Repository navigation
[DNSCrypt] systemd sockets disabled and dnscrypt-proxy-resolvconf file. #1394
Description
Activity
- ghost changed the title
[-][DNSCrypt] systemd sockets and `dnscrypt-proxy-resolvconf` file.[/-][+][DNSCrypt] systemd sockets disabled and `dnscrypt-proxy-resolvconf` file.[/+]on Jul 1, 2020 These files do not exist in the official releases of dnscrypt-proxy, so you'll probably find better luck asking the maintainer of the package you're using or their package-specific support channel. For what it's worth, I use
dnscrypt-proxy.socketwithoutdnscrypt-proxy-resolvconf.servicebecause I don't use resolvconf.Using GitHub's search function, it appears these files are mentioned on the systemd wiki page which suggests they might come from Arch. I don't run dnscrypt-proxy on an Arch-based system and I built my own custom package, so there's probably some minor differences.
Assuming your package contains the same contents as shown on the wiki, it looks like it relies on
dnscrypt-proxy.socketto dynamically add a resolvconf entry. If you're not using systemd sockets then I don't thinkdnscrypt-proxy-resolvconf.servicewill work properly. You might need to manually add a resolvconf entry for the listening address you configured.I'm just looking at what it does based on what's shown in the systemd page of the wiki here. It runs
systemctl show dnscrypt-proxy.socketto discover the listening address, so if you've manually configured a different listening address it won't know that.As I said, I don't use the resolvconf program so I don't use
dnscrypt-proxy-resolvconf.serviceeither - I was relying on you to know if you use resolvconf. If you rely on resolvconf and don't want to usednscrypt-proxy.socketthen you probably have to set it up yourself. If everything is working fine then you probably aren't using resolvconf.I'm not sure how else to explain it. No, you shouldn't use
dnscrypt-proxy-resolvconf.servicewhendnscrypt-proxy.socketis disabled becausednscrypt-proxy-resolvconf.serviceexplicitly makes use ofdnscrypt-proxy.socket.According to the
resolvconf(8)documentation I've read,lo.dnscrypt-proxyis simply a name for the resolvconf record. In this case it is being generated usingsystemctl show dnscrypt-proxy.socket.If you disable
dnscrypt-proxy.socketand still want to use resolvconf, you should disablednscrypt-proxy-resolvconf.serviceand generate your ownlo.dnscrypt-proxyrecord from the listening address you defined indnscrypt-proxy.toml.If you don't use resolvconf then none of this matters.
I think, that we just misunderstand each other. Well, things happen ;- )
I had the same concern, but it looks like your concerns are resolved now.
Yes, you're right "dnscrypt-proxy-resolvconf.service explicitly makes use of dnscrypt-proxy.socket" but when all options related to systemd sockets -
After/Require/Alsoare commented, thendnscrypt-proxy-resolvconf.servicecan still be used, even when systemd sockets are disabled. DNSCrypt just works normally etc.By "explicitly" I was really referring to the
systemctl show dnscrypt-proxy.socketpart. I believe this will still return an answer whendnscrypt-proxy.socketis disabled, it just won't necessarily agree with your running configuration. It will appear to work when in fact it is not doing what you would want. Hence my advice to disable it when disabling the sockets and configure resolvconf manually.- locked and limited conversation to collaborators
on Aug 1, 2020
Hello.
First, the most important thing: I want to thank Mr Frank Denis (and other Developers) for creating such an amazing and important application. Without your works, DNS privacy could depend only on two solutions explored by, amongst others, the IETF.
I have a question about the DNSCrypt with systemd sockets disabled and
dnscrypt-proxy-resolvconf.servicefile. Is this file needed or can it be disabled along withdnscrypt-proxy.socketfile? I'm asking because it seems, that this is file is not needed. DNSCrypt works okay and there are such an informations in Status:[NOTICE] Now listening to 127.0.2.1:53 [UDP][NOTICE] Now listening to 127.0.2.1:53 [TCP]Because
dnscrypt-proxy-resolvconf.servicefile is used to gather a nameserver IP address (videExecStart{,Stop}options) from thednscrypt-proxy.socketfile and this address is already added, defined indnscrypt-proxy.tomlfile (vialisten_addressesoption), it seems thatdnscrypt-proxy-resolvconf.servicefile is not needed. Am I right?Or maybe it's opposite and this file is needed because of
lo.dnscrypt-proxy? (dnscrypt-proxy-resolvconf.servicefile, contains/sbin/resolvconfcommand, used twice with-aand-doptions etc.) There are such possibilities:dnscrypt-proxy.serviceanddnscrypt-proxy-resolvconf.servicefile.dnscrypt-proxy.serviceonly and disablednscrypt-proxy-resolvconf.servicefile (what aboutlo.dnscrypt-proxy? Is it important, necessary?)So, what should be done with
dnscrypt-proxy-resolvconf.servicefile? In case when systemd sockets are disabled, of course.Sorry, for such a long message.
Best regards.