[16238] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #8776] Replay Cache FD Leak

daemon@ATHENA.MIT.EDU (Daniel Yeh via RT)
Thu Jan 24 14:00:55 2019

Mail-followup-to: rt@krbdev.mit.edu
mail-copies-to: never
From: Daniel Yeh via RT <rt-comment@KRBDEV-PROD-APP-1.mit.edu>
In-Reply-To: <rt-8776@krbdev.mit.edu>
Message-ID: <rt-8776-49280.13.9509011479937@krbdev.mit.edu>
To: "'AdminCc of krbdev.mit.edu Ticket #8776'":;
Date: Thu, 24 Jan 2019 14:00:49 -0500
MIME-Version: 1.0
Reply-To: rt-comment@KRBDEV-PROD-APP-1.mit.edu
Content-Type: multipart/mixed; boundary="===============2221799665829170253=="
Errors-To: krb5-bugs-bounces@mit.edu

--===============2221799665829170253==
Content-Type: text/plain

Hello,

We use krb5 lib v1.10.3 in our product. Recently, one of our customers ran into a replay cache file descriptor leak issue in that there were many opened but deleted replay cache temp files staying around for days. For instance,

--------
Jan  7 13:44:28   fd 1220 (/shared/tmp/krb5_RCB8Wi7X (deleted)) : cloexec,  Fflags[0x8002], read-write
…
Jan 11 09:25:40  fd 1220 (/shared/tmp/krb5_RCB8Wi7X (deleted)) : cloexec,  Fflags[0x8002], read-write
--------
Jan  8 15:33:17  fd 1529 (/shared/tmp/krb5_RCGIGQ1X (deleted)) : cloexec,  Fflags[0x8002], read-write
…
Jan 11 09:25:40  fd 1529 (/shared/tmp/krb5_RCGIGQ1X (deleted)) : cloexec,  Fflags[0x8002], read-write
--------
Jan  9 12:05:14  fd 355 (/shared/tmp/krb5_RCG6JmM9 (deleted)) : cloexec,  Fflags[0x8002], read-write
…
Jan 11 09:25:40  fd 355 (/shared/tmp/krb5_RCG6JmM9 (deleted)) : cloexec,  Fflags[0x8002], read-write

Someone encountered the same issue with v1.10.3 and upgrading to v1.14.5 did not help (https://groups.google.com/forum/#!searchin/comp.protocols.kerberos/leak%7Csort:date/comp.protocols.kerberos/pN4QCVcEMWc/xYMDKrLuBgAJ).

We were wondering if there is a solution to or a workaround for this issue.

TIA,
Daniel




--===============2221799665829170253==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
https://mailman.mit.edu/mailman/listinfo/krb5-bugs

--===============2221799665829170253==--

home help back first fref pref prev next nref lref last post