Check unbound root.key file contents, and remove it if invalid, before unbound-anchor runs otherwise it will fail and unbound will fail to start. fsync the file after writing to prevent the problem. Ticket #5334

This commit is contained in:
Chris Buechler 2015-10-21 19:54:10 -05:00
parent f3ee8205e6
commit d7f5b68ab3

View File

@ -450,7 +450,16 @@ function do_as_unbound_user($cmd) {
mwexec("echo '/usr/local/sbin/unbound-control reload' | /usr/bin/su -m unbound", true);
break;
case "unbound-anchor":
// sanity check root.key because unbound-anchor will fail without manual removal otherwise. redmine #5334
if (file_exists("{$g['unbound_chroot_path']}/root.key")) {
$rootkeycheck = mwexec("/usr/bin/grep 'autotrust trust anchor file' {$g['unbound_chroot_path']}/root.key", true);
if ($rootkeycheck != "0") {
log_error("Unbound root.key file is corrupt, removing and recreating.");
unlink_if_exists("{$g['unbound_chroot_path']}/root.key");
}
}
mwexec("echo '/usr/local/sbin/unbound-anchor -a {$g['unbound_chroot_path']}/root.key' | /usr/bin/su -m unbound", true);
pfSense_fsync("{$g['unbound_chroot_path']}/root.key");
break;
case "unbound-control-setup":
mwexec("echo '/usr/local/sbin/unbound-control-setup -d {$g['unbound_chroot_path']}' | /usr/bin/su -m unbound", true);