.
$
On Mon, Aug 28, 2017 at 12:01 PM, jorge valenzuela <jorgervt@gmail.com>
wrote:
> Hi,
>
> After a fail electricity power, we restar the server, then got this error:
> The chunk must have owner-id and group-id informix
>
> I list the chunk and see that it has owner and group informix.
>
> Any ideas?
>
> Thanks in advance.
>
>
> ************************************************************
> *******************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
Guardian of DBD::Informix - v2015.1101 - http://dbi.perl.org
"Blessed are we who can laugh at ourselves, for we shall never cease to be
amused."
Thanks.
> El 28/08/2017, a las 15:50, Jonathan Leffler <jonathan.leffler@gmail.com>
escribió:
>
> If you're not sure why a chunk name or other file or directory is regarded
> as insecure, then you can use the 'onsecurity' program (from
> $INFORMIXDIR/bin) to check. It uses the same code as the server uses it
> is just packaged as a standalone (and fairly small) program.
>
> onsecurity -h
>
> gives you help about how to use it. onsecurity -v tells you why it thinks
> something is secure; it tells you anyway if it thinks it is insecure.
>
> For example, on a Mac running 12.10.FC6:
>
> $ onsecurity -v $INFORMIXDIR
> # /opt/informix/12.10.FC6 (path is trusted)
> # Analysis:> # User Group Mode Type Secure Name
> # 0 root 0 wheel 0755 DIR YES /
> # 0 root 0 wheel 0755 DIR YES /opt
> # 503 informix 704 informix 0755 DIR YES /opt/informix
> # 503 informix 704 informix 0755 DIR YES /opt/informix/12.10.FC6
> $
>
> You can specify a chunk path or a directory or other file. It tracks
> symlinks and reports if there are components of the paths through those
> symlinks that it thinks are not secure, etc. It is paranoid, but it
> explains its paranoia. For example, there isn't a file 'interloper' in my
> $TMPDIR (and that is a peculiar location set by the system on a Mac):
>
> $ onsecurity $TMPDIR/interloper> # !!! SECURITY PROBLEM !!!
> # /var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T//interloper (path is not
> trusted)
> # Analysis:
> # User Group Mode Type Secure Name
> # 0 root 0 wheel 0755 DIR YES /
> # 0 root 0 wheel 0755 LINK YES /var
> # --> private/var
> # 0 root 0 wheel 0755 DIR YES /private
> # 0 root 0 wheel 0755 DIR YES /private/var
> # 0 root 0 wheel 0755 DIR YES /private/var/folders
> # 0 root 0 wheel 0755 DIR YES /private/var/folders/77
> # 501 jleffler 20 staff 0755 DIR NO
> /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
> # 501 jleffler 20 staff 0700 DIR NO
> /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
> # Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
> # Problem: owner jleffler (uid 501) is not trusted
> # Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
> # Problem: owner jleffler (uid 501) is not trusted
> # lstat() failed on
> /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T/interloper
> # errno = 2: No such file or directory
> $
>
> There is also a '-r' option to recommend changes:
>
> $ onsecurity -r $TMPDIR/interloper
> #!/bin/sh> # Script to fix permissions on specified files or directories
> # Should be run by user root
>
> # !!! SECURITY PROBLEM !!!
> # /var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T//interloper (path is not
> trusted)
> # Analysis:
> # User Group Mode Type Secure Name
> # 0 root 0 wheel 0755 DIR YES /
> # 0 root 0 wheel 0755 LINK YES /var
> # --> private/var
> # 0 root 0 wheel 0755 DIR YES /private
> # 0 root 0 wheel 0755 DIR YES /private/var
> # 0 root 0 wheel 0755 DIR YES /private/var/folders
> # 0 root 0 wheel 0755 DIR YES /private/var/folders/77
> # 501 jleffler 20 staff 0755 DIR NO
> /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
> # 501 jleffler 20 staff 0700 DIR NO
> /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
> # Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn
> # Problem: owner jleffler (uid 501) is not trusted
> # Name: /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
> # Problem: owner jleffler (uid 501) is not trusted
> # lstat() failed on
> /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T/interloper
> # errno = 2: No such file or directory
>
> chown root /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn \\\\
>
> /private/var/folders/77/zx9nk6dn7_dg4xd4stvt42v00000gn/T
>
> # End of script
> $
>
> This does not run any shell commands. It generates on standard output a
> set of commands that could be run by an appropriately privileged user
> (think 'root') to fix the problem. There are a bunch of options to tune
> the recommendations:
>
> $ onsecurity -h
> Usage: onsecurity [-dehinpqrtvV][-u user][-g group] [-G action] [-O action]>
> [-U action] file-or-directory [...]
> Option summary:
> -d Print diagnostic output
> -e Do not read files from /etc/informix
> -g group Treat group as trusted
> -h Print this help message and exit
> -i Do not trust user informix or group informix
> -n Do not trust system users (bin, sys) or groups (bin, sys,
> ....)
> -p Perform analysis, assuming PRIVATE mode installation
> -q Quiet: suppress analysis regardless of failure or success
> -r Recommend changes to fix security problems
>
> -t Terse: print minimal analysis on failure
> -u user Treat user as trusted
> -v Verbose: print analysis regardless of failure or success
> -G action How to fix directories with flawed group permissions
> -O action How to fix directories with flawed other permissions
> -U action How to fix directories with flawed user permissions
> -V Print version and exit
> -version Print extended version information and exit
>
> Actions (for -G, -O, -U):
> chgrp[=group] (-G) Change group to nominated group
> chown[=user] (-U) Change user to nominated user
> chmod (-G, -O) Change mode to remove write access
> add (-G, -O, -U) Add user, group or directory to trusted list
> Default actions are:
> -G chmod
> -O chmod
> -U chown
>
> Do not use the add option unless there is no acceptable alternative.
> Do NOT use the add option for -O (it leaves your system very insecure).
> Save and execute the script generated, possibly after editing it.
>
> $
>
> On Mon, Aug 28, 2017 at 12:01 PM, jorge valenzuela <jorgervt@gmail.com>
> wrote:
>
>> Hi,
>>
>> After a fail electricity power, we restar the server, then got this error:
>> The chunk must have owner-id and group-id informix
>>
>> I list the chunk and see that it has owner and group informix.
>>
>> Any ideas?
>>
>> Thanks in advance.
>>
>>
>> ************************************************************
>> *******************
>> Forum Note: Use "Reply" to post a response in the discussion forum.
>>
>>
>
> --
> Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
> Guardian of DBD::Informix - v2015.1101 - http://dbi.perl.org
> "Blessed are we who can laugh at ourselves, for we shall never cease to be
> amused."
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>