On Fri, Jun 10, 2016 at 09:26:38AM +0200, Lukas Slebodnik wrote:
> ehlo,
> 
> I took some time to find out why pam-srv-tests fails so often.
> https://fedorahosted.org/sssd/ticket/2994
> 
> It is caused by slow execution of function sysdb_cache_password_ex.
> 
> (Thu Jun  9 22:13:36:771048 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> start.
> (Thu Jun  9 22:13:36:771317 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before s3crypt_gen_salt
> (Thu Jun  9 22:13:36:771678 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before s3crypt_sha512
> (Thu Jun  9 22:13:38:022470 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before sysdb_new_attrs
> (Thu Jun  9 22:13:38:023115 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before sysdb_attrs_add_string
> (Thu Jun  9 22:13:38:023431 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before sysdb_attrs_add_long
> (Thu Jun  9 22:13:38:023829 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before sysdb_attrs_add_long v2
> (Thu Jun  9 22:13:38:024156 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before sysdb_attrs_add_long v3
> (Thu Jun  9 22:13:38:024482 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before sysdb_attrs_add_uint32
> (Thu Jun  9 22:13:38:024816 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> Before sysdb_set_user_attr
> (Thu Jun  9 22:13:38:035319 2016) [sssd] [sysdb_cache_password_ex] (0x0100): 
> return eok
> 
> As you can see, the execution of function s3crypt_sha512
> took almost two seconds.
> 
> Is it caused by valgrind all low entropy?

The random data for the salt is already collected in s3crypt_gen_salt().
sha512_crypt_r() basically mingles and password and the salt and does
hash operations.

From a short inspection I can see nothing obvious which might cause such
delay. Maybe nspr_nss_init() if we really have to init NSS at this
point. The main operations in sha512_crypt_r() are heavily CPU bound, so
maybe some scheduler decides that its time for a different process to get
some CPU time?

On the other hand can you give some details why the test fails because
of this delay? It looks a bit like we depend on a specific execution
time either in the test or the main code. If this is the case I think we
would make the code more robust by removing this dependency.

bye,
Sumit

> 
> I can try to go deeper and find out which part of function sha512_crypt_r
> is very slow. But it's faster to write to mailing list rather than
> wait for results from CI.
> 
> LS
> _______________________________________________
> sssd-devel mailing list
> [email protected]
> https://lists.fedorahosted.org/admin/lists/[email protected]
_______________________________________________
sssd-devel mailing list
[email protected]
https://lists.fedorahosted.org/admin/lists/[email protected]

Reply via email to