]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/resolve/resolved-bus.c
Merge pull request #10897 from keszybz/etc-fstab-parsing
[thirdparty/systemd.git] / src / resolve / resolved-bus.c
1 /* SPDX-License-Identifier: LGPL-2.1+ */
2
3 #include "alloc-util.h"
4 #include "bus-common-errors.h"
5 #include "bus-util.h"
6 #include "dns-domain.h"
7 #include "missing_capability.h"
8 #include "resolved-bus.h"
9 #include "resolved-def.h"
10 #include "resolved-dns-synthesize.h"
11 #include "resolved-dnssd.h"
12 #include "resolved-dnssd-bus.h"
13 #include "resolved-link-bus.h"
14 #include "user-util.h"
15 #include "utf8.h"
16
17 BUS_DEFINE_PROPERTY_GET_ENUM(bus_property_get_resolve_support, resolve_support, ResolveSupport);
18
19 static int reply_query_state(DnsQuery *q) {
20
21 switch (q->state) {
22
23 case DNS_TRANSACTION_NO_SERVERS:
24 return sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_NAME_SERVERS, "No appropriate name servers or networks for name found");
25
26 case DNS_TRANSACTION_TIMEOUT:
27 return sd_bus_reply_method_errorf(q->request, SD_BUS_ERROR_TIMEOUT, "Query timed out");
28
29 case DNS_TRANSACTION_ATTEMPTS_MAX_REACHED:
30 return sd_bus_reply_method_errorf(q->request, SD_BUS_ERROR_TIMEOUT, "All attempts to contact name servers or networks failed");
31
32 case DNS_TRANSACTION_INVALID_REPLY:
33 return sd_bus_reply_method_errorf(q->request, BUS_ERROR_INVALID_REPLY, "Received invalid reply");
34
35 case DNS_TRANSACTION_ERRNO:
36 return sd_bus_reply_method_errnof(q->request, q->answer_errno, "Lookup failed due to system error: %m");
37
38 case DNS_TRANSACTION_ABORTED:
39 return sd_bus_reply_method_errorf(q->request, BUS_ERROR_ABORTED, "Query aborted");
40
41 case DNS_TRANSACTION_DNSSEC_FAILED:
42 return sd_bus_reply_method_errorf(q->request, BUS_ERROR_DNSSEC_FAILED, "DNSSEC validation failed: %s",
43 dnssec_result_to_string(q->answer_dnssec_result));
44
45 case DNS_TRANSACTION_NO_TRUST_ANCHOR:
46 return sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_TRUST_ANCHOR, "No suitable trust anchor known");
47
48 case DNS_TRANSACTION_RR_TYPE_UNSUPPORTED:
49 return sd_bus_reply_method_errorf(q->request, BUS_ERROR_RR_TYPE_UNSUPPORTED, "Server does not support requested resource record type");
50
51 case DNS_TRANSACTION_NETWORK_DOWN:
52 return sd_bus_reply_method_errorf(q->request, BUS_ERROR_NETWORK_DOWN, "Network is down");
53
54 case DNS_TRANSACTION_NOT_FOUND:
55 /* We return this as NXDOMAIN. This is only generated when a host doesn't implement LLMNR/TCP, and we
56 * thus quickly know that we cannot resolve an in-addr.arpa or ip6.arpa address. */
57 return sd_bus_reply_method_errorf(q->request, _BUS_ERROR_DNS "NXDOMAIN", "'%s' not found", dns_query_string(q));
58
59 case DNS_TRANSACTION_RCODE_FAILURE: {
60 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
61
62 if (q->answer_rcode == DNS_RCODE_NXDOMAIN)
63 sd_bus_error_setf(&error, _BUS_ERROR_DNS "NXDOMAIN", "'%s' not found", dns_query_string(q));
64 else {
65 const char *rc, *n;
66 char p[DECIMAL_STR_MAX(q->answer_rcode)];
67
68 rc = dns_rcode_to_string(q->answer_rcode);
69 if (!rc) {
70 sprintf(p, "%i", q->answer_rcode);
71 rc = p;
72 }
73
74 n = strjoina(_BUS_ERROR_DNS, rc);
75 sd_bus_error_setf(&error, n, "Could not resolve '%s', server or network returned error %s", dns_query_string(q), rc);
76 }
77
78 return sd_bus_reply_method_error(q->request, &error);
79 }
80
81 case DNS_TRANSACTION_NULL:
82 case DNS_TRANSACTION_PENDING:
83 case DNS_TRANSACTION_VALIDATING:
84 case DNS_TRANSACTION_SUCCESS:
85 default:
86 assert_not_reached("Impossible state");
87 }
88 }
89
90 static int append_address(sd_bus_message *reply, DnsResourceRecord *rr, int ifindex) {
91 int r;
92
93 assert(reply);
94 assert(rr);
95
96 r = sd_bus_message_open_container(reply, 'r', "iiay");
97 if (r < 0)
98 return r;
99
100 r = sd_bus_message_append(reply, "i", ifindex);
101 if (r < 0)
102 return r;
103
104 if (rr->key->type == DNS_TYPE_A) {
105 r = sd_bus_message_append(reply, "i", AF_INET);
106 if (r < 0)
107 return r;
108
109 r = sd_bus_message_append_array(reply, 'y', &rr->a.in_addr, sizeof(struct in_addr));
110
111 } else if (rr->key->type == DNS_TYPE_AAAA) {
112 r = sd_bus_message_append(reply, "i", AF_INET6);
113 if (r < 0)
114 return r;
115
116 r = sd_bus_message_append_array(reply, 'y', &rr->aaaa.in6_addr, sizeof(struct in6_addr));
117 } else
118 return -EAFNOSUPPORT;
119
120 if (r < 0)
121 return r;
122
123 r = sd_bus_message_close_container(reply);
124 if (r < 0)
125 return r;
126
127 return 0;
128 }
129
130 static void bus_method_resolve_hostname_complete(DnsQuery *q) {
131 _cleanup_(dns_resource_record_unrefp) DnsResourceRecord *canonical = NULL;
132 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
133 _cleanup_free_ char *normalized = NULL;
134 DnsResourceRecord *rr;
135 unsigned added = 0;
136 int ifindex, r;
137
138 assert(q);
139
140 if (q->state != DNS_TRANSACTION_SUCCESS) {
141 r = reply_query_state(q);
142 goto finish;
143 }
144
145 r = dns_query_process_cname(q);
146 if (r == -ELOOP) {
147 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_CNAME_LOOP, "CNAME loop detected, or CNAME resolving disabled on '%s'", dns_query_string(q));
148 goto finish;
149 }
150 if (r < 0)
151 goto finish;
152 if (r == DNS_QUERY_RESTARTED) /* This was a cname, and the query was restarted. */
153 return;
154
155 r = sd_bus_message_new_method_return(q->request, &reply);
156 if (r < 0)
157 goto finish;
158
159 r = sd_bus_message_open_container(reply, 'a', "(iiay)");
160 if (r < 0)
161 goto finish;
162
163 DNS_ANSWER_FOREACH_IFINDEX(rr, ifindex, q->answer) {
164 DnsQuestion *question;
165
166 question = dns_query_question_for_protocol(q, q->answer_protocol);
167
168 r = dns_question_matches_rr(question, rr, DNS_SEARCH_DOMAIN_NAME(q->answer_search_domain));
169 if (r < 0)
170 goto finish;
171 if (r == 0)
172 continue;
173
174 r = append_address(reply, rr, ifindex);
175 if (r < 0)
176 goto finish;
177
178 if (!canonical)
179 canonical = dns_resource_record_ref(rr);
180
181 added++;
182 }
183
184 if (added <= 0) {
185 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_SUCH_RR, "'%s' does not have any RR of the requested type", dns_query_string(q));
186 goto finish;
187 }
188
189 r = sd_bus_message_close_container(reply);
190 if (r < 0)
191 goto finish;
192
193 /* The key names are not necessarily normalized, make sure that they are when we return them to our bus
194 * clients. */
195 r = dns_name_normalize(dns_resource_key_name(canonical->key), 0, &normalized);
196 if (r < 0)
197 goto finish;
198
199 /* Return the precise spelling and uppercasing and CNAME target reported by the server */
200 assert(canonical);
201 r = sd_bus_message_append(
202 reply, "st",
203 normalized,
204 SD_RESOLVED_FLAGS_MAKE(q->answer_protocol, q->answer_family, dns_query_fully_authenticated(q)));
205 if (r < 0)
206 goto finish;
207
208 r = sd_bus_send(q->manager->bus, reply, NULL);
209
210 finish:
211 if (r < 0) {
212 log_error_errno(r, "Failed to send hostname reply: %m");
213 sd_bus_reply_method_errno(q->request, r, NULL);
214 }
215
216 dns_query_free(q);
217 }
218
219 static int check_ifindex_flags(int ifindex, uint64_t *flags, uint64_t ok, sd_bus_error *error) {
220 assert(flags);
221
222 if (ifindex < 0)
223 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid interface index");
224
225 if (*flags & ~(SD_RESOLVED_PROTOCOLS_ALL|SD_RESOLVED_NO_CNAME|ok))
226 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid flags parameter");
227
228 if ((*flags & SD_RESOLVED_PROTOCOLS_ALL) == 0) /* If no protocol is enabled, enable all */
229 *flags |= SD_RESOLVED_PROTOCOLS_ALL;
230
231 return 0;
232 }
233
234 static int parse_as_address(sd_bus_message *m, int ifindex, const char *hostname, int family, uint64_t flags) {
235 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
236 _cleanup_free_ char *canonical = NULL;
237 union in_addr_union parsed;
238 int r, ff, parsed_ifindex = 0;
239
240 /* Check if the hostname is actually already an IP address formatted as string. In that case just parse it,
241 * let's not attempt to look it up. */
242
243 r = in_addr_ifindex_from_string_auto(hostname, &ff, &parsed, &parsed_ifindex);
244 if (r < 0) /* not an address */
245 return 0;
246
247 if (family != AF_UNSPEC && ff != family)
248 return sd_bus_reply_method_errorf(m, BUS_ERROR_NO_SUCH_RR, "The specified address is not of the requested family.");
249 if (ifindex > 0 && parsed_ifindex > 0 && parsed_ifindex != ifindex)
250 return sd_bus_reply_method_errorf(m, BUS_ERROR_NO_SUCH_RR, "The specified address interface index does not match requested interface.");
251
252 if (parsed_ifindex > 0)
253 ifindex = parsed_ifindex;
254
255 r = sd_bus_message_new_method_return(m, &reply);
256 if (r < 0)
257 return r;
258
259 r = sd_bus_message_open_container(reply, 'a', "(iiay)");
260 if (r < 0)
261 return r;
262
263 r = sd_bus_message_open_container(reply, 'r', "iiay");
264 if (r < 0)
265 return r;
266
267 r = sd_bus_message_append(reply, "ii", ifindex, ff);
268 if (r < 0)
269 return r;
270
271 r = sd_bus_message_append_array(reply, 'y', &parsed, FAMILY_ADDRESS_SIZE(ff));
272 if (r < 0)
273 return r;
274
275 r = sd_bus_message_close_container(reply);
276 if (r < 0)
277 return r;
278
279 r = sd_bus_message_close_container(reply);
280 if (r < 0)
281 return r;
282
283 /* When an IP address is specified we just return it as canonical name, in order to avoid a DNS
284 * look-up. However, we reformat it to make sure it's in a truly canonical form (i.e. on IPv6 the inner
285 * omissions are always done the same way). */
286 r = in_addr_ifindex_to_string(ff, &parsed, ifindex, &canonical);
287 if (r < 0)
288 return r;
289
290 r = sd_bus_message_append(reply, "st", canonical,
291 SD_RESOLVED_FLAGS_MAKE(dns_synthesize_protocol(flags), ff, true));
292 if (r < 0)
293 return r;
294
295 return sd_bus_send(sd_bus_message_get_bus(m), reply, NULL);
296 }
297
298 static int bus_method_resolve_hostname(sd_bus_message *message, void *userdata, sd_bus_error *error) {
299 _cleanup_(dns_question_unrefp) DnsQuestion *question_idna = NULL, *question_utf8 = NULL;
300 Manager *m = userdata;
301 const char *hostname;
302 int family, ifindex;
303 uint64_t flags;
304 DnsQuery *q;
305 int r;
306
307 assert(message);
308 assert(m);
309
310 assert_cc(sizeof(int) == sizeof(int32_t));
311
312 r = sd_bus_message_read(message, "isit", &ifindex, &hostname, &family, &flags);
313 if (r < 0)
314 return r;
315
316 if (!IN_SET(family, AF_INET, AF_INET6, AF_UNSPEC))
317 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Unknown address family %i", family);
318
319 r = check_ifindex_flags(ifindex, &flags, SD_RESOLVED_NO_SEARCH, error);
320 if (r < 0)
321 return r;
322
323 r = parse_as_address(message, ifindex, hostname, family, flags);
324 if (r != 0)
325 return r;
326
327 r = dns_name_is_valid(hostname);
328 if (r < 0)
329 return r;
330 if (r == 0)
331 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid hostname '%s'", hostname);
332
333 r = dns_question_new_address(&question_utf8, family, hostname, false);
334 if (r < 0)
335 return r;
336
337 r = dns_question_new_address(&question_idna, family, hostname, true);
338 if (r < 0 && r != -EALREADY)
339 return r;
340
341 r = dns_query_new(m, &q, question_utf8, question_idna ?: question_utf8, ifindex, flags);
342 if (r < 0)
343 return r;
344
345 q->request = sd_bus_message_ref(message);
346 q->request_family = family;
347 q->complete = bus_method_resolve_hostname_complete;
348 q->suppress_unroutable_family = family == AF_UNSPEC;
349
350 r = dns_query_bus_track(q, message);
351 if (r < 0)
352 goto fail;
353
354 r = dns_query_go(q);
355 if (r < 0)
356 goto fail;
357
358 return 1;
359
360 fail:
361 dns_query_free(q);
362 return r;
363 }
364
365 static void bus_method_resolve_address_complete(DnsQuery *q) {
366 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
367 DnsQuestion *question;
368 DnsResourceRecord *rr;
369 unsigned added = 0;
370 int ifindex, r;
371
372 assert(q);
373
374 if (q->state != DNS_TRANSACTION_SUCCESS) {
375 r = reply_query_state(q);
376 goto finish;
377 }
378
379 r = dns_query_process_cname(q);
380 if (r == -ELOOP) {
381 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_CNAME_LOOP, "CNAME loop detected, or CNAME resolving disabled on '%s'", dns_query_string(q));
382 goto finish;
383 }
384 if (r < 0)
385 goto finish;
386 if (r == DNS_QUERY_RESTARTED) /* This was a cname, and the query was restarted. */
387 return;
388
389 r = sd_bus_message_new_method_return(q->request, &reply);
390 if (r < 0)
391 goto finish;
392
393 r = sd_bus_message_open_container(reply, 'a', "(is)");
394 if (r < 0)
395 goto finish;
396
397 question = dns_query_question_for_protocol(q, q->answer_protocol);
398
399 DNS_ANSWER_FOREACH_IFINDEX(rr, ifindex, q->answer) {
400 _cleanup_free_ char *normalized = NULL;
401
402 r = dns_question_matches_rr(question, rr, NULL);
403 if (r < 0)
404 goto finish;
405 if (r == 0)
406 continue;
407
408 r = dns_name_normalize(rr->ptr.name, 0, &normalized);
409 if (r < 0)
410 goto finish;
411
412 r = sd_bus_message_append(reply, "(is)", ifindex, normalized);
413 if (r < 0)
414 goto finish;
415
416 added++;
417 }
418
419 if (added <= 0) {
420 _cleanup_free_ char *ip = NULL;
421
422 (void) in_addr_to_string(q->request_family, &q->request_address, &ip);
423 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_SUCH_RR,
424 "Address '%s' does not have any RR of requested type", strnull(ip));
425 goto finish;
426 }
427
428 r = sd_bus_message_close_container(reply);
429 if (r < 0)
430 goto finish;
431
432 r = sd_bus_message_append(reply, "t", SD_RESOLVED_FLAGS_MAKE(q->answer_protocol, q->answer_family, dns_query_fully_authenticated(q)));
433 if (r < 0)
434 goto finish;
435
436 r = sd_bus_send(q->manager->bus, reply, NULL);
437
438 finish:
439 if (r < 0) {
440 log_error_errno(r, "Failed to send address reply: %m");
441 sd_bus_reply_method_errno(q->request, r, NULL);
442 }
443
444 dns_query_free(q);
445 }
446
447 static int bus_method_resolve_address(sd_bus_message *message, void *userdata, sd_bus_error *error) {
448 _cleanup_(dns_question_unrefp) DnsQuestion *question = NULL;
449 Manager *m = userdata;
450 int family, ifindex;
451 uint64_t flags;
452 const void *d;
453 DnsQuery *q;
454 size_t sz;
455 int r;
456
457 assert(message);
458 assert(m);
459
460 assert_cc(sizeof(int) == sizeof(int32_t));
461
462 r = sd_bus_message_read(message, "ii", &ifindex, &family);
463 if (r < 0)
464 return r;
465
466 if (!IN_SET(family, AF_INET, AF_INET6))
467 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Unknown address family %i", family);
468
469 r = sd_bus_message_read_array(message, 'y', &d, &sz);
470 if (r < 0)
471 return r;
472
473 if (sz != FAMILY_ADDRESS_SIZE(family))
474 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid address size");
475
476 r = sd_bus_message_read(message, "t", &flags);
477 if (r < 0)
478 return r;
479
480 r = check_ifindex_flags(ifindex, &flags, 0, error);
481 if (r < 0)
482 return r;
483
484 r = dns_question_new_reverse(&question, family, d);
485 if (r < 0)
486 return r;
487
488 r = dns_query_new(m, &q, question, question, ifindex, flags|SD_RESOLVED_NO_SEARCH);
489 if (r < 0)
490 return r;
491
492 q->request = sd_bus_message_ref(message);
493 q->request_family = family;
494 memcpy(&q->request_address, d, sz);
495 q->complete = bus_method_resolve_address_complete;
496
497 r = dns_query_bus_track(q, message);
498 if (r < 0)
499 goto fail;
500
501 r = dns_query_go(q);
502 if (r < 0)
503 goto fail;
504
505 return 1;
506
507 fail:
508 dns_query_free(q);
509 return r;
510 }
511
512 static int bus_message_append_rr(sd_bus_message *m, DnsResourceRecord *rr, int ifindex) {
513 int r;
514
515 assert(m);
516 assert(rr);
517
518 r = sd_bus_message_open_container(m, 'r', "iqqay");
519 if (r < 0)
520 return r;
521
522 r = sd_bus_message_append(m, "iqq",
523 ifindex,
524 rr->key->class,
525 rr->key->type);
526 if (r < 0)
527 return r;
528
529 r = dns_resource_record_to_wire_format(rr, false);
530 if (r < 0)
531 return r;
532
533 r = sd_bus_message_append_array(m, 'y', rr->wire_format, rr->wire_format_size);
534 if (r < 0)
535 return r;
536
537 return sd_bus_message_close_container(m);
538 }
539
540 static void bus_method_resolve_record_complete(DnsQuery *q) {
541 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
542 DnsResourceRecord *rr;
543 DnsQuestion *question;
544 unsigned added = 0;
545 int ifindex;
546 int r;
547
548 assert(q);
549
550 if (q->state != DNS_TRANSACTION_SUCCESS) {
551 r = reply_query_state(q);
552 goto finish;
553 }
554
555 r = dns_query_process_cname(q);
556 if (r == -ELOOP) {
557 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_CNAME_LOOP, "CNAME loop detected, or CNAME resolving disabled on '%s'", dns_query_string(q));
558 goto finish;
559 }
560 if (r < 0)
561 goto finish;
562 if (r == DNS_QUERY_RESTARTED) /* This was a cname, and the query was restarted. */
563 return;
564
565 r = sd_bus_message_new_method_return(q->request, &reply);
566 if (r < 0)
567 goto finish;
568
569 r = sd_bus_message_open_container(reply, 'a', "(iqqay)");
570 if (r < 0)
571 goto finish;
572
573 question = dns_query_question_for_protocol(q, q->answer_protocol);
574
575 DNS_ANSWER_FOREACH_IFINDEX(rr, ifindex, q->answer) {
576 r = dns_question_matches_rr(question, rr, NULL);
577 if (r < 0)
578 goto finish;
579 if (r == 0)
580 continue;
581
582 r = bus_message_append_rr(reply, rr, ifindex);
583 if (r < 0)
584 goto finish;
585
586 added++;
587 }
588
589 if (added <= 0) {
590 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_SUCH_RR, "Name '%s' does not have any RR of the requested type", dns_query_string(q));
591 goto finish;
592 }
593
594 r = sd_bus_message_close_container(reply);
595 if (r < 0)
596 goto finish;
597
598 r = sd_bus_message_append(reply, "t", SD_RESOLVED_FLAGS_MAKE(q->answer_protocol, q->answer_family, dns_query_fully_authenticated(q)));
599 if (r < 0)
600 goto finish;
601
602 r = sd_bus_send(q->manager->bus, reply, NULL);
603
604 finish:
605 if (r < 0) {
606 log_error_errno(r, "Failed to send record reply: %m");
607 sd_bus_reply_method_errno(q->request, r, NULL);
608 }
609
610 dns_query_free(q);
611 }
612
613 static int bus_method_resolve_record(sd_bus_message *message, void *userdata, sd_bus_error *error) {
614 _cleanup_(dns_resource_key_unrefp) DnsResourceKey *key = NULL;
615 _cleanup_(dns_question_unrefp) DnsQuestion *question = NULL;
616 Manager *m = userdata;
617 uint16_t class, type;
618 const char *name;
619 int r, ifindex;
620 uint64_t flags;
621 DnsQuery *q;
622
623 assert(message);
624 assert(m);
625
626 assert_cc(sizeof(int) == sizeof(int32_t));
627
628 r = sd_bus_message_read(message, "isqqt", &ifindex, &name, &class, &type, &flags);
629 if (r < 0)
630 return r;
631
632 r = dns_name_is_valid(name);
633 if (r < 0)
634 return r;
635 if (r == 0)
636 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid name '%s'", name);
637
638 if (!dns_type_is_valid_query(type))
639 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Specified resource record type %" PRIu16 " may not be used in a query.", type);
640 if (dns_type_is_zone_transer(type))
641 return sd_bus_error_setf(error, SD_BUS_ERROR_NOT_SUPPORTED, "Zone transfers not permitted via this programming interface.");
642 if (dns_type_is_obsolete(type))
643 return sd_bus_error_setf(error, SD_BUS_ERROR_NOT_SUPPORTED, "Specified DNS resource record type %" PRIu16 " is obsolete.", type);
644
645 r = check_ifindex_flags(ifindex, &flags, 0, error);
646 if (r < 0)
647 return r;
648
649 question = dns_question_new(1);
650 if (!question)
651 return -ENOMEM;
652
653 key = dns_resource_key_new(class, type, name);
654 if (!key)
655 return -ENOMEM;
656
657 r = dns_question_add(question, key);
658 if (r < 0)
659 return r;
660
661 r = dns_query_new(m, &q, question, question, ifindex, flags|SD_RESOLVED_NO_SEARCH);
662 if (r < 0)
663 return r;
664
665 /* Let's request that the TTL is fixed up for locally cached entries, after all we return it in the wire format
666 * blob */
667 q->clamp_ttl = true;
668
669 q->request = sd_bus_message_ref(message);
670 q->complete = bus_method_resolve_record_complete;
671
672 r = dns_query_bus_track(q, message);
673 if (r < 0)
674 goto fail;
675
676 r = dns_query_go(q);
677 if (r < 0)
678 goto fail;
679
680 return 1;
681
682 fail:
683 dns_query_free(q);
684 return r;
685 }
686
687 static int append_srv(DnsQuery *q, sd_bus_message *reply, DnsResourceRecord *rr) {
688 _cleanup_(dns_resource_record_unrefp) DnsResourceRecord *canonical = NULL;
689 _cleanup_free_ char *normalized = NULL;
690 DnsQuery *aux;
691 int r;
692
693 assert(q);
694 assert(reply);
695 assert(rr);
696 assert(rr->key);
697
698 if (rr->key->type != DNS_TYPE_SRV)
699 return 0;
700
701 if ((q->flags & SD_RESOLVED_NO_ADDRESS) == 0) {
702 /* First, let's see if we could find an appropriate A or AAAA
703 * record for the SRV record */
704 LIST_FOREACH(auxiliary_queries, aux, q->auxiliary_queries) {
705 DnsResourceRecord *zz;
706 DnsQuestion *question;
707
708 if (aux->state != DNS_TRANSACTION_SUCCESS)
709 continue;
710 if (aux->auxiliary_result != 0)
711 continue;
712
713 question = dns_query_question_for_protocol(aux, aux->answer_protocol);
714
715 r = dns_name_equal(dns_question_first_name(question), rr->srv.name);
716 if (r < 0)
717 return r;
718 if (r == 0)
719 continue;
720
721 DNS_ANSWER_FOREACH(zz, aux->answer) {
722
723 r = dns_question_matches_rr(question, zz, NULL);
724 if (r < 0)
725 return r;
726 if (r == 0)
727 continue;
728
729 canonical = dns_resource_record_ref(zz);
730 break;
731 }
732
733 if (canonical)
734 break;
735 }
736
737 /* Is there are successful A/AAAA lookup for this SRV RR? If not, don't add it */
738 if (!canonical)
739 return 0;
740 }
741
742 r = sd_bus_message_open_container(reply, 'r', "qqqsa(iiay)s");
743 if (r < 0)
744 return r;
745
746 r = dns_name_normalize(rr->srv.name, 0, &normalized);
747 if (r < 0)
748 return r;
749
750 r = sd_bus_message_append(
751 reply,
752 "qqqs",
753 rr->srv.priority, rr->srv.weight, rr->srv.port, normalized);
754 if (r < 0)
755 return r;
756
757 r = sd_bus_message_open_container(reply, 'a', "(iiay)");
758 if (r < 0)
759 return r;
760
761 if ((q->flags & SD_RESOLVED_NO_ADDRESS) == 0) {
762 LIST_FOREACH(auxiliary_queries, aux, q->auxiliary_queries) {
763 DnsResourceRecord *zz;
764 DnsQuestion *question;
765 int ifindex;
766
767 if (aux->state != DNS_TRANSACTION_SUCCESS)
768 continue;
769 if (aux->auxiliary_result != 0)
770 continue;
771
772 question = dns_query_question_for_protocol(aux, aux->answer_protocol);
773
774 r = dns_name_equal(dns_question_first_name(question), rr->srv.name);
775 if (r < 0)
776 return r;
777 if (r == 0)
778 continue;
779
780 DNS_ANSWER_FOREACH_IFINDEX(zz, ifindex, aux->answer) {
781
782 r = dns_question_matches_rr(question, zz, NULL);
783 if (r < 0)
784 return r;
785 if (r == 0)
786 continue;
787
788 r = append_address(reply, zz, ifindex);
789 if (r < 0)
790 return r;
791 }
792 }
793 }
794
795 r = sd_bus_message_close_container(reply);
796 if (r < 0)
797 return r;
798
799 if (canonical) {
800 normalized = mfree(normalized);
801
802 r = dns_name_normalize(dns_resource_key_name(canonical->key), 0, &normalized);
803 if (r < 0)
804 return r;
805 }
806
807 /* Note that above we appended the hostname as encoded in the
808 * SRV, and here the canonical hostname this maps to. */
809 r = sd_bus_message_append(reply, "s", normalized);
810 if (r < 0)
811 return r;
812
813 r = sd_bus_message_close_container(reply);
814 if (r < 0)
815 return r;
816
817 return 1;
818 }
819
820 static int append_txt(sd_bus_message *reply, DnsResourceRecord *rr) {
821 DnsTxtItem *i;
822 int r;
823
824 assert(reply);
825 assert(rr);
826 assert(rr->key);
827
828 if (rr->key->type != DNS_TYPE_TXT)
829 return 0;
830
831 LIST_FOREACH(items, i, rr->txt.items) {
832
833 if (i->length <= 0)
834 continue;
835
836 r = sd_bus_message_append_array(reply, 'y', i->data, i->length);
837 if (r < 0)
838 return r;
839 }
840
841 return 1;
842 }
843
844 static void resolve_service_all_complete(DnsQuery *q) {
845 _cleanup_(dns_resource_record_unrefp) DnsResourceRecord *canonical = NULL;
846 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
847 _cleanup_free_ char *name = NULL, *type = NULL, *domain = NULL;
848 DnsQuestion *question;
849 DnsResourceRecord *rr;
850 unsigned added = 0;
851 DnsQuery *aux;
852 int r;
853
854 assert(q);
855
856 if (q->block_all_complete > 0)
857 return;
858
859 if ((q->flags & SD_RESOLVED_NO_ADDRESS) == 0) {
860 DnsQuery *bad = NULL;
861 bool have_success = false;
862
863 LIST_FOREACH(auxiliary_queries, aux, q->auxiliary_queries) {
864
865 switch (aux->state) {
866
867 case DNS_TRANSACTION_PENDING:
868 /* If an auxiliary query is still pending, let's wait */
869 return;
870
871 case DNS_TRANSACTION_SUCCESS:
872 if (aux->auxiliary_result == 0)
873 have_success = true;
874 else
875 bad = aux;
876 break;
877
878 default:
879 bad = aux;
880 break;
881 }
882 }
883
884 if (!have_success) {
885 /* We can only return one error, hence pick the last error we encountered */
886
887 assert(bad);
888
889 if (bad->state == DNS_TRANSACTION_SUCCESS) {
890 assert(bad->auxiliary_result != 0);
891
892 if (bad->auxiliary_result == -ELOOP) {
893 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_CNAME_LOOP, "CNAME loop detected, or CNAME resolving disabled on '%s'", dns_query_string(bad));
894 goto finish;
895 }
896
897 r = bad->auxiliary_result;
898 goto finish;
899 }
900
901 r = reply_query_state(bad);
902 goto finish;
903 }
904 }
905
906 r = sd_bus_message_new_method_return(q->request, &reply);
907 if (r < 0)
908 goto finish;
909
910 r = sd_bus_message_open_container(reply, 'a', "(qqqsa(iiay)s)");
911 if (r < 0)
912 goto finish;
913
914 question = dns_query_question_for_protocol(q, q->answer_protocol);
915 DNS_ANSWER_FOREACH(rr, q->answer) {
916 r = dns_question_matches_rr(question, rr, NULL);
917 if (r < 0)
918 goto finish;
919 if (r == 0)
920 continue;
921
922 r = append_srv(q, reply, rr);
923 if (r < 0)
924 goto finish;
925 if (r == 0) /* not an SRV record */
926 continue;
927
928 if (!canonical)
929 canonical = dns_resource_record_ref(rr);
930
931 added++;
932 }
933
934 if (added <= 0) {
935 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_SUCH_RR, "'%s' does not have any RR of the requested type", dns_query_string(q));
936 goto finish;
937 }
938
939 r = sd_bus_message_close_container(reply);
940 if (r < 0)
941 goto finish;
942
943 r = sd_bus_message_open_container(reply, 'a', "ay");
944 if (r < 0)
945 goto finish;
946
947 DNS_ANSWER_FOREACH(rr, q->answer) {
948 r = dns_question_matches_rr(question, rr, NULL);
949 if (r < 0)
950 goto finish;
951 if (r == 0)
952 continue;
953
954 r = append_txt(reply, rr);
955 if (r < 0)
956 goto finish;
957 }
958
959 r = sd_bus_message_close_container(reply);
960 if (r < 0)
961 goto finish;
962
963 assert(canonical);
964 r = dns_service_split(dns_resource_key_name(canonical->key), &name, &type, &domain);
965 if (r < 0)
966 goto finish;
967
968 r = sd_bus_message_append(
969 reply,
970 "ssst",
971 name, type, domain,
972 SD_RESOLVED_FLAGS_MAKE(q->answer_protocol, q->answer_family, dns_query_fully_authenticated(q)));
973 if (r < 0)
974 goto finish;
975
976 r = sd_bus_send(q->manager->bus, reply, NULL);
977
978 finish:
979 if (r < 0) {
980 log_error_errno(r, "Failed to send service reply: %m");
981 sd_bus_reply_method_errno(q->request, r, NULL);
982 }
983
984 dns_query_free(q);
985 }
986
987 static void resolve_service_hostname_complete(DnsQuery *q) {
988 int r;
989
990 assert(q);
991 assert(q->auxiliary_for);
992
993 if (q->state != DNS_TRANSACTION_SUCCESS) {
994 resolve_service_all_complete(q->auxiliary_for);
995 return;
996 }
997
998 r = dns_query_process_cname(q);
999 if (r == DNS_QUERY_RESTARTED) /* This was a cname, and the query was restarted. */
1000 return;
1001
1002 /* This auxiliary lookup is finished or failed, let's see if all are finished now. */
1003 q->auxiliary_result = r;
1004 resolve_service_all_complete(q->auxiliary_for);
1005 }
1006
1007 static int resolve_service_hostname(DnsQuery *q, DnsResourceRecord *rr, int ifindex) {
1008 _cleanup_(dns_question_unrefp) DnsQuestion *question = NULL;
1009 DnsQuery *aux;
1010 int r;
1011
1012 assert(q);
1013 assert(rr);
1014 assert(rr->key);
1015 assert(rr->key->type == DNS_TYPE_SRV);
1016
1017 /* OK, we found an SRV record for the service. Let's resolve
1018 * the hostname included in it */
1019
1020 r = dns_question_new_address(&question, q->request_family, rr->srv.name, false);
1021 if (r < 0)
1022 return r;
1023
1024 r = dns_query_new(q->manager, &aux, question, question, ifindex, q->flags|SD_RESOLVED_NO_SEARCH);
1025 if (r < 0)
1026 return r;
1027
1028 aux->request_family = q->request_family;
1029 aux->complete = resolve_service_hostname_complete;
1030
1031 r = dns_query_make_auxiliary(aux, q);
1032 if (r == -EAGAIN) {
1033 /* Too many auxiliary lookups? If so, don't complain,
1034 * let's just not add this one, we already have more
1035 * than enough */
1036
1037 dns_query_free(aux);
1038 return 0;
1039 }
1040 if (r < 0)
1041 goto fail;
1042
1043 /* Note that auxiliary queries do not track the original bus
1044 * client, only the primary request does that. */
1045
1046 r = dns_query_go(aux);
1047 if (r < 0)
1048 goto fail;
1049
1050 return 1;
1051
1052 fail:
1053 dns_query_free(aux);
1054 return r;
1055 }
1056
1057 static void bus_method_resolve_service_complete(DnsQuery *q) {
1058 bool has_root_domain = false;
1059 DnsResourceRecord *rr;
1060 DnsQuestion *question;
1061 unsigned found = 0;
1062 int ifindex, r;
1063
1064 assert(q);
1065
1066 if (q->state != DNS_TRANSACTION_SUCCESS) {
1067 r = reply_query_state(q);
1068 goto finish;
1069 }
1070
1071 r = dns_query_process_cname(q);
1072 if (r == -ELOOP) {
1073 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_CNAME_LOOP, "CNAME loop detected, or CNAME resolving disabled on '%s'", dns_query_string(q));
1074 goto finish;
1075 }
1076 if (r < 0)
1077 goto finish;
1078 if (r == DNS_QUERY_RESTARTED) /* This was a cname, and the query was restarted. */
1079 return;
1080
1081 question = dns_query_question_for_protocol(q, q->answer_protocol);
1082
1083 DNS_ANSWER_FOREACH_IFINDEX(rr, ifindex, q->answer) {
1084 r = dns_question_matches_rr(question, rr, NULL);
1085 if (r < 0)
1086 goto finish;
1087 if (r == 0)
1088 continue;
1089
1090 if (rr->key->type != DNS_TYPE_SRV)
1091 continue;
1092
1093 if (dns_name_is_root(rr->srv.name)) {
1094 has_root_domain = true;
1095 continue;
1096 }
1097
1098 if ((q->flags & SD_RESOLVED_NO_ADDRESS) == 0) {
1099 q->block_all_complete++;
1100 r = resolve_service_hostname(q, rr, ifindex);
1101 q->block_all_complete--;
1102
1103 if (r < 0)
1104 goto finish;
1105 }
1106
1107 found++;
1108 }
1109
1110 if (has_root_domain && found <= 0) {
1111 /* If there's exactly one SRV RR and it uses
1112 * the root domain as host name, then the
1113 * service is explicitly not offered on the
1114 * domain. Report this as a recognizable
1115 * error. See RFC 2782, Section "Usage
1116 * Rules". */
1117 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_SUCH_SERVICE, "'%s' does not provide the requested service", dns_query_string(q));
1118 goto finish;
1119 }
1120
1121 if (found <= 0) {
1122 r = sd_bus_reply_method_errorf(q->request, BUS_ERROR_NO_SUCH_RR, "'%s' does not have any RR of the requested type", dns_query_string(q));
1123 goto finish;
1124 }
1125
1126 /* Maybe we are already finished? check now... */
1127 resolve_service_all_complete(q);
1128 return;
1129
1130 finish:
1131 if (r < 0) {
1132 log_error_errno(r, "Failed to send service reply: %m");
1133 sd_bus_reply_method_errno(q->request, r, NULL);
1134 }
1135
1136 dns_query_free(q);
1137 }
1138
1139 static int bus_method_resolve_service(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1140 _cleanup_(dns_question_unrefp) DnsQuestion *question_idna = NULL, *question_utf8 = NULL;
1141 const char *name, *type, *domain;
1142 Manager *m = userdata;
1143 int family, ifindex;
1144 uint64_t flags;
1145 DnsQuery *q;
1146 int r;
1147
1148 assert(message);
1149 assert(m);
1150
1151 assert_cc(sizeof(int) == sizeof(int32_t));
1152
1153 r = sd_bus_message_read(message, "isssit", &ifindex, &name, &type, &domain, &family, &flags);
1154 if (r < 0)
1155 return r;
1156
1157 if (!IN_SET(family, AF_INET, AF_INET6, AF_UNSPEC))
1158 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Unknown address family %i", family);
1159
1160 if (isempty(name))
1161 name = NULL;
1162 else if (!dns_service_name_is_valid(name))
1163 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid service name '%s'", name);
1164
1165 if (isempty(type))
1166 type = NULL;
1167 else if (!dns_srv_type_is_valid(type))
1168 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid SRV service type '%s'", type);
1169
1170 r = dns_name_is_valid(domain);
1171 if (r < 0)
1172 return r;
1173 if (r == 0)
1174 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid domain '%s'", domain);
1175
1176 if (name && !type)
1177 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Service name cannot be specified without service type.");
1178
1179 r = check_ifindex_flags(ifindex, &flags, SD_RESOLVED_NO_TXT|SD_RESOLVED_NO_ADDRESS, error);
1180 if (r < 0)
1181 return r;
1182
1183 r = dns_question_new_service(&question_utf8, name, type, domain, !(flags & SD_RESOLVED_NO_TXT), false);
1184 if (r < 0)
1185 return r;
1186
1187 r = dns_question_new_service(&question_idna, name, type, domain, !(flags & SD_RESOLVED_NO_TXT), true);
1188 if (r < 0)
1189 return r;
1190
1191 r = dns_query_new(m, &q, question_utf8, question_idna, ifindex, flags|SD_RESOLVED_NO_SEARCH);
1192 if (r < 0)
1193 return r;
1194
1195 q->request = sd_bus_message_ref(message);
1196 q->request_family = family;
1197 q->complete = bus_method_resolve_service_complete;
1198
1199 r = dns_query_bus_track(q, message);
1200 if (r < 0)
1201 goto fail;
1202
1203 r = dns_query_go(q);
1204 if (r < 0)
1205 goto fail;
1206
1207 return 1;
1208
1209 fail:
1210 dns_query_free(q);
1211 return r;
1212 }
1213
1214 int bus_dns_server_append(sd_bus_message *reply, DnsServer *s, bool with_ifindex) {
1215 int r;
1216
1217 assert(reply);
1218
1219 if (!s) {
1220 if (with_ifindex)
1221 return sd_bus_message_append(reply, "(iiay)", 0, AF_UNSPEC, 0);
1222 else
1223 return sd_bus_message_append(reply, "(iay)", AF_UNSPEC, 0);
1224 }
1225
1226 r = sd_bus_message_open_container(reply, 'r', with_ifindex ? "iiay" : "iay");
1227 if (r < 0)
1228 return r;
1229
1230 if (with_ifindex) {
1231 r = sd_bus_message_append(reply, "i", dns_server_ifindex(s));
1232 if (r < 0)
1233 return r;
1234 }
1235
1236 r = sd_bus_message_append(reply, "i", s->family);
1237 if (r < 0)
1238 return r;
1239
1240 r = sd_bus_message_append_array(reply, 'y', &s->address, FAMILY_ADDRESS_SIZE(s->family));
1241 if (r < 0)
1242 return r;
1243
1244 return sd_bus_message_close_container(reply);
1245 }
1246
1247 static int bus_property_get_dns_servers(
1248 sd_bus *bus,
1249 const char *path,
1250 const char *interface,
1251 const char *property,
1252 sd_bus_message *reply,
1253 void *userdata,
1254 sd_bus_error *error) {
1255
1256 Manager *m = userdata;
1257 DnsServer *s;
1258 Iterator i;
1259 Link *l;
1260 int r;
1261
1262 assert(reply);
1263 assert(m);
1264
1265 r = sd_bus_message_open_container(reply, 'a', "(iiay)");
1266 if (r < 0)
1267 return r;
1268
1269 LIST_FOREACH(servers, s, m->dns_servers) {
1270 r = bus_dns_server_append(reply, s, true);
1271 if (r < 0)
1272 return r;
1273 }
1274
1275 HASHMAP_FOREACH(l, m->links, i) {
1276 LIST_FOREACH(servers, s, l->dns_servers) {
1277 r = bus_dns_server_append(reply, s, true);
1278 if (r < 0)
1279 return r;
1280 }
1281 }
1282
1283 return sd_bus_message_close_container(reply);
1284 }
1285
1286 static int bus_property_get_fallback_dns_servers(
1287 sd_bus *bus,
1288 const char *path,
1289 const char *interface,
1290 const char *property,
1291 sd_bus_message *reply,
1292 void *userdata,
1293 sd_bus_error *error) {
1294
1295 DnsServer *s, **f = userdata;
1296 int r;
1297
1298 assert(reply);
1299 assert(f);
1300
1301 r = sd_bus_message_open_container(reply, 'a', "(iiay)");
1302 if (r < 0)
1303 return r;
1304
1305 LIST_FOREACH(servers, s, *f) {
1306 r = bus_dns_server_append(reply, s, true);
1307 if (r < 0)
1308 return r;
1309 }
1310
1311 return sd_bus_message_close_container(reply);
1312 }
1313
1314 static int bus_property_get_current_dns_server(
1315 sd_bus *bus,
1316 const char *path,
1317 const char *interface,
1318 const char *property,
1319 sd_bus_message *reply,
1320 void *userdata,
1321 sd_bus_error *error) {
1322
1323 DnsServer *s;
1324
1325 assert(reply);
1326 assert(userdata);
1327
1328 s = *(DnsServer **) userdata;
1329
1330 return bus_dns_server_append(reply, s, true);
1331 }
1332
1333 static int bus_property_get_domains(
1334 sd_bus *bus,
1335 const char *path,
1336 const char *interface,
1337 const char *property,
1338 sd_bus_message *reply,
1339 void *userdata,
1340 sd_bus_error *error) {
1341
1342 Manager *m = userdata;
1343 DnsSearchDomain *d;
1344 Iterator i;
1345 Link *l;
1346 int r;
1347
1348 assert(reply);
1349 assert(m);
1350
1351 r = sd_bus_message_open_container(reply, 'a', "(isb)");
1352 if (r < 0)
1353 return r;
1354
1355 LIST_FOREACH(domains, d, m->search_domains) {
1356 r = sd_bus_message_append(reply, "(isb)", 0, d->name, d->route_only);
1357 if (r < 0)
1358 return r;
1359 }
1360
1361 HASHMAP_FOREACH(l, m->links, i) {
1362 LIST_FOREACH(domains, d, l->search_domains) {
1363 r = sd_bus_message_append(reply, "(isb)", l->ifindex, d->name, d->route_only);
1364 if (r < 0)
1365 return r;
1366 }
1367 }
1368
1369 return sd_bus_message_close_container(reply);
1370 }
1371
1372 static int bus_property_get_transaction_statistics(
1373 sd_bus *bus,
1374 const char *path,
1375 const char *interface,
1376 const char *property,
1377 sd_bus_message *reply,
1378 void *userdata,
1379 sd_bus_error *error) {
1380
1381 Manager *m = userdata;
1382
1383 assert(reply);
1384 assert(m);
1385
1386 return sd_bus_message_append(reply, "(tt)",
1387 (uint64_t) hashmap_size(m->dns_transactions),
1388 (uint64_t) m->n_transactions_total);
1389 }
1390
1391 static int bus_property_get_cache_statistics(
1392 sd_bus *bus,
1393 const char *path,
1394 const char *interface,
1395 const char *property,
1396 sd_bus_message *reply,
1397 void *userdata,
1398 sd_bus_error *error) {
1399
1400 uint64_t size = 0, hit = 0, miss = 0;
1401 Manager *m = userdata;
1402 DnsScope *s;
1403
1404 assert(reply);
1405 assert(m);
1406
1407 LIST_FOREACH(scopes, s, m->dns_scopes) {
1408 size += dns_cache_size(&s->cache);
1409 hit += s->cache.n_hit;
1410 miss += s->cache.n_miss;
1411 }
1412
1413 return sd_bus_message_append(reply, "(ttt)", size, hit, miss);
1414 }
1415
1416 static int bus_property_get_dnssec_statistics(
1417 sd_bus *bus,
1418 const char *path,
1419 const char *interface,
1420 const char *property,
1421 sd_bus_message *reply,
1422 void *userdata,
1423 sd_bus_error *error) {
1424
1425 Manager *m = userdata;
1426
1427 assert(reply);
1428 assert(m);
1429
1430 return sd_bus_message_append(reply, "(tttt)",
1431 (uint64_t) m->n_dnssec_verdict[DNSSEC_SECURE],
1432 (uint64_t) m->n_dnssec_verdict[DNSSEC_INSECURE],
1433 (uint64_t) m->n_dnssec_verdict[DNSSEC_BOGUS],
1434 (uint64_t) m->n_dnssec_verdict[DNSSEC_INDETERMINATE]);
1435 }
1436
1437 static int bus_property_get_ntas(
1438 sd_bus *bus,
1439 const char *path,
1440 const char *interface,
1441 const char *property,
1442 sd_bus_message *reply,
1443 void *userdata,
1444 sd_bus_error *error) {
1445
1446 Manager *m = userdata;
1447 const char *domain;
1448 Iterator i;
1449 int r;
1450
1451 assert(reply);
1452 assert(m);
1453
1454 r = sd_bus_message_open_container(reply, 'a', "s");
1455 if (r < 0)
1456 return r;
1457
1458 SET_FOREACH(domain, m->trust_anchor.negative_by_name, i) {
1459 r = sd_bus_message_append(reply, "s", domain);
1460 if (r < 0)
1461 return r;
1462 }
1463
1464 return sd_bus_message_close_container(reply);
1465 }
1466
1467 static BUS_DEFINE_PROPERTY_GET_ENUM(bus_property_get_dns_stub_listener_mode, dns_stub_listener_mode, DnsStubListenerMode);
1468 static BUS_DEFINE_PROPERTY_GET(bus_property_get_dnssec_supported, "b", Manager, manager_dnssec_supported);
1469 static BUS_DEFINE_PROPERTY_GET2(bus_property_get_dnssec_mode, "s", Manager, manager_get_dnssec_mode, dnssec_mode_to_string);
1470 static BUS_DEFINE_PROPERTY_GET2(bus_property_get_dns_over_tls_mode, "s", Manager, manager_get_dns_over_tls_mode, dns_over_tls_mode_to_string);
1471
1472 static int bus_method_reset_statistics(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1473 Manager *m = userdata;
1474 DnsScope *s;
1475
1476 assert(message);
1477 assert(m);
1478
1479 LIST_FOREACH(scopes, s, m->dns_scopes)
1480 s->cache.n_hit = s->cache.n_miss = 0;
1481
1482 m->n_transactions_total = 0;
1483 zero(m->n_dnssec_verdict);
1484
1485 return sd_bus_reply_method_return(message, NULL);
1486 }
1487
1488 static int get_any_link(Manager *m, int ifindex, Link **ret, sd_bus_error *error) {
1489 Link *l;
1490
1491 assert(m);
1492 assert(ret);
1493
1494 if (ifindex <= 0)
1495 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid interface index");
1496
1497 l = hashmap_get(m->links, INT_TO_PTR(ifindex));
1498 if (!l)
1499 return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_LINK, "Link %i not known", ifindex);
1500
1501 *ret = l;
1502 return 0;
1503 }
1504
1505 static int call_link_method(Manager *m, sd_bus_message *message, sd_bus_message_handler_t handler, sd_bus_error *error) {
1506 int ifindex, r;
1507 Link *l;
1508
1509 assert(m);
1510 assert(message);
1511 assert(handler);
1512
1513 assert_cc(sizeof(int) == sizeof(int32_t));
1514 r = sd_bus_message_read(message, "i", &ifindex);
1515 if (r < 0)
1516 return r;
1517
1518 r = get_any_link(m, ifindex, &l, error);
1519 if (r < 0)
1520 return r;
1521
1522 return handler(message, l, error);
1523 }
1524
1525 static int bus_method_set_link_dns_servers(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1526 return call_link_method(userdata, message, bus_link_method_set_dns_servers, error);
1527 }
1528
1529 static int bus_method_set_link_domains(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1530 return call_link_method(userdata, message, bus_link_method_set_domains, error);
1531 }
1532
1533 static int bus_method_set_link_llmnr(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1534 return call_link_method(userdata, message, bus_link_method_set_llmnr, error);
1535 }
1536
1537 static int bus_method_set_link_mdns(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1538 return call_link_method(userdata, message, bus_link_method_set_mdns, error);
1539 }
1540
1541 static int bus_method_set_link_dns_over_tls(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1542 return call_link_method(userdata, message, bus_link_method_set_dns_over_tls, error);
1543 }
1544
1545 static int bus_method_set_link_dnssec(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1546 return call_link_method(userdata, message, bus_link_method_set_dnssec, error);
1547 }
1548
1549 static int bus_method_set_link_dnssec_negative_trust_anchors(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1550 return call_link_method(userdata, message, bus_link_method_set_dnssec_negative_trust_anchors, error);
1551 }
1552
1553 static int bus_method_revert_link(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1554 return call_link_method(userdata, message, bus_link_method_revert, error);
1555 }
1556
1557 static int bus_method_get_link(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1558 _cleanup_free_ char *p = NULL;
1559 Manager *m = userdata;
1560 int r, ifindex;
1561 Link *l;
1562
1563 assert(message);
1564 assert(m);
1565
1566 assert_cc(sizeof(int) == sizeof(int32_t));
1567 r = sd_bus_message_read(message, "i", &ifindex);
1568 if (r < 0)
1569 return r;
1570
1571 r = get_any_link(m, ifindex, &l, error);
1572 if (r < 0)
1573 return r;
1574
1575 p = link_bus_path(l);
1576 if (!p)
1577 return -ENOMEM;
1578
1579 return sd_bus_reply_method_return(message, "o", p);
1580 }
1581
1582 static int bus_method_flush_caches(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1583 Manager *m = userdata;
1584
1585 assert(message);
1586 assert(m);
1587
1588 manager_flush_caches(m);
1589
1590 return sd_bus_reply_method_return(message, NULL);
1591 }
1592
1593 static int bus_method_reset_server_features(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1594 Manager *m = userdata;
1595
1596 assert(message);
1597 assert(m);
1598
1599 manager_reset_server_features(m);
1600
1601 return sd_bus_reply_method_return(message, NULL);
1602 }
1603
1604 static int on_bus_track(sd_bus_track *t, void *userdata) {
1605 DnssdService *s = userdata;
1606
1607 assert(t);
1608 assert(s);
1609
1610 log_debug("Client of active request vanished, destroying DNS-SD service.");
1611 dnssd_service_free(s);
1612
1613 return 0;
1614 }
1615
1616 static int bus_method_register_service(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1617 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
1618 _cleanup_(dnssd_service_freep) DnssdService *service = NULL;
1619 _cleanup_(sd_bus_track_unrefp) sd_bus_track *bus_track = NULL;
1620 _cleanup_free_ char *path = NULL;
1621 _cleanup_free_ char *instance_name = NULL;
1622 Manager *m = userdata;
1623 DnssdService *s = NULL;
1624 const char *name;
1625 const char *name_template;
1626 const char *type;
1627 uid_t euid;
1628 int r;
1629
1630 assert(message);
1631 assert(m);
1632
1633 if (m->mdns_support != RESOLVE_SUPPORT_YES)
1634 return sd_bus_error_setf(error, SD_BUS_ERROR_NOT_SUPPORTED, "Support for MulticastDNS is disabled");
1635
1636 r = bus_verify_polkit_async(message, CAP_SYS_ADMIN,
1637 "org.freedesktop.resolve1.register-service",
1638 NULL, false, UID_INVALID,
1639 &m->polkit_registry, error);
1640 if (r < 0)
1641 return r;
1642 if (r == 0)
1643 return 1; /* Polkit will call us back */
1644
1645 service = new0(DnssdService, 1);
1646 if (!service)
1647 return log_oom();
1648
1649 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
1650 if (r < 0)
1651 return r;
1652
1653 r = sd_bus_creds_get_euid(creds, &euid);
1654 if (r < 0)
1655 return r;
1656 service->originator = euid;
1657
1658 r = sd_bus_message_read(message, "sssqqq", &name, &name_template, &type,
1659 &service->port, &service->priority,
1660 &service->weight);
1661 if (r < 0)
1662 return r;
1663
1664 s = hashmap_get(m->dnssd_services, name);
1665 if (s)
1666 return sd_bus_error_setf(error, BUS_ERROR_DNSSD_SERVICE_EXISTS, "DNS-SD service '%s' exists already", name);
1667
1668 if (!dnssd_srv_type_is_valid(type))
1669 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "DNS-SD service type '%s' is invalid", type);
1670
1671 service->name = strdup(name);
1672 if (!service->name)
1673 return log_oom();
1674
1675 service->name_template = strdup(name_template);
1676 if (!service->name_template)
1677 return log_oom();
1678
1679 service->type = strdup(type);
1680 if (!service->type)
1681 return log_oom();
1682
1683 r = dnssd_render_instance_name(service, &instance_name);
1684 if (r < 0)
1685 return r;
1686
1687 r = sd_bus_message_enter_container(message, SD_BUS_TYPE_ARRAY, "a{say}");
1688 if (r < 0)
1689 return r;
1690
1691 while ((r = sd_bus_message_enter_container(message, SD_BUS_TYPE_ARRAY, "{say}")) > 0) {
1692 _cleanup_(dnssd_txtdata_freep) DnssdTxtData *txt_data = NULL;
1693 DnsTxtItem *last = NULL;
1694
1695 txt_data = new0(DnssdTxtData, 1);
1696 if (!txt_data)
1697 return log_oom();
1698
1699 while ((r = sd_bus_message_enter_container(message, SD_BUS_TYPE_DICT_ENTRY, "say")) > 0) {
1700 const char *key;
1701 const void *value;
1702 size_t size;
1703 DnsTxtItem *i;
1704
1705 r = sd_bus_message_read(message, "s", &key);
1706 if (r < 0)
1707 return r;
1708
1709 if (isempty(key))
1710 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Keys in DNS-SD TXT RRs can't be empty");
1711
1712 if (!ascii_is_valid(key))
1713 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "TXT key '%s' contains non-ASCII symbols", key);
1714
1715 r = sd_bus_message_read_array(message, 'y', &value, &size);
1716 if (r < 0)
1717 return r;
1718
1719 r = dnssd_txt_item_new_from_data(key, value, size, &i);
1720 if (r < 0)
1721 return r;
1722
1723 LIST_INSERT_AFTER(items, txt_data->txt, last, i);
1724 last = i;
1725
1726 r = sd_bus_message_exit_container(message);
1727 if (r < 0)
1728 return r;
1729
1730 }
1731 if (r < 0)
1732 return r;
1733
1734 r = sd_bus_message_exit_container(message);
1735 if (r < 0)
1736 return r;
1737
1738 if (txt_data->txt) {
1739 LIST_PREPEND(items, service->txt_data_items, txt_data);
1740 txt_data = NULL;
1741 }
1742 }
1743 if (r < 0)
1744 return r;
1745
1746 r = sd_bus_message_exit_container(message);
1747 if (r < 0)
1748 return r;
1749
1750 if (!service->txt_data_items) {
1751 _cleanup_(dnssd_txtdata_freep) DnssdTxtData *txt_data = NULL;
1752
1753 txt_data = new0(DnssdTxtData, 1);
1754 if (!txt_data)
1755 return log_oom();
1756
1757 r = dns_txt_item_new_empty(&txt_data->txt);
1758 if (r < 0)
1759 return r;
1760
1761 LIST_PREPEND(items, service->txt_data_items, txt_data);
1762 txt_data = NULL;
1763 }
1764
1765 r = sd_bus_path_encode("/org/freedesktop/resolve1/dnssd", service->name, &path);
1766 if (r < 0)
1767 return r;
1768
1769 r = hashmap_ensure_allocated(&m->dnssd_services, &string_hash_ops);
1770 if (r < 0)
1771 return r;
1772
1773 r = hashmap_put(m->dnssd_services, service->name, service);
1774 if (r < 0)
1775 return r;
1776
1777 r = sd_bus_track_new(sd_bus_message_get_bus(message), &bus_track, on_bus_track, service);
1778 if (r < 0)
1779 return r;
1780
1781 r = sd_bus_track_add_sender(bus_track, message);
1782 if (r < 0)
1783 return r;
1784
1785 service->manager = m;
1786
1787 service = NULL;
1788
1789 manager_refresh_rrs(m);
1790
1791 return sd_bus_reply_method_return(message, "o", path);
1792 }
1793
1794 static int call_dnssd_method(Manager *m, sd_bus_message *message, sd_bus_message_handler_t handler, sd_bus_error *error) {
1795 _cleanup_free_ char *name = NULL;
1796 DnssdService *s = NULL;
1797 const char *path;
1798 int r;
1799
1800 assert(m);
1801 assert(message);
1802 assert(handler);
1803
1804 r = sd_bus_message_read(message, "o", &path);
1805 if (r < 0)
1806 return r;
1807
1808 r = sd_bus_path_decode(path, "/org/freedesktop/resolve1/dnssd", &name);
1809 if (r == 0)
1810 return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_DNSSD_SERVICE, "DNS-SD service with object path '%s' does not exist", path);
1811 if (r < 0)
1812 return r;
1813
1814 s = hashmap_get(m->dnssd_services, name);
1815 if (!s)
1816 return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_DNSSD_SERVICE, "DNS-SD service '%s' not known", name);
1817
1818 return handler(message, s, error);
1819 }
1820
1821 static int bus_method_unregister_service(sd_bus_message *message, void *userdata, sd_bus_error *error) {
1822 Manager *m = userdata;
1823
1824 assert(message);
1825 assert(m);
1826
1827 return call_dnssd_method(m, message, bus_dnssd_method_unregister, error);
1828 }
1829
1830 static const sd_bus_vtable resolve_vtable[] = {
1831 SD_BUS_VTABLE_START(0),
1832 SD_BUS_PROPERTY("LLMNRHostname", "s", NULL, offsetof(Manager, llmnr_hostname), 0),
1833 SD_BUS_PROPERTY("LLMNR", "s", bus_property_get_resolve_support, offsetof(Manager, llmnr_support), 0),
1834 SD_BUS_PROPERTY("MulticastDNS", "s", bus_property_get_resolve_support, offsetof(Manager, mdns_support), 0),
1835 SD_BUS_PROPERTY("DNSOverTLS", "s", bus_property_get_dns_over_tls_mode, 0, 0),
1836 SD_BUS_PROPERTY("DNS", "a(iiay)", bus_property_get_dns_servers, 0, 0),
1837 SD_BUS_PROPERTY("FallbackDNS", "a(iiay)", bus_property_get_fallback_dns_servers, offsetof(Manager, fallback_dns_servers), SD_BUS_VTABLE_PROPERTY_CONST),
1838 SD_BUS_PROPERTY("CurrentDNSServer", "(iiay)", bus_property_get_current_dns_server, offsetof(Manager, current_dns_server), 0),
1839 SD_BUS_PROPERTY("Domains", "a(isb)", bus_property_get_domains, 0, 0),
1840 SD_BUS_PROPERTY("TransactionStatistics", "(tt)", bus_property_get_transaction_statistics, 0, 0),
1841 SD_BUS_PROPERTY("CacheStatistics", "(ttt)", bus_property_get_cache_statistics, 0, 0),
1842 SD_BUS_PROPERTY("DNSSEC", "s", bus_property_get_dnssec_mode, 0, 0),
1843 SD_BUS_PROPERTY("DNSSECStatistics", "(tttt)", bus_property_get_dnssec_statistics, 0, 0),
1844 SD_BUS_PROPERTY("DNSSECSupported", "b", bus_property_get_dnssec_supported, 0, 0),
1845 SD_BUS_PROPERTY("DNSSECNegativeTrustAnchors", "as", bus_property_get_ntas, 0, 0),
1846 SD_BUS_PROPERTY("DNSStubListener", "s", bus_property_get_dns_stub_listener_mode, offsetof(Manager, dns_stub_listener_mode), 0),
1847
1848 SD_BUS_METHOD("ResolveHostname", "isit", "a(iiay)st", bus_method_resolve_hostname, SD_BUS_VTABLE_UNPRIVILEGED),
1849 SD_BUS_METHOD("ResolveAddress", "iiayt", "a(is)t", bus_method_resolve_address, SD_BUS_VTABLE_UNPRIVILEGED),
1850 SD_BUS_METHOD("ResolveRecord", "isqqt", "a(iqqay)t", bus_method_resolve_record, SD_BUS_VTABLE_UNPRIVILEGED),
1851 SD_BUS_METHOD("ResolveService", "isssit", "a(qqqsa(iiay)s)aayssst", bus_method_resolve_service, SD_BUS_VTABLE_UNPRIVILEGED),
1852 SD_BUS_METHOD("ResetStatistics", NULL, NULL, bus_method_reset_statistics, 0),
1853 SD_BUS_METHOD("FlushCaches", NULL, NULL, bus_method_flush_caches, 0),
1854 SD_BUS_METHOD("ResetServerFeatures", NULL, NULL, bus_method_reset_server_features, 0),
1855 SD_BUS_METHOD("GetLink", "i", "o", bus_method_get_link, SD_BUS_VTABLE_UNPRIVILEGED),
1856 SD_BUS_METHOD("SetLinkDNS", "ia(iay)", NULL, bus_method_set_link_dns_servers, 0),
1857 SD_BUS_METHOD("SetLinkDomains", "ia(sb)", NULL, bus_method_set_link_domains, 0),
1858 SD_BUS_METHOD("SetLinkLLMNR", "is", NULL, bus_method_set_link_llmnr, 0),
1859 SD_BUS_METHOD("SetLinkMulticastDNS", "is", NULL, bus_method_set_link_mdns, 0),
1860 SD_BUS_METHOD("SetLinkDNSOverTLS", "is", NULL, bus_method_set_link_dns_over_tls, 0),
1861 SD_BUS_METHOD("SetLinkDNSSEC", "is", NULL, bus_method_set_link_dnssec, 0),
1862 SD_BUS_METHOD("SetLinkDNSSECNegativeTrustAnchors", "ias", NULL, bus_method_set_link_dnssec_negative_trust_anchors, 0),
1863 SD_BUS_METHOD("RevertLink", "i", NULL, bus_method_revert_link, 0),
1864
1865 SD_BUS_METHOD("RegisterService", "sssqqqaa{say}", "o", bus_method_register_service, SD_BUS_VTABLE_UNPRIVILEGED),
1866 SD_BUS_METHOD("UnregisterService", "o", NULL, bus_method_unregister_service, SD_BUS_VTABLE_UNPRIVILEGED),
1867 SD_BUS_VTABLE_END,
1868 };
1869
1870 static int match_prepare_for_sleep(sd_bus_message *message, void *userdata, sd_bus_error *ret_error) {
1871 Manager *m = userdata;
1872 int b, r;
1873
1874 assert(message);
1875 assert(m);
1876
1877 r = sd_bus_message_read(message, "b", &b);
1878 if (r < 0) {
1879 log_debug_errno(r, "Failed to parse PrepareForSleep signal: %m");
1880 return 0;
1881 }
1882
1883 if (b)
1884 return 0;
1885
1886 log_debug("Coming back from suspend, verifying all RRs...");
1887
1888 manager_verify_all(m);
1889 return 0;
1890 }
1891
1892 int manager_connect_bus(Manager *m) {
1893 int r;
1894
1895 assert(m);
1896
1897 if (m->bus)
1898 return 0;
1899
1900 r = bus_open_system_watch_bind_with_description(&m->bus, "bus-api-resolve");
1901 if (r < 0)
1902 return log_error_errno(r, "Failed to connect to system bus: %m");
1903
1904 r = sd_bus_add_object_vtable(m->bus, NULL, "/org/freedesktop/resolve1", "org.freedesktop.resolve1.Manager", resolve_vtable, m);
1905 if (r < 0)
1906 return log_error_errno(r, "Failed to register object: %m");
1907
1908 r = sd_bus_add_fallback_vtable(m->bus, NULL, "/org/freedesktop/resolve1/link", "org.freedesktop.resolve1.Link", link_vtable, link_object_find, m);
1909 if (r < 0)
1910 return log_error_errno(r, "Failed to register link objects: %m");
1911
1912 r = sd_bus_add_node_enumerator(m->bus, NULL, "/org/freedesktop/resolve1/link", link_node_enumerator, m);
1913 if (r < 0)
1914 return log_error_errno(r, "Failed to register link enumerator: %m");
1915
1916 r = sd_bus_add_fallback_vtable(m->bus, NULL, "/org/freedesktop/resolve1/dnssd", "org.freedesktop.resolve1.DnssdService", dnssd_vtable, dnssd_object_find, m);
1917 if (r < 0)
1918 return log_error_errno(r, "Failed to register dnssd objects: %m");
1919
1920 r = sd_bus_add_node_enumerator(m->bus, NULL, "/org/freedesktop/resolve1/dnssd", dnssd_node_enumerator, m);
1921 if (r < 0)
1922 return log_error_errno(r, "Failed to register dnssd enumerator: %m");
1923
1924 r = sd_bus_request_name_async(m->bus, NULL, "org.freedesktop.resolve1", 0, NULL, NULL);
1925 if (r < 0)
1926 return log_error_errno(r, "Failed to request name: %m");
1927
1928 r = sd_bus_attach_event(m->bus, m->event, 0);
1929 if (r < 0)
1930 return log_error_errno(r, "Failed to attach bus to event loop: %m");
1931
1932 r = sd_bus_match_signal_async(
1933 m->bus,
1934 NULL,
1935 "org.freedesktop.login1",
1936 "/org/freedesktop/login1",
1937 "org.freedesktop.login1.Manager",
1938 "PrepareForSleep",
1939 match_prepare_for_sleep,
1940 NULL,
1941 m);
1942 if (r < 0)
1943 log_warning_errno(r, "Failed to request match for PrepareForSleep, ignoring: %m");
1944
1945 return 0;
1946 }