Bug 173019
| Summary: | Nscd invalidates INITGROUPS very quickly | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | W. Michael Petullo <redhat> | ||||||||
| Component: | glibc | Assignee: | Jakub Jelinek <jakub> | ||||||||
| Status: | CLOSED RAWHIDE | QA Contact: | Brian Brock <bbrock> | ||||||||
| Severity: | medium | Docs Contact: | |||||||||
| Priority: | medium | ||||||||||
| Version: | rawhide | CC: | drepper, k.georgiou, tmraz | ||||||||
| Target Milestone: | --- | Keywords: | Reopened | ||||||||
| Target Release: | --- | ||||||||||
| Hardware: | All | ||||||||||
| OS: | Linux | ||||||||||
| Whiteboard: | |||||||||||
| Fixed In Version: | 2.4.90-17 | Doc Type: | Bug Fix | ||||||||
| Doc Text: | Story Points: | --- | |||||||||
| Clone Of: | Environment: | ||||||||||
| Last Closed: | 2006-08-03 06:45:17 UTC | Type: | --- | ||||||||
| Regression: | --- | Mount Type: | --- | ||||||||
| Documentation: | --- | CRM: | |||||||||
| Verified Versions: | Category: | --- | |||||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||||
| Embargoed: | |||||||||||
| Bug Depends On: | |||||||||||
| Bug Blocks: | 145044 | ||||||||||
| Attachments: |
|
||||||||||
|
Description
W. Michael Petullo
2005-11-12 16:33:00 UTC
Created attachment 121528 [details]
Program to test initgroups() and nscd
As of nscd-2.3.90-18, the daemon no longer crashes (that I have seen.)
However, the original symptoms remain.
The attached program may be used to test nscd. Here are some scenarios:
1. Execute program while attached to network/LDAP server, the nscd daemon
says:
31166: handle_request: request received (Version = 2) from PID 3904
31166: GETFDGR
31166: provide access to FD 9, for group
31166: handle_request: request received (Version = 2) from PID 3904
31166: INITGROUPS (mike)
31166: Haven't found "mike" in group cache!
2. Wait 10 seconds, the nscd daemon says (why removed so soon?):
31166: remove INITGROUPS entry "mike"
3. Disconnect from network, execute program, nscd daemon says:
31166: handle_request: request received (Version = 2) from PID 5090
31166: GETFDGR
31166: provide access to FD 9, for group
31166: handle_request: request received (Version = 2) from PID 5090
31166: INITGROUPS (mike)
31166: Haven't found "mike" in group cache!
Program hangs, trying to make LDAP request.
NOTE: if you disconnect and execute program before "remove INITGROUPS" message,
then program will NOT hang.
I also see this message printed by the daemon: "31166: short write in
addinitgroupsX: Broken pipe."
Can you please: 1) install glibc-debuginfo* corresponding to glibc/nscd you have installed 2) when you reproduce the hang in some application, as root gdb /usr/sbin/nscd `/sbin/pidof nscd` and get backtraces of all threads to see where exactly is it hang? It might very well be a nss_ldap bug, which is a separate package. Created attachment 121618 [details]
Backtrace of su during hang
Created attachment 121619 [details]
Backtrace of nscd threads during hang of su
It seems that nscd is prematurely invalidating its cache of initgroups data. See in comment #1, "31166: remove INITGROUPS entry 'mike'." Why is nscd invalidating this cache entry so soon after it has been entered (within seconds, according to comment #1?) You didn't explain what kind of entries are evacuated to early. I think it's an entry without auxiliary groups. For this I checked in a patch. The entries are now added with the usual timeout value. Should be in the next rawhide build. Why bz closed the bug I don't know. Until a new rawhide release is out it should remain open. The changes are in nscd-2.4.90-17 in rawhide. I tested nscd-2.4.90-21 and this seems fixed. Thank you. |