#1064452 dkim-rotate: Errors during --new leave state corrupted

Package:
dkim-rotate
Source:
dkim-rotate
Submitter:
Daniel Gröber
Date:
2024-02-25 02:39:03 UTC
Severity:
normal
Tags:
#1064452#5
Date:
2024-02-22 11:01:19 UTC
From:
To:
Hi Ian,

I'm trying to get started with dkim-rotate, but I hit an error during
initial provisioning with --new. I use knot for auth DNS so I don't
have the rndc, hence I tried to override dns_reload in the config.

The example config at /usr/share/doc/dkim-rotate/examples/example.zone has

    ;! mta_group -

so I copied that syntax for the dns_reload directive but it was
ineffective. Looking at the docs/code I figured out the prefix is
supposed to be just an exclamation mark. Honestly this is not very
intuitive because 1) the example config has it and 2) the SERIAL
directive also uses ';!'.

Example understandability aside with the broken config the resulting
error left the state file corrupted. Running --new (without rndc
installed) I get:

    $ dkim-rotate --new dkim
    dkim                  -  +X    reveal?      no key
    dkim                  -  +N    deadvertise? no key
    dkim                  -  -1    advance/use? no key
    dkim                  l     -1 generated.
    sh: 1: rndc: not found
    dkim-rotate: instance dkim: error: subprocess (DNS reload (rndc reload >/dev/null)) failed, exit status 127

Subsequent calls (say --status or --reinstall) will throw a state
corrupted errors:

    $ sudo dkim-rotate --status dkim
    dkim-rotate: instance dkim: error: state corrupted! /var/lib/dkim-rotate/dkim/state:5: bad key line

Looking at the state file the problem seems to be the 'DNS,MTA' bit in
the key line which isn't handled by read_config:

    sel_offset 11
    sel_limit 12
    last_serial 2
    status -1
    key l DNS,MTA 797b760fd46ee2e01eb6c959ff3060af v=DKIM1; h=sha256; s=email; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwxzPdpwjhd+tnMooAWxEYAhVKPI2qHKGRwXpwfSEdaijUPKchNpM79HVB1+FKDmSlFR6w30qbPAdyzl4m/+Txzmv2J/So3jJbqmlSFfN85zXJ3uIdgfePWkHWTP2DAEYDeOsc3nbDNVDHQeoJHQrVyN5tBXQ/eaNTrg6qBzE5Qc1nC+Cd0LE4T9vd9PwZSSoRhYH2yprsEtLVvI+zSDqtDbx3QWAMUvDIILiWi5J/46Qw3/hI04gAFpimSoL9YVmkCNWr+arTA4g5jZatahlzkOOmNnMXZdgSRxVByAp5RtQr8EVEG0jV31re3cgXVwJnqvcJvJzDCzS6+caGjYmpQIDAQAB
    status +0
    status +N
    status +X

Seems a bit of a usability problem for new users. I'd recommend not
commenting out directives in the example config without an
explaination and handling the intermediate DNS,MTA key state properly
even outside of key generation.

Thanks,
--Daniel

#1064452#10
Date:
2024-02-24 14:16:46 UTC
From:
To:
Daniel Gröber writes ("Bug#1064452: dkim-rotate: Errors during --new leave state corrupted"):

Thanks for the report.  I'm sorry it didn't work as expected.

I have reproduced this and will fix it.  I agree that this is a
serious bug and I will try to get it fixed in a stable update.

I'm afraid I don't have a clear workaround for you right now but I
will send you one as soon as I do.

Yes.  I may change the syntax too to remove the `;` from the SERIAL,
but that's not entirely trivial since I would want it to be backward
compatible.

Ian.

#1064452#17
Date:
2024-02-24 14:39:33 UTC
From:
To:
Hi Ian,

After fixing the config it does go through successfully so no workaround is
really needed. I just had to wipe the state first.

I don't think it's entirely necessary to do that. Just have to take care to
provide new users with an example that doesn't have this ambiguity. FYI:
You might also want to include an example config in the .7 manpage. I found
having to dig through the Debian package to find one a bit inconvenient ;)

Thanks,
--Daniel

#1064452#22
Date:
2024-02-24 18:49:14 UTC
From:
To:
Daniel Gröber writes ("Bug#1064452: dkim-rotate: Errors during --new leave state corrupted"):

I'm adding a note next ot the directive that invites the user to
uncomment it, which I hope will help.

I'll add a cross-reference to the example files in the SEE ALSO.

Ian.

#1064452#27
Date:
2024-02-25 02:34:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
dkim-rotate, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1064452@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ian Jackson <ijackson@chiark.greenend.org.uk> (supplier of updated dkim-rotate package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 25 Feb 2024 01:32:47 +0000
Source: dkim-rotate
Architecture: source
Version: 1.1
Distribution: unstable
Urgency: medium
Maintainer: Ian Jackson <ijackson@chiark.greenend.org.uk>
Changed-By: Ian Jackson <ijackson@chiark.greenend.org.uk>
Closes: 1064452
Changes:
 dkim-rotate (1.1) unstable; urgency=medium
 .
   Important bugfix:
   * Fix reload failure handling with multiple reload-neededs.
     Closes: #1064452.  [Report from Daniel Gröber]
 .
   Documentation etc.:
   * Correct spelling mistakes in docs etc.  [MR !1 from Edward Betts]
   * example.zone: Clarify commented directive.  [Report from Daniel Gröber]
   * dkim-rotate(5): Add a SEE ALSO referencing the example config.
   * debian/control: Improve description.
 .
   Tests:
   * tests: Test spurious "corrupted state" bug #1064452.
Checksums-Sha1:
 67ff90ec795de3b7d54837b7f4d1e8ca3796d09d 1327 dkim-rotate_1.1.dsc
 5a6e7e5f84b620ea41e701116232698f9609aac5 25220 dkim-rotate_1.1.tar.xz
Checksums-Sha256:
 15d0a4f73a4878ba000b232f1692a35373ef787b55acc2d7cd1a5e0d3197f4b5 1327 dkim-rotate_1.1.dsc
 8e2be2aa1270644588bc7e5454beb998345d8903e1607316105f51370d0b62d0 25220 dkim-rotate_1.1.tar.xz
Files:
 7f3523f339a8d4756c219da58be9c323 1327 mail optional dkim-rotate_1.1.dsc
 7ffee823a8431f3dce7e15419bb82387 25220 mail optional dkim-rotate_1.1.tar.xz
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEVZrkbC1rbTJl58uh4+M5I0i1DTkFAmXaolcACgkQ4+M5I0i1
DTnftAf+J2af+FPufzkhtdMvNa/TCFeUF4WHrd7sK2bO5Vpf4tHM2T62ZSo5Vf82
EPaC0HSEvp5tl5w+33abZD5x3a3xpJd+4mIf75zYf5d0XPyJmkkwhMKUQ/UwT1yg
yxXxfLw7Nn+Wbo16yoO2P/MliAlks/YlG0zERGTJJDWLwfehHeLT6+WvhDlUu5mO
lwPKsyaVuhnC7FXskecMAGG/9Ff6zxhVhhNy6f3dO+ZkcisKl2XFPYviTWDrsQLU
mEJI9cpf7ufbuT6WjJrw8ZZ9pFEx05/i6AJNcM7vMIj/txnpfhDpQ1EmcAr+ZV5T
Qc4fApHYaHmef7NuLW8Rrkme3jNnQA==
=q+Yk
-----END PGP SIGNATURE-----