/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to intro.xml

  • Committer: Teddy Hogeborn
  • Date: 2019-07-30 17:03:57 UTC
  • Revision ID: teddy@recompile.se-20190730170357-jte0piul5mq7j5pr
Server: Reap zombies created by multiprocessing.Process()

When creating checkers as multiprocessing.Process() objects, the
multiprocessing module also creates a parent process (for the
call_pipe() function) to call the actual checker process, but this
parent process is not reaped.  This is not a huge problem, since the
zombie is always reaped automatically the next time the multiprocess
starts a new process, but the zombies can be up to as many as there
have ever been simultaneous checker processes.  To fix this, the
process object must be join():ed when they report completion of the
child checker process.

* mandos (Client): Fix doc string to correctly state that
                   Client.checker is a multiprocess.Process() and not
                   a subprocess.Popen() object.
  (Client.checker_callback): After the returncode of the checker
                             process has been read, wait for the
                             self.checker Process object to finish by
                             calling join() on it.

Reported-by: Peter Palfrader <weasel@debian.org>

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY TIMESTAMP "2020-09-16">
 
4
<!ENTITY TIMESTAMP "2019-04-10">
5
5
<!ENTITY % common SYSTEM "common.ent">
6
6
%common;
7
7
]>
39
39
      <year>2017</year>
40
40
      <year>2018</year>
41
41
      <year>2019</year>
42
 
      <year>2020</year>
43
42
      <holder>Teddy Hogeborn</holder>
44
43
      <holder>Björn Påhlsson</holder>
45
44
    </copyright>
385
384
      plugin requirements.
386
385
    </para>
387
386
  </refsect1>
388
 
 
389
 
  <refsect1 id="systemd">
390
 
    <title>SYSTEMD</title>
391
 
    <para>
392
 
      More advanced startup systems like <citerefentry><refentrytitle
393
 
      >systemd</refentrytitle><manvolnum>1</manvolnum></citerefentry>,
394
 
      already have their own plugin-like mechanisms for allowing
395
 
      multiple agents to independently retrieve a password and deliver
396
 
      it to the subsystem requesting a password to unlock the root
397
 
      file system.  On these systems, it would make no sense to run
398
 
      <citerefentry><refentrytitle>plugin-runner</refentrytitle
399
 
      ><manvolnum>8mandos</manvolnum></citerefentry>, the plugins of
400
 
      which would largely duplicate the work of (and conflict with)
401
 
      the existing systems prompting for passwords.
402
 
    </para>
403
 
    <para>
404
 
      As for <citerefentry><refentrytitle>systemd</refentrytitle
405
 
      ><manvolnum>1</manvolnum></citerefentry> in particular, it has
406
 
      its own <ulink
407
 
      url="https://systemd.io/PASSWORD_AGENTS/">Password
408
 
      Agents</ulink> system.  Mandos uses this via its
409
 
      <citerefentry><refentrytitle>password-agent</refentrytitle
410
 
      ><manvolnum>8mandos</manvolnum></citerefentry> program, which is
411
 
      run instead of <citerefentry><refentrytitle
412
 
      >plugin-runner</refentrytitle><manvolnum>8mandos</manvolnum
413
 
      ></citerefentry> when <citerefentry><refentrytitle
414
 
      >systemd</refentrytitle><manvolnum>1</manvolnum></citerefentry>
415
 
      is used during system startup.
416
 
    </para>
417
 
  </refsect1>
 
387
  
418
388
  <refsect1 id="bugs">
419
389
    <title>BUGS</title>
420
390
    <xi:include href="bugs.xml"/>
435
405
      <manvolnum>8</manvolnum></citerefentry>,
436
406
      <citerefentry><refentrytitle>plugin-runner</refentrytitle>
437
407
      <manvolnum>8mandos</manvolnum></citerefentry>,
438
 
      <citerefentry><refentrytitle>password-agent</refentrytitle>
439
 
      <manvolnum>8mandos</manvolnum></citerefentry>,
440
408
      <citerefentry><refentrytitle>mandos-client</refentrytitle>
441
409
      <manvolnum>8mandos</manvolnum></citerefentry>,
442
410
      <citerefentry><refentrytitle>password-prompt</refentrytitle>