compat: utmp not cleared on tty logout

Reported by Pete Savage on 2008-01-17
This bug affects 5 people
Affects Status Importance Assigned to Milestone
Petr Lautrbach
kdebase-workspace (Ubuntu)
upstart (Fedora)
In Progress
upstart (Ubuntu)

Bug Description

Log into tty1, then tty2 and then log out of both. Now run a w command and you should see something similar to the following;

mac@tootoo:~/source/procps-3.2.7/proc$ w
 10:39:09 up 33 days, 23:11, 4 users, load average: 1.31, 0.62, 0.39
mac tty7 :0 11Jan08 4:34m 7:24m 36.02s x-session-manager
mac pts/1 :0.0 08:54 0.00s 0.19s 0.00s w

It shows that 4 users are logged in. Obviously this is wrong. I wrote a small C utility to hack out what w and uptime get as information from utmp.

#include <string.h>
#include <stdlib.h>
#include <pwd.h>
#include <unistd.h>
#include <utmp.h>
#include <stdio.h>

int main(int argc, char *argv[])
  struct utmp *utmpstruct;
  struct utmp entry;

  //system("echo before adding entry:;who");

  while ((utmpstruct = getutent())){
        if ((utmpstruct->ut_type == USER_PROCESS) && (utmpstruct->ut_name[0] != '\0'))
  return 0;

You'll get an output like this

mac@tootoo:~$ ./a.out
tty2 14989
tty1 4313
tty7 30255
pts/1 9712

However, running the following , to try to find the pid for the tty1 process, gives;

mac@tootoo:~/source/procps-3.2.7/proc$ ps aux | grep 4313
mac 15524 0.0 0.0 2988 768 pts/1 R+ 10:42 0:00 grep 4313

This is obviously wrong, utmp still has the old process id's associated as being logged in.

Running the following gives the new tty pid

mac@tootoo:~/source/procps-3.2.7/proc$ ps aux | grep tty1
root 14914 0.0 0.0 1692 516 tty1 Ss+ 10:33 0:00 /sbin/getty 38400 tty1
mac 15605 0.0 0.0 2988 764 pts/1 R+ 10:44 0:00 grep tty1

There is now a new pid for tty1

Koen Beek (koen-beek) wrote :

behaviour confirmed on gutsy amd64

2.6.22-14-generic #1 SMP Tue Dec 18 05:28:27 UTC 2007 x86_64 GNU/Linux

RobC (rccase) wrote :

I also have this problem on edgy-server i386
2.6.17-12-server #2 SMP Tue Dec 18 02:13:45 UTC 2007 i686 GNU/Linux

Well known bug in Upstart, simply due to its utter lack of utmp handling -- we've known that it behaves like this since edgy, but figured nobody would probably notice in practice.

It's on the TODO list to fix, but pretty low priority.

Changed in procps:
importance: Undecided → Low

Moving bug upstream (I wish Launchpad could do this properly)

Changed in upstart:
importance: Undecided → Low
status: New → Confirmed
status: Confirmed → Invalid
status: Confirmed → Triaged
Pete Savage (petesavage) wrote :


It caused me a fair amount of worry, when I thought my machine had hacked binaries ;)


Changed in upstart:
milestone: none → 0.5
arboc (dcobra) wrote :

I'm using kubuntu 8.04 / KDE-4 Remix. Here's my scenario:

During an X session, on occasion I need to use a virtual console for whatever reason. So I switch to tty1 (Ctrl-Alt-F1) , log in, do some stuff, then log out, go back to X (Alt-F7) and continue working. When I leave for the day, I select Shutdown, confirm, and go away, thinking the system will shutdown as usual.

The next time I use the computer (which may be several days later), I find out it never shut down at all, because kdm stopped at a dialog asking me if I want to abort an active session on vt1.

I think this bug deserves a higher priority. Even if I had seen the dialog, it is still annoying to have to click an extra button to confirm aborting an active session which no longer exists. I imagine these ghost sessions showing up in "finger", "last", etc. can probably cause other significant problems as well.

It would really help if the developers of upstart can suggest a workaround to clear the entry left over in utmp, until this bug is fixed in a future release (perhaps some command in the .logout file, or a change in /etc/event.d/tty?)

arboc (dcobra) wrote :

Here's the workaround I found myself, in case somebody is interested. Install the runit package, which seems to handle utmp better than upstart does, copy the /etc/sv/getty-5 directory that comes with it to /etc/sv/getty-1 through getty-4 and getty-6, modify the run and finish scripts and the supervise link in these directories, changing the tty numbers accordingly. Finally, stop upstart from running getty by moving /etc/event.d/tty? elsewhere and tell runit to take charge of running them by making soft links from /etc/service/getty-? to /etc/sv/getty-?. That's it, no more stale utmp entries.

I'm still interested if anybody cares to comment on whether there is a better workaround than this one.

As a side note, pardon my ignorance, but I thought moving a bug upstream meant that it is actually caused by some other bug in an underlying package, but I couldn't find the continuation of this bug anywhere in launchpad. So is it abandoned or where was it taken up?

Changed in upstart:
milestone: 0.5 → none
Changed in upstart:
status: Invalid → Triaged
Changed in upstart:
milestone: none → 0.5-later
Petr Lautrbach (plautrba) wrote :


This patch is againts lp:upstart/0.3 branch.

It adds "utmp <id>" stanza and writes utmp entries and wtmp log
as described in utmp(5).

How it works:

When child is forked and job->utmp is set, child inserts to first line with same id (utmp.ut_id)
new values with his own pid, id, actual time and type set to INIT_PROCESS and logs in wtmp.

When jobs die and utmp is set, init sets type DEAD_PROCESS and clears values for entry
with dead process pid. Entry is also logged to wtmp log.

Petr: that's pretty much how I was thinking it should be solved. Would you be willing to assign copyright for that to Canonical so I can apply it to the source?

summary: - utmp not cleared on tty logout
+ compat: utmp not cleared on tty logout
Changed in upstart:
milestone: 0.5-later → none
Petr Lautrbach (plautrba) wrote :

I've just sent copyright assignment in accordance with ContributingCode

Changed in upstart (Fedora):
status: Unknown → In Progress

Hi Petr,

I received the assignment, thanks very much! Sorry, I haven't dropped this; here's a quick review of the code, and thoughts on merging it with 0.6

0.6.x have a util/utmp.c already for reading and writing runlevel and reboot records, it feels like these process records should go in there as well - but then that'd mean having utmp.c shared between init/ and util/ and there's no directory for that yet (it's not appropriate to go into libnih)

Why the __GLIBC__ check? Unless I'm mistaken, the gettimeofday() and assign would work in either case. In general I've tried to avoid #ifdef in the Upstart code. Should use the utmpx.h functions rather than utmp.h?

Thoughts on the utmp stanza, firstly we should check the length of this at parse time rather than silently truncating. Also given instance jobs we probably want to expand environment variables here so you can do:

    utmp $ID

For things like a single getty job, that wouldn't be sufficient since you'd want the ids to match the getty ids. That'd mean supporting shell-style replacements in expansion (which we don't do yet)

    utmp ${TTY#tty}

Should init not always set DEAD_PROCESS for any pid it's supervised, whether or not it created the utmp entry in the first place? Problem there of course is that we don't know the ut_id of them I guess, so we'd have to iterate the entire utmp file every time?

paths.h defines a WTMP macro, this shouldn't be necessary since _PATH_WTMP is already defined in utmp.h

(Arguably a few of those things in paths.h should go away and be replaced by things from <paths.h> like _PATH_CONSOLE, _PATH_DEVNULL, _PATH_BSHELL, etc.)

Missing tests, should check for a utmp record being written, failing to write, etc. (possible by calling utmpname() in the test) - it should be ok for wtmp to fail at any time, so the test is safe. Should check for the entries being cleared too.

One thing that the manpage isn't quite clear about is what happens when you create an INIT_PROCESS entry but search for a USER_PROCESS entry to delete, as you've done there - I think this will still find it, but a test would help us be sure.

A. D. Nieman (adnieman) wrote :

I can appreciate that this is tasked to be fixed, but I feel that it is important enough that the issue should have been addressed a year ago. Do not take this as reproach. I understand that most of the software in the open source community is privately developed by the individuals in the community. I just would like it fixed.

Changed in kdebase-workspace (Ubuntu):
status: New → Invalid

For sanity's sake, I'm closing the Ubuntu tasks for upstream Upstart bugs. I've experimented with having both, but it is just making bugs hard to find now. Will use the policy whereby bugs on the Ubuntu package exist in the Ubuntu packaging or patches only, any bugs in the Upstart code are Upstream bugs.

Changed in upstart (Ubuntu):
status: Triaged → Invalid
Petr Lautrbach (plautrba) wrote :

If we assume that *getty takes care about setting INIT_PROCESS/LOGIN_PROCESS itself, we need just set DEAD_PROCESS for dead processes with pid in utmp table and log it into wtmp.

Init goes through the utmp table, tries to find entry with dead process pid and sets it to DEAD_PROCESS. There is no need to create/set up "utmp" stanza.

Test covers utmp table with 2 entries and with 2 situation - process is in LOGIN_PROCESS or USER_PROCESS.

Marc - A. Dahlhaus (mad-wol) wrote :

Petr's patch in comment #15 fixes the problem for me. agetty displays logged on users as expected in issue outputs.

Marc - A. Dahlhaus (mad-wol) wrote :

With Petr's patch in comment #15:
On boot issue still displays one user logged in. This is cleared by the first users logout.
Could be a leftover from the previous shutdown/reboot that got not cleared up the right way, but i am only guessing here...

I would love to see proper utmp and wtmp record handling in upstart would get some love in upstart soon.

Marc - A. Dahlhaus (mad-wol) wrote :

Found the cause of the stray login that was shown on startup, it was unrelated to Petr's patch or upstart itself in any way.
So please ignore the first part of comment #17.

Changed in upstart:
status: Triaged → Fix Committed
assignee: nobody → Petr Lautrbach (plautrba)
milestone: none → 0.6.8
Changed in upstart:
milestone: none → 1.0
Changed in upstart:
status: Fix Committed → Fix Released
Changed in upstart (Ubuntu):
status: Invalid → New
importance: Low → Undecided
tags: added: patch
Evan Peck (colors) wrote :

Since this both has patch(es) and instructions to replicate the error/problem,
I will mark this as Confirmed in upstart(Ubuntu).

Thank you!

Changed in upstart (Ubuntu):
status: New → Confirmed
Steve Langasek (vorlon) on 2012-02-04
Changed in upstart (Ubuntu):
status: Confirmed → Fix Released
Dirley (cpd-dirley) wrote :

This fix will be ported to 0.6 series? On my company, we have more then 50 servers using Ubuntu 10.04 LTS that are affect by this bug.

Steve Langasek (vorlon) wrote :

> This fix will be ported to 0.6 series?

No, sorry. If this is a blocking bug for you, I recommend upgrading to 12.04 LTS.

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.