Bug 13816 - dbcheck in the middle of the tombstone garbage collection causes replication failures
dbcheck in the middle of the tombstone garbage collection causes replication ...
Status: NEW
Product: Samba 4.1 and newer
Classification: Unclassified
Component: AD: LDB/DSDB/SAMDB
4.10.0rc2
All All
: P5 normal
: ---
Assigned To: Stefan Metzmacher
Samba QA Contact
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-03-01 14:22 UTC by Stefan Metzmacher
Modified: 2019-03-19 15:16 UTC (History)
3 users (show)

See Also:


Attachments
Testing patches for master (15.01 KB, patch)
2019-03-01 15:53 UTC, Stefan Metzmacher
no flags Details
Updated patches for master (15.32 KB, patch)
2019-03-07 14:03 UTC, Stefan Metzmacher
no flags Details
Patch for v4-10-test (97.23 KB, patch)
2019-03-19 11:00 UTC, Stefan Metzmacher
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Metzmacher 2019-03-01 14:22:20 UTC
When the (deleted) parent of a deleted object
(with the DISALLOW_MOVE_ON_DELETE bit in systemFlags),
is removed before the object itself, dbcheck moved
it in the LostAndFound[Config] subtree of the partition
as an originating change. That means that the object
will be in tombstone state again for 180 days on the local
DC. And other DCs fail to replicate the object as
it's already removed completely there and the replication
only gives the name and lastKnownParent attributes, because
all other attributes should already be known to the other DC.

Typically this race is unlikely to happen, but it can happen
if samba is stopped/restarted by a cronjob and dbcheck also
runs via a cronjob in fix mode at the same time.

The result is a message in the destination DSA that
a replicated object doesn't have an objectClass attribute.
Comment 1 Stefan Metzmacher 2019-03-01 15:53:01 UTC
Created attachment 14887 [details]
Testing patches for master
Comment 2 Stefan Metzmacher 2019-03-01 17:56:49 UTC
The message in the log is:

No objectClass found in replPropertyMetaData
Comment 3 Stefan Metzmacher 2019-03-07 14:03:58 UTC
Created attachment 14909 [details]
Updated patches for master

The change compared to the first patchset is that we now
don't treat the rdn attribute (cn in most cases) as unexpected.
Comment 4 Stefan Metzmacher 2019-03-19 11:00:45 UTC
Created attachment 14946 [details]
Patch for v4-10-test
Comment 5 Stefan Metzmacher 2019-03-19 15:16:17 UTC
Comment on attachment 14946 [details]
Patch for v4-10-test

First we need to merge https://gitlab.com/samba-team/samba/merge_requests/311
and include the patches for backports