Re: Permission error after upgrade to Debian Buster (10.2)

Wouter Wijngaards <[email protected]> Mon, 2 Dec 2019 10:22:03 +0100
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============2372171604871467782==
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="7kqLTRm0cg5cTjQ508tZ3XeitUxeog1ZO"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--7kqLTRm0cg5cTjQ508tZ3XeitUxeog1ZO
Content-Type: multipart/mixed; boundary="aBLkYMk9BUqhaTiPNuHP3KR1PiW2a41ow"

--aBLkYMk9BUqhaTiPNuHP3KR1PiW2a41ow
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

Hi Simon,

On 11/25/19 1:26 AM, Simon Deziel wrote:
> On 2019-11-24 6:10 p.m., Kaulkwappe wrote:
>> Hi Simon,
>>
>>  > I would have expect a permission error instead of a "read-only" one=
=2E It
>>  > looks as if /var/log was not properly added to be ReadWritePaths se=
t.
>>
>> That is what I have used:
>>  > ReadWritePaths=3D/var/lib/nsd /var/log /etc/nsd /run
>=20
> Not sure what would explain the read-only error then. I'd double check
> if it's indeed effective with "systemctl show nsd | grep ReadWritePaths=
"
>=20
>>  > This unlink failure is expected and AFAICT harmless.
>> It should be harmless, but it doesn't look nice. I would consider this=
 as a bug.
>=20
> Agreed. Interestingly, unbound accepts "-p" to skip managing its own
> PID. If nsd could get this, it would be handy when managing the daemon
> with systemd.

When trying to add the option for you, I saw the code should accept -P
"" on the commandline or pidfile: "" in nsd.conf omits creation of the
pidfile.

It should already work!  I could still create a convenience option or
perhaps a description for it?  Perhaps in nsd's usage printout something
to say that '-P "" stop creation of the pidfile' or something along
those lines.  If this also works, of course.

Best regards, Wouter

>=20
>>  > I believe that xfrd.state should be owned by nsd:nsd as the daemon =
needs
>>  > to write to that file.
>> After changing the owner to nsd:nsd I believe this problem is fixed. T=
hanks!
>=20
> Glad to hear that!
>=20
> Regards,
> Simon
> _______________________________________________
> nsd-users mailing list
> [email protected]
> https://open.nlnetlabs.nl/mailman/listinfo/nsd-users
>=20


--aBLkYMk9BUqhaTiPNuHP3KR1PiW2a41ow--

--7kqLTRm0cg5cTjQ508tZ3XeitUxeog1ZO
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIyBAEBCAAdFiEE7fqj8spObrBWga+On28cLX4EX40FAl3k17sACgkQn28cLX4E
X42yVA/3SKbvKvb+ACIYQTM7T49Ee8MHDIvWbHsvqOsHbby4TnGuRTFQSFqeVVQY
9hWVceu9oGh+BTiNHVQtWEmEu3mGENjMJJKILff6eVRGySxp+EB3UiR0EsTUfO9a
Ljw5T+TeHGjzaIxPVor7KheyUbUp53rEzu1racHurJa57AV1rI3ScH3NmlBooECw
udz4/INaleY8h+WcT/LfhwQdAxIerv71QkSVnktQ5By+J68GalqGDkfk0xrhVZBC
mk+aH9AEZ5cueWBAxZRZaEc1TvMO5xdOkMS2YpvViGN2K/dip+Q2aCWBLevomJqk
xRUoI7x3LKdWBASiUkUJgnIzWIHi3STFuEEDdizrDGjGsBVDjZP95X1HUMqXCnE+
Dpe+xkdSCW790DUex8i+c+AjBYmW9L0YdUfWG0qugcLD4Ccf/G5YbniuqHjJO39Z
T4XPR0ptVBAwk0NbNLUVxEEfZXvGZLrpxxNZvizLQM3WEXI03buHR+L/jZenfQ5B
YQksqlpW+uZ3n2lKFi227glLRyXXsstFDfPJM42UQBFXGhOScHOEohq1DP/dZ++k
BhU0Gvh/MOkjdTlqH7DXAk6fgpFPoifnQtMrz+IdkEEiUBjcvENytCi6vO/buvA6
SKhOvVmyX4SfwucddOJXhfW+8ac9z4iVext2EIceIHyXYsy5cw==
=gWPO
-----END PGP SIGNATURE-----

--7kqLTRm0cg5cTjQ508tZ3XeitUxeog1ZO--

--===============2372171604871467782==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
nsd-users mailing list
[email protected]
https://open.nlnetlabs.nl/mailman/listinfo/nsd-users

--===============2372171604871467782==--