getDiagnosticsData fails: www-data cannot mkdir /var/www/html/userdata on SSVM (Permission denied)
- 主要言語
- Java
- スター
- 3.1k
- フォーク
- 1.4k
- 平均マージ
- 6日 19時間
- マージ済み PR(30日)
- 32
説明
# problem
Retrieving diagnostics from a system VM fails. The archive is collected on the target VM, but the async job then errors and no download URL is produced:
```
Unable to create a link for entity at diagnostics//diagnostics_files_.zip on ssvm, Error in creating directory =mkdir: cannot create directory '/var/www/html/userdata//': Permission denied
```
Expected: the job succeeds and returns a usable download URL.
# versions
- CloudStack 4.22.1.0 (management and agents)
- System VMs from the stock `systemvm-kvm-4.22.0` template, not customized
- KVM hypervisors, NFS secondary storage
# The steps to reproduce the bug
1. Run `getDiagnosticsData` against a running system VM, e.g. `cmk get diagnosticsdata targetid= files=/var/log/cloud.log`.
2. Wait for the async job to complete.
3. The job fails with errorcode 530 and the error above.
# What to do about it?
The download directory is created as the `www-data` user ([UploadManagerImpl.java#L277-L291](https://github.com/apache/cloudstack/blob/4.22/services/secondary-storage/server/src/main/java/org/apache/cloudstack/storage/template/UploadManagerImpl.java#L277-L291)), but the docroot on the SSVM is not writable by `www-data`. Shipping `/var/www/html/userdata` owned by `www-data` in the system VM template, or creating it as root and chowning, would fix it. `extractVolume`/`extractTemplate` downloads use the same directory and may be affected as well; only the diagnostics case is verified.
Workaround on a running SSVM: `mkdir -p /var/www/html/userdata && chown www-data:www-data /var/www/html/userdata` (lost on SSVM recreation).
コントリビューションガイド
調査の方向性
UploadManagerImpl.java の 277-291 行目から始め、issue にあるコマンドを使って、実行中の system VM に対して getDiagnosticsData を再現します。SSVM template が /var/www/html/userdata をどのように作成して権限を設定するかを、関連する extractVolume および extractTemplate のパスも含めて確認します。async job が成功し、手動の回避策なしで使用可能な download URL を返せば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- java
- 領域
- cloud, infrastructure
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 55/100