summary refs log tree commit diff
path: root/src/dns-manager
diff options
context:
space:
mode:
Diffstat (limited to 'src/dns-manager')
-rw-r--r--src/dns-manager/Makefile.am28
-rw-r--r--src/dns-manager/Makefile.in626
-rw-r--r--src/dns-manager/nm-dns-bind.c528
-rw-r--r--src/dns-manager/nm-dns-bind.h47
-rw-r--r--src/dns-manager/nm-dns-dnsmasq.c371
-rw-r--r--src/dns-manager/nm-dns-dnsmasq.h47
-rw-r--r--src/dns-manager/nm-dns-manager.c1100
-rw-r--r--src/dns-manager/nm-dns-manager.h95
-rw-r--r--src/dns-manager/nm-dns-plugin.c319
-rw-r--r--src/dns-manager/nm-dns-plugin.h112
10 files changed, 3273 insertions, 0 deletions
diff --git a/src/dns-manager/Makefile.am b/src/dns-manager/Makefile.am
new file mode 100644
index 00000000..1ffe62dc
--- /dev/null
+++ b/src/dns-manager/Makefile.am
@@ -0,0 +1,28 @@
+INCLUDES = \
+	-I${top_srcdir}/src/logging \
+	-I${top_srcdir}/libnm-util \
+	-I${top_srcdir}/src \
+	-I${top_srcdir}/include
+
+noinst_LTLIBRARIES = libdns-manager.la
+
+libdns_manager_la_SOURCES = \
+	nm-dns-manager.h \
+	nm-dns-manager.c \
+	nm-dns-plugin.h \
+	nm-dns-plugin.c \
+	nm-dns-dnsmasq.h \
+	nm-dns-dnsmasq.c \
+	nm-dns-bind.h \
+	nm-dns-bind.c
+
+libdns_manager_la_CPPFLAGS = \
+	$(DBUS_CFLAGS) \
+	$(GLIB_CFLAGS) \
+	-DLOCALSTATEDIR=\"$(localstatedir)\"
+
+libdns_manager_la_LIBADD = \
+	$(top_builddir)/src/logging/libnm-logging.la \
+	$(DBUS_LIBS) \
+	$(GLIB_LIBS)
+
diff --git a/src/dns-manager/Makefile.in b/src/dns-manager/Makefile.in
new file mode 100644
index 00000000..496d3756
--- /dev/null
+++ b/src/dns-manager/Makefile.in
@@ -0,0 +1,626 @@
+# Makefile.in generated by automake 1.11.1 from Makefile.am.
+# @configure_input@
+
+# Copyright (C) 1994, 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002,
+# 2003, 2004, 2005, 2006, 2007, 2008, 2009  Free Software Foundation,
+# Inc.
+# This Makefile.in is free software; the Free Software Foundation
+# gives unlimited permission to copy and/or distribute it,
+# with or without modifications, as long as this notice is preserved.
+
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY, to the extent permitted by law; without
+# even the implied warranty of MERCHANTABILITY or FITNESS FOR A
+# PARTICULAR PURPOSE.
+
+@SET_MAKE@
+
+VPATH = @srcdir@
+pkgdatadir = $(datadir)/@PACKAGE@
+pkgincludedir = $(includedir)/@PACKAGE@
+pkglibdir = $(libdir)/@PACKAGE@
+pkglibexecdir = $(libexecdir)/@PACKAGE@
+am__cd = CDPATH="$${ZSH_VERSION+.}$(PATH_SEPARATOR)" && cd
+install_sh_DATA = $(install_sh) -c -m 644
+install_sh_PROGRAM = $(install_sh) -c
+install_sh_SCRIPT = $(install_sh) -c
+INSTALL_HEADER = $(INSTALL_DATA)
+transform = $(program_transform_name)
+NORMAL_INSTALL = :
+PRE_INSTALL = :
+POST_INSTALL = :
+NORMAL_UNINSTALL = :
+PRE_UNINSTALL = :
+POST_UNINSTALL = :
+build_triplet = @build@
+host_triplet = @host@
+subdir = src/dns-manager
+DIST_COMMON = $(srcdir)/Makefile.am $(srcdir)/Makefile.in
+ACLOCAL_M4 = $(top_srcdir)/aclocal.m4
+am__aclocal_m4_deps = $(top_srcdir)/m4/compiler_warnings.m4 \
+	$(top_srcdir)/m4/gtk-doc.m4 $(top_srcdir)/m4/intltool.m4 \
+	$(top_srcdir)/m4/libnl-check.m4 $(top_srcdir)/m4/libtool.m4 \
+	$(top_srcdir)/m4/ltoptions.m4 $(top_srcdir)/m4/ltsugar.m4 \
+	$(top_srcdir)/m4/ltversion.m4 $(top_srcdir)/m4/lt~obsolete.m4 \
+	$(top_srcdir)/configure.ac
+am__configure_deps = $(am__aclocal_m4_deps) $(CONFIGURE_DEPENDENCIES) \
+	$(ACLOCAL_M4)
+mkinstalldirs = $(install_sh) -d
+CONFIG_HEADER = $(top_builddir)/config.h
+CONFIG_CLEAN_FILES =
+CONFIG_CLEAN_VPATH_FILES =
+LTLIBRARIES = $(noinst_LTLIBRARIES)
+am__DEPENDENCIES_1 =
+libdns_manager_la_DEPENDENCIES =  \
+	$(top_builddir)/src/logging/libnm-logging.la \
+	$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
+am_libdns_manager_la_OBJECTS = libdns_manager_la-nm-dns-manager.lo \
+	libdns_manager_la-nm-dns-plugin.lo \
+	libdns_manager_la-nm-dns-dnsmasq.lo \
+	libdns_manager_la-nm-dns-bind.lo
+libdns_manager_la_OBJECTS = $(am_libdns_manager_la_OBJECTS)
+AM_V_lt = $(am__v_lt_$(V))
+am__v_lt_ = $(am__v_lt_$(AM_DEFAULT_VERBOSITY))
+am__v_lt_0 = --silent
+DEFAULT_INCLUDES = -I.@am__isrc@ -I$(top_builddir)
+depcomp = $(SHELL) $(top_srcdir)/depcomp
+am__depfiles_maybe = depfiles
+am__mv = mv -f
+COMPILE = $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(AM_CPPFLAGS) \
+	$(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS)
+LTCOMPILE = $(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) \
+	$(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) \
+	$(DEFAULT_INCLUDES) $(INCLUDES) $(AM_CPPFLAGS) $(CPPFLAGS) \
+	$(AM_CFLAGS) $(CFLAGS)
+AM_V_CC = $(am__v_CC_$(V))
+am__v_CC_ = $(am__v_CC_$(AM_DEFAULT_VERBOSITY))
+am__v_CC_0 = @echo "  CC    " $@;
+AM_V_at = $(am__v_at_$(V))
+am__v_at_ = $(am__v_at_$(AM_DEFAULT_VERBOSITY))
+am__v_at_0 = @
+CCLD = $(CC)
+LINK = $(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) \
+	$(LIBTOOLFLAGS) --mode=link $(CCLD) $(AM_CFLAGS) $(CFLAGS) \
+	$(AM_LDFLAGS) $(LDFLAGS) -o $@
+AM_V_CCLD = $(am__v_CCLD_$(V))
+am__v_CCLD_ = $(am__v_CCLD_$(AM_DEFAULT_VERBOSITY))
+am__v_CCLD_0 = @echo "  CCLD  " $@;
+AM_V_GEN = $(am__v_GEN_$(V))
+am__v_GEN_ = $(am__v_GEN_$(AM_DEFAULT_VERBOSITY))
+am__v_GEN_0 = @echo "  GEN   " $@;
+SOURCES = $(libdns_manager_la_SOURCES)
+DIST_SOURCES = $(libdns_manager_la_SOURCES)
+ETAGS = etags
+CTAGS = ctags
+DISTFILES = $(DIST_COMMON) $(DIST_SOURCES) $(TEXINFOS) $(EXTRA_DIST)
+ACLOCAL = @ACLOCAL@
+ACLOCAL_AMFLAGS = @ACLOCAL_AMFLAGS@
+ALL_LINGUAS = @ALL_LINGUAS@
+AMTAR = @AMTAR@
+AM_DEFAULT_VERBOSITY = @AM_DEFAULT_VERBOSITY@
+AR = @AR@
+AUTOCONF = @AUTOCONF@
+AUTOHEADER = @AUTOHEADER@
+AUTOMAKE = @AUTOMAKE@
+AWK = @AWK@
+CATALOGS = @CATALOGS@
+CATOBJEXT = @CATOBJEXT@
+CC = @CC@
+CCDEPMODE = @CCDEPMODE@
+CFLAGS = @CFLAGS@
+CPP = @CPP@
+CPPFLAGS = @CPPFLAGS@
+CYGPATH_W = @CYGPATH_W@
+DATADIRNAME = @DATADIRNAME@
+DBUS_CFLAGS = @DBUS_CFLAGS@
+DBUS_LIBS = @DBUS_LIBS@
+DBUS_SYS_DIR = @DBUS_SYS_DIR@
+DEFS = @DEFS@
+DEPDIR = @DEPDIR@
+DHCLIENT_PATH = @DHCLIENT_PATH@
+DHCLIENT_VERSION = @DHCLIENT_VERSION@
+DHCPCD_PATH = @DHCPCD_PATH@
+DISABLE_DEPRECATED = @DISABLE_DEPRECATED@
+DSYMUTIL = @DSYMUTIL@
+DUMPBIN = @DUMPBIN@
+ECHO_C = @ECHO_C@
+ECHO_N = @ECHO_N@
+ECHO_T = @ECHO_T@
+EGREP = @EGREP@
+EXEEXT = @EXEEXT@
+FGREP = @FGREP@
+GETTEXT_PACKAGE = @GETTEXT_PACKAGE@
+GIO_CFLAGS = @GIO_CFLAGS@
+GIO_LIBS = @GIO_LIBS@
+GLIB_CFLAGS = @GLIB_CFLAGS@
+GLIB_GENMARSHAL = @GLIB_GENMARSHAL@
+GLIB_LIBS = @GLIB_LIBS@
+GMODULE_CFLAGS = @GMODULE_CFLAGS@
+GMODULE_LIBS = @GMODULE_LIBS@
+GMOFILES = @GMOFILES@
+GMSGFMT = @GMSGFMT@
+GNUTLS_CFLAGS = @GNUTLS_CFLAGS@
+GNUTLS_LIBS = @GNUTLS_LIBS@
+GREP = @GREP@
+GTKDOC_CHECK = @GTKDOC_CHECK@
+GTKDOC_MKPDF = @GTKDOC_MKPDF@
+GTKDOC_REBASE = @GTKDOC_REBASE@
+GUDEV_CFLAGS = @GUDEV_CFLAGS@
+GUDEV_LIBS = @GUDEV_LIBS@
+HTML_DIR = @HTML_DIR@
+INSTALL = @INSTALL@
+INSTALL_DATA = @INSTALL_DATA@
+INSTALL_PROGRAM = @INSTALL_PROGRAM@
+INSTALL_SCRIPT = @INSTALL_SCRIPT@
+INSTALL_STRIP_PROGRAM = @INSTALL_STRIP_PROGRAM@
+INSTOBJEXT = @INSTOBJEXT@
+INTLLIBS = @INTLLIBS@
+INTLTOOL_EXTRACT = @INTLTOOL_EXTRACT@
+INTLTOOL_MERGE = @INTLTOOL_MERGE@
+INTLTOOL_PERL = @INTLTOOL_PERL@
+INTLTOOL_UPDATE = @INTLTOOL_UPDATE@
+IPTABLES_PATH = @IPTABLES_PATH@
+KERNEL_FIRMWARE_DIR = @KERNEL_FIRMWARE_DIR@
+LD = @LD@
+LDFLAGS = @LDFLAGS@
+LIBDL = @LIBDL@
+LIBGCRYPT_CFLAGS = @LIBGCRYPT_CFLAGS@
+LIBGCRYPT_CONFIG = @LIBGCRYPT_CONFIG@
+LIBGCRYPT_LIBS = @LIBGCRYPT_LIBS@
+LIBM = @LIBM@
+LIBNL_CFLAGS = @LIBNL_CFLAGS@
+LIBNL_LIBS = @LIBNL_LIBS@
+LIBOBJS = @LIBOBJS@
+LIBS = @LIBS@
+LIBTOOL = @LIBTOOL@
+LIPO = @LIPO@
+LN_S = @LN_S@
+LTLIBOBJS = @LTLIBOBJS@
+MAINT = @MAINT@
+MAKEINFO = @MAKEINFO@
+MKDIR_P = @MKDIR_P@
+MKINSTALLDIRS = @MKINSTALLDIRS@
+MSGFMT = @MSGFMT@
+MSGFMT_OPTS = @MSGFMT_OPTS@
+MSGMERGE = @MSGMERGE@
+NM = @NM@
+NMEDIT = @NMEDIT@
+NSS_CFLAGS = @NSS_CFLAGS@
+NSS_LIBS = @NSS_LIBS@
+OBJDUMP = @OBJDUMP@
+OBJEXT = @OBJEXT@
+OTOOL = @OTOOL@
+OTOOL64 = @OTOOL64@
+PACKAGE = @PACKAGE@
+PACKAGE_BUGREPORT = @PACKAGE_BUGREPORT@
+PACKAGE_NAME = @PACKAGE_NAME@
+PACKAGE_STRING = @PACKAGE_STRING@
+PACKAGE_TARNAME = @PACKAGE_TARNAME@
+PACKAGE_URL = @PACKAGE_URL@
+PACKAGE_VERSION = @PACKAGE_VERSION@
+PATH_SEPARATOR = @PATH_SEPARATOR@
+PKG_CONFIG = @PKG_CONFIG@
+PKG_CONFIG_LIBDIR = @PKG_CONFIG_LIBDIR@
+PKG_CONFIG_PATH = @PKG_CONFIG_PATH@
+POFILES = @POFILES@
+POLKIT_CFLAGS = @POLKIT_CFLAGS@
+POLKIT_LIBS = @POLKIT_LIBS@
+POSUB = @POSUB@
+PO_IN_DATADIR_FALSE = @PO_IN_DATADIR_FALSE@
+PO_IN_DATADIR_TRUE = @PO_IN_DATADIR_TRUE@
+PPPD_PLUGIN_DIR = @PPPD_PLUGIN_DIR@
+RANLIB = @RANLIB@
+RESOLVCONF_PATH = @RESOLVCONF_PATH@
+SED = @SED@
+SET_MAKE = @SET_MAKE@
+SHELL = @SHELL@
+STRIP = @STRIP@
+SYSTEM_CA_PATH = @SYSTEM_CA_PATH@
+UDEV_BASE_DIR = @UDEV_BASE_DIR@
+USE_NLS = @USE_NLS@
+UUID_CFLAGS = @UUID_CFLAGS@
+UUID_LIBS = @UUID_LIBS@
+VERSION = @VERSION@
+XGETTEXT = @XGETTEXT@
+abs_builddir = @abs_builddir@
+abs_srcdir = @abs_srcdir@
+abs_top_builddir = @abs_top_builddir@
+abs_top_srcdir = @abs_top_srcdir@
+ac_ct_CC = @ac_ct_CC@
+ac_ct_DUMPBIN = @ac_ct_DUMPBIN@
+am__include = @am__include@
+am__leading_dot = @am__leading_dot@
+am__quote = @am__quote@
+am__tar = @am__tar@
+am__untar = @am__untar@
+bindir = @bindir@
+build = @build@
+build_alias = @build_alias@
+build_cpu = @build_cpu@
+build_os = @build_os@
+build_vendor = @build_vendor@
+builddir = @builddir@
+datadir = @datadir@
+datarootdir = @datarootdir@
+docdir = @docdir@
+dvidir = @dvidir@
+exec_prefix = @exec_prefix@
+host = @host@
+host_alias = @host_alias@
+host_cpu = @host_cpu@
+host_os = @host_os@
+host_vendor = @host_vendor@
+htmldir = @htmldir@
+includedir = @includedir@
+infodir = @infodir@
+install_sh = @install_sh@
+libdir = @libdir@
+libexecdir = @libexecdir@
+localedir = @localedir@
+localstatedir = @localstatedir@
+mandir = @mandir@
+mkdir_p = @mkdir_p@
+oldincludedir = @oldincludedir@
+pdfdir = @pdfdir@
+prefix = @prefix@
+program_transform_name = @program_transform_name@
+psdir = @psdir@
+sbindir = @sbindir@
+sharedstatedir = @sharedstatedir@
+srcdir = @srcdir@
+sysconfdir = @sysconfdir@
+systemdsystemunitdir = @systemdsystemunitdir@
+target_alias = @target_alias@
+top_build_prefix = @top_build_prefix@
+top_builddir = @top_builddir@
+top_srcdir = @top_srcdir@
+INCLUDES = \
+	-I${top_srcdir}/src/logging \
+	-I${top_srcdir}/libnm-util \
+	-I${top_srcdir}/src \
+	-I${top_srcdir}/include
+
+noinst_LTLIBRARIES = libdns-manager.la
+libdns_manager_la_SOURCES = \
+	nm-dns-manager.h \
+	nm-dns-manager.c \
+	nm-dns-plugin.h \
+	nm-dns-plugin.c \
+	nm-dns-dnsmasq.h \
+	nm-dns-dnsmasq.c \
+	nm-dns-bind.h \
+	nm-dns-bind.c
+
+libdns_manager_la_CPPFLAGS = \
+	$(DBUS_CFLAGS) \
+	$(GLIB_CFLAGS) \
+	-DLOCALSTATEDIR=\"$(localstatedir)\"
+
+libdns_manager_la_LIBADD = \
+	$(top_builddir)/src/logging/libnm-logging.la \
+	$(DBUS_LIBS) \
+	$(GLIB_LIBS)
+
+all: all-am
+
+.SUFFIXES:
+.SUFFIXES: .c .lo .o .obj
+$(srcdir)/Makefile.in: @MAINTAINER_MODE_TRUE@ $(srcdir)/Makefile.am  $(am__configure_deps)
+	@for dep in $?; do \
+	  case '$(am__configure_deps)' in \
+	    *$$dep*) \
+	      ( cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh ) \
+	        && { if test -f $@; then exit 0; else break; fi; }; \
+	      exit 1;; \
+	  esac; \
+	done; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu src/dns-manager/Makefile'; \
+	$(am__cd) $(top_srcdir) && \
+	  $(AUTOMAKE) --gnu src/dns-manager/Makefile
+.PRECIOUS: Makefile
+Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
+	@case '$?' in \
+	  *config.status*) \
+	    cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh;; \
+	  *) \
+	    echo ' cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe)'; \
+	    cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe);; \
+	esac;
+
+$(top_builddir)/config.status: $(top_srcdir)/configure $(CONFIG_STATUS_DEPENDENCIES)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+
+$(top_srcdir)/configure: @MAINTAINER_MODE_TRUE@ $(am__configure_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(ACLOCAL_M4): @MAINTAINER_MODE_TRUE@ $(am__aclocal_m4_deps)
+	cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh
+$(am__aclocal_m4_deps):
+
+clean-noinstLTLIBRARIES:
+	-test -z "$(noinst_LTLIBRARIES)" || rm -f $(noinst_LTLIBRARIES)
+	@list='$(noinst_LTLIBRARIES)'; for p in $$list; do \
+	  dir="`echo $$p | sed -e 's|/[^/]*$$||'`"; \
+	  test "$$dir" != "$$p" || dir=.; \
+	  echo "rm -f \"$${dir}/so_locations\""; \
+	  rm -f "$${dir}/so_locations"; \
+	done
+libdns-manager.la: $(libdns_manager_la_OBJECTS) $(libdns_manager_la_DEPENDENCIES) 
+	$(AM_V_CCLD)$(LINK)  $(libdns_manager_la_OBJECTS) $(libdns_manager_la_LIBADD) $(LIBS)
+
+mostlyclean-compile:
+	-rm -f *.$(OBJEXT)
+
+distclean-compile:
+	-rm -f *.tab.c
+
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/libdns_manager_la-nm-dns-bind.Plo@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/libdns_manager_la-nm-dns-dnsmasq.Plo@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/libdns_manager_la-nm-dns-manager.Plo@am__quote@
+@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/libdns_manager_la-nm-dns-plugin.Plo@am__quote@
+
+.c.o:
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.o$$||'`;\
+@am__fastdepCC_TRUE@	$(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Po
+@am__fastdepCC_FALSE@	$(AM_V_CC) @AM_BACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(COMPILE) -c -o $@ $<
+
+.c.obj:
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.obj$$||'`;\
+@am__fastdepCC_TRUE@	$(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ `$(CYGPATH_W) '$<'` &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Po
+@am__fastdepCC_FALSE@	$(AM_V_CC) @AM_BACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(COMPILE) -c -o $@ `$(CYGPATH_W) '$<'`
+
+.c.lo:
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.lo$$||'`;\
+@am__fastdepCC_TRUE@	$(LTCOMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Plo
+@am__fastdepCC_FALSE@	$(AM_V_CC) @AM_BACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	source='$<' object='$@' libtool=yes @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(LTCOMPILE) -c -o $@ $<
+
+libdns_manager_la-nm-dns-manager.lo: nm-dns-manager.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT libdns_manager_la-nm-dns-manager.lo -MD -MP -MF $(DEPDIR)/libdns_manager_la-nm-dns-manager.Tpo -c -o libdns_manager_la-nm-dns-manager.lo `test -f 'nm-dns-manager.c' || echo '$(srcdir)/'`nm-dns-manager.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/libdns_manager_la-nm-dns-manager.Tpo $(DEPDIR)/libdns_manager_la-nm-dns-manager.Plo
+@am__fastdepCC_FALSE@	$(AM_V_CC) @AM_BACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	source='nm-dns-manager.c' object='libdns_manager_la-nm-dns-manager.lo' libtool=yes @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o libdns_manager_la-nm-dns-manager.lo `test -f 'nm-dns-manager.c' || echo '$(srcdir)/'`nm-dns-manager.c
+
+libdns_manager_la-nm-dns-plugin.lo: nm-dns-plugin.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT libdns_manager_la-nm-dns-plugin.lo -MD -MP -MF $(DEPDIR)/libdns_manager_la-nm-dns-plugin.Tpo -c -o libdns_manager_la-nm-dns-plugin.lo `test -f 'nm-dns-plugin.c' || echo '$(srcdir)/'`nm-dns-plugin.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/libdns_manager_la-nm-dns-plugin.Tpo $(DEPDIR)/libdns_manager_la-nm-dns-plugin.Plo
+@am__fastdepCC_FALSE@	$(AM_V_CC) @AM_BACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	source='nm-dns-plugin.c' object='libdns_manager_la-nm-dns-plugin.lo' libtool=yes @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o libdns_manager_la-nm-dns-plugin.lo `test -f 'nm-dns-plugin.c' || echo '$(srcdir)/'`nm-dns-plugin.c
+
+libdns_manager_la-nm-dns-dnsmasq.lo: nm-dns-dnsmasq.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT libdns_manager_la-nm-dns-dnsmasq.lo -MD -MP -MF $(DEPDIR)/libdns_manager_la-nm-dns-dnsmasq.Tpo -c -o libdns_manager_la-nm-dns-dnsmasq.lo `test -f 'nm-dns-dnsmasq.c' || echo '$(srcdir)/'`nm-dns-dnsmasq.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/libdns_manager_la-nm-dns-dnsmasq.Tpo $(DEPDIR)/libdns_manager_la-nm-dns-dnsmasq.Plo
+@am__fastdepCC_FALSE@	$(AM_V_CC) @AM_BACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	source='nm-dns-dnsmasq.c' object='libdns_manager_la-nm-dns-dnsmasq.lo' libtool=yes @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o libdns_manager_la-nm-dns-dnsmasq.lo `test -f 'nm-dns-dnsmasq.c' || echo '$(srcdir)/'`nm-dns-dnsmasq.c
+
+libdns_manager_la-nm-dns-bind.lo: nm-dns-bind.c
+@am__fastdepCC_TRUE@	$(AM_V_CC)$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -MT libdns_manager_la-nm-dns-bind.lo -MD -MP -MF $(DEPDIR)/libdns_manager_la-nm-dns-bind.Tpo -c -o libdns_manager_la-nm-dns-bind.lo `test -f 'nm-dns-bind.c' || echo '$(srcdir)/'`nm-dns-bind.c
+@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/libdns_manager_la-nm-dns-bind.Tpo $(DEPDIR)/libdns_manager_la-nm-dns-bind.Plo
+@am__fastdepCC_FALSE@	$(AM_V_CC) @AM_BACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	source='nm-dns-bind.c' object='libdns_manager_la-nm-dns-bind.lo' libtool=yes @AMDEPBACKSLASH@
+@AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
+@am__fastdepCC_FALSE@	$(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) $(LIBTOOLFLAGS) --mode=compile $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(libdns_manager_la_CPPFLAGS) $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) -c -o libdns_manager_la-nm-dns-bind.lo `test -f 'nm-dns-bind.c' || echo '$(srcdir)/'`nm-dns-bind.c
+
+mostlyclean-libtool:
+	-rm -f *.lo
+
+clean-libtool:
+	-rm -rf .libs _libs
+
+ID: $(HEADERS) $(SOURCES) $(LISP) $(TAGS_FILES)
+	list='$(SOURCES) $(HEADERS) $(LISP) $(TAGS_FILES)'; \
+	unique=`for i in $$list; do \
+	    if test -f "$$i"; then echo $$i; else echo $(srcdir)/$$i; fi; \
+	  done | \
+	  $(AWK) '{ files[$$0] = 1; nonempty = 1; } \
+	      END { if (nonempty) { for (i in files) print i; }; }'`; \
+	mkid -fID $$unique
+tags: TAGS
+
+TAGS:  $(HEADERS) $(SOURCES)  $(TAGS_DEPENDENCIES) \
+		$(TAGS_FILES) $(LISP)
+	set x; \
+	here=`pwd`; \
+	list='$(SOURCES) $(HEADERS)  $(LISP) $(TAGS_FILES)'; \
+	unique=`for i in $$list; do \
+	    if test -f "$$i"; then echo $$i; else echo $(srcdir)/$$i; fi; \
+	  done | \
+	  $(AWK) '{ files[$$0] = 1; nonempty = 1; } \
+	      END { if (nonempty) { for (i in files) print i; }; }'`; \
+	shift; \
+	if test -z "$(ETAGS_ARGS)$$*$$unique"; then :; else \
+	  test -n "$$unique" || unique=$$empty_fix; \
+	  if test $$# -gt 0; then \
+	    $(ETAGS) $(ETAGSFLAGS) $(AM_ETAGSFLAGS) $(ETAGS_ARGS) \
+	      "$$@" $$unique; \
+	  else \
+	    $(ETAGS) $(ETAGSFLAGS) $(AM_ETAGSFLAGS) $(ETAGS_ARGS) \
+	      $$unique; \
+	  fi; \
+	fi
+ctags: CTAGS
+CTAGS:  $(HEADERS) $(SOURCES)  $(TAGS_DEPENDENCIES) \
+		$(TAGS_FILES) $(LISP)
+	list='$(SOURCES) $(HEADERS)  $(LISP) $(TAGS_FILES)'; \
+	unique=`for i in $$list; do \
+	    if test -f "$$i"; then echo $$i; else echo $(srcdir)/$$i; fi; \
+	  done | \
+	  $(AWK) '{ files[$$0] = 1; nonempty = 1; } \
+	      END { if (nonempty) { for (i in files) print i; }; }'`; \
+	test -z "$(CTAGS_ARGS)$$unique" \
+	  || $(CTAGS) $(CTAGSFLAGS) $(AM_CTAGSFLAGS) $(CTAGS_ARGS) \
+	     $$unique
+
+GTAGS:
+	here=`$(am__cd) $(top_builddir) && pwd` \
+	  && $(am__cd) $(top_srcdir) \
+	  && gtags -i $(GTAGS_ARGS) "$$here"
+
+distclean-tags:
+	-rm -f TAGS ID GTAGS GRTAGS GSYMS GPATH tags
+
+distdir: $(DISTFILES)
+	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	list='$(DISTFILES)'; \
+	  dist_files=`for file in $$list; do echo $$file; done | \
+	  sed -e "s|^$$srcdirstrip/||;t" \
+	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
+	case $$dist_files in \
+	  */*) $(MKDIR_P) `echo "$$dist_files" | \
+			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sort -u` ;; \
+	esac; \
+	for file in $$dist_files; do \
+	  if test -f $$file || test -d $$file; then d=.; else d=$(srcdir); fi; \
+	  if test -d $$d/$$file; then \
+	    dir=`echo "/$$file" | sed -e 's,/[^/]*$$,,'`; \
+	    if test -d "$(distdir)/$$file"; then \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    if test -d $(srcdir)/$$file && test $$d != $(srcdir); then \
+	      cp -fpR $(srcdir)/$$file "$(distdir)$$dir" || exit 1; \
+	      find "$(distdir)/$$file" -type d ! -perm -700 -exec chmod u+rwx {} \;; \
+	    fi; \
+	    cp -fpR $$d/$$file "$(distdir)$$dir" || exit 1; \
+	  else \
+	    test -f "$(distdir)/$$file" \
+	    || cp -p $$d/$$file "$(distdir)/$$file" \
+	    || exit 1; \
+	  fi; \
+	done
+check-am: all-am
+check: check-am
+all-am: Makefile $(LTLIBRARIES)
+installdirs:
+install: install-am
+install-exec: install-exec-am
+install-data: install-data-am
+uninstall: uninstall-am
+
+install-am: all-am
+	@$(MAKE) $(AM_MAKEFLAGS) install-exec-am install-data-am
+
+installcheck: installcheck-am
+install-strip:
+	$(MAKE) $(AM_MAKEFLAGS) INSTALL_PROGRAM="$(INSTALL_STRIP_PROGRAM)" \
+	  install_sh_PROGRAM="$(INSTALL_STRIP_PROGRAM)" INSTALL_STRIP_FLAG=-s \
+	  `test -z '$(STRIP)' || \
+	    echo "INSTALL_PROGRAM_ENV=STRIPPROG='$(STRIP)'"` install
+mostlyclean-generic:
+
+clean-generic:
+
+distclean-generic:
+	-test -z "$(CONFIG_CLEAN_FILES)" || rm -f $(CONFIG_CLEAN_FILES)
+	-test . = "$(srcdir)" || test -z "$(CONFIG_CLEAN_VPATH_FILES)" || rm -f $(CONFIG_CLEAN_VPATH_FILES)
+
+maintainer-clean-generic:
+	@echo "This command is intended for maintainers to use"
+	@echo "it deletes files that may require special tools to rebuild."
+clean: clean-am
+
+clean-am: clean-generic clean-libtool clean-noinstLTLIBRARIES \
+	mostlyclean-am
+
+distclean: distclean-am
+	-rm -rf ./$(DEPDIR)
+	-rm -f Makefile
+distclean-am: clean-am distclean-compile distclean-generic \
+	distclean-tags
+
+dvi: dvi-am
+
+dvi-am:
+
+html: html-am
+
+html-am:
+
+info: info-am
+
+info-am:
+
+install-data-am:
+
+install-dvi: install-dvi-am
+
+install-dvi-am:
+
+install-exec-am:
+
+install-html: install-html-am
+
+install-html-am:
+
+install-info: install-info-am
+
+install-info-am:
+
+install-man:
+
+install-pdf: install-pdf-am
+
+install-pdf-am:
+
+install-ps: install-ps-am
+
+install-ps-am:
+
+installcheck-am:
+
+maintainer-clean: maintainer-clean-am
+	-rm -rf ./$(DEPDIR)
+	-rm -f Makefile
+maintainer-clean-am: distclean-am maintainer-clean-generic
+
+mostlyclean: mostlyclean-am
+
+mostlyclean-am: mostlyclean-compile mostlyclean-generic \
+	mostlyclean-libtool
+
+pdf: pdf-am
+
+pdf-am:
+
+ps: ps-am
+
+ps-am:
+
+uninstall-am:
+
+.MAKE: install-am install-strip
+
+.PHONY: CTAGS GTAGS all all-am check check-am clean clean-generic \
+	clean-libtool clean-noinstLTLIBRARIES ctags distclean \
+	distclean-compile distclean-generic distclean-libtool \
+	distclean-tags distdir dvi dvi-am html html-am info info-am \
+	install install-am install-data install-data-am install-dvi \
+	install-dvi-am install-exec install-exec-am install-html \
+	install-html-am install-info install-info-am install-man \
+	install-pdf install-pdf-am install-ps install-ps-am \
+	install-strip installcheck installcheck-am installdirs \
+	maintainer-clean maintainer-clean-generic mostlyclean \
+	mostlyclean-compile mostlyclean-generic mostlyclean-libtool \
+	pdf pdf-am ps ps-am tags uninstall uninstall-am
+
+
+# Tell versions [3.59,3.63) of GNU make to not export all variables.
+# Otherwise a system limit (for SysV at least) may be exceeded.
+.NOEXPORT:
diff --git a/src/dns-manager/nm-dns-bind.c b/src/dns-manager/nm-dns-bind.c
new file mode 100644
index 00000000..9e3fc173
--- /dev/null
+++ b/src/dns-manager/nm-dns-bind.c
@@ -0,0 +1,528 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/*
+ * Copyright (C) 2010 Dan Williams <dcbw@redhat.com>
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2, or (at your option)
+ * any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ */
+
+#include <config.h>
+#include <stdlib.h>
+#include <unistd.h>
+#include <sys/types.h>
+#include <sys/wait.h>
+#include <arpa/inet.h>
+#include <sys/stat.h>
+
+#include <glib.h>
+#include <glib/gi18n.h>
+
+#include "nm-dns-bind.h"
+#include "nm-logging.h"
+#include "nm-ip4-config.h"
+#include "nm-ip6-config.h"
+
+G_DEFINE_TYPE (NMDnsBind, nm_dns_bind, NM_TYPE_DNS_PLUGIN)
+
+#define NM_DNS_BIND_GET_PRIVATE(o) (G_TYPE_INSTANCE_GET_PRIVATE ((o), NM_TYPE_DNS_BIND, NMDnsBindPrivate))
+
+#define PIDFILE LOCALSTATEDIR "/run/nm-dns-named.pid"
+#define CONFFILE LOCALSTATEDIR "/run/nm-dns-named.conf"
+
+typedef struct {
+	GPid pid;
+} NMDnsBindPrivate;
+
+/*******************************************/
+
+static inline const char *
+find_bind (void)
+{
+	static const char *paths[] = {
+		"/usr/local/sbin/named",
+		"/usr/sbin/named",
+		"/sbin/named",
+		NULL
+	};
+	const char **binary = paths;
+
+	while (*binary != NULL) {
+		if (g_file_test (*binary, G_FILE_TEST_EXISTS))
+			return *binary;
+		binary++;
+	}
+	return NULL;
+}
+
+static gboolean
+start_bind (NMDnsBind *self)
+{
+	const char *argv[10];
+
+	argv[0] = find_bind ();
+	argv[1] = "-f";  /* don't daemonize; stay in foreground */
+	argv[2] = "-c";
+	argv[3] = CONFFILE;
+	argv[4] = NULL;
+
+	/* And finally spawn bind */
+	return nm_dns_plugin_child_spawn (NM_DNS_PLUGIN (self), argv, PIDFILE, "bin/named");
+}
+
+/*******************************************/
+
+static gboolean
+find_address (GPtrArray *array, const char *addr)
+{
+	int n;
+
+	for (n = 0; n < array->len; n++) {
+		if (g_strcmp0 ((const char*) g_ptr_array_index (array, n), addr) == 0)
+			return TRUE;
+	}
+	return FALSE;
+}
+
+static void
+add_ip4_nameservers (NMIP4Config *ip4, GPtrArray *array)
+{
+	int i;
+
+	for (i = 0; i < nm_ip4_config_get_num_nameservers (ip4); i++) {
+		char buf[INET_ADDRSTRLEN + 1];
+		struct in_addr addr;
+
+		memset (&buf[0], 0, sizeof (buf));
+		addr.s_addr = nm_ip4_config_get_nameserver (ip4, i);
+		if (inet_ntop (AF_INET, &addr, buf, sizeof (buf))) {
+			if (!find_address (array, buf))
+				g_ptr_array_add (array, g_strdup (buf));
+		}
+	}
+}
+
+static gboolean
+ip6_addr_to_string (const struct in6_addr *addr, char *buf, size_t buflen)
+{
+	/* inet_ntop is probably supposed to do this for us, but it doesn't */
+	if (IN6_IS_ADDR_V4MAPPED (addr))
+		return !!inet_ntop (AF_INET, &(addr->s6_addr32[3]), buf, buflen);
+
+	return !!inet_ntop (AF_INET6, addr, buf, buflen);
+}
+
+static void
+add_ip6_nameservers (NMIP6Config *ip6, GPtrArray *array)
+{
+	char buf[INET6_ADDRSTRLEN + 1];
+	int i;
+
+	for (i = 0; i < nm_ip6_config_get_num_nameservers (ip6); i++) {
+		memset (buf, 0, sizeof (buf));
+		if (ip6_addr_to_string (nm_ip6_config_get_nameserver (ip6, i), buf, sizeof (buf))) {
+			if (!find_address (array, buf))
+				g_ptr_array_add (array, g_strdup (buf));
+		}
+	}
+}
+
+typedef struct {
+	guint32 dhash;
+	char *domain;
+	GPtrArray *servers;
+} ZoneInfo;
+
+static ZoneInfo *
+zone_new (const char *domain)
+{
+	ZoneInfo *info;
+
+	g_return_val_if_fail (domain != NULL, NULL);
+
+	info = g_malloc0 (sizeof (ZoneInfo));
+	info->domain = g_strdup (domain);
+	info->dhash = g_str_hash (domain);
+	info->servers = g_ptr_array_sized_new (4);
+	return info;
+}
+
+static void
+zone_add_nameserver (ZoneInfo *info, const char *server)
+{
+	guint32 i;
+
+	g_return_if_fail (info != NULL);
+	g_return_if_fail (server != NULL);
+
+	for (i = 0; i < info->servers->len; i++) {
+		if (g_strcmp0 ((char *) g_ptr_array_index (info->servers, i), server) == 0)
+			return;
+	}
+	g_ptr_array_add (info->servers, g_strdup (server));
+}
+
+static void
+zone_free (ZoneInfo *info)
+{
+	g_return_if_fail (info != NULL);
+
+	g_free (info->domain);
+	g_ptr_array_foreach (info->servers, (GFunc) g_free, NULL);
+	g_ptr_array_free (info->servers, TRUE);
+	memset (info, 0, sizeof (ZoneInfo));
+	g_free (info);
+}
+
+static ZoneInfo *
+find_zone (GPtrArray *zones, const char *domain)
+{
+	guint32 dhash, i;
+
+	g_return_val_if_fail (domain != NULL, FALSE);
+
+	dhash = g_str_hash (domain);
+	for (i = 0; i < zones->len; i++) {
+		ZoneInfo *zone = g_ptr_array_index (zones, i);
+
+		if (zone->dhash == dhash)
+			return zone;
+	}
+	return NULL;
+}
+
+static void
+add_zone (GObject *ip, GPtrArray *zones)
+{
+	guint32 i, j, ns, nd, nn;
+	GPtrArray *to_add;
+	ZoneInfo *z;
+
+	if (NM_IS_IP4_CONFIG (ip)) {
+		ns = nm_ip4_config_get_num_searches (NM_IP4_CONFIG (ip));
+		nd = nm_ip4_config_get_num_domains (NM_IP4_CONFIG (ip));
+		nn = nm_ip4_config_get_num_nameservers (NM_IP4_CONFIG (ip));
+	} else if (NM_IS_IP6_CONFIG (ip)) {
+		ns = nm_ip6_config_get_num_searches (NM_IP6_CONFIG (ip));
+		nd = nm_ip6_config_get_num_domains (NM_IP6_CONFIG (ip));
+		nn = nm_ip6_config_get_num_nameservers (NM_IP6_CONFIG (ip));
+	} else
+		g_assert_not_reached ();
+
+	/* If we don't have any domains or searches, or we don't have any
+	 * nameservers, we can't do split DNS for this config.
+	 */
+	if ((!nd && !ns) || !nn)
+		return;
+
+	to_add = g_ptr_array_sized_new (MAX (ns, nd));
+
+	/* searches are preferred over domains */
+	for (i = 0; i < ns; i++) {
+		const char *domain = NULL;
+
+		if (NM_IS_IP4_CONFIG (ip))
+			domain = nm_ip4_config_get_search (NM_IP4_CONFIG (ip), i);
+		else if (NM_IS_IP6_CONFIG (ip))
+			domain = nm_ip6_config_get_search (NM_IP6_CONFIG (ip), i);
+
+		z = find_zone (zones, domain);
+		if (!z) {
+			z = zone_new (domain);
+			g_ptr_array_add (zones, z);
+		}
+		g_ptr_array_add (to_add, z);
+	}
+
+	if (ns == 0) {
+		/* If no searches, add any domains */
+		for (i = 0; i < nd; i++) {
+			const char *domain = NULL;
+
+			if (NM_IS_IP4_CONFIG (ip))
+				domain = nm_ip4_config_get_domain (NM_IP4_CONFIG (ip), i);
+			else if (NM_IS_IP6_CONFIG (ip))
+				domain = nm_ip6_config_get_domain (NM_IP6_CONFIG (ip), i);
+
+			z = find_zone (zones, domain);
+			if (!z) {
+				z = zone_new (domain);
+				g_ptr_array_add (zones, z);
+			}
+			g_ptr_array_add (to_add, z);
+		}
+	}
+
+	/* Now add the nameservers to every zone for this config */
+	for (i = 0; i < nn; i++) {
+		char buf[INET6_ADDRSTRLEN + 1];
+		struct in_addr addr4;
+		const struct in6_addr *addr6;
+
+		memset (&buf[0], 0, sizeof (buf));
+
+		if (NM_IS_IP4_CONFIG (ip)) {
+			addr4.s_addr = nm_ip4_config_get_nameserver (NM_IP4_CONFIG (ip), i);
+			if (!inet_ntop (AF_INET, &addr4, buf, sizeof (buf)))
+				continue;
+		} else if (NM_IS_IP6_CONFIG (ip)) {
+			addr6 = nm_ip6_config_get_nameserver (NM_IP6_CONFIG (ip), i);
+			if (!ip6_addr_to_string (addr6, buf, sizeof (buf)))
+				continue;
+		}
+
+		/* Add this nameserver to every zone from this IP config */
+		for (j = 0; j < to_add->len; j++) {
+			z = g_ptr_array_index (to_add, j);
+			zone_add_nameserver (z, buf);
+		}
+	}
+
+	g_ptr_array_free (to_add, TRUE);
+}
+
+static gboolean
+update (NMDnsPlugin *plugin,
+        const GSList *vpn_configs,
+        const GSList *dev_configs,
+        const GSList *other_configs,
+        const char *hostname)
+{
+	NMDnsBind *self = NM_DNS_BIND (plugin);
+	NMDnsBindPrivate *priv = NM_DNS_BIND_GET_PRIVATE (self);
+	GString *conf;
+	GPtrArray *globals, *zones;
+	GSList *iter;
+	GError *error = NULL;
+	int ignored, i, j;
+	gboolean success = FALSE;
+
+	/* Build up the new bind config file */
+	conf = g_string_sized_new (200);
+	globals = g_ptr_array_sized_new (6);
+
+	/* If any of the VPN configs *don't* have domains or searches, then we
+	 * dont' have any split DNS configuration for them, and we add them
+	 * first in the global nameserver lists.  Otherwise we add them later as
+	 * split DNS zones.
+	 */
+	for (iter = (GSList *) vpn_configs; iter;iter = g_slist_next (iter)) {
+		if (NM_IS_IP4_CONFIG (iter->data)) {
+			NMIP4Config *ip4 = NM_IP4_CONFIG (iter->data);
+
+			if (!nm_ip4_config_get_num_domains (ip4) && !nm_ip4_config_get_num_searches (ip4))
+				add_ip4_nameservers (ip4, globals);
+		} else if (NM_IS_IP6_CONFIG (iter->data)) {
+			NMIP6Config *ip6 = NM_IP6_CONFIG (iter->data);
+
+			if (!nm_ip6_config_get_num_domains (ip6) && !nm_ip6_config_get_num_searches (ip6))
+				add_ip6_nameservers (ip6, globals);
+		}
+	}
+
+	/* Get a list of global upstream servers with dupe checking */
+	for (iter = (GSList *) dev_configs; iter;iter = g_slist_next (iter)) {
+		if (NM_IS_IP4_CONFIG (iter->data))
+			add_ip4_nameservers (NM_IP4_CONFIG (iter->data), globals);
+		else if (NM_IS_IP6_CONFIG (iter->data))
+			add_ip6_nameservers (NM_IP6_CONFIG (iter->data), globals);
+	}
+
+	/* And any other random configs with dupe checking */
+	for (iter = (GSList *) other_configs; iter;iter = g_slist_next (iter)) {
+		if (NM_IS_IP4_CONFIG (iter->data))
+			add_ip4_nameservers (NM_IP4_CONFIG (iter->data), globals);
+		else if (NM_IS_IP6_CONFIG (iter->data))
+			add_ip6_nameservers (NM_IP6_CONFIG (iter->data), globals);
+	}
+
+	g_string_append (conf,
+		"options {\n"
+		"    directory \"" LOCALSTATEDIR "/named\";\n"
+		"    forward only;\n"
+		"    recursion yes;\n"
+		"    listen-on-v6 { ::1; };\n"
+		"    listen-on { 127.0.0.1; };\n"
+		"    forwarders {\n");
+
+	for (i = 0; i < globals->len; i++) {
+		char *ns = g_ptr_array_index (globals, i);
+
+		g_string_append_printf (conf, "        %s;\n", ns);
+		g_free (ns);
+	}
+	g_ptr_array_free (globals, TRUE);
+
+	g_string_append (conf,
+		"    };\n"
+		"};\n\n");
+
+	/* Build up the list of any split DNS zones, avoiding duplicates */
+	zones = g_ptr_array_sized_new (4);
+	for (iter = (GSList *) vpn_configs; iter;iter = g_slist_next (iter)) {
+		if (NM_IS_IP4_CONFIG (iter->data))
+			add_zone (G_OBJECT (iter->data), zones);
+		else if (NM_IS_IP6_CONFIG (iter->data))
+			add_zone (G_OBJECT (iter->data), zones);
+	}
+
+	/* Add all the zones to the config */
+	for (i = 0; i < zones->len; i++) {
+		ZoneInfo *z = g_ptr_array_index (zones, i);
+
+		g_string_append_printf (conf,
+			"zone \"%s\" IN {\n"
+			"    type forward;\n"
+			"    forward only;\n"
+			"    forwarders {\n",
+			z->domain);
+
+		/* Add each nameserver for this zone */
+		for (j = 0; j < z->servers->len; j++) {
+			g_string_append_printf (conf,
+				"        %s;\n",
+				(const char *) g_ptr_array_index (z->servers, j));
+		}
+
+		g_string_append (conf,
+			"    };\n"
+			"};\n\n");
+
+		zone_free (z);
+	}
+	g_ptr_array_free (zones, TRUE);
+
+	/* Write out the config file */
+	if (!g_file_set_contents (CONFFILE, conf->str, -1, &error)) {
+		nm_log_warn (LOGD_DNS, "Failed to write named config file %s: (%d) %s",
+		             CONFFILE,
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+		goto out;
+	}
+	ignored = chmod (CONFFILE, 0600);
+
+	nm_log_dbg (LOGD_DNS, "BIND local caching DNS configuration:");
+	nm_log_dbg (LOGD_DNS, "%s", conf->str);
+
+	if (priv->pid) {
+		/* Send it SIGHUP to reload the new configuration */
+		if (kill (priv->pid, SIGHUP) == 0)
+			success = TRUE;
+		else {
+			/* Sigh... some error.  Kill it and restart */
+			 nm_dns_plugin_child_kill (NM_DNS_PLUGIN (self));
+			 priv->pid = 0;
+		}
+	}
+
+	if (!success) {
+		/* Spawn it */
+		priv->pid = start_bind (self);
+		if (priv->pid)
+			success = TRUE;
+	}
+
+out:
+	g_string_free (conf, TRUE);
+	return success;
+}
+
+/****************************************************************/
+
+static void
+child_quit (NMDnsPlugin *plugin, gint status)
+{
+	NMDnsBind *self = NM_DNS_BIND (plugin);
+	gboolean failed = TRUE;
+	int err;
+
+	if (WIFEXITED (status)) {
+		err = WEXITSTATUS (status);
+		if (err) {
+			nm_log_warn (LOGD_DNS, "named exited with error %d", err);
+		} else
+			failed = FALSE;
+	} else if (WIFSTOPPED (status)) {
+		nm_log_warn (LOGD_DNS, "named stopped unexpectedly with signal %d", WSTOPSIG (status));
+	} else if (WIFSIGNALED (status)) {
+		nm_log_warn (LOGD_DNS, "named died with signal %d", WTERMSIG (status));
+	} else {
+		nm_log_warn (LOGD_DNS, "named died from an unknown cause");
+	}
+	unlink (CONFFILE);
+
+	if (failed)
+		g_signal_emit_by_name (self, NM_DNS_PLUGIN_FAILED);
+}
+
+/****************************************************************/
+
+static gboolean
+init (NMDnsPlugin *plugin)
+{
+	return TRUE;
+}
+
+static gboolean
+is_caching (NMDnsPlugin *plugin)
+{
+	return TRUE;
+}
+
+static const char *
+get_name (NMDnsPlugin *plugin)
+{
+	return "bind";
+}
+
+/****************************************************************/
+
+NMDnsBind *
+nm_dns_bind_new (void)
+{
+	return (NMDnsBind *) g_object_new (NM_TYPE_DNS_BIND, NULL);
+}
+
+static void
+nm_dns_bind_init (NMDnsBind *self)
+{
+}
+
+static void
+dispose (GObject *object)
+{
+	unlink (CONFFILE);
+
+	G_OBJECT_CLASS (nm_dns_bind_parent_class)->dispose (object);
+}
+
+static void
+nm_dns_bind_class_init (NMDnsBindClass *dns_class)
+{
+	NMDnsPluginClass *plugin_class = NM_DNS_PLUGIN_CLASS (dns_class);
+	GObjectClass *object_class = G_OBJECT_CLASS (dns_class);
+
+	g_type_class_add_private (dns_class, sizeof (NMDnsBindPrivate));
+
+	object_class->dispose = dispose;
+
+	plugin_class->init = init;
+	plugin_class->child_quit = child_quit;
+	plugin_class->is_caching = is_caching;
+	plugin_class->update = update;
+	plugin_class->get_name = get_name;
+}
+
diff --git a/src/dns-manager/nm-dns-bind.h b/src/dns-manager/nm-dns-bind.h
new file mode 100644
index 00000000..7127265f
--- /dev/null
+++ b/src/dns-manager/nm-dns-bind.h
@@ -0,0 +1,47 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/* This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2, or (at your option)
+ * any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Copyright (C) 2010 Red Hat, Inc.
+ */
+
+#ifndef NM_DNS_BIND_H
+#define NM_DNS_BIND_H
+
+#include <glib.h>
+#include <glib-object.h>
+
+#include "nm-dns-plugin.h"
+
+#define NM_TYPE_DNS_BIND            (nm_dns_bind_get_type ())
+#define NM_DNS_BIND(obj)            (G_TYPE_CHECK_INSTANCE_CAST ((obj), NM_TYPE_DNS_BIND, NMDnsBind))
+#define NM_DNS_BIND_CLASS(klass)    (G_TYPE_CHECK_CLASS_CAST ((klass), NM_TYPE_DNS_BIND, NMDnsBindClass))
+#define NM_IS_DNS_BIND(obj)         (G_TYPE_CHECK_INSTANCE_TYPE ((obj), NM_TYPE_DNS_BIND))
+#define NM_IS_DNS_BIND_CLASS(klass) (G_TYPE_CHECK_CLASS_TYPE ((obj), NM_TYPE_DNS_BIND))
+#define NM_DNS_BIND_GET_CLASS(obj)  (G_TYPE_INSTANCE_GET_CLASS ((obj), NM_TYPE_DNS_BIND, NMDnsBindClass))
+
+typedef struct {
+	NMDnsPlugin parent;
+} NMDnsBind;
+
+typedef struct {
+	NMDnsPluginClass parent;
+} NMDnsBindClass;
+
+GType nm_dns_bind_get_type (void);
+
+NMDnsBind *nm_dns_bind_new (void);
+
+#endif /* NM_DNS_BIND_H */
+
diff --git a/src/dns-manager/nm-dns-dnsmasq.c b/src/dns-manager/nm-dns-dnsmasq.c
new file mode 100644
index 00000000..41c8e2a6
--- /dev/null
+++ b/src/dns-manager/nm-dns-dnsmasq.c
@@ -0,0 +1,371 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/*
+ * Copyright (C) 2010 Dan Williams <dcbw@redhat.com>
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2, or (at your option)
+ * any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ */
+
+#include <config.h>
+#include <stdlib.h>
+#include <unistd.h>
+#include <sys/types.h>
+#include <sys/wait.h>
+#include <arpa/inet.h>
+#include <sys/stat.h>
+
+#include <glib.h>
+#include <glib/gi18n.h>
+
+#include "nm-dns-dnsmasq.h"
+#include "nm-logging.h"
+#include "nm-ip4-config.h"
+#include "nm-ip6-config.h"
+
+G_DEFINE_TYPE (NMDnsDnsmasq, nm_dns_dnsmasq, NM_TYPE_DNS_PLUGIN)
+
+#define NM_DNS_DNSMASQ_GET_PRIVATE(o) (G_TYPE_INSTANCE_GET_PRIVATE ((o), NM_TYPE_DNS_DNSMASQ, NMDnsDnsmasqPrivate))
+
+#define PIDFILE LOCALSTATEDIR "/run/nm-dns-dnsmasq.pid"
+#define CONFFILE LOCALSTATEDIR "/run/nm-dns-dnsmasq.conf"
+
+typedef struct {
+	guint32 foo;
+} NMDnsDnsmasqPrivate;
+
+/*******************************************/
+
+static inline const char *
+find_dnsmasq (void)
+{
+	static const char *paths[] = {
+		"/usr/local/sbin/dnsmasq",
+		"/usr/sbin/dnsmasq",
+		"/sbin/dnsmasq",
+		NULL
+	};
+	const char **binary = paths;
+
+	while (*binary != NULL) {
+		if (g_file_test (*binary, G_FILE_TEST_EXISTS))
+			return *binary;
+		binary++;
+	}
+	return NULL;
+}
+
+static gboolean
+add_ip4_config (GString *str, NMIP4Config *ip4, gboolean split)
+{
+	char buf[INET_ADDRSTRLEN + 1];
+	struct in_addr addr;
+	int n, i;
+	gboolean added = FALSE;
+
+	if (split) {
+		/* FIXME: it appears that dnsmasq can only handle one nameserver
+		 * per domain (at the manpage seems to indicate that) so only use
+		 * the first nameserver here.
+		 */
+		addr.s_addr = nm_ip4_config_get_nameserver (ip4, 0);
+		memset (&buf[0], 0, sizeof (buf));
+		if (!inet_ntop (AF_INET, &addr, buf, sizeof (buf)))
+			return FALSE;
+
+		/* searches are preferred over domains */
+		n = nm_ip4_config_get_num_searches (ip4);
+		for (i = 0; i < n; i++) {
+			g_string_append_printf (str, "server=/%s/%s\n",
+				                    nm_ip4_config_get_search (ip4, i),
+				                    buf);
+			added = TRUE;
+		}
+
+		if (n == 0) {
+			/* If not searches, use any domains */
+			n = nm_ip4_config_get_num_domains (ip4);
+			for (i = 0; i < n; i++) {
+				g_string_append_printf (str, "server=/%s/%s\n",
+							            nm_ip4_config_get_domain (ip4, i),
+							            buf);
+				added = TRUE;
+			}
+		}
+	}
+
+	/* If no searches or domains, just add the namservers */
+	if (!added) {
+		n = nm_ip4_config_get_num_nameservers (ip4);
+		for (i = 0; i < n; i++) {
+			memset (&buf[0], 0, sizeof (buf));
+			addr.s_addr = nm_ip4_config_get_nameserver (ip4, i);
+			if (inet_ntop (AF_INET, &addr, buf, sizeof (buf)))
+				g_string_append_printf (str, "server=%s\n", buf);
+		}
+	}
+
+	return TRUE;
+}
+
+static gboolean
+ip6_addr_to_string (const struct in6_addr *addr, char *buf, size_t buflen)
+{
+	memset (buf, 0, buflen);
+
+	/* inet_ntop is probably supposed to do this for us, but it doesn't */
+	if (IN6_IS_ADDR_V4MAPPED (addr))
+		return !!inet_ntop (AF_INET, &(addr->s6_addr32[3]), buf, buflen);
+
+	return !!inet_ntop (AF_INET6, addr, buf, buflen);
+}
+
+static gboolean
+add_ip6_config (GString *str, NMIP6Config *ip6, gboolean split)
+{
+	char buf[INET6_ADDRSTRLEN + 1];
+	const struct in6_addr *addr;
+	int n, i;
+	gboolean added = FALSE;
+
+	if (split) {
+		/* FIXME: it appears that dnsmasq can only handle one nameserver
+		 * per domain (at the manpage seems to indicate that) so only use
+		 * the first nameserver here.
+		 */
+		addr = nm_ip6_config_get_nameserver (ip6, 0);
+		if (!ip6_addr_to_string (addr, &buf[0], sizeof (buf)))
+			return FALSE;
+
+		/* searches are preferred over domains */
+		n = nm_ip6_config_get_num_searches (ip6);
+		for (i = 0; i < n; i++) {
+			g_string_append_printf (str, "server=/%s/%s\n",
+				                    nm_ip6_config_get_search (ip6, i),
+				                    buf);
+			added = TRUE;
+		}
+
+		if (n == 0) {
+			/* If not searches, use any domains */
+			n = nm_ip6_config_get_num_domains (ip6);
+			for (i = 0; i < n; i++) {
+				g_string_append_printf (str, "server=/%s/%s\n",
+							            nm_ip6_config_get_domain (ip6, i),
+							            buf);
+				added = TRUE;
+			}
+		}
+	}
+
+	/* If no searches or domains, just add the namservers */
+	if (!added) {
+		n = nm_ip6_config_get_num_nameservers (ip6);
+		for (i = 0; i < n; i++) {
+			addr = nm_ip6_config_get_nameserver (ip6, i);
+			if (ip6_addr_to_string (addr, &buf[0], sizeof (buf)))
+				g_string_append_printf (str, "server=%s\n", buf);
+		}
+	}
+
+	return TRUE;
+}
+
+static gboolean
+update (NMDnsPlugin *plugin,
+        const GSList *vpn_configs,
+        const GSList *dev_configs,
+        const GSList *other_configs,
+        const char *hostname)
+{
+	NMDnsDnsmasq *self = NM_DNS_DNSMASQ (plugin);
+	GString *conf;
+	GSList *iter;
+	const char *argv[10];
+	GError *error = NULL;
+	int ignored;
+	GPid pid = 0;
+
+	/* Kill the old dnsmasq; there doesn't appear to be a way to get dnsmasq
+	 * to reread the config file using SIGHUP or similar.  This is a small race
+	 * here when restarting dnsmasq when DNS requests could go to the upstream
+	 * servers instead of to dnsmasq.
+	 */
+	nm_dns_plugin_child_kill (plugin);
+
+	/* Build up the new dnsmasq config file */
+	conf = g_string_sized_new (150);
+
+	/* Use split DNS for VPN configs */
+	for (iter = (GSList *) vpn_configs; iter; iter = g_slist_next (iter)) {
+		if (NM_IS_IP4_CONFIG (iter->data))
+			add_ip4_config (conf, NM_IP4_CONFIG (iter->data), TRUE);
+		else if (NM_IS_IP6_CONFIG (iter->data))
+			add_ip6_config (conf, NM_IP6_CONFIG (iter->data), TRUE);
+	}
+
+	/* Now add interface configs without split DNS */
+	for (iter = (GSList *) dev_configs; iter;iter = g_slist_next (iter)) {
+		if (NM_IS_IP4_CONFIG (iter->data))
+			add_ip4_config (conf, NM_IP4_CONFIG (iter->data), FALSE);
+		else if (NM_IS_IP6_CONFIG (iter->data))
+			add_ip6_config (conf, NM_IP6_CONFIG (iter->data), FALSE);
+	}
+
+	/* And any other random configs */
+	for (iter = (GSList *) other_configs; iter;iter = g_slist_next (iter)) {
+		if (NM_IS_IP4_CONFIG (iter->data))
+			add_ip4_config (conf, NM_IP4_CONFIG (iter->data), FALSE);
+		else if (NM_IS_IP6_CONFIG (iter->data))
+			add_ip6_config (conf, NM_IP6_CONFIG (iter->data), FALSE);
+	}
+
+	/* Write out the config file */
+	if (!g_file_set_contents (CONFFILE, conf->str, -1, &error)) {
+		nm_log_warn (LOGD_DNS, "Failed to write dnsmasq config file %s: (%d) %s",
+		             CONFFILE,
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+		goto out;
+	}
+	ignored = chmod (CONFFILE, 0600);
+
+	nm_log_dbg (LOGD_DNS, "dnsmasq local caching DNS configuration:");
+	nm_log_dbg (LOGD_DNS, "%s", conf->str);
+
+	argv[0] = find_dnsmasq ();
+	argv[1] = "--no-resolv";  /* Use only commandline */
+	argv[2] = "--keep-in-foreground";
+	argv[3] = "--strict-order";
+	argv[4] = "--bind-interfaces";
+	argv[5] = "--pid-file=" PIDFILE;
+	argv[6] = "--listen-address=127.0.0.1"; /* Should work for both 4 and 6 */
+	argv[7] = "--conf-file=" CONFFILE;
+	argv[8] = NULL;
+
+	/* And finally spawn dnsmasq */
+	pid = nm_dns_plugin_child_spawn (NM_DNS_PLUGIN (self), argv, PIDFILE, "bin/dnsmasq");
+
+out:
+	g_string_free (conf, TRUE);
+	return pid ? TRUE : FALSE;
+}
+
+/****************************************************************/
+
+static const char *
+dm_exit_code_to_msg (int status)
+{
+	if (status == 1)
+		return "Configuration problem";
+	else if (status == 2)
+		return "Network access problem (address in use; permissions; etc)";
+	else if (status == 3)
+		return "Filesystem problem (missing file/directory; permissions; etc)";
+	else if (status == 4)
+		return "Memory allocation failure";
+	else if (status == 5)
+		return "Other problem";
+	else if (status >= 11)
+		return "Lease-script 'init' process failure";
+	return "Unknown error";
+}
+
+static void
+child_quit (NMDnsPlugin *plugin, gint status)
+{
+	NMDnsDnsmasq *self = NM_DNS_DNSMASQ (plugin);
+	gboolean failed = TRUE;
+	int err;
+
+	if (WIFEXITED (status)) {
+		err = WEXITSTATUS (status);
+		if (err) {
+			nm_log_warn (LOGD_DNS, "dnsmasq exited with error: %s (%d)",
+			             dm_exit_code_to_msg (err),
+			             err);
+		} else
+			failed = FALSE;
+	} else if (WIFSTOPPED (status)) {
+		nm_log_warn (LOGD_DNS, "dnsmasq stopped unexpectedly with signal %d", WSTOPSIG (status));
+	} else if (WIFSIGNALED (status)) {
+		nm_log_warn (LOGD_DNS, "dnsmasq died with signal %d", WTERMSIG (status));
+	} else {
+		nm_log_warn (LOGD_DNS, "dnsmasq died from an unknown cause");
+	}
+	unlink (CONFFILE);
+
+	if (failed)
+		g_signal_emit_by_name (self, NM_DNS_PLUGIN_FAILED);
+}
+
+/****************************************************************/
+
+static gboolean
+init (NMDnsPlugin *plugin)
+{
+	return TRUE;
+}
+
+static gboolean
+is_caching (NMDnsPlugin *plugin)
+{
+	return TRUE;
+}
+
+static const char *
+get_name (NMDnsPlugin *plugin)
+{
+	return "dnsmasq";
+}
+
+/****************************************************************/
+
+NMDnsDnsmasq *
+nm_dns_dnsmasq_new (void)
+{
+	return (NMDnsDnsmasq *) g_object_new (NM_TYPE_DNS_DNSMASQ, NULL);
+}
+
+static void
+nm_dns_dnsmasq_init (NMDnsDnsmasq *self)
+{
+}
+
+static void
+dispose (GObject *object)
+{
+	unlink (CONFFILE);
+
+	G_OBJECT_CLASS (nm_dns_dnsmasq_parent_class)->dispose (object);
+}
+
+static void
+nm_dns_dnsmasq_class_init (NMDnsDnsmasqClass *dns_class)
+{
+	NMDnsPluginClass *plugin_class = NM_DNS_PLUGIN_CLASS (dns_class);
+	GObjectClass *object_class = G_OBJECT_CLASS (dns_class);
+
+	g_type_class_add_private (dns_class, sizeof (NMDnsDnsmasqPrivate));
+
+	object_class->dispose = dispose;
+
+	plugin_class->init = init;
+	plugin_class->child_quit = child_quit;
+	plugin_class->is_caching = is_caching;
+	plugin_class->update = update;
+	plugin_class->get_name = get_name;
+}
+
diff --git a/src/dns-manager/nm-dns-dnsmasq.h b/src/dns-manager/nm-dns-dnsmasq.h
new file mode 100644
index 00000000..6491b271
--- /dev/null
+++ b/src/dns-manager/nm-dns-dnsmasq.h
@@ -0,0 +1,47 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/* This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2, or (at your option)
+ * any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Copyright (C) 2010 Red Hat, Inc.
+ */
+
+#ifndef NM_DNS_DNSMASQ_H
+#define NM_DNS_DNSMASQ_H
+
+#include <glib.h>
+#include <glib-object.h>
+
+#include "nm-dns-plugin.h"
+
+#define NM_TYPE_DNS_DNSMASQ            (nm_dns_dnsmasq_get_type ())
+#define NM_DNS_DNSMASQ(obj)            (G_TYPE_CHECK_INSTANCE_CAST ((obj), NM_TYPE_DNS_DNSMASQ, NMDnsDnsmasq))
+#define NM_DNS_DNSMASQ_CLASS(klass)    (G_TYPE_CHECK_CLASS_CAST ((klass), NM_TYPE_DNS_DNSMASQ, NMDnsDnsmasqClass))
+#define NM_IS_DNS_DNSMASQ(obj)         (G_TYPE_CHECK_INSTANCE_TYPE ((obj), NM_TYPE_DNS_DNSMASQ))
+#define NM_IS_DNS_DNSMASQ_CLASS(klass) (G_TYPE_CHECK_CLASS_TYPE ((obj), NM_TYPE_DNS_DNSMASQ))
+#define NM_DNS_DNSMASQ_GET_CLASS(obj)  (G_TYPE_INSTANCE_GET_CLASS ((obj), NM_TYPE_DNS_DNSMASQ, NMDnsDnsmasqClass))
+
+typedef struct {
+	NMDnsPlugin parent;
+} NMDnsDnsmasq;
+
+typedef struct {
+	NMDnsPluginClass parent;
+} NMDnsDnsmasqClass;
+
+GType nm_dns_dnsmasq_get_type (void);
+
+NMDnsDnsmasq *nm_dns_dnsmasq_new (void);
+
+#endif /* NM_DNS_DNSMASQ_H */
+
diff --git a/src/dns-manager/nm-dns-manager.c b/src/dns-manager/nm-dns-manager.c
new file mode 100644
index 00000000..7a6fbbc9
--- /dev/null
+++ b/src/dns-manager/nm-dns-manager.c
@@ -0,0 +1,1100 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/* NetworkManager -- Network link manager
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Copyright (C) 2004 - 2005 Colin Walters <walters@redhat.com>
+ * Copyright (C) 2004 - 2010 Red Hat, Inc.
+ * Copyright (C) 2005 - 2008 Novell, Inc.
+ *   and others
+ */
+
+#include "config.h"
+
+#include <limits.h>
+#include <stdio.h>
+#include <string.h>
+#include <stdlib.h>
+#include <errno.h>
+#include <arpa/inet.h>
+#include <sys/types.h>
+#include <sys/wait.h> 
+#include <unistd.h>
+#include <glib.h>
+
+#include <glib/gi18n.h>
+
+#include "nm-dns-manager.h"
+#include "nm-ip4-config.h"
+#include "nm-ip6-config.h"
+#include "nm-logging.h"
+#include "nm-system.h"
+#include "NetworkManagerUtils.h"
+
+#include "nm-dns-plugin.h"
+#include "nm-dns-dnsmasq.h"
+#include "nm-dns-bind.h"
+
+#ifdef HAVE_SELINUX
+#include <selinux/selinux.h>
+#endif
+
+#ifndef RESOLV_CONF
+#define RESOLV_CONF "/etc/resolv.conf"
+#endif
+
+G_DEFINE_TYPE(NMDnsManager, nm_dns_manager, G_TYPE_OBJECT)
+
+#define NM_DNS_MANAGER_GET_PRIVATE(o) (G_TYPE_INSTANCE_GET_PRIVATE ((o), \
+                                       NM_TYPE_DNS_MANAGER, \
+                                       NMDnsManagerPrivate))
+
+struct NMDnsManagerPrivate {
+	NMIP4Config *ip4_vpn_config;
+	NMIP4Config *ip4_device_config;
+	NMIP6Config *ip6_vpn_config;
+	NMIP6Config *ip6_device_config;
+	GSList *configs;
+	char *hostname;
+
+	/* poor man's hash; we assume that the IP4 config object won't change
+	 * after it's given to us, which is (at this time) a fair assumption. So
+	 * we track the order of the currently applied IP configs and if they
+	 * haven't changed we don't need to rewrite resolv.conf.
+	 */
+	#define HLEN 6
+	gpointer hash[HLEN];
+
+	GSList *plugins;
+
+	/* This is a hack because SUSE's netconfig always wants changes
+	 * associated with a network interface, but sometimes a change isn't
+	 * associated with a network interface (like hostnames).
+	 */
+	char *last_iface;
+};
+
+
+typedef struct {
+	GPtrArray *nameservers;
+	const char *domain;
+	GPtrArray *searches;
+	const char *nis_domain;
+	GPtrArray *nis_servers;
+} NMResolvConfData;
+
+static void
+add_string_item (GPtrArray *array, const char *str)
+{
+	int i;
+
+	g_return_if_fail (array != NULL);
+	g_return_if_fail (str != NULL);
+
+	/* Check for dupes before adding */
+	for (i = 0; i < array->len; i++) {
+		const char *candidate = g_ptr_array_index (array, i);
+
+		if (candidate && !strcmp (candidate, str))
+			return;
+	}
+
+	/* No dupes, add the new item */
+	g_ptr_array_add (array, g_strdup (str));
+}
+
+static void
+merge_one_ip4_config (NMResolvConfData *rc, NMIP4Config *src)
+{
+	guint32 num, i;
+
+	num = nm_ip4_config_get_num_nameservers (src);
+	for (i = 0; i < num; i++) {
+		struct in_addr addr;
+		char buf[INET_ADDRSTRLEN];
+
+		addr.s_addr = nm_ip4_config_get_nameserver (src, i);
+		if (inet_ntop (AF_INET, &addr, buf, INET_ADDRSTRLEN) > 0)
+			add_string_item (rc->nameservers, buf);
+	}
+
+	num = nm_ip4_config_get_num_domains (src);
+	for (i = 0; i < num; i++) {
+		const char *domain;
+
+		domain = nm_ip4_config_get_domain (src, i);
+		if (!rc->domain)
+			rc->domain = domain;
+		add_string_item (rc->searches, domain);
+	}
+
+	num = nm_ip4_config_get_num_searches (src);
+	for (i = 0; i < num; i++)
+		add_string_item (rc->searches, nm_ip4_config_get_search (src, i));
+
+	/* NIS stuff */
+	num = nm_ip4_config_get_num_nis_servers (src);
+	for (i = 0; i < num; i++) {
+		struct in_addr addr;
+		char buf[INET_ADDRSTRLEN];
+
+		addr.s_addr = nm_ip4_config_get_nis_server (src, i);
+		if (inet_ntop (AF_INET, &addr, buf, INET_ADDRSTRLEN) > 0)
+			add_string_item (rc->nis_servers, buf);
+	}
+
+	if (nm_ip4_config_get_nis_domain (src)) {
+		/* FIXME: handle multiple domains */
+		if (!rc->nis_domain)
+			rc->nis_domain = nm_ip4_config_get_nis_domain (src);
+	}
+}
+
+static void
+merge_one_ip6_config (NMResolvConfData *rc, NMIP6Config *src)
+{
+	guint32 num, i;
+
+	num = nm_ip6_config_get_num_nameservers (src);
+	for (i = 0; i < num; i++) {
+		const struct in6_addr *addr;
+		char buf[INET6_ADDRSTRLEN];
+
+		addr = nm_ip6_config_get_nameserver (src, i);
+
+		/* inet_ntop is probably supposed to do this for us, but it doesn't */
+		if (IN6_IS_ADDR_V4MAPPED (addr)) {
+			if (inet_ntop (AF_INET, &(addr->s6_addr32[3]), buf, INET_ADDRSTRLEN) > 0)
+				add_string_item (rc->nameservers, buf);
+		} else {
+			if (inet_ntop (AF_INET6, addr, buf, INET6_ADDRSTRLEN) > 0)
+				add_string_item (rc->nameservers, buf);
+		}
+	}
+
+	num = nm_ip6_config_get_num_domains (src);
+	for (i = 0; i < num; i++) {
+		const char *domain;
+
+		domain = nm_ip6_config_get_domain (src, i);
+		if (!rc->domain)
+			rc->domain = domain;
+		add_string_item (rc->searches, domain);
+	}
+
+	num = nm_ip6_config_get_num_searches (src);
+	for (i = 0; i < num; i++)
+		add_string_item (rc->searches, nm_ip6_config_get_search (src, i));
+}
+
+
+#if defined(TARGET_SUSE)
+/**********************************/
+/* SUSE */
+
+static void
+netconfig_child_setup (gpointer user_data G_GNUC_UNUSED)
+{
+	pid_t pid = getpid ();
+	setpgid (pid, pid);
+}
+
+static GPid
+run_netconfig (GError **error, gint *stdin_fd)
+{
+	char *argv[5];
+	char *tmp;
+	GPid pid = -1;
+
+	argv[0] = "/sbin/netconfig";
+	argv[1] = "modify";
+	argv[2] = "--service";
+	argv[3] = "NetworkManager";
+	argv[4] = NULL;
+
+	tmp = g_strjoinv (" ", argv);
+	nm_log_dbg (LOGD_DNS, "spawning '%s'", tmp);
+	g_free (tmp);
+
+	if (!g_spawn_async_with_pipes (NULL, argv, NULL, 0, netconfig_child_setup,
+	                               NULL, &pid, stdin_fd, NULL, NULL, error))
+		return -1;
+
+	return pid;
+}
+
+static void
+write_to_netconfig (gint fd, const char *key, const char *value)
+{
+	char *str;
+	int x;
+
+	str = g_strdup_printf ("%s='%s'\n", key, value);
+	nm_log_dbg (LOGD_DNS, "writing to netconfig: %s", str);
+	x = write (fd, str, strlen (str));
+	g_free (str);
+}
+
+static gboolean
+dispatch_netconfig (const char *domain,
+                    char **searches,
+                    char **nameservers,
+                    const char *nis_domain,
+                    char **nis_servers,
+                    const char *iface,
+                    GError **error)
+{
+	char *str, *tmp;
+	GPid pid;
+	gint fd;
+	int ret;
+
+	pid = run_netconfig (error, &fd);
+	if (pid < 0)
+		return FALSE;
+
+	// FIXME: this is wrong. We are not writing out the iface-specific
+	// resolv.conf data, we are writing out an already-fully-merged
+	// resolv.conf. Assuming netconfig works in the obvious way, then
+	// there are various failure modes, such as, eg, bringing up a VPN on
+	// eth0, then bringing up wlan0, then bringing down the VPN. Because
+	// NMDnsManager would have claimed that the VPN DNS server was also
+	// part of the wlan0 config, it will remain in resolv.conf after the
+	// VPN goes down, even though it is presumably no longer reachable
+	// at that point.
+	write_to_netconfig (fd, "INTERFACE", iface);
+
+	if (searches) {
+		str = g_strjoinv (" ", searches);
+
+		if (domain) {
+			tmp = g_strconcat (domain, " ", str, NULL);
+			g_free (str);
+			str = tmp;
+		}
+
+		write_to_netconfig (fd, "DNSSEARCH", str);
+		g_free (str);
+	}
+
+	if (nameservers) {
+		str = g_strjoinv (" ", nameservers);
+		write_to_netconfig (fd, "DNSSERVERS", str);
+		g_free (str);
+	}
+
+	if (nis_domain)
+		write_to_netconfig (fd, "NISDOMAIN", nis_domain);
+
+	if (nis_servers) {
+		str = g_strjoinv (" ", nis_servers);
+		write_to_netconfig (fd, "NISSERVERS", str);
+		g_free (str);
+	}
+
+	close (fd);
+
+	/* Wait until the process exits */
+
+ again:
+
+	ret = waitpid (pid, NULL, 0);
+	if (ret < 0 && errno == EINTR)
+		goto again;
+	else if (ret < 0 && errno == ECHILD) {
+		/* When the netconfig exist, the errno is ECHILD, it should return TRUE */
+		return TRUE;
+	}
+
+	return ret > 0;
+}
+#endif
+
+
+static gboolean
+write_resolv_conf (FILE *f, const char *domain,
+                   char **searches,
+                   char **nameservers,
+                   GError **error)
+{
+	char *domain_str = NULL;
+	char *searches_str = NULL;
+	char *nameservers_str = NULL;
+	int i;
+	gboolean retval = FALSE;
+	GString *str;
+
+	if (fprintf (f, "%s","# Generated by NetworkManager\n") < 0) {
+		g_set_error (error,
+		             NM_DNS_MANAGER_ERROR,
+		             NM_DNS_MANAGER_ERROR_SYSTEM,
+		             "Could not write " RESOLV_CONF ": %s\n",
+		             g_strerror (errno));
+		return FALSE;
+	}
+
+	if (domain)
+		domain_str = g_strconcat ("domain ", domain, "\n", NULL);
+
+	if (searches) {
+		char *tmp_str;
+
+		tmp_str = g_strjoinv (" ", searches);
+		searches_str = g_strconcat ("search ", tmp_str, "\n", NULL);
+		g_free (tmp_str);
+	}
+
+	str = g_string_new ("");
+
+	if (nameservers) {
+		int num = g_strv_length (nameservers);
+
+		for (i = 0; i < num; i++) {
+			if (i == 3) {
+				g_string_append (str, "# ");
+				g_string_append (str, _("NOTE: the libc resolver may not support more than 3 nameservers."));
+				g_string_append (str, "\n# ");
+				g_string_append (str, _("The nameservers listed below may not be recognized."));
+				g_string_append_c (str, '\n');
+			}
+
+			g_string_append (str, "nameserver ");
+			g_string_append (str, nameservers[i]);
+			g_string_append_c (str, '\n');
+		}
+	}
+
+	nameservers_str = g_string_free (str, FALSE);
+
+	if (fprintf (f, "%s%s%s",
+	             domain_str ? domain_str : "",
+	             searches_str ? searches_str : "",
+	             strlen (nameservers_str) ? nameservers_str : "") != -1)
+		retval = TRUE;
+
+	g_free (domain_str);
+	g_free (searches_str);
+	g_free (nameservers_str);
+
+	return retval;
+}
+
+#ifdef RESOLVCONF_PATH
+static gboolean
+dispatch_resolvconf (const char *domain,
+                     char **searches,
+                     char **nameservers,
+                     const char *iface,
+                     GError **error)
+{
+	char *cmd;
+	FILE *f;
+	gboolean retval = FALSE;
+
+	if (! g_file_test (RESOLVCONF_PATH, G_FILE_TEST_IS_EXECUTABLE))
+		return FALSE;
+
+	if (domain || searches || nameservers) {
+		cmd = g_strconcat (RESOLVCONF_PATH, " -a ", "NetworkManager", NULL);
+		nm_log_info (LOGD_DNS, "(%s): writing resolv.conf to %s", iface, RESOLVCONF_PATH);
+		if ((f = popen (cmd, "w")) == NULL)
+			g_set_error (error,
+			             NM_DNS_MANAGER_ERROR,
+			             NM_DNS_MANAGER_ERROR_SYSTEM,
+			             "Could not write to %s: %s\n",
+			             RESOLVCONF_PATH,
+			             g_strerror (errno));
+		else {
+			retval = write_resolv_conf (f, domain, searches, nameservers, error);
+			retval &= (pclose (f) == 0);
+		}
+	} else {
+		cmd = g_strconcat (RESOLVCONF_PATH, " -d ", "NetworkManager", NULL);
+		nm_log_info (LOGD_DNS, "(%s): removing resolv.conf from %s", iface, RESOLVCONF_PATH);
+		if (nm_spawn_process (cmd) == 0)
+			retval = TRUE;
+	}
+
+	g_free (cmd);
+
+	return retval;
+}
+#endif
+
+static gboolean
+update_resolv_conf (const char *domain,
+                    char **searches,
+                    char **nameservers,
+                    const char *iface,
+                    GError **error)
+{
+	char *tmp_resolv_conf;
+	char *tmp_resolv_conf_realpath;
+	char *resolv_conf_realpath;
+	FILE *f;
+	int do_rename = 1;
+	int old_errno = 0;
+
+	g_return_val_if_fail (error != NULL, FALSE);
+
+	/* Find the real path of resolv.conf; it could be a symlink to something */
+	resolv_conf_realpath = realpath (RESOLV_CONF, NULL);
+	if (!resolv_conf_realpath)
+		resolv_conf_realpath = strdup (RESOLV_CONF);
+
+	/* Build up the real path for the temp resolv.conf that we're about to
+	 * write out.
+	 */
+	tmp_resolv_conf = g_strdup_printf ("%s.tmp", resolv_conf_realpath);
+	tmp_resolv_conf_realpath = realpath (tmp_resolv_conf, NULL);
+	if (!tmp_resolv_conf_realpath)
+		tmp_resolv_conf_realpath = strdup (tmp_resolv_conf);
+	g_free (tmp_resolv_conf);
+	tmp_resolv_conf = NULL;
+
+	if ((f = fopen (tmp_resolv_conf_realpath, "w")) == NULL) {
+		do_rename = 0;
+		old_errno = errno;
+		if ((f = fopen (RESOLV_CONF, "w")) == NULL) {
+			g_set_error (error,
+			             NM_DNS_MANAGER_ERROR,
+			             NM_DNS_MANAGER_ERROR_SYSTEM,
+			             "Could not open %s: %s\nCould not open %s: %s\n",
+			             tmp_resolv_conf_realpath,
+			             g_strerror (old_errno),
+			             RESOLV_CONF,
+			             g_strerror (errno));
+			goto out;
+		}
+		/* Update tmp_resolv_conf_realpath so the error message on fclose()
+		 * failure will be correct.
+		 */
+		strcpy (tmp_resolv_conf_realpath, RESOLV_CONF);
+	}
+
+	write_resolv_conf (f, domain, searches, nameservers, error);
+
+	if (fclose (f) < 0) {
+		if (*error == NULL) {
+			/* only set an error here if write_resolv_conf() was successful,
+			 * since its error is more important.
+			 */
+			g_set_error (error,
+			             NM_DNS_MANAGER_ERROR,
+			             NM_DNS_MANAGER_ERROR_SYSTEM,
+			             "Could not close %s: %s\n",
+			             tmp_resolv_conf_realpath,
+			             g_strerror (errno));
+		}
+	}
+
+	/* Don't rename the tempfile over top of the existing resolv.conf if there
+	 * was an error writing it out.
+	 */
+	if (*error == NULL && do_rename) {
+		if (rename (tmp_resolv_conf_realpath, resolv_conf_realpath) < 0) {
+			g_set_error (error,
+			             NM_DNS_MANAGER_ERROR,
+			             NM_DNS_MANAGER_ERROR_SYSTEM,
+			             "Could not replace " RESOLV_CONF ": %s\n",
+			             g_strerror (errno));
+		}
+	}
+
+out:
+	free (tmp_resolv_conf_realpath);
+	free (resolv_conf_realpath);
+	return *error ? FALSE : TRUE;
+}
+
+static void
+compute_hash (NMDnsManager *self, gpointer *hash)
+{
+	NMDnsManagerPrivate *priv = NM_DNS_MANAGER_GET_PRIVATE (self);
+	gpointer check[HLEN];
+	GSList *iter;
+	int i = 0;
+
+	memset (check, 0, sizeof (check));
+
+	if (priv->ip4_vpn_config)
+		check[i++] = priv->ip4_vpn_config;
+	if (priv->ip4_device_config)
+		check[i++] = priv->ip4_device_config;
+
+	if (priv->ip6_vpn_config)
+		check[i++] = priv->ip6_vpn_config;
+	if (priv->ip6_device_config)
+		check[i++] = priv->ip6_device_config;
+
+	/* Add two more "other" configs if any exist */
+	for (iter = priv->configs; iter && i < HLEN; iter = g_slist_next (iter)) {
+		if (   (iter->data != priv->ip4_vpn_config)
+		    && (iter->data != priv->ip4_device_config)
+		    && (iter->data != priv->ip6_vpn_config)
+		    && (iter->data != priv->ip6_device_config))
+			check[i++] = iter->data;
+	}
+	memcpy (hash, check, sizeof (check));
+}
+
+static gboolean
+update_dns (NMDnsManager *self,
+            const char *iface,
+            gboolean no_caching,
+            GError **error)
+{
+	NMDnsManagerPrivate *priv;
+	NMResolvConfData rc;
+	GSList *iter, *vpn_configs = NULL, *dev_configs = NULL, *other_configs = NULL;
+	const char *domain = NULL;
+	const char *nis_domain = NULL;
+	char **searches = NULL;
+	char **nameservers = NULL;
+	char **nis_servers = NULL;
+	int num, i, len;
+	gboolean success = FALSE, caching = FALSE;
+
+	g_return_val_if_fail (error != NULL, FALSE);
+	g_return_val_if_fail (*error == NULL, FALSE);
+
+	priv = NM_DNS_MANAGER_GET_PRIVATE (self);
+
+	if (iface && (iface != priv->last_iface)) {
+		g_free (priv->last_iface);
+		priv->last_iface = g_strdup (iface);
+	}
+
+	/* Update hash with config we're applying */
+	compute_hash (self, priv->hash);
+
+	rc.nameservers = g_ptr_array_new ();
+	rc.domain = NULL;
+	rc.searches = g_ptr_array_new ();
+	rc.nis_servers = g_ptr_array_new ();
+
+	if (priv->ip4_vpn_config)
+		merge_one_ip4_config (&rc, priv->ip4_vpn_config);
+	if (priv->ip4_device_config)
+		merge_one_ip4_config (&rc, priv->ip4_device_config);
+
+	if (priv->ip6_vpn_config)
+		merge_one_ip6_config (&rc, priv->ip6_vpn_config);
+	if (priv->ip6_device_config)
+		merge_one_ip6_config (&rc, priv->ip6_device_config);
+
+	for (iter = priv->configs; iter; iter = g_slist_next (iter)) {
+		if (   (iter->data == priv->ip4_vpn_config)
+		    || (iter->data == priv->ip4_device_config)
+		    || (iter->data == priv->ip6_vpn_config)
+		    || (iter->data == priv->ip6_device_config))
+			continue;
+
+		if (NM_IS_IP4_CONFIG (iter->data)) {
+			NMIP4Config *config = NM_IP4_CONFIG (iter->data);
+
+			merge_one_ip4_config (&rc, config);
+		} else if (NM_IS_IP6_CONFIG (iter->data)) {
+			NMIP6Config *config = NM_IP6_CONFIG (iter->data);
+
+			merge_one_ip6_config (&rc, config);
+		} else
+			g_assert_not_reached ();
+	}
+
+	/* Add the current domain name (from the hostname) to the searches list;
+	 * see rh #600407.  The bug report is that when the hostname is set to
+	 * something like 'dcbw.foobar.com' (ie an FQDN) that pinging 'dcbw' doesn't
+	 * work because the resolver doesn't have anything to append to 'dcbw' when
+	 * looking it up.
+	 */
+	if (priv->hostname) {
+		const char *hostsearch = strchr (priv->hostname, '.');
+
+		/* +1 to get rid of the dot */
+		if (hostsearch && strlen (hostsearch + 1))
+			add_string_item (rc.searches, hostsearch + 1);
+	}
+
+	domain = rc.domain;
+
+	/* Per 'man resolv.conf', the search list is limited to 6 domains
+	 * totalling 256 characters.
+	 */
+	num = MIN (rc.searches->len, 6);
+	for (i = 0, len = 0; i < num; i++) {
+		len += strlen (rc.searches->pdata[i]) + 1; /* +1 for spaces */
+		if (len > 256)
+			break;
+	}
+	g_ptr_array_set_size (rc.searches, i);
+	if (rc.searches->len) {
+		g_ptr_array_add (rc.searches, NULL);
+		searches = (char **) g_ptr_array_free (rc.searches, FALSE);
+	} else
+		g_ptr_array_free (rc.searches, TRUE);
+
+	if (rc.nameservers->len) {
+		g_ptr_array_add (rc.nameservers, NULL);
+		nameservers = (char **) g_ptr_array_free (rc.nameservers, FALSE);
+	} else
+		g_ptr_array_free (rc.nameservers, TRUE);
+
+	if (rc.nis_servers->len) {
+		g_ptr_array_add (rc.nis_servers, NULL);
+		nis_servers = (char **) g_ptr_array_free (rc.nis_servers, FALSE);
+	} else
+		g_ptr_array_free (rc.nis_servers, TRUE);
+
+	nis_domain = rc.nis_domain;
+
+	/* Build up config lists for plugins; we use the raw configs here, not the
+	 * merged information that we write to resolv.conf so that the plugins can
+	 * still use the domain information in each config to provide split DNS if
+	 * they want to.
+	 */
+	if (priv->ip4_vpn_config)
+		vpn_configs = g_slist_append (vpn_configs, priv->ip4_vpn_config);
+	if (priv->ip6_vpn_config)
+		vpn_configs = g_slist_append (vpn_configs, priv->ip6_vpn_config);
+	if (priv->ip4_device_config)
+		dev_configs = g_slist_append (dev_configs, priv->ip4_device_config);
+	if (priv->ip6_device_config)
+		dev_configs = g_slist_append (dev_configs, priv->ip6_device_config);
+
+	for (iter = priv->configs; iter; iter = g_slist_next (iter)) {
+		if (   (iter->data != priv->ip4_vpn_config)
+		    && (iter->data != priv->ip4_device_config)
+		    && (iter->data != priv->ip6_vpn_config)
+		    && (iter->data != priv->ip6_device_config))
+			other_configs = g_slist_append (other_configs, iter->data);
+	}
+
+	/* Let any plugins do their thing first */
+	for (iter = priv->plugins; iter; iter = g_slist_next (iter)) {
+		NMDnsPlugin *plugin = NM_DNS_PLUGIN (iter->data);
+		const char *plugin_name = nm_dns_plugin_get_name (plugin);
+
+		if (nm_dns_plugin_is_caching (plugin)) {
+			if (no_caching) {
+				nm_log_dbg (LOGD_DNS, "DNS: plugin %s ignored (caching disabled)",
+				            plugin_name);
+				continue;
+			}
+			caching = TRUE;
+		}
+
+		nm_log_dbg (LOGD_DNS, "DNS: updating plugin %s", plugin_name);
+		if (!nm_dns_plugin_update (plugin,
+		                           vpn_configs,
+		                           dev_configs,
+		                           other_configs,
+		                           priv->hostname)) {
+			nm_log_warn (LOGD_DNS, "DNS: plugin %s update failed", plugin_name);
+
+			/* If the plugin failed to update, we shouldn't write out a local
+			 * caching DNS configuration to resolv.conf.
+			 */
+			caching = FALSE;
+		}
+	}
+	g_slist_free (vpn_configs);
+	g_slist_free (dev_configs);
+	g_slist_free (other_configs);
+
+	/* If caching was successful, we only send 127.0.0.1 to /etc/resolv.conf
+	 * to ensure that the glibc resolver doesn't try to round-robin nameservers,
+	 * but only uses the local caching nameserver.
+	 */
+	if (caching) {
+		if (nameservers)
+			g_strfreev (nameservers);
+		nameservers = g_new0 (char*, 2);
+		nameservers[0] = g_strdup ("127.0.0.1");
+	}
+
+#ifdef RESOLVCONF_PATH
+	success = dispatch_resolvconf (domain, searches, nameservers, iface, error);
+#endif
+
+#ifdef TARGET_SUSE
+	if (success == FALSE) {
+		success = dispatch_netconfig (domain, searches, nameservers,
+		                              nis_domain, nis_servers,
+		                              iface, error);
+	}
+#endif
+
+	if (success == FALSE)
+		success = update_resolv_conf (domain, searches, nameservers, iface, error);
+
+	if (success)
+		nm_system_update_dns ();
+
+	if (searches)
+		g_strfreev (searches);
+	if (nameservers)
+		g_strfreev (nameservers);
+	if (nis_servers)
+		g_strfreev (nis_servers);
+
+	return success;
+}
+
+static void
+plugin_failed (NMDnsPlugin *plugin, gpointer user_data)
+{
+	NMDnsManager *self = NM_DNS_MANAGER (user_data);
+	NMDnsManagerPrivate *priv = NM_DNS_MANAGER_GET_PRIVATE (self);
+	GError *error = NULL;
+
+	/* Errors with non-caching plugins aren't fatal */
+	if (!nm_dns_plugin_is_caching (plugin))
+		return;
+
+	/* Disable caching until the next DNS update */
+	if (!update_dns (self, priv->last_iface, TRUE, &error)) {
+		nm_log_warn (LOGD_DNS, "could not commit DNS changes: (%d) %s",
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+	}
+}
+
+static gboolean
+config_changed (NMDnsManager *self)
+{
+	NMDnsManagerPrivate *priv = NM_DNS_MANAGER_GET_PRIVATE (self);
+	gpointer check[HLEN];
+
+	/* We only store HLEN configs; so if there are actually more than that,
+	 * we have to assume that the config has changed.
+	 */
+	if (g_slist_length (priv->configs) > HLEN)
+		return TRUE;
+
+	/* Otherwise return TRUE if the configuration has changed */
+	compute_hash (self, check);
+	return memcmp (check, priv->hash, sizeof (check)) ? TRUE : FALSE;
+}
+
+gboolean
+nm_dns_manager_add_ip4_config (NMDnsManager *mgr,
+                               const char *iface,
+                               NMIP4Config *config,
+                               NMDnsIPConfigType cfg_type)
+{
+	NMDnsManagerPrivate *priv;
+	GError *error = NULL;
+
+	g_return_val_if_fail (mgr != NULL, FALSE);
+	g_return_val_if_fail (iface != NULL, FALSE);
+	g_return_val_if_fail (config != NULL, FALSE);
+
+	priv = NM_DNS_MANAGER_GET_PRIVATE (mgr);
+
+	switch (cfg_type) {
+	case NM_DNS_IP_CONFIG_TYPE_VPN:
+		priv->ip4_vpn_config = config;
+		break;
+	case NM_DNS_IP_CONFIG_TYPE_BEST_DEVICE:
+		priv->ip4_device_config = config;
+		break;
+	default:
+		break;
+	}
+
+	/* Don't allow the same zone added twice */
+	if (!g_slist_find (priv->configs, config))
+		priv->configs = g_slist_append (priv->configs, g_object_ref (config));
+
+	if (!config_changed (mgr))
+		return TRUE;
+
+	if (!update_dns (mgr, iface, FALSE, &error)) {
+		nm_log_warn (LOGD_DNS, "could not commit DNS changes: (%d) %s",
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+	}
+
+	return TRUE;
+}
+
+gboolean
+nm_dns_manager_remove_ip4_config (NMDnsManager *mgr,
+                                  const char *iface,
+                                  NMIP4Config *config)
+{
+	NMDnsManagerPrivate *priv;
+	GError *error = NULL;
+
+	g_return_val_if_fail (mgr != NULL, FALSE);
+	g_return_val_if_fail (iface != NULL, FALSE);
+	g_return_val_if_fail (config != NULL, FALSE);
+
+	priv = NM_DNS_MANAGER_GET_PRIVATE (mgr);
+
+	/* Can't remove it if it wasn't in the list to begin with */
+	if (!g_slist_find (priv->configs, config))
+		return FALSE;
+
+	priv->configs = g_slist_remove (priv->configs, config);
+
+	if (config == priv->ip4_vpn_config)
+		priv->ip4_vpn_config = NULL;
+	if (config == priv->ip4_device_config)
+		priv->ip4_device_config = NULL;
+
+	g_object_unref (config);
+
+	if (config_changed (mgr))
+		return TRUE;
+
+	if (!update_dns (mgr, iface, FALSE, &error)) {
+		nm_log_warn (LOGD_DNS, "could not commit DNS changes: (%d) %s",
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+	}
+
+	return TRUE;
+}
+
+gboolean
+nm_dns_manager_add_ip6_config (NMDnsManager *mgr,
+                               const char *iface,
+                               NMIP6Config *config,
+                               NMDnsIPConfigType cfg_type)
+{
+	NMDnsManagerPrivate *priv;
+	GError *error = NULL;
+
+	g_return_val_if_fail (mgr != NULL, FALSE);
+	g_return_val_if_fail (iface != NULL, FALSE);
+	g_return_val_if_fail (config != NULL, FALSE);
+
+	priv = NM_DNS_MANAGER_GET_PRIVATE (mgr);
+
+	switch (cfg_type) {
+	case NM_DNS_IP_CONFIG_TYPE_VPN:
+		/* FIXME: not quite yet... */
+		g_return_val_if_fail (cfg_type != NM_DNS_IP_CONFIG_TYPE_VPN, FALSE);
+		priv->ip6_vpn_config = config;
+		break;
+	case NM_DNS_IP_CONFIG_TYPE_BEST_DEVICE:
+		priv->ip6_device_config = config;
+		break;
+	default:
+		break;
+	}
+
+	/* Don't allow the same zone added twice */
+	if (!g_slist_find (priv->configs, config))
+		priv->configs = g_slist_append (priv->configs, g_object_ref (config));
+
+	if (config_changed (mgr))
+		return TRUE;
+
+	if (!update_dns (mgr, iface, FALSE, &error)) {
+		nm_log_warn (LOGD_DNS, "could not commit DNS changes: (%d) %s",
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+	}
+
+	return TRUE;
+}
+
+gboolean
+nm_dns_manager_remove_ip6_config (NMDnsManager *mgr,
+                                  const char *iface,
+                                  NMIP6Config *config)
+{
+	NMDnsManagerPrivate *priv;
+	GError *error = NULL;
+
+	g_return_val_if_fail (mgr != NULL, FALSE);
+	g_return_val_if_fail (iface != NULL, FALSE);
+	g_return_val_if_fail (config != NULL, FALSE);
+
+	priv = NM_DNS_MANAGER_GET_PRIVATE (mgr);
+
+	/* Can't remove it if it wasn't in the list to begin with */
+	if (!g_slist_find (priv->configs, config))
+		return FALSE;
+
+	priv->configs = g_slist_remove (priv->configs, config);
+
+	if (config == priv->ip6_vpn_config)
+		priv->ip6_vpn_config = NULL;
+	if (config == priv->ip6_device_config)
+		priv->ip6_device_config = NULL;
+
+	g_object_unref (config);	
+
+	if (config_changed (mgr))
+		return TRUE;
+
+	if (!update_dns (mgr, iface, FALSE, &error)) {
+		nm_log_warn (LOGD_DNS, "could not commit DNS changes: (%d) %s",
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+	}
+
+	return TRUE;
+}
+
+void
+nm_dns_manager_set_hostname (NMDnsManager *mgr,
+                               const char *hostname)
+{
+	NMDnsManagerPrivate *priv = NM_DNS_MANAGER_GET_PRIVATE (mgr);
+	GError *error = NULL;
+	const char *filtered = NULL;
+
+	/* Certain hostnames we don't want to include in resolv.conf 'searches' */
+	if (   hostname
+	    && strcmp (hostname, "localhost.localdomain")
+	    && strcmp (hostname, "localhost6.localdomain6")
+	    && !strstr (hostname, ".in-addr.arpa")
+	    && strchr (hostname, '.')) {
+		filtered = hostname;
+	}
+
+	if (   (!priv->hostname && !filtered)
+	    || (priv->hostname && filtered && !strcmp (priv->hostname, filtered)))
+		return;
+
+	g_free (priv->hostname);
+	priv->hostname = g_strdup (filtered);
+
+	/* Passing the last interface here is completely bogus, but SUSE's netconfig
+	 * wants one.  But hostname changes are system-wide and *not* tied to a
+	 * specific interface, so netconfig can't really handle this.  Fake it.
+	 */
+	if (!update_dns (mgr, priv->last_iface, FALSE, &error)) {
+		nm_log_warn (LOGD_DNS, "could not commit DNS changes: (%d) %s",
+		             error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+	}
+}
+
+static void
+load_plugins (NMDnsManager *self, const char **plugins)
+{
+	NMDnsManagerPrivate *priv = NM_DNS_MANAGER_GET_PRIVATE (self);
+	NMDnsPlugin *plugin;
+	const char **iter;
+	gboolean have_caching = FALSE;
+
+	if (plugins && *plugins) {
+		/* Create each configured plugin */
+		for (iter = plugins; iter && *iter; iter++) {
+			if (!strcasecmp (*iter, "dnsmasq"))
+				plugin = NM_DNS_PLUGIN (nm_dns_dnsmasq_new ());
+			else if (!strcasecmp (*iter, "bind")) {
+				plugin = NM_DNS_PLUGIN (nm_dns_bind_new ());
+				nm_log_warn (LOGD_DNS, "The BIND plugin is experimental!");
+			} else {
+				nm_log_warn (LOGD_DNS, "Unknown DNS plugin '%s'", *iter);\
+				continue;
+			}
+			g_assert (plugin);
+
+			/* Only one caching DNS plugin is allowed */
+			if (nm_dns_plugin_is_caching (plugin)) {
+				if (have_caching) {
+					nm_log_warn (LOGD_DNS,
+					             "Ignoring plugin %s; only one caching DNS "
+					             "plugin is allowed.",
+					             *iter);
+					g_object_unref (plugin);
+					continue;
+				}
+				have_caching = TRUE;
+			}
+
+			nm_log_info (LOGD_DNS, "DNS: loaded plugin %s", nm_dns_plugin_get_name (plugin));
+			priv->plugins = g_slist_append (priv->plugins, plugin);
+			g_signal_connect (plugin, NM_DNS_PLUGIN_FAILED,
+			                  G_CALLBACK (plugin_failed),
+			                  self);
+		}
+	} else {
+		/* Create default plugins */
+	}
+}
+
+/******************************************************************/
+
+NMDnsManager *
+nm_dns_manager_get (const char **plugins)
+{
+	static NMDnsManager * singleton = NULL;
+
+	if (!singleton) {
+		singleton = NM_DNS_MANAGER (g_object_new (NM_TYPE_DNS_MANAGER, NULL));
+		g_assert (singleton);
+		load_plugins (singleton, plugins);
+	} else
+		g_object_ref (singleton);
+
+	return singleton;
+}
+
+GQuark
+nm_dns_manager_error_quark (void)
+{
+	static GQuark quark = 0;
+	if (!quark)
+		quark = g_quark_from_static_string ("nm_dns_manager_error");
+
+	return quark;
+}
+
+static void
+nm_dns_manager_init (NMDnsManager *mgr)
+{
+}
+
+static void
+nm_dns_manager_finalize (GObject *object)
+{
+	NMDnsManagerPrivate *priv = NM_DNS_MANAGER_GET_PRIVATE (object);
+
+	g_slist_foreach (priv->configs, (GFunc) g_object_unref, NULL);
+	g_slist_free (priv->configs);
+	g_free (priv->hostname);
+	g_free (priv->last_iface);
+
+	g_slist_foreach (priv->plugins, (GFunc) g_object_unref, NULL);
+	g_slist_free (priv->plugins);
+
+	G_OBJECT_CLASS (nm_dns_manager_parent_class)->finalize (object);
+}
+
+static void
+nm_dns_manager_class_init (NMDnsManagerClass *klass)
+{
+	GObjectClass *object_class = G_OBJECT_CLASS (klass);
+
+	object_class->finalize = nm_dns_manager_finalize;
+
+	g_type_class_add_private (object_class, sizeof (NMDnsManagerPrivate));
+}
+
diff --git a/src/dns-manager/nm-dns-manager.h b/src/dns-manager/nm-dns-manager.h
new file mode 100644
index 00000000..eb1c73a7
--- /dev/null
+++ b/src/dns-manager/nm-dns-manager.h
@@ -0,0 +1,95 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/* NetworkManager -- Network link manager
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Copyright (C) 2004 - 2005 Colin Walters <walters@redhat.com>
+ * Copyright (C) 2004 - 2010 Red Hat, Inc.
+ * Copyright (C) 2005 - 2008 Novell, Inc.
+ *   and others
+ */
+
+#ifndef NM_DNS_MANAGER_H
+#define NM_DNS_MANAGER_H
+
+#include "config.h"
+#include <glib-object.h>
+#include <dbus/dbus.h>
+#include "nm-ip4-config.h"
+#include "nm-ip6-config.h"
+
+typedef enum {
+	NM_DNS_MANAGER_ERROR_SYSTEM,
+	NM_DNS_MANAGER_ERROR_INVALID_NAMESERVER,
+	NM_DNS_MANAGER_ERROR_INVALID_HOST,
+	NM_DNS_MANAGER_ERROR_INVALID_ID
+} NMDnsManagerError;
+
+typedef enum {
+	NM_DNS_IP_CONFIG_TYPE_DEFAULT = 0,
+	NM_DNS_IP_CONFIG_TYPE_BEST_DEVICE,
+	NM_DNS_IP_CONFIG_TYPE_VPN
+} NMDnsIPConfigType;
+
+#define NM_DNS_MANAGER_ERROR nm_dns_manager_error_quark ()
+GQuark nm_dns_manager_error_quark (void);
+
+G_BEGIN_DECLS
+
+#define NM_TYPE_DNS_MANAGER (nm_dns_manager_get_type ())
+#define NM_DNS_MANAGER(o) (G_TYPE_CHECK_INSTANCE_CAST ((o), NM_TYPE_DNS_MANAGER, NMDnsManager))
+#define NM_DNS_MANAGER_CLASS(k) (G_TYPE_CHECK_CLASS_CAST((k), NM_TYPE_DNS_MANAGER, NMDnsManagerClass))
+#define NM_IS_DNS_MANAGER(o) (G_TYPE_CHECK_INSTANCE_TYPE ((o), NM_TYPE_DNS_MANAGER))
+#define NM_IS_DNS_MANAGER_CLASS(k) (G_TYPE_CHECK_CLASS_TYPE ((k), NM_TYPE_DNS_MANAGER))
+#define NM_DNS_MANAGER_GET_CLASS(o) (G_TYPE_INSTANCE_GET_CLASS ((o), NM_TYPE_DNS_MANAGER, NMDnsManagerClass)) 
+
+typedef struct NMDnsManagerPrivate NMDnsManagerPrivate;
+
+typedef struct {
+	GObject parent;
+} NMDnsManager;
+
+typedef struct {
+	GObjectClass parent;
+} NMDnsManagerClass;
+
+GType nm_dns_manager_get_type (void);
+
+NMDnsManager * nm_dns_manager_get (const char **plugins);
+
+gboolean nm_dns_manager_add_ip4_config (NMDnsManager *mgr,
+                                        const char *iface,
+                                        NMIP4Config *config,
+                                        NMDnsIPConfigType cfg_type);
+
+gboolean nm_dns_manager_remove_ip4_config (NMDnsManager *mgr,
+                                           const char *iface,
+                                           NMIP4Config *config);
+
+gboolean nm_dns_manager_add_ip6_config (NMDnsManager *mgr,
+                                        const char *iface,
+                                        NMIP6Config *config,
+                                        NMDnsIPConfigType cfg_type);
+
+gboolean nm_dns_manager_remove_ip6_config (NMDnsManager *mgr,
+                                           const char *iface,
+                                           NMIP6Config *config);
+
+void nm_dns_manager_set_hostname (NMDnsManager *mgr,
+                                  const char *hostname);
+
+G_END_DECLS
+
+#endif /* NM_DNS_MANAGER_H */
diff --git a/src/dns-manager/nm-dns-plugin.c b/src/dns-manager/nm-dns-plugin.c
new file mode 100644
index 00000000..f7d65a52
--- /dev/null
+++ b/src/dns-manager/nm-dns-plugin.c
@@ -0,0 +1,319 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/* This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2, or (at your option)
+ * any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Copyright (C) 2010 Red Hat, Inc.
+ *
+ */
+
+#include <config.h>
+#include <string.h>
+#include <stdlib.h>
+#include <unistd.h>
+#include <sys/types.h>
+#include <sys/wait.h>
+#include <glib.h>
+
+#include "nm-dns-plugin.h"
+#include "nm-logging.h"
+
+typedef struct {
+	gboolean disposed;
+
+	GPid pid;
+	guint32 watch_id;
+	char *progname;
+	char *pidfile;
+} NMDnsPluginPrivate;
+
+#define NM_DNS_PLUGIN_GET_PRIVATE(o) (G_TYPE_INSTANCE_GET_PRIVATE ((o), NM_TYPE_DNS_PLUGIN, NMDnsPluginPrivate))
+
+G_DEFINE_TYPE_EXTENDED (NMDnsPlugin, nm_dns_plugin, G_TYPE_OBJECT, G_TYPE_FLAG_ABSTRACT, {})
+
+enum {
+	FAILED,
+	CHILD_QUIT,
+	LAST_SIGNAL
+};
+static guint signals[LAST_SIGNAL] = { 0 };
+
+/********************************************/
+
+gboolean
+nm_dns_plugin_update (NMDnsPlugin *self,
+                      const GSList *vpn_configs,
+                      const GSList *dev_configs,
+                      const GSList *other_configs,
+                      const char *hostname)
+{
+	g_return_val_if_fail (NM_DNS_PLUGIN_GET_CLASS (self)->update != NULL, FALSE);
+
+	return NM_DNS_PLUGIN_GET_CLASS (self)->update (self,
+	                                               vpn_configs,
+	                                               dev_configs,
+	                                               other_configs,
+	                                               hostname);
+}
+
+static gboolean
+is_caching (NMDnsPlugin *self)
+{
+	return FALSE;
+}
+
+gboolean
+nm_dns_plugin_is_caching (NMDnsPlugin *self)
+{
+	return NM_DNS_PLUGIN_GET_CLASS (self)->is_caching (self);
+}
+
+const char *
+nm_dns_plugin_get_name (NMDnsPlugin *self)
+{
+	g_assert (NM_DNS_PLUGIN_GET_CLASS (self)->get_name);
+	return NM_DNS_PLUGIN_GET_CLASS (self)->get_name (self);
+}
+
+/********************************************/
+
+static void
+kill_existing (const char *progname, const char *pidfile, const char *kill_match)
+{
+	char *contents = NULL;
+	glong pid;
+	char *proc_path = NULL;
+	char *cmdline_contents = NULL;
+
+	if (!g_file_get_contents (pidfile, &contents, NULL, NULL))
+		return;
+
+	pid = strtol (contents, NULL, 10);
+	if (pid < 1 || pid > INT_MAX)
+		goto out;
+
+	proc_path = g_strdup_printf ("/proc/%ld/cmdline", pid);
+	if (!g_file_get_contents (proc_path, &cmdline_contents, NULL, NULL))
+		goto out;
+
+	if (strstr (cmdline_contents, kill_match)) {
+		if (kill (pid, 0) == 0) {
+			nm_log_dbg (LOGD_DNS, "Killing stale %s child process %ld", progname, pid);
+			kill (pid, SIGKILL);
+		}
+		unlink (pidfile);
+	}
+
+out:
+	g_free (cmdline_contents);
+	g_free (proc_path);
+	g_free (contents);
+}
+
+static void
+watch_cb (GPid pid, gint status, gpointer user_data)
+{
+	NMDnsPlugin *self = NM_DNS_PLUGIN (user_data);
+	NMDnsPluginPrivate *priv = NM_DNS_PLUGIN_GET_PRIVATE (self);
+
+	priv->pid = 0;
+	g_free (priv->progname);
+	priv->progname = NULL;
+
+	g_signal_emit (self, signals[CHILD_QUIT], 0, status);
+}
+
+static void
+child_setup (gpointer user_data G_GNUC_UNUSED)
+{
+	/* We are in the child process at this point */
+	pid_t pid = getpid ();
+	setpgid (pid, pid);
+}
+
+GPid
+nm_dns_plugin_child_spawn (NMDnsPlugin *self,
+                           const char **argv,
+                           const char *pidfile,
+                           const char *kill_match)
+{
+	NMDnsPluginPrivate *priv = NM_DNS_PLUGIN_GET_PRIVATE (self);
+	GError *error = NULL;
+	char *cmdline;
+
+	g_return_val_if_fail (argv != NULL, 0);
+	g_return_val_if_fail (argv[0] != NULL, 0);
+
+	g_warn_if_fail (priv->progname == NULL);
+	g_free (priv->progname);
+	priv->progname = g_path_get_basename (argv[0]);
+
+	if (pidfile) {
+		g_return_val_if_fail (kill_match != NULL, 0);
+		kill_existing (priv->progname, pidfile, kill_match);
+
+		g_free (priv->pidfile);
+		priv->pidfile = g_strdup (pidfile);
+	}
+
+	nm_log_info (LOGD_DNS, "DNS: starting %s...", priv->progname);
+	cmdline = g_strjoinv (" ", (char **) argv);
+	nm_log_dbg (LOGD_DNS, "DNS: command line: %s", cmdline);
+	g_free (cmdline);
+
+	priv->pid = 0;
+	if (g_spawn_async (NULL, (char **) argv, NULL,
+	                   G_SPAWN_DO_NOT_REAP_CHILD,
+	                   child_setup,
+	                   NULL, &priv->pid,
+	                   &error)) {
+		nm_log_dbg (LOGD_DNS, "%s started with pid %d", priv->progname, priv->pid);
+		priv->watch_id = g_child_watch_add (priv->pid, (GChildWatchFunc) watch_cb, self);
+	} else {
+		nm_log_warn (LOGD_DNS, "Failed to spawn %s: (%d) %s",
+		             priv->progname, error ? error->code : -1,
+		             error && error->message ? error->message : "(unknown)");
+		g_clear_error (&error);
+	}
+
+	return priv->pid;
+}
+
+typedef struct {
+	int pid;
+	char *progname;
+} KillInfo;
+
+static gboolean
+ensure_killed (gpointer data)
+{
+	KillInfo *info = data;
+
+	if (kill (info->pid, 0) == 0)
+		kill (info->pid, SIGKILL);
+
+	/* ensure the child is reaped */
+	nm_log_dbg (LOGD_DNS, "waiting for %s pid %d to exit", info->progname, info->pid);
+	waitpid (info->pid, NULL, 0);
+	nm_log_dbg (LOGD_DNS, "dnsmasq pid %d cleaned up", info->progname, info->pid);
+
+	g_free (info->progname);
+	g_free (info);
+	return FALSE;
+}
+
+gboolean nm_dns_plugin_child_kill (NMDnsPlugin *self)
+{
+	NMDnsPluginPrivate *priv = NM_DNS_PLUGIN_GET_PRIVATE (self);
+
+	if (priv->watch_id) {
+		g_source_remove (priv->watch_id);
+		priv->watch_id = 0;
+	}
+
+	if (priv->pid) {
+		KillInfo *info;
+
+		if (kill (priv->pid, SIGTERM) == 0) {
+			info = g_malloc0 (sizeof (KillInfo));
+			info->pid = priv->pid;
+			info->progname = g_strdup (priv->progname);
+			g_timeout_add_seconds (2, ensure_killed, info);
+		} else {
+			kill (priv->pid, SIGKILL);
+
+			/* ensure the child is reaped */
+			nm_log_dbg (LOGD_DNS, "waiting for %s pid %d to exit", priv->progname, priv->pid);
+			waitpid (priv->pid, NULL, 0);
+			nm_log_dbg (LOGD_DNS, "%s pid %d cleaned up", priv->progname, priv->pid);
+		}
+		priv->pid = 0;
+		g_free (priv->progname);
+		priv->progname = NULL;
+	}
+
+	if (priv->pidfile) {
+		unlink (priv->pidfile);
+		g_free (priv->pidfile);
+		priv->pidfile = NULL;
+	}
+
+	return TRUE;
+}
+
+/********************************************/
+
+static void
+nm_dns_plugin_init (NMDnsPlugin *self)
+{
+}
+
+static void
+dispose (GObject *object)
+{
+	NMDnsPlugin *self = NM_DNS_PLUGIN (object);
+	NMDnsPluginPrivate *priv = NM_DNS_PLUGIN_GET_PRIVATE (self);
+
+	if (!priv->disposed) {
+		priv->disposed = TRUE;
+
+		nm_dns_plugin_child_kill (self);
+	}
+
+	G_OBJECT_CLASS (nm_dns_plugin_parent_class)->dispose (object);
+}
+
+static void
+finalize (GObject *object)
+{
+	NMDnsPlugin *self = NM_DNS_PLUGIN (object);
+	NMDnsPluginPrivate *priv = NM_DNS_PLUGIN_GET_PRIVATE (self);
+
+	g_free (priv->progname);
+	g_free (priv->pidfile);
+
+	G_OBJECT_CLASS (nm_dns_plugin_parent_class)->finalize (object);
+}
+
+static void
+nm_dns_plugin_class_init (NMDnsPluginClass *plugin_class)
+{
+	GObjectClass *object_class = G_OBJECT_CLASS (plugin_class);
+
+	g_type_class_add_private (plugin_class, sizeof (NMDnsPluginPrivate));
+
+	/* virtual methods */
+	object_class->dispose = dispose;
+	object_class->finalize = finalize;
+	plugin_class->is_caching = is_caching;
+
+	/* signals */
+	signals[FAILED] =
+		g_signal_new (NM_DNS_PLUGIN_FAILED,
+					  G_OBJECT_CLASS_TYPE (object_class),
+					  G_SIGNAL_RUN_FIRST,
+					  G_STRUCT_OFFSET (NMDnsPluginClass, failed),
+					  NULL, NULL,
+					  g_cclosure_marshal_VOID__VOID,
+					  G_TYPE_NONE, 0);
+
+	signals[CHILD_QUIT] =
+		g_signal_new (NM_DNS_PLUGIN_CHILD_QUIT,
+					  G_OBJECT_CLASS_TYPE (object_class),
+					  G_SIGNAL_RUN_FIRST,
+					  G_STRUCT_OFFSET (NMDnsPluginClass, child_quit),
+					  NULL, NULL,
+					  g_cclosure_marshal_VOID__INT,
+					  G_TYPE_NONE, 1, G_TYPE_INT);
+}
+
diff --git a/src/dns-manager/nm-dns-plugin.h b/src/dns-manager/nm-dns-plugin.h
new file mode 100644
index 00000000..d4298b86
--- /dev/null
+++ b/src/dns-manager/nm-dns-plugin.h
@@ -0,0 +1,112 @@
+/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
+/* This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2, or (at your option)
+ * any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License along
+ * with this program; if not, write to the Free Software Foundation, Inc.,
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Copyright (C) 2010 Red Hat, Inc.
+ */
+
+#ifndef NM_DNS_PLUGIN_H
+#define NM_DNS_PLUGIN_H
+
+#include <glib.h>
+#include <glib-object.h>
+
+#define NM_TYPE_DNS_PLUGIN            (nm_dns_plugin_get_type ())
+#define NM_DNS_PLUGIN(obj)            (G_TYPE_CHECK_INSTANCE_CAST ((obj), NM_TYPE_DNS_PLUGIN, NMDnsPlugin))
+#define NM_DNS_PLUGIN_CLASS(klass)    (G_TYPE_CHECK_CLASS_CAST ((klass), NM_TYPE_DNS_PLUGIN, NMDnsPluginClass))
+#define NM_IS_DNS_PLUGIN(obj)         (G_TYPE_CHECK_INSTANCE_TYPE ((obj), NM_TYPE_DNS_PLUGIN))
+#define NM_IS_DNS_PLUGIN_CLASS(klass) (G_TYPE_CHECK_CLASS_TYPE ((obj), NM_TYPE_DNS_PLUGIN))
+#define NM_DNS_PLUGIN_GET_CLASS(obj)  (G_TYPE_INSTANCE_GET_CLASS ((obj), NM_TYPE_DNS_PLUGIN, NMDnsPluginClass))
+
+#define NM_DNS_PLUGIN_FAILED "failed"
+#define NM_DNS_PLUGIN_CHILD_QUIT "child-quit"
+
+typedef struct {
+	GObject parent;
+} NMDnsPlugin;
+
+typedef struct {
+	GObjectClass parent;
+
+	/* Methods */
+	gboolean (*init) (NMDnsPlugin *self);
+
+	/* Called when DNS information is changed.  'vpn_configs' is a list of
+	 * NMIP4Config or NMIP6Config objects from VPN connections, while
+	 * 'dev_configs' is a list of NMPI4Config or NMIP6Config objects from
+	 * active devices.  'other_configs' represent other IP configuration that
+	 * may be in-use.  Configs of the same IP version are sorted in priority
+	 * order.
+	 */
+	gboolean (*update) (NMDnsPlugin *self,
+	                    const GSList *vpn_configs,
+	                    const GSList *dev_configs,
+	                    const GSList *other_configs,
+	                    const char *hostname);
+
+	/* Subclasses should override and return TRUE if they start a local
+	 * caching nameserver that listens on localhost and would block any
+	 * other local caching nameserver from operating.
+	 */
+	gboolean (*is_caching) (NMDnsPlugin *self);
+
+	/* Subclasses should override this and return their plugin name */
+	const char *(*get_name) (NMDnsPlugin *self);
+
+	/* Signals */
+
+	/* Emitted by the plugin and consumed by NMDnsManager when
+	 * some error happens with the nameserver subprocess.  Causes NM to fall
+	 * back to writing out a non-local-caching resolv.conf until the next
+	 * DNS update.
+	 */
+	void (*failed) (NMDnsPlugin *self);
+
+	/* Emitted by the plugin base class when the nameserver subprocess
+	 * quits.  This signal is consumed by the plugin subclasses and not
+	 * by NMDnsManager.  If the subclass decides the exit status (as returned
+	 * by waitpid(2)) is fatal it should then emit the 'failed' signal.
+	 */
+	void (*child_quit) (NMDnsPlugin *self, gint status);
+} NMDnsPluginClass;
+
+GType nm_dns_plugin_get_type (void);
+
+gboolean nm_dns_plugin_is_caching (NMDnsPlugin *self);
+
+const char *nm_dns_plugin_get_name (NMDnsPlugin *self);
+
+gboolean nm_dns_plugin_update (NMDnsPlugin *self,
+                               const GSList *vpn_configs,
+                               const GSList *dev_configs,
+                               const GSList *other_configs,
+                               const char *hostname);
+
+/* For subclasses/plugins */
+
+/* Spawn a child process and watch for it to quit.  'argv' is the NULL-terminated
+ * argument vector to spawn the child with, where argv[0] is the full path to
+ * the child's executable.  If 'pidfile' is given the process owning the PID
+ * contained in 'pidfile' will be killed if its command line matches 'kill_match'
+ * and the pidfile will be deleted.
+ */
+GPid nm_dns_plugin_child_spawn (NMDnsPlugin *self,
+                                const char **argv,
+                                const char *pidfile,
+                                const char *kill_match);
+
+gboolean nm_dns_plugin_child_kill (NMDnsPlugin *self);
+
+#endif /* NM_DNS_PLUGIN_H */
+