- Package:
- kea-common
- Source:
- kea-common
- Description:
- Common libraries for the Kea DHCP server
- Submitter:
- Aka Sikrom
- Date:
- 2026-08-17 18:23:02 UTC
- Severity:
- normal
Dear Maintainer, After upgrading kea-common to 3.0.3-2, directory /etc/kea is forced to mode 0750 via /usr/lib/tmpfiles.d/kea-common.conf. Due to the nature of systemd-tmpfiles, if the system admin tries to set /etc/kea to another mode like 0755, they will find after the next boot that their chmod has been quietly reverted. In practice, this means you now need to become root or _kea just to *read* your own, local, system-specific Kea config(s). Admins can work around this by, for example: (1) symlinking /etc/tmpfiles.d/kea-common.conf to /dev/null, (2) creating /etc/tmpfiles.d/kea-common.conf as a regular file and force the particular mode you want, (3) adding your regular user account as a member of the _kea system group (probably a no-no), (4) overriding kea-dhcp*-server.service to start Kea with '-c /custom/location/kea.conf' (prone to failure on future dist-upgrades), or (5) dpkg-diverting /usr/lib/tmpfiles.d/kea-common.conf. According to the commit [1] where this behaviour was implemented, the intention was to facilitate "factory resetting a system and recreating /etc/ on boot". Since /etc has not been deleted in my case, and I am not performing a factory reset, it seems like forcing a mode and owner to an *existing* directory within /etc could potentially be unintentional. On the other hand, if this change in Debian-specific behaviour for Kea *is* intentional, may I ask what the justification is for undermining the purpose of the system-specific config area that is /etc on every (regular, non-factory-resetting) boot? Also, I thought the purpose of systemd-tmpfiles was to manage temporary/volatile files, not permanent config files. Have I misunderstood something there? Shipping with 0750 as default mode is one thing. But, as a system admin, I should be able to adjust that default mode according to my own workflow and preferences, without having to also negate systemd-tmpfiles just to make my mode change on *my* local system-specific config directory stick. For my particular use case, I would very much like to avoid having to run my DHCP compliance- and sanity-checking scripts as root, or as the _kea user for that matter, since both have write permissions which my scripts do not need and which they definitely should not have. If this change sticks in Forky, I will likely apply one of the former mentioned workarounds by the time Forky reaches stable and I upgrade my Trixie-powered Kea nodes to it. I can live with that, but having to do so in the first place seems awkward, confusing and annoying. Thanks for all your hard and good work. Best regards Aka Sikrom [1] https://salsa.debian.org/debian/isc-kea/-/commit/85d32fc3570bb764107f60ed0969ac28745c7022
We believe that the bug you reported is fixed in the latest version of isc-kea, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1142356@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Andreas Hasenack <panlinux@gmail.com> (supplier of updated isc-kea package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Mon, 17 Aug 2026 14:27:14 -0300 Source: isc-kea Built-For-Profiles: derivative.ubuntu noudeb Architecture: source Version: 3.0.4-2 Distribution: unstable Urgency: medium Maintainer: Kea <isc-kea@packages.debian.org> Changed-By: Andreas Hasenack <panlinux@gmail.com> Closes: 1142356 1144411 Changes: isc-kea (3.0.4-2) unstable; urgency=medium . [ Paride Legovini ] * Preserve /etc/kea manually configured mode (Closes: #1142356) . [ Athos Ribeiro ] * d/tests: drop isc-dhcp-client test dependency (Closes: #1144411) Checksums-Sha1: 53d9c5a39eba4cf73b7a82c0052297ffffdda164 3203 isc-kea_3.0.4-2.dsc 6770438ac609c0afc591f60fc37ffdbab9e48d7f 44180 isc-kea_3.0.4-2.debian.tar.xz cade978e26218a33d92537439665a8ded706c942 8749 isc-kea_3.0.4-2_source.buildinfo Checksums-Sha256: 8e06c67f9dbccd7653ccaa2958f26298a68cf8a604414ed6e42da23fb0aabb7f 3203 isc-kea_3.0.4-2.dsc 0e2dd2ae7f43841531a39b16b9d4b4b28a31e65178c3df53ac491fc72af2c006 44180 isc-kea_3.0.4-2.debian.tar.xz a96f5634ee9cecdbda7cfc807e7b427d8e65b0b84c7d1eb5b0b88add5dca06a4 8749 isc-kea_3.0.4-2_source.buildinfo Files: e50dfbb3ef4dcb21a38c692bee39fb57 3203 net optional isc-kea_3.0.4-2.dsc c2e1aa6aa33e0fcf2e0af877de3afcfc 44180 net optional isc-kea_3.0.4-2.debian.tar.xz 59bc7ddae531e386d3c31c7d45d21a4c 8749 net optional isc-kea_3.0.4-2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEQ5iE5oYqQpwpDfY7AzxMonYCSDQFAmqDSAkRHGF0aG9zQGRl Ymlhbi5vcmcACgkQAzxMonYCSDRQjw//bq4C0K6TOcpnFIRCYG/AznYoqRvBlq4U CGLQYVnLZQ/lmCWwFODWGe6sdlb8SyZzKiyjU5qlEfmGnlCa6RG03W5RVpcihSW4 h4G5H0905IjsHavumQ4BjTT6MhQBtncyQ+PInatpilhSRxjMo574XqafQisRDVpN GJtMEhtCS6xEIU3atVoc/tWPVam08y2zr/xvZrpPj6Ed69BTaGxsUxIsiHXKM+sh UQhcVQ+IfHjHlMbLck8v/g+SbZJl+96GToe/NSnNNspoajXq5TiCtLysB3lqCkiw /gfBzovBu1+UtkAis6K8ZttM8IWEfpSDqJhgE0jzm0ttRPrrPVKRVpaoOITeUWqe qr+WbEwLDLiyKmZaJFbVZp3a6SNnZ5fl1vUWR0eC5q9q8OLNOuhPu16sfbpPPOoT r10MtIG4aLWx0QsoL3TRHWdJ4ZnitbAwJdZpc23vhWciYwBvlaBo9te48uXsVK+L ZPPnxMFpXpouvHSFkm2v7vQWBrX9XFApXSeQxTwoDWPfK5fugCpi7N4Dfis8qhao KZu84GjcW1caSYK6ywC8AfjJMZiuEkVilEgEcqRPK0TPOLtNo/d7Suz0xzv1UhTz tlc5rqC7GOEe08JCALF0VCwaQiOVu3DBolgYAsdTsYbFoJ8e8kayGt96wz12Qx4t 9OT3TPtldQ4= =b6Rk -----END PGP SIGNATURE-----