force-init of nsswitch modules?
Michael Tokarev
mjt@tls.msk.ru
Sun Dec 22 08:34:36 GMT 2024
21.12.2024 22:01, Florian Weimer
> <https://sourceware.org/pipermail/libc-alpha/2021-February/122737.html>
HMM Wait...
> In order to avoid security regressions, we disabled reloading of
> /etc/nsswitch.conf after the chroot has changed. We also went a step
> further and disabled loading additional NSS modules based on the
> *current* loaded configuration.
Do I understand it correctly that libnss modules are currently useless
to have in chroot, because their loading is disabled if a different
root dir is detected?
HMM. This simplifies chroot setup *greatly*, and, at the same time,
breaks some stuff.. Interesting...
And how about libnss_dns.so.2, libnss_files.so.2 - are they always
present in libc.so.6 as built-ins? Because it looks like I've some
inconsistent results. A program does getpwnam() lookup (so it reads
nsswitch.conf et al), next it does chroot(), and next it performs
some DNS lookup or getaddrinfo() call (for the first time during
runtime, and this first time being in chroot already - so if
libnss_dns.so were a module, it hasn't been loaded yet). And the
DNS (and /etc/hosts) lookup actually works without loading
libnss_dns.so.2!
It feels like this badly needs to be documented somewhere (though
I've no idea where - maybe in nsswitch.conf manpage?) -- this and
the tzset() issue in chroot. To my shame, I just read the
nsswitch.conf manpage for the *first* time, - and it does mention
re-loading of nsswitch.conf on changes at least (since 2.33).
Thanks,
/mjt
More information about the Libc-help
mailing list