Skip to content

Import primary data on DNSSEC primaries; add DATA_DROP_IMPORT (0.6.5) - #17

Merged
alexy merged 2 commits into
masterfrom
fix/import-data-dnssec
Sep 13, 2026
Merged

alexy merged 2 commits into
masterfrom
fix/import-data-dnssec

Conversation

@alexy

@alexy alexy commented Sep 12, 2026

Copy link
Copy Markdown
Member

Problem

rgbdns-data-import.service fails with status 1 and no message on every upload to a DNSSEC primary. On the cron.sh primary it has failed on every deploy since DNSSEC was enabled on 2026-08-19.

import-data copies the upload into an empty stage and runs compile-zone there. With /etc/rgbdns/dnssec.env present, compile-zone does not compile. It only verifies the already published signed data.cdb, starting with test -r data.cdb, and the stage has none. set -eu ends the run silently. compile-zone gained its DNSSEC branch in ca8f134 on 2026-08-18. import-data has not changed since 2026-08-02.

Fix

  • DNSSEC primary. import-data validates the upload with the plain tinydns-data compiler in the stage, replaces only data, and leaves data.cdb to rgbdns-dnssec-publish.service. The unit already starts that service in ExecStartPost, and it signs, verifies and publishes. An unsigned database is never served. compile-zone is not used for uploads in this mode.
  • Unsigned primary. Unchanged.

Flag

DATA_DROP_IMPORT=disabled in /etc/rgbdns/data-drop.env turns the import off, for primaries whose data is deployed straight into /var/lib/rgbdns/tinydns, as the cron.sh CI deploy does. rgbdns-setup primary --data-drop-import disabled writes it. The unit checks it with ExecCondition=/usr/lib/rgbdns/import-data --check-enabled. That exits 1 to skip the run, which is not a failure, and 255 for an invalid value, which is. A direct run while disabled exits 0 and changes nothing.

Tests

packaging/tests/test-import-data.sh now covers:

  • DNSSEC path. compile-zone is never called. The source is replaced and the signed CDB is untouched. Invalid uploads are rejected. No stage is left behind.
  • Flag. All four values: empty, enabled, disabled and invalid. Also a disabled direct run.
  • Hermetic. The test no longer reads the host's /etc/rgbdns.

It passes locally. The Debian and RPM build workflows run it.

Version 0.6.5: changelog entries in CHANGELOG.md, debian/changelog and the spec. Every other change is a version string.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Qr8nqvR6NP8Bi6vjdKFRM4

alexy and others added 2 commits September 12, 2026 23:56
rgbdns-data-import failed silently (status 1, no message) on every upload
to a DNSSEC primary: import-data stages only the uploaded data and runs
compile-zone there, but with /etc/rgbdns/dnssec.env present compile-zone
only verifies the already published signed data.cdb, which the stage does
not contain, so `test -r data.cdb` ended the run.

On a DNSSEC primary import-data now validates the upload with the plain
tinydns-data compiler in the stage, replaces only data, and leaves
data.cdb to rgbdns-dnssec-publish.service (already started by the unit's
ExecStartPost), which signs, verifies and publishes it. An unsigned
database is never served. Unsigned primaries are unchanged.

DATA_DROP_IMPORT=disabled in /etc/rgbdns/data-drop.env (rgbdns-setup
--data-drop-import disabled) turns the import off for primaries whose data
is deployed into the state directory by other means. The unit checks it
with ExecCondition=, so a disabled run is skipped, not failed.

test-import-data covers the DNSSEC path (compile-zone never used, signed
CDB untouched, invalid uploads rejected, stage removed) and the flag, and
no longer depends on the host's /etc/rgbdns.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qr8nqvR6NP8Bi6vjdKFRM4
The openSUSE Leap build container has no findutils, so the new stage
check failed with 'find: command not found'.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qr8nqvR6NP8Bi6vjdKFRM4
@alexy
alexy merged commit a12465d into master Sep 13, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant