]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/resolve/resolved-conf.c
tree-wide: support a bunch of additional specifiers
[thirdparty/systemd.git] / src / resolve / resolved-conf.c
1 /* SPDX-License-Identifier: LGPL-2.1+ */
2
3 #include "alloc-util.h"
4 #include "conf-parser.h"
5 #include "def.h"
6 #include "extract-word.h"
7 #include "hexdecoct.h"
8 #include "parse-util.h"
9 #include "resolved-conf.h"
10 #include "resolved-dnssd.h"
11 #include "resolved-util.h"
12 #include "specifier.h"
13 #include "string-table.h"
14 #include "string-util.h"
15 #include "utf8.h"
16
17 DEFINE_CONFIG_PARSE_ENUM(config_parse_dns_stub_listener_mode, dns_stub_listener_mode, DnsStubListenerMode, "Failed to parse DNS stub listener mode setting");
18
19 static const char* const dns_stub_listener_mode_table[_DNS_STUB_LISTENER_MODE_MAX] = {
20 [DNS_STUB_LISTENER_NO] = "no",
21 [DNS_STUB_LISTENER_UDP] = "udp",
22 [DNS_STUB_LISTENER_TCP] = "tcp",
23 [DNS_STUB_LISTENER_YES] = "yes",
24 };
25 DEFINE_STRING_TABLE_LOOKUP_WITH_BOOLEAN(dns_stub_listener_mode, DnsStubListenerMode, DNS_STUB_LISTENER_YES);
26
27 static int manager_add_dns_server_by_string(Manager *m, DnsServerType type, const char *word) {
28 union in_addr_union address;
29 int family, r, ifindex = 0;
30 DnsServer *s;
31 _cleanup_free_ char *server_name = NULL;
32
33 assert(m);
34 assert(word);
35
36 r = in_addr_ifindex_name_from_string_auto(word, &family, &address, &ifindex, &server_name);
37 if (r < 0)
38 return r;
39
40 /* Silently filter out 0.0.0.0 and 127.0.0.53 (our own stub DNS listener) */
41 if (!dns_server_address_valid(family, &address))
42 return 0;
43
44 /* Filter out duplicates */
45 s = dns_server_find(manager_get_first_dns_server(m, type), family, &address, ifindex);
46 if (s) {
47 /*
48 * Drop the marker. This is used to find the servers
49 * that ceased to exist, see
50 * manager_mark_dns_servers() and
51 * manager_flush_marked_dns_servers().
52 */
53 dns_server_move_back_and_unmark(s);
54 return 0;
55 }
56
57 return dns_server_new(m, NULL, type, NULL, family, &address, ifindex, server_name);
58 }
59
60 int manager_parse_dns_server_string_and_warn(Manager *m, DnsServerType type, const char *string) {
61 int r;
62
63 assert(m);
64 assert(string);
65
66 for (;;) {
67 _cleanup_free_ char *word = NULL;
68
69 r = extract_first_word(&string, &word, NULL, 0);
70 if (r < 0)
71 return r;
72 if (r == 0)
73 break;
74
75 r = manager_add_dns_server_by_string(m, type, word);
76 if (r < 0)
77 log_warning_errno(r, "Failed to add DNS server address '%s', ignoring: %m", word);
78 }
79
80 return 0;
81 }
82
83 static int manager_add_search_domain_by_string(Manager *m, const char *domain) {
84 DnsSearchDomain *d;
85 bool route_only;
86 int r;
87
88 assert(m);
89 assert(domain);
90
91 route_only = *domain == '~';
92 if (route_only)
93 domain++;
94
95 if (dns_name_is_root(domain) || streq(domain, "*")) {
96 route_only = true;
97 domain = ".";
98 }
99
100 r = dns_search_domain_find(m->search_domains, domain, &d);
101 if (r < 0)
102 return r;
103 if (r > 0)
104 dns_search_domain_move_back_and_unmark(d);
105 else {
106 r = dns_search_domain_new(m, &d, DNS_SEARCH_DOMAIN_SYSTEM, NULL, domain);
107 if (r < 0)
108 return r;
109 }
110
111 d->route_only = route_only;
112 return 0;
113 }
114
115 int manager_parse_search_domains_and_warn(Manager *m, const char *string) {
116 int r;
117
118 assert(m);
119 assert(string);
120
121 for (;;) {
122 _cleanup_free_ char *word = NULL;
123
124 r = extract_first_word(&string, &word, NULL, EXTRACT_UNQUOTE);
125 if (r < 0)
126 return r;
127 if (r == 0)
128 break;
129
130 r = manager_add_search_domain_by_string(m, word);
131 if (r < 0)
132 log_warning_errno(r, "Failed to add search domain '%s', ignoring: %m", word);
133 }
134
135 return 0;
136 }
137
138 int config_parse_dns_servers(
139 const char *unit,
140 const char *filename,
141 unsigned line,
142 const char *section,
143 unsigned section_line,
144 const char *lvalue,
145 int ltype,
146 const char *rvalue,
147 void *data,
148 void *userdata) {
149
150 Manager *m = userdata;
151 int r;
152
153 assert(filename);
154 assert(lvalue);
155 assert(rvalue);
156 assert(m);
157
158 if (isempty(rvalue))
159 /* Empty assignment means clear the list */
160 dns_server_unlink_all(manager_get_first_dns_server(m, ltype));
161 else {
162 /* Otherwise, add to the list */
163 r = manager_parse_dns_server_string_and_warn(m, ltype, rvalue);
164 if (r < 0) {
165 log_syntax(unit, LOG_ERR, filename, line, r, "Failed to parse DNS server string '%s'. Ignoring.", rvalue);
166 return 0;
167 }
168 }
169
170 /* If we have a manual setting, then we stop reading
171 * /etc/resolv.conf */
172 if (ltype == DNS_SERVER_SYSTEM)
173 m->read_resolv_conf = false;
174 if (ltype == DNS_SERVER_FALLBACK)
175 m->need_builtin_fallbacks = false;
176
177 return 0;
178 }
179
180 int config_parse_search_domains(
181 const char *unit,
182 const char *filename,
183 unsigned line,
184 const char *section,
185 unsigned section_line,
186 const char *lvalue,
187 int ltype,
188 const char *rvalue,
189 void *data,
190 void *userdata) {
191
192 Manager *m = userdata;
193 int r;
194
195 assert(filename);
196 assert(lvalue);
197 assert(rvalue);
198 assert(m);
199
200 if (isempty(rvalue))
201 /* Empty assignment means clear the list */
202 dns_search_domain_unlink_all(m->search_domains);
203 else {
204 /* Otherwise, add to the list */
205 r = manager_parse_search_domains_and_warn(m, rvalue);
206 if (r < 0) {
207 log_syntax(unit, LOG_ERR, filename, line, r, "Failed to parse search domains string '%s'. Ignoring.", rvalue);
208 return 0;
209 }
210 }
211
212 /* If we have a manual setting, then we stop reading
213 * /etc/resolv.conf */
214 m->read_resolv_conf = false;
215
216 return 0;
217 }
218
219 int config_parse_dnssd_service_name(const char *unit, const char *filename, unsigned line, const char *section, unsigned section_line, const char *lvalue, int ltype, const char *rvalue, void *data, void *userdata) {
220 static const Specifier specifier_table[] = {
221 { 'm', specifier_machine_id, NULL },
222 { 'b', specifier_boot_id, NULL },
223 { 'H', specifier_host_name, NULL },
224 { 'v', specifier_kernel_release, NULL },
225 { 'a', specifier_architecture, NULL },
226 { 'o', specifier_os_id, NULL },
227 { 'w', specifier_os_version_id, NULL },
228 { 'B', specifier_os_build_id, NULL },
229 { 'W', specifier_os_variant_id, NULL },
230 {}
231 };
232 DnssdService *s = userdata;
233 _cleanup_free_ char *name = NULL;
234 int r;
235
236 assert(filename);
237 assert(lvalue);
238 assert(rvalue);
239 assert(s);
240
241 if (isempty(rvalue)) {
242 log_syntax(unit, LOG_ERR, filename, line, 0, "Service instance name can't be empty. Ignoring.");
243 return -EINVAL;
244 }
245
246 r = free_and_strdup(&s->name_template, rvalue);
247 if (r < 0)
248 return log_oom();
249
250 r = specifier_printf(s->name_template, specifier_table, NULL, &name);
251 if (r < 0)
252 return log_debug_errno(r, "Failed to replace specifiers: %m");
253
254 if (!dns_service_name_is_valid(name)) {
255 log_syntax(unit, LOG_ERR, filename, line, 0, "Service instance name template renders to invalid name '%s'. Ignoring.", name);
256 return -EINVAL;
257 }
258
259 return 0;
260 }
261
262 int config_parse_dnssd_service_type(const char *unit, const char *filename, unsigned line, const char *section, unsigned section_line, const char *lvalue, int ltype, const char *rvalue, void *data, void *userdata) {
263 DnssdService *s = userdata;
264 int r;
265
266 assert(filename);
267 assert(lvalue);
268 assert(rvalue);
269 assert(s);
270
271 if (isempty(rvalue)) {
272 log_syntax(unit, LOG_ERR, filename, line, 0, "Service type can't be empty. Ignoring.");
273 return -EINVAL;
274 }
275
276 if (!dnssd_srv_type_is_valid(rvalue)) {
277 log_syntax(unit, LOG_ERR, filename, line, 0, "Service type is invalid. Ignoring.");
278 return -EINVAL;
279 }
280
281 r = free_and_strdup(&s->type, rvalue);
282 if (r < 0)
283 return log_oom();
284
285 return 0;
286 }
287
288 int config_parse_dnssd_txt(const char *unit, const char *filename, unsigned line, const char *section, unsigned section_line, const char *lvalue, int ltype, const char *rvalue, void *data, void *userdata) {
289 _cleanup_(dnssd_txtdata_freep) DnssdTxtData *txt_data = NULL;
290 DnssdService *s = userdata;
291 DnsTxtItem *last = NULL;
292
293 assert(filename);
294 assert(lvalue);
295 assert(rvalue);
296 assert(s);
297
298 if (isempty(rvalue)) {
299 /* Flush out collected items */
300 s->txt_data_items = dnssd_txtdata_free_all(s->txt_data_items);
301 return 0;
302 }
303
304 txt_data = new0(DnssdTxtData, 1);
305 if (!txt_data)
306 return log_oom();
307
308 for (;;) {
309 _cleanup_free_ char *word = NULL;
310 _cleanup_free_ char *key = NULL;
311 _cleanup_free_ char *value = NULL;
312 _cleanup_free_ void *decoded = NULL;
313 size_t length = 0;
314 DnsTxtItem *i;
315 int r;
316
317 r = extract_first_word(&rvalue, &word, NULL,
318 EXTRACT_UNQUOTE|EXTRACT_CUNESCAPE|EXTRACT_CUNESCAPE_RELAX);
319 if (r == 0)
320 break;
321 if (r == -ENOMEM)
322 return log_oom();
323 if (r < 0)
324 return log_syntax(unit, LOG_ERR, filename, line, r, "Invalid syntax, ignoring: %s", rvalue);
325
326 r = split_pair(word, "=", &key, &value);
327 if (r == -ENOMEM)
328 return log_oom();
329 if (r == -EINVAL)
330 key = TAKE_PTR(word);
331
332 if (!ascii_is_valid(key)) {
333 log_syntax(unit, LOG_ERR, filename, line, 0, "Invalid syntax, ignoring: %s", key);
334 return -EINVAL;
335 }
336
337 switch (ltype) {
338
339 case DNS_TXT_ITEM_DATA:
340 if (value) {
341 r = unbase64mem(value, strlen(value), &decoded, &length);
342 if (r == -ENOMEM)
343 return log_oom();
344 if (r < 0)
345 return log_syntax(unit, LOG_ERR, filename, line, r,
346 "Invalid base64 encoding, ignoring: %s", value);
347 }
348
349 r = dnssd_txt_item_new_from_data(key, decoded, length, &i);
350 if (r < 0)
351 return log_oom();
352 break;
353
354 case DNS_TXT_ITEM_TEXT:
355 r = dnssd_txt_item_new_from_string(key, value, &i);
356 if (r < 0)
357 return log_oom();
358 break;
359
360 default:
361 assert_not_reached("Unknown type of Txt config");
362 }
363
364 LIST_INSERT_AFTER(items, txt_data->txt, last, i);
365 last = i;
366 }
367
368 if (!LIST_IS_EMPTY(txt_data->txt)) {
369 LIST_PREPEND(items, s->txt_data_items, txt_data);
370 txt_data = NULL;
371 }
372
373 return 0;
374 }
375
376 int manager_parse_config_file(Manager *m) {
377 int r;
378
379 assert(m);
380
381 r = config_parse_many_nulstr(PKGSYSCONFDIR "/resolved.conf",
382 CONF_PATHS_NULSTR("systemd/resolved.conf.d"),
383 "Resolve\0",
384 config_item_perf_lookup, resolved_gperf_lookup,
385 CONFIG_PARSE_WARN, m);
386 if (r < 0)
387 return r;
388
389 if (m->need_builtin_fallbacks) {
390 r = manager_parse_dns_server_string_and_warn(m, DNS_SERVER_FALLBACK, DNS_SERVERS);
391 if (r < 0)
392 return r;
393 }
394
395 #if ! HAVE_GCRYPT
396 if (m->dnssec_mode != DNSSEC_NO) {
397 log_warning("DNSSEC option cannot be enabled or set to allow-downgrade when systemd-resolved is built without gcrypt support. Turning off DNSSEC support.");
398 m->dnssec_mode = DNSSEC_NO;
399 }
400 #endif
401
402 #if ! ENABLE_DNS_OVER_TLS
403 if (m->dns_over_tls_mode != DNS_OVER_TLS_NO) {
404 log_warning("DNS-over-TLS option cannot be enabled or set to opportunistic when systemd-resolved is built without DNS-over-TLS support. Turning off DNS-over-TLS support.");
405 m->dns_over_tls_mode = DNS_OVER_TLS_NO;
406 }
407 #endif
408 return 0;
409
410 }