#8496 [Tracker] Multiple nightly test failures in test_dnssec, test_backup_and_restore and test_dns_locations
Closed: fixed by frenaud. Opened by frenaud.

The nightly tests [testing_master_389ds] and [testingipa-4.8] have new failures in test_dnssec and test_backup_and_restore. See PR #403: test report and PR#623, report

  • test_integration/test_dnssec.py::TestInstallDNSSECLast::test_if_zone_is_signed_master
  • test_integration/test_dnssec.py::TestInstallDNSSECLast::test_disable_reenable_signing_master
  • test_integration/test_dnssec.py::TestInstallDNSSECFirst::test_sign_root_zone
  • test_integration/test_dnssec.py::TestMigrateDNSSECMaster::test_migrate_dnssec_master
  • test_integration/test_dnssec.py::TestInstallDNSSECFirst::test_chain_of_trust
  • test_integration/test_backup_and_restore.py::TestBackupReinstallRestoreWithDNSSEC::test_full_backup_reinstall_restore_with_DNSSEC_zone

The failures need to be investigated as they were seen only with 389ds/nightly copr repo. This repo contains a fix related to syncrepl: 51190 that could be related to the new failures


Linking to https://github.com/389ds/389-ds-base/issues/4329 on DS side

Metadata Update from @frenaud:
- Issue tagged with: test-failure, tests

Additional failures seen in testing_master_testing_selinux Nightly PR #459
logs

And indeed, there is a new version of DS in testing: https://bodhi.fedoraproject.org/updates/FEDORA-2020-f7a1de9dec

A complete investigation must be done.

Early fix of https://github.com/389ds/389-ds-base/issues/4329 does not fix the DNSSEC regression.
I suspect that DNSSEC failures are related to https://github.com/389ds/389-ds-base/issues/4363

The issue also happens in [testing_master_testing] since 389-ds-base-1.4.3.13-1.fc32 has been pushed to updates-testing 2020-10-05, see PR #468

And now in [testing_master] since 389-ds-base-1.4.3.13-1.fc32 has been pushed to updates

Metadata Update from @frenaud:
- Issue tagged with: tracker

Similar error observed in [testing_master_testing_selinux] PR 526 : Logs
for tests:
- test_sign_root_zone
- test_chain_of_trust
- test_migrate_dnssec_master

Similar error observed in [testing_master_testing_selinux] PR 526 : Logs
for test:
- test_replica_promotion_TestHiddenReplicaKRA
- test_replica_promotion_TestHiddenReplicaPromotion : Logs
- test_replica_promotion_TestProhibitReplicaUninstallation : Logs
- test_replication_layouts_TestLineTopologyWithCA : Logs
- http://freeipa-org-pr-ci.s3-website.eu-central-1.amazonaws.com/jobs/593e001c-2445-11eb-8c57-fa163eeafbeb/report.html : Logs

master:

  • a33530f2f6cc7933edc537eb5055d4f147741654 ipatests: temporarily remove test_dnssec.py::TestInstallDNSSECFirst from gating

ipa-4-8:

  • c694c0f8199e3c830511026fc17ae4f34a617b76 ipatests: temporarily remove test_dnssec.py::TestInstallDNSSECFirst from gating

The issue also affects
- TestDNSLocations::test_without_locations
- TestDNSLocations::test_nsupdate_without_locations
- TestDNSLocations::test_one_replica_in_location
- TestDNSLocations::test_adtrust_system_records

test failures observed:
test_ipa_ca_records
test_adtrust_system_records
PR
report

test failures observed:

test_if_zone_is_signed_replica
test_disable_reenable_signing_replica

PR
report

test failures obersved due to dns

test_hidden_replica_automatic_crl
test_replica_from_hidden

PR report

Metadata Update from @frenaud:
- Issue assigned to frenaud

Metadata Update from @frenaud:
- Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/5571

master:

  • f3cd85ea81fc5b255670b4759161d49b07ef8a08 freeipa.spec: bump the required version of 389ds

ipa-4-9:

  • 1c1c469fc94b3c6b26a73173bfba7698108ec69c freeipa.spec: bump the required version of 389ds

Remaining work:
- The 389ds version still needs to be bumped on fedora32, we are waiting for a build with the fix.
For full ref, the 389ds ticket is https://github.com/389ds/389-ds-base/issues/4526
- When the fix is available on all supported version we can re-add test_dnssec.py::TestInstallDNSSECFirst to gating

Test failures observed in testing_master_previous :

test_integration/test_backup_and_restore.py::TestBackupReinstallRestoreWithDNSSEC::test_full_backup_reinstall_restore_with_DNSSEC_zone : PR Logs

test_replica_promotion_TestHiddenReplicaKRA : PR Logs

test_replica_promotion_TestProhibitReplicaUninstallation : PR Logs

test_replication_layouts_TestLineTopologyWithCA PR
Logs

test_replication_layouts_TestLineTopologyWithCAKRA : PR Logs

Faliures observed in : testing_master_previous

dns_locations : PR 753
Logs

test_client_uninstallation PR 753
Logs

test_replica_promotion_TestHiddenReplicaPromotion PR 753
Logs

test_replica_promotion_TestProhibitReplicaUninstallation : PR Logs

test_line_topology_with_ca : PR753 Logs

test_line_topology_with_ca_kra : PR753 Logs

master:

  • a9b4ed4f528b01076403750872ddb899532b6c01 ipatests: re-add test_dnssec.py::TestInstallDNSSECFirst in gating
  • fb107b9180ad1d679d2b0842536cc9cb907b96f5 ipatests: fix TestInstalDNSSECFirst::test_resolvconf logic

ipa-4-9:

  • ab23ecdad53d2095d9534a4c941dab7e205f286c ipatests: re-add test_dnssec.py::TestInstallDNSSECFirst in gating
  • 5af574326bd60c52ddcaf7f7cfe73f4e810bc04a ipatests: fix TestInstalDNSSECFirst::test_resolvconf logic

Metadata Update from @frenaud:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

ipa-4-8:

  • c02544c07d040e4e96ed17233b479c958a68b8fa azure: bump F32->F34
  • 7802e14f5e209512fc736af56972f572bc599bec freeipa.spec: do not use jsl for linting on Fedora 34+
  • 7433be926c6e084f7f1f3bead060544a1334c86e azure: Collect systemd boot log
  • 523a9f863815cccfa05f0f87269d6b448a5ab12a azure: Enforce multi-user.target as default systemd's target
  • 677df148c7d606242ae14665e3d0580f12e972b3 azure: Wait for systemd booted
  • 04c90fb4f2fb16e932f5d198cacb31c75dc9b955 azure: Remove no longer needed repo
  • 8fea2f6f3573cd18f6d1cf2af5f95f0f5da2a643 azure: Mask systemd-resolved
  • 976a3bf4c388e71c3dc85c8c50b9c727bc07de65 ipatests: Update expectations for test_detect_container
  • e5731634a17aa96f4efa235f12bcca993726e6fc azure: Add workaround for PhantomJS against OpenSSL 1.1.1
  • 01237953a21b80219ebd6665e0eb67558a951a83 azure: Warn about memory issues
  • 835df314d65f42c2e36ac52737eecc1f4e9536e6 BIND: Setup logging
  • 2a9dea81254accb08a114a0e853a4c485d1082e4 ipatests: Setup and collect BIND logs
  • e23f9767ce2d509c00efa3c0fa5684e7a1fe1973 azure: Run Base and XMLRPC tests is isolated network
  • 34e1f6ab3971468a0fa485fe7588e469632d3d0f ipatests: Handle network-isolated mode
  • c8e5867d01e4a3a75f7abebf08caf29bbeae5eb6 dnsutil: Improvements for IPA DNS Resolver
  • fe0b5ff449da473a69449f7c3267e4a17245a753 dns: get_reverse_zone: Ignore resolver's timeout
  • d40306b90527337e504d019797ffb41b7c13d035 pytest: Show extra summary information for all except passed tests
  • ff70aacbf8f9035ec496c5e8ea8b23ac6724a8c6 ipatests: Ignore warnings on failed to read files on tarring
  • cb3b396fbbbf11462597a7289d5a89cb9fe2cbc9 ipatests: Suppress list trust or certificates
  • 21a520181f0e8c2a1e19b3a9e559fd77d9df4b04 azure: Collect installed packages
  • c65c7eb05779425355266486c02a30d9cc1f9659 ipatests: dnssec: Add alternative approach for checking chain of trust
  • 6710ff42ea853a5dcee96ab64a72051fb4e3f6f7 azure: Warn about extra and missing gating tests compared to PR-CI
  • a5730f5053a706c9ce93ef7ec4c52f44b32ca432 azure: Re-balance tests envs
  • e66eb48ac43ec513b1e787dcb0da3ee7f7ea3908 azure: coredump: Wait for systemd fully booted
  • 6561fc689800c390b8a05cec01e3e69e563edebb ipatests: re-add test_dnssec.py::TestInstallDNSSECFirst in gating
  • 8bf95380f1e3608be993e90c0005742db1cb9090 azure: Make it possible to adjust Docker resources per test env
  • 2a7f21a9c308cba33edf9ffa43c4aaf271e3a612 ipa-kdb: fix gcc complaints in kdb tests
  • e94261f9d9a09dbeca581dfe77f0ae94d2cb1c0b Set client keytab location for 389ds
  • ba6eb857ee7abf0fdead07a86e60b0308935ed38 dnssec: fix the key type with OpenDNSSEC 2.1
  • 7daf47c83a11ee9cf63462bef8c34a4899054623 ipatests: add a test for ZSK/KSK keytype in DNSKEY record
  • b8242e64ee7765d17746281192eaefc4f8fd7dcc handle Y2038 in timestamp to datetime conversions
  • 5bfe16a8182f2a2903d12ddd93c9d86a20cae198 OpenDNSSEC: fix timezone in key creation date
  • 56746ec0055803b8f6c73c382bed1132a950c0df freeipa.spec: bump the required version of 389ds
  • 2b8ccc8a1ec00fe2b4054f169233092c12d78522 freeipa.spec: synchronize with Fedora for 389-ds and PKI versions
  • a8686043a521ab115e21700c7782f3fad8ee9752 ipatests: collect config files for NetworkManager and systemd-resolved
  • bc9ca47fbd006a533a5f520fe303913b56b13712 ipatests: add utility for managing domain name resolvers
  • cdc78af9d77e22b27fc13d3a82e511f7693dff89 ipatests: setup resolvers during replica and client installations
  • 549ef48c4bf749919fcd93a7ee71641c180b1687 ipatests: do not manually modify /etc/resolv.conf in tests
  • 324ba203ebdd5e8ca5837d40a549c6f43e214d13 ipatests: disable systemd-resolved cache
  • 9a28022e4792a905137da9b8a463057473a86499 ipatests: mock resolver factory
  • 63a3cfff967eadc8b8ca07ab82ea47d876cc8491 ipatests: always try to create A records for hosts in IPA domain
  • d9744e7fa3a9ada6af44b993047fde6521f9bac3 ipatests: do not configure nameserver when installing client and replica
  • 47e9df18cd85295e02dd96c95d5888a84aaceaae ipatests: fix TestInstalDNSSECFirst::test_resolvconf logic
  • bca86ced8dd4fc36685137b32361e311ba34c04f pr-ci: Run tests on F34
  • 0b8517d6f1f09ce246ef2e6c5305099ceec8ac48 Revert "ipatests: configure client to use IPA server as DNS resolver"
  • d43d9ca8afa20c83010a3e862e806936414631fc ipatests: Fetch sudo rules without time offset
Metadata