force-init of nsswitch modules?

Michael Tokarev mjt@tls.msk.ru
Sun Dec 22 06:39:03 GMT 2024


21.12.2024 22:01, Florian Weimer wrote:

> This has come up before:

Sure it had!

> | May I suggest a more radical approach?
> |
> | Load all the NSS service modules when the first modules is loaded,
> | and keep the the fix in place?
> 
> <https://sourceware.org/pipermail/libc-alpha/2021-February/122737.html>
> 
> Maybe it's finally time to implement this.  Although current Fedora
> now has five NSS modules active by default (not counting the built-in
> files and dns modules provided by glibc).  It might add quite a bit of
> overhead to a simple “ls -l” call.

It doesn't need to be forced (on `ls' and everything).  I think it should
be an opt-in thing: programs who know they need it, might call an init-all
function at an appropriate place, all the rest can live with the current
lazy loading.

I can imagine other situations where immediate load of everything is not
a good idea - for example, during system startup when not all filesystems
are mounted already, - things like that.

I had an analogy in mind, but it is broken in glibc currently: it is tzset().
In the past, it was enough for a program to call tzset() before entering
chroot jail, to init localtime structures.  Now, tzset() in this context
is doing nothing, since it resets localtime structures back to the default
UTC if there's no /etc/localtime on the next access.  It looks like this
one should depend on unchanged / like for nsswitch, too.

Thanks,

/mjt


More information about the Libc-help mailing list