#3869 Incomplete group list
Closed: cloned-to-github 5 years ago by pbrezina. Opened 6 years ago by sternber.

Hello!

When we list the members of certain unix groups, we see on some nodes not the
complete list. If I add or remove members has no effect
To purge the cache with "sss_cache -E" has no effect.
The only workaround is to remove the cache files and restart sssd. Afterwards
everythings works and I can add add and remove members again.

When I log into a node with a broken cache I see lines like this in the log:
[sssd[be[LDAP]]] [sysdb_set_cache_entry_attr] (0x0080): ldb_modify failed: No such object[ldb_wait from ldb_modify with LDB_WAIT_ALL: No such object (32)]
[sssd[be[LDAP]]] [sysdb_set_entry_attr] (0x0080): Cannot set ts attrs for name=twhite@ldap,cn=users,cn=LDAP,cn=sysdb

If I remove manually one of the missing user record with
ldbdel -H /var/lib/sss/db/cache_LDAP.ldb "name=foo@ldap,cn=users,cn=LDAP,cn=sysdb"
and then run "sss_cache -E". I get "foo" in the list afterwards

Facts:
Centos 7.5
sssd-1.16.0-19.el7.x86_64


The message is unrelated, it's just an optimalization technique (note the _ts_cache in the debug message).

Can you add the complete debug logs?

Hi there,

Has there been any progress on this issue? It appears that we're seeing the same thing - only affecting groups - on a significant number of our machines.

Scientific Linux 7.5
1.16.2-13.el7

Thanks
Toby

Metadata Update from @pbrezina:
- Issue tagged with: Future milestone

5 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/4859

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata Update from @pbrezina:
- Issue close_status updated to: cloned-to-github
- Issue status updated to: Closed (was: Open)

5 years ago

Log in to comment on this ticket.

Metadata
Attachments 2
Attached 6 years ago View Comment
Attached 6 years ago View Comment