Skip to content

nss_cache: implement initgroups_dyn - #113

Open
kmjohansen wants to merge 1 commit into
google:mainfrom
kmjohansen:johansen/initgroups-dyn
Open

kmjohansen wants to merge 1 commit into
google:mainfrom
kmjohansen:johansen/initgroups-dyn

Conversation

@kmjohansen

Copy link
Copy Markdown
Contributor

glibc's libnss has a callback for initgroups(3) which it uses preferentially to getgrent_r. The getgrent_r fallback is used if initgroups_dyn is not implemented, but glibc does not have any serialization around the callback. This means that if multiple threads call initgroups simultaneously and the nss backend does not implment initgroups_dyn, then it's possible the supplemental group lists will become truncated as multiple getgrent_r calls race with one another.

Fix this in libnss_cache by implementing an initgroups_dyn callback. This callback is written in the style of nss-files but with the libnss-cache idioms. It holds the cache lock across the getgrent_r iteration to ensure no supplemental group calls are truncated.

This was tested by reproducing the truncation race with an fresh nscd that is bombarded with id -G calls. Without this fix present, it's possible to observe truncated results. However, with initgroups_dyn users always get their correct supplemental groups.

glibc's libnss has a callback for initgroups(3) which it uses
preferentially to getgrent_r.  The getgrent_r fallback is used if
initgroups_dyn is not implemented, but glibc does not have any
serialization around the callback.  This means that if multiple threads
call initgroups simultaneously and the nss backend does not implment
initgroups_dyn, then it's possible the supplemental group lists will
become truncated as multiple getgrent_r calls race with one another.

Fix this in libnss_cache by implementing an initgroups_dyn callback.
This callback is written in the style of nss-files but with the
libnss-cache idioms.  It holds the cache lock across the getgrent_r
iteration to ensure no supplemental group calls are truncated.

This was tested by reproducing the truncation race with an fresh nscd
that is bombarded with id -G calls.  Without this fix present, it's
possible to observe truncated results.  However, with initgroups_dyn
users always get their correct supplemental groups.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant