- Document limitation of pidfile removal outside of chroot directory.

This commit is contained in:
Ralph Dolmans 2019-08-19 13:27:19 +02:00
parent d3b3d64ef3
commit 8b752e359e
2 changed files with 6 additions and 1 deletions

View file

@ -1,3 +1,6 @@
19 August 2019: Ralph
- Document limitation of pidfile removal outside of chroot directory.
16 August 2019: Wouter
- Fix unittest valgrind false positive uninitialised value report,
where if gcc 9.1.1 uses -O2 (but not -O1) then valgrind 3.15.0

View file

@ -629,7 +629,9 @@ In the last case the path is adjusted to remove the unused portion.
The pidfile can be either a relative path to the working directory, or
an absolute path relative to the original root. It is written just prior
to chroot and dropping permissions. This allows the pidfile to be
/var/run/unbound.pid and the chroot to be /var/unbound, for example.
/var/run/unbound.pid and the chroot to be /var/unbound, for example. Note that
Unbound is not able to remove the pidfile after termination when it is located
outside of the chroot directory.
.IP
Additionally, unbound may need to access /dev/random (for entropy)
from inside the chroot.