only start the resolver if tproxy mode #2715
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Nest the resolver, a privileged listener, under tproxy mode. That way, the router process doesn't spew errors about lacking permission to bind privileged port 53 unless it's actually necessary to listen for DNS queries on the specified resolver address in the tunnel binding options. This change reflects the earlier modifications to the non-RDM xgress router tunneler interface in #2483 .