mirror of
https://github.com/pfsense/pfsense.git
synced 2025-10-26 11:38:35 +00:00
Check unbound root.key file contents, and remove it if invalid, before unbound-anchor runs otherwise it will fail and unbound will fail to start. fsync the file after writing to prevent the problem. Ticket #5334
This commit is contained in:
parent
f3ee8205e6
commit
d7f5b68ab3
@ -450,7 +450,16 @@ function do_as_unbound_user($cmd) {
|
||||
mwexec("echo '/usr/local/sbin/unbound-control reload' | /usr/bin/su -m unbound", true);
|
||||
break;
|
||||
case "unbound-anchor":
|
||||
// sanity check root.key because unbound-anchor will fail without manual removal otherwise. redmine #5334
|
||||
if (file_exists("{$g['unbound_chroot_path']}/root.key")) {
|
||||
$rootkeycheck = mwexec("/usr/bin/grep 'autotrust trust anchor file' {$g['unbound_chroot_path']}/root.key", true);
|
||||
if ($rootkeycheck != "0") {
|
||||
log_error("Unbound root.key file is corrupt, removing and recreating.");
|
||||
unlink_if_exists("{$g['unbound_chroot_path']}/root.key");
|
||||
}
|
||||
}
|
||||
mwexec("echo '/usr/local/sbin/unbound-anchor -a {$g['unbound_chroot_path']}/root.key' | /usr/bin/su -m unbound", true);
|
||||
pfSense_fsync("{$g['unbound_chroot_path']}/root.key");
|
||||
break;
|
||||
case "unbound-control-setup":
|
||||
mwexec("echo '/usr/local/sbin/unbound-control-setup -d {$g['unbound_chroot_path']}' | /usr/bin/su -m unbound", true);
|
||||
|
||||
Loading…
Reference in New Issue
Block a user