The goal isn't to kill the smbd process. We want to know what's going on in it.
Yes you're right of course. I wanted to give a reason why I believe smbcontrol might not work :)
In here I try smbcontrol:
I have one
smbd
process using 100% cpu currently, its PID is 59596.
It seems running
smbcontrol 59596 debug 7
did not have any effect. Here's the last couple of lines of
/var/log/samba4/log.smbd
- all of it after my issueing the smcontrol debug 7 command.
Code:
[2018/07/30 17:59:23.301178, 2] ../source3/auth/auth.c:314(auth_check_ntlm_password)
check_ntlm_password: authentication for user [ss] -> [ss] -> [ss] succeeded
[2018/07/30 18:00:23.280075, 2] ../source3/smbd/process.c:2878(deadtime_fn)
Closing idle connection
[2018/07/30 18:00:23.444188, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[accurate]"
[2018/07/30 18:00:23.445223, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[backup]"
[2018/07/30 18:00:23.446196, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[cloudsim]"
[2018/07/30 18:00:23.447126, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[guest]"
[2018/07/30 18:00:23.448297, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[homes]"
[2018/07/30 18:00:23.449328, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[sync]"
[2018/07/30 18:00:23.458654, 2] ../source3/auth/auth.c:314(auth_check_ntlm_password)
check_ntlm_password: authentication for user [ss] -> [ss] -> [ss] succeeded
[2018/07/30 18:00:37.036461, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[accurate]"
[2018/07/30 18:00:37.037522, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[backup]"
[2018/07/30 18:00:37.038493, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[cloudsim]"
[2018/07/30 18:00:37.039425, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[guest]"
[2018/07/30 18:00:37.040596, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[homes]"
[2018/07/30 18:00:37.041640, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[sync]"
[2018/07/30 18:00:37.044191, 2] ../source3/auth/auth.c:332(auth_check_ntlm_password)
check_ntlm_password: Authentication for user [Sophie] -> [Sophie] FAILED with error NT_STATUS_NO_SUCH_USER, authoritative=1
[2018/07/30 18:00:37.044347, 2] ../auth/auth_log.c:760(log_authentication_event_human_readable)
Auth: [SMB2,(null)] user [Dell-T1700-2]\[Sophie] at [Mon, 30 Jul 2018 18:00:37.044297 CEST] with [NTLMv2] status [NT_STATUS_NO_SUCH_USER] workstation [DELL-T1700-2] remote host [ipv4:192.168.1.154:64037] mapped to [Dell-T1700-2]\[Sophie]. local host [ipv4:192.168.1.12:445]
[2018/07/30 18:00:37.047976, 2] ../source3/smbd/service.c:338(create_connection_session_info)
guest user (from session setup) not permitted to access this share (accurate)
[2018/07/30 18:00:37.048066, 1] ../source3/smbd/service.c:521(make_connection_snum)
create_connection_session_info failed: NT_STATUS_ACCESS_DENIED
[2018/07/30 18:00:37.048881, 2] ../source3/smbd/service.c:338(create_connection_session_info)
guest user (from session setup) not permitted to access this share (accurate)
[2018/07/30 18:00:37.048957, 1] ../source3/smbd/service.c:521(make_connection_snum)
create_connection_session_info failed: NT_STATUS_ACCESS_DENIED
[2018/07/30 18:01:23.458137, 2] ../source3/smbd/process.c:2878(deadtime_fn)
Closing idle connection
[2018/07/30 18:01:23.541661, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[accurate]"
[2018/07/30 18:01:23.542697, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[backup]"
[2018/07/30 18:01:23.543705, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[cloudsim]"
[2018/07/30 18:01:23.544666, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[guest]"
[2018/07/30 18:01:23.545842, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[homes]"
[2018/07/30 18:01:23.546895, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[sync]"
[2018/07/30 18:01:23.556097, 2] ../source3/auth/auth.c:314(auth_check_ntlm_password)
check_ntlm_password: authentication for user [ss] -> [ss] -> [ss] succeeded
[2018/07/30 18:01:29.622199, 2] ../source3/smbd/server.c:803(remove_child_pid)
Could not find child 80116 -- ignoring
[2018/07/30 18:02:23.535067, 2] ../source3/smbd/process.c:2878(deadtime_fn)
Closing idle connection
[2018/07/30 18:02:23.742423, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[accurate]"
[2018/07/30 18:02:23.743474, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[backup]"
[2018/07/30 18:02:23.744445, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[cloudsim]"
[2018/07/30 18:02:23.745408, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[guest]"
[2018/07/30 18:02:23.746580, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[homes]"
[2018/07/30 18:02:23.747615, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[sync]"
[2018/07/30 18:02:23.756905, 2] ../source3/auth/auth.c:314(auth_check_ntlm_password)
check_ntlm_password: authentication for user [ss] -> [ss] -> [ss] succeeded
[2018/07/30 18:03:23.736067, 2] ../source3/smbd/process.c:2878(deadtime_fn)
Closing idle connection
[2018/07/30 18:03:24.548028, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[accurate]"
[2018/07/30 18:03:24.549084, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[backup]"
[2018/07/30 18:03:24.550053, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[cloudsim]"
[2018/07/30 18:03:24.550977, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[guest]"
[2018/07/30 18:03:24.552151, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[homes]"
[2018/07/30 18:03:24.553184, 2] ../source3/param/loadparm.c:2787(lp_do_section)
Processing section "[sync]"
[2018/07/30 18:03:24.562504, 2] ../source3/auth/auth.c:314(auth_check_ntlm_password)
check_ntlm_password: authentication for user [ss] -> [ss] -> [ss] succeeded
Sophie
really is no/has no valid user currently. She started working for the summer here today.
Sophie
and Sophia (
ss
) are two distinct persons.
ss
is currently having trouble with the NAS (her computer stalling, not able to connect, etc), and
smbstatus
shows her UID on the process in question:
smbstatus | grep ss
Code:
59596 ss accurate SS-X230.office.accu-rate (ipv4:192.168.1.217:64203) SMB3_11 -
partial(AES-128-CMAC)
74554 ss accurate SS-X230.office.accu-rate (ipv4:192.168.1.217:49736) SMB3_11 -
partial(AES-128-CMAC)
ss 74554 SS-X230.office.accu-rate Mon Jul 30 17:11:10 2018 CEST - -
ss 59596 SS-X230.office.accu-rate Mon Jul 30 14:59:12 2018 CEST - -
Pid Uid DenyMode Access R/W Oplock SharePath Name Time
60253 1007 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/accurate sync-archiv/projekte/redacted/1-requirements-engineering/Grundrisse Mon Jul 30 17:56:03 2018
60253 1007 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/accurate sync-archiv/projekte/redacted/1-requirements-engineering/Grundrisse Mon Jul 30 17:56:03 2018
60253 1007 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/accurate sync-archiv/projekte/redacted/3-simulation/3-2-szenario01-besucherfluss Mon Jul 30 17:56:03 2018
60253 1007 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/accurate sync-archiv/projekte/redacted/3-simulation/3-2-szenario01-besucherfluss Mon Jul 30 17:56:03 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/Pressemitteilungen Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/Pressemitteilungen Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss . Mon Jul 30 14:59:15 2018
74554 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss . Mon Jul 30 17:11:09 2018
74554 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss . Mon Jul 30 17:11:09 2018
59596 817 DENY_WRITE 0x13019f RDWR LEASE(RWH) /mnt/storage/sync 20 Sales & Marketing/messen/~$messe-output.xlsx Mon Jul 30 14:58:33 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss Literatur Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss Literatur Mon Jul 30 14:59:11 2018
59596 817 DENY_WRITE 0x12019f RDWR LEASE(RWH) /mnt/storage/sync 20 Sales & Marketing/messen/messe-output.xlsx Mon Jul 30 14:58:33 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 11 Business Development Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 11 Business Development Mon Jul 30 14:59:11 2018
This is the other things that process is doing according to smbstatus:
smbstatus | grep 59596
Code:
59596 ss accurate SS-X230.office.accu-rate (ipv4:192.168.1.217:64203) SMB3_11 -
partial(AES-128-CMAC)
sync 59596 SS-X230.office.accu-rate Mon Jul 30 14:57:29 2018 CEST - -
IPC$ 59596 SS-X230.office.accu-rate Mon Jul 30 15:05:30 2018 CEST - -
accurate 59596 SS-X230.office.accu-rate Mon Jul 30 14:59:11 2018 CEST - -
ss 59596 SS-X230.office.accu-rate Mon Jul 30 14:59:12 2018 CEST - -
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 10 Research & Development/workshops-konferenzen Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 10 Research & Development/workshops-konferenzen Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/Pressemitteilungen Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/Pressemitteilungen Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 10 Research & Development/Softwareentwicklung/produkt/schulung Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 10 Research & Development/Softwareentwicklung/produkt/schulung Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss . Mon Jul 30 14:59:15 2018
59596 817 DENY_WRITE 0x120089 RDONLY LEASE(RWH) /mnt/storage/sync 50 Finance & Legal/finanzen/redacted/redacted.xlsx Mon Jul 30 15:05:30 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 10 Research & Development Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 10 Research & Development Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing
Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing
Mon Jul 30 14:59:11 2018
59596 817 DENY_WRITE 0x13019f RDWR LEASE(RWH) /mnt/storage/sync 20 Sales & Marketing/messen/~$messe-output.xlsx Mon Jul 30 14:58:33 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/10 Vorlagen Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/10 Vorlagen Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss Literatur Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/home/ss Literatur Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 40 Operations & Organisation Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 40 Operations & Organisation Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/accurate sync-archiv/projekte/1-completed projects/redacted/1-requirements-engineering/1-2-ausgang/e-mails Mon Jul 30 15:05:31 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/50 Strategie Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/50 Strategie Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen Mon Jul 30 15:05:28 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen Mon Jul 30 15:05:28 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen/redacted Mon Jul 30 15:05:30 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen/redacted Mon Jul 30 15:05:30 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise/2018/redacted/03-angebot/vertrag Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise/2018/redacted/03-angebot/vertrag Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen/redacted/#archiv Mon Jul 30 15:05:30 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen/redacted/#archiv Mon Jul 30 15:05:30 2018
59596 817 DENY_WRITE 0x12019f RDWR LEASE(RWH) /mnt/storage/sync 20 Sales & Marketing/messen/messe-output.xlsx Mon Jul 30 14:58:33 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 11 Business Development Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 11 Business Development Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise/redacted Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise/redacted Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen/controlling Mon Jul 30 15:05:28 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzen/controlling Mon Jul 30 15:05:28 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzierungen/redacted Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 50 Finance & Legal/finanzierungen/redacted Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync . Mon Jul 30 15:04:12 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/accurate sync-archiv/projekte Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/accurate sync-archiv/projekte Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/infopaket Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync 20 Sales & Marketing/infopaket Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise/2018/redacted/03-angebot/angebotsteile-vertrag Mon Jul 30 14:59:11 2018
59596 817 DENY_NONE 0x100081 RDONLY NONE /mnt/storage/sync akquise/2018/redacted/03-angebot/angebotsteile-vertrag Mon Jul 30 14:59:11 2018
59596 1012 DENY_NONE 0x80 RDONLY NONE /mnt/storage/accurate . Mon Jul 30 15:00:49 2018
That's that. Next up is truss and tcpdump.