mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 11:38:24 +00:00
Give a package-manager-neutral systemd-resolved hint when no DNS resolver is found
When fips-dns-setup finds no supported resolver it printed "sudo apt install systemd-resolved", although the script is not Debian-only: the Arch packages and the systemd tarball ship it too. The hint now names no package manager. It says to install systemd-resolved if needed, to start it with "systemctl enable --now systemd-resolved", since setup uses systemd-resolved only when the unit is active, and then to restart fips-dns.service so detection runs again. A packaging unit test checks the hint line and that the script names no package manager install command, and the dns-resolver no-resolver scenario asserts the same on the script's real output.
This commit is contained in:
@@ -224,7 +224,7 @@ log "To resolve .fips domains, configure your DNS resolver to forward"
|
||||
log "the .fips domain to [${FIPS_DNS_LOOPBACK_V6}]:${FIPS_DNS_PORT} (matches the daemon's default bind)."
|
||||
log ""
|
||||
log "Examples:"
|
||||
log " systemd-resolved: sudo apt install systemd-resolved"
|
||||
log " systemd-resolved: install it if needed (a separate package on some distributions), run 'sudo systemctl enable --now systemd-resolved', then 'sudo systemctl restart fips-dns.service'"
|
||||
log " dnsmasq: echo 'server=/fips/${FIPS_DNS_LOOPBACK_V6}#${FIPS_DNS_PORT}' | sudo tee /etc/dnsmasq.d/fips.conf"
|
||||
save_backend "none"
|
||||
exit 0
|
||||
|
||||
@@ -1258,3 +1258,60 @@ fn openwrt_config_offers_no_ble_block_because_musl_builds_have_no_ble() {
|
||||
where the BLE transport is not compiled: {found:?}"
|
||||
);
|
||||
}
|
||||
|
||||
/// `fips-dns-setup` is shared by the Debian package, the Arch packages, the
|
||||
/// systemd tarball and, where it is packaged, the RPM, so the hint it prints
|
||||
/// when it finds no DNS resolver must not tell the host to use one
|
||||
/// distribution's package manager.
|
||||
///
|
||||
/// Every systemd-resolved backend in the script gates on the unit being active
|
||||
/// (`is_active`), so the hint must say to start it (`enable --now`), not only to
|
||||
/// install or enable it, and then to restart `fips-dns.service` so detection
|
||||
/// runs again. `test_no_resolver` in `testing/dns-resolver/test.sh` asserts the
|
||||
/// same on the script's real output.
|
||||
#[test]
|
||||
fn fips_dns_setup_no_resolver_hint_starts_resolved_and_names_no_package_manager_because_the_script_is_not_debian_only()
|
||||
{
|
||||
const SETUP: &str = "packaging/common/fips-dns-setup";
|
||||
const BANNED: [&str; 6] = [
|
||||
"apt install",
|
||||
"apt-get install",
|
||||
"dnf install",
|
||||
"yum install",
|
||||
"zypper install",
|
||||
"pacman -S",
|
||||
];
|
||||
let lines = code_lines(&repo_file(SETUP));
|
||||
let mut problems = Vec::new();
|
||||
|
||||
let hints: Vec<&String> = lines
|
||||
.iter()
|
||||
.filter(|l| l.starts_with("log \" systemd-resolved:"))
|
||||
.collect();
|
||||
match hints.as_slice() {
|
||||
[hint] => {
|
||||
for needed in ["enable --now", "restart fips-dns.service"] {
|
||||
if !hint.contains(needed) {
|
||||
problems.push(format!("hint lacks '{needed}': {hint}"));
|
||||
}
|
||||
}
|
||||
}
|
||||
_ => problems.push(format!(
|
||||
"expected one systemd-resolved hint line, found {}: {hints:?}",
|
||||
hints.len()
|
||||
)),
|
||||
}
|
||||
for line in &lines {
|
||||
for banned in BANNED {
|
||||
if line.contains(banned) {
|
||||
problems.push(format!("names a package manager ('{banned}'): {line}"));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
assert!(
|
||||
problems.is_empty(),
|
||||
"{SETUP}'s no-resolver hint is wrong:\n {}",
|
||||
problems.join("\n ")
|
||||
);
|
||||
}
|
||||
|
||||
@@ -684,6 +684,22 @@ DOCKERFILE
|
||||
fail "missing manual instructions warning"
|
||||
fi
|
||||
|
||||
# The script ships beyond Debian, so the hint must not name one
|
||||
# distribution's package manager.
|
||||
if echo "$output" | grep -qE '(apt|apt-get|dnf|yum|zypper) install|pacman -S'; then
|
||||
fail "manual instructions name a package manager"
|
||||
else
|
||||
pass "manual instructions name no package manager"
|
||||
fi
|
||||
|
||||
# Setup uses systemd-resolved only when it is active, so the hint
|
||||
# must say to start it, not only to install or enable it.
|
||||
if echo "$output" | grep -qF 'enable --now systemd-resolved'; then
|
||||
pass "manual instructions start systemd-resolved"
|
||||
else
|
||||
fail "manual instructions do not start systemd-resolved"
|
||||
fi
|
||||
|
||||
run_teardown "$name" >/dev/null 2>&1
|
||||
check_removed "$name" /run/fips/dns-backend \
|
||||
"teardown cleaned state file" \
|
||||
|
||||
Reference in New Issue
Block a user