After upgrading to net-dns/bind-9.18.29-r2 and restarting bind, this is shown in the logs: named[10573]: couldn't mkdir '/var/run': Permission denied named[10573]: could not create /var/run/named/session.key named[10573]: failed to generate session key for dynamic DNS: permission denied This is a chrooted dns setup net-dns/bind-9.18.29-r2::gentoo was built with the following: USE="caps -dnsrps -dnstap -doc -doh -fixed-rrset -geoip -gssapi -idn (-jemalloc) -lmdb (-selinux) -static-libs -test -xml" ABI_X86="(64)" FEATURES="assume-digests binpkg-docompress binpkg-dostrip binpkg-logs binpkg-multi-instance buildpkg buildpkg-live config-protect-if-modified distlocks ebuild-locks fixlafiles ipc-sandbox merge-sync merge-wait multilib-strict network-sandbox news parallel-fetch pid-sandbox pkgdir-index-trusted preserve-libs protect-owned qa-unresolved-soname-deps sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"