Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-56243

Jenkins GUI is slow -removing cookie fixes it (temporarily)

    • Jenkins 2.184

      The last few week/months all our Jenkins users experience very a very slow web GUI after some time. 

      Situation:

      • In a clean browser (no cache, cookies) Jenkins is very fast
      • After some time (workday - 8 hours of active Jenkins use), Jenkins GUI starts to slow down:
        Loading jobs takes 10+ seconds, loading of static resources are very long pending etc.
        Jenkins just isn't workable for users at that time.
      • Logging out + in again does not fix it for that user.
      • Removing the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie fixes everything for that user and makes Jenkins blazing fast again.

       So, what happens with the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE? 
      Why does it cause the slowness after hours of use?

       [update]

       SECURITY-901 / CVE-2019-1003004 in Jenkins 2.150.2 introduced a security fix, but with a side effect that after some time (hours) the Jenkins GUI for that user starts to slow down to a crawl.

          [JENKINS-56243] Jenkins GUI is slow -removing cookie fixes it (temporarily)

          Henjo van Rees created issue -
          Henjo van Rees made changes -
          Description Original: The last few week/months all our Jenkins users experience very a very slow web GUI after some time. 

          Situation:
           * In a clean browser (no cache, cookies) Jenkins is very fast
           * After some time (workday - 8 hours of active Jenkins use), Jenkins GUI starts to slow down:
          Loading jobs takes 10+ seconds, loading of static resources are very long pending etc.
          Jenkins just isn't workable for users at that time.
           * Logging out + in again does not fix it for that user.
           * _Removing the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie fixes everything for that user and makes Jenkins blazing fast again._

           

          So, what happens with the _ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE?_ 
          Why does it cause the slowness after hours of use?
          New: The last few week/months all our Jenkins users experience very a very slow web GUI after some time. 

          Situation:
           * In a clean browser (no cache, cookies) Jenkins is very fast
           * After some time (workday - 8 hours of active Jenkins use), Jenkins GUI starts to slow down:
           Loading jobs takes 10+ seconds, loading of static resources are very long pending etc.
           Jenkins just isn't workable for users at that time.
           * Logging out + in again does not fix it for that user.
           * _Removing the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie fixes everything for that user and makes Jenkins blazing fast again._

           So, what happens with the _ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE?_ 
           Why does it cause the slowness after hours of use?
          Henjo van Rees made changes -
          Priority Original: Minor [ 4 ] New: Major [ 3 ]
          Henjo van Rees made changes -
          Description Original: The last few week/months all our Jenkins users experience very a very slow web GUI after some time. 

          Situation:
           * In a clean browser (no cache, cookies) Jenkins is very fast
           * After some time (workday - 8 hours of active Jenkins use), Jenkins GUI starts to slow down:
           Loading jobs takes 10+ seconds, loading of static resources are very long pending etc.
           Jenkins just isn't workable for users at that time.
           * Logging out + in again does not fix it for that user.
           * _Removing the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie fixes everything for that user and makes Jenkins blazing fast again._

           So, what happens with the _ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE?_ 
           Why does it cause the slowness after hours of use?
          New: The last few week/months all our Jenkins users experience very a very slow web GUI after some time. 

          Situation:
           * In a clean browser (no cache, cookies) Jenkins is very fast
           * After some time (workday - 8 hours of active Jenkins use), Jenkins GUI starts to slow down:
           Loading jobs takes 10+ seconds, loading of static resources are very long pending etc.
           Jenkins just isn't workable for users at that time.
           * Logging out + in again does not fix it for that user.
           * _Removing the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie fixes everything for that user and makes Jenkins blazing fast again._

           So, what happens with the _ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE?_ 
           Why does it cause the slowness after hours of use?

           

          [update]

           
          Henjo van Rees made changes -
          Description Original: The last few week/months all our Jenkins users experience very a very slow web GUI after some time. 

          Situation:
           * In a clean browser (no cache, cookies) Jenkins is very fast
           * After some time (workday - 8 hours of active Jenkins use), Jenkins GUI starts to slow down:
           Loading jobs takes 10+ seconds, loading of static resources are very long pending etc.
           Jenkins just isn't workable for users at that time.
           * Logging out + in again does not fix it for that user.
           * _Removing the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie fixes everything for that user and makes Jenkins blazing fast again._

           So, what happens with the _ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE?_ 
           Why does it cause the slowness after hours of use?

           

          [update]

           
          New: The last few week/months all our Jenkins users experience very a very slow web GUI after some time. 

          Situation:
           * In a clean browser (no cache, cookies) Jenkins is very fast
           * After some time (workday - 8 hours of active Jenkins use), Jenkins GUI starts to slow down:
           Loading jobs takes 10+ seconds, loading of static resources are very long pending etc.
           Jenkins just isn't workable for users at that time.
           * Logging out + in again does not fix it for that user.
           * _Removing the ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE cookie fixes everything for that user and makes Jenkins blazing fast again._

           So, what happens with the _ACEGI_SECURITY_HASHED_REMEMBER_ME_COOKIE?_ 
           Why does it cause the slowness after hours of use?

           _*[update]*_

           _*SECURITY-901 / CVE-2019-1003004 in Jenkins 2.150.2 introduced a security fix, but with a side effect that after some time (hours) the Jenkins GUI for that user starts to slow down to a crawl.*_
          Linus Geson made changes -
          Attachment New: Thread dump [Jenkins].html [ 46514 ]
          Linus Geson made changes -
          Attachment New: Thread dump2 [Jenkins].html [ 46516 ]
          Meghna Pandey made changes -
          Priority Original: Major [ 3 ] New: Critical [ 2 ]
          Sverre Moe made changes -
          Labels New: user-experience
          Matt Sicker made changes -
          Assignee New: Matt Sicker [ jvz ]
          Matt Sicker made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]

            jvz Matt Sicker
            henjovr Henjo van Rees
            Votes:
            26 Vote for this issue
            Watchers:
            43 Start watching this issue

              Created:
              Updated:
              Resolved: