Agent SIGSEGV on /api/v2|v3/claim — claim_add_user_info_command() calls strchr(NULL) when the lib dir is not writable
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 72/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Pouca atividade
- Stack de tecnologia
- c, linux
- Domínio
- api, backend, observability
Direção de pesquisa
Comece em src/web/api/v2/api_v2_claim.c, em claim_add_user_info_command(), depois rastreie netdata_random_session_id_get_filename() e reproduza com a requisição curl fornecida quando o diretório lib não tiver permissão de escrita. Confirme que o endpoint de claim não trava mais quando o nome do arquivo não está disponível e verifique system/systemd/netdata.service.in em busca do gatilho de empacotamento.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Summary
A self-hosted (unclaimed) Netdata Agent crashes with SIGSEGV on every GET /api/v2/claim / GET /api/v3/claim request whenever it cannot create its random-session-id file in netdata_configured_varlib_dir (e.g. when that directory is read-only for the agent process). The web UI issues this request on load / when showing the "Sign-in to continue" panel, so the dashboard reliably crashes the agent in a restart loop.
Root cause is a missing NULL check in claim_add_user_info_command():
// src/web/api/v2/api_v2_claim.c
static void claim_add_user_info_command(BUFFER *wb) {
const char *filename = netdata_random_session_id_get_filename(); // may be NULL
...
os_filename = filename; // NULL
...
if(strchr(os_filename, ' ')) // <-- strchr(NULL) => SIGSEGV
netdata_random_session_id_get_filename() returns NULL when netdata_random_session_id_generate() failed (its open(O_WRONLY|O_CREAT...) returned -1 and netdata_random_session_id_filename was left NULL). The caller dereferences it unconditionally.
gdb backtrace (v2.10.3, official Debian .deb)
#0 __strchr_avx2 () at ../sysdeps/x86_64/multiarch/strchr-avx2.S:67
#1 0x... in claim_add_user_info_command (wb=0x...) at src/web/api/v2/api_v2_claim.c:131
#2 claim_json_response (wb=..., response=CLAIM_RESP_INFO, msg=...) at src/web/api/v2/api_v2_claim.c:158
#3 0x... in api_claim (version=..., w=..., url=...) at src/web/api/v2/api_v2_claim.c:230
#4 0x... in web_client_api_request_v3 (...) at src/web/api/web_api_v3.c:269
#5 web_client_api_request (...) at src/web/server/web_client.c:576
#6 check_host_and_call (...) at src/web/server/web_client.c:542
#7 web_client_process_url (... filename = "/api/v3/claim_info" ...) at src/web/server/web_client.c:1163
#8 web_client_process_request_from_web_server (...)
#9 web_server_rcv_callback (...) at src/web/server/static/static-threaded.c:196
...
bt full for frame #1 shows os_message = "We need to verify this server is yours. SSH to this server and run this command. ...", os_prefix = "sudo cat", and os_filename resolving from the (NULL) session-id filename.
How the file creation fails (the trigger on the official .deb)
netdata_random_session_id_generate() does:
snprintfz(filename, FILENAME_MAX, "%s/netdata_random_session_id", netdata_configured_varlib_dir);
...
int fd = open(filename, O_WRONLY|O_CREAT|O_TRUNC|O_CLOEXEC, 640);
if(fd == -1) { netdata_log_error(...); ret = false; } // filename stays NULL
On the official Debian package, the shipped systemd unit (system/systemd/netdata.service.in) runs with:
ProtectSystem=full
ProtectHome=read-only
ReadWriteDirectories=/run/netdata
ReadWriteDirectories=-/var/spool/postfix/maildrop
With this sandbox the agent process cannot write to /var/lib/netdata (verified by entering the service's mount namespace):
$ sudo nsenter -t <netdata-pid> -m -- touch /var/lib/netdata/__t
touch: cannot touch '/var/lib/netdata/__t': Read-only file system
So open() returns -1 (EROFS) → netdata_random_session_id_filename stays NULL → get_filename() returns NULL → strchr(NULL) → SIGSEGV. (The same crash would occur on any system where the lib dir is non-writable: full disk, wrong ownership, etc.)
Reproduction
On a v2.10.3 Debian .deb install (agent running as a streaming parent, unclaimed, self-hosted):
# crashes the agent every time:
curl -s -o /dev/null -w '%{http_code}\n' http://127.0.0.1:19999/api/v3/claim
# -> empty reply / 000, journal shows: netdata.service: Main process exited, code=killed, status=11/SEGV
systemctl then restart-loops the agent (Restart=on-failure). Opening the dashboard or clicking "Sign in anonymously" triggers the same request and the same crash.
Suggested fixes
1. Code (the actual crash) — add a NULL guard in claim_add_user_info_command() so the agent never dereferences a NULL session-id filename. (PR incoming.)
2. Packaging (the trigger) — let the agent write its lib dir. Add the lib directory to the unit's writable paths, e.g. in system/systemd/netdata.service.in:
ReadWritePaths=/var/lib/netdata
I verified that adding this drop-in alone makes /api/v3/claim return 200 and the session-id file gets created normally — but the NULL guard is still needed so other "lib dir not writable" conditions can't crash the agent.
Environment
- Netdata v2.10.3, official
.deb(repository.netdata.cloud, stable channel) - Debian 12 (bookworm), x86_64, kernel 6.12
- Agent role: streaming parent for 3 nodes, unclaimed / self-hosted (no Netdata Cloud)
netdatacli aclk-state→ACLK Available: Yes
Happy to also send the full bt full / a coredump if useful.
- Linguagem predominante
- Go
- Estrelas
- 80.8k
- Forks
- 6.6k
- Merge médio
- 17h 49min
- PRs com merge (30d)
- 306
Preparar o ambiente
- Inclui um Dockerfile ou arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de netdata/netdata
-
bug needs triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
area/docs area/packaging bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
netdata/netdata#23398 · 2 reações ·
Mantenedores costumam responder em até 1 dia
-
bug needs triage
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 68/100
netdata/netdata#24082 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
bug needs triage
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 74/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 52/100
Mantenedores costumam responder em até 1 dia
Todas as issues de netdata/netdata
Issues semelhantes
-
bug docs
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
Mantenedores costumam responder em até 1 dia
-
bug needs-acceptance wg/evaluation-quality
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
vllm-project/semantic-router#4424 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 90/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
NVIDIA/k8s-device-plugin#2076 ·
Mantenedores costumam responder em até 1 dia
-
Documentation help wanted
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
golang/go#81933 · 2 comentários ·
Mantenedores costumam responder em até 1 dia