zun compute - failed to drop privileges

Bug #1883604 reported by alpha23
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Zun
Undecided
Unassigned
kolla
Undecided
hongbin
Rocky
Medium
Radosław Piliszek
kolla-ansible
Undecided
hongbin

Bug Description

Rocky/stable, deployed via kolla-ansible centos/source containers.

Error during Manager.inventory_host: FailedToDropPrivileges: privsep helper command exited non-zero (96)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task Traceback (most recent call last):
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/oslo_service/periodic_task.py", line 220, in run_periodic_tasks
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task task(self, context)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/zun/compute/manager.py", line 1060, in inventory_host
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task rt.update_available_resources(context)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/zun/compute/compute_node_tracker.py", line 65, in update_available_resources
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task self.container_driver.get_available_resources(node)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/zun/container/driver.py", line 251, in get_available_resources
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task disk_total = self.get_total_disk_for_container()
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/zun/container/docker/driver.py", line 1078, in get_total_disk_for_container
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task run_as_root=True)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/zun/common/utils.py", line 352, in execute
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task return execute_root(*cmd, **kwargs)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/oslo_privsep/priv_context.py", line 206, in _wrap
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task self.start()
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/oslo_privsep/priv_context.py", line 217, in start
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task channel = daemon.RootwrapClientChannel(context=self)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task File "/var/lib/kolla/venv/lib/python2.7/site-packages/oslo_privsep/daemon.py", line 327, in __init__
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task raise FailedToDropPrivileges(msg)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task FailedToDropPrivileges: privsep helper command exited non-zero (96)
2020-06-15 14:53:06.412 7 ERROR oslo_service.periodic_task

hongbin (hongbin034)
Changed in kolla-ansible:
assignee: nobody → hongbin (hongbin034)
status: New → Confirmed
Revision history for this message
hongbin (hongbin034) wrote :
Changed in zun:
status: New → Invalid
Revision history for this message
hongbin (hongbin034) wrote :
Revision history for this message
hongbin (hongbin034) wrote :
Changed in kolla:
status: New → In Progress
assignee: nobody → hongbin (hongbin034)
Changed in kolla-ansible:
status: Confirmed → Invalid
Changed in kolla:
status: In Progress → Invalid
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to kolla (stable/rocky)

Reviewed: https://review.opendev.org/737198
Committed: https://git.openstack.org/cgit/openstack/kolla/commit/?id=dd0069addbfba430d1a8cf15e91005d0f0279c11
Submitter: Zuul
Branch: stable/rocky

commit dd0069addbfba430d1a8cf15e91005d0f0279c11
Author: Hongbin Lu <email address hidden>
Date: Sun Sep 30 16:14:31 2018 +0000

    Add /var/lib/kolla/venv/bin to Zun exec_dirs

    This is necessary for rootwrap/privsep to work properly

    Closes-Bug: #1883604
    Change-Id: I128fb04a5ddeb77428697d33e2015158bc74738f
    (cherry picked from commit 570a6120be48dde70a793be52574a0ae1e0fce6f)

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers