Files
fips/packaging/common/fips-dns-teardown
T
Johnathan CorganandGitHub fe205e74de Multi-backend DNS configuration for .fips domain (#58)
Replace the resolvectl-only fips-dns.service with a detection script
that configures whichever DNS resolver is available:

1. systemd dns-delegate (systemd >= 258, declarative drop-in)
2. systemd-resolved via resolvectl (most systemd distros)
3. dnsmasq (standalone)
4. NetworkManager with dnsmasq plugin
5. Warning with manual instructions if none found

Service reloads are non-fatal — config is written and the backend
is recorded even if the reload fails, preventing state file cleanup
issues under set -e.

Teardown reads the recorded backend from /run/fips/dns-backend and
reverses the configuration, or cleans up all possible backends if
the state file is missing.

Includes a Docker-based test harness (testing/dns-resolver/test.sh)
covering all five backends across Debian 12, Debian 13, Fedora,
and bare systems.

Fixes #52.
2026-04-11 18:45:17 +01:00

78 lines
2.0 KiB
Bash
Executable File

#!/bin/bash
# fips-dns-teardown — Remove DNS routing for the .fips domain.
#
# Reverses whatever fips-dns-setup configured. Reads the backend from
# the state file, or cleans up all possible backends if state is missing.
set -e
FIPS_INTERFACE="fips0"
DNS_DELEGATE_FILE="/etc/systemd/dns-delegate/fips.dns-delegate"
DNSMASQ_CONF="/etc/dnsmasq.d/fips.conf"
NM_DNSMASQ_CONF="/etc/NetworkManager/dnsmasq.d/fips.conf"
STATE_FILE="/run/fips/dns-backend"
log() { echo "fips-dns: $*"; }
is_active() {
systemctl is-active --quiet "$1" 2>/dev/null
}
teardown_dns_delegate() {
[ -f "$DNS_DELEGATE_FILE" ] || return 0
log "Removing dns-delegate config"
rm -f "$DNS_DELEGATE_FILE"
is_active systemd-resolved.service && systemctl restart systemd-resolved
return 0
}
teardown_resolvectl() {
command -v resolvectl >/dev/null 2>&1 || return 0
is_active systemd-resolved.service || return 0
ip link show "$FIPS_INTERFACE" >/dev/null 2>&1 || return 0
log "Reverting resolvectl config"
resolvectl revert "$FIPS_INTERFACE" 2>/dev/null || true
return 0
}
teardown_dnsmasq() {
[ -f "$DNSMASQ_CONF" ] || return 0
log "Removing dnsmasq config"
rm -f "$DNSMASQ_CONF"
is_active dnsmasq.service && systemctl reload dnsmasq || true
return 0
}
teardown_nm_dnsmasq() {
[ -f "$NM_DNSMASQ_CONF" ] || return 0
log "Removing NetworkManager dnsmasq config"
rm -f "$NM_DNSMASQ_CONF"
is_active NetworkManager.service && nmcli general reload 2>/dev/null || true
return 0
}
# --- Main ---
backend=""
if [ -f "$STATE_FILE" ]; then
backend=$(cat "$STATE_FILE")
fi
case "$backend" in
dns-delegate) teardown_dns_delegate ;;
resolvectl) teardown_resolvectl ;;
dnsmasq) teardown_dnsmasq ;;
nm-dnsmasq) teardown_nm_dnsmasq ;;
none) ;; # Nothing was configured
*)
# State unknown — clean up everything
teardown_dns_delegate
teardown_resolvectl
teardown_dnsmasq
teardown_nm_dnsmasq
;;
esac
rm -f "$STATE_FILE"
exit 0