Re: Permission error after upgrade to Debian Buster (10.2)

"Kaulkwappe" <[email protected]> Mon, 25 Nov 2019 00:10:58 +0100
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
--d70379a78f35271971389e53ad71e6f0709ef50461a7d4a415b53ad08f8d5242
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div style=3D"font-family: Arial; text-align: left; font-size: 14px; color:=
 #000000;">Hi Simon,</div><div style=3D"font-family: Arial; text-align: lef=
t; font-size: 14px; color: #000000;"><br></div><div style=3D"font-family: A=
rial; text-align: left; font-size: 14px; color: #000000;"><div>&gt; I would=
 have expect a permission error instead of a "read-only" one. It</div><div>=
&gt; looks as if /var/log was not properly added to be ReadWritePaths set.<=
/div></div><div style=3D"font-family: Arial; text-align: left; font-size: 1=
4px; color: #000000;"><br></div><div style=3D"font-family: Arial; text-alig=
n: left; font-size: 14px; color: #000000;">That is what I have used:</div><=
div style=3D"font-family: Arial; text-align: left; font-size: 14px; color: =
#000000;">&gt;&nbsp;ReadWritePaths=3D/var/lib/nsd /var/log /etc/nsd /run</d=
iv><div style=3D"font-family: Arial; text-align: left; font-size: 14px; col=
or: #000000;"><br></div><div style=3D"font-family: Arial; text-align: left;=
 font-size: 14px; color: #000000;">&gt; This unlink failure is expected and=
 AFAICT harmless.</div><div style=3D"font-family: Arial; text-align: left; =
font-size: 14px; color: #000000;">It should be harmless, but it doesn't loo=
k nice. I would consider this as a bug.</div><div style=3D"font-family: Ari=
al; text-align: left; font-size: 14px; color: #000000;"><br></div><div styl=
e=3D"font-family: Arial; text-align: left; font-size: 14px; color: #000000;=
"><div>&gt; I believe that xfrd.state should be owned by nsd:nsd as the dae=
mon needs</div><div>&gt; to write to that file.</div></div><div style=3D"fo=
nt-family: Arial; text-align: left; font-size: 14px; color: #000000;">After=
 changing the owner to nsd:nsd I believe this problem is fixed. Thanks!</di=
v><div style=3D"font-family: Arial; text-align: left; font-size: 14px; colo=
r: #000000;"><br></div><div style=3D"font-family: Arial; text-align: left; =
font-size: 14px; color: #000000;">Kind Regards,</div><div style=3D"font-fam=
ily: Arial; text-align: left; font-size: 14px; color: #000000;">Kaulkwappe<=
br><br><br><hr style=3D"border: 0; border-bottom: 1px solid #DADADA;"><b>Fr=
om:</b> Simon Deziel &lt;<a href=3D"/email/new/1/simon%40sdeziel.info">simo=
[email protected]</a>&gt;<br><b>Sent:</b> Sunday, 24. Nov 2019 =E2=80=93 22:07=
  CET +0100<br><b>To:</b> <a href=3D"/email/new/1/nsd-users%40NLnetLabs.nl"=
>[email protected]</a><br><br><b>Subject:</b> Re: [nsd-users] Permissi=
on error after upgrade to Debian Buster (10.2)<br><br></div><div>=0A=09=09=
=09=09=0A=09=09=09=09=09<style>=0A=09=09=09=09=09=09=0A=09=09=09=09=09=09bo=
dy {=0A=09=09=09=09=09=09=09font-family: "Arial";=0A=09=09=09=09=09=09=09fo=
nt-size: 100% !important;=0A=09=09=09=09=09=09=09margin: 0;=0A=09=09=09=09=
=09=09=09line-height: 1.2rem;=0A=09=09=09=09=09=09}=0A=09=09=09=09=09=09=0A=
=09=09=09=09=09</style>=0A=0A=09=09=09=09=09<pre style=3D"white-space: pre-=
wrap; color: #173860;">On 2019-11-24 3:05 p.m., Kaulkwappe wrote:=0A&gt; Hi=
 Simon,=0A&gt; =0A&gt; thanks for your fast answer.=0A&gt; =0A&gt; It seems=
 that you're right that NSD tries to open the files as root user =E2=80=
=93 which =0A&gt; seems is blocked by the restrictive nsd.service configura=
tion. See also:=0A&gt; https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D=
938987=0A&gt; =0A&gt; So, I changed the owner of all the files to 'root:roo=
t' and added '/var/log' to =0A&gt; 'ReadWritePaths'. Then NSD starts withou=
t any problems.=0A&gt; =0A&gt; However, on the next startup I see that NSD =
always changes back the ownership of =0A&gt; '/var/log/nsd.log' from 'root:=
root' back to the nsd user. This leads to =0A&gt; following error message:=
=0A&gt;  &gt; Nov 24 18:48:05 ns2 nsd[1959]: [2019-11-24 18:48:05.896] nsd[=
1959]: error: =0A&gt; Cannot open /var/log/nsd.log for appending (Read-only=
 file system), logging to =0A&gt; stderr=0A=0AI would have expect a permiss=
ion error instead of a "read-only" one. It=0Alooks as if /var/log was not p=
roperly added to be ReadWritePaths set.=0A=0A&gt; When I stop NSD, I get fo=
llowing messages:=0A&gt;  &gt; Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 2=
1:01:22.109] nsd[2169]: warning: =0A&gt; signal received, shutting down...=
=0A&gt;  &gt; Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.112] nsd[=
2169]: warning: =0A&gt; failed to unlink pidfile /run/nsd/nsd.pid: Permissi=
on denied=0A=0AThis unlink failure is expected and AFAICT harmless.=0A=0A&g=
t;  &gt; Nov 24 21:01:22 ns2 nsd[2168]: [2019-11-24 21:01:22.117] nsd[2168]=
: error: =0A&gt; xfrd: Could not open file /var/lib/nsd/xfrd.state for writ=
ing: Permission denied=0A&gt; =0A&gt; This is very confusing since /var/lib=
/nsd/xfrd.state still has root:root, while =0A&gt; NSD created the /run/nsd=
/nsd.pid using nsd:nsd.=0A=0AI believe that xfrd.state should be owned by n=
sd:nsd as the daemon needs=0Ato write to that file.=0A=0AFor reference, her=
e's what it looks on my local slave:=0A=0Aroot@ns0:~# ll /var/lib/nsd/xfrd.=
state /run/nsd/nsd.*=0Asrwxr-xr-x 1 nsd nsd    0 Nov 24 19:41 /run/nsd/nsd.=
ctl=3D=0A-rw-r--r-- 1 nsd nsd    4 Nov 24 19:41 /run/nsd/nsd.pid=0A-rw-r--r=
-- 1 nsd nsd 2702 Nov 24 19:39 /var/lib/nsd/xfrd.state=0A=0ARegards,=0ASimo=
n=0A_______________________________________________=0Ansd-users mailing lis=
[email protected]=0Ahttps://open.nlnetlabs.nl/mailman/listinfo/nsd=
-users=0A</pre>=09=09=09=09=09=0A=09=09=09=09</div>


--d70379a78f35271971389e53ad71e6f0709ef50461a7d4a415b53ad08f8d5242
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
nsd-users mailing list
[email protected]
https://open.nlnetlabs.nl/mailman/listinfo/nsd-users

--d70379a78f35271971389e53ad71e6f0709ef50461a7d4a415b53ad08f8d5242--