From 54931ed72ebde041f5a7e15b4534d530a2b66861 Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Mon, 5 Oct 2026 23:31:31 +0000 Subject: [PATCH] Give a package-manager-neutral systemd-resolved hint when no DNS resolver is found When fips-dns-setup finds no supported resolver it printed "sudo apt install systemd-resolved", although the script is not Debian-only: the Arch packages and the systemd tarball ship it too. The hint now names no package manager. It says to install systemd-resolved if needed, to start it with "systemctl enable --now systemd-resolved", since setup uses systemd-resolved only when the unit is active, and then to restart fips-dns.service so detection runs again. A packaging unit test checks the hint line and that the script names no package manager install command, and the dns-resolver no-resolver scenario asserts the same on the script's real output. --- packaging/common/fips-dns-setup | 2 +- src/packaging_tests.rs | 57 +++++++++++++++++++++++++++++++++ testing/dns-resolver/test.sh | 16 +++++++++ 3 files changed, 74 insertions(+), 1 deletion(-) diff --git a/packaging/common/fips-dns-setup b/packaging/common/fips-dns-setup index 6617060f..fe26b5c0 100755 --- a/packaging/common/fips-dns-setup +++ b/packaging/common/fips-dns-setup @@ -224,7 +224,7 @@ log "To resolve .fips domains, configure your DNS resolver to forward" log "the .fips domain to [${FIPS_DNS_LOOPBACK_V6}]:${FIPS_DNS_PORT} (matches the daemon's default bind)." log "" log "Examples:" -log " systemd-resolved: sudo apt install systemd-resolved" +log " systemd-resolved: install it if needed (a separate package on some distributions), run 'sudo systemctl enable --now systemd-resolved', then 'sudo systemctl restart fips-dns.service'" log " dnsmasq: echo 'server=/fips/${FIPS_DNS_LOOPBACK_V6}#${FIPS_DNS_PORT}' | sudo tee /etc/dnsmasq.d/fips.conf" save_backend "none" exit 0 diff --git a/src/packaging_tests.rs b/src/packaging_tests.rs index 18b525c9..10338974 100644 --- a/src/packaging_tests.rs +++ b/src/packaging_tests.rs @@ -1258,3 +1258,60 @@ fn openwrt_config_offers_no_ble_block_because_musl_builds_have_no_ble() { where the BLE transport is not compiled: {found:?}" ); } + +/// `fips-dns-setup` is shared by the Debian package, the Arch packages, the +/// systemd tarball and, where it is packaged, the RPM, so the hint it prints +/// when it finds no DNS resolver must not tell the host to use one +/// distribution's package manager. +/// +/// Every systemd-resolved backend in the script gates on the unit being active +/// (`is_active`), so the hint must say to start it (`enable --now`), not only to +/// install or enable it, and then to restart `fips-dns.service` so detection +/// runs again. `test_no_resolver` in `testing/dns-resolver/test.sh` asserts the +/// same on the script's real output. +#[test] +fn fips_dns_setup_no_resolver_hint_starts_resolved_and_names_no_package_manager_because_the_script_is_not_debian_only() + { + const SETUP: &str = "packaging/common/fips-dns-setup"; + const BANNED: [&str; 6] = [ + "apt install", + "apt-get install", + "dnf install", + "yum install", + "zypper install", + "pacman -S", + ]; + let lines = code_lines(&repo_file(SETUP)); + let mut problems = Vec::new(); + + let hints: Vec<&String> = lines + .iter() + .filter(|l| l.starts_with("log \" systemd-resolved:")) + .collect(); + match hints.as_slice() { + [hint] => { + for needed in ["enable --now", "restart fips-dns.service"] { + if !hint.contains(needed) { + problems.push(format!("hint lacks '{needed}': {hint}")); + } + } + } + _ => problems.push(format!( + "expected one systemd-resolved hint line, found {}: {hints:?}", + hints.len() + )), + } + for line in &lines { + for banned in BANNED { + if line.contains(banned) { + problems.push(format!("names a package manager ('{banned}'): {line}")); + } + } + } + + assert!( + problems.is_empty(), + "{SETUP}'s no-resolver hint is wrong:\n {}", + problems.join("\n ") + ); +} diff --git a/testing/dns-resolver/test.sh b/testing/dns-resolver/test.sh index 07f72df9..96f0be93 100755 --- a/testing/dns-resolver/test.sh +++ b/testing/dns-resolver/test.sh @@ -684,6 +684,22 @@ DOCKERFILE fail "missing manual instructions warning" fi + # The script ships beyond Debian, so the hint must not name one + # distribution's package manager. + if echo "$output" | grep -qE '(apt|apt-get|dnf|yum|zypper) install|pacman -S'; then + fail "manual instructions name a package manager" + else + pass "manual instructions name no package manager" + fi + + # Setup uses systemd-resolved only when it is active, so the hint + # must say to start it, not only to install or enable it. + if echo "$output" | grep -qF 'enable --now systemd-resolved'; then + pass "manual instructions start systemd-resolved" + else + fail "manual instructions do not start systemd-resolved" + fi + run_teardown "$name" >/dev/null 2>&1 check_removed "$name" /run/fips/dns-backend \ "teardown cleaned state file" \