Your message dated Tue, 26 Jul 2022 10:34:07 +0000
with message-id <[email protected]>
and subject line Bug#682156: fixed in adduser 3.125
has caused the Debian Bug report #682156,
regarding delgroup I/O requirements are O(n^2) with regards to number of 
configured users
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
682156: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=682156
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: adduser
Version: 3.112+nmu2

delgroup is a wrapper to groupdel which performs additional
validations.  It checks to see whether any other user on the system
has, as its primary group, the group that it is potentially deleting.

It does so with the following code:

    setpwent;
    while ((my $acctname,my $primgrp) = (getpwent)[0,3]) {
        if( $primgrp eq $gr_gid ) {
            fail (7, gtx("`%s' still has `%s' as their primary
group!\n"),$acctname,$group);
        }
    }
    endpwent;

Perl's implementation of getpwent will call getspnam() for each user
to get the shadow password.  On a default system (using /etc/passwd
and /etc/shadow) this means, for each line of /etc/passwd,
perl will open /etc/shadow, scan it until it finds the matching user,
and close the file.  Given adding users adds lines to /etc/passwd and
/etc/shadow, this means the overall I/O complexity for deleting
a group is O(n^2).  On systems with ~100k users this quickly ends up
being hundreds of gigabytes that needs to be read and processed in
order to remove a group; given how often delgroup gets
called from postrm scripts this can make a lot of operations rather expensive.

groupdel performs the same check from C, using getpwent() without
calling the getspnam(), so safety-wise this check is not needed.  The
only thing we gain from it is the opportunity to detect
the error before printing "Removing group ..." and calling groupdel.
groupdel has a return value specifically for this case (it will return
8) in the event we wanted to make any behavior conditional
on this case.

The simplest fix is to simply remove the offending lines of perl
entirely. This will result in a slightly different output being
printed when attempting to remove a group in use, but will otherwise
behave the same, as so:

With current delgroup:

# delgroup root
/usr/sbin/delgroup: `root' still has `root' as their primary group!

If offending code were simply removed:

# delgroup root
Removing group `root' ...
groupdel: cannot remove the primary group of user 'root'
/usr/sbin/delgroup: `/usr/sbin/groupdel root' returned error code 8. Exiting.

The bug was introduced in this commit:
http://anonscm.debian.org/viewvc/adduser/trunk/deluser?r1=233&r2=234&;

and it's entirely plausible (I haven't checked) that groupdel didn't
have any check at all at this point in time.  If people believe it's
unacceptable to simply remove the check and rely on groupdel to fail,
this also suggests an alternate approach to fixing this bug -- calling
out to grep via a subshell will be O(n) instead of O(n^2) and should
work fine on systems with much larger numbers of users.

Daniel

--- End Message ---
--- Begin Message ---
Source: adduser
Source-Version: 3.125
Done: Marc Haber <[email protected]>

We believe that the bug you reported is fixed in the latest version of
adduser, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Marc Haber <[email protected]> (supplier of updated adduser 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Tue, 26 Jul 2022 09:57:52 +0200
Source: adduser
Architecture: source
Version: 3.125
Distribution: experimental
Urgency: medium
Maintainer: Debian Adduser Developers <[email protected]>
Changed-By: Marc Haber <[email protected]>
Closes: 57280 398802 541620 682156 1012492 1015907
Changes:
 adduser (3.125) experimental; urgency=medium
 .
   [ Marc Haber ]
   * remove debconf. (Closes: #57280, #398802)
   * install (add|del)user.conf as examples.
   * install adduser.conf as dpkg-conffile directly to /etc.
     (Closes: #541620)
   * remove postinst/postrm. (Closes: #1012492)
 .
   [ Jason Franklin ]
   * Remove the unused "get_users_groups" subroutine. (Closes: #1015907)
 .
   [ Matt Barry ]
   * Do not check for group being empty on 'delgroup'. (Closes: #682156)
Checksums-Sha1:
 d10b88eaafedf88528ce1d067b2eec32614721a6 1671 adduser_3.125.dsc
 df800d2b0680c00fb2f62d1d1db5f4241c4de279 224132 adduser_3.125.tar.xz
 ed3caca334b35f7f6623348fb64b2efb6e47f3e5 5651 adduser_3.125_source.buildinfo
Checksums-Sha256:
 277bde3cb4c6e3e0de5a18bc131a2e72be0708b5aa6cb04f8660e3ac300177ea 1671 
adduser_3.125.dsc
 962be3f7cbc907a06044dbd4ba3974d51069bb01884718cf7671d592549b4a58 224132 
adduser_3.125.tar.xz
 b900414d720f71c43ff514cead02e59e257873ae40ebfb5c21db11196ce0200a 5651 
adduser_3.125_source.buildinfo
Files:
 8c99a88f29c93a8338d514e63151088c 1671 admin important adduser_3.125.dsc
 f26b8bd8ae1f8c1de06e85a74ab7b0cd 224132 admin important adduser_3.125.tar.xz
 5cf1c2d28bc98a17d13788c0ce442a91 5651 admin important 
adduser_3.125_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE6QL5UJ/L0pcuNEbjj3cgEwEyBEIFAmLfQdwACgkQj3cgEwEy
BEIEQhAAkz64JtkXcdEMI4RsijAUAHZjSLPOLK+Ku+kpsduPwFwE2B0DSYOHTYVA
SZZTgk0izzX5ORpt7Sx3DiAYZlfaWGoc+R9CCCdfBewdV5nhpUip7npEFJzbXzur
70K6S8CkPDQ9XAXgsW57IgLmq8O9lrm+JSpUQGki7aeJnK3Oj8QheUbe5Mncb9TL
uUZ0UOtIsdg1kYGdy+rPkPQ55rb2lia8+/ITPYSP1MLq3I10CrxzVKi9IXq8FrHl
v/H5n4AKzWpzN45ROIRECYh2lagzutnxRIedIQEZyVFgZ37vUuEXD3yR/AK2Uec1
jTYimsMJCXYs1yBDF+lfbs+EF3Z+LynSWrFzngFP0JE3rhJ9Y9KCj3xkjdDeO/F2
FAYYBLllcqU1i0FR27KXIC5zNldZS+TNv0k7FZePj/q93aVC74s6bwr+HV6JF24S
m4JyYXq76kN4W5nlJtlkzq52qoqBdPQh+jFlcVdMn/WZc/jQVLHkxnGgmGSowSmn
cYoHjRNNZcmmeXZ6pxK5eK72pTycXPRBuZIqllInCs4v0uiZ+JNmJuIf4pclP0Wt
pVTWEepRMbfZtDt8Xs2u8TIGIvmzSIcPjj05UrqWq1xHaW24fb1Xbttwnv1pZRkL
KxPE9zrNTXq2nX+Z80kvCPRR6rPWKT+aKVuIh56K79RA+x2rQR8=
=qYpl
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to