Re: Zombie users
Posted in 1998
In article <34C4E33E.B52F4525@NOSPAM.KingofMyDomain.MAPSON.Segel.com>, Michael Segel <Mikey@NOSPAM.KingofMyDomain.MAPSON.Segel.com> writes > > >David Levine wrote: > >> "G'khan Tercan" wrote in message <698de5$7i6@cssun.mathcs.emory.edu>... >> > >> >...but when I try to kill the user's pid with kill -9, SCO gives me "no >> such >> >process". >> >This causes many zombie users and eventually this causes a very slow >> >system. >> >> I've seen this exact situation. The users that you see from 'who -u' are >> appearing because they are in the /etc/utmp and /etc/wtmp files. This >> condition does not, in my experience, cause a slowdown in the system. >> > >Uhmm, these aren't zombies.Hell if you have r/w access to these files, you can >have a little fun by >removing your name or changing your name so that your system admin doesn't >know you are there. :-) > Or under the latets Linux sysvinit, do >/etc/utmp; >/etc/wtmp Then you cannot shutdown the box as init does not know the current runlevel!! >> When the system runs very slowly, check to see if you have any sqlexec >> processes with a PPID=1; these are consuming resources even though the >> process that called them has ended >> (usually in some error condition). These rogue sqlexec's cannot be killed >> either. > >These are zombies, or well sort of.Zombies occur when you kill the parent, but >you don't kill the child. (Damn, doesn't it >sound so satanic?) :-) I once wrote a server which controlled a CD-ROM box with 2 CD-ROMs in it. The parent forked children to do the actual copying of the data into a cache directory on hard disk. The parent would send a message to the child and expect a reply back. (this is the actual comment in the code). /* read a reply from the child, if the child does not listen to us then kill it! */ if (read(...)...) kill(-9,child_pid); ... >The child then consider's root to be its parent, however, root doesn't know >that it has a >new child! (The rat bastard!) > >So you can't send any kill SIGs to the child. Hence a zombie. > >Now IMHO, I thought this was limited to SYS V R4 variants. I thought BSD >variants >didn't have this problem. (Hell its been a while since I did any kernel >hacking so I could >be wrong.) > This was a problem with some version of init where it would not wait for it's children. this should have been fixed a long time ago). You can still kill -9 the process but it will then go <defunct> as it's parent is not waiting for it. Unfortunaely there is no fix for this, waitpid allows you to wait for a given process but even root cannot wait for children which are not it's own! [ Can I log this as a bug report???] >-Mikey > >BTW, The rumors of my stalking Mike Saranga for blackmail evidence are greatly >exagerated. >In fact, they are damn lies. At least that's what my lawyers tell me to say! >;-) > > > -- David Williams Maintainer of the Informix FAQ Primary site (Beta Version) http://www.smooth1.demon.co.uk Official site http://www.iiug.org/techinfo/faq/faq_top.html I see you standin', Standin' on your own, It's such a lonely place for you, For you to be If you need a shoulder, Or if you need a friend, I'll be here standing, Until the bitter end... So don't chastise me Or think I, I mean you harm... All I ever wanted Was for you To know that I care