Re: Permission error after upgrade to Debian Buster (10.2)
"Kaulkwappe" <[email protected]> Sun, 24 Nov 2019 21:05:11 +0100
| Newsgroups | gmane.network.dns.nsd.general |
|---|---|
| Message-ID | <[email protected]> |
--8905cc4124a42a0324873c5851f43f24d105c518ec87e51be447a210a9e23a86 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div style=3D"font-family: Arial; text-align: left; font-size: 14px; color:= #000000;">Hi Simon,</div><div style=3D"font-family: Arial; text-align: lef= t; font-size: 14px; color: #000000;"><br></div><div style=3D"font-family: A= rial; text-align: left; font-size: 14px; color: #000000;">thanks for your f= ast answer.</div><div style=3D"font-family: Arial; text-align: left; font-s= ize: 14px; color: #000000;"><br></div><div style=3D"font-family: Arial; tex= t-align: left; font-size: 14px; color: #000000;">It seems that you're right= that NSD tries to open the files as root user =E2=80=93 which seems is blo= cked by the restrictive nsd.service configuration. See also:</div><div styl= e=3D"text-align: left;"><span style=3D"font-size: 14px;">https://bugs.debia= n.org/cgi-bin/bugreport.cgi?bug=3D938987</span></div><div style=3D"text-ali= gn: left;"><span style=3D"font-size: 14px;"><br></span></div><div style=3D"= text-align: left;"><span style=3D"font-size: 14px;">So, I changed the owner= of all the files to 'root:root' and added '/var/log' to '</span><span styl= e=3D"font-size: 14px;">ReadWritePaths'. </span><span style=3D"font-siz= e: 14px;">Then NSD starts without any problems.</span></div><div style=3D"t= ext-align: left;"><span style=3D"font-size: 14px;"><div><br></div><div>Howe= ver, on the next startup I see that NSD always changes back the ownership o= f '/var/log/nsd.log' from 'root:root' back to the nsd user. This leads to f= ollowing error message:</div></span></div><div style=3D"font-family: Arial;= text-align: left; font-size: 14px; color: #000000;">> Nov 24 18:48= :05 ns2 nsd[1959]: [2019-11-24 18:48:05.896] nsd[1959]: error: Cannot open = /var/log/nsd.log for appending (Read-only file system), logging to stderr</= div><div style=3D"font-family: Arial; text-align: left; font-size: 14px; co= lor: #000000;"><br></div><div style=3D"font-family: Arial; text-align: left= ; font-size: 14px; color: #000000;">When I stop NSD, I get following messag= es:</div><div style=3D"font-family: Arial; text-align: left; font-size: 14p= x; color: #000000;"><div>> Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21= :01:22.109] nsd[2169]: warning: signal received, shutting down...</div><div= >> Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.112] nsd[2169]: w= arning: failed to unlink pidfile /run/nsd/nsd.pid: Permission denied</div><= div>> Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.117] nsd[2168]= : error: xfrd: Could not open file /var/lib/nsd/xfrd.state for writing: Per= mission denied</div></div><div style=3D"font-family: Arial; text-align: lef= t; font-size: 14px; color: #000000;"><br></div><div style=3D"font-family: A= rial; text-align: left; font-size: 14px; color: #000000;">This is very conf= using since /var/lib/nsd/xfrd.state still has root:root, while NSD cre= ated the /run/nsd/nsd.pid using nsd:nsd.</div><div style=3D"font-family: Ar= ial; text-align: left; font-size: 14px; color: #000000;"><br></div><div sty= le=3D"font-family: Arial; text-align: left; font-size: 14px; color: #000000= ;">Kind Regards,</div><div style=3D"font-family: Arial; text-align: left; f= ont-size: 14px; color: #000000;">Kaulkwappe<br><br><br><hr style=3D"border:= 0; border-bottom: 1px solid #DADADA;"><b>From:</b> Simon Deziel <<a hre= f=3D"/email/new/1/simon%40sdeziel.info">[email protected]</a>><br><b>Se= nt:</b> Sunday, 24. Nov 2019 =E2=80=93 17:09 CET +0100<br><b>To:</b> <a hr= ef=3D"/email/new/1/nsd-users%40NLnetLabs.nl">[email protected]</a><br>= <br><b>Subject:</b> Re: [nsd-users] Permission error after upgrade to Debia= n Buster (10.2)<br><br></div><div>=0A=09=09=09=09=0A=09=09=09=09=09<style>= =0A=09=09=09=09=09=09=0A=09=09=09=09=09=09body {=0A=09=09=09=09=09=09=09fon= t-family: "Arial";=0A=09=09=09=09=09=09=09font-size: 100% !important;=0A=09= =09=09=09=09=09=09margin: 0;=0A=09=09=09=09=09=09=09line-height: 1.2rem;=0A= =09=09=09=09=09=09}=0A=09=09=09=09=09=09=0A=09=09=09=09=09</style>=0A=0A=09= =09=09=09=09<pre style=3D"white-space: pre-wrap; color: #173860;">Hi Kaulkw= appe,=0A=0AOn 2019-11-24 10:41 a.m., Kaulkwappe wrote:=0A> Dear colleagu= es,=0A> =0A> after upgrading from Stretch to Debian Buster (10.2) I g= et following error =0A> message which blocks NSD (4.1.26) from starting:= =0A> =0A> > Nov 24 16:18:40 ns2 nsd[989]: [2019-11-24 16:18:40.03= 0] nsd[989]: error: =0A> could not open zone list /var/lib/nsd/zone.list= : Permission denied=0A> > Nov 24 16:18:40 ns2 nsd[989]: [2019-11-24 = 16:18:40.032] nsd[989]: error: =0A> could not read zonelist file /var/li= b/nsd/zone.list=0A> =0A> However, the permissions are all fine; they = did not change during the update.=0A> =0A> ls -l /var/lib/nsd/zone.li= st=0A> > -rw-r--r-- 1 nsd nsd 1195 Nov 4 17:33 /var/lib/nsd/zone.li= st=0A> =0A> I had a look into /lib/systemd/system/nsd.service:=0A>= =0A> > [Unit]=0A> > Description=3DName Server Daemon=0A> = > Documentation=3Dman:nsd(8)=0A> > After=3Dnetwork.target=0A>= =0A> > [Service]=0A> > Type=3Dnotify=0A> > Restart=3D= always=0A> > ExecStart=3D/usr/sbin/nsd -d=0A> > ExecReload=3D= +/bin/kill -HUP $MAINPID=0A> > CapabilityBoundingSet=3DCAP_CHOWN CAP= _IPC_LOCK CAP_NET_BIND_SERVICE CAP_SETGID =0A> CAP_SETUID CAP_SYS_CHROOT= =0A> > MemoryDenyWriteExecute=3Dtrue=0A> > NoNewPrivileges=3D= true=0A> > PrivateDevices=3Dtrue=0A> > PrivateTmp=3Dtrue=0A&g= t; > ProtectHome=3Dtrue=0A> > ProtectControlGroups=3Dtrue=0A>= > ProtectKernelModules=3Dtrue=0A> > ProtectKernelTunables=3Dtru= e=0A> > ProtectSystem=3Dstrict=0A> > ReadWritePaths=3D/var/li= b/nsd /etc/nsd /run=0A> > RuntimeDirectory=3Dnsd=0A> > Restri= ctRealtime=3Dtrue=0A> > SystemCallArchitectures=3Dnative=0A> >= ; SystemCallFilter=3D~@clock @cpu-emulation @debug @keyring @module mount = =0A> @obsolete @resources=0A> =0A> > [Install]=0A> > Wa= ntedBy=3Dmulti-user.target=0A> =0A> Once I remove following line,=0A&= gt; =0A> > CapabilityBoundingSet=3DCAP_CHOWN CAP_IPC_LOCK CAP_NET_BI= ND_SERVICE CAP_SETGID =0A> CAP_SETUID CAP_SYS_CHROOT=0A> =0A> whil= e it does not help to only remove params from it (I need to remove the full= =0A> line), the error message changes to:=0A=0ATo override a setting yo= u need to reset it and then set it to what you=0Awant, otherwise similar di= rectives accumulate. Like this:=0A=0ACapabilityBoundingSet=3D=0ACapabilityB= oundingSet=3DMY_NEW_SET_OF_CAPS=0A=0A> > Nov 24 16:37:57 ns2 systemd= [1]: Starting Name Server Daemon...=0A> > Nov 24 16:37:57 ns2 nsd[16= 07]: [2019-11-24 16:37:57.144] nsd[1607]: error: =0A> Cannot open /var/l= og/nsd.log for appending (Read-only file system), logging to =0A> stderr= =0A=0AWith the IMO good ProtectSystem=3Dstrict, nsd can only ever write to= =0Adirectories listed in ReadWritePaths=3D.=0A=0A> > Nov 24 16:37:57= ns2 nsd[1607]: [2019-11-24 16:37:57.145] nsd[1607]: notice: =0A> nsd st= arting (NSD 4.1.26)=0A> > Nov 24 16:37:57 ns2 nsd[1607]: [2019-11-24= 16:37:57.252] nsd[1608]: notice: =0A> nsd started (NSD 4.1.26), pid 160= 7=0A> > Nov 24 16:37:57 ns2 systemd[1]: Started Name Server Daemon.= =0A> =0A> Since nsd-control zonestatus now works, NSD now can read = =0A> the /var/lib/nsd/zone.list.=0A=0AIt's a wild guess but maybe /var/l= ib/nsd/zone.list is opened by nsd=0Awhile still running as root. When you h= ave reduced caps=0A(CapabilityBoundingSet), you don't have CAP_FOWNER, CAP_= DAC_READ_SEARCH=0Aand/or CAP_DAC_OVERRIDE so might get a permission error.= =0A=0AI'm not sure if the right thing to do would be to have nsd open the f= ile=0Apost SETUID/GID or if more caps should be added.=0A=0A> However, i= t is still not running fine because now =0A> NSD says it cannot open the= /var/log/nsd.log.=0A> =0A> Does anyone know how to fix that?=0A=0AIf= you want nsd to do logging to a file directly, you'll need to add it=0Ato = the ReadWritePaths. I'd suggest "sudo systemctl edit nsd" then enter=0Aand = save the following:=0A=0A [Service]=0A ReadWritePaths=3D/var/log=0A=0AThe= n "sudo systemctl restart nsd". You can also throw in the=0ACapabilityBound= ingSet tweaks you want in there.=0A=0AHTH,=0ASimon=0A______________________= _________________________=0Ansd-users mailing [email protected]= =0Ahttps://open.nlnetlabs.nl/mailman/listinfo/nsd-users=0A</pre>=09=09=09= =09=09=0A=09=09=09=09</div> --8905cc4124a42a0324873c5851f43f24d105c518ec87e51be447a210a9e23a86 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ nsd-users mailing list [email protected] https://open.nlnetlabs.nl/mailman/listinfo/nsd-users --8905cc4124a42a0324873c5851f43f24d105c518ec87e51be447a210a9e23a86--