Re: Odd situation - SETUID fail
Posted in 2009
On Fri, Apr 3, 2009 at 10:02, <cesar_inacio_martins@yahoo.com.br> wrote:
> This is a very specific and odd situation, I already discover the
> workaround (odd too), but I like to try understand the real origin of the
> problem, if anybody have a explanation, I appreciate..
> In small talk , the problem are with SETUID effect ( or not effect in this
> case).
> For me , appear be a Bug on OpenSuse (kernel or glibc).
> I install OpenSuse 11.1 on my new notebook and update the packages and
> patches,
Relatively unlikely to be a bug in OpenSuSE; that is an audacious
claim and would need more backing than what you've shown here (though
what you've shown is interesting).
> | cmartins@note-cim:~> uname -a
> | Linux note-cim 2.6.27.7-9-pae #1 SMP 2008-12-04 18:10:04 +0100 i686 i686
> i386 GNU/Linux
> | cmartins@note-cim:~> rpm -q glibc
> | glibc-2.9-2.11.1
>
> After that I install IDS 11.5 UC3 Developer Edition and try to initialize
> it with very basic configuration.
> When I execute the "oninit -iv" with user "informix" I got this (pay
> attention to ">" ):
>
> | informix@note-cim:~> oninit -ivy
> | Checking group membership to determine server run mode...succeeded
> | Reading configuration file
> '/opt/IBM/ids1150uc3de/etc/onconfig.idsmoon'...succeeded
>>| Creating /INFORMIXTMP/.infxdirs...FAILED
So, it appears that for some reason, oninit does not have sufficient
privileges to create /INFORMIXTMP.
I checked on my Solaris machine; if /INFORMIXTMP does not exist, it is
created. For some reason as yet unexplained, your system was unable
to create it.
> | Creating infos file
> "/opt/IBM/ids1150uc3de/etc/.infos.idsmoon"...succeeded
> | Linking conf file "/opt/IBM/ids1150uc3de/etc/.conf.idsmoon"...succeeded
> | Checking config parameters...succeeded
> | Writing to infos file...succeeded
> | Allocating and attaching to shared memory...succeeded
> | Creating resident pool 10570 kbytes...succeeded
> | Allocating 100016 kbytes for buffer pool of 2K page size...succeeded
> | Initializing rhead structure...succeeded
> | Initialization of Encryption...succeeded
> | tail: cannot open `$INFORMIXDIR/log/online.log' for reading: No such file
> or directory
You're supposed to have the online.log file already created before running IDS.
> | touch: cannot touch `/INFORMIXTMP/.idsmoon.alarm': No such file or
> directory
That's a consequential failure.
>>| awk: cmd. line:1: fatal: cannot open file `/INFORMIXTMP/.idsmoon.alarm'
>> for reading (No such file or directory)
>>| mv: cannot move `/tmp/.idsmoon.alarm_9782' to
>> `/INFORMIXTMP/.idsmoon.alarm': No such file or directory
>>| SENDER IS NULL NO MAIL WILL BE SENT
>>| /opt/IBM/ids1150uc3de/etc/alarmprogram.sh[517]:
>> /INFORMIXTMP/.idsmoon.alarm: cannot create [No such file or directory]
More consequential failures.
> | WARNING: server initialization failed, or possibly timed out (if -w was
> used).
> | Check the message log, online.log, for errors.
>
>
>
> Here is the log
>
> | informix@note-cim:/opt/IBM/ids1150uc3de/log> cat online.log
> | 17:33:43 IBM Informix Dynamic Server Started.
> | 17:33:43 Warning: The IBM IDS Developer Edition license restriction
> limits
> | 17:33:43 the total shared memory size for this server to 1048576 KB.
> | 17:33:43 The size has been reset to the limit to bring up the database
> server.
>>| 17:33:44 Could not disable priority aging: errno = 13
> | Wed Apr 1 17:33:44 2009
>>| 17:33:44 Error: Unable to reset open files limit, must run as super-user
> | 17:33:44 Event alarms enabled. ALARMPROG =
> '/opt/IBM/ids1150uc3de/etc/alarmprogram.sh'
>>| 17:33:44 Assert Failed: net_init.c, line 321, thread 1, errno=13, error
>> in creating /INFORMIXTMP.
errno 13 ENOPERM Permission denied.
> | 17:33:44 IBM Informix Dynamic Server Version 11.50.UC3DE
> | 17:33:44 Who: Session(0, @, 0, (nil))
> | Thread(1, main_thread, 0, 1)
> | File: neterrb.c Line: 658
> | 17:33:44 stack trace for pid 9819 written to
> /opt/IBM/ids1150uc3de/tmp/af.3e9cfa8
> | 17:33:44 See Also: /opt/IBM/ids1150uc3de/tmp/af.3e9cfa8,
> shmem.3e9cfa8.0
> | 17:33:47 neterrb.c, line 658, thread 1, proc id 9819, net_init.c, line
> 321, thread 1, errno=13, error in creating /INFORMIXTMP..
> | 17:33:47 PANIC: Attempting to bring system down
I'm not convinced that it should be giving an AF - that's a bug in
IDS. It can decide not to run; that's legitimate. But it should not
give an AF.
> Searching for errno 13 in the /usr/include/asm-generic/errno-base.h
> | #define EACCES 13 /* Permission denied */
>
> So, for me this appear be a problem with SETUID on binaries , but, when I
> look them , are all ok!
>
> | informix@note-cim:/opt/IBM/ids1150uc3de/log> ls -l $INFORMIXDIR/bin/on*
[...]
> | -rwsr-sr-- 1 root informix 15854167 2009-03-30 16:04
> /opt/IBM/ids1150uc3de/bin/oninit
[...]
Those are the correct permissions. Questions arising:
* Is the /opt file system mounted with SUID and SGID disabled?
> If I try initialize with "root" the /INFORMIXTMP is created , but others
> problems appears:
>
> | 17:39:29 IBM Informix Dynamic Server Version 11.50.UC3DE Software Serial
> Number AAA#B000000
> | 17:39:29 The chunk '/ifmxdados/L_rootdbs.ch1' must have owner-ID
> "informix" and group-ID "root".
That is an odd error message. Which group is listed for user informix
in the /etc/passwd file (or equivalent)? If the group is 0 rather
than informix, then you have 'officially' misconfigured your machine;
the primary group for user informix (the one listed in /etc/passwd)
must be group informix (because the server takes a short-cut and
assumes that the group listed in /etc/passwd for user informix is
group informix). It is a bug on my list of 'to be fixed one day - but
it does not hurt anyone'. However, the second half of the sentence
might be shown to be incorrect.
> Insisting to use with "root" , after change the group-id of the chunk ,
> apparently all appears works fine and the instance are initialized, when I
> try to use onstat with "informix" user, this occur:
> | informix@note-cim:~> onstat -
> | onstat: Shared memory: permission denied.
> |
> | root@note-cim:~# ipcs -mc
> | ------ Shared Memory Segment Creators/Owners --------
> | shmid perms cuid cgid uid gid
>>| 1343488 660 root root root root
>>| 1376257 660 root root root root
So the shared memory segments are created by root, not informix. And
SGID informix programs won't be able to attach to the shared memory.
The group problem could again be related to the password file entry.
> So, to resolve the situation I wrote the C code below , and finally , this
> way use the IDS on my note:
> | cmartins@note-cim:~/fontes/c> cat myexec.c
> | #include <stdio.h>
> | #include <unistd.h>
> | #include <stdlib.h>
> |
> | int main(int argc, char *argv[] ) {
> | if ( argc != 4 ) {
> | printf("\\
Invalid Parameters!\\
syntax: [uid] [gid] [command]\\
\\
");
> | exit(1) ;
> | }
> | int i;
> | printf("argc = %i\\
",