You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

LDAP内管理员禁用用户引发Jenkins构建误报问题求助

重装Jenkins后LDAP禁用用户引发构建误报问题

问题描述

更新/重装公司Jenkins后,遇到由LDAP及一名管理员禁用用户引发的构建误报问题。最初以为是邮件通知时LDAP无法获取该用户邮箱导致,但禁用所有通知后问题仍存在。每当SVN触发构建且该禁用用户在提交列表中时,就会出现误报,同时变更列表中显示该用户时会出现视觉Bug。

错误日志

构建成功后日志

...
[INFO] BUILD SUCCESS
[INFO] ------------------------------------------------------------------------
[INFO] Total time:  14:28 min
[INFO] Finished at: 2024-04-16T09:34:13+02:00
...

抛出的错误堆栈

FATAL: org.springframework.security.authentication.DisabledException: The user "userxyz" is administratively disabled.
org.springframework.security.authentication.DisabledException: The user "userxyz" is administratively disabled.
    at hudson.security.UserAttributesHelper.checkIfUserEnabled(UserAttributesHelper.java:92)
    at hudson.security.LDAPSecurityRealm$LDAPUserDetailsService.loadUserByUsername(LDAPSecurityRealm.java:1319)
    at hudson.security.LDAPSecurityRealm$DelegateLDAPUserDetailsService.loadUserByUsername(LDAPSecurityRealm.java:1232)
    at hudson.security.LDAPSecurityRealm.loadUserByUsername2(LDAPSecurityRealm.java:765)
    at jenkins.security.UserDetailsCache$Retriever.call(UserDetailsCache.java:170)
    at jenkins.security.UserDetailsCache$Retriever.call(UserDetailsCache.java:159)
    at com.google.common.cache.LocalCache$LocalManualCache$1.load(LocalCache.java:4955)
    at com.google.common.cache.LocalCache$LoadingValueReference.loadFuture(LocalCache.java:3589)
    at com.google.common.cache.LocalCache$Segment.loadSync(LocalCache.java:2328)
    at com.google.common.cache.LocalCache$Segment.lockedGetOrLoad(LocalCache.java:2187)
    at com.google.common.cache.LocalCache$Segment.get(LocalCache.java:2081)
Caused: com.google.common.util.concurrent.UncheckedExecutionException
    at com.google.common.cache.LocalCache$Segment.get(LocalCache.java:2087)
    at com.google.common.cache.LocalCache.get(LocalCache.java:4036)
    at com.google.common.cache.LocalCache$LocalManualCache.get(LocalCache.java:4950)
    at jenkins.security.UserDetailsCache.loadUserByUsername(UserDetailsCache.java:127)
    at hudson.model.User$UserIDCanonicalIdResolver.resolveCanonicalId(User.java:1262)
    at hudson.model.User$CanonicalIdResolver.resolve(User.java:1203)
    at hudson.model.User.get(User.java:530)
    at hudson.model.User.getOrCreateByIdOrFullName(User.java:593)
    at hudson.model.User.get(User.java:574)
    at hudson.scm.SubversionChangeLogSet$LogEntry.setUser(SubversionChangeLogSet.java:305)
    at hudson.scm.SubversionChangeLogParser.parse(SubversionChangeLogParser.java:92)
    at hudson.scm.SubversionChangeLogParser.parse(SubversionChangeLogParser.java:43)
    at hudson.scm.ChangeLogParser.parse(ChangeLogParser.java:57)
    at hudson.model.AbstractBuild.calcChangeSet(AbstractBuild.java:947)
    at hudson.model.AbstractBuild.getChangeSet(AbstractBuild.java:915)
    at hudson.model.AbstractBuild.getChangeSets(AbstractBuild.java:929)
    at jenkins.scm.RunWithSCM.calculateCulprits(RunWithSCM.java:136)
    at hudson.model.AbstractBuild.calculateCulprits(AbstractBuild.java:353)
    at jenkins.scm.RunWithSCM.getCulprits(RunWithSCM.java:93)
    at hudson.model.AbstractBuild.getCulprits(AbstractBuild.java:342)
    at jenkins.scm.RunWithSCM.calculateCulprits(RunWithSCM.java:133)
    at hudson.model.AbstractBuild.calculateCulprits(AbstractBuild.java:353)
    at jenkins.scm.RunWithSCM.getCulprits(RunWithSCM.java:93)
    at hudson.model.AbstractBuild.getCulprits(AbstractBuild.java:342)
    at jenkins.scm.RunWithSCM.calculateCulprits(RunWithSCM.java:133)
    at hudson.model.AbstractBuild.calculateCulprits(AbstractBuild.java:353)
    at jenkins.scm.RunWithSCM.getCulprits(RunWithSCM.java:93)
    at hudson.model.AbstractBuild.getCulprits(AbstractBuild.java:342)
    at hudson.model.AbstractBuild$AbstractBuildExecution.post(AbstractBuild.java:715)
    at hudson.model.Run.execute(Run.java:1918)
    at hudson.model.FreeStyleBuild.run(FreeStyleBuild.java:44)
    at hudson.model.ResourceController.execute(ResourceController.java:101)
    at hudson.model.Executor.run(Executor.java:442)

已尝试的解决措施

  • 禁用所有通知(邮件、IRC、Webhook)
  • 更新所有插件
  • 检查LDAP配置(与重装前一致)

问题解答

1. 是否可忽略该禁用用户?

可以通过两种方式处理:

  • 临时方案:在Jenkins中手动创建该禁用用户(无需关联LDAP),这样构建时就不会因无法加载用户信息抛出异常。
  • 长期方案:等待Jenkins官方修复对应问题,或修改SVN提交记录的用户关联逻辑,跳过禁用用户的信息加载。

2. 问题根源是什么?

根源是Jenkins的LDAP安全域与SVN变更日志解析逻辑的协同问题:

  • 当SVN构建触发后,Jenkins会解析变更日志中的提交用户,尝试通过LDAP加载该用户的详细信息。
  • 若该用户在LDAP中被禁用,UserAttributesHelper.checkIfUserEnabled会抛出DisabledException,但Jenkins的变更解析流程未捕获该异常,导致构建从成功转为失败(误报)。
  • SVN本身只是提供了提交用户的标识,并非问题直接原因,核心是Jenkins处理禁用LDAP用户时的异常未被正确处理。

内容的提问来源于stack exchange,提问作者TheQuaX

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 15:25:22