]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/core/dbus-scope.c
7b07bb8bb9c2cb77a32ea7206164c89256c46ab1
[thirdparty/systemd.git] / src / core / dbus-scope.c
1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
2
3 #include "alloc-util.h"
4 #include "bus-common-errors.h"
5 #include "bus-get-properties.h"
6 #include "dbus-cgroup.h"
7 #include "dbus-kill.h"
8 #include "dbus-manager.h"
9 #include "dbus-scope.h"
10 #include "dbus-unit.h"
11 #include "dbus-util.h"
12 #include "dbus.h"
13 #include "scope.h"
14 #include "selinux-access.h"
15 #include "unit.h"
16
17 int bus_scope_method_abandon(sd_bus_message *message, void *userdata, sd_bus_error *error) {
18 Scope *s = ASSERT_PTR(userdata);
19 int r;
20
21 assert(message);
22
23 r = mac_selinux_unit_access_check(UNIT(s), message, "stop", error);
24 if (r < 0)
25 return r;
26
27 r = bus_verify_manage_units_async(UNIT(s)->manager, message, error);
28 if (r < 0)
29 return r;
30 if (r == 0)
31 return 1; /* No authorization for now, but the async polkit stuff will call us again when it has it */
32
33 r = scope_abandon(s);
34 if (r == -ESTALE)
35 return sd_bus_error_setf(error, BUS_ERROR_SCOPE_NOT_RUNNING, "Scope %s is not running, cannot abandon.", UNIT(s)->id);
36 if (r < 0)
37 return r;
38
39 return sd_bus_reply_method_return(message, NULL);
40 }
41
42 static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_result, scope_result, ScopeResult);
43 static BUS_DEFINE_SET_TRANSIENT_PARSE(oom_policy, OOMPolicy, oom_policy_from_string);
44
45 const sd_bus_vtable bus_scope_vtable[] = {
46 SD_BUS_VTABLE_START(0),
47 SD_BUS_PROPERTY("Controller", "s", NULL, offsetof(Scope, controller), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
48 SD_BUS_PROPERTY("TimeoutStopUSec", "t", bus_property_get_usec, offsetof(Scope, timeout_stop_usec), SD_BUS_VTABLE_PROPERTY_CONST),
49 SD_BUS_PROPERTY("Result", "s", property_get_result, offsetof(Scope, result), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
50 SD_BUS_PROPERTY("RuntimeMaxUSec", "t", bus_property_get_usec, offsetof(Scope, runtime_max_usec), SD_BUS_VTABLE_PROPERTY_CONST),
51 SD_BUS_PROPERTY("RuntimeRandomizedExtraUSec", "t", bus_property_get_usec, offsetof(Scope, runtime_rand_extra_usec), SD_BUS_VTABLE_PROPERTY_CONST),
52 SD_BUS_PROPERTY("OOMPolicy", "s", bus_property_get_oom_policy, offsetof(Scope, oom_policy), SD_BUS_VTABLE_PROPERTY_CONST),
53 SD_BUS_SIGNAL("RequestStop", NULL, 0),
54 SD_BUS_METHOD("Abandon", NULL, NULL, bus_scope_method_abandon, SD_BUS_VTABLE_UNPRIVILEGED),
55 SD_BUS_VTABLE_END
56 };
57
58 static int bus_scope_set_transient_property(
59 Scope *s,
60 const char *name,
61 sd_bus_message *message,
62 UnitWriteFlags flags,
63 sd_bus_error *error) {
64
65 Unit *u = UNIT(s);
66 int r;
67
68 assert(s);
69 assert(name);
70 assert(message);
71
72 flags |= UNIT_PRIVATE;
73
74 if (streq(name, "TimeoutStopUSec"))
75 return bus_set_transient_usec(u, name, &s->timeout_stop_usec, message, flags, error);
76
77 if (streq(name, "RuntimeMaxUSec"))
78 return bus_set_transient_usec(u, name, &s->runtime_max_usec, message, flags, error);
79
80 if (streq(name, "RuntimeRandomizedExtraUSec"))
81 return bus_set_transient_usec(u, name, &s->runtime_rand_extra_usec, message, flags, error);
82
83 if (streq(name, "OOMPolicy"))
84 return bus_set_transient_oom_policy(u, name, &s->oom_policy, message, flags, error);
85
86 if (streq(name, "PIDs")) {
87 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
88 unsigned n = 0;
89
90 r = sd_bus_message_enter_container(message, 'a', "u");
91 if (r < 0)
92 return r;
93
94 for (;;) {
95 uint32_t upid;
96 pid_t pid;
97
98 r = sd_bus_message_read(message, "u", &upid);
99 if (r < 0)
100 return r;
101 if (r == 0)
102 break;
103
104 if (upid == 0) {
105 if (!creds) {
106 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_PID, &creds);
107 if (r < 0)
108 return r;
109 }
110
111 r = sd_bus_creds_get_pid(creds, &pid);
112 if (r < 0)
113 return r;
114 } else
115 pid = (uid_t) upid;
116
117 r = unit_pid_attachable(u, pid, error);
118 if (r < 0)
119 return r;
120
121 if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
122 r = unit_watch_pid(u, pid, false);
123 if (r < 0 && r != -EEXIST)
124 return r;
125 }
126
127 n++;
128 }
129
130 r = sd_bus_message_exit_container(message);
131 if (r < 0)
132 return r;
133
134 if (n <= 0)
135 return -EINVAL;
136
137 return 1;
138
139 } else if (streq(name, "Controller")) {
140 const char *controller;
141
142 /* We can't support direct connections with this, as direct connections know no service or unique name
143 * concept, but the Controller field stores exactly that. */
144 if (sd_bus_message_get_bus(message) != u->manager->api_bus)
145 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Sorry, Controller= logic only supported via the bus.");
146
147 r = sd_bus_message_read(message, "s", &controller);
148 if (r < 0)
149 return r;
150
151 if (!isempty(controller) && !sd_bus_service_name_is_valid(controller))
152 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Controller '%s' is not a valid bus name.", controller);
153
154 if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
155 r = free_and_strdup(&s->controller, empty_to_null(controller));
156 if (r < 0)
157 return r;
158 }
159
160 return 1;
161 }
162
163 return 0;
164 }
165
166 int bus_scope_set_property(
167 Unit *u,
168 const char *name,
169 sd_bus_message *message,
170 UnitWriteFlags flags,
171 sd_bus_error *error) {
172
173 Scope *s = SCOPE(u);
174 int r;
175
176 assert(s);
177 assert(name);
178 assert(message);
179
180 r = bus_cgroup_set_property(u, &s->cgroup_context, name, message, flags, error);
181 if (r != 0)
182 return r;
183
184 if (u->load_state == UNIT_STUB) {
185 /* While we are created we still accept PIDs */
186
187 r = bus_scope_set_transient_property(s, name, message, flags, error);
188 if (r != 0)
189 return r;
190
191 r = bus_kill_context_set_transient_property(u, &s->kill_context, name, message, flags, error);
192 if (r != 0)
193 return r;
194
195 if (streq(name, "User"))
196 return bus_set_transient_user_relaxed(u, name, &s->user, message, flags, error);
197
198 if (streq(name, "Group"))
199 return bus_set_transient_user_relaxed(u, name, &s->group, message, flags, error);
200 }
201
202 return 0;
203 }
204
205 int bus_scope_commit_properties(Unit *u) {
206 assert(u);
207
208 unit_realize_cgroup(u);
209
210 return 0;
211 }
212
213 int bus_scope_send_request_stop(Scope *s) {
214 _cleanup_(sd_bus_message_unrefp) sd_bus_message *m = NULL;
215 _cleanup_free_ char *p = NULL;
216 int r;
217
218 assert(s);
219
220 if (!s->controller)
221 return 0;
222
223 p = unit_dbus_path(UNIT(s));
224 if (!p)
225 return -ENOMEM;
226
227 r = sd_bus_message_new_signal(
228 UNIT(s)->manager->api_bus,
229 &m,
230 p,
231 "org.freedesktop.systemd1.Scope",
232 "RequestStop");
233 if (r < 0)
234 return r;
235
236 return sd_bus_send_to(UNIT(s)->manager->api_bus, m, s->controller, NULL);
237 }
238
239 static int on_controller_gone(sd_bus_track *track, void *userdata) {
240 Scope *s = userdata;
241
242 assert(track);
243
244 if (s->controller) {
245 log_unit_debug(UNIT(s), "Controller %s disappeared from bus.", s->controller);
246 unit_add_to_dbus_queue(UNIT(s));
247 s->controller = mfree(s->controller);
248 }
249
250 s->controller_track = sd_bus_track_unref(s->controller_track);
251
252 return 0;
253 }
254
255 int bus_scope_track_controller(Scope *s) {
256 int r;
257
258 assert(s);
259
260 if (!s->controller || s->controller_track)
261 return 0;
262
263 r = sd_bus_track_new(UNIT(s)->manager->api_bus, &s->controller_track, on_controller_gone, s);
264 if (r < 0)
265 return r;
266
267 r = sd_bus_track_add_name(s->controller_track, s->controller);
268 if (r < 0) {
269 s->controller_track = sd_bus_track_unref(s->controller_track);
270 return r;
271 }
272
273 return 0;
274 }