login: T8086: replace getpwall() based user enumeration to avoid NSS/TACACS timeouts #4892
+141
−63
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Change summary
The previous implementation of
system loginrelied on Python'spwd.getpwall()to enumerate user accounts. This forces a full walk through the NSS stack, which is acceptable in general but problematic for our use-case. VyOS only needs information about locally created accounts and not remote accounts provided via AAA backends such as TACACS or RADIUS.When TACACS servers are unreachable, NSS lookups become extremely slow due to repeated timeouts. As a result, any operation triggering
pwd.getpwall()(including configuration commits) can stall for several minutes.This change introduces a dedicated helper,
get_local_passwd_entries(), which reads/etc/passwddirectly and avoids NSS entirely. Since only local UIDs are relevant, this provides all required data with no external dependencies.Performance improvement on VyOS 1.4.3 with two unreachable TACACS servers:
Before
After
This significantly improves commit performance and removes sensitivity to AAA server outages.
Types of changes
Related Task(s)
Related PR(s)
How to test / Smoketest result
All smoketests passed:
make test-interfacesmake test-no-interfaces-no-vppmake testcChecklist: