Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Duplicate groups creation bug #20964

Merged
merged 2 commits into from
Jun 2, 2023
Merged

Duplicate groups creation bug #20964

merged 2 commits into from
Jun 2, 2023

Conversation

akshya96
Copy link
Contributor

@akshya96 akshya96 commented Jun 2, 2023

https://hashicorp.atlassian.net/browse/VAULT-16649
Vault does not prevent the creation of duplicate groups when multiple "create group" requests with the same group name are sent simultaneously to different nodes. The issue arises because Vault relies on the view of MemDB from IdentityStore, which is independent for each node, to check for the presence of another group with the same name. As a result, when requests occur within a short time frame, the MemDB on each node may not have the group names.

Currently, the request is only forwarded to the active node for writing to storage based on the ID i.e, as part of UpsertGroupInTxn function, we would only forward the write to storage request using SendGroupUpdate https://github.com/hashicorp/vault-enterprise/blob/5e4c01ae563d2ad3f4138171e95cb6bdb2ee9e20/vault/identity_store_util.go#LL1826C1-L1834C4.

Approved ent PR: https://github.com/hashicorp/vault-enterprise/pull/4137

@akshya96 akshya96 added this to the 1.14 milestone Jun 2, 2023
@akshya96 akshya96 requested review from raskchanky and ncabatoff June 2, 2023 17:59
@akshya96 akshya96 modified the milestones: 1.14, 1.14.1 Jun 2, 2023
@akshya96 akshya96 merged commit 8931e47 into main Jun 2, 2023
@akshya96 akshya96 deleted the vault-16649-oss branch June 2, 2023 21:02
akshya96 added a commit that referenced this pull request Jun 2, 2023
* fix duplicate groups creation

* add changelog
akshya96 added a commit that referenced this pull request Jun 2, 2023
* fix duplicate groups creation

* add changelog
akshya96 added a commit that referenced this pull request Jun 2, 2023
* fix duplicate groups creation

* add changelog
akshya96 added a commit that referenced this pull request Jun 8, 2023
* fix duplicate groups creation

* add changelog

Co-authored-by: akshya96 <[email protected]>
akshya96 added a commit that referenced this pull request Jun 8, 2023
* fix duplicate groups creation

* add changelog

Co-authored-by: akshya96 <[email protected]>
akshya96 added a commit that referenced this pull request Jun 8, 2023
* Duplicate groups creation bug  (#20964)

* fix duplicate groups creation

* add changelog

* make fmt

---------

Co-authored-by: akshya96 <[email protected]>
Co-authored-by: akshya96 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants