netblue30 / fdns

Firejail DNS-over-HTTPS Proxy Server
GNU General Public License v3.0
125 stars 30 forks source link

fdns resolver processes getting killed by seccomp - syscall 230 (clock_nanosleep) #37

Closed glitsj16 closed 4 years ago

glitsj16 commented 4 years ago

Issue noticed today on Arch with fdns from git master. I guess this is due to the recently upgraded openssl package.

Testing server appliedprivacy
    SSL connection opened in 165.52 ms
    DoH response average 29.41 ms
fdns starting
connecting to appliedprivacy server
    non-profit, Austria, Europe
listening on all available interfaces
342 filter entries added from /etc/fdns/trackers
5277 filter entries added from /etc/fdns/fp-trackers
51399 filter entries added from /etc/fdns/adblocker
12604 filter entries added from /etc/fdns/coinblocker
90 filter entries added from /etc/fdns/doh
1577 filter entries added from /etc/fdns/hosts
(0) SSL connection opened
(2) SSL connection opened
(1) SSL connection opened
Error: fdns resolver process 1 killed by seccomp - syscall 230 (clock_nanosleep)
zx2c4.com, encrypted
(1) Error: fdns resolver process 1 killed by seccomp - syscall 230 (clock_nanosleep)
Error: resolver 1 (pid 365882) terminated, restarting it...
(1) SSL connection opened
Error: fdns resolver process 1 killed by seccomp - syscall 230 (clock_nanosleep)
zx2c4.com, encrypted
(1) Error: fdns resolver process 1 killed by seccomp - syscall 230 (clock_nanosleep)
Error: fdns resolver process 2 killed by seccomp - syscall 230 (clock_nanosleep)
zx2c4.com, encrypted
(2) Error: fdns resolver process 2 killed by seccomp - syscall 230 (clock_nanosleep)
Error: resolver 1 (pid 366801) terminated, restarting it...
Error: resolver 2 (pid 365883) terminated, restarting it...
(1) SSL connection opened
(2) SSL connection opened
Error: fdns resolver process 1 killed by seccomp - syscall 230 (clock_nanosleep)
zx2c4.com, encrypted
(1) Error: fdns resolver process 1 killed by seccomp - syscall 230 (clock_nanosleep)
Error: resolver 1 (pid 366840) terminated, restarting it...
(1) SSL connection opened
signal 15 caught, shutting down all resolvers
tag index 1

I'll make a PR to add clock_nanosleep to etc/resolvers.seccomp.