NetBSD Problem Report #48658

From john@andromeda.ziaspace.com  Fri Mar 14 21:52:04 2014
Return-Path: <john@andromeda.ziaspace.com>
Received: from mail.netbsd.org (mail.netbsd.org [149.20.53.66])
	(using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits))
	(Client CN "mail.netbsd.org", Issuer "Postmaster NetBSD.org" (verified OK))
	by mollari.NetBSD.org (Postfix) with ESMTPS id 3014AA57FF
	for <gnats-bugs@gnats.NetBSD.org>; Fri, 14 Mar 2014 21:52:04 +0000 (UTC)
Message-Id: <201403142151.s2ELpsQv026850@andromeda.ziaspace.com>
Date: Fri, 14 Mar 2014 21:51:54 GMT
From: john@ziaspace.com
Reply-To: john@ziaspace.com
To: gnats-bugs@gnats.NetBSD.org
Subject: BIND doesn't work in chroot after OpenSSL update
X-Send-Pr-Version: 3.95

>Number:         48658
>Category:       pkg
>Synopsis:       BIND doesn't work in chroot after OpenSSL update
>Confidential:   no
>Severity:       serious
>Priority:       high
>Responsible:    pkg-manager
>State:          closed
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Fri Mar 14 21:55:00 +0000 2014
>Closed-Date:    Fri Dec 26 23:03:33 +0000 2014
>Last-Modified:  Fri Dec 26 23:03:33 +0000 2014
>Originator:     John Klos
>Release:        NetBSD 5.2_STABLE
>Organization:

>Environment:


System: NetBSD andromeda.ziaspace.com 5.2_STABLE NetBSD 5.2_STABLE (ANDROMEDA-$Revision: 5.2Y $) #0: Tue Dec 31 21:31:39 UTC 2013 john@andromeda.ziaspace.com:/usr/obj-macppc/sys/arch/macppc/compile/ANDROMEDA macppc
Architecture: powerpc
Machine: macppc
>Description:

After updating net/bind99 from pkgsrc which now uses OpenSSL, also from 
pkgsrc, BIND will not start in a chroot:
Mar 14 21:38:46 andromeda named[10042]: ENGINE_by_id failed (crypto failure)
Mar 14 21:38:46 andromeda named[10042]: error:25070067:DSO support 
routines:DSO_load:could not load the shared library:dso_lib.c:244:
Mar 14 21:38:46 andromeda named[10042]: error:260B6084:engine 
routines:DYNAMIC_LOAD:dso not found:eng_dyn.c:450:
Mar 14 21:38:46 andromeda named[10042]: error:2606A074:engine 
routines:ENGINE_by_id:no such engine:eng_list.c:417:id=gost
Mar 14 21:38:46 andromeda named[10042]: initializing DST: crypto failure
Mar 14 21:38:46 andromeda named[10042]: exiting (due to fatal error)
>How-To-Repeat:

Update net/bind99 on a system which uses pkgsrc OpenSSL. Try to run in 
chroot. Apparently BIND only uses OpenSSL on NetBSD 5 and older.
>Fix:

mkdir -p /var/chroot/named/usr/local/lib
cp -R /usr/local/lib/engines /var/chroot/named/usr/local/lib/

Or don't run in a chroot for now.

>Release-Note:

>Audit-Trail:
From: "OBATA Akio" <obata@lins.jp>
To: gnats-bugs@netbsd.org
Cc: 
Subject: Re: pkg/48658: BIND doesn't work in chroot after OpenSSL update
Date: Mon, 24 Mar 2014 18:32:17 +0900

 Following change may resolve the issue:

 Index: Makefile
 ===================================================================
 RCS file: /cvsroot/pkgsrc/net/bind99/Makefile,v
 retrieving revision 1.34
 diff -u -r1.34 Makefile
 --- Makefile    11 Mar 2014 14:34:38 -0000      1.34
 +++ Makefile    24 Mar 2014 09:30:01 -0000
 @@ -56,7 +56,8 @@
   DOCS=                  CHANGES FAQ README

   FILES_SUBST+=          BIND_GROUP=${BIND_GROUP:Q} \
 -                       BIND_USER=${BIND_USER:Q} PAX=${PAX:Q}
 +                       BIND_USER=${BIND_USER:Q} PAX=${PAX:Q} \
 +                       SSLBASE=${SSLBASE:Q}
   MESSAGE_SUBST+=                BIND_DIR=${BIND_DIR} BIND_USER=${BIND_USER}
   DOCDIR=                        ${DESTDIR}${PREFIX}/share/doc/bind9

 Index: files/named9.sh
 ===================================================================
 RCS file: /cvsroot/pkgsrc/net/bind99/files/named9.sh,v
 retrieving revision 1.2
 diff -u -r1.2 named9.sh
 --- files/named9.sh     20 May 2012 12:00:15 -0000      1.2
 +++ files/named9.sh     24 Mar 2014 09:30:01 -0000
 @@ -49,12 +49,12 @@
                      @CP@ -p /etc/localtime "${named_chrootdir}/etc/localtime"
          fi

 -       if [ -f /usr/lib/engines/libgost.so ]; then
 -               if [ ! -d ${named_chrootdir}/usr/lib/engines ]; then
 -                       @MKDIR@ ${named_chrootdir}/usr/lib/engines
 +       if [ -f @SSLBASE@/lib/engines/libgost.so ]; then
 +               if [ ! -d ${named_chrootdir}@SSLBASE@/lib/engines ]; then
 +                       @MKDIR@ ${named_chrootdir}@SSLBASE@/lib/engines
                  fi
 -               @CMP@ -s /usr/lib/engines/libgost.so "${named_chrootdir}/usr/lib/engines/libgost.so" || \
 -                   @CP@ -p /usr/lib/engines/libgost.so "${named_chrootdir}/usr/lib/engines/libgost.so"
 +               @CMP@ -s @SSLBASE@/lib/engines/libgost.so "${named_chrootdir}@SSLBASE@/lib/engines/libgost.so" || \
 +                   @CP@ -p @SSLBASE@/lib/engines/libgost.so "${named_chrootdir}@SSLBASE@/lib/engines/libgost.so"
          fi

                  if [ ! -d ${named_chrootdir}@VARBASE@/run/named ]; then

State-Changed-From-To: open->feedback
State-Changed-By: obache@NetBSD.org
State-Changed-When: Tue, 01 Apr 2014 11:02:21 +0000
State-Changed-Why:
Please try to apply proposed patch and feedback the result.


From: "OBATA Akio" <obache@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc: 
Subject: PR/48658 CVS commit: pkgsrc/net/bind99
Date: Fri, 12 Dec 2014 07:39:33 +0000

 Module Name:	pkgsrc
 Committed By:	obache
 Date:		Fri Dec 12 07:39:32 UTC 2014

 Modified Files:
 	pkgsrc/net/bind99: Makefile
 	pkgsrc/net/bind99/files: named9.sh

 Log Message:
 Use SSLBASE for location of engines.
 PR pkg/48658.


 To generate a diff of this commit:
 cvs rdiff -u -r1.40 -r1.41 pkgsrc/net/bind99/Makefile
 cvs rdiff -u -r1.2 -r1.3 pkgsrc/net/bind99/files/named9.sh

 Please note that diffs are not public domain; they are subject to the
 copyright notices on the relevant files.

State-Changed-From-To: feedback->closed
State-Changed-By: dholland@NetBSD.org
State-Changed-When: Fri, 26 Dec 2014 23:03:33 +0000
State-Changed-Why:
Feedback timeout on patch suggested in April; patch committed in December.


>Unformatted:

NetBSD Home
NetBSD PR Database Search

(Contact us) $NetBSD: query-full-pr,v 1.39 2013/11/01 18:47:49 spz Exp $
$NetBSD: gnats_config.sh,v 1.8 2006/05/07 09:23:38 tsutsui Exp $
Copyright © 1994-2007 The NetBSD Foundation, Inc. ALL RIGHTS RESERVED.