]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/login/logind-session-dbus.c
logind: rework logic to decide whether lock + idle + display applies to a session
[thirdparty/systemd.git] / src / login / logind-session-dbus.c
CommitLineData
db9ecf05 1/* SPDX-License-Identifier: LGPL-2.1-or-later */
3f49d45a
LP
2
3#include <errno.h>
4
b5efdb8a 5#include "alloc-util.h"
96aad8d1 6#include "bus-common-errors.h"
40af3d02 7#include "bus-get-properties.h"
a6278b88 8#include "bus-label.h"
269e4d2d 9#include "bus-polkit.h"
3ffd4af2 10#include "bus-util.h"
7176f06c 11#include "devnum-util.h"
3ffd4af2 12#include "fd-util.h"
2a66c2a1 13#include "logind-brightness.h"
6ecda0fb 14#include "logind-dbus.h"
7820a56c 15#include "logind-polkit.h"
6ecda0fb
LP
16#include "logind-seat-dbus.h"
17#include "logind-session-dbus.h"
118ecf32 18#include "logind-session-device.h"
3ffd4af2 19#include "logind-session.h"
6ecda0fb 20#include "logind-user-dbus.h"
3ffd4af2 21#include "logind.h"
36dd5ffd 22#include "missing_capability.h"
2a66c2a1 23#include "path-util.h"
6eb7c172 24#include "signal-util.h"
3ffd4af2 25#include "strv.h"
092e6cd1 26#include "terminal-util.h"
3b92c086 27#include "user-util.h"
3f49d45a 28
cc377381
LP
29static int property_get_user(
30 sd_bus *bus,
31 const char *path,
32 const char *interface,
33 const char *property,
34 sd_bus_message *reply,
ebcf1f97
LP
35 void *userdata,
36 sd_bus_error *error) {
cc377381
LP
37
38 _cleanup_free_ char *p = NULL;
99534007 39 Session *s = ASSERT_PTR(userdata);
cc377381
LP
40
41 assert(bus);
42 assert(reply);
3f49d45a 43
cc377381
LP
44 p = user_bus_path(s->user);
45 if (!p)
3f49d45a
LP
46 return -ENOMEM;
47
22c902fa 48 return sd_bus_message_append(reply, "(uo)", (uint32_t) s->user->user_record->uid, p);
cc377381 49}
3f49d45a 50
cc377381
LP
51static int property_get_name(
52 sd_bus *bus,
53 const char *path,
54 const char *interface,
55 const char *property,
56 sd_bus_message *reply,
ebcf1f97
LP
57 void *userdata,
58 sd_bus_error *error) {
3f49d45a 59
99534007 60 Session *s = ASSERT_PTR(userdata);
3f49d45a 61
cc377381
LP
62 assert(bus);
63 assert(reply);
3f49d45a 64
22c902fa 65 return sd_bus_message_append(reply, "s", s->user->user_record->user_name);
3f49d45a
LP
66}
67
cc377381
LP
68static int property_get_seat(
69 sd_bus *bus,
70 const char *path,
71 const char *interface,
72 const char *property,
73 sd_bus_message *reply,
ebcf1f97
LP
74 void *userdata,
75 sd_bus_error *error) {
3f49d45a 76
cc377381 77 _cleanup_free_ char *p = NULL;
99534007 78 Session *s = ASSERT_PTR(userdata);
3f49d45a 79
cc377381
LP
80 assert(bus);
81 assert(reply);
3f49d45a 82
cc377381 83 p = s->seat ? seat_bus_path(s->seat) : strdup("/");
3f49d45a
LP
84 if (!p)
85 return -ENOMEM;
86
cc377381
LP
87 return sd_bus_message_append(reply, "(so)", s->seat ? s->seat->id : "", p);
88}
3f49d45a 89
cc377381
LP
90static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_type, session_type, SessionType);
91static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_class, session_class, SessionClass);
01adcd69
YW
92static BUS_DEFINE_PROPERTY_GET(property_get_active, "b", Session, session_is_active);
93static BUS_DEFINE_PROPERTY_GET2(property_get_state, "s", Session, session_get_state, session_state_to_string);
cc377381
LP
94
95static int property_get_idle_hint(
96 sd_bus *bus,
97 const char *path,
98 const char *interface,
99 const char *property,
100 sd_bus_message *reply,
ebcf1f97
LP
101 void *userdata,
102 sd_bus_error *error) {
a185c5aa 103
99534007 104 Session *s = ASSERT_PTR(userdata);
cc377381
LP
105
106 assert(bus);
107 assert(reply);
cc377381
LP
108
109 return sd_bus_message_append(reply, "b", session_get_idle_hint(s, NULL) > 0);
a185c5aa
LP
110}
111
cc377381
LP
112static int property_get_idle_since_hint(
113 sd_bus *bus,
114 const char *path,
115 const char *interface,
116 const char *property,
117 sd_bus_message *reply,
ebcf1f97
LP
118 void *userdata,
119 sd_bus_error *error) {
cc377381 120
99534007 121 Session *s = ASSERT_PTR(userdata);
5cb14b37 122 dual_timestamp t = DUAL_TIMESTAMP_NULL;
a185c5aa 123 uint64_t u;
ca4f2b6d 124 int r;
a185c5aa 125
cc377381
LP
126 assert(bus);
127 assert(reply);
a185c5aa 128
ca4f2b6d
VP
129 r = session_get_idle_hint(s, &t);
130 if (r < 0)
131 return r;
132
a185c5aa
LP
133 u = streq(property, "IdleSinceHint") ? t.realtime : t.monotonic;
134
cc377381 135 return sd_bus_message_append(reply, "t", u);
a185c5aa
LP
136}
137
42d35e13
VT
138static int property_get_locked_hint(
139 sd_bus *bus,
140 const char *path,
141 const char *interface,
142 const char *property,
143 sd_bus_message *reply,
144 void *userdata,
145 sd_bus_error *error) {
146
99534007 147 Session *s = ASSERT_PTR(userdata);
42d35e13
VT
148
149 assert(bus);
150 assert(reply);
42d35e13
VT
151
152 return sd_bus_message_append(reply, "b", session_get_locked_hint(s) > 0);
153}
154
19070062 155int bus_session_method_terminate(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 156 Session *s = ASSERT_PTR(userdata);
cc377381 157 int r;
0604381b 158
cc377381 159 assert(message);
0604381b 160
7b36fb9f 161 r = bus_verify_polkit_async_full(
c529695e 162 message,
c529695e 163 "org.freedesktop.login1.manage",
7b36fb9f
LP
164 /* details= */ NULL,
165 /* interactive= */ false,
22c902fa 166 s->user->user_record->uid,
c529695e
LP
167 &s->manager->polkit_registry,
168 error);
169 if (r < 0)
170 return r;
171 if (r == 0)
172 return 1; /* Will call us back */
173
bda62573 174 r = session_stop(s, /* force = */ true);
cc377381 175 if (r < 0)
ebcf1f97 176 return r;
0604381b 177
df2d202e 178 return sd_bus_reply_method_return(message, NULL);
0604381b
LP
179}
180
19070062 181int bus_session_method_activate(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 182 Session *s = ASSERT_PTR(userdata);
cc377381 183 int r;
3f49d45a 184
cc377381 185 assert(message);
3f49d45a 186
7820a56c 187 r = check_polkit_chvt(message, s->manager, error);
4acf0cfd
LP
188 if (r < 0)
189 return r;
190 if (r == 0)
191 return 1; /* Will call us back */
192
cc377381
LP
193 r = session_activate(s);
194 if (r < 0)
ebcf1f97 195 return r;
3f49d45a 196
df2d202e 197 return sd_bus_reply_method_return(message, NULL);
cc377381
LP
198}
199
19070062 200int bus_session_method_lock(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 201 Session *s = ASSERT_PTR(userdata);
cc377381
LP
202 int r;
203
cc377381 204 assert(message);
3f49d45a 205
7b36fb9f 206 r = bus_verify_polkit_async_full(
c529695e 207 message,
c529695e 208 "org.freedesktop.login1.lock-sessions",
7b36fb9f
LP
209 /* details= */ NULL,
210 /* interactive= */ false,
22c902fa 211 s->user->user_record->uid,
c529695e
LP
212 &s->manager->polkit_registry,
213 error);
214 if (r < 0)
215 return r;
216 if (r == 0)
217 return 1; /* Will call us back */
218
b4f01bc1
LP
219 r = session_send_lock(s, /* lock= */ strstr(sd_bus_message_get_member(message), "Lock"));
220 if (r == -ENOTTY)
221 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Session does not support lock screen.");
cc377381 222 if (r < 0)
ebcf1f97 223 return r;
3f49d45a 224
df2d202e 225 return sd_bus_reply_method_return(message, NULL);
3f49d45a
LP
226}
227
19070062 228static int method_set_idle_hint(sd_bus_message *message, void *userdata, sd_bus_error *error) {
4afd3348 229 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
99534007 230 Session *s = ASSERT_PTR(userdata);
cc377381
LP
231 uid_t uid;
232 int r, b;
d200735e 233
cc377381 234 assert(message);
cc377381
LP
235
236 r = sd_bus_message_read(message, "b", &b);
237 if (r < 0)
ebcf1f97 238 return r;
d200735e 239
05bae4a6 240 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
5b12334d
LP
241 if (r < 0)
242 return r;
243
05bae4a6 244 r = sd_bus_creds_get_euid(creds, &uid);
cc377381 245 if (r < 0)
ebcf1f97 246 return r;
cc377381 247
22c902fa 248 if (uid != 0 && uid != s->user->user_record->uid)
1b09b81c 249 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may set idle hint");
cc377381 250
be2bb14f
LP
251 r = session_set_idle_hint(s, b);
252 if (r == -ENOTTY)
b4f01bc1 253 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Idle hint control is not supported on non-graphical and non-user sessions.");
be2bb14f
LP
254 if (r < 0)
255 return r;
3f49d45a 256
df2d202e 257 return sd_bus_reply_method_return(message, NULL);
cc377381
LP
258}
259
42d35e13
VT
260static int method_set_locked_hint(sd_bus_message *message, void *userdata, sd_bus_error *error) {
261 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
99534007 262 Session *s = ASSERT_PTR(userdata);
42d35e13
VT
263 uid_t uid;
264 int r, b;
265
266 assert(message);
42d35e13
VT
267
268 r = sd_bus_message_read(message, "b", &b);
269 if (r < 0)
270 return r;
271
272 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
273 if (r < 0)
274 return r;
275
276 r = sd_bus_creds_get_euid(creds, &uid);
277 if (r < 0)
278 return r;
279
22c902fa 280 if (uid != 0 && uid != s->user->user_record->uid)
1b09b81c 281 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may set locked hint");
42d35e13 282
b4f01bc1
LP
283 r = session_set_locked_hint(s, b);
284 if (r == -ENOTTY)
285 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Session does not support lock screen.");
286 if (r < 0)
287 return r;
42d35e13
VT
288
289 return sd_bus_reply_method_return(message, NULL);
290}
291
19070062 292int bus_session_method_kill(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 293 Session *s = ASSERT_PTR(userdata);
cc377381
LP
294 const char *swho;
295 int32_t signo;
296 KillWho who;
bef422ae
LP
297 int r;
298
3f49d45a
LP
299 assert(message);
300
cc377381
LP
301 r = sd_bus_message_read(message, "si", &swho, &signo);
302 if (r < 0)
ebcf1f97 303 return r;
cc377381
LP
304
305 if (isempty(swho))
306 who = KILL_ALL;
307 else {
308 who = kill_who_from_string(swho);
309 if (who < 0)
ebcf1f97 310 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid kill parameter '%s'", swho);
cc377381 311 }
bef422ae 312
6eb7c172 313 if (!SIGNAL_VALID(signo))
ebcf1f97 314 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid signal %i", signo);
bef422ae 315
7b36fb9f 316 r = bus_verify_polkit_async_full(
c529695e 317 message,
c529695e 318 "org.freedesktop.login1.manage",
7b36fb9f
LP
319 /* details= */ NULL,
320 /* interactive= */ false,
22c902fa 321 s->user->user_record->uid,
c529695e
LP
322 &s->manager->polkit_registry,
323 error);
324 if (r < 0)
325 return r;
326 if (r == 0)
327 return 1; /* Will call us back */
328
cc377381
LP
329 r = session_kill(s, who, signo);
330 if (r < 0)
ebcf1f97 331 return r;
bef422ae 332
df2d202e 333 return sd_bus_reply_method_return(message, NULL);
cc377381 334}
bef422ae 335
19070062 336static int method_take_control(sd_bus_message *message, void *userdata, sd_bus_error *error) {
4afd3348 337 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
99534007 338 Session *s = ASSERT_PTR(userdata);
cc377381
LP
339 int r, force;
340 uid_t uid;
bef422ae 341
cc377381 342 assert(message);
bef422ae 343
cc377381
LP
344 r = sd_bus_message_read(message, "b", &force);
345 if (r < 0)
ebcf1f97 346 return r;
bef422ae 347
05bae4a6 348 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
5b12334d
LP
349 if (r < 0)
350 return r;
351
05bae4a6 352 r = sd_bus_creds_get_euid(creds, &uid);
cc377381 353 if (r < 0)
ebcf1f97 354 return r;
bef422ae 355
22c902fa 356 if (uid != 0 && (force || uid != s->user->user_record->uid))
1b09b81c 357 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may take control");
bef422ae 358
dc6284e9 359 r = session_set_controller(s, sd_bus_message_get_sender(message), force, true);
cc377381 360 if (r < 0)
ebcf1f97 361 return r;
bef422ae 362
df2d202e 363 return sd_bus_reply_method_return(message, NULL);
cc377381 364}
bef422ae 365
19070062 366static int method_release_control(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 367 Session *s = ASSERT_PTR(userdata);
bef422ae 368
cc377381 369 assert(message);
5bc849fd 370
cc377381 371 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 372 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
5bc849fd 373
cc377381 374 session_drop_controller(s);
bef422ae 375
df2d202e 376 return sd_bus_reply_method_return(message, NULL);
cc377381 377}
bef422ae 378
db72aea4 379static int method_set_type(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 380 Session *s = ASSERT_PTR(userdata);
db72aea4
CH
381 const char *t;
382 SessionType type;
383 int r;
384
385 assert(message);
db72aea4
CH
386
387 r = sd_bus_message_read(message, "s", &t);
388 if (r < 0)
389 return r;
390
391 type = session_type_from_string(t);
392 if (type < 0)
393 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS,
394 "Invalid session type '%s'", t);
395
396 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 397 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You must be in control of this session to set type");
db72aea4
CH
398
399 session_set_type(s, type);
400
401 return sd_bus_reply_method_return(message, NULL);
402}
403
4885d749
DT
404static int method_set_display(sd_bus_message *message, void *userdata, sd_bus_error *error) {
405 Session *s = ASSERT_PTR(userdata);
406 const char *display;
407 int r;
408
409 assert(message);
410
411 r = sd_bus_message_read(message, "s", &display);
412 if (r < 0)
413 return r;
414
415 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
416 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You must be in control of this session to set display");
417
418 if (!SESSION_TYPE_IS_GRAPHICAL(s->type))
419 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Setting display is only supported for graphical sessions");
420
421 r = session_set_display(s, display);
422 if (r < 0)
423 return r;
424
425 return sd_bus_reply_method_return(message, NULL);
426}
427
092e6cd1
TK
428static int method_set_tty(sd_bus_message *message, void *userdata, sd_bus_error *error) {
429 Session *s = ASSERT_PTR(userdata);
430 int fd, r, flags;
431 _cleanup_free_ char *q = NULL;
432
433 assert(message);
434
435 r = sd_bus_message_read(message, "h", &fd);
436 if (r < 0)
437 return r;
438
439 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
440 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You must be in control of this session to set tty");
441
442 assert(fd >= 0);
443
444 flags = fcntl(fd, F_GETFL, 0);
445 if (flags < 0)
446 return -errno;
447 if ((flags & O_ACCMODE) != O_RDWR)
448 return -EACCES;
449 if (FLAGS_SET(flags, O_PATH))
450 return -ENOTTY;
451
452 r = getttyname_malloc(fd, &q);
453 if (r < 0)
454 return r;
455
456 r = session_set_tty(s, q);
457 if (r < 0)
458 return r;
459
460 return sd_bus_reply_method_return(message, NULL);
461}
462
19070062 463static int method_take_device(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 464 Session *s = ASSERT_PTR(userdata);
cc377381 465 uint32_t major, minor;
360179ea 466 _cleanup_(session_device_freep) SessionDevice *sd = NULL;
cc377381
LP
467 dev_t dev;
468 int r;
de07ab16 469
cc377381 470 assert(message);
de07ab16 471
cc377381
LP
472 r = sd_bus_message_read(message, "uu", &major, &minor);
473 if (r < 0)
ebcf1f97 474 return r;
cc377381 475
fa583ab1 476 if (!DEVICE_MAJOR_VALID(major) || !DEVICE_MINOR_VALID(minor))
1b09b81c 477 return sd_bus_error_set(error, SD_BUS_ERROR_INVALID_ARGS, "Device major/minor is not valid.");
fa583ab1 478
cc377381 479 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 480 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
cc377381
LP
481
482 dev = makedev(major, minor);
483 sd = hashmap_get(s->devices, &dev);
484 if (sd)
485 /* We don't allow retrieving a device multiple times.
486 * The related ReleaseDevice call is not ref-counted.
487 * The caller should use dup() if it requires more
488 * than one fd (it would be functionally
489 * equivalent). */
1b09b81c 490 return sd_bus_error_set(error, BUS_ERROR_DEVICE_IS_TAKEN, "Device already taken");
cc377381 491
aed24c4c 492 r = session_device_new(s, dev, true, &sd);
cc377381 493 if (r < 0)
ebcf1f97 494 return r;
de07ab16 495
aed24c4c
FB
496 r = session_device_save(sd);
497 if (r < 0)
360179ea 498 return r;
aed24c4c 499
df2d202e 500 r = sd_bus_reply_method_return(message, "hb", sd->fd, !sd->active);
cc377381 501 if (r < 0)
360179ea 502 return r;
aed24c4c
FB
503
504 session_save(s);
360179ea 505 TAKE_PTR(sd);
118ecf32 506
360179ea 507 return 1;
cc377381 508}
118ecf32 509
19070062 510static int method_release_device(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 511 Session *s = ASSERT_PTR(userdata);
cc377381
LP
512 uint32_t major, minor;
513 SessionDevice *sd;
514 dev_t dev;
515 int r;
118ecf32 516
cc377381 517 assert(message);
118ecf32 518
cc377381
LP
519 r = sd_bus_message_read(message, "uu", &major, &minor);
520 if (r < 0)
ebcf1f97 521 return r;
118ecf32 522
fa583ab1 523 if (!DEVICE_MAJOR_VALID(major) || !DEVICE_MINOR_VALID(minor))
1b09b81c 524 return sd_bus_error_set(error, SD_BUS_ERROR_INVALID_ARGS, "Device major/minor is not valid.");
fa583ab1 525
cc377381 526 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 527 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
118ecf32 528
cc377381
LP
529 dev = makedev(major, minor);
530 sd = hashmap_get(s->devices, &dev);
531 if (!sd)
1b09b81c 532 return sd_bus_error_set(error, BUS_ERROR_DEVICE_NOT_TAKEN, "Device not taken");
118ecf32 533
cc377381 534 session_device_free(sd);
aed24c4c
FB
535 session_save(s);
536
df2d202e 537 return sd_bus_reply_method_return(message, NULL);
cc377381 538}
118ecf32 539
19070062 540static int method_pause_device_complete(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 541 Session *s = ASSERT_PTR(userdata);
cc377381
LP
542 uint32_t major, minor;
543 SessionDevice *sd;
544 dev_t dev;
545 int r;
118ecf32 546
cc377381 547 assert(message);
bef422ae 548
cc377381
LP
549 r = sd_bus_message_read(message, "uu", &major, &minor);
550 if (r < 0)
ebcf1f97 551 return r;
cc377381 552
fa583ab1 553 if (!DEVICE_MAJOR_VALID(major) || !DEVICE_MINOR_VALID(minor))
1b09b81c 554 return sd_bus_error_set(error, SD_BUS_ERROR_INVALID_ARGS, "Device major/minor is not valid.");
fa583ab1 555
cc377381 556 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 557 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
bef422ae 558
cc377381
LP
559 dev = makedev(major, minor);
560 sd = hashmap_get(s->devices, &dev);
561 if (!sd)
1b09b81c 562 return sd_bus_error_set(error, BUS_ERROR_DEVICE_NOT_TAKEN, "Device not taken");
bef422ae 563
cc377381 564 session_device_complete_pause(sd);
bef422ae 565
df2d202e 566 return sd_bus_reply_method_return(message, NULL);
3f49d45a
LP
567}
568
2a66c2a1
LP
569static int method_set_brightness(sd_bus_message *message, void *userdata, sd_bus_error *error) {
570 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
571 _cleanup_(sd_device_unrefp) sd_device *d = NULL;
572 const char *subsystem, *name, *seat;
99534007 573 Session *s = ASSERT_PTR(userdata);
2a66c2a1
LP
574 uint32_t brightness;
575 uid_t uid;
576 int r;
577
578 assert(message);
2a66c2a1
LP
579
580 r = sd_bus_message_read(message, "ssu", &subsystem, &name, &brightness);
581 if (r < 0)
582 return r;
583
584 if (!STR_IN_SET(subsystem, "backlight", "leds"))
585 return sd_bus_error_setf(error, SD_BUS_ERROR_NOT_SUPPORTED, "Subsystem type %s not supported, must be one of 'backlight' or 'leds'.", subsystem);
586 if (!filename_is_valid(name))
587 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Not a valid device name %s, refusing.", name);
588
589 if (!s->seat)
1b09b81c 590 return sd_bus_error_set(error, BUS_ERROR_NOT_YOUR_DEVICE, "Your session has no seat, refusing.");
2a66c2a1 591 if (s->seat->active != s)
1b09b81c 592 return sd_bus_error_set(error, BUS_ERROR_NOT_YOUR_DEVICE, "Session is not in foreground, refusing.");
2a66c2a1
LP
593
594 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
595 if (r < 0)
596 return r;
597
598 r = sd_bus_creds_get_euid(creds, &uid);
599 if (r < 0)
600 return r;
601
22c902fa 602 if (uid != 0 && uid != s->user->user_record->uid)
1b09b81c 603 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may change brightness.");
2a66c2a1
LP
604
605 r = sd_device_new_from_subsystem_sysname(&d, subsystem, name);
606 if (r < 0)
607 return sd_bus_error_set_errnof(error, r, "Failed to open device %s:%s: %m", subsystem, name);
608
609 if (sd_device_get_property_value(d, "ID_SEAT", &seat) >= 0 && !streq_ptr(seat, s->seat->id))
610 return sd_bus_error_setf(error, BUS_ERROR_NOT_YOUR_DEVICE, "Device %s:%s does not belong to your seat %s, refusing.", subsystem, name, s->seat->id);
611
612 r = manager_write_brightness(s->manager, d, brightness, message);
613 if (r < 0)
614 return r;
615
616 return 1;
617}
618
c2b178d3 619static int session_object_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
3b92c086
LP
620 _cleanup_free_ char *e = NULL;
621 sd_bus_message *message;
99534007 622 Manager *m = ASSERT_PTR(userdata);
cc377381 623 Session *session;
3b92c086 624 const char *p;
927b1649 625 int r;
3f49d45a 626
cc377381
LP
627 assert(bus);
628 assert(path);
629 assert(interface);
630 assert(found);
3f49d45a 631
3b92c086
LP
632 p = startswith(path, "/org/freedesktop/login1/session/");
633 if (!p)
634 return 0;
3f49d45a 635
3b92c086
LP
636 e = bus_label_unescape(p);
637 if (!e)
638 return -ENOMEM;
927b1649 639
3b92c086 640 message = sd_bus_get_current_message(bus);
927b1649 641
3b92c086
LP
642 r = manager_get_session_from_creds(m, message, e, error, &session);
643 if (r == -ENXIO) {
644 sd_bus_error_free(error);
645 return 0;
927b1649 646 }
3b92c086
LP
647 if (r < 0)
648 return r;
3f49d45a 649
cc377381
LP
650 *found = session;
651 return 1;
3f49d45a
LP
652}
653
3f49d45a 654char *session_bus_path(Session *s) {
9444b1f2 655 _cleanup_free_ char *t = NULL;
3f49d45a
LP
656
657 assert(s);
658
a6278b88 659 t = bus_label_escape(s->id);
3f49d45a
LP
660 if (!t)
661 return NULL;
662
b910cc72 663 return strjoin("/org/freedesktop/login1/session/", t);
3f49d45a 664}
da119395 665
c2b178d3 666static int session_node_enumerator(sd_bus *bus, const char *path, void *userdata, char ***nodes, sd_bus_error *error) {
cc377381 667 _cleanup_strv_free_ char **l = NULL;
ca56b0a6 668 sd_bus_message *message;
cc377381
LP
669 Manager *m = userdata;
670 Session *session;
cc377381
LP
671 int r;
672
673 assert(bus);
674 assert(path);
675 assert(nodes);
676
90e74a66 677 HASHMAP_FOREACH(session, m->sessions) {
cc377381
LP
678 char *p;
679
680 p = session_bus_path(session);
681 if (!p)
682 return -ENOMEM;
683
6e18964d
ZJS
684 r = strv_consume(&l, p);
685 if (r < 0)
cc377381 686 return r;
cc377381
LP
687 }
688
ca56b0a6
DH
689 message = sd_bus_get_current_message(bus);
690 if (message) {
4afd3348 691 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
ca56b0a6 692
3b92c086 693 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_SESSION|SD_BUS_CREDS_OWNER_UID|SD_BUS_CREDS_AUGMENT, &creds);
ca56b0a6 694 if (r >= 0) {
3b92c086
LP
695 bool may_auto = false;
696 const char *name;
697
ca56b0a6
DH
698 r = sd_bus_creds_get_session(creds, &name);
699 if (r >= 0) {
700 session = hashmap_get(m->sessions, name);
701 if (session) {
702 r = strv_extend(&l, "/org/freedesktop/login1/session/self");
703 if (r < 0)
704 return r;
3b92c086
LP
705
706 may_auto = true;
707 }
708 }
709
710 if (!may_auto) {
711 uid_t uid;
712
713 r = sd_bus_creds_get_owner_uid(creds, &uid);
714 if (r >= 0) {
715 User *user;
716
717 user = hashmap_get(m->users, UID_TO_PTR(uid));
718 may_auto = user && user->display;
ca56b0a6
DH
719 }
720 }
3b92c086
LP
721
722 if (may_auto) {
723 r = strv_extend(&l, "/org/freedesktop/login1/session/auto");
724 if (r < 0)
725 return r;
726 }
ca56b0a6
DH
727 }
728 }
b298e984 729
1cc6c93a 730 *nodes = TAKE_PTR(l);
cc377381
LP
731 return 1;
732}
733
da119395 734int session_send_signal(Session *s, bool new_session) {
ce0fc5f5 735 _cleanup_free_ char *p = NULL;
da119395
LP
736
737 assert(s);
738
da119395
LP
739 p = session_bus_path(s);
740 if (!p)
4654e558 741 return -ENOMEM;
da119395 742
cc377381
LP
743 return sd_bus_emit_signal(
744 s->manager->bus,
745 "/org/freedesktop/login1",
746 "org.freedesktop.login1.Manager",
747 new_session ? "SessionNew" : "SessionRemoved",
748 "so", s->id, p);
da119395 749}
9418f147 750
cc377381 751int session_send_changed(Session *s, const char *properties, ...) {
ce0fc5f5 752 _cleanup_free_ char *p = NULL;
cc377381 753 char **l;
9418f147
LP
754
755 assert(s);
756
ed18b08b
LP
757 if (!s->started)
758 return 0;
759
9418f147
LP
760 p = session_bus_path(s);
761 if (!p)
762 return -ENOMEM;
763
cc377381 764 l = strv_from_stdarg_alloca(properties);
9418f147 765
cc377381 766 return sd_bus_emit_properties_changed_strv(s->manager->bus, p, "org.freedesktop.login1.Session", l);
9418f147 767}
88e3dc90
LP
768
769int session_send_lock(Session *s, bool lock) {
ce0fc5f5 770 _cleanup_free_ char *p = NULL;
88e3dc90
LP
771
772 assert(s);
773
b4f01bc1
LP
774 if (!SESSION_CLASS_CAN_LOCK(s->class))
775 return -ENOTTY;
776
88e3dc90
LP
777 p = session_bus_path(s);
778 if (!p)
779 return -ENOMEM;
780
cc377381
LP
781 return sd_bus_emit_signal(
782 s->manager->bus,
783 p,
784 "org.freedesktop.login1.Session",
785 lock ? "Lock" : "Unlock",
786 NULL);
88e3dc90 787}
7ba64386
LP
788
789int session_send_lock_all(Manager *m, bool lock) {
790 Session *session;
7ba64386
LP
791 int r = 0;
792
793 assert(m);
794
90e74a66 795 HASHMAP_FOREACH(session, m->sessions) {
7ba64386
LP
796 int k;
797
b4f01bc1
LP
798 if (!SESSION_CLASS_CAN_LOCK(session->class))
799 continue;
800
7ba64386
LP
801 k = session_send_lock(session, lock);
802 if (k < 0)
803 r = k;
804 }
805
806 return r;
807}
fb6becb4 808
b1951bc8
LP
809static bool session_ready(Session *s) {
810 assert(s);
811
812 /* Returns true when the session is ready, i.e. all jobs we enqueued for it are done (regardless if successful or not) */
813
814 return !s->scope_job &&
5099a50d 815 (!SESSION_CLASS_WANTS_SERVICE_MANAGER(s->class) || !s->user->service_job);
b1951bc8
LP
816}
817
cc377381 818int session_send_create_reply(Session *s, sd_bus_error *error) {
4afd3348 819 _cleanup_(sd_bus_message_unrefp) sd_bus_message *c = NULL;
254d1313 820 _cleanup_close_ int fifo_fd = -EBADF;
cc377381 821 _cleanup_free_ char *p = NULL;
fb6becb4
LP
822
823 assert(s);
824
b1951bc8 825 /* This is called after the session scope and the user service were successfully created, and finishes where
dd9b67aa 826 * bus_manager_create_session() left off. */
cba38758 827
cc377381
LP
828 if (!s->create_message)
829 return 0;
fb6becb4 830
b1951bc8 831 if (!sd_bus_error_is_set(error) && !session_ready(s))
dd9b67aa
LP
832 return 0;
833
1b88ed3b 834 c = TAKE_PTR(s->create_message);
cc377381 835 if (error)
df2d202e 836 return sd_bus_reply_method_error(c, error);
fb6becb4 837
cc377381
LP
838 fifo_fd = session_create_fifo(s);
839 if (fifo_fd < 0)
840 return fifo_fd;
fb6becb4 841
b1951bc8 842 /* Update the session state file before we notify the client about the result. */
38fdcbed
TA
843 session_save(s);
844
cc377381
LP
845 p = session_bus_path(s);
846 if (!p)
847 return -ENOMEM;
fb6becb4 848
5a330cda 849 log_debug("Sending reply about created session: "
236af516
DH
850 "id=%s object_path=%s uid=%u runtime_path=%s "
851 "session_fd=%d seat=%s vtnr=%u",
5a330cda
ZJS
852 s->id,
853 p,
22c902fa 854 (uint32_t) s->user->user_record->uid,
5a330cda
ZJS
855 s->user->runtime_path,
856 fifo_fd,
857 s->seat ? s->seat->id : "",
858 (uint32_t) s->vtnr);
859
cc377381 860 return sd_bus_reply_method_return(
baae0358 861 c, "soshusub",
cc377381
LP
862 s->id,
863 p,
864 s->user->runtime_path,
865 fifo_fd,
22c902fa 866 (uint32_t) s->user->user_record->uid,
cc377381
LP
867 s->seat ? s->seat->id : "",
868 (uint32_t) s->vtnr,
869 false);
fb6becb4 870}
c2b178d3
ZJS
871
872static const sd_bus_vtable session_vtable[] = {
873 SD_BUS_VTABLE_START(0),
874
875 SD_BUS_PROPERTY("Id", "s", NULL, offsetof(Session, id), SD_BUS_VTABLE_PROPERTY_CONST),
876 SD_BUS_PROPERTY("User", "(uo)", property_get_user, 0, SD_BUS_VTABLE_PROPERTY_CONST),
877 SD_BUS_PROPERTY("Name", "s", property_get_name, 0, SD_BUS_VTABLE_PROPERTY_CONST),
878 BUS_PROPERTY_DUAL_TIMESTAMP("Timestamp", offsetof(Session, timestamp), SD_BUS_VTABLE_PROPERTY_CONST),
879 SD_BUS_PROPERTY("VTNr", "u", NULL, offsetof(Session, vtnr), SD_BUS_VTABLE_PROPERTY_CONST),
880 SD_BUS_PROPERTY("Seat", "(so)", property_get_seat, 0, SD_BUS_VTABLE_PROPERTY_CONST),
f1e02423 881 SD_BUS_PROPERTY("TTY", "s", NULL, offsetof(Session, tty), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
236cb016 882 SD_BUS_PROPERTY("Display", "s", NULL, offsetof(Session, display), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
c2b178d3
ZJS
883 SD_BUS_PROPERTY("Remote", "b", bus_property_get_bool, offsetof(Session, remote), SD_BUS_VTABLE_PROPERTY_CONST),
884 SD_BUS_PROPERTY("RemoteHost", "s", NULL, offsetof(Session, remote_host), SD_BUS_VTABLE_PROPERTY_CONST),
885 SD_BUS_PROPERTY("RemoteUser", "s", NULL, offsetof(Session, remote_user), SD_BUS_VTABLE_PROPERTY_CONST),
886 SD_BUS_PROPERTY("Service", "s", NULL, offsetof(Session, service), SD_BUS_VTABLE_PROPERTY_CONST),
887 SD_BUS_PROPERTY("Desktop", "s", NULL, offsetof(Session, desktop), SD_BUS_VTABLE_PROPERTY_CONST),
888 SD_BUS_PROPERTY("Scope", "s", NULL, offsetof(Session, scope), SD_BUS_VTABLE_PROPERTY_CONST),
89bad70f 889 SD_BUS_PROPERTY("Leader", "u", bus_property_get_pid, offsetof(Session, leader.pid), SD_BUS_VTABLE_PROPERTY_CONST),
c2b178d3
ZJS
890 SD_BUS_PROPERTY("Audit", "u", NULL, offsetof(Session, audit_id), SD_BUS_VTABLE_PROPERTY_CONST),
891 SD_BUS_PROPERTY("Type", "s", property_get_type, offsetof(Session, type), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
892 SD_BUS_PROPERTY("Class", "s", property_get_class, offsetof(Session, class), SD_BUS_VTABLE_PROPERTY_CONST),
893 SD_BUS_PROPERTY("Active", "b", property_get_active, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
894 SD_BUS_PROPERTY("State", "s", property_get_state, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
895 SD_BUS_PROPERTY("IdleHint", "b", property_get_idle_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
896 SD_BUS_PROPERTY("IdleSinceHint", "t", property_get_idle_since_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
897 SD_BUS_PROPERTY("IdleSinceHintMonotonic", "t", property_get_idle_since_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
898 SD_BUS_PROPERTY("LockedHint", "b", property_get_locked_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
899
900 SD_BUS_METHOD("Terminate",
901 NULL,
902 NULL,
903 bus_session_method_terminate,
904 SD_BUS_VTABLE_UNPRIVILEGED),
905 SD_BUS_METHOD("Activate",
906 NULL,
907 NULL,
908 bus_session_method_activate,
909 SD_BUS_VTABLE_UNPRIVILEGED),
910 SD_BUS_METHOD("Lock",
911 NULL,
912 NULL,
913 bus_session_method_lock,
914 SD_BUS_VTABLE_UNPRIVILEGED),
915 SD_BUS_METHOD("Unlock",
916 NULL,
917 NULL,
918 bus_session_method_lock,
919 SD_BUS_VTABLE_UNPRIVILEGED),
a6293b05
NK
920 SD_BUS_METHOD_WITH_ARGS("SetIdleHint",
921 SD_BUS_ARGS("b", idle),
922 SD_BUS_NO_RESULT,
923 method_set_idle_hint,
924 SD_BUS_VTABLE_UNPRIVILEGED),
925 SD_BUS_METHOD_WITH_ARGS("SetLockedHint",
926 SD_BUS_ARGS("b", locked),
927 SD_BUS_NO_RESULT,
928 method_set_locked_hint,
929 SD_BUS_VTABLE_UNPRIVILEGED),
930 SD_BUS_METHOD_WITH_ARGS("Kill",
931 SD_BUS_ARGS("s", who, "i", signal_number),
932 SD_BUS_NO_RESULT,
933 bus_session_method_kill,
934 SD_BUS_VTABLE_UNPRIVILEGED),
935 SD_BUS_METHOD_WITH_ARGS("TakeControl",
936 SD_BUS_ARGS("b", force),
937 SD_BUS_NO_RESULT,
938 method_take_control,
939 SD_BUS_VTABLE_UNPRIVILEGED),
c2b178d3
ZJS
940 SD_BUS_METHOD("ReleaseControl",
941 NULL,
942 NULL,
943 method_release_control,
944 SD_BUS_VTABLE_UNPRIVILEGED),
a6293b05
NK
945 SD_BUS_METHOD_WITH_ARGS("SetType",
946 SD_BUS_ARGS("s", type),
947 SD_BUS_NO_RESULT,
948 method_set_type,
949 SD_BUS_VTABLE_UNPRIVILEGED),
4885d749
DT
950 SD_BUS_METHOD_WITH_ARGS("SetDisplay",
951 SD_BUS_ARGS("s", display),
952 SD_BUS_NO_RESULT,
953 method_set_display,
954 SD_BUS_VTABLE_UNPRIVILEGED),
092e6cd1
TK
955 SD_BUS_METHOD_WITH_ARGS("SetTTY",
956 SD_BUS_ARGS("h", tty_fd),
957 SD_BUS_NO_RESULT,
958 method_set_tty,
959 SD_BUS_VTABLE_UNPRIVILEGED),
a6293b05
NK
960 SD_BUS_METHOD_WITH_ARGS("TakeDevice",
961 SD_BUS_ARGS("u", major, "u", minor),
962 SD_BUS_RESULT("h", fd, "b", inactive),
963 method_take_device,
964 SD_BUS_VTABLE_UNPRIVILEGED),
965 SD_BUS_METHOD_WITH_ARGS("ReleaseDevice",
966 SD_BUS_ARGS("u", major, "u", minor),
967 SD_BUS_NO_RESULT,
968 method_release_device,
969 SD_BUS_VTABLE_UNPRIVILEGED),
970 SD_BUS_METHOD_WITH_ARGS("PauseDeviceComplete",
971 SD_BUS_ARGS("u", major, "u", minor),
972 SD_BUS_NO_RESULT,
973 method_pause_device_complete,
974 SD_BUS_VTABLE_UNPRIVILEGED),
975 SD_BUS_METHOD_WITH_ARGS("SetBrightness",
976 SD_BUS_ARGS("s", subsystem, "s", name, "u", brightness),
977 SD_BUS_NO_RESULT,
978 method_set_brightness,
979 SD_BUS_VTABLE_UNPRIVILEGED),
980
981 SD_BUS_SIGNAL_WITH_ARGS("PauseDevice",
982 SD_BUS_ARGS("u", major, "u", minor, "s", type),
983 0),
984 SD_BUS_SIGNAL_WITH_ARGS("ResumeDevice",
985 SD_BUS_ARGS("u", major, "u", minor, "h", fd),
986 0),
c2b178d3
ZJS
987 SD_BUS_SIGNAL("Lock", NULL, 0),
988 SD_BUS_SIGNAL("Unlock", NULL, 0),
989
990 SD_BUS_VTABLE_END
991};
992
993const BusObjectImplementation session_object = {
994 "/org/freedesktop/login1/session",
995 "org.freedesktop.login1.Session",
996 .fallback_vtables = BUS_FALLBACK_VTABLES({session_vtable, session_object_find}),
997 .node_enumerator = session_node_enumerator,
998};