#51066 Help With Arch Linux Packaging
Closed: wontfix by imntreal. Opened by imntreal.

Issue Description

I've been running 389 Directory Server on Arch for a while, now. However, I recently tried to start managing it via Cockpit. I'm looking for someone to help me consolidate the differences between the Fedora and Arch packages for the 389 DS Cockpit config.

The issue I'm ultimately trying to resolve is the 389 Directory Server tab in Cockpit suggesting that it isn't installed.

Package Version and Platform

~ pacman -Q 389-ds-base
389-ds-base 1.4.3.4-3
~ pacman -Q cockpit
cockpit 217-1

I've compared the contents of this 389-ds-base package with Fedora's cockpit-389-ds-1.4.3.7-1.fc32.noarch.rpm package.

Steps to reproduce

  1. pacman -S 389-ds-base
  2. Get the bellow files installed

Actual results

~ pacman -Ql 389-ds-base | egrep 'cockpit|metadata'
389-ds-base /usr/share/cockpit/
389-ds-base /usr/share/cockpit/389-console/
389-ds-base /usr/share/cockpit/389-console/banner.html
389-ds-base /usr/share/cockpit/389-console/css/
389-ds-base /usr/share/cockpit/389-console/css/ds.css
389-ds-base /usr/share/cockpit/389-console/fonts/
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Bold-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Bold-webfont.woff2
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-BoldItalic-webfont.woff2
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Italic-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Italic-webfont.woff2
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Light-webfont.ttf
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Light-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Light-webfont.woff2
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Regular-webfont.ttf
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Regular-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Regular-webfont.woff2
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Semibold-webfont.ttf
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Semibold-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-Semibold-webfont.woff2
389-ds-base /usr/share/cockpit/389-console/fonts/OpenSans-SemiboldItalic-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/PatternFlyIcons-webfont.ttf
389-ds-base /usr/share/cockpit/389-console/fonts/PatternFlyIcons-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/fontawesome-webfont.woff
389-ds-base /usr/share/cockpit/389-console/fonts/fontawesome-webfont.woff2
389-ds-base /usr/share/cockpit/389-console/fonts/glyphicons-halflings-regular.woff
389-ds-base /usr/share/cockpit/389-console/fonts/glyphicons-halflings-regular.woff2
389-ds-base /usr/share/cockpit/389-console/images/
389-ds-base /usr/share/cockpit/389-console/images/sort_asc.png
389-ds-base /usr/share/cockpit/389-console/images/sort_asc_disabled.png
389-ds-base /usr/share/cockpit/389-console/images/sort_both.png
389-ds-base /usr/share/cockpit/389-console/images/sort_desc.png
389-ds-base /usr/share/cockpit/389-console/images/sort_desc_disabled.png
389-ds-base /usr/share/cockpit/389-console/index.html
389-ds-base /usr/share/cockpit/389-console/index.min.js.gz
389-ds-base /usr/share/cockpit/389-console/manifest.json
389-ds-base /usr/share/cockpit/389-console/static/
389-ds-base /usr/share/cockpit/389-console/static/32px.png
389-ds-base /usr/share/cockpit/389-console/static/40px.png
389-ds-base /usr/share/cockpit/389-console/static/Typeahead.css
389-ds-base /usr/share/cockpit/389-console/static/bootpopup.min.js
389-ds-base /usr/share/cockpit/389-console/static/bootstrap-theme.min.css
389-ds-base /usr/share/cockpit/389-console/static/bootstrap-theme.min.css.map
389-ds-base /usr/share/cockpit/389-console/static/bootstrap.min.css
389-ds-base /usr/share/cockpit/389-console/static/bootstrap.min.css.map
389-ds-base /usr/share/cockpit/389-console/static/bootstrap.min.js
389-ds-base /usr/share/cockpit/389-console/static/c3.min.js
389-ds-base /usr/share/cockpit/389-console/static/d3.min.js
389-ds-base /usr/share/cockpit/389-console/static/dataTables.datetime-moment.js
389-ds-base /usr/share/cockpit/389-console/static/images/
389-ds-base /usr/share/cockpit/389-console/static/images/ui-icons_444444_256x240.png
389-ds-base /usr/share/cockpit/389-console/static/images/ui-icons_555555_256x240.png
389-ds-base /usr/share/cockpit/389-console/static/images/ui-icons_777620_256x240.png
389-ds-base /usr/share/cockpit/389-console/static/images/ui-icons_777777_256x240.png
389-ds-base /usr/share/cockpit/389-console/static/images/ui-icons_cc0000_256x240.png
389-ds-base /usr/share/cockpit/389-console/static/images/ui-icons_ffffff_256x240.png
389-ds-base /usr/share/cockpit/389-console/static/jquery-3.3.1.min.js
389-ds-base /usr/share/cockpit/389-console/static/jquery.dataTables.min.css
389-ds-base /usr/share/cockpit/389-console/static/jquery.dataTables.min.js
389-ds-base /usr/share/cockpit/389-console/static/jquery.dataTables.select.min.js
389-ds-base /usr/share/cockpit/389-console/static/jquery.timepicker.min.css
389-ds-base /usr/share/cockpit/389-console/static/jquery.timepicker.min.js
389-ds-base /usr/share/cockpit/389-console/static/jstree.min.js
389-ds-base /usr/share/cockpit/389-console/static/moment.min.js
389-ds-base /usr/share/cockpit/389-console/static/page.min.css
389-ds-base /usr/share/cockpit/389-console/static/patternfly-additions.css
389-ds-base /usr/share/cockpit/389-console/static/patternfly.css
389-ds-base /usr/share/cockpit/389-console/static/patternfly.min.js
389-ds-base /usr/share/cockpit/389-console/static/style.min.css
389-ds-base /usr/share/cockpit/389-console/static/throbber.gif
389-ds-base /usr/share/metainfo/389-console/org.port389.cockpit_console.metainfo.xml

Expected results

~ pacman -Ql 389-ds-base | egrep 'cockpit|metadata'
389-ds-base /usr/share/cockpit/389-console/css/branding.css
389-ds-base /usr/share/cockpit/389-console/css/ds.css
389-ds-base /usr/share/cockpit/389-console/index.html
389-ds-base /usr/share/cockpit/389-console/index.min.js.gz
389-ds-base /usr/share/cockpit/389-console/index.min.js.map
389-ds-base /usr/share/cockpit/389-console/manifest.json
389-ds-base /usr/share/doc/cockpit-389-ds/README.rd
389-ds-base /usr/share/metainfo/389-console/org.port389.cockpit_console.metainfo.xml

(or similar)

It looks to me that the only important file missing from the Arch package is /usr/share/cockpit/389-console/index.min.js.map, but I could be mistaken as I'm not very knowledgeable about what the Cockpit modules need to contain.


Here's the PKGBUILD: https://pastebin.com/m95UDRHq

Also, I should mention the issue on the Arch bug tracker: https://bugs.archlinux.org/task/66363

I'm the maintainer. I'm really not doing any funny stuff in the PKGBUILD so I would expect the locations to just be correct.

I'm not really seeing what's wrong with those paths you mention here. Even if a js file was missing, it would only cause an issue at runtime. I wonder if something else is going on for your system, I'm not very familiar with arch/cockpit though ....

Metadata Update from @firstyear:
- Custom field origin adjusted to None
- Custom field reviewstatus adjusted to None

Cockpit issue: https://github.com/cockpit-project/cockpit/issues/14034

Previously cockpit plugin was checking for 389-ds-base by running rpm -q 389-ds-base, which is only applicable on rpm-based distributions. This was fixed in 1.4.3.5 (862d0445280ed19837b8e518ba3b7e20de813ba2, see checkPackageAndLoad) by completely removing the check.

So I'd suggest ask @svenstaro to bump the version in PKGBUILD.

I can confirm that bumping the package version to 1.4.3.5 removes the message about 389-ds-base not being installed. However, it throws an error. This is what I got from my JavaScript console:
Sending message that cannot be cloned. Are you trying to send an XPCOM object? MessageChannel.jsm:1009:17
Sending message that cannot be cloned. Are you trying to send an XPCOM object? MessageChannel.jsm:1009:17
NS_ERROR_FAILURE: Component returned failure code: 0x80004005 (NS_ERROR_FAILURE) [nsIInterfaceRequestor.getInterface] network-response-listener.js:84
Sending message that cannot be cloned. Are you trying to send an XPCOM object? 3 MessageChannel.jsm:1009:17
Sending message that cannot be cloned. Are you trying to send an XPCOM object? MessageChannel.jsm:1009:17
Content Security Policy: Ignoring “'unsafe-inline'” within script-src: ‘strict-dynamic’ specified
Content Security Policy: Ignoring “https:” within script-src: ‘strict-dynamic’ specified
Content Security Policy: Ignoring “http:” within script-src: ‘strict-dynamic’ specified
Content Security Policy: Ignoring “'unsafe-inline'” within script-src: ‘strict-dynamic’ specified
Content Security Policy: Ignoring “https:” within script-src: ‘strict-dynamic’ specified
Content Security Policy: Ignoring “http:” within script-src: ‘strict-dynamic’ specified

I'm guessing this will probably require some more debugging, but it seems to have resolved the differences between the Cockpit files installed by the Fedora package versus the Arch package.

The version of the Arch package was bumped to 1.4.4.1. For some reason, the Cockpit plugin stopped being built by default, so I modified the PKGBUILD to include steps to manually build the plugin. Now, instead of throwing an error, I get a message that says "This server instance is running, but we can not connect to it. Check LDAPI is properly configured on this instance."

Here's how LDAPI is currently configured on my machine:
[root@server slapd-server]# grep ldapi dse.ldif
nsslapd-ldapifilepath: /var/run/dirsrv/slapd-server.socket
nsslapd-ldapilisten: on
nsslapd-ldapiautobind: off
nsslapd-ldapimaprootdn: cn=Directory Manager
nsslapd-ldapimaptoentries: off
nsslapd-ldapiuidnumbertype: uidNumber
nsslapd-ldapigidnumbertype: gidNumber
nsslapd-ldapientrysearchbase: dc=vtscrew,dc=com
[root@server slapd-server]# ls -l /var/run/dirsrv/slapd-server.socket
srw-rw-rw- 1 root root 0 May 11 12:06 /var/run/dirsrv/slapd-server.socket

Here's how LDAPI is currently configured on my machine:
[root@server slapd-server]# grep ldapi dse.ldif
nsslapd-ldapifilepath: /var/run/dirsrv/slapd-server.socket

change this to: /var/run/slapd-server.socket

I changed it, but t's still failing to connect. If I run ldapsearch, and specify -H ldapi://%2fvar%2frun%2fslapd-server.socket, it works. I'm thinking I'll have to get the output of what cockpit-bridge is doing to have an idea why it's failing.

I changed it, but t's still failing to connect. If I run ldapsearch, and specify -H ldapi://%2fvar%2frun%2fslapd-server.socket, it works. I'm thinking I'll have to get the output of what cockpit-bridge is doing to have an idea why it's failing.

Also check the cockpit console log (press F12). It logs all the CLI commands, and its parameters.

It looks like:
dsconf -j ldapi://%2fvar%2frun%2fslapd-server.socket backend suffix list --suffix

Is resulting in:
{"desc": "Inappropriate authentication", "info": "SASL EXTERNAL bind requires an SSL connection"}

It looks like:
dsconf -j ldapi://%2fvar%2frun%2fslapd-server.socket backend suffix list --suffix
Is resulting in:
{"desc": "Inappropriate authentication", "info": "SASL EXTERNAL bind requires an SSL connection"}

If you run this command yourself does it work?

dsconf -j ldapi://%2fvar%2frun%2fslapd-server.socket backend suffix list --suffix

Who are you logging into the cockpit UI as? root?

I can reproduce your error if I use a non-root user to bind. I suspect you are not logging into cockpit as root. Or not a user in the admin group with nopassword sudo rights. Make sure to also check "Reuse my password for privileged tasks" when logging into cockpit

[root@server ~]# dsconf -j ldapi://%2fvar%2frun%2fslapd-server.socket backend suffix list --suffix
{"desc": "Inappropriate authentication", "info": "SASL EXTERNAL bind requires an SSL connection"}

Can you provide the cn=config entry from dse.ldif? I want to see all the ldapi settings, thanks!

Can you provide the cn=config entry from dse.ldif? I want to see all the ldapi settings, thanks!

If the config entry from a previous comment is accurate then all you have to do is set:

nsslapd-ldapiautobind: on

That did the trick. It seems to be working, now. Thanks!

Metadata Update from @imntreal:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

389-ds-base is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in 389-ds-base's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/389ds/389-ds-base/issues/4119

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata Update from @spichugi:
- Issue close_status updated to: wontfix (was: fixed)

Metadata