Skip to main content
Question

Please add more specific error message for sudo during installation

  • August 20, 2019
  • 5 replies
  • 22 views

MariusI

Hello all!
Just finished a day of troubleshooting a new vertica installation coming up, unfortunately the error message was totally different than what the actual issue was, and put me in some weird directions and in the end i just manage to resolve it due to dumb luck.
If SUDO fails to run properly, due to NOPASSWD not being set on the user, it will return errors on all other checks as well. It will complain that your default shell is not bash, that the ssh session times out, that your /opt/vertica permissions is not set properly++, all which was already setup correctly.
Now the issue itself was 100% on my side, i put the NOPASSWD config too high in our sudoers file, which ended up being overwritten longer down the line.
If the installer script would have pointed this out from the start, that sudo did not perform correctly, it would have saved both me and someone else a large amount of work :)
The only way we came across it was to comment out each health check in the init.py in the vertica installation python folder, and in the end we could see that it was having more trouble with sudo than anything else...

5 replies

skeswani
Forum|alt.badge.img
  • Participating Frequently
  • August 20, 2019

you need sudo access to read the sudoers file.
Hence in order to detect a mis-configuration in the sudoers file you need to have the sudoers file configured correctly.

skeswani@skeswani-laptop:~$ cat /etc/sudoers
cat: /etc/sudoers: Permission denied

This is not a bug or a feature request. Its not possible to protect against these kinds of error.


MariusI
  • Author
  • New Participant
  • August 20, 2019

The returned error during ssh.execute in your scripts is sudo asking for a password, that could easily be picked up and displaying the proper error message instead of failing and displaying the wrong errors.


skeswani
Forum|alt.badge.img
  • Participating Frequently
  • August 20, 2019

agreed, can you open a ticket.
What error was seen and what you would expect to see in order to better diagnose the problem


MariusI
  • Author
  • New Participant
  • August 20, 2019

Unfortunately I am unaware of the process (I work with Micro Focus, and not Vertica directly). Would you be able to copy paste it into a ticket?
Comment is:
If sudo is misconfigured on any node during a cluster installation, any pre-check will fail and the error message returned complains that the pre-check fails + the ssh connection timing out. Example below:

Mapping hostnames in --hosts (-s) to addresses...
Starting installation tasks.
Getting system information for cluster (this may take a while)...
Error: Default shell on the following nodes are not bash. Default shell must be set to bash.
10.10.11.34 SSH (Connection timed out):
(10.10.11.34)
Exiting...
Installation FAILED with errors.
Installation stopped before any changes were made.

The error message states that the default shell is wrong and that the connection timed out, but what actually happens is that the sudo commands asks for a password, which is what breaks the script.
In your code, when elevating the logged in user with sudo, please add a check before it, that ensures that a password prompt is not returned.
There is certain patterns already used, but this does not take into account that other languages might be used (which in my case was german)
"searcher: searcher_re:
0: TIMEOUT
1: EOF
2: re.compile("(?i)are you sure you want to continue connecting")
3: re.compile("(?i)permission denied")
4: re.compile("(?i)terminal type\?")
5: re.compile("VERTICA MAGIC PROMPT:")
6: re.compile("Disconnecting: Timeout, server not responding")
** 7: re.compile("(?i)(?:(?<=\s)|^)\bpassword\b")**
8: re.compile("][#$]|~[#$]|bash.*?[#$]|[#$]|[>$] *")"

Possible solution:
Instead of using regular expressions for this specific option, you can add "if sudo -n true 2>/dev/null; then ". Because if this fails, that means a password is needed, run this check before your other commands, especially the first pre-check, or add it as the first pre-check by itself would resolve your issue.


MariusI
  • Author
  • New Participant
  • August 20, 2019

Unfortunately i am unable to create a ticket (not direct Vertica employee, but Micro Focus Employee), would you be able to help on this?
When sudo is not configured correctly on a node, the error returned is something completely different and confusing, example:

Vertica Analytic Database 9.2.1-0 Installation Tool
Validating options...
Mapping hostnames in --hosts (-s) to addresses...
Starting installation tasks.Getting system information for cluster (this may take a while)...
Error: Default shell on the following nodes are not bash. Default shell must be set to bash.
10.10.11.34 SSH (Connection timed out):
(10.10.11.34)
Exiting...
Installation FAILED with errors.

When this happens, it makes it so that customers (including me) starts looking at the errors above, like bash shell not being configured, or that connections are timing out, or that permissions are wrong on a folder.
The current implementations looks for something similar, but does not take into account that other languages are used, the current regex implementation below:

searcher: searcher_re:
0: TIMEOUT
1: EOF
2: re.compile("(?i)are you sure you want to continue connecting")
3: re.compile("(?i)permission denied")
4: re.compile("(?i)terminal type\?")
5: re.compile("VERTICA MAGIC PROMPT:")
6: re.compile("Disconnecting: Timeout, server not responding")
7: re.compile("(?i)(?:(?<=\s)|^)\bpassword\b")
8: re.compile("][#$]|~[#$]|bash.*?[#$]|[#$]|[>$] *")

If you add sudo as a pre-check, it would save us a lot of time.
For example, in /opt/vertica/oss/python/lib/python2.7/site-packages/vertica/install/init.py
you can add another pre-check, that always runs first, which runs:
"if sudo -n true 2>/dev/null; then "
This returns true if sudo is running without a password, and false if it asks for a password, then you can continue the other checks afterwards.