apache / apache/cloudstack

getDiagnosticsData fails: www-data cannot mkdir /var/www/html/userdata on SSVM (Permission denied)

Offen
#13,959 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
component:healthcheck Severity:Critical
Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 19 Std.
Gemergte PRs (30 T.)
32

Beschreibung

# problem

Retrieving diagnostics from a system VM fails. The archive is collected on the target VM, but the async job then errors and no download URL is produced:

```
Unable to create a link for entity at diagnostics//diagnostics_files_.zip on ssvm, Error in creating directory =mkdir: cannot create directory '/var/www/html/userdata//': Permission denied
```

Expected: the job succeeds and returns a usable download URL.

# versions

- CloudStack 4.22.1.0 (management and agents)
- System VMs from the stock `systemvm-kvm-4.22.0` template, not customized
- KVM hypervisors, NFS secondary storage

# The steps to reproduce the bug

1. Run `getDiagnosticsData` against a running system VM, e.g. `cmk get diagnosticsdata targetid= files=/var/log/cloud.log`.
2. Wait for the async job to complete.
3. The job fails with errorcode 530 and the error above.

# What to do about it?

The download directory is created as the `www-data` user ([UploadManagerImpl.java#L277-L291](https://github.com/apache/cloudstack/blob/4.22/services/secondary-storage/server/src/main/java/org/apache/cloudstack/storage/template/UploadManagerImpl.java#L277-L291)), but the docroot on the SSVM is not writable by `www-data`. Shipping `/var/www/html/userdata` owned by `www-data` in the system VM template, or creating it as root and chowning, would fix it. `extractVolume`/`extractTemplate` downloads use the same directory and may be affected as well; only the diagnostics case is verified.

Workaround on a running SSVM: `mkdir -p /var/www/html/userdata && chown www-data:www-data /var/www/html/userdata` (lost on SSVM recreation).

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginnen Sie mit den Zeilen 277–291 von UploadManagerImpl.java und reproduzieren Sie getDiagnosticsData anhand einer laufenden System-VM mit dem im Issue angegebenen Befehl. Prüfen Sie, wie das SSVM-Template /var/www/html/userdata erstellt und mit Berechtigungen versieht, einschließlich der zugehörigen extractVolume- und extractTemplate-Pfade. Als erledigt gilt die Aufgabe, wenn der asynchrone Job erfolgreich ist und eine nutzbare Download-URL zurückgibt, ohne manuelle Umgehungslösung.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
cloud, infrastructure
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.