Re: Permission error after upgrade to Debian Buster (10.2)
"Kaulkwappe" <[email protected]> Mon, 25 Nov 2019 00:10:58 +0100
| Newsgroups | gmane.network.dns.nsd.general |
|---|---|
| Message-ID | <[email protected]> |
--d70379a78f35271971389e53ad71e6f0709ef50461a7d4a415b53ad08f8d5242 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div style=3D"font-family: Arial; text-align: left; font-size: 14px; color:= #000000;">Hi Simon,</div><div style=3D"font-family: Arial; text-align: lef= t; font-size: 14px; color: #000000;"><br></div><div style=3D"font-family: A= rial; text-align: left; font-size: 14px; color: #000000;"><div>> I would= have expect a permission error instead of a "read-only" one. It</div><div>= > looks as if /var/log was not properly added to be ReadWritePaths set.<= /div></div><div style=3D"font-family: Arial; text-align: left; font-size: 1= 4px; color: #000000;"><br></div><div style=3D"font-family: Arial; text-alig= n: left; font-size: 14px; color: #000000;">That is what I have used:</div><= div style=3D"font-family: Arial; text-align: left; font-size: 14px; color: = #000000;">> ReadWritePaths=3D/var/lib/nsd /var/log /etc/nsd /run</d= iv><div style=3D"font-family: Arial; text-align: left; font-size: 14px; col= or: #000000;"><br></div><div style=3D"font-family: Arial; text-align: left;= font-size: 14px; color: #000000;">> This unlink failure is expected and= AFAICT harmless.</div><div style=3D"font-family: Arial; text-align: left; = font-size: 14px; color: #000000;">It should be harmless, but it doesn't loo= k nice. I would consider this as a bug.</div><div style=3D"font-family: Ari= al; text-align: left; font-size: 14px; color: #000000;"><br></div><div styl= e=3D"font-family: Arial; text-align: left; font-size: 14px; color: #000000;= "><div>> I believe that xfrd.state should be owned by nsd:nsd as the dae= mon needs</div><div>> to write to that file.</div></div><div style=3D"fo= nt-family: Arial; text-align: left; font-size: 14px; color: #000000;">After= changing the owner to nsd:nsd I believe this problem is fixed. Thanks!</di= v><div style=3D"font-family: Arial; text-align: left; font-size: 14px; colo= r: #000000;"><br></div><div style=3D"font-family: Arial; text-align: left; = font-size: 14px; color: #000000;">Kind Regards,</div><div style=3D"font-fam= ily: Arial; text-align: left; font-size: 14px; color: #000000;">Kaulkwappe<= br><br><br><hr style=3D"border: 0; border-bottom: 1px solid #DADADA;"><b>Fr= om:</b> Simon Deziel <<a href=3D"/email/new/1/simon%40sdeziel.info">simo= [email protected]</a>><br><b>Sent:</b> Sunday, 24. Nov 2019 =E2=80=93 22:07= CET +0100<br><b>To:</b> <a href=3D"/email/new/1/nsd-users%40NLnetLabs.nl"= >[email protected]</a><br><br><b>Subject:</b> Re: [nsd-users] Permissi= on error after upgrade to Debian Buster (10.2)<br><br></div><div>=0A=09=09= =09=09=0A=09=09=09=09=09<style>=0A=09=09=09=09=09=09=0A=09=09=09=09=09=09bo= dy {=0A=09=09=09=09=09=09=09font-family: "Arial";=0A=09=09=09=09=09=09=09fo= nt-size: 100% !important;=0A=09=09=09=09=09=09=09margin: 0;=0A=09=09=09=09= =09=09=09line-height: 1.2rem;=0A=09=09=09=09=09=09}=0A=09=09=09=09=09=09=0A= =09=09=09=09=09</style>=0A=0A=09=09=09=09=09<pre style=3D"white-space: pre-= wrap; color: #173860;">On 2019-11-24 3:05 p.m., Kaulkwappe wrote:=0A> Hi= Simon,=0A> =0A> thanks for your fast answer.=0A> =0A> It seems= that you're right that NSD tries to open the files as root user =E2=80= =93 which =0A> seems is blocked by the restrictive nsd.service configura= tion. See also:=0A> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D= 938987=0A> =0A> So, I changed the owner of all the files to 'root:roo= t' and added '/var/log' to =0A> 'ReadWritePaths'. Then NSD starts withou= t any problems.=0A> =0A> However, on the next startup I see that NSD = always changes back the ownership of =0A> '/var/log/nsd.log' from 'root:= root' back to the nsd user. This leads to =0A> following error message:= =0A> > Nov 24 18:48:05 ns2 nsd[1959]: [2019-11-24 18:48:05.896] nsd[= 1959]: error: =0A> Cannot open /var/log/nsd.log for appending (Read-only= file system), logging to =0A> stderr=0A=0AI would have expect a permiss= ion error instead of a "read-only" one. It=0Alooks as if /var/log was not p= roperly added to be ReadWritePaths set.=0A=0A> When I stop NSD, I get fo= llowing messages:=0A> > Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 2= 1:01:22.109] nsd[2169]: warning: =0A> signal received, shutting down...= =0A> > Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.112] nsd[= 2169]: warning: =0A> failed to unlink pidfile /run/nsd/nsd.pid: Permissi= on denied=0A=0AThis unlink failure is expected and AFAICT harmless.=0A=0A&g= t; > Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.117] nsd[2168]= : error: =0A> xfrd: Could not open file /var/lib/nsd/xfrd.state for writ= ing: Permission denied=0A> =0A> This is very confusing since /var/lib= /nsd/xfrd.state still has root:root, while =0A> NSD created the /run/nsd= /nsd.pid using nsd:nsd.=0A=0AI believe that xfrd.state should be owned by n= sd:nsd as the daemon needs=0Ato write to that file.=0A=0AFor reference, her= e's what it looks on my local slave:=0A=0Aroot@ns0:~# ll /var/lib/nsd/xfrd.= state /run/nsd/nsd.*=0Asrwxr-xr-x 1 nsd nsd 0 Nov 24 19:41 /run/nsd/nsd.= ctl=3D=0A-rw-r--r-- 1 nsd nsd 4 Nov 24 19:41 /run/nsd/nsd.pid=0A-rw-r--r= -- 1 nsd nsd 2702 Nov 24 19:39 /var/lib/nsd/xfrd.state=0A=0ARegards,=0ASimo= n=0A_______________________________________________=0Ansd-users mailing lis= [email protected]=0Ahttps://open.nlnetlabs.nl/mailman/listinfo/nsd= -users=0A</pre>=09=09=09=09=09=0A=09=09=09=09</div> --d70379a78f35271971389e53ad71e6f0709ef50461a7d4a415b53ad08f8d5242 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ nsd-users mailing list [email protected] https://open.nlnetlabs.nl/mailman/listinfo/nsd-users --d70379a78f35271971389e53ad71e6f0709ef50461a7d4a415b53ad08f8d5242--