Skip to content

v1.6.0 - DNS Privilege Dropping

Choose a tag to compare

@33xception 33xception released this 25 Apr 17:53
· 17 commits to master since this release

🔐 DNS Privilege Dropping

The DNS server can now drop root privileges after binding to the listen port, matching the behaviour already present in the DHCP server. This reduces the attack surface in production deployments.


✨ Added

  • DNS privilege dropping – new [security] configuration options: dns_privilege_drop_user, dns_privilege_drop_group, and dns_chroot_dir. After binding the UDP/TCP listeners, the server switches to the specified user and group (and optionally chroots). Disabled by default (empty values).
    Hot‑reloading via SIGHUP is not affected, as the listen address/port is unchanged.
  • New tests – 5 unit tests verify the privilege‑dropping helper logic (non‑root skip, successful drop, default group, error handling).

🛠️ Changed

  • run_server() in core/dserver.py now calls _drop_dns_privileges() after both listeners are created.
  • Configuration template (config/phantomd.conf) updated with commented‑out examples for the new privilege‑drop settings.

📦 Upgrading

  • Update: ./installer.sh --update then systemctl restart phantomd
  • Fresh install: ./installer.sh

Full Changelog: v1.5.0...v1.6.0