Give a package-manager-neutral systemd-resolved hint when no DNS resolver is found

When fips-dns-setup finds no supported resolver it printed
"sudo apt install systemd-resolved", although the script is not
Debian-only: the Arch packages and the systemd tarball ship it too.

The hint now names no package manager. It says to install
systemd-resolved if needed, to start it with
"systemctl enable --now systemd-resolved", since setup uses
systemd-resolved only when the unit is active, and then to restart
fips-dns.service so detection runs again.

A packaging unit test checks the hint line and that the script names no
package manager install command, and the dns-resolver no-resolver
scenario asserts the same on the script's real output.
This commit is contained in:
Johnathan Corgan
2026-10-06 00:25:59 +00:00
parent faeac11ca8
commit 54931ed72e
3 changed files with 74 additions and 1 deletions
+1 -1
View File
@@ -224,7 +224,7 @@ log "To resolve .fips domains, configure your DNS resolver to forward"
log "the .fips domain to [${FIPS_DNS_LOOPBACK_V6}]:${FIPS_DNS_PORT} (matches the daemon's default bind)."
log ""
log "Examples:"
log " systemd-resolved: sudo apt install systemd-resolved"
log " systemd-resolved: install it if needed (a separate package on some distributions), run 'sudo systemctl enable --now systemd-resolved', then 'sudo systemctl restart fips-dns.service'"
log " dnsmasq: echo 'server=/fips/${FIPS_DNS_LOOPBACK_V6}#${FIPS_DNS_PORT}' | sudo tee /etc/dnsmasq.d/fips.conf"
save_backend "none"
exit 0
+57
View File
@@ -1258,3 +1258,60 @@ fn openwrt_config_offers_no_ble_block_because_musl_builds_have_no_ble() {
where the BLE transport is not compiled: {found:?}"
);
}
/// `fips-dns-setup` is shared by the Debian package, the Arch packages, the
/// systemd tarball and, where it is packaged, the RPM, so the hint it prints
/// when it finds no DNS resolver must not tell the host to use one
/// distribution's package manager.
///
/// Every systemd-resolved backend in the script gates on the unit being active
/// (`is_active`), so the hint must say to start it (`enable --now`), not only to
/// install or enable it, and then to restart `fips-dns.service` so detection
/// runs again. `test_no_resolver` in `testing/dns-resolver/test.sh` asserts the
/// same on the script's real output.
#[test]
fn fips_dns_setup_no_resolver_hint_starts_resolved_and_names_no_package_manager_because_the_script_is_not_debian_only()
{
const SETUP: &str = "packaging/common/fips-dns-setup";
const BANNED: [&str; 6] = [
"apt install",
"apt-get install",
"dnf install",
"yum install",
"zypper install",
"pacman -S",
];
let lines = code_lines(&repo_file(SETUP));
let mut problems = Vec::new();
let hints: Vec<&String> = lines
.iter()
.filter(|l| l.starts_with("log \" systemd-resolved:"))
.collect();
match hints.as_slice() {
[hint] => {
for needed in ["enable --now", "restart fips-dns.service"] {
if !hint.contains(needed) {
problems.push(format!("hint lacks '{needed}': {hint}"));
}
}
}
_ => problems.push(format!(
"expected one systemd-resolved hint line, found {}: {hints:?}",
hints.len()
)),
}
for line in &lines {
for banned in BANNED {
if line.contains(banned) {
problems.push(format!("names a package manager ('{banned}'): {line}"));
}
}
}
assert!(
problems.is_empty(),
"{SETUP}'s no-resolver hint is wrong:\n {}",
problems.join("\n ")
);
}
+16
View File
@@ -684,6 +684,22 @@ DOCKERFILE
fail "missing manual instructions warning"
fi
# The script ships beyond Debian, so the hint must not name one
# distribution's package manager.
if echo "$output" | grep -qE '(apt|apt-get|dnf|yum|zypper) install|pacman -S'; then
fail "manual instructions name a package manager"
else
pass "manual instructions name no package manager"
fi
# Setup uses systemd-resolved only when it is active, so the hint
# must say to start it, not only to install or enable it.
if echo "$output" | grep -qF 'enable --now systemd-resolved'; then
pass "manual instructions start systemd-resolved"
else
fail "manual instructions do not start systemd-resolved"
fi
run_teardown "$name" >/dev/null 2>&1
check_removed "$name" /run/fips/dns-backend \
"teardown cleaned state file" \