From owner-freebsd-questions@freebsd.org Fri Dec 28 15:39:44 2018 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 187E4143BE13 for ; Fri, 28 Dec 2018 15:39:44 +0000 (UTC) (envelope-from starikarp@yandex.com) Received: from forward102j.mail.yandex.net (forward102j.mail.yandex.net [IPv6:2a02:6b8:0:801:2::102]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 6CB858F032 for ; Fri, 28 Dec 2018 15:39:42 +0000 (UTC) (envelope-from starikarp@yandex.com) Received: from mxback10o.mail.yandex.net (mxback10o.mail.yandex.net [IPv6:2a02:6b8:0:1a2d::24]) by forward102j.mail.yandex.net (Yandex) with ESMTP id 4F3CC1E80C17; Fri, 28 Dec 2018 18:39:38 +0300 (MSK) Received: from smtp3o.mail.yandex.net (smtp3o.mail.yandex.net [2a02:6b8:0:1a2d::27]) by mxback10o.mail.yandex.net (nwsmtp/Yandex) with ESMTP id 8wQmWPMBHp-dcGG9etC; Fri, 28 Dec 2018 18:39:38 +0300 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yandex.com; s=mail; t=1546011578; bh=NApXmILRZsgHLLVXWtJyR3LDuEl65DKnDnkwkF0JfnM=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References; b=nAgTnUkf1Aydk6P34obnUF9MqDMlpkLJqNHidzh8vtF/VmiZ0nW5pdOyqUP6Qzeul 00TYXkhyXqDg1o+IYvJHuN2Eppu9Hitdoy/EAHRcUh9t7qEfKcwhde9SZ60WyZ1uY/ UfjLjYEes5vfEcQeXp6QWFiuLScM+7nV6smTiCLM= Received: by smtp3o.mail.yandex.net (nwsmtp/Yandex) with ESMTPSA id Z6wC8TKSUx-dagSf7pf; Fri, 28 Dec 2018 18:39:37 +0300 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client certificate not present) Date: Fri, 28 Dec 2018 10:39:34 -0500 From: To: "James B. Byrne via freebsd-questions" Cc: byrnejb@harte-lyne.ca Subject: Re: /etc/resolv.conf overwritten by what? Message-ID: <20181228103934.1e3dd752@yandex.com> In-Reply-To: <961dc39c14de8d519801ca9fe3b2cdd9.squirrel@webmail.harte-lyne.ca> References: <961dc39c14de8d519801ca9fe3b2cdd9.squirrel@webmail.harte-lyne.ca> X-Mailer: Claws Mail 3.17.3 (GTK+ 2.24.32; amd64-portbld-freebsd12.0) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Queue-Id: 6CB858F032 X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=yandex.com header.s=mail header.b=nAgTnUkf; dmarc=pass (policy=none) header.from=yandex.com; spf=pass (mx1.freebsd.org: domain of starikarp@yandex.com designates 2a02:6b8:0:801:2::102 as permitted sender) smtp.mailfrom=starikarp@yandex.com X-Spamd-Result: default: False [-4.85 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; TO_DN_SOME(0.00)[]; R_SPF_ALLOW(-0.20)[+ip6:2a02:6b8:0::/52]; FREEMAIL_FROM(0.00)[yandex.com]; RCVD_COUNT_THREE(0.00)[4]; DKIM_TRACE(0.00)[yandex.com:+]; RCPT_COUNT_TWO(0.00)[2]; DMARC_POLICY_ALLOW(-0.50)[yandex.com,none]; MX_GOOD(-0.01)[mx.yandex.ru,mx.yandex.ru,mx.yandex.ru,mx.yandex.ru,mx.yandex.ru]; NEURAL_HAM_SHORT(-1.00)[-0.997,0]; FROM_EQ_ENVFROM(0.00)[]; RCVD_TLS_LAST(0.00)[]; MIME_TRACE(0.00)[0:+]; FREEMAIL_ENVFROM(0.00)[yandex.com]; ASN(0.00)[asn:13238, ipnet:2a02:6b8::/32, country:RU]; MID_RHS_MATCH_FROM(0.00)[]; RCVD_IN_DNSWL_LOW(-0.10)[2.0.1.0.0.0.0.0.0.0.0.0.2.0.0.0.1.0.8.0.0.0.0.0.8.b.6.0.2.0.a.2.list.dnswl.org : 127.0.5.1]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; R_DKIM_ALLOW(-0.20)[yandex.com:s=mail]; SUBJECT_ENDS_QUESTION(1.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; MIME_GOOD(-0.10)[text/plain]; IP_SCORE(-1.74)[ipnet: 2a02:6b8::/32(-4.84), asn: 13238(-3.88), country: RU(0.00)]; TO_MATCH_ENVRCPT_SOME(0.00)[]; FROM_NO_DN(0.00)[] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Dec 2018 15:39:44 -0000 On Fri, 28 Dec 2018 10:15:54 -0500 "James B. Byrne via freebsd-questions" wrote: > At 09:12EST this morning: > > ls -l resolv* > -rw-r--r-- 1 root wheel 46 Dec 28 09:12 resolv.conf_empty_problem > > > Something changed the contents of /etc/resolv.conf from this: > > search hamilton.harte-lyne.ca harte-lyne.ca > # nameserver ::216:33 > # nameserver ::216:34 > # nameserver 127.0.0.1 > nameserver 216.185.71.33 > nameserver 216.185.71.34 > options edns0 timeout:5 attempts:3 > > to this: > > # Generated by resolvconf > search localdomain > > Now /sbin/resolvconf says that it has not been accessed recently: > > # ls -lu /sbin/resolvconf > -r-xr-xr-x 1 root wheel 21803 Apr 3 2018 /sbin/resolvconf > > And this change was immediately noticed at ~19:13EST by people > accessing that host when all of their dns queries stopped resolving. > So, I am reasonably certain that whatever overwrote the existing file > did so at 09:12 as shown on the mtime-stamp. > > There are no crontab entries for root on this system: > > # crontab -l > crontab: no crontab for root > > I have never encountered this problem before. Has anyone any idea of > why this happened? > I have in /etc/ file dhclient-enter-hooks which has: add_new_resolv_conf() { # We don't want /etc/resolv.conf changed # So this is an empty function return 0 } and I do not have problems.