]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/resolve/resolvectl.c
varlink: introduce varlink_call_and_log() which calls and then logs an error
[thirdparty/systemd.git] / src / resolve / resolvectl.c
1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
2
3 #include <getopt.h>
4 #include <locale.h>
5 #include <net/if.h>
6
7 #include "sd-bus.h"
8 #include "sd-netlink.h"
9
10 #include "af-list.h"
11 #include "alloc-util.h"
12 #include "build.h"
13 #include "bus-common-errors.h"
14 #include "bus-error.h"
15 #include "bus-locator.h"
16 #include "bus-map-properties.h"
17 #include "bus-message-util.h"
18 #include "dns-domain.h"
19 #include "errno-list.h"
20 #include "escape.h"
21 #include "format-table.h"
22 #include "format-util.h"
23 #include "gcrypt-util.h"
24 #include "hostname-util.h"
25 #include "json.h"
26 #include "main-func.h"
27 #include "missing_network.h"
28 #include "netlink-util.h"
29 #include "openssl-util.h"
30 #include "pager.h"
31 #include "parse-argument.h"
32 #include "parse-util.h"
33 #include "pretty-print.h"
34 #include "process-util.h"
35 #include "resolvconf-compat.h"
36 #include "resolve-util.h"
37 #include "resolvectl.h"
38 #include "resolved-def.h"
39 #include "resolved-dns-packet.h"
40 #include "resolved-util.h"
41 #include "socket-netlink.h"
42 #include "sort-util.h"
43 #include "stdio-util.h"
44 #include "string-table.h"
45 #include "strv.h"
46 #include "terminal-util.h"
47 #include "utf8.h"
48 #include "varlink.h"
49 #include "verb-log-control.h"
50 #include "verbs.h"
51
52 static int arg_family = AF_UNSPEC;
53 static int arg_ifindex = 0;
54 static char *arg_ifname = NULL;
55 static uint16_t arg_type = 0;
56 static uint16_t arg_class = 0;
57 static bool arg_legend = true;
58 static uint64_t arg_flags = 0;
59 static JsonFormatFlags arg_json_format_flags = JSON_FORMAT_OFF;
60 static PagerFlags arg_pager_flags = 0;
61 bool arg_ifindex_permissive = false; /* If true, don't generate an error if the specified interface index doesn't exist */
62 static const char *arg_service_family = NULL;
63
64 typedef enum RawType {
65 RAW_NONE,
66 RAW_PAYLOAD,
67 RAW_PACKET,
68 } RawType;
69 static RawType arg_raw = RAW_NONE;
70
71 ExecutionMode arg_mode = MODE_RESOLVE_HOST;
72
73 char **arg_set_dns = NULL;
74 char **arg_set_domain = NULL;
75 static const char *arg_set_llmnr = NULL;
76 static const char *arg_set_mdns = NULL;
77 static const char *arg_set_dns_over_tls = NULL;
78 static const char *arg_set_dnssec = NULL;
79 static char **arg_set_nta = NULL;
80
81 STATIC_DESTRUCTOR_REGISTER(arg_ifname, freep);
82 STATIC_DESTRUCTOR_REGISTER(arg_set_dns, strv_freep);
83 STATIC_DESTRUCTOR_REGISTER(arg_set_domain, strv_freep);
84 STATIC_DESTRUCTOR_REGISTER(arg_set_nta, strv_freep);
85
86 typedef enum StatusMode {
87 STATUS_ALL,
88 STATUS_DNS,
89 STATUS_DOMAIN,
90 STATUS_DEFAULT_ROUTE,
91 STATUS_LLMNR,
92 STATUS_MDNS,
93 STATUS_PRIVATE,
94 STATUS_DNSSEC,
95 STATUS_NTA,
96 } StatusMode;
97
98 typedef struct InterfaceInfo {
99 int index;
100 const char *name;
101 } InterfaceInfo;
102
103 static int interface_info_compare(const InterfaceInfo *a, const InterfaceInfo *b) {
104 int r;
105
106 r = CMP(a->index, b->index);
107 if (r != 0)
108 return r;
109
110 return strcmp_ptr(a->name, b->name);
111 }
112
113 int ifname_mangle_full(const char *s, bool drop_protocol_specifier) {
114 _cleanup_(sd_netlink_unrefp) sd_netlink *rtnl = NULL;
115 _cleanup_strv_free_ char **found = NULL;
116 int r;
117
118 assert(s);
119
120 if (drop_protocol_specifier) {
121 _cleanup_free_ char *buf = NULL;
122 int ifindex_longest_name = -ENODEV;
123
124 /* When invoked as resolvconf, drop the protocol specifier(s) at the end. */
125
126 buf = strdup(s);
127 if (!buf)
128 return log_oom();
129
130 for (;;) {
131 r = rtnl_resolve_interface(&rtnl, buf);
132 if (r > 0) {
133 if (ifindex_longest_name <= 0)
134 ifindex_longest_name = r;
135
136 r = strv_extend(&found, buf);
137 if (r < 0)
138 return log_oom();
139 }
140
141 char *dot = strrchr(buf, '.');
142 if (!dot)
143 break;
144
145 *dot = '\0';
146 }
147
148 unsigned n = strv_length(found);
149 if (n > 1) {
150 _cleanup_free_ char *joined = NULL;
151
152 joined = strv_join(found, ", ");
153 log_warning("Found multiple interfaces (%s) matching with '%s'. Using '%s' (ifindex=%i).",
154 strna(joined), s, found[0], ifindex_longest_name);
155
156 } else if (n == 1) {
157 const char *proto;
158
159 proto = ASSERT_PTR(startswith(s, found[0]));
160 if (!isempty(proto))
161 log_info("Dropped protocol specifier '%s' from '%s'. Using '%s' (ifindex=%i).",
162 proto, s, found[0], ifindex_longest_name);
163 }
164
165 r = ifindex_longest_name;
166 } else
167 r = rtnl_resolve_interface(&rtnl, s);
168 if (r < 0) {
169 if (ERRNO_IS_DEVICE_ABSENT(r) && arg_ifindex_permissive) {
170 log_debug_errno(r, "Interface '%s' not found, but -f specified, ignoring: %m", s);
171 return 0; /* done */
172 }
173 return log_error_errno(r, "Failed to resolve interface \"%s\": %m", s);
174 }
175
176 if (arg_ifindex > 0 && arg_ifindex != r)
177 return log_error_errno(SYNTHETIC_ERRNO(EINVAL), "Specified multiple different interfaces. Refusing.");
178
179 arg_ifindex = r;
180 return free_and_strdup_warn(&arg_ifname, found ? found[0] : s); /* found */
181 }
182
183 static void print_source(uint64_t flags, usec_t rtt) {
184 if (!arg_legend)
185 return;
186
187 if (flags == 0)
188 return;
189
190 printf("\n%s-- Information acquired via", ansi_grey());
191
192 printf(" protocol%s%s%s%s%s",
193 flags & SD_RESOLVED_DNS ? " DNS" :"",
194 flags & SD_RESOLVED_LLMNR_IPV4 ? " LLMNR/IPv4" : "",
195 flags & SD_RESOLVED_LLMNR_IPV6 ? " LLMNR/IPv6" : "",
196 flags & SD_RESOLVED_MDNS_IPV4 ? " mDNS/IPv4" : "",
197 flags & SD_RESOLVED_MDNS_IPV6 ? " mDNS/IPv6" : "");
198
199 printf(" in %s.%s\n"
200 "%s-- Data is authenticated: %s; Data was acquired via local or encrypted transport: %s%s\n",
201 FORMAT_TIMESPAN(rtt, 100),
202 ansi_normal(),
203 ansi_grey(),
204 yes_no(flags & SD_RESOLVED_AUTHENTICATED),
205 yes_no(flags & SD_RESOLVED_CONFIDENTIAL),
206 ansi_normal());
207
208 if ((flags & (SD_RESOLVED_FROM_MASK|SD_RESOLVED_SYNTHETIC)) != 0)
209 printf("%s-- Data from:%s%s%s%s%s%s\n",
210 ansi_grey(),
211 FLAGS_SET(flags, SD_RESOLVED_SYNTHETIC) ? " synthetic" : "",
212 FLAGS_SET(flags, SD_RESOLVED_FROM_CACHE) ? " cache" : "",
213 FLAGS_SET(flags, SD_RESOLVED_FROM_ZONE) ? " zone" : "",
214 FLAGS_SET(flags, SD_RESOLVED_FROM_TRUST_ANCHOR) ? " trust-anchor" : "",
215 FLAGS_SET(flags, SD_RESOLVED_FROM_NETWORK) ? " network" : "",
216 ansi_normal());
217 }
218
219 static void print_ifindex_comment(int printed_so_far, int ifindex) {
220 char ifname[IF_NAMESIZE];
221 int r;
222
223 if (ifindex <= 0)
224 return;
225
226 r = format_ifname(ifindex, ifname);
227 if (r < 0)
228 return (void) log_warning_errno(r, "Failed to resolve interface name for index %i, ignoring: %m", ifindex);
229
230 printf("%*s%s-- link: %s%s",
231 60 > printed_so_far ? 60 - printed_so_far : 0, " ", /* Align comment to the 60th column */
232 ansi_grey(), ifname, ansi_normal());
233 }
234
235 static int resolve_host_error(const char *name, int r, const sd_bus_error *error) {
236 if (sd_bus_error_has_name(error, BUS_ERROR_DNS_NXDOMAIN))
237 return log_error_errno(r, "%s: %s", name, bus_error_message(error, r));
238
239 return log_error_errno(r, "%s: resolve call failed: %s", name, bus_error_message(error, r));
240 }
241
242 static int resolve_host(sd_bus *bus, const char *name) {
243 _cleanup_(sd_bus_message_unrefp) sd_bus_message *req = NULL, *reply = NULL;
244 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
245 const char *canonical = NULL;
246 unsigned c = 0;
247 uint64_t flags;
248 usec_t ts;
249 int r;
250
251 assert(name);
252
253 log_debug("Resolving %s (family %s, interface %s).", name, af_to_name(arg_family) ?: "*", isempty(arg_ifname) ? "*" : arg_ifname);
254
255 r = bus_message_new_method_call(bus, &req, bus_resolve_mgr, "ResolveHostname");
256 if (r < 0)
257 return bus_log_create_error(r);
258
259 r = sd_bus_message_append(req, "isit", arg_ifindex, name, arg_family, arg_flags);
260 if (r < 0)
261 return bus_log_create_error(r);
262
263 ts = now(CLOCK_MONOTONIC);
264
265 r = sd_bus_call(bus, req, SD_RESOLVED_QUERY_TIMEOUT_USEC, &error, &reply);
266 if (r < 0)
267 return resolve_host_error(name, r, &error);
268
269 ts = now(CLOCK_MONOTONIC) - ts;
270
271 r = sd_bus_message_enter_container(reply, 'a', "(iiay)");
272 if (r < 0)
273 return bus_log_parse_error(r);
274
275 while ((r = sd_bus_message_enter_container(reply, 'r', "iiay")) > 0) {
276 _cleanup_free_ char *pretty = NULL;
277 int ifindex, family, k;
278 union in_addr_union a;
279
280 assert_cc(sizeof(int) == sizeof(int32_t));
281
282 r = sd_bus_message_read(reply, "i", &ifindex);
283 if (r < 0)
284 return bus_log_parse_error(r);
285
286 sd_bus_error_free(&error);
287 r = bus_message_read_in_addr_auto(reply, &error, &family, &a);
288 if (r < 0 && !sd_bus_error_has_name(&error, SD_BUS_ERROR_INVALID_ARGS))
289 return log_error_errno(r, "%s: systemd-resolved returned invalid result: %s", name, bus_error_message(&error, r));
290
291 r = sd_bus_message_exit_container(reply);
292 if (r < 0)
293 return bus_log_parse_error(r);
294
295 if (sd_bus_error_has_name(&error, SD_BUS_ERROR_INVALID_ARGS)) {
296 log_debug_errno(r, "%s: systemd-resolved returned invalid result, ignoring: %s", name, bus_error_message(&error, r));
297 continue;
298 }
299
300 r = in_addr_ifindex_to_string(family, &a, ifindex, &pretty);
301 if (r < 0)
302 return log_error_errno(r, "Failed to print address for %s: %m", name);
303
304 k = printf("%*s%s %s%s%s",
305 (int) strlen(name), c == 0 ? name : "", c == 0 ? ":" : " ",
306 ansi_highlight(), pretty, ansi_normal());
307
308 print_ifindex_comment(k, ifindex);
309 fputc('\n', stdout);
310
311 c++;
312 }
313 if (r < 0)
314 return bus_log_parse_error(r);
315
316 r = sd_bus_message_exit_container(reply);
317 if (r < 0)
318 return bus_log_parse_error(r);
319
320 r = sd_bus_message_read(reply, "st", &canonical, &flags);
321 if (r < 0)
322 return bus_log_parse_error(r);
323
324 if (!streq(name, canonical))
325 printf("%*s%s (%s)\n",
326 (int) strlen(name), c == 0 ? name : "", c == 0 ? ":" : " ",
327 canonical);
328
329 if (c == 0)
330 return log_error_errno(SYNTHETIC_ERRNO(ESRCH),
331 "%s: no addresses found", name);
332
333 print_source(flags, ts);
334
335 return 0;
336 }
337
338 static int resolve_address(sd_bus *bus, int family, const union in_addr_union *address, int ifindex) {
339 _cleanup_(sd_bus_message_unrefp) sd_bus_message *req = NULL, *reply = NULL;
340 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
341 _cleanup_free_ char *pretty = NULL;
342 uint64_t flags;
343 unsigned c = 0;
344 usec_t ts;
345 int r;
346
347 assert(bus);
348 assert(IN_SET(family, AF_INET, AF_INET6));
349 assert(address);
350
351 if (ifindex <= 0)
352 ifindex = arg_ifindex;
353
354 r = in_addr_ifindex_to_string(family, address, ifindex, &pretty);
355 if (r < 0)
356 return log_oom();
357
358 log_debug("Resolving %s.", pretty);
359
360 r = bus_message_new_method_call(bus, &req, bus_resolve_mgr, "ResolveAddress");
361 if (r < 0)
362 return bus_log_create_error(r);
363
364 r = sd_bus_message_append(req, "ii", ifindex, family);
365 if (r < 0)
366 return bus_log_create_error(r);
367
368 r = sd_bus_message_append_array(req, 'y', address, FAMILY_ADDRESS_SIZE(family));
369 if (r < 0)
370 return bus_log_create_error(r);
371
372 r = sd_bus_message_append(req, "t", arg_flags);
373 if (r < 0)
374 return bus_log_create_error(r);
375
376 ts = now(CLOCK_MONOTONIC);
377
378 r = sd_bus_call(bus, req, SD_RESOLVED_QUERY_TIMEOUT_USEC, &error, &reply);
379 if (r < 0)
380 return log_error_errno(r, "%s: resolve call failed: %s", pretty, bus_error_message(&error, r));
381
382 ts = now(CLOCK_MONOTONIC) - ts;
383
384 r = sd_bus_message_enter_container(reply, 'a', "(is)");
385 if (r < 0)
386 return bus_log_create_error(r);
387
388 while ((r = sd_bus_message_enter_container(reply, 'r', "is")) > 0) {
389 const char *n;
390 int k;
391
392 assert_cc(sizeof(int) == sizeof(int32_t));
393
394 r = sd_bus_message_read(reply, "is", &ifindex, &n);
395 if (r < 0)
396 return r;
397
398 r = sd_bus_message_exit_container(reply);
399 if (r < 0)
400 return r;
401
402 k = printf("%*s%s %s%s%s",
403 (int) strlen(pretty), c == 0 ? pretty : "",
404 c == 0 ? ":" : " ",
405 ansi_highlight(), n, ansi_normal());
406
407 print_ifindex_comment(k, ifindex);
408 fputc('\n', stdout);
409
410 c++;
411 }
412 if (r < 0)
413 return bus_log_parse_error(r);
414
415 r = sd_bus_message_exit_container(reply);
416 if (r < 0)
417 return bus_log_parse_error(r);
418
419 r = sd_bus_message_read(reply, "t", &flags);
420 if (r < 0)
421 return bus_log_parse_error(r);
422
423 if (c == 0)
424 return log_error_errno(SYNTHETIC_ERRNO(ESRCH),
425 "%s: no names found", pretty);
426
427 print_source(flags, ts);
428
429 return 0;
430 }
431
432 static int output_rr_packet(const void *d, size_t l, int ifindex) {
433 _cleanup_(dns_resource_record_unrefp) DnsResourceRecord *rr = NULL;
434 int r;
435
436 r = dns_resource_record_new_from_raw(&rr, d, l);
437 if (r < 0)
438 return log_error_errno(r, "Failed to parse RR: %m");
439
440 if (arg_raw == RAW_PAYLOAD) {
441 void *data;
442 ssize_t k;
443
444 k = dns_resource_record_payload(rr, &data);
445 if (k < 0)
446 return log_error_errno(k, "Cannot dump RR: %m");
447 fwrite(data, 1, k, stdout);
448 } else {
449 const char *s;
450 int k;
451
452 s = dns_resource_record_to_string(rr);
453 if (!s)
454 return log_oom();
455
456 k = printf("%s", s);
457 print_ifindex_comment(k, ifindex);
458 fputc('\n', stdout);
459 }
460
461 return 0;
462 }
463
464 static int idna_candidate(const char *name, char **ret) {
465 _cleanup_free_ char *idnafied = NULL;
466 int r;
467
468 assert(name);
469 assert(ret);
470
471 r = dns_name_apply_idna(name, &idnafied);
472 if (r < 0)
473 return log_error_errno(r, "Failed to apply IDNA to name '%s': %m", name);
474 if (r > 0 && !streq(name, idnafied)) {
475 *ret = TAKE_PTR(idnafied);
476 return true;
477 }
478
479 *ret = NULL;
480 return false;
481 }
482
483 static bool single_label_nonsynthetic(const char *name) {
484 _cleanup_free_ char *first_label = NULL;
485 int r;
486
487 if (!dns_name_is_single_label(name))
488 return false;
489
490 if (is_localhost(name) ||
491 is_gateway_hostname(name) ||
492 is_outbound_hostname(name) ||
493 is_dns_stub_hostname(name) ||
494 is_dns_proxy_stub_hostname(name))
495 return false;
496
497 r = resolve_system_hostname(NULL, &first_label);
498 if (r < 0) {
499 log_warning_errno(r, "Failed to determine the hostname: %m");
500 return false;
501 }
502
503 return !streq(name, first_label);
504 }
505
506 static int resolve_record(sd_bus *bus, const char *name, uint16_t class, uint16_t type, bool warn_missing) {
507 _cleanup_(sd_bus_message_unrefp) sd_bus_message *req = NULL, *reply = NULL;
508 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
509 _cleanup_free_ char *idnafied = NULL;
510 bool needs_authentication = false;
511 unsigned n = 0;
512 uint64_t flags;
513 usec_t ts;
514 int r;
515
516 assert(name);
517
518 log_debug("Resolving %s %s %s (interface %s).", name, dns_class_to_string(class), dns_type_to_string(type), isempty(arg_ifname) ? "*" : arg_ifname);
519
520 if (dns_name_dot_suffixed(name) == 0 && single_label_nonsynthetic(name))
521 log_notice("(Note that search domains are not appended when --type= is specified. "
522 "Please specify fully qualified domain names, or remove --type= switch from invocation in order to request regular hostname resolution.)");
523
524 r = idna_candidate(name, &idnafied);
525 if (r < 0)
526 return r;
527 if (r > 0)
528 log_notice("(Note that IDNA translation is not applied when --type= is specified. "
529 "Please specify translated domain names — i.e. '%s' — when resolving raw records, or remove --type= switch from invocation in order to request regular hostname resolution.",
530 idnafied);
531
532 r = bus_message_new_method_call(bus, &req, bus_resolve_mgr, "ResolveRecord");
533 if (r < 0)
534 return bus_log_create_error(r);
535
536 r = sd_bus_message_append(req, "isqqt", arg_ifindex, name, class, type, arg_flags);
537 if (r < 0)
538 return bus_log_create_error(r);
539
540 ts = now(CLOCK_MONOTONIC);
541
542 r = sd_bus_call(bus, req, SD_RESOLVED_QUERY_TIMEOUT_USEC, &error, &reply);
543 if (r < 0) {
544 if (warn_missing || r != -ENXIO)
545 log_error("%s: resolve call failed: %s", name, bus_error_message(&error, r));
546 return r;
547 }
548
549 ts = now(CLOCK_MONOTONIC) - ts;
550
551 r = sd_bus_message_enter_container(reply, 'a', "(iqqay)");
552 if (r < 0)
553 return bus_log_parse_error(r);
554
555 while ((r = sd_bus_message_enter_container(reply, 'r', "iqqay")) > 0) {
556 uint16_t c, t;
557 int ifindex;
558 const void *d;
559 size_t l;
560
561 assert_cc(sizeof(int) == sizeof(int32_t));
562
563 r = sd_bus_message_read(reply, "iqq", &ifindex, &c, &t);
564 if (r < 0)
565 return bus_log_parse_error(r);
566
567 r = sd_bus_message_read_array(reply, 'y', &d, &l);
568 if (r < 0)
569 return bus_log_parse_error(r);
570
571 r = sd_bus_message_exit_container(reply);
572 if (r < 0)
573 return bus_log_parse_error(r);
574
575 if (arg_raw == RAW_PACKET) {
576 uint64_t u64 = htole64(l);
577
578 fwrite(&u64, sizeof(u64), 1, stdout);
579 fwrite(d, 1, l, stdout);
580 } else {
581 r = output_rr_packet(d, l, ifindex);
582 if (r < 0)
583 return r;
584 }
585
586 if (dns_type_needs_authentication(t))
587 needs_authentication = true;
588
589 n++;
590 }
591 if (r < 0)
592 return bus_log_parse_error(r);
593
594 r = sd_bus_message_exit_container(reply);
595 if (r < 0)
596 return bus_log_parse_error(r);
597
598 r = sd_bus_message_read(reply, "t", &flags);
599 if (r < 0)
600 return bus_log_parse_error(r);
601
602 if (n == 0) {
603 if (warn_missing)
604 log_error("%s: no records found", name);
605 return -ESRCH;
606 }
607
608 print_source(flags, ts);
609
610 if ((flags & SD_RESOLVED_AUTHENTICATED) == 0 && needs_authentication) {
611 fflush(stdout);
612
613 fprintf(stderr, "\n%s"
614 "WARNING: The resources shown contain cryptographic key data which could not be\n"
615 " authenticated. It is not suitable to authenticate any communication.\n"
616 " This is usually indication that DNSSEC authentication was not enabled\n"
617 " or is not available for the selected protocol or DNS servers.%s\n",
618 ansi_highlight_red(),
619 ansi_normal());
620 }
621
622 return 0;
623 }
624
625 static int resolve_rfc4501(sd_bus *bus, const char *name) {
626 uint16_t type = 0, class = 0;
627 const char *p, *q, *n;
628 int r;
629
630 assert(bus);
631 assert(name);
632 assert(startswith(name, "dns:"));
633
634 /* Parse RFC 4501 dns: URIs */
635
636 p = name + 4;
637
638 if (p[0] == '/') {
639 const char *e;
640
641 if (p[1] != '/')
642 goto invalid;
643
644 e = strchr(p + 2, '/');
645 if (!e)
646 goto invalid;
647
648 if (e != p + 2)
649 log_warning("DNS authority specification not supported; ignoring specified authority.");
650
651 p = e + 1;
652 }
653
654 q = strchr(p, '?');
655 if (q) {
656 n = strndupa_safe(p, q - p);
657 q++;
658
659 for (;;) {
660 const char *f;
661
662 f = startswith_no_case(q, "class=");
663 if (f) {
664 _cleanup_free_ char *t = NULL;
665 const char *e;
666
667 if (class != 0)
668 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
669 "DNS class specified twice.");
670
671 e = strchrnul(f, ';');
672 t = strndup(f, e - f);
673 if (!t)
674 return log_oom();
675
676 r = dns_class_from_string(t);
677 if (r < 0)
678 return log_error_errno(r, "Unknown DNS class %s.", t);
679
680 class = r;
681
682 if (*e == ';') {
683 q = e + 1;
684 continue;
685 }
686
687 break;
688 }
689
690 f = startswith_no_case(q, "type=");
691 if (f) {
692 _cleanup_free_ char *t = NULL;
693 const char *e;
694
695 if (type != 0)
696 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
697 "DNS type specified twice.");
698
699 e = strchrnul(f, ';');
700 t = strndup(f, e - f);
701 if (!t)
702 return log_oom();
703
704 r = dns_type_from_string(t);
705 if (r < 0)
706 return log_error_errno(r, "Unknown DNS type %s: %m", t);
707
708 type = r;
709
710 if (*e == ';') {
711 q = e + 1;
712 continue;
713 }
714
715 break;
716 }
717
718 goto invalid;
719 }
720 } else
721 n = p;
722
723 if (class == 0)
724 class = arg_class ?: DNS_CLASS_IN;
725 if (type == 0)
726 type = arg_type ?: DNS_TYPE_A;
727
728 return resolve_record(bus, n, class, type, true);
729
730 invalid:
731 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
732 "Invalid DNS URI: %s", name);
733 }
734
735 static int verb_query(int argc, char **argv, void *userdata) {
736 sd_bus *bus = userdata;
737 int q, r = 0;
738
739 if (arg_type != 0)
740 STRV_FOREACH(p, argv + 1) {
741 q = resolve_record(bus, *p, arg_class, arg_type, true);
742 if (q < 0)
743 r = q;
744 }
745
746 else
747 STRV_FOREACH(p, argv + 1) {
748 if (startswith(*p, "dns:"))
749 q = resolve_rfc4501(bus, *p);
750 else {
751 int family, ifindex;
752 union in_addr_union a;
753
754 q = in_addr_ifindex_from_string_auto(*p, &family, &a, &ifindex);
755 if (q >= 0)
756 q = resolve_address(bus, family, &a, ifindex);
757 else
758 q = resolve_host(bus, *p);
759 }
760 if (q < 0)
761 r = q;
762 }
763
764 return r;
765 }
766
767 static int resolve_service(sd_bus *bus, const char *name, const char *type, const char *domain) {
768 const char *canonical_name, *canonical_type, *canonical_domain;
769 _cleanup_(sd_bus_message_unrefp) sd_bus_message *req = NULL, *reply = NULL;
770 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
771 size_t indent, sz;
772 uint64_t flags;
773 const char *p;
774 unsigned c;
775 usec_t ts;
776 int r;
777
778 assert(bus);
779 assert(domain);
780
781 name = empty_to_null(name);
782 type = empty_to_null(type);
783
784 if (name)
785 log_debug("Resolving service \"%s\" of type %s in %s (family %s, interface %s).", name, type, domain, af_to_name(arg_family) ?: "*", isempty(arg_ifname) ? "*" : arg_ifname);
786 else if (type)
787 log_debug("Resolving service type %s of %s (family %s, interface %s).", type, domain, af_to_name(arg_family) ?: "*", isempty(arg_ifname) ? "*" : arg_ifname);
788 else
789 log_debug("Resolving service type %s (family %s, interface %s).", domain, af_to_name(arg_family) ?: "*", isempty(arg_ifname) ? "*" : arg_ifname);
790
791 r = bus_message_new_method_call(bus, &req, bus_resolve_mgr, "ResolveService");
792 if (r < 0)
793 return bus_log_create_error(r);
794
795 r = sd_bus_message_append(req, "isssit", arg_ifindex, name, type, domain, arg_family, arg_flags);
796 if (r < 0)
797 return bus_log_create_error(r);
798
799 ts = now(CLOCK_MONOTONIC);
800
801 r = sd_bus_call(bus, req, SD_RESOLVED_QUERY_TIMEOUT_USEC, &error, &reply);
802 if (r < 0)
803 return log_error_errno(r, "Resolve call failed: %s", bus_error_message(&error, r));
804
805 ts = now(CLOCK_MONOTONIC) - ts;
806
807 r = sd_bus_message_enter_container(reply, 'a', "(qqqsa(iiay)s)");
808 if (r < 0)
809 return bus_log_parse_error(r);
810
811 indent =
812 (name ? strlen(name) + 1 : 0) +
813 (type ? strlen(type) + 1 : 0) +
814 strlen(domain) + 2;
815
816 c = 0;
817 while ((r = sd_bus_message_enter_container(reply, 'r', "qqqsa(iiay)s")) > 0) {
818 uint16_t priority, weight, port;
819 const char *hostname, *canonical;
820
821 r = sd_bus_message_read(reply, "qqqs", &priority, &weight, &port, &hostname);
822 if (r < 0)
823 return bus_log_parse_error(r);
824
825 if (name)
826 printf("%*s%s", (int) strlen(name), c == 0 ? name : "", c == 0 ? "/" : " ");
827 if (type)
828 printf("%*s%s", (int) strlen(type), c == 0 ? type : "", c == 0 ? "/" : " ");
829
830 printf("%*s%s %s:%u [priority=%u, weight=%u]\n",
831 (int) strlen(domain), c == 0 ? domain : "",
832 c == 0 ? ":" : " ",
833 hostname, port,
834 priority, weight);
835
836 r = sd_bus_message_enter_container(reply, 'a', "(iiay)");
837 if (r < 0)
838 return bus_log_parse_error(r);
839
840 while ((r = sd_bus_message_enter_container(reply, 'r', "iiay")) > 0) {
841 _cleanup_free_ char *pretty = NULL;
842 int ifindex, family, k;
843 union in_addr_union a;
844
845 assert_cc(sizeof(int) == sizeof(int32_t));
846
847 r = sd_bus_message_read(reply, "i", &ifindex);
848 if (r < 0)
849 return bus_log_parse_error(r);
850
851 sd_bus_error_free(&error);
852 r = bus_message_read_in_addr_auto(reply, &error, &family, &a);
853 if (r < 0 && !sd_bus_error_has_name(&error, SD_BUS_ERROR_INVALID_ARGS))
854 return log_error_errno(r, "%s: systemd-resolved returned invalid result: %s", name, bus_error_message(&error, r));
855
856 r = sd_bus_message_exit_container(reply);
857 if (r < 0)
858 return bus_log_parse_error(r);
859
860 if (sd_bus_error_has_name(&error, SD_BUS_ERROR_INVALID_ARGS)) {
861 log_debug_errno(r, "%s: systemd-resolved returned invalid result, ignoring: %s", name, bus_error_message(&error, r));
862 continue;
863 }
864
865 r = in_addr_ifindex_to_string(family, &a, ifindex, &pretty);
866 if (r < 0)
867 return log_error_errno(r, "Failed to print address for %s: %m", name);
868
869 k = printf("%*s%s", (int) indent, "", pretty);
870 print_ifindex_comment(k, ifindex);
871 fputc('\n', stdout);
872 }
873 if (r < 0)
874 return bus_log_parse_error(r);
875
876 r = sd_bus_message_exit_container(reply);
877 if (r < 0)
878 return bus_log_parse_error(r);
879
880 r = sd_bus_message_read(reply, "s", &canonical);
881 if (r < 0)
882 return bus_log_parse_error(r);
883
884 if (!streq(hostname, canonical))
885 printf("%*s(%s)\n", (int) indent, "", canonical);
886
887 r = sd_bus_message_exit_container(reply);
888 if (r < 0)
889 return bus_log_parse_error(r);
890
891 c++;
892 }
893 if (r < 0)
894 return bus_log_parse_error(r);
895
896 r = sd_bus_message_exit_container(reply);
897 if (r < 0)
898 return bus_log_parse_error(r);
899
900 r = sd_bus_message_enter_container(reply, 'a', "ay");
901 if (r < 0)
902 return bus_log_parse_error(r);
903
904 while ((r = sd_bus_message_read_array(reply, 'y', (const void**) &p, &sz)) > 0) {
905 _cleanup_free_ char *escaped = NULL;
906
907 escaped = cescape_length(p, sz);
908 if (!escaped)
909 return log_oom();
910
911 printf("%*s%s\n", (int) indent, "", escaped);
912 }
913 if (r < 0)
914 return bus_log_parse_error(r);
915
916 r = sd_bus_message_exit_container(reply);
917 if (r < 0)
918 return bus_log_parse_error(r);
919
920 r = sd_bus_message_read(reply, "ssst", &canonical_name, &canonical_type, &canonical_domain, &flags);
921 if (r < 0)
922 return bus_log_parse_error(r);
923
924 canonical_name = empty_to_null(canonical_name);
925 canonical_type = empty_to_null(canonical_type);
926
927 if (!streq_ptr(name, canonical_name) ||
928 !streq_ptr(type, canonical_type) ||
929 !streq_ptr(domain, canonical_domain)) {
930
931 printf("%*s(", (int) indent, "");
932
933 if (canonical_name)
934 printf("%s/", canonical_name);
935 if (canonical_type)
936 printf("%s/", canonical_type);
937
938 printf("%s)\n", canonical_domain);
939 }
940
941 print_source(flags, ts);
942
943 return 0;
944 }
945
946 static int verb_service(int argc, char **argv, void *userdata) {
947 sd_bus *bus = userdata;
948
949 if (argc == 2)
950 return resolve_service(bus, NULL, NULL, argv[1]);
951 else if (argc == 3)
952 return resolve_service(bus, NULL, argv[1], argv[2]);
953 else
954 return resolve_service(bus, argv[1], argv[2], argv[3]);
955 }
956
957 static int resolve_openpgp(sd_bus *bus, const char *address) {
958 const char *domain, *full;
959 int r;
960 _cleanup_free_ char *hashed = NULL;
961
962 assert(bus);
963 assert(address);
964
965 domain = strrchr(address, '@');
966 if (!domain)
967 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
968 "Address does not contain '@': \"%s\"", address);
969 if (domain == address || domain[1] == '\0')
970 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
971 "Address starts or ends with '@': \"%s\"", address);
972 domain++;
973
974 r = string_hashsum_sha256(address, domain - 1 - address, &hashed);
975 if (r < 0)
976 return log_error_errno(r, "Hashing failed: %m");
977
978 strshorten(hashed, 56);
979
980 full = strjoina(hashed, "._openpgpkey.", domain);
981 log_debug("Looking up \"%s\".", full);
982
983 r = resolve_record(bus, full,
984 arg_class ?: DNS_CLASS_IN,
985 arg_type ?: DNS_TYPE_OPENPGPKEY, false);
986
987 if (IN_SET(r, -ENXIO, -ESRCH)) { /* NXDOMAIN or NODATA? */
988 hashed = mfree(hashed);
989 r = string_hashsum_sha224(address, domain - 1 - address, &hashed);
990 if (r < 0)
991 return log_error_errno(r, "Hashing failed: %m");
992
993 full = strjoina(hashed, "._openpgpkey.", domain);
994 log_debug("Looking up \"%s\".", full);
995
996 return resolve_record(bus, full,
997 arg_class ?: DNS_CLASS_IN,
998 arg_type ?: DNS_TYPE_OPENPGPKEY, true);
999 }
1000
1001 return r;
1002 }
1003
1004 static int verb_openpgp(int argc, char **argv, void *userdata) {
1005 sd_bus *bus = userdata;
1006 int q, r = 0;
1007
1008 STRV_FOREACH(p, argv + 1) {
1009 q = resolve_openpgp(bus, *p);
1010 if (q < 0)
1011 r = q;
1012 }
1013
1014 return r;
1015 }
1016
1017 static int resolve_tlsa(sd_bus *bus, const char *family, const char *address) {
1018 const char *port;
1019 uint16_t port_num = 443;
1020 _cleanup_free_ char *full = NULL;
1021 int r;
1022
1023 assert(bus);
1024 assert(address);
1025
1026 port = strrchr(address, ':');
1027 if (port) {
1028 r = parse_ip_port(port + 1, &port_num);
1029 if (r < 0)
1030 return log_error_errno(r, "Invalid port \"%s\".", port + 1);
1031
1032 address = strndupa_safe(address, port - address);
1033 }
1034
1035 r = asprintf(&full, "_%u._%s.%s",
1036 port_num,
1037 family,
1038 address);
1039 if (r < 0)
1040 return log_oom();
1041
1042 log_debug("Looking up \"%s\".", full);
1043
1044 return resolve_record(bus, full,
1045 arg_class ?: DNS_CLASS_IN,
1046 arg_type ?: DNS_TYPE_TLSA, true);
1047 }
1048
1049 static bool service_family_is_valid(const char *s) {
1050 return STR_IN_SET(s, "tcp", "udp", "sctp");
1051 }
1052
1053 static int verb_tlsa(int argc, char **argv, void *userdata) {
1054 sd_bus *bus = userdata;
1055 char **args = argv + 1;
1056 const char *family = "tcp";
1057 int q, r = 0;
1058
1059 if (service_family_is_valid(argv[1])) {
1060 family = argv[1];
1061 args++;
1062 }
1063
1064 STRV_FOREACH(p, args) {
1065 q = resolve_tlsa(bus, family, *p);
1066 if (q < 0)
1067 r = q;
1068 }
1069
1070 return r;
1071 }
1072
1073 static int show_statistics(int argc, char **argv, void *userdata) {
1074 _cleanup_(table_unrefp) Table *table = NULL;
1075 JsonVariant *reply = NULL;
1076 _cleanup_(varlink_unrefp) Varlink *vl = NULL;
1077 int r;
1078
1079 r = varlink_connect_address(&vl, "/run/systemd/resolve/io.systemd.Resolve.Monitor");
1080 if (r < 0)
1081 return log_error_errno(r, "Failed to connect to query monitoring service /run/systemd/resolve/io.systemd.Resolve.Monitor: %m");
1082
1083 r = varlink_call_and_log(vl, "io.systemd.Resolve.Monitor.DumpStatistics", /* parameters= */ NULL, &reply);
1084 if (r < 0)
1085 return r;
1086
1087 if (!FLAGS_SET(arg_json_format_flags, JSON_FORMAT_OFF))
1088 return json_variant_dump(reply, arg_json_format_flags, NULL, NULL);
1089
1090 struct statistics {
1091 JsonVariant *transactions;
1092 JsonVariant *cache;
1093 JsonVariant *dnssec;
1094 } statistics;
1095
1096 static const JsonDispatch statistics_dispatch_table[] = {
1097 { "transactions", JSON_VARIANT_OBJECT, json_dispatch_variant_noref, offsetof(struct statistics, transactions), JSON_MANDATORY },
1098 { "cache", JSON_VARIANT_OBJECT, json_dispatch_variant_noref, offsetof(struct statistics, cache), JSON_MANDATORY },
1099 { "dnssec", JSON_VARIANT_OBJECT, json_dispatch_variant_noref, offsetof(struct statistics, dnssec), JSON_MANDATORY },
1100 {},
1101 };
1102
1103 r = json_dispatch(reply, statistics_dispatch_table, JSON_LOG, &statistics);
1104 if (r < 0)
1105 return r;
1106
1107 struct transactions {
1108 uint64_t n_current_transactions;
1109 uint64_t n_transactions_total;
1110 uint64_t n_timeouts_total;
1111 uint64_t n_timeouts_served_stale_total;
1112 uint64_t n_failure_responses_total;
1113 uint64_t n_failure_responses_served_stale_total;
1114 } transactions;
1115
1116 static const JsonDispatch transactions_dispatch_table[] = {
1117 { "currentTransactions", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct transactions, n_current_transactions), JSON_MANDATORY },
1118 { "totalTransactions", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct transactions, n_transactions_total), JSON_MANDATORY },
1119 { "totalTimeouts", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct transactions, n_timeouts_total), JSON_MANDATORY },
1120 { "totalTimeoutsServedStale", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct transactions, n_timeouts_served_stale_total), JSON_MANDATORY },
1121 { "totalFailedResponses", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct transactions, n_failure_responses_total), JSON_MANDATORY },
1122 { "totalFailedResponsesServedStale", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct transactions, n_failure_responses_served_stale_total), JSON_MANDATORY },
1123 {},
1124 };
1125
1126 r = json_dispatch(statistics.transactions, transactions_dispatch_table, JSON_LOG, &transactions);
1127 if (r < 0)
1128 return r;
1129
1130 struct cache {
1131 uint64_t cache_size;
1132 uint64_t n_cache_hit;
1133 uint64_t n_cache_miss;
1134 } cache;
1135
1136 static const JsonDispatch cache_dispatch_table[] = {
1137 { "size", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct cache, cache_size), JSON_MANDATORY },
1138 { "hits", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct cache, n_cache_hit), JSON_MANDATORY },
1139 { "misses", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct cache, n_cache_miss), JSON_MANDATORY },
1140 {},
1141 };
1142
1143 r = json_dispatch(statistics.cache, cache_dispatch_table, JSON_LOG, &cache);
1144 if (r < 0)
1145 return r;
1146
1147 struct dnsssec {
1148 uint64_t n_dnssec_secure;
1149 uint64_t n_dnssec_insecure;
1150 uint64_t n_dnssec_bogus;
1151 uint64_t n_dnssec_indeterminate;
1152 } dnsssec;
1153
1154 static const JsonDispatch dnssec_dispatch_table[] = {
1155 { "secure", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct dnsssec, n_dnssec_secure), JSON_MANDATORY },
1156 { "insecure", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct dnsssec, n_dnssec_insecure), JSON_MANDATORY },
1157 { "bogus", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct dnsssec, n_dnssec_bogus), JSON_MANDATORY },
1158 { "indeterminate", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct dnsssec, n_dnssec_indeterminate), JSON_MANDATORY },
1159 {},
1160 };
1161
1162 r = json_dispatch(statistics.dnssec, dnssec_dispatch_table, JSON_LOG, &dnsssec);
1163 if (r < 0)
1164 return r;
1165
1166 table = table_new_vertical();
1167 if (!table)
1168 return log_oom();
1169
1170 r = table_add_many(table,
1171 TABLE_STRING, "Transactions",
1172 TABLE_SET_COLOR, ansi_highlight(),
1173 TABLE_SET_ALIGN_PERCENT, 0,
1174 TABLE_EMPTY,
1175 TABLE_FIELD, "Current Transactions",
1176 TABLE_SET_ALIGN_PERCENT, 100,
1177 TABLE_UINT64, transactions.n_current_transactions,
1178 TABLE_SET_ALIGN_PERCENT, 100,
1179 TABLE_FIELD, "Total Transactions",
1180 TABLE_UINT64, transactions.n_transactions_total,
1181 TABLE_EMPTY, TABLE_EMPTY,
1182 TABLE_STRING, "Cache",
1183 TABLE_SET_COLOR, ansi_highlight(),
1184 TABLE_SET_ALIGN_PERCENT, 0,
1185 TABLE_EMPTY,
1186 TABLE_FIELD, "Current Cache Size",
1187 TABLE_SET_ALIGN_PERCENT, 100,
1188 TABLE_UINT64, cache.cache_size,
1189 TABLE_FIELD, "Cache Hits",
1190 TABLE_UINT64, cache.n_cache_hit,
1191 TABLE_FIELD, "Cache Misses",
1192 TABLE_UINT64, cache.n_cache_miss,
1193 TABLE_EMPTY, TABLE_EMPTY,
1194 TABLE_STRING, "Failure Transactions",
1195 TABLE_SET_COLOR, ansi_highlight(),
1196 TABLE_SET_ALIGN_PERCENT, 0,
1197 TABLE_EMPTY,
1198 TABLE_FIELD, "Total Timeouts",
1199 TABLE_SET_ALIGN_PERCENT, 100,
1200 TABLE_UINT64, transactions.n_timeouts_total,
1201 TABLE_FIELD, "Total Timeouts (Stale Data Served)",
1202 TABLE_UINT64, transactions.n_timeouts_served_stale_total,
1203 TABLE_FIELD, "Total Failure Responses",
1204 TABLE_UINT64, transactions.n_failure_responses_total,
1205 TABLE_FIELD, "Total Failure Responses (Stale Data Served)",
1206 TABLE_UINT64, transactions.n_failure_responses_served_stale_total,
1207 TABLE_EMPTY, TABLE_EMPTY,
1208 TABLE_STRING, "DNSSEC Verdicts",
1209 TABLE_SET_COLOR, ansi_highlight(),
1210 TABLE_SET_ALIGN_PERCENT, 0,
1211 TABLE_EMPTY,
1212 TABLE_FIELD, "Secure",
1213 TABLE_SET_ALIGN_PERCENT, 100,
1214 TABLE_UINT64, dnsssec.n_dnssec_secure,
1215 TABLE_FIELD, "Insecure",
1216 TABLE_UINT64, dnsssec.n_dnssec_insecure,
1217 TABLE_FIELD, "Bogus",
1218 TABLE_UINT64, dnsssec.n_dnssec_bogus,
1219 TABLE_FIELD, "Indeterminate",
1220 TABLE_UINT64, dnsssec.n_dnssec_indeterminate
1221 );
1222 if (r < 0)
1223 return table_log_add_error(r);
1224
1225 r = table_print(table, NULL);
1226 if (r < 0)
1227 return table_log_print_error(r);
1228
1229 return 0;
1230 }
1231
1232 static int reset_statistics(int argc, char **argv, void *userdata) {
1233 JsonVariant *reply = NULL;
1234 _cleanup_(varlink_unrefp) Varlink *vl = NULL;
1235 int r;
1236
1237 r = varlink_connect_address(&vl, "/run/systemd/resolve/io.systemd.Resolve.Monitor");
1238 if (r < 0)
1239 return log_error_errno(r, "Failed to connect to query monitoring service /run/systemd/resolve/io.systemd.Resolve.Monitor: %m");
1240
1241 r = varlink_call_and_log(vl, "io.systemd.Resolve.Monitor.ResetStatistics", /* parameters= */ NULL, &reply);
1242 if (r < 0)
1243 return r;
1244
1245 if (!FLAGS_SET(arg_json_format_flags, JSON_FORMAT_OFF))
1246 return json_variant_dump(reply, arg_json_format_flags, NULL, NULL);
1247
1248 return 0;
1249 }
1250
1251 static int flush_caches(int argc, char **argv, void *userdata) {
1252 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
1253 sd_bus *bus = userdata;
1254 int r;
1255
1256 r = bus_call_method(bus, bus_resolve_mgr, "FlushCaches", &error, NULL, NULL);
1257 if (r < 0)
1258 return log_error_errno(r, "Failed to flush caches: %s", bus_error_message(&error, r));
1259
1260 return 0;
1261 }
1262
1263 static int reset_server_features(int argc, char **argv, void *userdata) {
1264 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
1265 sd_bus *bus = userdata;
1266 int r;
1267
1268 r = bus_call_method(bus, bus_resolve_mgr, "ResetServerFeatures", &error, NULL, NULL);
1269 if (r < 0)
1270 return log_error_errno(r, "Failed to reset server features: %s", bus_error_message(&error, r));
1271
1272 return 0;
1273 }
1274
1275 static int read_dns_server_one(
1276 sd_bus_message *m,
1277 bool with_ifindex, /* read "ifindex" reply that also carries an interface index */
1278 bool extended, /* read "extended" reply, i.e. with port number and server name */
1279 bool only_global, /* suppress entries with an (non-loopback) ifindex set (i.e. which are specific to some interface) */
1280 char **ret) {
1281
1282 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
1283 _cleanup_free_ char *pretty = NULL;
1284 union in_addr_union a;
1285 const char *name = NULL;
1286 int32_t ifindex = 0;
1287 int family, r, k;
1288 uint16_t port = 0;
1289
1290 assert(m);
1291 assert(ret);
1292
1293 r = sd_bus_message_enter_container(
1294 m,
1295 'r',
1296 with_ifindex ? (extended ? "iiayqs" : "iiay") :
1297 (extended ? "iayqs" : "iay"));
1298 if (r <= 0)
1299 return r;
1300
1301 if (with_ifindex) {
1302 r = sd_bus_message_read(m, "i", &ifindex);
1303 if (r < 0)
1304 return r;
1305 }
1306
1307 k = bus_message_read_in_addr_auto(m, &error, &family, &a);
1308 if (k < 0 && !sd_bus_error_has_name(&error, SD_BUS_ERROR_INVALID_ARGS))
1309 return k;
1310
1311 if (extended) {
1312 r = sd_bus_message_read(m, "q", &port);
1313 if (r < 0)
1314 return r;
1315
1316 r = sd_bus_message_read(m, "s", &name);
1317 if (r < 0)
1318 return r;
1319 }
1320
1321 r = sd_bus_message_exit_container(m);
1322 if (r < 0)
1323 return r;
1324
1325 if (k < 0) {
1326 log_debug("Invalid DNS server, ignoring: %s", bus_error_message(&error, k));
1327 *ret = NULL;
1328 return 1;
1329 }
1330
1331 if (only_global && ifindex > 0 && ifindex != LOOPBACK_IFINDEX) {
1332 /* This one has an (non-loopback) ifindex set, and we were told to suppress those. Hence do so. */
1333 *ret = NULL;
1334 return 1;
1335 }
1336
1337 r = in_addr_port_ifindex_name_to_string(family, &a, port, ifindex, name, &pretty);
1338 if (r < 0)
1339 return r;
1340
1341 *ret = TAKE_PTR(pretty);
1342 return 1;
1343 }
1344
1345 static int map_link_dns_servers_internal(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata, bool extended) {
1346 char ***l = ASSERT_PTR(userdata);
1347 int r;
1348
1349 assert(bus);
1350 assert(member);
1351 assert(m);
1352
1353 r = sd_bus_message_enter_container(m, 'a', extended ? "(iayqs)" : "(iay)");
1354 if (r < 0)
1355 return r;
1356
1357 for (;;) {
1358 _cleanup_free_ char *pretty = NULL;
1359
1360 r = read_dns_server_one(m, /* with_ifindex= */ false, extended, /* only_global= */ false, &pretty);
1361 if (r < 0)
1362 return r;
1363 if (r == 0)
1364 break;
1365
1366 if (isempty(pretty))
1367 continue;
1368
1369 r = strv_consume(l, TAKE_PTR(pretty));
1370 if (r < 0)
1371 return r;
1372 }
1373
1374 r = sd_bus_message_exit_container(m);
1375 if (r < 0)
1376 return r;
1377
1378 return 0;
1379 }
1380
1381 static int map_link_dns_servers(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1382 return map_link_dns_servers_internal(bus, member, m, error, userdata, false);
1383 }
1384
1385 static int map_link_dns_servers_ex(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1386 return map_link_dns_servers_internal(bus, member, m, error, userdata, true);
1387 }
1388
1389 static int map_link_current_dns_server(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1390 assert(m);
1391 assert(userdata);
1392
1393 return read_dns_server_one(m, /* with_ifindex= */ false, /* extended= */ false, /* only_global= */ false, userdata);
1394 }
1395
1396 static int map_link_current_dns_server_ex(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1397 assert(m);
1398 assert(userdata);
1399
1400 return read_dns_server_one(m, /* with_ifindex= */ false, /* extended= */ true, /* only_global= */ false, userdata);
1401 }
1402
1403 static int read_domain_one(sd_bus_message *m, bool with_ifindex, char **ret) {
1404 _cleanup_free_ char *str = NULL;
1405 int ifindex, route_only, r;
1406 const char *domain;
1407
1408 assert(m);
1409 assert(ret);
1410
1411 if (with_ifindex)
1412 r = sd_bus_message_read(m, "(isb)", &ifindex, &domain, &route_only);
1413 else
1414 r = sd_bus_message_read(m, "(sb)", &domain, &route_only);
1415 if (r <= 0)
1416 return r;
1417
1418 if (with_ifindex && ifindex != 0) {
1419 /* only show the global ones here */
1420 *ret = NULL;
1421 return 1;
1422 }
1423
1424 if (route_only)
1425 str = strjoin("~", domain);
1426 else
1427 str = strdup(domain);
1428 if (!str)
1429 return -ENOMEM;
1430
1431 *ret = TAKE_PTR(str);
1432
1433 return 1;
1434 }
1435
1436 static int map_link_domains(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1437 char ***l = ASSERT_PTR(userdata);
1438 int r;
1439
1440 assert(bus);
1441 assert(member);
1442 assert(m);
1443
1444 r = sd_bus_message_enter_container(m, 'a', "(sb)");
1445 if (r < 0)
1446 return r;
1447
1448 for (;;) {
1449 _cleanup_free_ char *pretty = NULL;
1450
1451 r = read_domain_one(m, false, &pretty);
1452 if (r < 0)
1453 return r;
1454 if (r == 0)
1455 break;
1456
1457 if (isempty(pretty))
1458 continue;
1459
1460 r = strv_consume(l, TAKE_PTR(pretty));
1461 if (r < 0)
1462 return r;
1463 }
1464
1465 r = sd_bus_message_exit_container(m);
1466 if (r < 0)
1467 return r;
1468
1469 return 0;
1470 }
1471
1472 static int status_print_strv_ifindex(int ifindex, const char *ifname, char **p) {
1473 const unsigned indent = strlen("Global: "); /* Use the same indentation everywhere to make things nice */
1474 int pos1, pos2;
1475
1476 if (ifname)
1477 printf("%s%nLink %i (%s)%n%s:", ansi_highlight(), &pos1, ifindex, ifname, &pos2, ansi_normal());
1478 else
1479 printf("%s%nGlobal%n%s:", ansi_highlight(), &pos1, &pos2, ansi_normal());
1480
1481 size_t cols = columns(), position = pos2 - pos1 + 2;
1482
1483 STRV_FOREACH(i, p) {
1484 size_t our_len = utf8_console_width(*i); /* This returns -1 on invalid utf-8 (which shouldn't happen).
1485 * If that happens, we'll just print one item per line. */
1486
1487 if (position <= indent || size_add(size_add(position, 1), our_len) < cols) {
1488 printf(" %s", *i);
1489 position = size_add(size_add(position, 1), our_len);
1490 } else {
1491 printf("\n%*s%s", (int) indent, "", *i);
1492 position = size_add(our_len, indent);
1493 }
1494 }
1495
1496 printf("\n");
1497
1498 return 0;
1499 }
1500
1501 static int status_print_strv_global(char **p) {
1502 return status_print_strv_ifindex(0, NULL, p);
1503 }
1504
1505 typedef struct LinkInfo {
1506 uint64_t scopes_mask;
1507 const char *llmnr;
1508 const char *mdns;
1509 const char *dns_over_tls;
1510 const char *dnssec;
1511 char *current_dns;
1512 char *current_dns_ex;
1513 char **dns;
1514 char **dns_ex;
1515 char **domains;
1516 char **ntas;
1517 bool dnssec_supported;
1518 bool default_route;
1519 } LinkInfo;
1520
1521 typedef struct GlobalInfo {
1522 char *current_dns;
1523 char *current_dns_ex;
1524 char **dns;
1525 char **dns_ex;
1526 char **fallback_dns;
1527 char **fallback_dns_ex;
1528 char **domains;
1529 char **ntas;
1530 const char *llmnr;
1531 const char *mdns;
1532 const char *dns_over_tls;
1533 const char *dnssec;
1534 const char *resolv_conf_mode;
1535 bool dnssec_supported;
1536 } GlobalInfo;
1537
1538 static void link_info_clear(LinkInfo *p) {
1539 free(p->current_dns);
1540 free(p->current_dns_ex);
1541 strv_free(p->dns);
1542 strv_free(p->dns_ex);
1543 strv_free(p->domains);
1544 strv_free(p->ntas);
1545 }
1546
1547 static void global_info_clear(GlobalInfo *p) {
1548 free(p->current_dns);
1549 free(p->current_dns_ex);
1550 strv_free(p->dns);
1551 strv_free(p->dns_ex);
1552 strv_free(p->fallback_dns);
1553 strv_free(p->fallback_dns_ex);
1554 strv_free(p->domains);
1555 strv_free(p->ntas);
1556 }
1557
1558 static int dump_list(Table *table, const char *field, char * const *l) {
1559 int r;
1560
1561 if (strv_isempty(l))
1562 return 0;
1563
1564 r = table_add_many(table,
1565 TABLE_FIELD, field,
1566 TABLE_STRV_WRAPPED, l);
1567 if (r < 0)
1568 return table_log_add_error(r);
1569
1570 return 0;
1571 }
1572
1573 static int strv_extend_extended_bool(char ***strv, const char *name, const char *value) {
1574 int r;
1575
1576 if (value) {
1577 r = parse_boolean(value);
1578 if (r >= 0)
1579 return strv_extendf(strv, "%s%s", plus_minus(r), name);
1580 }
1581
1582 return strv_extendf(strv, "%s=%s", name, value ?: "???");
1583 }
1584
1585 static char** link_protocol_status(const LinkInfo *info) {
1586 _cleanup_strv_free_ char **s = NULL;
1587
1588 if (strv_extendf(&s, "%sDefaultRoute", plus_minus(info->default_route)) < 0)
1589 return NULL;
1590
1591 if (strv_extend_extended_bool(&s, "LLMNR", info->llmnr) < 0)
1592 return NULL;
1593
1594 if (strv_extend_extended_bool(&s, "mDNS", info->mdns) < 0)
1595 return NULL;
1596
1597 if (strv_extend_extended_bool(&s, "DNSOverTLS", info->dns_over_tls) < 0)
1598 return NULL;
1599
1600 if (strv_extendf(&s, "DNSSEC=%s/%s",
1601 info->dnssec ?: "???",
1602 info->dnssec_supported ? "supported" : "unsupported") < 0)
1603 return NULL;
1604
1605 return TAKE_PTR(s);
1606 }
1607
1608 static char** global_protocol_status(const GlobalInfo *info) {
1609 _cleanup_strv_free_ char **s = NULL;
1610
1611 if (strv_extend_extended_bool(&s, "LLMNR", info->llmnr) < 0)
1612 return NULL;
1613
1614 if (strv_extend_extended_bool(&s, "mDNS", info->mdns) < 0)
1615 return NULL;
1616
1617 if (strv_extend_extended_bool(&s, "DNSOverTLS", info->dns_over_tls) < 0)
1618 return NULL;
1619
1620 if (strv_extendf(&s, "DNSSEC=%s/%s",
1621 info->dnssec ?: "???",
1622 info->dnssec_supported ? "supported" : "unsupported") < 0)
1623 return NULL;
1624
1625 return TAKE_PTR(s);
1626 }
1627
1628 static int status_ifindex(sd_bus *bus, int ifindex, const char *name, StatusMode mode, bool *empty_line) {
1629 static const struct bus_properties_map property_map[] = {
1630 { "ScopesMask", "t", NULL, offsetof(LinkInfo, scopes_mask) },
1631 { "DNS", "a(iay)", map_link_dns_servers, offsetof(LinkInfo, dns) },
1632 { "DNSEx", "a(iayqs)", map_link_dns_servers_ex, offsetof(LinkInfo, dns_ex) },
1633 { "CurrentDNSServer", "(iay)", map_link_current_dns_server, offsetof(LinkInfo, current_dns) },
1634 { "CurrentDNSServerEx", "(iayqs)", map_link_current_dns_server_ex, offsetof(LinkInfo, current_dns_ex) },
1635 { "Domains", "a(sb)", map_link_domains, offsetof(LinkInfo, domains) },
1636 { "DefaultRoute", "b", NULL, offsetof(LinkInfo, default_route) },
1637 { "LLMNR", "s", NULL, offsetof(LinkInfo, llmnr) },
1638 { "MulticastDNS", "s", NULL, offsetof(LinkInfo, mdns) },
1639 { "DNSOverTLS", "s", NULL, offsetof(LinkInfo, dns_over_tls) },
1640 { "DNSSEC", "s", NULL, offsetof(LinkInfo, dnssec) },
1641 { "DNSSECNegativeTrustAnchors", "as", bus_map_strv_sort, offsetof(LinkInfo, ntas) },
1642 { "DNSSECSupported", "b", NULL, offsetof(LinkInfo, dnssec_supported) },
1643 {}
1644 };
1645 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
1646 _cleanup_(sd_bus_message_unrefp) sd_bus_message *m = NULL;
1647 _cleanup_(link_info_clear) LinkInfo link_info = {};
1648 _cleanup_(table_unrefp) Table *table = NULL;
1649 _cleanup_free_ char *p = NULL;
1650 char ifi[DECIMAL_STR_MAX(int)], ifname[IF_NAMESIZE];
1651 int r;
1652
1653 assert(bus);
1654 assert(ifindex > 0);
1655
1656 if (!name) {
1657 r = format_ifname(ifindex, ifname);
1658 if (r < 0)
1659 return log_error_errno(r, "Failed to resolve interface name for %i: %m", ifindex);
1660
1661 name = ifname;
1662 }
1663
1664 xsprintf(ifi, "%i", ifindex);
1665 r = sd_bus_path_encode("/org/freedesktop/resolve1/link", ifi, &p);
1666 if (r < 0)
1667 return log_oom();
1668
1669 r = bus_map_all_properties(bus,
1670 "org.freedesktop.resolve1",
1671 p,
1672 property_map,
1673 BUS_MAP_BOOLEAN_AS_BOOL,
1674 &error,
1675 &m,
1676 &link_info);
1677 if (r < 0)
1678 return log_error_errno(r, "Failed to get link data for %i: %s", ifindex, bus_error_message(&error, r));
1679
1680 pager_open(arg_pager_flags);
1681
1682 if (mode == STATUS_DNS)
1683 return status_print_strv_ifindex(ifindex, name, link_info.dns_ex ?: link_info.dns);
1684
1685 if (mode == STATUS_DOMAIN)
1686 return status_print_strv_ifindex(ifindex, name, link_info.domains);
1687
1688 if (mode == STATUS_NTA)
1689 return status_print_strv_ifindex(ifindex, name, link_info.ntas);
1690
1691 if (mode == STATUS_DEFAULT_ROUTE) {
1692 printf("%sLink %i (%s)%s: %s\n",
1693 ansi_highlight(), ifindex, name, ansi_normal(),
1694 yes_no(link_info.default_route));
1695
1696 return 0;
1697 }
1698
1699 if (mode == STATUS_LLMNR) {
1700 printf("%sLink %i (%s)%s: %s\n",
1701 ansi_highlight(), ifindex, name, ansi_normal(),
1702 strna(link_info.llmnr));
1703
1704 return 0;
1705 }
1706
1707 if (mode == STATUS_MDNS) {
1708 printf("%sLink %i (%s)%s: %s\n",
1709 ansi_highlight(), ifindex, name, ansi_normal(),
1710 strna(link_info.mdns));
1711
1712 return 0;
1713 }
1714
1715 if (mode == STATUS_PRIVATE) {
1716 printf("%sLink %i (%s)%s: %s\n",
1717 ansi_highlight(), ifindex, name, ansi_normal(),
1718 strna(link_info.dns_over_tls));
1719
1720 return 0;
1721 }
1722
1723 if (mode == STATUS_DNSSEC) {
1724 printf("%sLink %i (%s)%s: %s\n",
1725 ansi_highlight(), ifindex, name, ansi_normal(),
1726 strna(link_info.dnssec));
1727
1728 return 0;
1729 }
1730
1731 if (empty_line && *empty_line)
1732 fputc('\n', stdout);
1733
1734 printf("%sLink %i (%s)%s\n",
1735 ansi_highlight(), ifindex, name, ansi_normal());
1736
1737 table = table_new_vertical();
1738 if (!table)
1739 return log_oom();
1740
1741 r = table_add_many(table,
1742 TABLE_FIELD, "Current Scopes",
1743 TABLE_SET_MINIMUM_WIDTH, 19);
1744 if (r < 0)
1745 return table_log_add_error(r);
1746
1747 if (link_info.scopes_mask == 0)
1748 r = table_add_cell(table, NULL, TABLE_STRING, "none");
1749 else {
1750 _cleanup_free_ char *buf = NULL;
1751 size_t len;
1752
1753 if (asprintf(&buf, "%s%s%s%s%s",
1754 link_info.scopes_mask & SD_RESOLVED_DNS ? "DNS " : "",
1755 link_info.scopes_mask & SD_RESOLVED_LLMNR_IPV4 ? "LLMNR/IPv4 " : "",
1756 link_info.scopes_mask & SD_RESOLVED_LLMNR_IPV6 ? "LLMNR/IPv6 " : "",
1757 link_info.scopes_mask & SD_RESOLVED_MDNS_IPV4 ? "mDNS/IPv4 " : "",
1758 link_info.scopes_mask & SD_RESOLVED_MDNS_IPV6 ? "mDNS/IPv6 " : "") < 0)
1759 return log_oom();
1760
1761 len = strlen(buf);
1762 assert(len > 0);
1763 buf[len - 1] = '\0';
1764
1765 r = table_add_cell(table, NULL, TABLE_STRING, buf);
1766 }
1767 if (r < 0)
1768 return table_log_add_error(r);
1769
1770 _cleanup_strv_free_ char **pstatus = link_protocol_status(&link_info);
1771 if (!pstatus)
1772 return log_oom();
1773
1774 r = table_add_many(table,
1775 TABLE_FIELD, "Protocols",
1776 TABLE_STRV_WRAPPED, pstatus);
1777 if (r < 0)
1778 return table_log_add_error(r);
1779
1780 if (link_info.current_dns) {
1781 r = table_add_many(table,
1782 TABLE_FIELD, "Current DNS Server",
1783 TABLE_STRING, link_info.current_dns_ex ?: link_info.current_dns);
1784 if (r < 0)
1785 return table_log_add_error(r);
1786 }
1787
1788 r = dump_list(table, "DNS Servers", link_info.dns_ex ?: link_info.dns);
1789 if (r < 0)
1790 return r;
1791
1792 r = dump_list(table, "DNS Domain", link_info.domains);
1793 if (r < 0)
1794 return r;
1795
1796 r = table_print(table, NULL);
1797 if (r < 0)
1798 return table_log_print_error(r);
1799
1800 if (empty_line)
1801 *empty_line = true;
1802
1803 return 0;
1804 }
1805
1806 static int map_global_dns_servers_internal(
1807 sd_bus *bus,
1808 const char *member,
1809 sd_bus_message *m,
1810 sd_bus_error *error,
1811 void *userdata,
1812 bool extended) {
1813
1814 char ***l = ASSERT_PTR(userdata);
1815 int r;
1816
1817 assert(bus);
1818 assert(member);
1819 assert(m);
1820
1821 r = sd_bus_message_enter_container(m, 'a', extended ? "(iiayqs)" : "(iiay)");
1822 if (r < 0)
1823 return r;
1824
1825 for (;;) {
1826 _cleanup_free_ char *pretty = NULL;
1827
1828 r = read_dns_server_one(m, /* with_ifindex= */ true, extended, /* only_global= */ true, &pretty);
1829 if (r < 0)
1830 return r;
1831 if (r == 0)
1832 break;
1833
1834 if (isempty(pretty))
1835 continue;
1836
1837 r = strv_consume(l, TAKE_PTR(pretty));
1838 if (r < 0)
1839 return r;
1840 }
1841
1842 r = sd_bus_message_exit_container(m);
1843 if (r < 0)
1844 return r;
1845
1846 return 0;
1847 }
1848
1849 static int map_global_dns_servers(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1850 return map_global_dns_servers_internal(bus, member, m, error, userdata, /* extended= */ false);
1851 }
1852
1853 static int map_global_dns_servers_ex(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1854 return map_global_dns_servers_internal(bus, member, m, error, userdata, /* extended= */ true);
1855 }
1856
1857 static int map_global_current_dns_server(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1858 return read_dns_server_one(m, /* with_ifindex= */ true, /* extended= */ false, /* only_global= */ true, userdata);
1859 }
1860
1861 static int map_global_current_dns_server_ex(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1862 return read_dns_server_one(m, /* with_ifindex= */ true, /* extended= */ true, /* only_global= */ true, userdata);
1863 }
1864
1865 static int map_global_domains(sd_bus *bus, const char *member, sd_bus_message *m, sd_bus_error *error, void *userdata) {
1866 char ***l = ASSERT_PTR(userdata);
1867 int r;
1868
1869 assert(bus);
1870 assert(member);
1871 assert(m);
1872
1873 r = sd_bus_message_enter_container(m, 'a', "(isb)");
1874 if (r < 0)
1875 return r;
1876
1877 for (;;) {
1878 _cleanup_free_ char *pretty = NULL;
1879
1880 r = read_domain_one(m, true, &pretty);
1881 if (r < 0)
1882 return r;
1883 if (r == 0)
1884 break;
1885
1886 if (isempty(pretty))
1887 continue;
1888
1889 r = strv_consume(l, TAKE_PTR(pretty));
1890 if (r < 0)
1891 return r;
1892 }
1893
1894 r = sd_bus_message_exit_container(m);
1895 if (r < 0)
1896 return r;
1897
1898 strv_sort(*l);
1899
1900 return 0;
1901 }
1902
1903 static int status_global(sd_bus *bus, StatusMode mode, bool *empty_line) {
1904 static const struct bus_properties_map property_map[] = {
1905 { "DNS", "a(iiay)", map_global_dns_servers, offsetof(GlobalInfo, dns) },
1906 { "DNSEx", "a(iiayqs)", map_global_dns_servers_ex, offsetof(GlobalInfo, dns_ex) },
1907 { "FallbackDNS", "a(iiay)", map_global_dns_servers, offsetof(GlobalInfo, fallback_dns) },
1908 { "FallbackDNSEx", "a(iiayqs)", map_global_dns_servers_ex, offsetof(GlobalInfo, fallback_dns_ex) },
1909 { "CurrentDNSServer", "(iiay)", map_global_current_dns_server, offsetof(GlobalInfo, current_dns) },
1910 { "CurrentDNSServerEx", "(iiayqs)", map_global_current_dns_server_ex, offsetof(GlobalInfo, current_dns_ex) },
1911 { "Domains", "a(isb)", map_global_domains, offsetof(GlobalInfo, domains) },
1912 { "DNSSECNegativeTrustAnchors", "as", bus_map_strv_sort, offsetof(GlobalInfo, ntas) },
1913 { "LLMNR", "s", NULL, offsetof(GlobalInfo, llmnr) },
1914 { "MulticastDNS", "s", NULL, offsetof(GlobalInfo, mdns) },
1915 { "DNSOverTLS", "s", NULL, offsetof(GlobalInfo, dns_over_tls) },
1916 { "DNSSEC", "s", NULL, offsetof(GlobalInfo, dnssec) },
1917 { "DNSSECSupported", "b", NULL, offsetof(GlobalInfo, dnssec_supported) },
1918 { "ResolvConfMode", "s", NULL, offsetof(GlobalInfo, resolv_conf_mode) },
1919 {}
1920 };
1921 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
1922 _cleanup_(sd_bus_message_unrefp) sd_bus_message *m = NULL;
1923 _cleanup_(global_info_clear) GlobalInfo global_info = {};
1924 _cleanup_(table_unrefp) Table *table = NULL;
1925 int r;
1926
1927 assert(bus);
1928 assert(empty_line);
1929
1930 r = bus_map_all_properties(bus,
1931 "org.freedesktop.resolve1",
1932 "/org/freedesktop/resolve1",
1933 property_map,
1934 BUS_MAP_BOOLEAN_AS_BOOL,
1935 &error,
1936 &m,
1937 &global_info);
1938 if (r < 0)
1939 return log_error_errno(r, "Failed to get global data: %s", bus_error_message(&error, r));
1940
1941 pager_open(arg_pager_flags);
1942
1943 if (mode == STATUS_DNS)
1944 return status_print_strv_global(global_info.dns_ex ?: global_info.dns);
1945
1946 if (mode == STATUS_DOMAIN)
1947 return status_print_strv_global(global_info.domains);
1948
1949 if (mode == STATUS_NTA)
1950 return status_print_strv_global(global_info.ntas);
1951
1952 if (mode == STATUS_LLMNR) {
1953 printf("%sGlobal%s: %s\n", ansi_highlight(), ansi_normal(),
1954 strna(global_info.llmnr));
1955
1956 return 0;
1957 }
1958
1959 if (mode == STATUS_MDNS) {
1960 printf("%sGlobal%s: %s\n", ansi_highlight(), ansi_normal(),
1961 strna(global_info.mdns));
1962
1963 return 0;
1964 }
1965
1966 if (mode == STATUS_PRIVATE) {
1967 printf("%sGlobal%s: %s\n", ansi_highlight(), ansi_normal(),
1968 strna(global_info.dns_over_tls));
1969
1970 return 0;
1971 }
1972
1973 if (mode == STATUS_DNSSEC) {
1974 printf("%sGlobal%s: %s\n", ansi_highlight(), ansi_normal(),
1975 strna(global_info.dnssec));
1976
1977 return 0;
1978 }
1979
1980 printf("%sGlobal%s\n", ansi_highlight(), ansi_normal());
1981
1982 table = table_new_vertical();
1983 if (!table)
1984 return log_oom();
1985
1986 _cleanup_strv_free_ char **pstatus = global_protocol_status(&global_info);
1987 if (!pstatus)
1988 return log_oom();
1989
1990 r = table_add_many(table,
1991 TABLE_FIELD, "Protocols",
1992 TABLE_SET_MINIMUM_WIDTH, 19,
1993 TABLE_STRV_WRAPPED, pstatus);
1994 if (r < 0)
1995 return table_log_add_error(r);
1996
1997 if (global_info.resolv_conf_mode) {
1998 r = table_add_many(table,
1999 TABLE_FIELD, "resolv.conf mode",
2000 TABLE_STRING, global_info.resolv_conf_mode);
2001 if (r < 0)
2002 return table_log_add_error(r);
2003 }
2004
2005 if (global_info.current_dns) {
2006 r = table_add_many(table,
2007 TABLE_FIELD, "Current DNS Server",
2008 TABLE_STRING, global_info.current_dns_ex ?: global_info.current_dns);
2009 if (r < 0)
2010 return table_log_add_error(r);
2011 }
2012
2013 r = dump_list(table, "DNS Servers", global_info.dns_ex ?: global_info.dns);
2014 if (r < 0)
2015 return r;
2016
2017 r = dump_list(table, "Fallback DNS Servers", global_info.fallback_dns_ex ?: global_info.fallback_dns);
2018 if (r < 0)
2019 return r;
2020
2021 r = dump_list(table, "DNS Domain", global_info.domains);
2022 if (r < 0)
2023 return r;
2024
2025 r = table_print(table, NULL);
2026 if (r < 0)
2027 return table_log_print_error(r);
2028
2029 *empty_line = true;
2030
2031 return 0;
2032 }
2033
2034 static int status_all(sd_bus *bus, StatusMode mode) {
2035 _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL, *reply = NULL;
2036 _cleanup_(sd_netlink_unrefp) sd_netlink *rtnl = NULL;
2037 bool empty_line = false;
2038 int r;
2039
2040 assert(bus);
2041
2042 r = status_global(bus, mode, &empty_line);
2043 if (r < 0)
2044 return r;
2045
2046 r = sd_netlink_open(&rtnl);
2047 if (r < 0)
2048 return log_error_errno(r, "Failed to connect to netlink: %m");
2049
2050 r = sd_rtnl_message_new_link(rtnl, &req, RTM_GETLINK, 0);
2051 if (r < 0)
2052 return rtnl_log_create_error(r);
2053
2054 r = sd_netlink_message_set_request_dump(req, true);
2055 if (r < 0)
2056 return rtnl_log_create_error(r);
2057
2058 r = sd_netlink_call(rtnl, req, 0, &reply);
2059 if (r < 0)
2060 return log_error_errno(r, "Failed to enumerate links: %m");
2061
2062 _cleanup_free_ InterfaceInfo *infos = NULL;
2063 size_t n_infos = 0;
2064
2065 for (sd_netlink_message *i = reply; i; i = sd_netlink_message_next(i)) {
2066 const char *name;
2067 int ifindex;
2068 uint16_t type;
2069
2070 r = sd_netlink_message_get_type(i, &type);
2071 if (r < 0)
2072 return rtnl_log_parse_error(r);
2073
2074 if (type != RTM_NEWLINK)
2075 continue;
2076
2077 r = sd_rtnl_message_link_get_ifindex(i, &ifindex);
2078 if (r < 0)
2079 return rtnl_log_parse_error(r);
2080
2081 if (ifindex == LOOPBACK_IFINDEX)
2082 continue;
2083
2084 r = sd_netlink_message_read_string(i, IFLA_IFNAME, &name);
2085 if (r < 0)
2086 return rtnl_log_parse_error(r);
2087
2088 if (!GREEDY_REALLOC(infos, n_infos + 1))
2089 return log_oom();
2090
2091 infos[n_infos++] = (InterfaceInfo) { ifindex, name };
2092 }
2093
2094 typesafe_qsort(infos, n_infos, interface_info_compare);
2095
2096 r = 0;
2097 for (size_t i = 0; i < n_infos; i++) {
2098 int q = status_ifindex(bus, infos[i].index, infos[i].name, mode, &empty_line);
2099 if (q < 0 && r >= 0)
2100 r = q;
2101 }
2102
2103 return r;
2104 }
2105
2106 static int verb_status(int argc, char **argv, void *userdata) {
2107 sd_bus *bus = userdata;
2108 _cleanup_(sd_netlink_unrefp) sd_netlink *rtnl = NULL;
2109 int r = 0;
2110
2111 if (argc > 1) {
2112 bool empty_line = false;
2113
2114 STRV_FOREACH(ifname, argv + 1) {
2115 int ifindex, q;
2116
2117 ifindex = rtnl_resolve_interface(&rtnl, *ifname);
2118 if (ifindex < 0) {
2119 log_warning_errno(ifindex, "Failed to resolve interface \"%s\", ignoring: %m", *ifname);
2120 continue;
2121 }
2122
2123 q = status_ifindex(bus, ifindex, NULL, STATUS_ALL, &empty_line);
2124 if (q < 0)
2125 r = q;
2126 }
2127 } else
2128 r = status_all(bus, STATUS_ALL);
2129
2130 return r;
2131 }
2132
2133 static int call_dns(sd_bus *bus, char **dns, const BusLocator *locator, sd_bus_error *error, bool extended) {
2134 _cleanup_(sd_bus_message_unrefp) sd_bus_message *req = NULL;
2135 int r;
2136
2137 r = bus_message_new_method_call(bus, &req, locator, extended ? "SetLinkDNSEx" : "SetLinkDNS");
2138 if (r < 0)
2139 return bus_log_create_error(r);
2140
2141 r = sd_bus_message_append(req, "i", arg_ifindex);
2142 if (r < 0)
2143 return bus_log_create_error(r);
2144
2145 r = sd_bus_message_open_container(req, 'a', extended ? "(iayqs)" : "(iay)");
2146 if (r < 0)
2147 return bus_log_create_error(r);
2148
2149 /* If only argument is the empty string, then call SetLinkDNS() with an
2150 * empty list, which will clear the list of domains for an interface. */
2151 if (!strv_equal(dns, STRV_MAKE("")))
2152 STRV_FOREACH(p, dns) {
2153 _cleanup_free_ char *name = NULL;
2154 struct in_addr_data data;
2155 uint16_t port;
2156 int ifindex;
2157
2158 r = in_addr_port_ifindex_name_from_string_auto(*p, &data.family, &data.address, &port, &ifindex, &name);
2159 if (r < 0)
2160 return log_error_errno(r, "Failed to parse DNS server address: %s", *p);
2161
2162 if (ifindex != 0 && ifindex != arg_ifindex)
2163 return log_error_errno(SYNTHETIC_ERRNO(EINVAL), "Invalid ifindex: %i", ifindex);
2164
2165 r = sd_bus_message_open_container(req, 'r', extended ? "iayqs" : "iay");
2166 if (r < 0)
2167 return bus_log_create_error(r);
2168
2169 r = sd_bus_message_append(req, "i", data.family);
2170 if (r < 0)
2171 return bus_log_create_error(r);
2172
2173 r = sd_bus_message_append_array(req, 'y', &data.address, FAMILY_ADDRESS_SIZE(data.family));
2174 if (r < 0)
2175 return bus_log_create_error(r);
2176
2177 if (extended) {
2178 r = sd_bus_message_append(req, "q", port);
2179 if (r < 0)
2180 return bus_log_create_error(r);
2181
2182 r = sd_bus_message_append(req, "s", name);
2183 if (r < 0)
2184 return bus_log_create_error(r);
2185 }
2186
2187 r = sd_bus_message_close_container(req);
2188 if (r < 0)
2189 return bus_log_create_error(r);
2190 }
2191
2192 r = sd_bus_message_close_container(req);
2193 if (r < 0)
2194 return bus_log_create_error(r);
2195
2196 r = sd_bus_call(bus, req, 0, error, NULL);
2197 if (r < 0 && extended && sd_bus_error_has_name(error, SD_BUS_ERROR_UNKNOWN_METHOD)) {
2198 sd_bus_error_free(error);
2199 return call_dns(bus, dns, locator, error, false);
2200 }
2201 return r;
2202 }
2203
2204 static int verb_dns(int argc, char **argv, void *userdata) {
2205 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2206 sd_bus *bus = ASSERT_PTR(userdata);
2207 int r;
2208
2209 if (argc >= 2) {
2210 r = ifname_mangle(argv[1]);
2211 if (r < 0)
2212 return r;
2213 }
2214
2215 if (arg_ifindex <= 0)
2216 return status_all(bus, STATUS_DNS);
2217
2218 if (argc < 3)
2219 return status_ifindex(bus, arg_ifindex, NULL, STATUS_DNS, NULL);
2220
2221 r = call_dns(bus, argv + 2, bus_resolve_mgr, &error, true);
2222 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2223 sd_bus_error_free(&error);
2224
2225 r = call_dns(bus, argv + 2, bus_network_mgr, &error, true);
2226 }
2227 if (r < 0) {
2228 if (arg_ifindex_permissive &&
2229 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2230 return 0;
2231
2232 return log_error_errno(r, "Failed to set DNS configuration: %s", bus_error_message(&error, r));
2233 }
2234
2235 return 0;
2236 }
2237
2238 static int call_domain(sd_bus *bus, char **domain, const BusLocator *locator, sd_bus_error *error) {
2239 _cleanup_(sd_bus_message_unrefp) sd_bus_message *req = NULL;
2240 int r;
2241
2242 r = bus_message_new_method_call(bus, &req, locator, "SetLinkDomains");
2243 if (r < 0)
2244 return bus_log_create_error(r);
2245
2246 r = sd_bus_message_append(req, "i", arg_ifindex);
2247 if (r < 0)
2248 return bus_log_create_error(r);
2249
2250 r = sd_bus_message_open_container(req, 'a', "(sb)");
2251 if (r < 0)
2252 return bus_log_create_error(r);
2253
2254 /* If only argument is the empty string, then call SetLinkDomains() with an
2255 * empty list, which will clear the list of domains for an interface. */
2256 if (!strv_equal(domain, STRV_MAKE("")))
2257 STRV_FOREACH(p, domain) {
2258 const char *n;
2259
2260 n = **p == '~' ? *p + 1 : *p;
2261
2262 r = dns_name_is_valid(n);
2263 if (r < 0)
2264 return log_error_errno(r, "Failed to validate specified domain %s: %m", n);
2265 if (r == 0)
2266 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
2267 "Domain not valid: %s",
2268 n);
2269
2270 r = sd_bus_message_append(req, "(sb)", n, **p == '~');
2271 if (r < 0)
2272 return bus_log_create_error(r);
2273 }
2274
2275 r = sd_bus_message_close_container(req);
2276 if (r < 0)
2277 return bus_log_create_error(r);
2278
2279 return sd_bus_call(bus, req, 0, error, NULL);
2280 }
2281
2282 static int verb_domain(int argc, char **argv, void *userdata) {
2283 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2284 sd_bus *bus = ASSERT_PTR(userdata);
2285 int r;
2286
2287 if (argc >= 2) {
2288 r = ifname_mangle(argv[1]);
2289 if (r < 0)
2290 return r;
2291 }
2292
2293 if (arg_ifindex <= 0)
2294 return status_all(bus, STATUS_DOMAIN);
2295
2296 if (argc < 3)
2297 return status_ifindex(bus, arg_ifindex, NULL, STATUS_DOMAIN, NULL);
2298
2299 r = call_domain(bus, argv + 2, bus_resolve_mgr, &error);
2300 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2301 sd_bus_error_free(&error);
2302
2303 r = call_domain(bus, argv + 2, bus_network_mgr, &error);
2304 }
2305 if (r < 0) {
2306 if (arg_ifindex_permissive &&
2307 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2308 return 0;
2309
2310 return log_error_errno(r, "Failed to set domain configuration: %s", bus_error_message(&error, r));
2311 }
2312
2313 return 0;
2314 }
2315
2316 static int verb_default_route(int argc, char **argv, void *userdata) {
2317 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2318 sd_bus *bus = ASSERT_PTR(userdata);
2319 int r, b;
2320
2321 if (argc >= 2) {
2322 r = ifname_mangle(argv[1]);
2323 if (r < 0)
2324 return r;
2325 }
2326
2327 if (arg_ifindex <= 0)
2328 return status_all(bus, STATUS_DEFAULT_ROUTE);
2329
2330 if (argc < 3)
2331 return status_ifindex(bus, arg_ifindex, NULL, STATUS_DEFAULT_ROUTE, NULL);
2332
2333 b = parse_boolean(argv[2]);
2334 if (b < 0)
2335 return log_error_errno(b, "Failed to parse boolean argument: %s", argv[2]);
2336
2337 r = bus_call_method(bus, bus_resolve_mgr, "SetLinkDefaultRoute", &error, NULL, "ib", arg_ifindex, b);
2338 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2339 sd_bus_error_free(&error);
2340
2341 r = bus_call_method(bus, bus_network_mgr, "SetLinkDefaultRoute", &error, NULL, "ib", arg_ifindex, b);
2342 }
2343 if (r < 0) {
2344 if (arg_ifindex_permissive &&
2345 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2346 return 0;
2347
2348 return log_error_errno(r, "Failed to set default route configuration: %s", bus_error_message(&error, r));
2349 }
2350
2351 return 0;
2352 }
2353
2354 static int verb_llmnr(int argc, char **argv, void *userdata) {
2355 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2356 _cleanup_free_ char *global_llmnr_support_str = NULL;
2357 ResolveSupport global_llmnr_support, llmnr_support;
2358 sd_bus *bus = ASSERT_PTR(userdata);
2359 int r;
2360
2361 if (argc >= 2) {
2362 r = ifname_mangle(argv[1]);
2363 if (r < 0)
2364 return r;
2365 }
2366
2367 if (arg_ifindex <= 0)
2368 return status_all(bus, STATUS_LLMNR);
2369
2370 if (argc < 3)
2371 return status_ifindex(bus, arg_ifindex, NULL, STATUS_LLMNR, NULL);
2372
2373 llmnr_support = resolve_support_from_string(argv[2]);
2374 if (llmnr_support < 0)
2375 return log_error_errno(llmnr_support, "Invalid LLMNR setting: %s", argv[2]);
2376
2377 r = bus_get_property_string(bus, bus_resolve_mgr, "LLMNR", &error, &global_llmnr_support_str);
2378 if (r < 0)
2379 return log_error_errno(r, "Failed to get the global LLMNR support state: %s", bus_error_message(&error, r));
2380
2381 global_llmnr_support = resolve_support_from_string(global_llmnr_support_str);
2382 if (global_llmnr_support < 0)
2383 return log_error_errno(global_llmnr_support, "Received invalid global LLMNR setting: %s", global_llmnr_support_str);
2384
2385 if (global_llmnr_support < llmnr_support)
2386 log_warning("Setting LLMNR support level \"%s\" for \"%s\", but the global support level is \"%s\".",
2387 argv[2], arg_ifname, global_llmnr_support_str);
2388
2389 r = bus_call_method(bus, bus_resolve_mgr, "SetLinkLLMNR", &error, NULL, "is", arg_ifindex, argv[2]);
2390 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2391 sd_bus_error_free(&error);
2392
2393 r = bus_call_method(bus, bus_network_mgr, "SetLinkLLMNR", &error, NULL, "is", arg_ifindex, argv[2]);
2394 }
2395 if (r < 0) {
2396 if (arg_ifindex_permissive &&
2397 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2398 return 0;
2399
2400 return log_error_errno(r, "Failed to set LLMNR configuration: %s", bus_error_message(&error, r));
2401 }
2402
2403 return 0;
2404 }
2405
2406 static int verb_mdns(int argc, char **argv, void *userdata) {
2407 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2408 _cleanup_free_ char *global_mdns_support_str = NULL;
2409 ResolveSupport global_mdns_support, mdns_support;
2410 sd_bus *bus = ASSERT_PTR(userdata);
2411 int r;
2412
2413 if (argc >= 2) {
2414 r = ifname_mangle(argv[1]);
2415 if (r < 0)
2416 return r;
2417 }
2418
2419 if (arg_ifindex <= 0)
2420 return status_all(bus, STATUS_MDNS);
2421
2422 if (argc < 3)
2423 return status_ifindex(bus, arg_ifindex, NULL, STATUS_MDNS, NULL);
2424
2425 mdns_support = resolve_support_from_string(argv[2]);
2426 if (mdns_support < 0)
2427 return log_error_errno(mdns_support, "Invalid mDNS setting: %s", argv[2]);
2428
2429 r = bus_get_property_string(bus, bus_resolve_mgr, "MulticastDNS", &error, &global_mdns_support_str);
2430 if (r < 0)
2431 return log_error_errno(r, "Failed to get the global mDNS support state: %s", bus_error_message(&error, r));
2432
2433 global_mdns_support = resolve_support_from_string(global_mdns_support_str);
2434 if (global_mdns_support < 0)
2435 return log_error_errno(global_mdns_support, "Received invalid global mDNS setting: %s", global_mdns_support_str);
2436
2437 if (global_mdns_support < mdns_support)
2438 log_warning("Setting mDNS support level \"%s\" for \"%s\", but the global support level is \"%s\".",
2439 argv[2], arg_ifname, global_mdns_support_str);
2440
2441 r = bus_call_method(bus, bus_resolve_mgr, "SetLinkMulticastDNS", &error, NULL, "is", arg_ifindex, argv[2]);
2442 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2443 sd_bus_error_free(&error);
2444
2445 r = bus_call_method(
2446 bus,
2447 bus_network_mgr,
2448 "SetLinkMulticastDNS",
2449 &error,
2450 NULL,
2451 "is", arg_ifindex, argv[2]);
2452 }
2453 if (r < 0) {
2454 if (arg_ifindex_permissive &&
2455 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2456 return 0;
2457
2458 return log_error_errno(r, "Failed to set MulticastDNS configuration: %s", bus_error_message(&error, r));
2459 }
2460
2461 return 0;
2462 }
2463
2464 static int verb_dns_over_tls(int argc, char **argv, void *userdata) {
2465 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2466 sd_bus *bus = ASSERT_PTR(userdata);
2467 int r;
2468
2469 if (argc >= 2) {
2470 r = ifname_mangle(argv[1]);
2471 if (r < 0)
2472 return r;
2473 }
2474
2475 if (arg_ifindex <= 0)
2476 return status_all(bus, STATUS_PRIVATE);
2477
2478 if (argc < 3)
2479 return status_ifindex(bus, arg_ifindex, NULL, STATUS_PRIVATE, NULL);
2480
2481 r = bus_call_method(bus, bus_resolve_mgr, "SetLinkDNSOverTLS", &error, NULL, "is", arg_ifindex, argv[2]);
2482 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2483 sd_bus_error_free(&error);
2484
2485 r = bus_call_method(
2486 bus,
2487 bus_network_mgr,
2488 "SetLinkDNSOverTLS",
2489 &error,
2490 NULL,
2491 "is", arg_ifindex, argv[2]);
2492 }
2493 if (r < 0) {
2494 if (arg_ifindex_permissive &&
2495 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2496 return 0;
2497
2498 return log_error_errno(r, "Failed to set DNSOverTLS configuration: %s", bus_error_message(&error, r));
2499 }
2500
2501 return 0;
2502 }
2503
2504 static int verb_dnssec(int argc, char **argv, void *userdata) {
2505 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2506 sd_bus *bus = ASSERT_PTR(userdata);
2507 int r;
2508
2509 if (argc >= 2) {
2510 r = ifname_mangle(argv[1]);
2511 if (r < 0)
2512 return r;
2513 }
2514
2515 if (arg_ifindex <= 0)
2516 return status_all(bus, STATUS_DNSSEC);
2517
2518 if (argc < 3)
2519 return status_ifindex(bus, arg_ifindex, NULL, STATUS_DNSSEC, NULL);
2520
2521 r = bus_call_method(bus, bus_resolve_mgr, "SetLinkDNSSEC", &error, NULL, "is", arg_ifindex, argv[2]);
2522 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2523 sd_bus_error_free(&error);
2524
2525 r = bus_call_method(bus, bus_network_mgr, "SetLinkDNSSEC", &error, NULL, "is", arg_ifindex, argv[2]);
2526 }
2527 if (r < 0) {
2528 if (arg_ifindex_permissive &&
2529 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2530 return 0;
2531
2532 return log_error_errno(r, "Failed to set DNSSEC configuration: %s", bus_error_message(&error, r));
2533 }
2534
2535 return 0;
2536 }
2537
2538 static int call_nta(sd_bus *bus, char **nta, const BusLocator *locator, sd_bus_error *error) {
2539 _cleanup_(sd_bus_message_unrefp) sd_bus_message *req = NULL;
2540 int r;
2541
2542 r = bus_message_new_method_call(bus, &req, locator, "SetLinkDNSSECNegativeTrustAnchors");
2543 if (r < 0)
2544 return bus_log_create_error(r);
2545
2546 r = sd_bus_message_append(req, "i", arg_ifindex);
2547 if (r < 0)
2548 return bus_log_create_error(r);
2549
2550 r = sd_bus_message_append_strv(req, nta);
2551 if (r < 0)
2552 return bus_log_create_error(r);
2553
2554 return sd_bus_call(bus, req, 0, error, NULL);
2555 }
2556
2557 static int verb_nta(int argc, char **argv, void *userdata) {
2558 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2559 sd_bus *bus = ASSERT_PTR(userdata);
2560 int r;
2561 bool clear;
2562
2563 if (argc >= 2) {
2564 r = ifname_mangle(argv[1]);
2565 if (r < 0)
2566 return r;
2567 }
2568
2569 if (arg_ifindex <= 0)
2570 return status_all(bus, STATUS_NTA);
2571
2572 if (argc < 3)
2573 return status_ifindex(bus, arg_ifindex, NULL, STATUS_NTA, NULL);
2574
2575 /* If only argument is the empty string, then call SetLinkDNSSECNegativeTrustAnchors()
2576 * with an empty list, which will clear the list of domains for an interface. */
2577 clear = strv_equal(argv + 2, STRV_MAKE(""));
2578
2579 if (!clear)
2580 STRV_FOREACH(p, argv + 2) {
2581 r = dns_name_is_valid(*p);
2582 if (r < 0)
2583 return log_error_errno(r, "Failed to validate specified domain %s: %m", *p);
2584 if (r == 0)
2585 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
2586 "Domain not valid: %s",
2587 *p);
2588 }
2589
2590 r = call_nta(bus, clear ? NULL : argv + 2, bus_resolve_mgr, &error);
2591 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2592 sd_bus_error_free(&error);
2593
2594 r = call_nta(bus, clear ? NULL : argv + 2, bus_network_mgr, &error);
2595 }
2596 if (r < 0) {
2597 if (arg_ifindex_permissive &&
2598 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2599 return 0;
2600
2601 return log_error_errno(r, "Failed to set DNSSEC NTA configuration: %s", bus_error_message(&error, r));
2602 }
2603
2604 return 0;
2605 }
2606
2607 static int verb_revert_link(int argc, char **argv, void *userdata) {
2608 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
2609 sd_bus *bus = ASSERT_PTR(userdata);
2610 int r;
2611
2612 if (argc >= 2) {
2613 r = ifname_mangle(argv[1]);
2614 if (r < 0)
2615 return r;
2616 }
2617
2618 if (arg_ifindex <= 0)
2619 return log_error_errno(SYNTHETIC_ERRNO(EINVAL), "Interface argument required.");
2620
2621 r = bus_call_method(bus, bus_resolve_mgr, "RevertLink", &error, NULL, "i", arg_ifindex);
2622 if (r < 0 && sd_bus_error_has_name(&error, BUS_ERROR_LINK_BUSY)) {
2623 sd_bus_error_free(&error);
2624
2625 r = bus_call_method(bus, bus_network_mgr, "RevertLinkDNS", &error, NULL, "i", arg_ifindex);
2626 }
2627 if (r < 0) {
2628 if (arg_ifindex_permissive &&
2629 sd_bus_error_has_name(&error, BUS_ERROR_NO_SUCH_LINK))
2630 return 0;
2631
2632 return log_error_errno(r, "Failed to revert interface configuration: %s", bus_error_message(&error, r));
2633 }
2634
2635 return 0;
2636 }
2637
2638 static int verb_log_level(int argc, char *argv[], void *userdata) {
2639 sd_bus *bus = ASSERT_PTR(userdata);
2640
2641 assert(IN_SET(argc, 1, 2));
2642
2643 return verb_log_control_common(bus, "org.freedesktop.resolve1", argv[0], argc == 2 ? argv[1] : NULL);
2644 }
2645
2646 static int print_question(char prefix, const char *color, JsonVariant *question) {
2647 JsonVariant *q = NULL;
2648 int r;
2649
2650 assert(color);
2651
2652 JSON_VARIANT_ARRAY_FOREACH(q, question) {
2653 _cleanup_(dns_resource_key_unrefp) DnsResourceKey *key = NULL;
2654 char buf[DNS_RESOURCE_KEY_STRING_MAX];
2655
2656 r = dns_resource_key_from_json(q, &key);
2657 if (r < 0) {
2658 log_warning_errno(r, "Received monitor message with invalid question key, ignoring: %m");
2659 continue;
2660 }
2661
2662 printf("%s%s %c%s: %s\n",
2663 color,
2664 special_glyph(SPECIAL_GLYPH_ARROW_RIGHT),
2665 prefix,
2666 ansi_normal(),
2667 dns_resource_key_to_string(key, buf, sizeof(buf)));
2668 }
2669
2670 return 0;
2671 }
2672
2673 static int print_answer(JsonVariant *answer) {
2674 JsonVariant *a;
2675 int r;
2676
2677 JSON_VARIANT_ARRAY_FOREACH(a, answer) {
2678 _cleanup_(dns_resource_record_unrefp) DnsResourceRecord *rr = NULL;
2679 _cleanup_free_ void *d = NULL;
2680 JsonVariant *jraw;
2681 const char *s;
2682 size_t l;
2683
2684 jraw = json_variant_by_key(a, "raw");
2685 if (!jraw) {
2686 log_warning("Received monitor answer lacking valid raw data, ignoring.");
2687 continue;
2688 }
2689
2690 r = json_variant_unbase64(jraw, &d, &l);
2691 if (r < 0) {
2692 log_warning_errno(r, "Failed to undo base64 encoding of monitor answer raw data, ignoring.");
2693 continue;
2694 }
2695
2696 r = dns_resource_record_new_from_raw(&rr, d, l);
2697 if (r < 0) {
2698 log_warning_errno(r, "Failed to parse monitor answer RR, ignoring: %m");
2699 continue;
2700 }
2701
2702 s = dns_resource_record_to_string(rr);
2703 if (!s)
2704 return log_oom();
2705
2706 printf("%s%s A%s: %s\n",
2707 ansi_highlight_yellow(),
2708 special_glyph(SPECIAL_GLYPH_ARROW_LEFT),
2709 ansi_normal(),
2710 s);
2711 }
2712
2713 return 0;
2714 }
2715
2716 static void monitor_query_dump(JsonVariant *v) {
2717 _cleanup_(json_variant_unrefp) JsonVariant *question = NULL, *answer = NULL, *collected_questions = NULL;
2718 int rcode = -1, error = 0, ede_code = -1;
2719 const char *state = NULL, *result = NULL, *ede_msg = NULL;
2720
2721 assert(v);
2722
2723 JsonDispatch dispatch_table[] = {
2724 { "question", JSON_VARIANT_ARRAY, json_dispatch_variant, PTR_TO_SIZE(&question), JSON_MANDATORY },
2725 { "answer", JSON_VARIANT_ARRAY, json_dispatch_variant, PTR_TO_SIZE(&answer), 0 },
2726 { "collectedQuestions", JSON_VARIANT_ARRAY, json_dispatch_variant, PTR_TO_SIZE(&collected_questions), 0 },
2727 { "state", JSON_VARIANT_STRING, json_dispatch_const_string, PTR_TO_SIZE(&state), JSON_MANDATORY },
2728 { "result", JSON_VARIANT_STRING, json_dispatch_const_string, PTR_TO_SIZE(&result), 0 },
2729 { "rcode", _JSON_VARIANT_TYPE_INVALID, json_dispatch_int, PTR_TO_SIZE(&rcode), 0 },
2730 { "errno", _JSON_VARIANT_TYPE_INVALID, json_dispatch_int, PTR_TO_SIZE(&error), 0 },
2731 { "extendedDNSErrorCode", _JSON_VARIANT_TYPE_INVALID, json_dispatch_int, PTR_TO_SIZE(&ede_code), 0 },
2732 { "extendedDNSErrorMessage", JSON_VARIANT_STRING, json_dispatch_const_string, PTR_TO_SIZE(&ede_msg), 0 },
2733 {}
2734 };
2735
2736 if (json_dispatch(v, dispatch_table, JSON_LOG|JSON_ALLOW_EXTENSIONS, NULL) < 0)
2737 return;
2738
2739 /* First show the current question */
2740 print_question('Q', ansi_highlight_cyan(), question);
2741
2742 /* And then show the questions that led to this one in case this was a CNAME chain */
2743 print_question('C', ansi_highlight_grey(), collected_questions);
2744
2745 printf("%s%s S%s: %s",
2746 streq_ptr(state, "success") ? ansi_highlight_green() : ansi_highlight_red(),
2747 special_glyph(SPECIAL_GLYPH_ARROW_LEFT),
2748 ansi_normal(),
2749 strna(streq_ptr(state, "errno") ? errno_to_name(error) :
2750 streq_ptr(state, "rcode-failure") ? dns_rcode_to_string(rcode) :
2751 state));
2752
2753 if (!isempty(result))
2754 printf(": %s", result);
2755
2756 if (ede_code >= 0)
2757 printf(" (%s%s%s)",
2758 FORMAT_DNS_EDE_RCODE(ede_code),
2759 !isempty(ede_msg) ? ": " : "",
2760 strempty(ede_msg));
2761
2762 puts("");
2763
2764 print_answer(answer);
2765 }
2766
2767 static int monitor_reply(
2768 Varlink *link,
2769 JsonVariant *parameters,
2770 const char *error_id,
2771 VarlinkReplyFlags flags,
2772 void *userdata) {
2773
2774 assert(link);
2775
2776 if (error_id) {
2777 bool disconnect;
2778
2779 disconnect = streq(error_id, VARLINK_ERROR_DISCONNECTED);
2780 if (disconnect)
2781 log_info("Disconnected.");
2782 else
2783 log_error("Varlink error: %s", error_id);
2784
2785 (void) sd_event_exit(ASSERT_PTR(varlink_get_event(link)), disconnect ? EXIT_SUCCESS : EXIT_FAILURE);
2786 return 0;
2787 }
2788
2789 if (json_variant_by_key(parameters, "ready")) {
2790 /* The first message coming in will just indicate that we are now subscribed. We let our
2791 * caller know if they asked for it. Once the caller sees this they should know that we are
2792 * not going to miss any queries anymore. */
2793 (void) sd_notify(/* unset_environment=false */ false, "READY=1");
2794 return 0;
2795 }
2796
2797 if (arg_json_format_flags & JSON_FORMAT_OFF) {
2798 monitor_query_dump(parameters);
2799 printf("\n");
2800 } else
2801 json_variant_dump(parameters, arg_json_format_flags, NULL, NULL);
2802
2803 fflush(stdout);
2804
2805 return 0;
2806 }
2807
2808 static int verb_monitor(int argc, char *argv[], void *userdata) {
2809 _cleanup_(sd_event_unrefp) sd_event *event = NULL;
2810 _cleanup_(varlink_unrefp) Varlink *vl = NULL;
2811 int r, c;
2812
2813 r = sd_event_default(&event);
2814 if (r < 0)
2815 return log_error_errno(r, "Failed to get event loop: %m");
2816
2817 r = sd_event_set_signal_exit(event, true);
2818 if (r < 0)
2819 return log_error_errno(r, "Failed to enable exit on SIGINT/SIGTERM: %m");
2820
2821 r = varlink_connect_address(&vl, "/run/systemd/resolve/io.systemd.Resolve.Monitor");
2822 if (r < 0)
2823 return log_error_errno(r, "Failed to connect to query monitoring service /run/systemd/resolve/io.systemd.Resolve.Monitor: %m");
2824
2825 r = varlink_set_relative_timeout(vl, USEC_INFINITY); /* We want the monitor to run basically forever */
2826 if (r < 0)
2827 return log_error_errno(r, "Failed to set varlink time-out: %m");
2828
2829 r = varlink_attach_event(vl, event, SD_EVENT_PRIORITY_NORMAL);
2830 if (r < 0)
2831 return log_error_errno(r, "Failed to attach varlink connection to event loop: %m");
2832
2833 r = varlink_bind_reply(vl, monitor_reply);
2834 if (r < 0)
2835 return log_error_errno(r, "Failed to bind reply callback to varlink connection: %m");
2836
2837 r = varlink_observe(vl, "io.systemd.Resolve.Monitor.SubscribeQueryResults", NULL);
2838 if (r < 0)
2839 return log_error_errno(r, "Failed to issue SubscribeQueryResults() varlink call: %m");
2840
2841 r = sd_event_loop(event);
2842 if (r < 0)
2843 return log_error_errno(r, "Failed to run event loop: %m");
2844
2845 r = sd_event_get_exit_code(event, &c);
2846 if (r < 0)
2847 return log_error_errno(r, "Failed to get exit code: %m");
2848
2849 return c;
2850 }
2851
2852 static int dump_cache_item(JsonVariant *item) {
2853
2854 struct item_info {
2855 JsonVariant *key;
2856 JsonVariant *rrs;
2857 const char *type;
2858 uint64_t until;
2859 } item_info = {};
2860
2861 static const JsonDispatch dispatch_table[] = {
2862 { "key", JSON_VARIANT_OBJECT, json_dispatch_variant_noref, offsetof(struct item_info, key), JSON_MANDATORY },
2863 { "rrs", JSON_VARIANT_ARRAY, json_dispatch_variant_noref, offsetof(struct item_info, rrs), 0 },
2864 { "type", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct item_info, type), 0 },
2865 { "until", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct item_info, until), 0 },
2866 {},
2867 };
2868
2869 _cleanup_(dns_resource_key_unrefp) DnsResourceKey *k = NULL;
2870 int r, c = 0;
2871
2872 r = json_dispatch(item, dispatch_table, JSON_LOG|JSON_ALLOW_EXTENSIONS, &item_info);
2873 if (r < 0)
2874 return r;
2875
2876 r = dns_resource_key_from_json(item_info.key, &k);
2877 if (r < 0)
2878 return log_error_errno(r, "Failed to turn JSON data to resource key: %m");
2879
2880 if (item_info.type)
2881 printf("%s %s%s%s\n", DNS_RESOURCE_KEY_TO_STRING(k), ansi_highlight_red(), item_info.type, ansi_normal());
2882 else {
2883 JsonVariant *i;
2884
2885 JSON_VARIANT_ARRAY_FOREACH(i, item_info.rrs) {
2886 _cleanup_(dns_resource_record_unrefp) DnsResourceRecord *rr = NULL;
2887 _cleanup_free_ void *data = NULL;
2888 JsonVariant *raw;
2889 size_t size;
2890
2891 raw = json_variant_by_key(i, "raw");
2892 if (!raw)
2893 return log_error_errno(SYNTHETIC_ERRNO(ENOTRECOVERABLE), "raw field missing from RR JSON data.");
2894
2895 r = json_variant_unbase64(raw, &data, &size);
2896 if (r < 0)
2897 return log_error_errno(r, "Unable to decode raw RR JSON data: %m");
2898
2899 r = dns_resource_record_new_from_raw(&rr, data, size);
2900 if (r < 0)
2901 return log_error_errno(r, "Failed to parse DNS data: %m");
2902
2903 printf("%s\n", dns_resource_record_to_string(rr));
2904 c++;
2905 }
2906 }
2907
2908 return c;
2909 }
2910
2911 static int dump_cache_scope(JsonVariant *scope) {
2912
2913 struct scope_info {
2914 const char *protocol;
2915 int family;
2916 int ifindex;
2917 const char *ifname;
2918 JsonVariant *cache;
2919 } scope_info = {
2920 .family = AF_UNSPEC,
2921 };
2922 JsonVariant *i;
2923 int r, c = 0;
2924
2925 static const JsonDispatch dispatch_table[] = {
2926 { "protocol", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct scope_info, protocol), JSON_MANDATORY },
2927 { "family", _JSON_VARIANT_TYPE_INVALID, json_dispatch_int, offsetof(struct scope_info, family), 0 },
2928 { "ifindex", _JSON_VARIANT_TYPE_INVALID, json_dispatch_int, offsetof(struct scope_info, ifindex), 0 },
2929 { "ifname", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct scope_info, ifname), 0 },
2930 { "cache", JSON_VARIANT_ARRAY, json_dispatch_variant_noref, offsetof(struct scope_info, cache), JSON_MANDATORY },
2931 {},
2932 };
2933
2934 r = json_dispatch(scope, dispatch_table, JSON_LOG|JSON_ALLOW_EXTENSIONS, &scope_info);
2935 if (r < 0)
2936 return r;
2937
2938 printf("%sScope protocol=%s", ansi_underline(), scope_info.protocol);
2939
2940 if (scope_info.family != AF_UNSPEC)
2941 printf(" family=%s", af_to_name(scope_info.family));
2942
2943 if (scope_info.ifindex > 0)
2944 printf(" ifindex=%i", scope_info.ifindex);
2945 if (scope_info.ifname)
2946 printf(" ifname=%s", scope_info.ifname);
2947
2948 printf("%s\n", ansi_normal());
2949
2950 JSON_VARIANT_ARRAY_FOREACH(i, scope_info.cache) {
2951 r = dump_cache_item(i);
2952 if (r < 0)
2953 return r;
2954
2955 c += r;
2956 }
2957
2958 if (c == 0)
2959 printf("%sNo entries.%s\n\n", ansi_grey(), ansi_normal());
2960 else
2961 printf("\n");
2962
2963 return 0;
2964 }
2965
2966 static int verb_show_cache(int argc, char *argv[], void *userdata) {
2967 JsonVariant *reply = NULL, *d = NULL;
2968 _cleanup_(varlink_unrefp) Varlink *vl = NULL;
2969 int r;
2970
2971 r = varlink_connect_address(&vl, "/run/systemd/resolve/io.systemd.Resolve.Monitor");
2972 if (r < 0)
2973 return log_error_errno(r, "Failed to connect to query monitoring service /run/systemd/resolve/io.systemd.Resolve.Monitor: %m");
2974
2975 r = varlink_call_and_log(vl, "io.systemd.Resolve.Monitor.DumpCache", /* parameters= */ NULL, &reply);
2976 if (r < 0)
2977 return r;
2978
2979 d = json_variant_by_key(reply, "dump");
2980 if (!d)
2981 return log_error_errno(SYNTHETIC_ERRNO(ENOTRECOVERABLE),
2982 "DumpCache() response is missing 'dump' key.");
2983
2984 if (!json_variant_is_array(d))
2985 return log_error_errno(SYNTHETIC_ERRNO(ENOTRECOVERABLE),
2986 "DumpCache() response 'dump' field not an array");
2987
2988 if (FLAGS_SET(arg_json_format_flags, JSON_FORMAT_OFF)) {
2989 JsonVariant *i;
2990
2991 JSON_VARIANT_ARRAY_FOREACH(i, d) {
2992 r = dump_cache_scope(i);
2993 if (r < 0)
2994 return r;
2995 }
2996
2997 return 0;
2998 }
2999
3000 return json_variant_dump(d, arg_json_format_flags, NULL, NULL);
3001 }
3002
3003 static int dump_server_state(JsonVariant *server) {
3004 _cleanup_(table_unrefp) Table *table = NULL;
3005 TableCell *cell;
3006
3007 struct server_state {
3008 const char *server_name;
3009 const char *type;
3010 const char *ifname;
3011 int ifindex;
3012 const char *verified_feature_level;
3013 const char *possible_feature_level;
3014 const char *dnssec_mode;
3015 bool dnssec_supported;
3016 size_t received_udp_fragment_max;
3017 uint64_t n_failed_udp;
3018 uint64_t n_failed_tcp;
3019 bool packet_truncated;
3020 bool packet_bad_opt;
3021 bool packet_rrsig_missing;
3022 bool packet_invalid;
3023 bool packet_do_off;
3024 } server_state = {
3025 .ifindex = -1,
3026 };
3027
3028 int r;
3029
3030 static const JsonDispatch dispatch_table[] = {
3031 { "Server", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct server_state, server_name), JSON_MANDATORY },
3032 { "Type", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct server_state, type), JSON_MANDATORY },
3033 { "Interface", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct server_state, ifname), 0 },
3034 { "InterfaceIndex", _JSON_VARIANT_TYPE_INVALID, json_dispatch_int, offsetof(struct server_state, ifindex), 0 },
3035 { "VerifiedFeatureLevel", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct server_state, verified_feature_level), 0 },
3036 { "PossibleFeatureLevel", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct server_state, possible_feature_level), 0 },
3037 { "DNSSECMode", JSON_VARIANT_STRING, json_dispatch_const_string, offsetof(struct server_state, dnssec_mode), JSON_MANDATORY },
3038 { "DNSSECSupported", JSON_VARIANT_BOOLEAN, json_dispatch_boolean, offsetof(struct server_state, dnssec_supported), JSON_MANDATORY },
3039 { "ReceivedUDPFragmentMax", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct server_state, received_udp_fragment_max), JSON_MANDATORY },
3040 { "FailedUDPAttempts", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct server_state, n_failed_udp), JSON_MANDATORY },
3041 { "FailedTCPAttempts", _JSON_VARIANT_TYPE_INVALID, json_dispatch_uint64, offsetof(struct server_state, n_failed_tcp), JSON_MANDATORY },
3042 { "PacketTruncated", JSON_VARIANT_BOOLEAN, json_dispatch_boolean, offsetof(struct server_state, packet_truncated), JSON_MANDATORY },
3043 { "PacketBadOpt", JSON_VARIANT_BOOLEAN, json_dispatch_boolean, offsetof(struct server_state, packet_bad_opt), JSON_MANDATORY },
3044 { "PacketRRSIGMissing", JSON_VARIANT_BOOLEAN, json_dispatch_boolean, offsetof(struct server_state, packet_rrsig_missing), JSON_MANDATORY },
3045 { "PacketInvalid", JSON_VARIANT_BOOLEAN, json_dispatch_boolean, offsetof(struct server_state, packet_invalid), JSON_MANDATORY },
3046 { "PacketDoOff", JSON_VARIANT_BOOLEAN, json_dispatch_boolean, offsetof(struct server_state, packet_do_off), JSON_MANDATORY },
3047 {},
3048 };
3049
3050 r = json_dispatch(server, dispatch_table, JSON_LOG|JSON_ALLOW_EXTENSIONS, &server_state);
3051 if (r < 0)
3052 return r;
3053
3054 table = table_new_vertical();
3055 if (!table)
3056 return log_oom();
3057
3058 assert_se(cell = table_get_cell(table, 0, 0));
3059 (void) table_set_ellipsize_percent(table, cell, 100);
3060 (void) table_set_align_percent(table, cell, 0);
3061
3062 r = table_add_cell_stringf(table, NULL, "Server: %s", server_state.server_name);
3063 if (r < 0)
3064 return table_log_add_error(r);
3065
3066 r = table_add_many(table,
3067 TABLE_EMPTY,
3068 TABLE_FIELD, "Type",
3069 TABLE_SET_ALIGN_PERCENT, 100,
3070 TABLE_STRING, server_state.type);
3071 if (r < 0)
3072 return table_log_add_error(r);
3073
3074 if (server_state.ifname) {
3075 r = table_add_many(table,
3076 TABLE_FIELD, "Interface",
3077 TABLE_STRING, server_state.ifname);
3078 if (r < 0)
3079 return table_log_add_error(r);
3080 }
3081
3082 if (server_state.ifindex >= 0) {
3083 r = table_add_many(table,
3084 TABLE_FIELD, "Interface Index",
3085 TABLE_INT, server_state.ifindex);
3086 if (r < 0)
3087 return table_log_add_error(r);
3088 }
3089
3090 if (server_state.verified_feature_level) {
3091 r = table_add_many(table,
3092 TABLE_FIELD, "Verified feature level",
3093 TABLE_STRING, server_state.verified_feature_level);
3094 if (r < 0)
3095 return table_log_add_error(r);
3096 }
3097
3098 if (server_state.possible_feature_level) {
3099 r = table_add_many(table,
3100 TABLE_FIELD, "Possible feature level",
3101 TABLE_STRING, server_state.possible_feature_level);
3102 if (r < 0)
3103 return table_log_add_error(r);
3104 }
3105
3106 r = table_add_many(table,
3107 TABLE_FIELD, "DNSSEC Mode",
3108 TABLE_STRING, server_state.dnssec_mode,
3109 TABLE_FIELD, "DNSSEC Supported",
3110 TABLE_STRING, yes_no(server_state.dnssec_supported),
3111 TABLE_FIELD, "Maximum UDP fragment size received",
3112 TABLE_UINT64, server_state.received_udp_fragment_max,
3113 TABLE_FIELD, "Failed UDP attempts",
3114 TABLE_UINT64, server_state.n_failed_udp,
3115 TABLE_FIELD, "Failed TCP attempts",
3116 TABLE_UINT64, server_state.n_failed_tcp,
3117 TABLE_FIELD, "Seen truncated packet",
3118 TABLE_STRING, yes_no(server_state.packet_truncated),
3119 TABLE_FIELD, "Seen OPT RR getting lost",
3120 TABLE_STRING, yes_no(server_state.packet_bad_opt),
3121 TABLE_FIELD, "Seen RRSIG RR missing",
3122 TABLE_STRING, yes_no(server_state.packet_rrsig_missing),
3123 TABLE_FIELD, "Seen invalid packet",
3124 TABLE_STRING, yes_no(server_state.packet_invalid),
3125 TABLE_FIELD, "Server dropped DO flag",
3126 TABLE_STRING, yes_no(server_state.packet_do_off),
3127 TABLE_SET_ALIGN_PERCENT, 0,
3128 TABLE_EMPTY, TABLE_EMPTY);
3129
3130 if (r < 0)
3131 return table_log_add_error(r);
3132
3133 r = table_print(table, NULL);
3134 if (r < 0)
3135 return table_log_print_error(r);
3136
3137 return 0;
3138 }
3139
3140 static int verb_show_server_state(int argc, char *argv[], void *userdata) {
3141 JsonVariant *reply = NULL, *d = NULL;
3142 _cleanup_(varlink_unrefp) Varlink *vl = NULL;
3143 int r;
3144
3145 r = varlink_connect_address(&vl, "/run/systemd/resolve/io.systemd.Resolve.Monitor");
3146 if (r < 0)
3147 return log_error_errno(r, "Failed to connect to query monitoring service /run/systemd/resolve/io.systemd.Resolve.Monitor: %m");
3148
3149 r = varlink_call_and_log(vl, "io.systemd.Resolve.Monitor.DumpServerState", /* parameters= */ NULL, &reply);
3150 if (r < 0)
3151 return r;
3152
3153 d = json_variant_by_key(reply, "dump");
3154 if (!d)
3155 return log_error_errno(SYNTHETIC_ERRNO(ENOTRECOVERABLE),
3156 "DumpCache() response is missing 'dump' key.");
3157
3158 if (!json_variant_is_array(d))
3159 return log_error_errno(SYNTHETIC_ERRNO(ENOTRECOVERABLE),
3160 "DumpCache() response 'dump' field not an array");
3161
3162 if (FLAGS_SET(arg_json_format_flags, JSON_FORMAT_OFF)) {
3163 JsonVariant *i;
3164
3165 JSON_VARIANT_ARRAY_FOREACH(i, d) {
3166 r = dump_server_state(i);
3167 if (r < 0)
3168 return r;
3169 }
3170
3171 return 0;
3172 }
3173
3174 return json_variant_dump(d, arg_json_format_flags, NULL, NULL);
3175 }
3176
3177 static void help_protocol_types(void) {
3178 if (arg_legend)
3179 puts("Known protocol types:");
3180 puts("dns\n"
3181 "llmnr\n"
3182 "llmnr-ipv4\n"
3183 "llmnr-ipv6\n"
3184 "mdns\n"
3185 "mdns-ipv4\n"
3186 "mdns-ipv6");
3187 }
3188
3189 static void help_dns_types(void) {
3190 if (arg_legend)
3191 puts("Known DNS RR types:");
3192
3193 DUMP_STRING_TABLE(dns_type, int, _DNS_TYPE_MAX);
3194 }
3195
3196 static void help_dns_classes(void) {
3197 if (arg_legend)
3198 puts("Known DNS RR classes:");
3199
3200 DUMP_STRING_TABLE(dns_class, int, _DNS_CLASS_MAX);
3201 }
3202
3203 static int compat_help(void) {
3204 _cleanup_free_ char *link = NULL;
3205 int r;
3206
3207 r = terminal_urlify_man("resolvectl", "1", &link);
3208 if (r < 0)
3209 return log_oom();
3210
3211 printf("%1$s [OPTIONS...] HOSTNAME|ADDRESS...\n"
3212 "%1$s [OPTIONS...] --service [[NAME] TYPE] DOMAIN\n"
3213 "%1$s [OPTIONS...] --openpgp EMAIL@DOMAIN...\n"
3214 "%1$s [OPTIONS...] --statistics\n"
3215 "%1$s [OPTIONS...] --reset-statistics\n"
3216 "\n"
3217 "%2$sResolve domain names, IPv4 and IPv6 addresses, DNS records, and services.%3$s\n\n"
3218 " -h --help Show this help\n"
3219 " --version Show package version\n"
3220 " --no-pager Do not pipe output into a pager\n"
3221 " -4 Resolve IPv4 addresses\n"
3222 " -6 Resolve IPv6 addresses\n"
3223 " -i --interface=INTERFACE Look on interface\n"
3224 " -p --protocol=PROTO|help Look via protocol\n"
3225 " -t --type=TYPE|help Query RR with DNS type\n"
3226 " -c --class=CLASS|help Query RR with DNS class\n"
3227 " --service Resolve service (SRV)\n"
3228 " --service-address=BOOL Resolve address for services (default: yes)\n"
3229 " --service-txt=BOOL Resolve TXT records for services (default: yes)\n"
3230 " --openpgp Query OpenPGP public key\n"
3231 " --tlsa Query TLS public key\n"
3232 " --cname=BOOL Follow CNAME redirects (default: yes)\n"
3233 " --search=BOOL Use search domains for single-label names\n"
3234 " (default: yes)\n"
3235 " --raw[=payload|packet] Dump the answer as binary data\n"
3236 " --legend=BOOL Print headers and additional info (default: yes)\n"
3237 " --statistics Show resolver statistics\n"
3238 " --reset-statistics Reset resolver statistics\n"
3239 " --status Show link and server status\n"
3240 " --flush-caches Flush all local DNS caches\n"
3241 " --reset-server-features\n"
3242 " Forget learnt DNS server feature levels\n"
3243 " --set-dns=SERVER Set per-interface DNS server address\n"
3244 " --set-domain=DOMAIN Set per-interface search domain\n"
3245 " --set-llmnr=MODE Set per-interface LLMNR mode\n"
3246 " --set-mdns=MODE Set per-interface MulticastDNS mode\n"
3247 " --set-dnsovertls=MODE Set per-interface DNS-over-TLS mode\n"
3248 " --set-dnssec=MODE Set per-interface DNSSEC mode\n"
3249 " --set-nta=DOMAIN Set per-interface DNSSEC NTA\n"
3250 " --revert Revert per-interface configuration\n"
3251 "\nSee the %4$s for details.\n",
3252 program_invocation_short_name,
3253 ansi_highlight(),
3254 ansi_normal(),
3255 link);
3256
3257 return 0;
3258 }
3259
3260 static int native_help(void) {
3261 _cleanup_free_ char *link = NULL;
3262 int r;
3263
3264 r = terminal_urlify_man("resolvectl", "1", &link);
3265 if (r < 0)
3266 return log_oom();
3267
3268 printf("%s [OPTIONS...] COMMAND ...\n"
3269 "\n"
3270 "%sSend control commands to the network name resolution manager, or%s\n"
3271 "%sresolve domain names, IPv4 and IPv6 addresses, DNS records, and services.%s\n"
3272 "\nCommands:\n"
3273 " query HOSTNAME|ADDRESS... Resolve domain names, IPv4 and IPv6 addresses\n"
3274 " service [[NAME] TYPE] DOMAIN Resolve service (SRV)\n"
3275 " openpgp EMAIL@DOMAIN... Query OpenPGP public key\n"
3276 " tlsa DOMAIN[:PORT]... Query TLS public key\n"
3277 " status [LINK...] Show link and server status\n"
3278 " statistics Show resolver statistics\n"
3279 " reset-statistics Reset resolver statistics\n"
3280 " flush-caches Flush all local DNS caches\n"
3281 " reset-server-features Forget learnt DNS server feature levels\n"
3282 " monitor Monitor DNS queries\n"
3283 " show-cache Show cache contents\n"
3284 " show-server-state Show servers state\n"
3285 " dns [LINK [SERVER...]] Get/set per-interface DNS server address\n"
3286 " domain [LINK [DOMAIN...]] Get/set per-interface search domain\n"
3287 " default-route [LINK [BOOL]] Get/set per-interface default route flag\n"
3288 " llmnr [LINK [MODE]] Get/set per-interface LLMNR mode\n"
3289 " mdns [LINK [MODE]] Get/set per-interface MulticastDNS mode\n"
3290 " dnsovertls [LINK [MODE]] Get/set per-interface DNS-over-TLS mode\n"
3291 " dnssec [LINK [MODE]] Get/set per-interface DNSSEC mode\n"
3292 " nta [LINK [DOMAIN...]] Get/set per-interface DNSSEC NTA\n"
3293 " revert LINK Revert per-interface configuration\n"
3294 " log-level [LEVEL] Get/set logging threshold for systemd-resolved\n"
3295 "\nOptions:\n"
3296 " -h --help Show this help\n"
3297 " --version Show package version\n"
3298 " --no-pager Do not pipe output into a pager\n"
3299 " -4 Resolve IPv4 addresses\n"
3300 " -6 Resolve IPv6 addresses\n"
3301 " -i --interface=INTERFACE Look on interface\n"
3302 " -p --protocol=PROTO|help Look via protocol\n"
3303 " -t --type=TYPE|help Query RR with DNS type\n"
3304 " -c --class=CLASS|help Query RR with DNS class\n"
3305 " --service-address=BOOL Resolve address for services (default: yes)\n"
3306 " --service-txt=BOOL Resolve TXT records for services (default: yes)\n"
3307 " --cname=BOOL Follow CNAME redirects (default: yes)\n"
3308 " --validate=BOOL Allow DNSSEC validation (default: yes)\n"
3309 " --synthesize=BOOL Allow synthetic response (default: yes)\n"
3310 " --cache=BOOL Allow response from cache (default: yes)\n"
3311 " --stale-data=BOOL Allow response from cache with stale data (default: yes)\n"
3312 " --zone=BOOL Allow response from locally registered mDNS/LLMNR\n"
3313 " records (default: yes)\n"
3314 " --trust-anchor=BOOL Allow response from local trust anchor (default:\n"
3315 " yes)\n"
3316 " --network=BOOL Allow response from network (default: yes)\n"
3317 " --search=BOOL Use search domains for single-label names (default:\n"
3318 " yes)\n"
3319 " --raw[=payload|packet] Dump the answer as binary data\n"
3320 " --legend=BOOL Print headers and additional info (default: yes)\n"
3321 " --json=MODE Output as JSON\n"
3322 " -j Same as --json=pretty on tty, --json=short\n"
3323 " otherwise\n"
3324 "\nSee the %s for details.\n",
3325 program_invocation_short_name,
3326 ansi_highlight(),
3327 ansi_normal(),
3328 ansi_highlight(),
3329 ansi_normal(),
3330 link);
3331
3332 return 0;
3333 }
3334
3335 static int verb_help(int argc, char **argv, void *userdata) {
3336 return native_help();
3337 }
3338
3339 static int compat_parse_argv(int argc, char *argv[]) {
3340 enum {
3341 ARG_VERSION = 0x100,
3342 ARG_LEGEND,
3343 ARG_SERVICE,
3344 ARG_CNAME,
3345 ARG_SERVICE_ADDRESS,
3346 ARG_SERVICE_TXT,
3347 ARG_OPENPGP,
3348 ARG_TLSA,
3349 ARG_RAW,
3350 ARG_SEARCH,
3351 ARG_STATISTICS,
3352 ARG_RESET_STATISTICS,
3353 ARG_STATUS,
3354 ARG_FLUSH_CACHES,
3355 ARG_RESET_SERVER_FEATURES,
3356 ARG_NO_PAGER,
3357 ARG_SET_DNS,
3358 ARG_SET_DOMAIN,
3359 ARG_SET_LLMNR,
3360 ARG_SET_MDNS,
3361 ARG_SET_PRIVATE,
3362 ARG_SET_DNSSEC,
3363 ARG_SET_NTA,
3364 ARG_REVERT_LINK,
3365 };
3366
3367 static const struct option options[] = {
3368 { "help", no_argument, NULL, 'h' },
3369 { "version", no_argument, NULL, ARG_VERSION },
3370 { "type", required_argument, NULL, 't' },
3371 { "class", required_argument, NULL, 'c' },
3372 { "legend", required_argument, NULL, ARG_LEGEND },
3373 { "interface", required_argument, NULL, 'i' },
3374 { "protocol", required_argument, NULL, 'p' },
3375 { "cname", required_argument, NULL, ARG_CNAME },
3376 { "service", no_argument, NULL, ARG_SERVICE },
3377 { "service-address", required_argument, NULL, ARG_SERVICE_ADDRESS },
3378 { "service-txt", required_argument, NULL, ARG_SERVICE_TXT },
3379 { "openpgp", no_argument, NULL, ARG_OPENPGP },
3380 { "tlsa", optional_argument, NULL, ARG_TLSA },
3381 { "raw", optional_argument, NULL, ARG_RAW },
3382 { "search", required_argument, NULL, ARG_SEARCH },
3383 { "statistics", no_argument, NULL, ARG_STATISTICS, },
3384 { "reset-statistics", no_argument, NULL, ARG_RESET_STATISTICS },
3385 { "status", no_argument, NULL, ARG_STATUS },
3386 { "flush-caches", no_argument, NULL, ARG_FLUSH_CACHES },
3387 { "reset-server-features", no_argument, NULL, ARG_RESET_SERVER_FEATURES },
3388 { "no-pager", no_argument, NULL, ARG_NO_PAGER },
3389 { "set-dns", required_argument, NULL, ARG_SET_DNS },
3390 { "set-domain", required_argument, NULL, ARG_SET_DOMAIN },
3391 { "set-llmnr", required_argument, NULL, ARG_SET_LLMNR },
3392 { "set-mdns", required_argument, NULL, ARG_SET_MDNS },
3393 { "set-dnsovertls", required_argument, NULL, ARG_SET_PRIVATE },
3394 { "set-dnssec", required_argument, NULL, ARG_SET_DNSSEC },
3395 { "set-nta", required_argument, NULL, ARG_SET_NTA },
3396 { "revert", no_argument, NULL, ARG_REVERT_LINK },
3397 {}
3398 };
3399
3400 int c, r;
3401
3402 assert(argc >= 0);
3403 assert(argv);
3404
3405 while ((c = getopt_long(argc, argv, "h46i:t:c:p:", options, NULL)) >= 0)
3406 switch (c) {
3407
3408 case 'h':
3409 return compat_help();
3410
3411 case ARG_VERSION:
3412 return version();
3413
3414 case '4':
3415 arg_family = AF_INET;
3416 break;
3417
3418 case '6':
3419 arg_family = AF_INET6;
3420 break;
3421
3422 case 'i':
3423 r = ifname_mangle(optarg);
3424 if (r < 0)
3425 return r;
3426 break;
3427
3428 case 't':
3429 if (streq(optarg, "help")) {
3430 help_dns_types();
3431 return 0;
3432 }
3433
3434 r = dns_type_from_string(optarg);
3435 if (r < 0)
3436 return log_error_errno(r, "Failed to parse RR record type %s: %m", optarg);
3437
3438 arg_type = (uint16_t) r;
3439 assert((int) arg_type == r);
3440
3441 arg_mode = MODE_RESOLVE_RECORD;
3442 break;
3443
3444 case 'c':
3445 if (streq(optarg, "help")) {
3446 help_dns_classes();
3447 return 0;
3448 }
3449
3450 r = dns_class_from_string(optarg);
3451 if (r < 0)
3452 return log_error_errno(r, "Failed to parse RR record class %s: %m", optarg);
3453
3454 arg_class = (uint16_t) r;
3455 assert((int) arg_class == r);
3456
3457 break;
3458
3459 case ARG_LEGEND:
3460 r = parse_boolean_argument("--legend=", optarg, &arg_legend);
3461 if (r < 0)
3462 return r;
3463 break;
3464
3465 case 'p':
3466 if (streq(optarg, "help")) {
3467 help_protocol_types();
3468 return 0;
3469 } else if (streq(optarg, "dns"))
3470 arg_flags |= SD_RESOLVED_DNS;
3471 else if (streq(optarg, "llmnr"))
3472 arg_flags |= SD_RESOLVED_LLMNR;
3473 else if (streq(optarg, "llmnr-ipv4"))
3474 arg_flags |= SD_RESOLVED_LLMNR_IPV4;
3475 else if (streq(optarg, "llmnr-ipv6"))
3476 arg_flags |= SD_RESOLVED_LLMNR_IPV6;
3477 else if (streq(optarg, "mdns"))
3478 arg_flags |= SD_RESOLVED_MDNS;
3479 else if (streq(optarg, "mdns-ipv4"))
3480 arg_flags |= SD_RESOLVED_MDNS_IPV4;
3481 else if (streq(optarg, "mdns-ipv6"))
3482 arg_flags |= SD_RESOLVED_MDNS_IPV6;
3483 else
3484 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3485 "Unknown protocol specifier: %s", optarg);
3486
3487 break;
3488
3489 case ARG_SERVICE:
3490 arg_mode = MODE_RESOLVE_SERVICE;
3491 break;
3492
3493 case ARG_OPENPGP:
3494 arg_mode = MODE_RESOLVE_OPENPGP;
3495 break;
3496
3497 case ARG_TLSA:
3498 arg_mode = MODE_RESOLVE_TLSA;
3499 if (!optarg || service_family_is_valid(optarg))
3500 arg_service_family = optarg;
3501 else
3502 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3503 "Unknown service family \"%s\".", optarg);
3504 break;
3505
3506 case ARG_RAW:
3507 if (on_tty())
3508 return log_error_errno(SYNTHETIC_ERRNO(ENOTTY),
3509 "Refusing to write binary data to tty.");
3510
3511 if (optarg == NULL || streq(optarg, "payload"))
3512 arg_raw = RAW_PAYLOAD;
3513 else if (streq(optarg, "packet"))
3514 arg_raw = RAW_PACKET;
3515 else
3516 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3517 "Unknown --raw specifier \"%s\".",
3518 optarg);
3519
3520 arg_legend = false;
3521 break;
3522
3523 case ARG_CNAME:
3524 r = parse_boolean_argument("--cname=", optarg, NULL);
3525 if (r < 0)
3526 return r;
3527 SET_FLAG(arg_flags, SD_RESOLVED_NO_CNAME, r == 0);
3528 break;
3529
3530 case ARG_SERVICE_ADDRESS:
3531 r = parse_boolean_argument("--service-address=", optarg, NULL);
3532 if (r < 0)
3533 return r;
3534 SET_FLAG(arg_flags, SD_RESOLVED_NO_ADDRESS, r == 0);
3535 break;
3536
3537 case ARG_SERVICE_TXT:
3538 r = parse_boolean_argument("--service-txt=", optarg, NULL);
3539 if (r < 0)
3540 return r;
3541 SET_FLAG(arg_flags, SD_RESOLVED_NO_TXT, r == 0);
3542 break;
3543
3544 case ARG_SEARCH:
3545 r = parse_boolean_argument("--search=", optarg, NULL);
3546 if (r < 0)
3547 return r;
3548 SET_FLAG(arg_flags, SD_RESOLVED_NO_SEARCH, r == 0);
3549 break;
3550
3551 case ARG_STATISTICS:
3552 arg_mode = MODE_STATISTICS;
3553 break;
3554
3555 case ARG_RESET_STATISTICS:
3556 arg_mode = MODE_RESET_STATISTICS;
3557 break;
3558
3559 case ARG_FLUSH_CACHES:
3560 arg_mode = MODE_FLUSH_CACHES;
3561 break;
3562
3563 case ARG_RESET_SERVER_FEATURES:
3564 arg_mode = MODE_RESET_SERVER_FEATURES;
3565 break;
3566
3567 case ARG_STATUS:
3568 arg_mode = MODE_STATUS;
3569 break;
3570
3571 case ARG_NO_PAGER:
3572 arg_pager_flags |= PAGER_DISABLE;
3573 break;
3574
3575 case ARG_SET_DNS:
3576 r = strv_extend(&arg_set_dns, optarg);
3577 if (r < 0)
3578 return log_oom();
3579
3580 arg_mode = MODE_SET_LINK;
3581 break;
3582
3583 case ARG_SET_DOMAIN:
3584 r = strv_extend(&arg_set_domain, optarg);
3585 if (r < 0)
3586 return log_oom();
3587
3588 arg_mode = MODE_SET_LINK;
3589 break;
3590
3591 case ARG_SET_LLMNR:
3592 arg_set_llmnr = optarg;
3593 arg_mode = MODE_SET_LINK;
3594 break;
3595
3596 case ARG_SET_MDNS:
3597 arg_set_mdns = optarg;
3598 arg_mode = MODE_SET_LINK;
3599 break;
3600
3601 case ARG_SET_PRIVATE:
3602 arg_set_dns_over_tls = optarg;
3603 arg_mode = MODE_SET_LINK;
3604 break;
3605
3606 case ARG_SET_DNSSEC:
3607 arg_set_dnssec = optarg;
3608 arg_mode = MODE_SET_LINK;
3609 break;
3610
3611 case ARG_SET_NTA:
3612 r = strv_extend(&arg_set_nta, optarg);
3613 if (r < 0)
3614 return log_oom();
3615
3616 arg_mode = MODE_SET_LINK;
3617 break;
3618
3619 case ARG_REVERT_LINK:
3620 arg_mode = MODE_REVERT_LINK;
3621 break;
3622
3623 case '?':
3624 return -EINVAL;
3625
3626 default:
3627 assert_not_reached();
3628 }
3629
3630 if (arg_type == 0 && arg_class != 0)
3631 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3632 "--class= may only be used in conjunction with --type=.");
3633
3634 if (arg_type != 0 && arg_mode == MODE_RESOLVE_SERVICE)
3635 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3636 "--service and --type= may not be combined.");
3637
3638 if (arg_type != 0 && arg_class == 0)
3639 arg_class = DNS_CLASS_IN;
3640
3641 if (arg_class != 0 && arg_type == 0)
3642 arg_type = DNS_TYPE_A;
3643
3644 if (IN_SET(arg_mode, MODE_SET_LINK, MODE_REVERT_LINK)) {
3645
3646 if (arg_ifindex <= 0)
3647 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3648 "--set-dns=, --set-domain=, --set-llmnr=, --set-mdns=, --set-dnsovertls=, --set-dnssec=, --set-nta= and --revert require --interface=.");
3649 }
3650
3651 return 1 /* work to do */;
3652 }
3653
3654 static int native_parse_argv(int argc, char *argv[]) {
3655 enum {
3656 ARG_VERSION = 0x100,
3657 ARG_LEGEND,
3658 ARG_CNAME,
3659 ARG_VALIDATE,
3660 ARG_SYNTHESIZE,
3661 ARG_CACHE,
3662 ARG_ZONE,
3663 ARG_TRUST_ANCHOR,
3664 ARG_NETWORK,
3665 ARG_SERVICE_ADDRESS,
3666 ARG_SERVICE_TXT,
3667 ARG_RAW,
3668 ARG_SEARCH,
3669 ARG_NO_PAGER,
3670 ARG_JSON,
3671 ARG_STALE_DATA
3672 };
3673
3674 static const struct option options[] = {
3675 { "help", no_argument, NULL, 'h' },
3676 { "version", no_argument, NULL, ARG_VERSION },
3677 { "type", required_argument, NULL, 't' },
3678 { "class", required_argument, NULL, 'c' },
3679 { "legend", required_argument, NULL, ARG_LEGEND },
3680 { "interface", required_argument, NULL, 'i' },
3681 { "protocol", required_argument, NULL, 'p' },
3682 { "cname", required_argument, NULL, ARG_CNAME },
3683 { "validate", required_argument, NULL, ARG_VALIDATE },
3684 { "synthesize", required_argument, NULL, ARG_SYNTHESIZE },
3685 { "cache", required_argument, NULL, ARG_CACHE },
3686 { "zone", required_argument, NULL, ARG_ZONE },
3687 { "trust-anchor", required_argument, NULL, ARG_TRUST_ANCHOR },
3688 { "network", required_argument, NULL, ARG_NETWORK },
3689 { "service-address", required_argument, NULL, ARG_SERVICE_ADDRESS },
3690 { "service-txt", required_argument, NULL, ARG_SERVICE_TXT },
3691 { "raw", optional_argument, NULL, ARG_RAW },
3692 { "search", required_argument, NULL, ARG_SEARCH },
3693 { "no-pager", no_argument, NULL, ARG_NO_PAGER },
3694 { "json", required_argument, NULL, ARG_JSON },
3695 { "stale-data", required_argument, NULL, ARG_STALE_DATA },
3696 {}
3697 };
3698
3699 int c, r;
3700
3701 assert(argc >= 0);
3702 assert(argv);
3703
3704 while ((c = getopt_long(argc, argv, "h46i:t:c:p:j", options, NULL)) >= 0)
3705 switch (c) {
3706
3707 case 'h':
3708 return native_help();
3709
3710 case ARG_VERSION:
3711 return version();
3712
3713 case '4':
3714 arg_family = AF_INET;
3715 break;
3716
3717 case '6':
3718 arg_family = AF_INET6;
3719 break;
3720
3721 case 'i':
3722 r = ifname_mangle(optarg);
3723 if (r < 0)
3724 return r;
3725 break;
3726
3727 case 't':
3728 if (streq(optarg, "help")) {
3729 help_dns_types();
3730 return 0;
3731 }
3732
3733 r = dns_type_from_string(optarg);
3734 if (r < 0)
3735 return log_error_errno(r, "Failed to parse RR record type %s: %m", optarg);
3736
3737 arg_type = (uint16_t) r;
3738 assert((int) arg_type == r);
3739
3740 break;
3741
3742 case 'c':
3743 if (streq(optarg, "help")) {
3744 help_dns_classes();
3745 return 0;
3746 }
3747
3748 r = dns_class_from_string(optarg);
3749 if (r < 0)
3750 return log_error_errno(r, "Failed to parse RR record class %s: %m", optarg);
3751
3752 arg_class = (uint16_t) r;
3753 assert((int) arg_class == r);
3754
3755 break;
3756
3757 case ARG_LEGEND:
3758 r = parse_boolean_argument("--legend=", optarg, &arg_legend);
3759 if (r < 0)
3760 return r;
3761 break;
3762
3763 case 'p':
3764 if (streq(optarg, "help")) {
3765 help_protocol_types();
3766 return 0;
3767 } else if (streq(optarg, "dns"))
3768 arg_flags |= SD_RESOLVED_DNS;
3769 else if (streq(optarg, "llmnr"))
3770 arg_flags |= SD_RESOLVED_LLMNR;
3771 else if (streq(optarg, "llmnr-ipv4"))
3772 arg_flags |= SD_RESOLVED_LLMNR_IPV4;
3773 else if (streq(optarg, "llmnr-ipv6"))
3774 arg_flags |= SD_RESOLVED_LLMNR_IPV6;
3775 else if (streq(optarg, "mdns"))
3776 arg_flags |= SD_RESOLVED_MDNS;
3777 else if (streq(optarg, "mdns-ipv4"))
3778 arg_flags |= SD_RESOLVED_MDNS_IPV4;
3779 else if (streq(optarg, "mdns-ipv6"))
3780 arg_flags |= SD_RESOLVED_MDNS_IPV6;
3781 else
3782 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3783 "Unknown protocol specifier: %s",
3784 optarg);
3785
3786 break;
3787
3788 case ARG_RAW:
3789 if (on_tty())
3790 return log_error_errno(SYNTHETIC_ERRNO(ENOTTY),
3791 "Refusing to write binary data to tty.");
3792
3793 if (optarg == NULL || streq(optarg, "payload"))
3794 arg_raw = RAW_PAYLOAD;
3795 else if (streq(optarg, "packet"))
3796 arg_raw = RAW_PACKET;
3797 else
3798 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3799 "Unknown --raw specifier \"%s\".",
3800 optarg);
3801
3802 arg_legend = false;
3803 break;
3804
3805 case ARG_CNAME:
3806 r = parse_boolean_argument("--cname=", optarg, NULL);
3807 if (r < 0)
3808 return r;
3809 SET_FLAG(arg_flags, SD_RESOLVED_NO_CNAME, r == 0);
3810 break;
3811
3812 case ARG_VALIDATE:
3813 r = parse_boolean_argument("--validate=", optarg, NULL);
3814 if (r < 0)
3815 return r;
3816 SET_FLAG(arg_flags, SD_RESOLVED_NO_VALIDATE, r == 0);
3817 break;
3818
3819 case ARG_SYNTHESIZE:
3820 r = parse_boolean_argument("--synthesize=", optarg, NULL);
3821 if (r < 0)
3822 return r;
3823 SET_FLAG(arg_flags, SD_RESOLVED_NO_SYNTHESIZE, r == 0);
3824 break;
3825
3826 case ARG_CACHE:
3827 r = parse_boolean_argument("--cache=", optarg, NULL);
3828 if (r < 0)
3829 return r;
3830 SET_FLAG(arg_flags, SD_RESOLVED_NO_CACHE, r == 0);
3831 break;
3832
3833 case ARG_STALE_DATA:
3834 r = parse_boolean_argument("--stale-data=", optarg, NULL);
3835 if (r < 0)
3836 return r;
3837 SET_FLAG(arg_flags, SD_RESOLVED_NO_STALE, r == 0);
3838 break;
3839
3840 case ARG_ZONE:
3841 r = parse_boolean_argument("--zone=", optarg, NULL);
3842 if (r < 0)
3843 return r;
3844 SET_FLAG(arg_flags, SD_RESOLVED_NO_ZONE, r == 0);
3845 break;
3846
3847 case ARG_TRUST_ANCHOR:
3848 r = parse_boolean_argument("--trust-anchor=", optarg, NULL);
3849 if (r < 0)
3850 return r;
3851 SET_FLAG(arg_flags, SD_RESOLVED_NO_TRUST_ANCHOR, r == 0);
3852 break;
3853
3854 case ARG_NETWORK:
3855 r = parse_boolean_argument("--network=", optarg, NULL);
3856 if (r < 0)
3857 return r;
3858 SET_FLAG(arg_flags, SD_RESOLVED_NO_NETWORK, r == 0);
3859 break;
3860
3861 case ARG_SERVICE_ADDRESS:
3862 r = parse_boolean_argument("--service-address=", optarg, NULL);
3863 if (r < 0)
3864 return r;
3865 SET_FLAG(arg_flags, SD_RESOLVED_NO_ADDRESS, r == 0);
3866 break;
3867
3868 case ARG_SERVICE_TXT:
3869 r = parse_boolean_argument("--service-txt=", optarg, NULL);
3870 if (r < 0)
3871 return r;
3872 SET_FLAG(arg_flags, SD_RESOLVED_NO_TXT, r == 0);
3873 break;
3874
3875 case ARG_SEARCH:
3876 r = parse_boolean_argument("--search=", optarg, NULL);
3877 if (r < 0)
3878 return r;
3879 SET_FLAG(arg_flags, SD_RESOLVED_NO_SEARCH, r == 0);
3880 break;
3881
3882 case ARG_NO_PAGER:
3883 arg_pager_flags |= PAGER_DISABLE;
3884 break;
3885
3886 case ARG_JSON:
3887 r = parse_json_argument(optarg, &arg_json_format_flags);
3888 if (r <= 0)
3889 return r;
3890
3891 break;
3892
3893 case 'j':
3894 arg_json_format_flags = JSON_FORMAT_PRETTY_AUTO|JSON_FORMAT_COLOR_AUTO;
3895 break;
3896
3897 case '?':
3898 return -EINVAL;
3899
3900 default:
3901 assert_not_reached();
3902 }
3903
3904 if (arg_type == 0 && arg_class != 0)
3905 return log_error_errno(SYNTHETIC_ERRNO(EINVAL),
3906 "--class= may only be used in conjunction with --type=.");
3907
3908 if (arg_type != 0 && arg_class == 0)
3909 arg_class = DNS_CLASS_IN;
3910
3911 if (arg_class != 0 && arg_type == 0)
3912 arg_type = DNS_TYPE_A;
3913
3914 return 1 /* work to do */;
3915 }
3916
3917 static int native_main(int argc, char *argv[], sd_bus *bus) {
3918
3919 static const Verb verbs[] = {
3920 { "help", VERB_ANY, VERB_ANY, 0, verb_help },
3921 { "status", VERB_ANY, VERB_ANY, VERB_DEFAULT, verb_status },
3922 { "query", 2, VERB_ANY, 0, verb_query },
3923 { "service", 2, 4, 0, verb_service },
3924 { "openpgp", 2, VERB_ANY, 0, verb_openpgp },
3925 { "tlsa", 2, VERB_ANY, 0, verb_tlsa },
3926 { "statistics", VERB_ANY, 1, 0, show_statistics },
3927 { "reset-statistics", VERB_ANY, 1, 0, reset_statistics },
3928 { "flush-caches", VERB_ANY, 1, 0, flush_caches },
3929 { "reset-server-features", VERB_ANY, 1, 0, reset_server_features },
3930 { "dns", VERB_ANY, VERB_ANY, 0, verb_dns },
3931 { "domain", VERB_ANY, VERB_ANY, 0, verb_domain },
3932 { "default-route", VERB_ANY, 3, 0, verb_default_route },
3933 { "llmnr", VERB_ANY, 3, 0, verb_llmnr },
3934 { "mdns", VERB_ANY, 3, 0, verb_mdns },
3935 { "dnsovertls", VERB_ANY, 3, 0, verb_dns_over_tls },
3936 { "dnssec", VERB_ANY, 3, 0, verb_dnssec },
3937 { "nta", VERB_ANY, VERB_ANY, 0, verb_nta },
3938 { "revert", VERB_ANY, 2, 0, verb_revert_link },
3939 { "log-level", VERB_ANY, 2, 0, verb_log_level },
3940 { "monitor", VERB_ANY, 1, 0, verb_monitor },
3941 { "show-cache", VERB_ANY, 1, 0, verb_show_cache },
3942 { "show-server-state", VERB_ANY, 1, 0, verb_show_server_state},
3943 {}
3944 };
3945
3946 return dispatch_verb(argc, argv, verbs, bus);
3947 }
3948
3949 static int translate(const char *verb, const char *single_arg, size_t num_args, char **args, sd_bus *bus) {
3950 char **fake, **p;
3951 size_t num;
3952
3953 assert(verb);
3954 assert(num_args == 0 || args);
3955
3956 num = !!single_arg + num_args + 1;
3957
3958 p = fake = newa0(char *, num + 1);
3959 *p++ = (char *) verb;
3960 if (single_arg)
3961 *p++ = (char *) single_arg;
3962 for (size_t i = 0; i < num_args; i++)
3963 *p++ = args[i];
3964
3965 optind = 0;
3966 return native_main((int) num, fake, bus);
3967 }
3968
3969 static int compat_main(int argc, char *argv[], sd_bus *bus) {
3970 int r = 0;
3971
3972 switch (arg_mode) {
3973 case MODE_RESOLVE_HOST:
3974 case MODE_RESOLVE_RECORD:
3975 return translate("query", NULL, argc - optind, argv + optind, bus);
3976
3977 case MODE_RESOLVE_SERVICE:
3978 return translate("service", NULL, argc - optind, argv + optind, bus);
3979
3980 case MODE_RESOLVE_OPENPGP:
3981 return translate("openpgp", NULL, argc - optind, argv + optind, bus);
3982
3983 case MODE_RESOLVE_TLSA:
3984 return translate("tlsa", arg_service_family, argc - optind, argv + optind, bus);
3985
3986 case MODE_STATISTICS:
3987 return translate("statistics", NULL, 0, NULL, bus);
3988
3989 case MODE_RESET_STATISTICS:
3990 return translate("reset-statistics", NULL, 0, NULL, bus);
3991
3992 case MODE_FLUSH_CACHES:
3993 return translate("flush-caches", NULL, 0, NULL, bus);
3994
3995 case MODE_RESET_SERVER_FEATURES:
3996 return translate("reset-server-features", NULL, 0, NULL, bus);
3997
3998 case MODE_STATUS:
3999 return translate("status", NULL, argc - optind, argv + optind, bus);
4000
4001 case MODE_SET_LINK:
4002 assert(arg_ifname);
4003
4004 if (arg_set_dns) {
4005 r = translate("dns", arg_ifname, strv_length(arg_set_dns), arg_set_dns, bus);
4006 if (r < 0)
4007 return r;
4008 }
4009
4010 if (arg_set_domain) {
4011 r = translate("domain", arg_ifname, strv_length(arg_set_domain), arg_set_domain, bus);
4012 if (r < 0)
4013 return r;
4014 }
4015
4016 if (arg_set_nta) {
4017 r = translate("nta", arg_ifname, strv_length(arg_set_nta), arg_set_nta, bus);
4018 if (r < 0)
4019 return r;
4020 }
4021
4022 if (arg_set_llmnr) {
4023 r = translate("llmnr", arg_ifname, 1, (char **) &arg_set_llmnr, bus);
4024 if (r < 0)
4025 return r;
4026 }
4027
4028 if (arg_set_mdns) {
4029 r = translate("mdns", arg_ifname, 1, (char **) &arg_set_mdns, bus);
4030 if (r < 0)
4031 return r;
4032 }
4033
4034 if (arg_set_dns_over_tls) {
4035 r = translate("dnsovertls", arg_ifname, 1, (char **) &arg_set_dns_over_tls, bus);
4036 if (r < 0)
4037 return r;
4038 }
4039
4040 if (arg_set_dnssec) {
4041 r = translate("dnssec", arg_ifname, 1, (char **) &arg_set_dnssec, bus);
4042 if (r < 0)
4043 return r;
4044 }
4045
4046 return r;
4047
4048 case MODE_REVERT_LINK:
4049 assert(arg_ifname);
4050
4051 return translate("revert", arg_ifname, 0, NULL, bus);
4052
4053 case _MODE_INVALID:
4054 assert_not_reached();
4055 }
4056
4057 return 0;
4058 }
4059
4060 static int run(int argc, char **argv) {
4061 _cleanup_(sd_bus_flush_close_unrefp) sd_bus *bus = NULL;
4062 bool compat = false;
4063 int r;
4064
4065 setlocale(LC_ALL, "");
4066 log_setup();
4067
4068 if (invoked_as(argv, "resolvconf")) {
4069 compat = true;
4070 r = resolvconf_parse_argv(argc, argv);
4071 } else if (invoked_as(argv, "systemd-resolve")) {
4072 compat = true;
4073 r = compat_parse_argv(argc, argv);
4074 } else
4075 r = native_parse_argv(argc, argv);
4076 if (r <= 0)
4077 return r;
4078
4079 r = sd_bus_open_system(&bus);
4080 if (r < 0)
4081 return log_error_errno(r, "sd_bus_open_system: %m");
4082
4083 if (compat)
4084 return compat_main(argc, argv, bus);
4085
4086 return native_main(argc, argv, bus);
4087 }
4088
4089 DEFINE_MAIN_FUNCTION(run);