Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 48969 - <=app-admin/bacula-1.34.0 - Race condition backing up multiple hosts
Summary: <=app-admin/bacula-1.34.0 - Race condition backing up multiple hosts
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: GLSA Errors (show other bugs)
Hardware: All Linux
: High critical (vote)
Assignee: Gentoo Security
URL: http://cvs.sourceforge.net/viewcvs.py...
Whiteboard:
Keywords: SECURITY
Depends on:
Blocks:
 
Reported: 2004-04-25 13:24 UTC by Bryn Hughes
Modified: 2004-05-06 04:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bryn Hughes 2004-04-25 13:24:29 UTC
bacula-1.34.0 has a race condition when backing up multiple hosts:

  major race condition in the job scheduler when multiple
  simultaneous jobs is enabled. This occurred only when on job had
  blocked another because of resource usage. This caused a deadlock
  and CPU usage. 

Reproducible: Always
Steps to Reproduce:
1. Schedule multiple jobs at the same time
2. Let them run

Actual Results:  
bacula-dir will race after the first backup job completes


this bug is fixed in bacula-1.34.1
Comment 1 Chuck Short (RETIRED) gentoo-dev 2004-04-25 17:44:02 UTC
I have added 1.34.1 and removed 1.34.0. 1.34.0 wasnt marked stable so neither was 1.34.1.
Comment 2 solar (RETIRED) gentoo-dev 2004-04-25 18:11:44 UTC
Reassigning bug to security@ for further processing.
Adding arches from
KEYWORDS="~x86 ~ppc ~sparc"

Bryn Hughes
Please provide a URL to your source of information on this.

zul,
Anything your aware of that would prevent this package from going stable?
Comment 3 Chuck Short (RETIRED) gentoo-dev 2004-04-25 19:29:13 UTC
Nope, i just marked it stable for x86.
Comment 4 Bryn Hughes 2004-04-25 22:32:30 UTC
It's in the Changelog for Bacula-1.34.1 which can be found here:

http://cvs.sourceforge.net/viewcvs.py/*checkout*/bacula/bacula/ChangeLog?content-type=text%2Fplain&rev=1.120

Look under April 18 2004
Comment 5 Jason Wever (RETIRED) gentoo-dev 2004-04-26 17:30:33 UTC
Stable on sparc (though we didn't have a stable release before).
Comment 6 Bryn Hughes 2004-04-28 11:52:01 UTC
With regards to the specific versions affected, I believe this bug ONLY affects 1.34.0, there were quite a few changes between 1.32 and 1.34.  From further testing I believe this bug is only triggered when a SpoolDevice is defined and enabled - this feature only exists in >=bacula-1.34.0.  <bacula-1.34.0 should NOT be affected by this bug.
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2004-05-04 07:18:36 UTC
We don't really need ppc stable as it was never stable on ppc anyway, so bacula-1.34.1 is ready for a GLSA, but I'm not sure one is needed...
-K
Comment 8 Kurt Lieber (RETIRED) gentoo-dev 2004-05-06 04:50:58 UTC
this is more of a bug than a security vulnerability.  I don't think a glsa is needed in this particular case. 

closing as fixed.