1 /* SPDX-License-Identifier: LGPL-2.1+ */
4 #include <netinet/in.h>
5 #include <sys/capability.h>
7 #include "alloc-util.h"
8 #include "bus-common-errors.h"
9 #include "bus-get-properties.h"
10 #include "bus-polkit.h"
11 #include "parse-util.h"
12 #include "resolve-util.h"
13 #include "resolved-bus.h"
14 #include "resolved-link-bus.h"
15 #include "resolved-resolv-conf.h"
16 #include "socket-netlink.h"
17 #include "stdio-util.h"
19 #include "user-util.h"
21 static BUS_DEFINE_PROPERTY_GET(property_get_dnssec_supported
, "b", Link
, link_dnssec_supported
);
22 static BUS_DEFINE_PROPERTY_GET2(property_get_dnssec_mode
, "s", Link
, link_get_dnssec_mode
, dnssec_mode_to_string
);
24 static int property_get_dns_over_tls_mode(
27 const char *interface
,
29 sd_bus_message
*reply
,
31 sd_bus_error
*error
) {
38 return sd_bus_message_append(reply
, "s", dns_over_tls_mode_to_string(link_get_dns_over_tls_mode(l
)));
41 static int property_get_dns(
44 const char *interface
,
46 sd_bus_message
*reply
,
48 sd_bus_error
*error
) {
57 r
= sd_bus_message_open_container(reply
, 'a', "(iay)");
61 LIST_FOREACH(servers
, s
, l
->dns_servers
) {
62 r
= bus_dns_server_append(reply
, s
, false);
67 return sd_bus_message_close_container(reply
);
70 static int property_get_current_dns_server(
73 const char *interface
,
75 sd_bus_message
*reply
,
77 sd_bus_error
*error
) {
84 s
= *(DnsServer
**) userdata
;
86 return bus_dns_server_append(reply
, s
, false);
89 static int property_get_domains(
92 const char *interface
,
94 sd_bus_message
*reply
,
96 sd_bus_error
*error
) {
105 r
= sd_bus_message_open_container(reply
, 'a', "(sb)");
109 LIST_FOREACH(domains
, d
, l
->search_domains
) {
110 r
= sd_bus_message_append(reply
, "(sb)", d
->name
, d
->route_only
);
115 return sd_bus_message_close_container(reply
);
118 static int property_get_default_route(
121 const char *interface
,
122 const char *property
,
123 sd_bus_message
*reply
,
125 sd_bus_error
*error
) {
132 /* Return what is configured, if there's something configured */
133 if (l
->default_route
>= 0)
134 return sd_bus_message_append(reply
, "b", l
->default_route
);
136 /* Otherwise report what is in effect */
137 if (l
->unicast_scope
)
138 return sd_bus_message_append(reply
, "b", dns_scope_is_default_route(l
->unicast_scope
));
140 return sd_bus_message_append(reply
, "b", false);
143 static int property_get_scopes_mask(
146 const char *interface
,
147 const char *property
,
148 sd_bus_message
*reply
,
150 sd_bus_error
*error
) {
158 mask
= (l
->unicast_scope
? SD_RESOLVED_DNS
: 0) |
159 (l
->llmnr_ipv4_scope
? SD_RESOLVED_LLMNR_IPV4
: 0) |
160 (l
->llmnr_ipv6_scope
? SD_RESOLVED_LLMNR_IPV6
: 0) |
161 (l
->mdns_ipv4_scope
? SD_RESOLVED_MDNS_IPV4
: 0) |
162 (l
->mdns_ipv6_scope
? SD_RESOLVED_MDNS_IPV6
: 0);
164 return sd_bus_message_append(reply
, "t", mask
);
167 static int property_get_ntas(
170 const char *interface
,
171 const char *property
,
172 sd_bus_message
*reply
,
174 sd_bus_error
*error
) {
184 r
= sd_bus_message_open_container(reply
, 'a', "s");
188 SET_FOREACH(name
, l
->dnssec_negative_trust_anchors
, i
) {
189 r
= sd_bus_message_append(reply
, "s", name
);
194 return sd_bus_message_close_container(reply
);
197 static int verify_unmanaged_link(Link
*l
, sd_bus_error
*error
) {
200 if (l
->flags
& IFF_LOOPBACK
)
201 return sd_bus_error_setf(error
, BUS_ERROR_LINK_BUSY
, "Link %s is loopback device.", l
->ifname
);
203 return sd_bus_error_setf(error
, BUS_ERROR_LINK_BUSY
, "Link %s is managed.", l
->ifname
);
208 static int bus_link_method_set_dns_servers_internal(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
, bool extended
) {
209 struct in_addr_full
**dns
= NULL
;
210 size_t allocated
= 0, n
= 0;
217 r
= verify_unmanaged_link(l
, error
);
221 r
= sd_bus_message_enter_container(message
, 'a', extended
? "(iayqs)" : "(iay)");
226 const char *server_name
= NULL
;
227 union in_addr_union a
;
233 assert_cc(sizeof(int) == sizeof(int32_t));
235 r
= sd_bus_message_enter_container(message
, 'r', extended
? "iayqs" : "iay");
241 r
= sd_bus_message_read(message
, "i", &family
);
245 if (!IN_SET(family
, AF_INET
, AF_INET6
)) {
246 r
= sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Unknown address family %i", family
);
250 r
= sd_bus_message_read_array(message
, 'y', &d
, &sz
);
253 if (sz
!= FAMILY_ADDRESS_SIZE(family
)) {
254 r
= sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid address size");
258 if (!dns_server_address_valid(family
, d
)) {
259 r
= sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNS server address");
264 r
= sd_bus_message_read(message
, "q", &port
);
268 if (IN_SET(port
, 53, 853))
271 r
= sd_bus_message_read(message
, "s", &server_name
);
276 r
= sd_bus_message_exit_container(message
);
280 if (!GREEDY_REALLOC(dns
, allocated
, n
+1)) {
286 r
= in_addr_full_new(family
, &a
, port
, 0, server_name
, dns
+ n
);
292 r
= sd_bus_message_exit_container(message
);
296 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
297 "org.freedesktop.resolve1.set-dns-servers",
298 NULL
, true, UID_INVALID
,
299 &l
->manager
->polkit_registry
, error
);
303 r
= 1; /* Polkit will call us back */
307 dns_server_mark_all(l
->dns_servers
);
309 for (size_t i
= 0; i
< n
; i
++) {
312 s
= dns_server_find(l
->dns_servers
, dns
[i
]->family
, &dns
[i
]->address
, dns
[i
]->port
, 0, dns
[i
]->server_name
);
314 dns_server_move_back_and_unmark(s
);
316 r
= dns_server_new(l
->manager
, NULL
, DNS_SERVER_LINK
, l
, dns
[i
]->family
, &dns
[i
]->address
, dns
[i
]->port
, 0, dns
[i
]->server_name
);
318 dns_server_unlink_all(l
->dns_servers
);
325 dns_server_unlink_marked(l
->dns_servers
);
326 link_allocate_scopes(l
);
328 (void) link_save_user(l
);
329 (void) manager_write_resolv_conf(l
->manager
);
330 (void) manager_send_changed(l
->manager
, "DNS");
332 r
= sd_bus_reply_method_return(message
, NULL
);
335 for (size_t i
= 0; i
< n
; i
++)
336 in_addr_full_free(dns
[i
]);
342 int bus_link_method_set_dns_servers(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
343 return bus_link_method_set_dns_servers_internal(message
, userdata
, error
, false);
346 int bus_link_method_set_dns_servers_ex(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
347 return bus_link_method_set_dns_servers_internal(message
, userdata
, error
, true);
350 int bus_link_method_set_domains(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
357 r
= verify_unmanaged_link(l
, error
);
361 r
= sd_bus_message_enter_container(message
, 'a', "(sb)");
369 r
= sd_bus_message_read(message
, "(sb)", &name
, &route_only
);
375 r
= dns_name_is_valid(name
);
379 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid search domain %s", name
);
380 if (!route_only
&& dns_name_is_root(name
))
381 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Root domain is not suitable as search domain");
384 r
= sd_bus_message_rewind(message
, false);
388 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
389 "org.freedesktop.resolve1.set-domains",
390 NULL
, true, UID_INVALID
,
391 &l
->manager
->polkit_registry
, error
);
395 return 1; /* Polkit will call us back */
397 dns_search_domain_mark_all(l
->search_domains
);
404 r
= sd_bus_message_read(message
, "(sb)", &name
, &route_only
);
410 r
= dns_search_domain_find(l
->search_domains
, name
, &d
);
415 dns_search_domain_move_back_and_unmark(d
);
417 r
= dns_search_domain_new(l
->manager
, &d
, DNS_SEARCH_DOMAIN_LINK
, l
, name
);
422 d
->route_only
= route_only
;
425 r
= sd_bus_message_exit_container(message
);
429 dns_search_domain_unlink_marked(l
->search_domains
);
431 (void) link_save_user(l
);
432 (void) manager_write_resolv_conf(l
->manager
);
434 return sd_bus_reply_method_return(message
, NULL
);
437 dns_search_domain_unlink_all(l
->search_domains
);
441 int bus_link_method_set_default_route(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
448 r
= verify_unmanaged_link(l
, error
);
452 r
= sd_bus_message_read(message
, "b", &b
);
456 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
457 "org.freedesktop.resolve1.set-default-route",
458 NULL
, true, UID_INVALID
,
459 &l
->manager
->polkit_registry
, error
);
463 return 1; /* Polkit will call us back */
465 if (l
->default_route
!= b
) {
466 l
->default_route
= b
;
468 (void) link_save_user(l
);
469 (void) manager_write_resolv_conf(l
->manager
);
472 return sd_bus_reply_method_return(message
, NULL
);
475 int bus_link_method_set_llmnr(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
484 r
= verify_unmanaged_link(l
, error
);
488 r
= sd_bus_message_read(message
, "s", &llmnr
);
493 mode
= RESOLVE_SUPPORT_YES
;
495 mode
= resolve_support_from_string(llmnr
);
497 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid LLMNR setting: %s", llmnr
);
500 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
501 "org.freedesktop.resolve1.set-llmnr",
502 NULL
, true, UID_INVALID
,
503 &l
->manager
->polkit_registry
, error
);
507 return 1; /* Polkit will call us back */
509 l
->llmnr_support
= mode
;
510 link_allocate_scopes(l
);
511 link_add_rrs(l
, false);
513 (void) link_save_user(l
);
515 return sd_bus_reply_method_return(message
, NULL
);
518 int bus_link_method_set_mdns(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
527 r
= verify_unmanaged_link(l
, error
);
531 r
= sd_bus_message_read(message
, "s", &mdns
);
536 mode
= RESOLVE_SUPPORT_NO
;
538 mode
= resolve_support_from_string(mdns
);
540 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid MulticastDNS setting: %s", mdns
);
543 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
544 "org.freedesktop.resolve1.set-mdns",
545 NULL
, true, UID_INVALID
,
546 &l
->manager
->polkit_registry
, error
);
550 return 1; /* Polkit will call us back */
552 l
->mdns_support
= mode
;
553 link_allocate_scopes(l
);
554 link_add_rrs(l
, false);
556 (void) link_save_user(l
);
558 return sd_bus_reply_method_return(message
, NULL
);
561 int bus_link_method_set_dns_over_tls(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
563 const char *dns_over_tls
;
570 r
= verify_unmanaged_link(l
, error
);
574 r
= sd_bus_message_read(message
, "s", &dns_over_tls
);
578 if (isempty(dns_over_tls
))
579 mode
= _DNS_OVER_TLS_MODE_INVALID
;
581 mode
= dns_over_tls_mode_from_string(dns_over_tls
);
583 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNSOverTLS setting: %s", dns_over_tls
);
586 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
587 "org.freedesktop.resolve1.set-dns-over-tls",
588 NULL
, true, UID_INVALID
,
589 &l
->manager
->polkit_registry
, error
);
593 return 1; /* Polkit will call us back */
595 link_set_dns_over_tls_mode(l
, mode
);
597 (void) link_save_user(l
);
599 return sd_bus_reply_method_return(message
, NULL
);
602 int bus_link_method_set_dnssec(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
611 r
= verify_unmanaged_link(l
, error
);
615 r
= sd_bus_message_read(message
, "s", &dnssec
);
620 mode
= _DNSSEC_MODE_INVALID
;
622 mode
= dnssec_mode_from_string(dnssec
);
624 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Invalid DNSSEC setting: %s", dnssec
);
627 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
628 "org.freedesktop.resolve1.set-dnssec",
629 NULL
, true, UID_INVALID
,
630 &l
->manager
->polkit_registry
, error
);
634 return 1; /* Polkit will call us back */
636 link_set_dnssec_mode(l
, mode
);
638 (void) link_save_user(l
);
640 return sd_bus_reply_method_return(message
, NULL
);
643 int bus_link_method_set_dnssec_negative_trust_anchors(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
644 _cleanup_set_free_free_ Set
*ns
= NULL
;
645 _cleanup_strv_free_
char **ntas
= NULL
;
653 r
= verify_unmanaged_link(l
, error
);
657 ns
= set_new(&dns_name_hash_ops
);
661 r
= sd_bus_message_read_strv(message
, &ntas
);
665 STRV_FOREACH(i
, ntas
) {
666 r
= dns_name_is_valid(*i
);
670 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
,
671 "Invalid negative trust anchor domain: %s", *i
);
673 r
= set_put_strdup(&ns
, *i
);
678 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
679 "org.freedesktop.resolve1.set-dnssec-negative-trust-anchors",
680 NULL
, true, UID_INVALID
,
681 &l
->manager
->polkit_registry
, error
);
685 return 1; /* Polkit will call us back */
687 set_free_free(l
->dnssec_negative_trust_anchors
);
688 l
->dnssec_negative_trust_anchors
= TAKE_PTR(ns
);
690 (void) link_save_user(l
);
692 return sd_bus_reply_method_return(message
, NULL
);
695 int bus_link_method_revert(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
702 r
= verify_unmanaged_link(l
, error
);
706 r
= bus_verify_polkit_async(message
, CAP_NET_ADMIN
,
707 "org.freedesktop.resolve1.revert",
708 NULL
, true, UID_INVALID
,
709 &l
->manager
->polkit_registry
, error
);
713 return 1; /* Polkit will call us back */
715 link_flush_settings(l
);
716 link_allocate_scopes(l
);
717 link_add_rrs(l
, false);
719 (void) link_save_user(l
);
720 (void) manager_write_resolv_conf(l
->manager
);
721 (void) manager_send_changed(l
->manager
, "DNS");
723 return sd_bus_reply_method_return(message
, NULL
);
726 static int link_object_find(sd_bus
*bus
, const char *path
, const char *interface
, void *userdata
, void **found
, sd_bus_error
*error
) {
727 _cleanup_free_
char *e
= NULL
;
728 Manager
*m
= userdata
;
738 r
= sd_bus_path_decode(path
, "/org/freedesktop/resolve1/link", &e
);
742 ifindex
= parse_ifindex(e
);
746 link
= hashmap_get(m
->links
, INT_TO_PTR(ifindex
));
754 char *link_bus_path(const Link
*link
) {
755 char *p
, ifindex
[DECIMAL_STR_MAX(link
->ifindex
)];
760 xsprintf(ifindex
, "%i", link
->ifindex
);
762 r
= sd_bus_path_encode("/org/freedesktop/resolve1/link", ifindex
, &p
);
769 static int link_node_enumerator(sd_bus
*bus
, const char *path
, void *userdata
, char ***nodes
, sd_bus_error
*error
) {
770 _cleanup_strv_free_
char **l
= NULL
;
771 Manager
*m
= userdata
;
781 l
= new0(char*, hashmap_size(m
->links
) + 1);
785 HASHMAP_FOREACH(link
, m
->links
, i
) {
788 p
= link_bus_path(link
);
796 *nodes
= TAKE_PTR(l
);
801 static const sd_bus_vtable link_vtable
[] = {
802 SD_BUS_VTABLE_START(0),
804 SD_BUS_PROPERTY("ScopesMask", "t", property_get_scopes_mask
, 0, 0),
805 SD_BUS_PROPERTY("DNS", "a(iay)", property_get_dns
, 0, 0),
806 SD_BUS_PROPERTY("CurrentDNSServer", "(iay)", property_get_current_dns_server
, offsetof(Link
, current_dns_server
), 0),
807 SD_BUS_PROPERTY("Domains", "a(sb)", property_get_domains
, 0, 0),
808 SD_BUS_PROPERTY("DefaultRoute", "b", property_get_default_route
, 0, 0),
809 SD_BUS_PROPERTY("LLMNR", "s", bus_property_get_resolve_support
, offsetof(Link
, llmnr_support
), 0),
810 SD_BUS_PROPERTY("MulticastDNS", "s", bus_property_get_resolve_support
, offsetof(Link
, mdns_support
), 0),
811 SD_BUS_PROPERTY("DNSOverTLS", "s", property_get_dns_over_tls_mode
, 0, 0),
812 SD_BUS_PROPERTY("DNSSEC", "s", property_get_dnssec_mode
, 0, 0),
813 SD_BUS_PROPERTY("DNSSECNegativeTrustAnchors", "as", property_get_ntas
, 0, 0),
814 SD_BUS_PROPERTY("DNSSECSupported", "b", property_get_dnssec_supported
, 0, 0),
816 SD_BUS_METHOD_WITH_ARGS("SetDNS",
817 SD_BUS_ARGS("a(iay)", addresses
),
819 bus_link_method_set_dns_servers
,
820 SD_BUS_VTABLE_UNPRIVILEGED
),
821 SD_BUS_METHOD_WITH_ARGS("SetDNSEx",
822 SD_BUS_ARGS("a(iayqs)", addresses
),
824 bus_link_method_set_dns_servers_ex
,
825 SD_BUS_VTABLE_UNPRIVILEGED
),
826 SD_BUS_METHOD_WITH_ARGS("SetDomains",
827 SD_BUS_ARGS("a(sb)", domains
),
829 bus_link_method_set_domains
,
830 SD_BUS_VTABLE_UNPRIVILEGED
),
831 SD_BUS_METHOD_WITH_ARGS("SetDefaultRoute",
832 SD_BUS_ARGS("b", enable
),
834 bus_link_method_set_default_route
,
835 SD_BUS_VTABLE_UNPRIVILEGED
),
836 SD_BUS_METHOD_WITH_ARGS("SetLLMNR",
837 SD_BUS_ARGS("s", mode
),
839 bus_link_method_set_llmnr
,
840 SD_BUS_VTABLE_UNPRIVILEGED
),
841 SD_BUS_METHOD_WITH_ARGS("SetMulticastDNS",
842 SD_BUS_ARGS("s", mode
),
844 bus_link_method_set_mdns
,
845 SD_BUS_VTABLE_UNPRIVILEGED
),
846 SD_BUS_METHOD_WITH_ARGS("SetDNSOverTLS",
847 SD_BUS_ARGS("s", mode
),
849 bus_link_method_set_dns_over_tls
,
850 SD_BUS_VTABLE_UNPRIVILEGED
),
851 SD_BUS_METHOD_WITH_ARGS("SetDNSSEC",
852 SD_BUS_ARGS("s", mode
),
854 bus_link_method_set_dnssec
,
855 SD_BUS_VTABLE_UNPRIVILEGED
),
856 SD_BUS_METHOD_WITH_ARGS("SetDNSSECNegativeTrustAnchors",
857 SD_BUS_ARGS("as", names
),
859 bus_link_method_set_dnssec_negative_trust_anchors
,
860 SD_BUS_VTABLE_UNPRIVILEGED
),
861 SD_BUS_METHOD_WITH_ARGS("Revert",
864 bus_link_method_revert
,
865 SD_BUS_VTABLE_UNPRIVILEGED
),
870 const BusObjectImplementation link_object
= {
871 "/org/freedesktop/resolve1/link",
872 "org.freedesktop.resolve1.Link",
873 .fallback_vtables
= BUS_FALLBACK_VTABLES({link_vtable
, link_object_find
}),
874 .node_enumerator
= link_node_enumerator
,