In NethServer/ns8-samba 3.5.0, samba-dc/usr/local/sbin/join-domain executes samba-tool domain join inside a brace group piped to tee:
{ samba-tool domain join ... || exit_code=$?
} | tee "$tmpout"
...
exit "${exit_code:-0}"
Bash runs the left pipeline component in a subshell, so its assignment to exit_code is lost. The pipeline returns tee's status (usually zero), and non-credential join failures are reported as success. The NS8 module's configure-module/40start_provisioning then may start and advertise a partially provisioned DC. A failed join may leave a stale computer account in the remote AD.
Minimal reproduction:
bash -c 'unset exit_code; { false || exit_code=$?; } | cat; printf "reported=%s\n" "${exit_code:-0}"'
# reported=0
Capture the exit status with PIPESTATUS[0] immediately after the pipeline or another status-preserving pattern, and retain the LDAP insufficient-rights mapping to exit 34. samba-dc/usr/local/sbin/join-member uses a similar pipeline and should be checked as well.
The ns8-samba repository has Issues disabled (HTTP 410), so I am filing this in the NethServer development tracker.
In NethServer/ns8-samba 3.5.0,
samba-dc/usr/local/sbin/join-domainexecutessamba-tool domain joininside a brace group piped totee:{ samba-tool domain join ... || exit_code=$? } | tee "$tmpout" ... exit "${exit_code:-0}"Bash runs the left pipeline component in a subshell, so its assignment to
exit_codeis lost. The pipeline returnstee's status (usually zero), and non-credential join failures are reported as success. The NS8 module'sconfigure-module/40start_provisioningthen may start and advertise a partially provisioned DC. A failed join may leave a stale computer account in the remote AD.Minimal reproduction:
Capture the exit status with
PIPESTATUS[0]immediately after the pipeline or another status-preserving pattern, and retain the LDAP insufficient-rights mapping to exit 34.samba-dc/usr/local/sbin/join-memberuses a similar pipeline and should be checked as well.The ns8-samba repository has Issues disabled (HTTP 410), so I am filing this in the NethServer development tracker.