The script is run by isc-dhcp, which runs as nobody:nobody.

That means the sudo is impossible to happen and will generate a security even in the log:


This is related to this change:

As well as the other ticket about the socket.

Not really, the change to nobody:nogroup was by c-po in
The commit by me you referenced just fixed a bug that resulted from that change.

I think this should be fixed by the one that broke this, or no? I don't have the time to do any real work right now. Maybe in a week or 2.

No worries. I think I've got a simple fix for this. Just needed to step away for a bit

This PR419 should take care of this and the parent task

The above PR419 did not fix the issue as a wrong pdns-recursor process name was used (its real name is 'pdns-rec/worker'). It was fixed as part of T2486.

