mirror of https://github.com/OpenIdentityPlatform/OpenDJ.git

Valery Kharseko
2 days ago 92ea60ad34783ab90ab7e2574f2169fc8ef03900
[#1157] Quote BASE_DN when the Docker bootstrap creates the userRoot backend (#1164)

Fixes #1157

### Problem

`bootstrap/setup.sh` passed the base DN to `dsconfig create-backend`
without quotes:

```sh
--set base-dn:$BASE_DN
```

If `BASE_DN` contains a space, for example `o=My Company,c=US`, the
shell splits it into `base-dn:o=My` and a stray
argument `Company,c=US`. dsconfig rejects the command line and `|| exit
1` stops the bootstrap at "creating backend".
The container never becomes healthy.

### Change

- **`setup.sh`**: `--set "base-dn:$BASE_DN"`. This was the only unquoted
use of `BASE_DN` in the Docker scripts.
- **`build.yml`**: a new step, `Docker test base DN with a space`, in
both image jobs (default and alpine), right after
`Docker test custom password`. It starts a container with `BASE_DN="o=My
Company,c=US"` and `--addBaseEntry`, waits
for it to become healthy, and checks that a base search returns `dn:
o=My Company,c=US`.

### Testing

I built the image locally from master's server zip and ran it with that
base DN.

- Without the fix, the container logs the error below and stays in
`starting`:

```
creating backend: je db-directory: db
An error occurred while parsing the command-line arguments: Argument
"Company,c=US" does not start with one or two dashes and unnamed
trailing
arguments are not allowed
```

- With the fix, the container becomes healthy and the base search
returns `dn: o=My Company,c=US`. The check the new
step makes passes.
2 files modified
22 ■■■■■ changed files
.github/workflows/build.yml 20 ●●●●● patch | view | raw | blame | history
opendj-packages/opendj-docker/bootstrap/setup.sh 2 ●●●●● patch | view | raw | blame | history
.github/workflows/build.yml
@@ -564,6 +564,16 @@
          timeout 3m bash -c 'until docker inspect --format="{{json .State.Health.Status}}" test_custom | grep -q \"healthy\"; do sleep 10; done'
          docker exec test_custom 'sh' '-c' '/opt/opendj/bin/ldapsearch --hostname localhost --port 1636 --bindDN "cn=Directory Manager" --bindPassword custom_password --useSsl --trustAll --baseDN "dc=example,dc=com" --searchScope base "(objectClass=*)" 1.1'
          docker kill test_custom
      - name: Docker test base DN with a space
        # the shell must hand the base DN to dsconfig as one value, or the bootstrap stops at
        # "creating backend" (#1157)
        shell: bash
        run: |
          trap 'code=$?; echo "::group::container logs (test_base_dn)"; docker logs test_base_dn 2>&1 || true; echo "::endgroup::"; exit $code' ERR
          docker run --rm -it -d --memory="512m" -e ADD_BASE_ENTRY="--addBaseEntry" -e BASE_DN="o=My Company,c=US" --name=test_base_dn localhost:5000/${GITHUB_REPOSITORY,,}:${{ env.release_version }}
          timeout 3m bash -c 'until docker inspect --format="{{json .State.Health.Status}}" test_base_dn | grep -q \"healthy\"; do sleep 10; done'
          docker exec test_base_dn 'sh' '-c' '/opt/opendj/bin/ldapsearch --hostname localhost --port 1636 --bindDN "cn=Directory Manager" --bindPassword password --useSsl --trustAll --baseDN "o=My Company,c=US" --searchScope base "(objectClass=*)" 1.1 | grep -qx "dn: o=My Company,c=US"'
          docker kill test_base_dn
      - name: Docker test arbitrary uid
        # OpenShift runs a container under an arbitrary uid that is only in group 0 (#1088)
        shell: bash
@@ -1010,6 +1020,16 @@
          timeout 3m bash -c 'until docker inspect --format="{{json .State.Health.Status}}" test_custom | grep -q \"healthy\"; do sleep 10; done'
          docker exec test_custom 'sh' '-c' '/opt/opendj/bin/ldapsearch --hostname localhost --port 1636 --bindDN "cn=Directory Manager" --bindPassword custom_password --useSsl --trustAll --baseDN "dc=example,dc=com" --searchScope base "(objectClass=*)" 1.1'
          docker kill test_custom
      - name: Docker test base DN with a space
        # the shell must hand the base DN to dsconfig as one value, or the bootstrap stops at
        # "creating backend" (#1157)
        shell: bash
        run: |
          trap 'code=$?; echo "::group::container logs (test_base_dn)"; docker logs test_base_dn 2>&1 || true; echo "::endgroup::"; exit $code' ERR
          docker run --rm -it -d --memory="1g" -e ADD_BASE_ENTRY="--addBaseEntry" -e BASE_DN="o=My Company,c=US" --name=test_base_dn localhost:5000/${GITHUB_REPOSITORY,,}:${{ env.release_version }}-alpine
          timeout 3m bash -c 'until docker inspect --format="{{json .State.Health.Status}}" test_base_dn | grep -q \"healthy\"; do sleep 10; done'
          docker exec test_base_dn 'sh' '-c' '/opt/opendj/bin/ldapsearch --hostname localhost --port 1636 --bindDN "cn=Directory Manager" --bindPassword password --useSsl --trustAll --baseDN "o=My Company,c=US" --searchScope base "(objectClass=*)" 1.1 | grep -qx "dn: o=My Company,c=US"'
          docker kill test_base_dn
      - name: Docker test arbitrary uid
        # OpenShift runs a container under an arbitrary uid that is only in group 0 (#1088)
        shell: bash
opendj-packages/opendj-docker/bootstrap/setup.sh
@@ -84,7 +84,7 @@
echo "creating backend: $BACKEND_TYPE db-directory: ${BACKEND_DB_DIRECTORY}"
/opt/opendj/bin/dsconfig create-backend -h localhost -p $ADMIN_PORT --bindDN "$ROOT_USER_DN" --bindPasswordFile "$PASSWORD_FILE" \
  --backend-name=userRoot --type $BACKEND_TYPE --set base-dn:$BASE_DN --set "db-directory:$BACKEND_DB_DIRECTORY" \
  --backend-name=userRoot --type $BACKEND_TYPE --set "base-dn:$BASE_DN" --set "db-directory:$BACKEND_DB_DIRECTORY" \
  --set enabled:true --no-prompt --trustAll || exit 1
if [ "$ADD_BASE_ENTRY" = "--addBaseEntry"  ]; then