Re: Permission error after upgrade to Debian Buster (10.2)

"Kaulkwappe" <[email protected]> Sun, 24 Nov 2019 21:05:11 +0100
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
--8905cc4124a42a0324873c5851f43f24d105c518ec87e51be447a210a9e23a86
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div style=3D"font-family: Arial; text-align: left; font-size: 14px; color:=
 #000000;">Hi Simon,</div><div style=3D"font-family: Arial; text-align: lef=
t; font-size: 14px; color: #000000;"><br></div><div style=3D"font-family: A=
rial; text-align: left; font-size: 14px; color: #000000;">thanks for your f=
ast answer.</div><div style=3D"font-family: Arial; text-align: left; font-s=
ize: 14px; color: #000000;"><br></div><div style=3D"font-family: Arial; tex=
t-align: left; font-size: 14px; color: #000000;">It seems that you're right=
 that NSD tries to open the files as root user =E2=80=93 which seems is blo=
cked by the restrictive nsd.service configuration. See also:</div><div styl=
e=3D"text-align: left;"><span style=3D"font-size: 14px;">https://bugs.debia=
n.org/cgi-bin/bugreport.cgi?bug=3D938987</span></div><div style=3D"text-ali=
gn: left;"><span style=3D"font-size: 14px;"><br></span></div><div style=3D"=
text-align: left;"><span style=3D"font-size: 14px;">So, I changed the owner=
 of all the files to 'root:root' and added '/var/log' to '</span><span styl=
e=3D"font-size: 14px;">ReadWritePaths'.&nbsp;</span><span style=3D"font-siz=
e: 14px;">Then NSD starts without any problems.</span></div><div style=3D"t=
ext-align: left;"><span style=3D"font-size: 14px;"><div><br></div><div>Howe=
ver, on the next startup I see that NSD always changes back the ownership o=
f '/var/log/nsd.log' from 'root:root' back to the nsd user. This leads to f=
ollowing error message:</div></span></div><div style=3D"font-family: Arial;=
 text-align: left; font-size: 14px; color: #000000;">&gt;&nbsp;Nov 24 18:48=
:05 ns2 nsd[1959]: [2019-11-24 18:48:05.896] nsd[1959]: error: Cannot open =
/var/log/nsd.log for appending (Read-only file system), logging to stderr</=
div><div style=3D"font-family: Arial; text-align: left; font-size: 14px; co=
lor: #000000;"><br></div><div style=3D"font-family: Arial; text-align: left=
; font-size: 14px; color: #000000;">When I stop NSD, I get following messag=
es:</div><div style=3D"font-family: Arial; text-align: left; font-size: 14p=
x; color: #000000;"><div>&gt; Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21=
:01:22.109] nsd[2169]: warning: signal received, shutting down...</div><div=
>&gt; Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.112] nsd[2169]: w=
arning: failed to unlink pidfile /run/nsd/nsd.pid: Permission denied</div><=
div>&gt; Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.117] nsd[2168]=
: error: xfrd: Could not open file /var/lib/nsd/xfrd.state for writing: Per=
mission denied</div></div><div style=3D"font-family: Arial; text-align: lef=
t; font-size: 14px; color: #000000;"><br></div><div style=3D"font-family: A=
rial; text-align: left; font-size: 14px; color: #000000;">This is very conf=
using since&nbsp;/var/lib/nsd/xfrd.state still has root:root, while NSD cre=
ated the /run/nsd/nsd.pid using nsd:nsd.</div><div style=3D"font-family: Ar=
ial; text-align: left; font-size: 14px; color: #000000;"><br></div><div sty=
le=3D"font-family: Arial; text-align: left; font-size: 14px; color: #000000=
;">Kind Regards,</div><div style=3D"font-family: Arial; text-align: left; f=
ont-size: 14px; color: #000000;">Kaulkwappe<br><br><br><hr style=3D"border:=
 0; border-bottom: 1px solid #DADADA;"><b>From:</b> Simon Deziel &lt;<a hre=
f=3D"/email/new/1/simon%40sdeziel.info">[email protected]</a>&gt;<br><b>Se=
nt:</b> Sunday, 24. Nov 2019 =E2=80=93 17:09  CET +0100<br><b>To:</b> <a hr=
ef=3D"/email/new/1/nsd-users%40NLnetLabs.nl">[email protected]</a><br>=
<br><b>Subject:</b> Re: [nsd-users] Permission error after upgrade to Debia=
n Buster (10.2)<br><br></div><div>=0A=09=09=09=09=0A=09=09=09=09=09<style>=
=0A=09=09=09=09=09=09=0A=09=09=09=09=09=09body {=0A=09=09=09=09=09=09=09fon=
t-family: "Arial";=0A=09=09=09=09=09=09=09font-size: 100% !important;=0A=09=
=09=09=09=09=09=09margin: 0;=0A=09=09=09=09=09=09=09line-height: 1.2rem;=0A=
=09=09=09=09=09=09}=0A=09=09=09=09=09=09=0A=09=09=09=09=09</style>=0A=0A=09=
=09=09=09=09<pre style=3D"white-space: pre-wrap; color: #173860;">Hi Kaulkw=
appe,=0A=0AOn 2019-11-24 10:41 a.m., Kaulkwappe wrote:=0A&gt; Dear colleagu=
es,=0A&gt; =0A&gt; after upgrading from Stretch to Debian Buster (10.2) I g=
et following error =0A&gt; message which blocks NSD (4.1.26) from starting:=
=0A&gt; =0A&gt;  &gt; Nov 24 16:18:40 ns2 nsd[989]: [2019-11-24 16:18:40.03=
0] nsd[989]: error: =0A&gt; could not open zone list /var/lib/nsd/zone.list=
: Permission denied=0A&gt;  &gt; Nov 24 16:18:40 ns2 nsd[989]: [2019-11-24 =
16:18:40.032] nsd[989]: error: =0A&gt; could not read zonelist file /var/li=
b/nsd/zone.list=0A&gt; =0A&gt; However, the permissions are all fine; they =
did not change during the update.=0A&gt; =0A&gt; ls -l /var/lib/nsd/zone.li=
st=0A&gt;  &gt; -rw-r--r-- 1 nsd nsd 1195 Nov  4 17:33 /var/lib/nsd/zone.li=
st=0A&gt; =0A&gt; I had a look into /lib/systemd/system/nsd.service:=0A&gt;=
 =0A&gt;  &gt; [Unit]=0A&gt;  &gt; Description=3DName Server Daemon=0A&gt; =
 &gt; Documentation=3Dman:nsd(8)=0A&gt;  &gt; After=3Dnetwork.target=0A&gt;=
 =0A&gt;  &gt; [Service]=0A&gt;  &gt; Type=3Dnotify=0A&gt;  &gt; Restart=3D=
always=0A&gt;  &gt; ExecStart=3D/usr/sbin/nsd -d=0A&gt;  &gt; ExecReload=3D=
+/bin/kill -HUP $MAINPID=0A&gt;  &gt; CapabilityBoundingSet=3DCAP_CHOWN CAP=
_IPC_LOCK CAP_NET_BIND_SERVICE CAP_SETGID =0A&gt; CAP_SETUID CAP_SYS_CHROOT=
=0A&gt;  &gt; MemoryDenyWriteExecute=3Dtrue=0A&gt;  &gt; NoNewPrivileges=3D=
true=0A&gt;  &gt; PrivateDevices=3Dtrue=0A&gt;  &gt; PrivateTmp=3Dtrue=0A&g=
t;  &gt; ProtectHome=3Dtrue=0A&gt;  &gt; ProtectControlGroups=3Dtrue=0A&gt;=
  &gt; ProtectKernelModules=3Dtrue=0A&gt;  &gt; ProtectKernelTunables=3Dtru=
e=0A&gt;  &gt; ProtectSystem=3Dstrict=0A&gt;  &gt; ReadWritePaths=3D/var/li=
b/nsd /etc/nsd /run=0A&gt;  &gt; RuntimeDirectory=3Dnsd=0A&gt;  &gt; Restri=
ctRealtime=3Dtrue=0A&gt;  &gt; SystemCallArchitectures=3Dnative=0A&gt;  &gt=
; SystemCallFilter=3D~@clock @cpu-emulation @debug @keyring @module mount =
=0A&gt; @obsolete @resources=0A&gt; =0A&gt;  &gt; [Install]=0A&gt;  &gt; Wa=
ntedBy=3Dmulti-user.target=0A&gt; =0A&gt; Once I remove following line,=0A&=
gt; =0A&gt;  &gt; CapabilityBoundingSet=3DCAP_CHOWN CAP_IPC_LOCK CAP_NET_BI=
ND_SERVICE CAP_SETGID =0A&gt; CAP_SETUID CAP_SYS_CHROOT=0A&gt; =0A&gt; whil=
e it does not help to only remove params from it (I need to remove the full=
 =0A&gt; line), the error message changes to:=0A=0ATo override a setting yo=
u need to reset it and then set it to what you=0Awant, otherwise similar di=
rectives accumulate. Like this:=0A=0ACapabilityBoundingSet=3D=0ACapabilityB=
oundingSet=3DMY_NEW_SET_OF_CAPS=0A=0A&gt;  &gt; Nov 24 16:37:57 ns2 systemd=
[1]: Starting Name Server Daemon...=0A&gt;  &gt; Nov 24 16:37:57 ns2 nsd[16=
07]: [2019-11-24 16:37:57.144] nsd[1607]: error: =0A&gt; Cannot open /var/l=
og/nsd.log for appending (Read-only file system), logging to =0A&gt; stderr=
=0A=0AWith the IMO good ProtectSystem=3Dstrict, nsd can only ever write to=
=0Adirectories listed in ReadWritePaths=3D.=0A=0A&gt;  &gt; Nov 24 16:37:57=
 ns2 nsd[1607]: [2019-11-24 16:37:57.145] nsd[1607]: notice: =0A&gt; nsd st=
arting (NSD 4.1.26)=0A&gt;  &gt; Nov 24 16:37:57 ns2 nsd[1607]: [2019-11-24=
 16:37:57.252] nsd[1608]: notice: =0A&gt; nsd started (NSD 4.1.26), pid 160=
7=0A&gt;  &gt; Nov 24 16:37:57 ns2 systemd[1]: Started Name Server Daemon.=
=0A&gt; =0A&gt; Since nsd-control zonestatus now works, NSD now can read =
=0A&gt; the /var/lib/nsd/zone.list.=0A=0AIt's a wild guess but maybe /var/l=
ib/nsd/zone.list is opened by nsd=0Awhile still running as root. When you h=
ave reduced caps=0A(CapabilityBoundingSet), you don't have CAP_FOWNER, CAP_=
DAC_READ_SEARCH=0Aand/or CAP_DAC_OVERRIDE so might get a permission error.=
=0A=0AI'm not sure if the right thing to do would be to have nsd open the f=
ile=0Apost SETUID/GID or if more caps should be added.=0A=0A&gt; However, i=
t is still not running fine because now =0A&gt; NSD says it cannot open the=
 /var/log/nsd.log.=0A&gt; =0A&gt; Does anyone know how to fix that?=0A=0AIf=
 you want nsd to do logging to a file directly, you'll need to add it=0Ato =
the ReadWritePaths. I'd suggest "sudo systemctl edit nsd" then enter=0Aand =
save the following:=0A=0A  [Service]=0A  ReadWritePaths=3D/var/log=0A=0AThe=
n "sudo systemctl restart nsd". You can also throw in the=0ACapabilityBound=
ingSet tweaks you want in there.=0A=0AHTH,=0ASimon=0A______________________=
_________________________=0Ansd-users mailing [email protected]=
=0Ahttps://open.nlnetlabs.nl/mailman/listinfo/nsd-users=0A</pre>=09=09=09=
=09=09=0A=09=09=09=09</div>


--8905cc4124a42a0324873c5851f43f24d105c518ec87e51be447a210a9e23a86
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
nsd-users mailing list
[email protected]
https://open.nlnetlabs.nl/mailman/listinfo/nsd-users

--8905cc4124a42a0324873c5851f43f24d105c518ec87e51be447a210a9e23a86--