Repository navigation
Import primary data on DNSSEC primaries; add DATA_DROP_IMPORT (0.6.5) - #17
Merged
Merged
Conversation
rgbdns-data-import failed silently (status 1, no message) on every upload to a DNSSEC primary: import-data stages only the uploaded data and runs compile-zone there, but with /etc/rgbdns/dnssec.env present compile-zone only verifies the already published signed data.cdb, which the stage does not contain, so `test -r data.cdb` ended the run. On a DNSSEC primary import-data now validates the upload with the plain tinydns-data compiler in the stage, replaces only data, and leaves data.cdb to rgbdns-dnssec-publish.service (already started by the unit's ExecStartPost), which signs, verifies and publishes it. An unsigned database is never served. Unsigned primaries are unchanged. DATA_DROP_IMPORT=disabled in /etc/rgbdns/data-drop.env (rgbdns-setup --data-drop-import disabled) turns the import off for primaries whose data is deployed into the state directory by other means. The unit checks it with ExecCondition=, so a disabled run is skipped, not failed. test-import-data covers the DNSSEC path (compile-zone never used, signed CDB untouched, invalid uploads rejected, stage removed) and the flag, and no longer depends on the host's /etc/rgbdns. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qr8nqvR6NP8Bi6vjdKFRM4
The openSUSE Leap build container has no findutils, so the new stage check failed with 'find: command not found'. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qr8nqvR6NP8Bi6vjdKFRM4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
rgbdns-data-import.servicefails with status 1 and no message on every upload to a DNSSEC primary. On the cron.sh primary it has failed on every deploy since DNSSEC was enabled on 2026-08-19.import-datacopies the upload into an empty stage and runscompile-zonethere. With/etc/rgbdns/dnssec.envpresent,compile-zonedoes not compile. It only verifies the already published signeddata.cdb, starting withtest -r data.cdb, and the stage has none.set -euends the run silently.compile-zonegained its DNSSEC branch in ca8f134 on 2026-08-18.import-datahas not changed since 2026-08-02.Fix
import-datavalidates the upload with the plaintinydns-datacompiler in the stage, replaces onlydata, and leavesdata.cdbtorgbdns-dnssec-publish.service. The unit already starts that service inExecStartPost, and it signs, verifies and publishes. An unsigned database is never served.compile-zoneis not used for uploads in this mode.Flag
DATA_DROP_IMPORT=disabledin/etc/rgbdns/data-drop.envturns the import off, for primaries whose data is deployed straight into/var/lib/rgbdns/tinydns, as the cron.sh CI deploy does.rgbdns-setup primary --data-drop-import disabledwrites it. The unit checks it withExecCondition=/usr/lib/rgbdns/import-data --check-enabled. That exits 1 to skip the run, which is not a failure, and 255 for an invalid value, which is. A direct run while disabled exits 0 and changes nothing.Tests
packaging/tests/test-import-data.shnow covers:compile-zoneis never called. The source is replaced and the signed CDB is untouched. Invalid uploads are rejected. No stage is left behind./etc/rgbdns.It passes locally. The Debian and RPM build workflows run it.
Version 0.6.5: changelog entries in
CHANGELOG.md,debian/changelogand the spec. Every other change is a version string.🤖 Generated with Claude Code
https://claude.ai/code/session_01Qr8nqvR6NP8Bi6vjdKFRM4