Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #79005 > unrolled thread

Bug#1035840: nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency

Started byAram Akhavan <debian@aram.nubmail.ca>
First post2023-05-10 04:40 +0200
Last post2023-08-01 15:40 +0200
Articles 4 — 4 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1035840: nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency Aram Akhavan <debian@aram.nubmail.ca> - 2023-05-10 04:40 +0200
    Bug#1035840: nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency Diederik de Haas <didi.debian@cknow.org> - 2023-05-10 10:10 +0200
    Bug#1035840: nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency Salvatore Bonaccorso <carnil@debian.org> - 2023-05-11 06:40 +0200
    Bug#1035840: marked as done (nfs-utils: nfs-idmapd startup race  condition due to missing systemd dependency) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2023-08-01 15:40 +0200

#79005 — Bug#1035840: nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency

FromAram Akhavan <debian@aram.nubmail.ca>
Date2023-05-10 04:40 +0200
SubjectBug#1035840: nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency
Message-ID<GtHUd-7OFi-1@gated-at.bofh.it>
Package: nfs-common
Version: 1:1.3.4-6
Severity: important
Tags: upstream
X-Debbugs-Cc: debian@aram.nubmail.ca

Dear Maintainer,

The nfs-idmapd.service included in nfs-utils does not wait for the
network to start. If DNS resolution is not yet available, and no domain
is explicitly set up in the config file, then due to
the behavior of libnfsidmap, the NFSv4 domain reverts to the default
"localdomain", which breaks id mapping, and thus any export that needs
it.

nfs-server.service already has Wants= and After=network-online.target,
but nfs-idmapd.service starts after it, potentially before the network
is up. Given that nfs-idmapd needs the network, DNS specifically, the same
should probably be added to its systemd service.

It's worth noting that in my case, adding this did not completely
resolve the race condition (i.e., DNS still came up after), but it did
reduce the amount of delay I needed to add to nfs-idmapd.service startup
to have id mapping start correctly.

This issue exists in the upstream nfs-utils source.

Part of the problem needs to be addressed in libnfsidmap: if the
DNS lookup of the hostname fails, it fallsback to "localdomain", but
it could instead use the domain part of the hostname, if it exists. I
will create a separate bug report for that.

I sent an email about this to the nfs mailing list with more info about
the race overall as well as the context, but got no responses (see https://marc.info/?l=linux-nfs&m=167834665013860&w=2).
I'm hoping someone on the Debian team can point me in the right direction in terms of whether this fix is
appropriate and how to submit a patch upstream.

Thanks,

Aram

-- Package-specific info:
-- rpcinfo --

-- System Information:
Debian Release: 11.4
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-16-amd64 (SMP w/4 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages nfs-common depends on:
ii  adduser             3.118
ii  keyutils            1.6.1-2
ii  libc6               2.31-13+deb11u3
ii  libcap2             1:2.44-1
ii  libcom-err2         1.46.2-2
ii  libdevmapper1.02.1  2:1.02.175-2.1
ii  libevent-2.1-7      2.1.12-stable-1
ii  libgssapi-krb5-2    1.18.3-6+deb11u1
ii  libkeyutils1        1.6.1-2
ii  libkrb5-3           1.18.3-6+deb11u1
ii  libmount1           2.36.1-8+deb11u1
ii  libnfsidmap2        0.25-6
ii  libtirpc3           1.3.1-1+deb11u1
ii  libwrap0            7.6.q-31
ii  lsb-base            11.1.0
ii  rpcbind             1.2.5-9
ii  ucf                 3.0043

Versions of packages nfs-common recommends:
ii  python3  3.9.2-3

Versions of packages nfs-common suggests:
pn  open-iscsi  <none>
pn  watchdog    <none>

Versions of packages nfs-kernel-server depends on:
ii  keyutils      1.6.1-2
ii  libblkid1     2.36.1-8+deb11u1
ii  libc6         2.31-13+deb11u3
ii  libcap2       1:2.44-1
ii  libsqlite3-0  3.34.1-3
ii  libtirpc3     1.3.1-1+deb11u1
ii  libwrap0      7.6.q-31
ii  lsb-base      11.1.0
ii  netbase       6.3
ii  ucf           3.0043

-- Configuration Files:
/etc/default/nfs-common changed [not included]

-- no debconf information

[toc] | [next] | [standalone]


#79015

FromDiederik de Haas <didi.debian@cknow.org>
Date2023-05-10 10:10 +0200
Message-ID<GtN3z-7S3t-13@gated-at.bofh.it>
In reply to#79005

[Multipart message — attachments visible in raw view] — view raw

On Wednesday, 10 May 2023 04:29:10 CEST Aram Akhavan wrote:
> Package: nfs-common
> Version: 1:1.3.4-6

We're currently at version 2.6.2 (or .3 in experimental) and I doubt that 
upstream cares about version 1.3.4.
Can you reproduce the issue with version 2.6.2 (or higher)?

[toc] | [prev] | [next] | [standalone]


#79026

FromSalvatore Bonaccorso <carnil@debian.org>
Date2023-05-11 06:40 +0200
Message-ID<Gu6fT-83KV-3@gated-at.bofh.it>
In reply to#79005
HI Aram,

On Wed, May 10, 2023 at 04:39:34PM -0700, Aram Akhavan wrote:
> Yes. The issue still exists with nfs-common 2.6.2 (and the new libnfsidmap1
> dependency). Not surprising since systemd unit in question is the same. The
> fix for nfs-idmapd.service is a trivial two-line addition:
> 
> Wants=network-online.target
> After=network-online.target
> 
> I recall a comment somewhere mentioning that other distros already implement
> this fix. I can dig up which particular one, if it's helpful.
> 
> Please let me know how to proceed!

We have diverged already too much in past with nfs-utils from
upstream, leading to Debian having for a very long time ancient
nfs-utils versions. So the way to go here is to make sure the fix is
integrated upstream in the service files. Then we can pick up the fix
in anvance and drop it again once we rebase the version.

Does this helps?

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#79882 — Bug#1035840: marked as done (nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2023-08-01 15:40 +0200
SubjectBug#1035840: marked as done (nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency)
Message-ID<GXXLr-4iFp-21@gated-at.bofh.it>
In reply to#79005

[Multipart message — attachments visible in raw view] — view raw

Your message dated Tue, 01 Aug 2023 13:19:48 +0000
with message-id <E1qQpHw-0014fF-0D@fasolo.debian.org>
and subject line Bug#1035840: fixed in nfs-utils 1:2.6.3-3
has caused the Debian Bug report #1035840,
regarding nfs-utils: nfs-idmapd startup race condition due to missing systemd dependency
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1035840: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035840
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web