You are not logged in.

#1 2008-07-03 08:44:59

silvik
Member
From: Bucharest/Romania
Registered: 2006-11-08
Posts: 110

dnsmasq and capabilities

Hi,

I use to run dnsmasq as user and group dns:dns. Until the last dnsmasq upgrade everything was ok, but now I have in my log files this message:

Jul  3 11:25:14 morgana dnsmasq[17520]: started, version 2.42 cachesize 512
Jul  3 11:25:14 morgana dnsmasq[17520]: compile time options: IPv6 GNU-getopt no-ISC-leasefile no-DBus no-I18N TFTP
Jul  3 11:25:14 morgana dnsmasq[17520]: DHCP, IP range 192.168.1.200 -- 192.168.1.210, lease time 2h
Jul  3 11:25:14 morgana dnsmasq[17520]: warning: setting capabilities failed: Operation not permitted
Jul  3 11:25:14 morgana dnsmasq[17520]: running as root
Jul  3 11:25:14 morgana dnsmasq[17520]: reading /etc/resolv.conf.dnsmasq
Jul  3 11:25:14 morgana dnsmasq[17520]: using nameserver .... etc

and of course the process is running as root. It gets the job done, but I don't like running unnecesary root processes, especially network stuff.

Looks like that's a capabilities problem, but the dnsmasq CHANGELOG says:

version 2.42
[...]
        Support new capability interface on suitable Linux 
        kernels, removes "legacy support in use" messages. Thanks 
            to Jorge Bastos for pointing this out. 
[...]

they say the capabilities problems were solved.

so maybe it's a kernel related problem? or a dnsmasq bug? (I'm using the normal i686 Arch kernel)

thanks,
Silvian

Last edited by silvik (2008-07-03 08:59:48)

Offline

Board footer

Powered by FluxBB