1 /* SPDX-License-Identifier: LGPL-2.1+ */
4 #include <netinet/in.h>
5 #include <sys/capability.h>
7 #include "alloc-util.h"
8 #include "bus-common-errors.h"
10 #include "parse-util.h"
11 #include "resolve-util.h"
12 #include "resolved-bus.h"
13 #include "resolved-link-bus.h"
14 #include "resolved-resolv-conf.h"
15 #include "stdio-util.h"
17 #include "user-util.h"
19 static BUS_DEFINE_PROPERTY_GET(property_get_dnssec_supported
, "b", Link
, link_dnssec_supported
);
20 static BUS_DEFINE_PROPERTY_GET2(property_get_dnssec_mode
, "s", Link
, link_get_dnssec_mode
, dnssec_mode_to_string
);
22 static int property_get_dns_over_tls_mode(
25 const char *interface
,
27 sd_bus_message
*reply
,
29 sd_bus_error
*error
) {
36 return sd_bus_message_append(reply
, "s", dns_over_tls_mode_to_string(link_get_dns_over_tls_mode(l
)));
39 static int property_get_dns(
42 const char *interface
,
44 sd_bus_message
*reply
,
46 sd_bus_error
*error
) {
55 r
= sd_bus_message_open_container(reply
, 'a', "(iay)");
59 LIST_FOREACH(servers
, s
, l
->dns_servers
) {
60 r
= bus_dns_server_append(reply
, s
, false);
65 return sd_bus_message_close_container(reply
);
68 static int property_get_current_dns_server(
71 const char *interface
,
73 sd_bus_message
*reply
,
75 sd_bus_error
*error
) {
82 s
= *(DnsServer
**) userdata
;
84 return bus_dns_server_append(reply
, s
, false);
87 static int property_get_domains(
90 const char *interface
,
92 sd_bus_message
*reply
,
94 sd_bus_error
*error
) {
103 r
= sd_bus_message_open_container(reply
, 'a', "(sb)");
107 LIST_FOREACH(domains
, d
, l
->search_domains
) {
108 r
= sd_bus_message_append(reply
, "(sb)", d
->name
, d
->route_only
);
113 return sd_bus_message_close_container(reply
);
116 static int property_get_default_route(
119 const char *interface
,
120 const char *property
,
121 sd_bus_message
*reply
,
123 sd_bus_error
*error
) {
130 /* Return what is configured, if there's something configured */
131 if (l
->default_route
>= 0)
132 return sd_bus_message_append(reply
, "b", l
->default_route
);
134 /* Otherwise report what is in effect */
135 if (l
->unicast_scope
)
136 return sd_bus_message_append(reply
, "b", dns_scope_is_default_route(l
->unicast_scope
));
138 return sd_bus_message_append(reply
, "b", false);
141 static int property_get_scopes_mask(
144 const char *interface
,
145 const char *property
,
146 sd_bus_message
*reply
,
148 sd_bus_error
*error
) {
156 mask
= (l
->unicast_scope
? SD_RESOLVED_DNS
: 0) |
157 (l
->llmnr_ipv4_scope
? SD_RESOLVED_LLMNR_IPV4
: 0) |
158 (l
->llmnr_ipv6_scope
? SD_RESOLVED_LLMNR_IPV6
: 0) |
159 (l
->mdns_ipv4_scope
? SD_RESOLVED_MDNS_IPV4
: 0) |
160 (l
->mdns_ipv6_scope
? SD_RESOLVED_MDNS_IPV6
: 0);
162 return sd_bus_message_append(reply
, "t", mask
);
165 static int property_get_ntas(
168 const char *interface
,
169 const char *property
,
170 sd_bus_message
*reply
,
172 sd_bus_error
*error
) {
182 r
= sd_bus_message_open_container(reply
, 'a', "s");
186 SET_FOREACH(name
, l
->dnssec_negative_trust_anchors
, i
) {
187 r
= sd_bus_message_append(reply
, "s", name
);
192 return sd_bus_message_close_container(reply
);
195 static int verify_unmanaged_link(Link
*l
, sd_bus_error
*error
) {
198 if (l
->flags
& IFF_LOOPBACK
)
199 return sd_bus_error_setf(error
, BUS_ERROR_LINK_BUSY
, "Link %s is loopback device.", l
->ifname
);
201 return sd_bus_error_setf(error
, BUS_ERROR_LINK_BUSY
, "Link %s is managed.", l
->ifname
);
206 int bus_link_method_set_dns_servers(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
207 _cleanup_free_
struct in_addr_data
*dns
= NULL
;
208 size_t allocated
= 0, n
= 0;
216 r
= verify_unmanaged_link(l
, error
);
220 r
= sd_bus_message_enter_container(message
, 'a', "(iay)");
229 assert_cc(sizeof(int) == sizeof(int32_t));
231 r
= sd_bus_message_enter_container(message
, 'r', "iay");
237 r
= sd_bus_message_read(message
, "i", &family
);
241 if (!IN_SET(family
, AF_INET
, AF_INET6
))
242 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Unknown address family %i", family
);
244 r
= sd_bus_message_read_array(message
, 'y', &d
, &sz
);
247 if (sz
!= FAMILY_ADDRESS_SIZE(family
))
248 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid address size");
250 if (!dns_server_address_valid(family
, d
))
251 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNS server address");
253 r
= sd_bus_message_exit_container(message
);
257 if (!GREEDY_REALLOC(dns
, allocated
, n
+1))
260 dns
[n
].family
= family
;
261 memcpy(&dns
[n
].address
, d
, sz
);
265 r
= sd_bus_message_exit_container(message
);
269 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
270 "org.freedesktop.resolve1.set-dns-servers",
271 NULL
, true, UID_INVALID
,
272 &l
->manager
->polkit_registry
, error
);
276 return 1; /* Polkit will call us back */
278 dns_server_mark_all(l
->dns_servers
);
280 for (i
= 0; i
< n
; i
++) {
283 s
= dns_server_find(l
->dns_servers
, dns
[i
].family
, &dns
[i
].address
, 0);
285 dns_server_move_back_and_unmark(s
);
287 r
= dns_server_new(l
->manager
, NULL
, DNS_SERVER_LINK
, l
, dns
[i
].family
, &dns
[i
].address
, 0, NULL
);
294 dns_server_unlink_marked(l
->dns_servers
);
295 link_allocate_scopes(l
);
297 (void) link_save_user(l
);
298 (void) manager_write_resolv_conf(l
->manager
);
299 (void) manager_send_changed(l
->manager
, "DNS");
301 return sd_bus_reply_method_return(message
, NULL
);
304 dns_server_unlink_all(l
->dns_servers
);
308 int bus_link_method_set_domains(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
315 r
= verify_unmanaged_link(l
, error
);
319 r
= sd_bus_message_enter_container(message
, 'a', "(sb)");
327 r
= sd_bus_message_read(message
, "(sb)", &name
, &route_only
);
333 r
= dns_name_is_valid(name
);
337 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid search domain %s", name
);
338 if (!route_only
&& dns_name_is_root(name
))
339 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Root domain is not suitable as search domain");
342 r
= sd_bus_message_rewind(message
, false);
346 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
347 "org.freedesktop.resolve1.set-domains",
348 NULL
, true, UID_INVALID
,
349 &l
->manager
->polkit_registry
, error
);
353 return 1; /* Polkit will call us back */
355 dns_search_domain_mark_all(l
->search_domains
);
362 r
= sd_bus_message_read(message
, "(sb)", &name
, &route_only
);
368 r
= dns_search_domain_find(l
->search_domains
, name
, &d
);
373 dns_search_domain_move_back_and_unmark(d
);
375 r
= dns_search_domain_new(l
->manager
, &d
, DNS_SEARCH_DOMAIN_LINK
, l
, name
);
380 d
->route_only
= route_only
;
383 r
= sd_bus_message_exit_container(message
);
387 dns_search_domain_unlink_marked(l
->search_domains
);
389 (void) link_save_user(l
);
390 (void) manager_write_resolv_conf(l
->manager
);
392 return sd_bus_reply_method_return(message
, NULL
);
395 dns_search_domain_unlink_all(l
->search_domains
);
399 int bus_link_method_set_default_route(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
406 r
= verify_unmanaged_link(l
, error
);
410 r
= sd_bus_message_read(message
, "b", &b
);
414 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
415 "org.freedesktop.resolve1.set-default-route",
416 NULL
, true, UID_INVALID
,
417 &l
->manager
->polkit_registry
, error
);
421 return 1; /* Polkit will call us back */
423 if (l
->default_route
!= b
) {
424 l
->default_route
= b
;
426 (void) link_save_user(l
);
427 (void) manager_write_resolv_conf(l
->manager
);
430 return sd_bus_reply_method_return(message
, NULL
);
433 int bus_link_method_set_llmnr(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
442 r
= verify_unmanaged_link(l
, error
);
446 r
= sd_bus_message_read(message
, "s", &llmnr
);
451 mode
= RESOLVE_SUPPORT_YES
;
453 mode
= resolve_support_from_string(llmnr
);
455 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid LLMNR setting: %s", llmnr
);
458 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
459 "org.freedesktop.resolve1.set-llmnr",
460 NULL
, true, UID_INVALID
,
461 &l
->manager
->polkit_registry
, error
);
465 return 1; /* Polkit will call us back */
467 l
->llmnr_support
= mode
;
468 link_allocate_scopes(l
);
469 link_add_rrs(l
, false);
471 (void) link_save_user(l
);
473 return sd_bus_reply_method_return(message
, NULL
);
476 int bus_link_method_set_mdns(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
485 r
= verify_unmanaged_link(l
, error
);
489 r
= sd_bus_message_read(message
, "s", &mdns
);
494 mode
= RESOLVE_SUPPORT_NO
;
496 mode
= resolve_support_from_string(mdns
);
498 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid MulticastDNS setting: %s", mdns
);
501 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
502 "org.freedesktop.resolve1.set-mdns",
503 NULL
, true, UID_INVALID
,
504 &l
->manager
->polkit_registry
, error
);
508 return 1; /* Polkit will call us back */
510 l
->mdns_support
= mode
;
511 link_allocate_scopes(l
);
512 link_add_rrs(l
, false);
514 (void) link_save_user(l
);
516 return sd_bus_reply_method_return(message
, NULL
);
519 int bus_link_method_set_dns_over_tls(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
521 const char *dns_over_tls
;
528 r
= verify_unmanaged_link(l
, error
);
532 r
= sd_bus_message_read(message
, "s", &dns_over_tls
);
536 if (isempty(dns_over_tls
))
537 mode
= _DNS_OVER_TLS_MODE_INVALID
;
539 mode
= dns_over_tls_mode_from_string(dns_over_tls
);
541 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNSOverTLS setting: %s", dns_over_tls
);
544 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
545 "org.freedesktop.resolve1.set-dns-over-tls",
546 NULL
, true, UID_INVALID
,
547 &l
->manager
->polkit_registry
, error
);
551 return 1; /* Polkit will call us back */
553 link_set_dns_over_tls_mode(l
, mode
);
555 (void) link_save_user(l
);
557 return sd_bus_reply_method_return(message
, NULL
);
560 int bus_link_method_set_dnssec(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
569 r
= verify_unmanaged_link(l
, error
);
573 r
= sd_bus_message_read(message
, "s", &dnssec
);
578 mode
= _DNSSEC_MODE_INVALID
;
580 mode
= dnssec_mode_from_string(dnssec
);
582 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNSSEC setting: %s", dnssec
);
585 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
586 "org.freedesktop.resolve1.set-dnssec",
587 NULL
, true, UID_INVALID
,
588 &l
->manager
->polkit_registry
, error
);
592 return 1; /* Polkit will call us back */
594 link_set_dnssec_mode(l
, mode
);
596 (void) link_save_user(l
);
598 return sd_bus_reply_method_return(message
, NULL
);
601 int bus_link_method_set_dnssec_negative_trust_anchors(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
602 _cleanup_set_free_free_ Set
*ns
= NULL
;
603 _cleanup_strv_free_
char **ntas
= NULL
;
611 r
= verify_unmanaged_link(l
, error
);
615 ns
= set_new(&dns_name_hash_ops
);
619 r
= sd_bus_message_read_strv(message
, &ntas
);
623 STRV_FOREACH(i
, ntas
) {
624 r
= dns_name_is_valid(*i
);
628 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
,
629 "Invalid negative trust anchor domain: %s", *i
);
631 r
= set_put_strdup(ns
, *i
);
636 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
637 "org.freedesktop.resolve1.set-dnssec-negative-trust-anchors",
638 NULL
, true, UID_INVALID
,
639 &l
->manager
->polkit_registry
, error
);
643 return 1; /* Polkit will call us back */
645 set_free_free(l
->dnssec_negative_trust_anchors
);
646 l
->dnssec_negative_trust_anchors
= TAKE_PTR(ns
);
648 (void) link_save_user(l
);
650 return sd_bus_reply_method_return(message
, NULL
);
653 int bus_link_method_revert(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
660 r
= verify_unmanaged_link(l
, error
);
664 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
665 "org.freedesktop.resolve1.revert",
666 NULL
, true, UID_INVALID
,
667 &l
->manager
->polkit_registry
, error
);
671 return 1; /* Polkit will call us back */
673 link_flush_settings(l
);
674 link_allocate_scopes(l
);
675 link_add_rrs(l
, false);
677 (void) link_save_user(l
);
678 (void) manager_write_resolv_conf(l
->manager
);
679 (void) manager_send_changed(l
->manager
, "DNS");
681 return sd_bus_reply_method_return(message
, NULL
);
684 const sd_bus_vtable link_vtable
[] = {
685 SD_BUS_VTABLE_START(0),
687 SD_BUS_PROPERTY("ScopesMask", "t", property_get_scopes_mask
, 0, 0),
688 SD_BUS_PROPERTY("DNS", "a(iay)", property_get_dns
, 0, 0),
689 SD_BUS_PROPERTY("CurrentDNSServer", "(iay)", property_get_current_dns_server
, offsetof(Link
, current_dns_server
), 0),
690 SD_BUS_PROPERTY("Domains", "a(sb)", property_get_domains
, 0, 0),
691 SD_BUS_PROPERTY("DefaultRoute", "b", property_get_default_route
, 0, 0),
692 SD_BUS_PROPERTY("LLMNR", "s", bus_property_get_resolve_support
, offsetof(Link
, llmnr_support
), 0),
693 SD_BUS_PROPERTY("MulticastDNS", "s", bus_property_get_resolve_support
, offsetof(Link
, mdns_support
), 0),
694 SD_BUS_PROPERTY("DNSOverTLS", "s", property_get_dns_over_tls_mode
, 0, 0),
695 SD_BUS_PROPERTY("DNSSEC", "s", property_get_dnssec_mode
, 0, 0),
696 SD_BUS_PROPERTY("DNSSECNegativeTrustAnchors", "as", property_get_ntas
, 0, 0),
697 SD_BUS_PROPERTY("DNSSECSupported", "b", property_get_dnssec_supported
, 0, 0),
699 SD_BUS_METHOD("SetDNS", "a(iay)", NULL
, bus_link_method_set_dns_servers
, SD_BUS_VTABLE_UNPRIVILEGED
),
700 SD_BUS_METHOD("SetDomains", "a(sb)", NULL
, bus_link_method_set_domains
, SD_BUS_VTABLE_UNPRIVILEGED
),
701 SD_BUS_METHOD("SetDefaultRoute", "b", NULL
, bus_link_method_set_default_route
, SD_BUS_VTABLE_UNPRIVILEGED
),
702 SD_BUS_METHOD("SetLLMNR", "s", NULL
, bus_link_method_set_llmnr
, SD_BUS_VTABLE_UNPRIVILEGED
),
703 SD_BUS_METHOD("SetMulticastDNS", "s", NULL
, bus_link_method_set_mdns
, SD_BUS_VTABLE_UNPRIVILEGED
),
704 SD_BUS_METHOD("SetDNSOverTLS", "s", NULL
, bus_link_method_set_dns_over_tls
, SD_BUS_VTABLE_UNPRIVILEGED
),
705 SD_BUS_METHOD("SetDNSSEC", "s", NULL
, bus_link_method_set_dnssec
, SD_BUS_VTABLE_UNPRIVILEGED
),
706 SD_BUS_METHOD("SetDNSSECNegativeTrustAnchors", "as", NULL
, bus_link_method_set_dnssec_negative_trust_anchors
, SD_BUS_VTABLE_UNPRIVILEGED
),
707 SD_BUS_METHOD("Revert", NULL
, NULL
, bus_link_method_revert
, SD_BUS_VTABLE_UNPRIVILEGED
),
712 int link_object_find(sd_bus
*bus
, const char *path
, const char *interface
, void *userdata
, void **found
, sd_bus_error
*error
) {
713 _cleanup_free_
char *e
= NULL
;
714 Manager
*m
= userdata
;
724 r
= sd_bus_path_decode(path
, "/org/freedesktop/resolve1/link", &e
);
728 ifindex
= parse_ifindex(e
);
732 link
= hashmap_get(m
->links
, INT_TO_PTR(ifindex
));
740 char *link_bus_path(const Link
*link
) {
741 char *p
, ifindex
[DECIMAL_STR_MAX(link
->ifindex
)];
746 xsprintf(ifindex
, "%i", link
->ifindex
);
748 r
= sd_bus_path_encode("/org/freedesktop/resolve1/link", ifindex
, &p
);
755 int link_node_enumerator(sd_bus
*bus
, const char *path
, void *userdata
, char ***nodes
, sd_bus_error
*error
) {
756 _cleanup_strv_free_
char **l
= NULL
;
757 Manager
*m
= userdata
;
767 l
= new0(char*, hashmap_size(m
->links
) + 1);
771 HASHMAP_FOREACH(link
, m
->links
, i
) {
774 p
= link_bus_path(link
);
782 *nodes
= TAKE_PTR(l
);