1 /* SPDX-License-Identifier: LGPL-2.1+ */
4 #include <netinet/in.h>
5 #include <sys/capability.h>
7 #include "alloc-util.h"
8 #include "bus-common-errors.h"
10 #include "parse-util.h"
11 #include "resolve-util.h"
12 #include "resolved-bus.h"
13 #include "resolved-link-bus.h"
14 #include "resolved-resolv-conf.h"
16 #include "user-util.h"
18 static BUS_DEFINE_PROPERTY_GET(property_get_dnssec_supported
, "b", Link
, link_dnssec_supported
);
19 static BUS_DEFINE_PROPERTY_GET2(property_get_dnssec_mode
, "s", Link
, link_get_dnssec_mode
, dnssec_mode_to_string
);
21 static int property_get_dns_over_tls_mode(
24 const char *interface
,
26 sd_bus_message
*reply
,
28 sd_bus_error
*error
) {
35 return sd_bus_message_append(reply
, "s", dns_over_tls_mode_to_string(link_get_dns_over_tls_mode(l
)));
38 static int property_get_dns(
41 const char *interface
,
43 sd_bus_message
*reply
,
45 sd_bus_error
*error
) {
54 r
= sd_bus_message_open_container(reply
, 'a', "(iay)");
58 LIST_FOREACH(servers
, s
, l
->dns_servers
) {
59 r
= bus_dns_server_append(reply
, s
, false);
64 return sd_bus_message_close_container(reply
);
67 static int property_get_current_dns_server(
70 const char *interface
,
72 sd_bus_message
*reply
,
74 sd_bus_error
*error
) {
81 s
= *(DnsServer
**) userdata
;
83 return bus_dns_server_append(reply
, s
, false);
86 static int property_get_domains(
89 const char *interface
,
91 sd_bus_message
*reply
,
93 sd_bus_error
*error
) {
102 r
= sd_bus_message_open_container(reply
, 'a', "(sb)");
106 LIST_FOREACH(domains
, d
, l
->search_domains
) {
107 r
= sd_bus_message_append(reply
, "(sb)", d
->name
, d
->route_only
);
112 return sd_bus_message_close_container(reply
);
115 static int property_get_default_route(
118 const char *interface
,
119 const char *property
,
120 sd_bus_message
*reply
,
122 sd_bus_error
*error
) {
129 /* Return what is configured, if there's something configured */
130 if (l
->default_route
>= 0)
131 return sd_bus_message_append(reply
, "b", l
->default_route
);
133 /* Otherwise report what is in effect */
134 if (l
->unicast_scope
)
135 return sd_bus_message_append(reply
, "b", dns_scope_is_default_route(l
->unicast_scope
));
137 return sd_bus_message_append(reply
, "b", false);
140 static int property_get_scopes_mask(
143 const char *interface
,
144 const char *property
,
145 sd_bus_message
*reply
,
147 sd_bus_error
*error
) {
155 mask
= (l
->unicast_scope
? SD_RESOLVED_DNS
: 0) |
156 (l
->llmnr_ipv4_scope
? SD_RESOLVED_LLMNR_IPV4
: 0) |
157 (l
->llmnr_ipv6_scope
? SD_RESOLVED_LLMNR_IPV6
: 0) |
158 (l
->mdns_ipv4_scope
? SD_RESOLVED_MDNS_IPV4
: 0) |
159 (l
->mdns_ipv6_scope
? SD_RESOLVED_MDNS_IPV6
: 0);
161 return sd_bus_message_append(reply
, "t", mask
);
164 static int property_get_ntas(
167 const char *interface
,
168 const char *property
,
169 sd_bus_message
*reply
,
171 sd_bus_error
*error
) {
181 r
= sd_bus_message_open_container(reply
, 'a', "s");
185 SET_FOREACH(name
, l
->dnssec_negative_trust_anchors
, i
) {
186 r
= sd_bus_message_append(reply
, "s", name
);
191 return sd_bus_message_close_container(reply
);
194 static int verify_unmanaged_link(Link
*l
, sd_bus_error
*error
) {
197 if (l
->flags
& IFF_LOOPBACK
)
198 return sd_bus_error_setf(error
, BUS_ERROR_LINK_BUSY
, "Link %s is loopback device.", l
->ifname
);
200 return sd_bus_error_setf(error
, BUS_ERROR_LINK_BUSY
, "Link %s is managed.", l
->ifname
);
205 int bus_link_method_set_dns_servers(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
206 _cleanup_free_
struct in_addr_data
*dns
= NULL
;
207 size_t allocated
= 0, n
= 0;
215 r
= verify_unmanaged_link(l
, error
);
219 r
= sd_bus_message_enter_container(message
, 'a', "(iay)");
228 assert_cc(sizeof(int) == sizeof(int32_t));
230 r
= sd_bus_message_enter_container(message
, 'r', "iay");
236 r
= sd_bus_message_read(message
, "i", &family
);
240 if (!IN_SET(family
, AF_INET
, AF_INET6
))
241 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Unknown address family %i", family
);
243 r
= sd_bus_message_read_array(message
, 'y', &d
, &sz
);
246 if (sz
!= FAMILY_ADDRESS_SIZE(family
))
247 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid address size");
249 if (!dns_server_address_valid(family
, d
))
250 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNS server address");
252 r
= sd_bus_message_exit_container(message
);
256 if (!GREEDY_REALLOC(dns
, allocated
, n
+1))
259 dns
[n
].family
= family
;
260 memcpy(&dns
[n
].address
, d
, sz
);
264 r
= sd_bus_message_exit_container(message
);
268 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
269 "org.freedesktop.resolve1.set-dns-servers",
270 NULL
, true, UID_INVALID
,
271 &l
->manager
->polkit_registry
, error
);
275 return 1; /* Polkit will call us back */
277 dns_server_mark_all(l
->dns_servers
);
279 for (i
= 0; i
< n
; i
++) {
282 s
= dns_server_find(l
->dns_servers
, dns
[i
].family
, &dns
[i
].address
, 0);
284 dns_server_move_back_and_unmark(s
);
286 r
= dns_server_new(l
->manager
, NULL
, DNS_SERVER_LINK
, l
, dns
[i
].family
, &dns
[i
].address
, 0);
293 dns_server_unlink_marked(l
->dns_servers
);
294 link_allocate_scopes(l
);
296 (void) link_save_user(l
);
297 (void) manager_write_resolv_conf(l
->manager
);
299 return sd_bus_reply_method_return(message
, NULL
);
302 dns_server_unlink_all(l
->dns_servers
);
306 int bus_link_method_set_domains(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
313 r
= verify_unmanaged_link(l
, error
);
317 r
= sd_bus_message_enter_container(message
, 'a', "(sb)");
325 r
= sd_bus_message_read(message
, "(sb)", &name
, &route_only
);
331 r
= dns_name_is_valid(name
);
335 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid search domain %s", name
);
336 if (!route_only
&& dns_name_is_root(name
))
337 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Root domain is not suitable as search domain");
340 r
= sd_bus_message_rewind(message
, false);
344 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
345 "org.freedesktop.resolve1.set-domains",
346 NULL
, true, UID_INVALID
,
347 &l
->manager
->polkit_registry
, error
);
351 return 1; /* Polkit will call us back */
353 dns_search_domain_mark_all(l
->search_domains
);
360 r
= sd_bus_message_read(message
, "(sb)", &name
, &route_only
);
366 r
= dns_search_domain_find(l
->search_domains
, name
, &d
);
371 dns_search_domain_move_back_and_unmark(d
);
373 r
= dns_search_domain_new(l
->manager
, &d
, DNS_SEARCH_DOMAIN_LINK
, l
, name
);
378 d
->route_only
= route_only
;
381 r
= sd_bus_message_exit_container(message
);
385 dns_search_domain_unlink_marked(l
->search_domains
);
387 (void) link_save_user(l
);
388 (void) manager_write_resolv_conf(l
->manager
);
390 return sd_bus_reply_method_return(message
, NULL
);
393 dns_search_domain_unlink_all(l
->search_domains
);
397 int bus_link_method_set_default_route(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
404 r
= verify_unmanaged_link(l
, error
);
408 r
= sd_bus_message_read(message
, "b", &b
);
412 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
413 "org.freedesktop.resolve1.set-default-route",
414 NULL
, true, UID_INVALID
,
415 &l
->manager
->polkit_registry
, error
);
419 return 1; /* Polkit will call us back */
421 if (l
->default_route
!= b
) {
422 l
->default_route
= b
;
424 (void) link_save_user(l
);
425 (void) manager_write_resolv_conf(l
->manager
);
428 return sd_bus_reply_method_return(message
, NULL
);
431 int bus_link_method_set_llmnr(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
440 r
= verify_unmanaged_link(l
, error
);
444 r
= sd_bus_message_read(message
, "s", &llmnr
);
449 mode
= RESOLVE_SUPPORT_YES
;
451 mode
= resolve_support_from_string(llmnr
);
453 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid LLMNR setting: %s", llmnr
);
456 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
457 "org.freedesktop.resolve1.set-llmnr",
458 NULL
, true, UID_INVALID
,
459 &l
->manager
->polkit_registry
, error
);
463 return 1; /* Polkit will call us back */
465 l
->llmnr_support
= mode
;
466 link_allocate_scopes(l
);
467 link_add_rrs(l
, false);
469 (void) link_save_user(l
);
471 return sd_bus_reply_method_return(message
, NULL
);
474 int bus_link_method_set_mdns(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
483 r
= verify_unmanaged_link(l
, error
);
487 r
= sd_bus_message_read(message
, "s", &mdns
);
492 mode
= RESOLVE_SUPPORT_NO
;
494 mode
= resolve_support_from_string(mdns
);
496 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid MulticastDNS setting: %s", mdns
);
499 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
500 "org.freedesktop.resolve1.set-mdns",
501 NULL
, true, UID_INVALID
,
502 &l
->manager
->polkit_registry
, error
);
506 return 1; /* Polkit will call us back */
508 l
->mdns_support
= mode
;
509 link_allocate_scopes(l
);
510 link_add_rrs(l
, false);
512 (void) link_save_user(l
);
514 return sd_bus_reply_method_return(message
, NULL
);
517 int bus_link_method_set_dns_over_tls(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
519 const char *dns_over_tls
;
526 r
= verify_unmanaged_link(l
, error
);
530 r
= sd_bus_message_read(message
, "s", &dns_over_tls
);
534 if (isempty(dns_over_tls
))
535 mode
= _DNS_OVER_TLS_MODE_INVALID
;
537 mode
= dns_over_tls_mode_from_string(dns_over_tls
);
539 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNSOverTLS setting: %s", dns_over_tls
);
542 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
543 "org.freedesktop.resolve1.set-dns-over-tls",
544 NULL
, true, UID_INVALID
,
545 &l
->manager
->polkit_registry
, error
);
549 return 1; /* Polkit will call us back */
551 link_set_dns_over_tls_mode(l
, mode
);
553 (void) link_save_user(l
);
555 return sd_bus_reply_method_return(message
, NULL
);
558 int bus_link_method_set_dnssec(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
567 r
= verify_unmanaged_link(l
, error
);
571 r
= sd_bus_message_read(message
, "s", &dnssec
);
576 mode
= _DNSSEC_MODE_INVALID
;
578 mode
= dnssec_mode_from_string(dnssec
);
580 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNSSEC setting: %s", dnssec
);
583 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
584 "org.freedesktop.resolve1.set-dnssec",
585 NULL
, true, UID_INVALID
,
586 &l
->manager
->polkit_registry
, error
);
590 return 1; /* Polkit will call us back */
592 link_set_dnssec_mode(l
, mode
);
594 (void) link_save_user(l
);
596 return sd_bus_reply_method_return(message
, NULL
);
599 int bus_link_method_set_dnssec_negative_trust_anchors(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
600 _cleanup_set_free_free_ Set
*ns
= NULL
;
601 _cleanup_strv_free_
char **ntas
= NULL
;
609 r
= verify_unmanaged_link(l
, error
);
613 ns
= set_new(&dns_name_hash_ops
);
617 r
= sd_bus_message_read_strv(message
, &ntas
);
621 STRV_FOREACH(i
, ntas
) {
622 r
= dns_name_is_valid(*i
);
626 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
,
627 "Invalid negative trust anchor domain: %s", *i
);
629 r
= set_put_strdup(ns
, *i
);
634 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
635 "org.freedesktop.resolve1.set-dnssec-negative-trust-anchors",
636 NULL
, true, UID_INVALID
,
637 &l
->manager
->polkit_registry
, error
);
641 return 1; /* Polkit will call us back */
643 set_free_free(l
->dnssec_negative_trust_anchors
);
644 l
->dnssec_negative_trust_anchors
= TAKE_PTR(ns
);
646 (void) link_save_user(l
);
648 return sd_bus_reply_method_return(message
, NULL
);
651 int bus_link_method_revert(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
658 r
= verify_unmanaged_link(l
, error
);
662 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
663 "org.freedesktop.resolve1.revert",
664 NULL
, true, UID_INVALID
,
665 &l
->manager
->polkit_registry
, error
);
669 return 1; /* Polkit will call us back */
671 link_flush_settings(l
);
672 link_allocate_scopes(l
);
673 link_add_rrs(l
, false);
675 (void) link_save_user(l
);
676 (void) manager_write_resolv_conf(l
->manager
);
678 return sd_bus_reply_method_return(message
, NULL
);
681 const sd_bus_vtable link_vtable
[] = {
682 SD_BUS_VTABLE_START(0),
684 SD_BUS_PROPERTY("ScopesMask", "t", property_get_scopes_mask
, 0, 0),
685 SD_BUS_PROPERTY("DNS", "a(iay)", property_get_dns
, 0, 0),
686 SD_BUS_PROPERTY("CurrentDNSServer", "(iay)", property_get_current_dns_server
, offsetof(Link
, current_dns_server
), 0),
687 SD_BUS_PROPERTY("Domains", "a(sb)", property_get_domains
, 0, 0),
688 SD_BUS_PROPERTY("DefaultRoute", "b", property_get_default_route
, 0, 0),
689 SD_BUS_PROPERTY("LLMNR", "s", bus_property_get_resolve_support
, offsetof(Link
, llmnr_support
), 0),
690 SD_BUS_PROPERTY("MulticastDNS", "s", bus_property_get_resolve_support
, offsetof(Link
, mdns_support
), 0),
691 SD_BUS_PROPERTY("DNSOverTLS", "s", property_get_dns_over_tls_mode
, 0, 0),
692 SD_BUS_PROPERTY("DNSSEC", "s", property_get_dnssec_mode
, 0, 0),
693 SD_BUS_PROPERTY("DNSSECNegativeTrustAnchors", "as", property_get_ntas
, 0, 0),
694 SD_BUS_PROPERTY("DNSSECSupported", "b", property_get_dnssec_supported
, 0, 0),
696 SD_BUS_METHOD("SetDNS", "a(iay)", NULL
, bus_link_method_set_dns_servers
, SD_BUS_VTABLE_UNPRIVILEGED
),
697 SD_BUS_METHOD("SetDomains", "a(sb)", NULL
, bus_link_method_set_domains
, SD_BUS_VTABLE_UNPRIVILEGED
),
698 SD_BUS_METHOD("SetDefaultRoute", "b", NULL
, bus_link_method_set_default_route
, SD_BUS_VTABLE_UNPRIVILEGED
),
699 SD_BUS_METHOD("SetLLMNR", "s", NULL
, bus_link_method_set_llmnr
, SD_BUS_VTABLE_UNPRIVILEGED
),
700 SD_BUS_METHOD("SetMulticastDNS", "s", NULL
, bus_link_method_set_mdns
, SD_BUS_VTABLE_UNPRIVILEGED
),
701 SD_BUS_METHOD("SetDNSOverTLS", "s", NULL
, bus_link_method_set_dns_over_tls
, SD_BUS_VTABLE_UNPRIVILEGED
),
702 SD_BUS_METHOD("SetDNSSEC", "s", NULL
, bus_link_method_set_dnssec
, SD_BUS_VTABLE_UNPRIVILEGED
),
703 SD_BUS_METHOD("SetDNSSECNegativeTrustAnchors", "as", NULL
, bus_link_method_set_dnssec_negative_trust_anchors
, SD_BUS_VTABLE_UNPRIVILEGED
),
704 SD_BUS_METHOD("Revert", NULL
, NULL
, bus_link_method_revert
, SD_BUS_VTABLE_UNPRIVILEGED
),
709 int link_object_find(sd_bus
*bus
, const char *path
, const char *interface
, void *userdata
, void **found
, sd_bus_error
*error
) {
710 _cleanup_free_
char *e
= NULL
;
711 Manager
*m
= userdata
;
722 r
= sd_bus_path_decode(path
, "/org/freedesktop/resolve1/link", &e
);
726 r
= parse_ifindex(e
, &ifindex
);
730 link
= hashmap_get(m
->links
, INT_TO_PTR(ifindex
));
738 char *link_bus_path(Link
*link
) {
739 _cleanup_free_
char *ifindex
= NULL
;
745 if (asprintf(&ifindex
, "%i", link
->ifindex
) < 0)
748 r
= sd_bus_path_encode("/org/freedesktop/resolve1/link", ifindex
, &p
);
755 int link_node_enumerator(sd_bus
*bus
, const char *path
, void *userdata
, char ***nodes
, sd_bus_error
*error
) {
756 _cleanup_strv_free_
char **l
= NULL
;
757 Manager
*m
= userdata
;
767 l
= new0(char*, hashmap_size(m
->links
) + 1);
771 HASHMAP_FOREACH(link
, m
->links
, i
) {
774 p
= link_bus_path(link
);
782 *nodes
= TAKE_PTR(l
);