]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/login/logind-session-dbus.c
polkit: simplify bus_verify_polkit_async() + drop auth-by-cap dbus feature
[thirdparty/systemd.git] / src / login / logind-session-dbus.c
CommitLineData
db9ecf05 1/* SPDX-License-Identifier: LGPL-2.1-or-later */
3f49d45a
LP
2
3#include <errno.h>
4
b5efdb8a 5#include "alloc-util.h"
96aad8d1 6#include "bus-common-errors.h"
40af3d02 7#include "bus-get-properties.h"
a6278b88 8#include "bus-label.h"
269e4d2d 9#include "bus-polkit.h"
3ffd4af2 10#include "bus-util.h"
7176f06c 11#include "devnum-util.h"
3ffd4af2 12#include "fd-util.h"
2a66c2a1 13#include "logind-brightness.h"
6ecda0fb 14#include "logind-dbus.h"
7820a56c 15#include "logind-polkit.h"
6ecda0fb
LP
16#include "logind-seat-dbus.h"
17#include "logind-session-dbus.h"
118ecf32 18#include "logind-session-device.h"
3ffd4af2 19#include "logind-session.h"
6ecda0fb 20#include "logind-user-dbus.h"
3ffd4af2 21#include "logind.h"
36dd5ffd 22#include "missing_capability.h"
2a66c2a1 23#include "path-util.h"
6eb7c172 24#include "signal-util.h"
3ffd4af2 25#include "strv.h"
092e6cd1 26#include "terminal-util.h"
3b92c086 27#include "user-util.h"
3f49d45a 28
cc377381
LP
29static int property_get_user(
30 sd_bus *bus,
31 const char *path,
32 const char *interface,
33 const char *property,
34 sd_bus_message *reply,
ebcf1f97
LP
35 void *userdata,
36 sd_bus_error *error) {
cc377381
LP
37
38 _cleanup_free_ char *p = NULL;
99534007 39 Session *s = ASSERT_PTR(userdata);
cc377381
LP
40
41 assert(bus);
42 assert(reply);
3f49d45a 43
cc377381
LP
44 p = user_bus_path(s->user);
45 if (!p)
3f49d45a
LP
46 return -ENOMEM;
47
22c902fa 48 return sd_bus_message_append(reply, "(uo)", (uint32_t) s->user->user_record->uid, p);
cc377381 49}
3f49d45a 50
cc377381
LP
51static int property_get_name(
52 sd_bus *bus,
53 const char *path,
54 const char *interface,
55 const char *property,
56 sd_bus_message *reply,
ebcf1f97
LP
57 void *userdata,
58 sd_bus_error *error) {
3f49d45a 59
99534007 60 Session *s = ASSERT_PTR(userdata);
3f49d45a 61
cc377381
LP
62 assert(bus);
63 assert(reply);
3f49d45a 64
22c902fa 65 return sd_bus_message_append(reply, "s", s->user->user_record->user_name);
3f49d45a
LP
66}
67
cc377381
LP
68static int property_get_seat(
69 sd_bus *bus,
70 const char *path,
71 const char *interface,
72 const char *property,
73 sd_bus_message *reply,
ebcf1f97
LP
74 void *userdata,
75 sd_bus_error *error) {
3f49d45a 76
cc377381 77 _cleanup_free_ char *p = NULL;
99534007 78 Session *s = ASSERT_PTR(userdata);
3f49d45a 79
cc377381
LP
80 assert(bus);
81 assert(reply);
3f49d45a 82
cc377381 83 p = s->seat ? seat_bus_path(s->seat) : strdup("/");
3f49d45a
LP
84 if (!p)
85 return -ENOMEM;
86
cc377381
LP
87 return sd_bus_message_append(reply, "(so)", s->seat ? s->seat->id : "", p);
88}
3f49d45a 89
cc377381
LP
90static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_type, session_type, SessionType);
91static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_class, session_class, SessionClass);
01adcd69
YW
92static BUS_DEFINE_PROPERTY_GET(property_get_active, "b", Session, session_is_active);
93static BUS_DEFINE_PROPERTY_GET2(property_get_state, "s", Session, session_get_state, session_state_to_string);
cc377381
LP
94
95static int property_get_idle_hint(
96 sd_bus *bus,
97 const char *path,
98 const char *interface,
99 const char *property,
100 sd_bus_message *reply,
ebcf1f97
LP
101 void *userdata,
102 sd_bus_error *error) {
a185c5aa 103
99534007 104 Session *s = ASSERT_PTR(userdata);
cc377381
LP
105
106 assert(bus);
107 assert(reply);
cc377381
LP
108
109 return sd_bus_message_append(reply, "b", session_get_idle_hint(s, NULL) > 0);
a185c5aa
LP
110}
111
cc377381
LP
112static int property_get_idle_since_hint(
113 sd_bus *bus,
114 const char *path,
115 const char *interface,
116 const char *property,
117 sd_bus_message *reply,
ebcf1f97
LP
118 void *userdata,
119 sd_bus_error *error) {
cc377381 120
99534007 121 Session *s = ASSERT_PTR(userdata);
5cb14b37 122 dual_timestamp t = DUAL_TIMESTAMP_NULL;
a185c5aa 123 uint64_t u;
ca4f2b6d 124 int r;
a185c5aa 125
cc377381
LP
126 assert(bus);
127 assert(reply);
a185c5aa 128
ca4f2b6d
VP
129 r = session_get_idle_hint(s, &t);
130 if (r < 0)
131 return r;
132
a185c5aa
LP
133 u = streq(property, "IdleSinceHint") ? t.realtime : t.monotonic;
134
cc377381 135 return sd_bus_message_append(reply, "t", u);
a185c5aa
LP
136}
137
42d35e13
VT
138static int property_get_locked_hint(
139 sd_bus *bus,
140 const char *path,
141 const char *interface,
142 const char *property,
143 sd_bus_message *reply,
144 void *userdata,
145 sd_bus_error *error) {
146
99534007 147 Session *s = ASSERT_PTR(userdata);
42d35e13
VT
148
149 assert(bus);
150 assert(reply);
42d35e13
VT
151
152 return sd_bus_message_append(reply, "b", session_get_locked_hint(s) > 0);
153}
154
19070062 155int bus_session_method_terminate(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 156 Session *s = ASSERT_PTR(userdata);
cc377381 157 int r;
0604381b 158
cc377381 159 assert(message);
0604381b 160
7b36fb9f 161 r = bus_verify_polkit_async_full(
c529695e 162 message,
c529695e 163 "org.freedesktop.login1.manage",
7b36fb9f
LP
164 /* details= */ NULL,
165 /* interactive= */ false,
22c902fa 166 s->user->user_record->uid,
c529695e
LP
167 &s->manager->polkit_registry,
168 error);
169 if (r < 0)
170 return r;
171 if (r == 0)
172 return 1; /* Will call us back */
173
bda62573 174 r = session_stop(s, /* force = */ true);
cc377381 175 if (r < 0)
ebcf1f97 176 return r;
0604381b 177
df2d202e 178 return sd_bus_reply_method_return(message, NULL);
0604381b
LP
179}
180
19070062 181int bus_session_method_activate(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 182 Session *s = ASSERT_PTR(userdata);
cc377381 183 int r;
3f49d45a 184
cc377381 185 assert(message);
3f49d45a 186
7820a56c 187 r = check_polkit_chvt(message, s->manager, error);
4acf0cfd
LP
188 if (r < 0)
189 return r;
190 if (r == 0)
191 return 1; /* Will call us back */
192
cc377381
LP
193 r = session_activate(s);
194 if (r < 0)
ebcf1f97 195 return r;
3f49d45a 196
df2d202e 197 return sd_bus_reply_method_return(message, NULL);
cc377381
LP
198}
199
19070062 200int bus_session_method_lock(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 201 Session *s = ASSERT_PTR(userdata);
cc377381
LP
202 int r;
203
cc377381 204 assert(message);
3f49d45a 205
7b36fb9f 206 r = bus_verify_polkit_async_full(
c529695e 207 message,
c529695e 208 "org.freedesktop.login1.lock-sessions",
7b36fb9f
LP
209 /* details= */ NULL,
210 /* interactive= */ false,
22c902fa 211 s->user->user_record->uid,
c529695e
LP
212 &s->manager->polkit_registry,
213 error);
214 if (r < 0)
215 return r;
216 if (r == 0)
217 return 1; /* Will call us back */
218
219 r = session_send_lock(s, strstr(sd_bus_message_get_member(message), "Lock"));
cc377381 220 if (r < 0)
ebcf1f97 221 return r;
3f49d45a 222
df2d202e 223 return sd_bus_reply_method_return(message, NULL);
3f49d45a
LP
224}
225
19070062 226static int method_set_idle_hint(sd_bus_message *message, void *userdata, sd_bus_error *error) {
4afd3348 227 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
99534007 228 Session *s = ASSERT_PTR(userdata);
cc377381
LP
229 uid_t uid;
230 int r, b;
d200735e 231
cc377381 232 assert(message);
cc377381
LP
233
234 r = sd_bus_message_read(message, "b", &b);
235 if (r < 0)
ebcf1f97 236 return r;
d200735e 237
05bae4a6 238 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
5b12334d
LP
239 if (r < 0)
240 return r;
241
05bae4a6 242 r = sd_bus_creds_get_euid(creds, &uid);
cc377381 243 if (r < 0)
ebcf1f97 244 return r;
cc377381 245
22c902fa 246 if (uid != 0 && uid != s->user->user_record->uid)
1b09b81c 247 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may set idle hint");
cc377381 248
be2bb14f
LP
249 r = session_set_idle_hint(s, b);
250 if (r == -ENOTTY)
1b09b81c 251 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Idle hint control is not supported on non-graphical sessions.");
be2bb14f
LP
252 if (r < 0)
253 return r;
3f49d45a 254
df2d202e 255 return sd_bus_reply_method_return(message, NULL);
cc377381
LP
256}
257
42d35e13
VT
258static int method_set_locked_hint(sd_bus_message *message, void *userdata, sd_bus_error *error) {
259 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
99534007 260 Session *s = ASSERT_PTR(userdata);
42d35e13
VT
261 uid_t uid;
262 int r, b;
263
264 assert(message);
42d35e13
VT
265
266 r = sd_bus_message_read(message, "b", &b);
267 if (r < 0)
268 return r;
269
270 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
271 if (r < 0)
272 return r;
273
274 r = sd_bus_creds_get_euid(creds, &uid);
275 if (r < 0)
276 return r;
277
22c902fa 278 if (uid != 0 && uid != s->user->user_record->uid)
1b09b81c 279 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may set locked hint");
42d35e13
VT
280
281 session_set_locked_hint(s, b);
282
283 return sd_bus_reply_method_return(message, NULL);
284}
285
19070062 286int bus_session_method_kill(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 287 Session *s = ASSERT_PTR(userdata);
cc377381
LP
288 const char *swho;
289 int32_t signo;
290 KillWho who;
bef422ae
LP
291 int r;
292
3f49d45a
LP
293 assert(message);
294
cc377381
LP
295 r = sd_bus_message_read(message, "si", &swho, &signo);
296 if (r < 0)
ebcf1f97 297 return r;
cc377381
LP
298
299 if (isempty(swho))
300 who = KILL_ALL;
301 else {
302 who = kill_who_from_string(swho);
303 if (who < 0)
ebcf1f97 304 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid kill parameter '%s'", swho);
cc377381 305 }
bef422ae 306
6eb7c172 307 if (!SIGNAL_VALID(signo))
ebcf1f97 308 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Invalid signal %i", signo);
bef422ae 309
7b36fb9f 310 r = bus_verify_polkit_async_full(
c529695e 311 message,
c529695e 312 "org.freedesktop.login1.manage",
7b36fb9f
LP
313 /* details= */ NULL,
314 /* interactive= */ false,
22c902fa 315 s->user->user_record->uid,
c529695e
LP
316 &s->manager->polkit_registry,
317 error);
318 if (r < 0)
319 return r;
320 if (r == 0)
321 return 1; /* Will call us back */
322
cc377381
LP
323 r = session_kill(s, who, signo);
324 if (r < 0)
ebcf1f97 325 return r;
bef422ae 326
df2d202e 327 return sd_bus_reply_method_return(message, NULL);
cc377381 328}
bef422ae 329
19070062 330static int method_take_control(sd_bus_message *message, void *userdata, sd_bus_error *error) {
4afd3348 331 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
99534007 332 Session *s = ASSERT_PTR(userdata);
cc377381
LP
333 int r, force;
334 uid_t uid;
bef422ae 335
cc377381 336 assert(message);
bef422ae 337
cc377381
LP
338 r = sd_bus_message_read(message, "b", &force);
339 if (r < 0)
ebcf1f97 340 return r;
bef422ae 341
05bae4a6 342 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
5b12334d
LP
343 if (r < 0)
344 return r;
345
05bae4a6 346 r = sd_bus_creds_get_euid(creds, &uid);
cc377381 347 if (r < 0)
ebcf1f97 348 return r;
bef422ae 349
22c902fa 350 if (uid != 0 && (force || uid != s->user->user_record->uid))
1b09b81c 351 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may take control");
bef422ae 352
dc6284e9 353 r = session_set_controller(s, sd_bus_message_get_sender(message), force, true);
cc377381 354 if (r < 0)
ebcf1f97 355 return r;
bef422ae 356
df2d202e 357 return sd_bus_reply_method_return(message, NULL);
cc377381 358}
bef422ae 359
19070062 360static int method_release_control(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 361 Session *s = ASSERT_PTR(userdata);
bef422ae 362
cc377381 363 assert(message);
5bc849fd 364
cc377381 365 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 366 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
5bc849fd 367
cc377381 368 session_drop_controller(s);
bef422ae 369
df2d202e 370 return sd_bus_reply_method_return(message, NULL);
cc377381 371}
bef422ae 372
db72aea4 373static int method_set_type(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 374 Session *s = ASSERT_PTR(userdata);
db72aea4
CH
375 const char *t;
376 SessionType type;
377 int r;
378
379 assert(message);
db72aea4
CH
380
381 r = sd_bus_message_read(message, "s", &t);
382 if (r < 0)
383 return r;
384
385 type = session_type_from_string(t);
386 if (type < 0)
387 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS,
388 "Invalid session type '%s'", t);
389
390 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 391 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You must be in control of this session to set type");
db72aea4
CH
392
393 session_set_type(s, type);
394
395 return sd_bus_reply_method_return(message, NULL);
396}
397
4885d749
DT
398static int method_set_display(sd_bus_message *message, void *userdata, sd_bus_error *error) {
399 Session *s = ASSERT_PTR(userdata);
400 const char *display;
401 int r;
402
403 assert(message);
404
405 r = sd_bus_message_read(message, "s", &display);
406 if (r < 0)
407 return r;
408
409 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
410 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You must be in control of this session to set display");
411
412 if (!SESSION_TYPE_IS_GRAPHICAL(s->type))
413 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Setting display is only supported for graphical sessions");
414
415 r = session_set_display(s, display);
416 if (r < 0)
417 return r;
418
419 return sd_bus_reply_method_return(message, NULL);
420}
421
092e6cd1
TK
422static int method_set_tty(sd_bus_message *message, void *userdata, sd_bus_error *error) {
423 Session *s = ASSERT_PTR(userdata);
424 int fd, r, flags;
425 _cleanup_free_ char *q = NULL;
426
427 assert(message);
428
429 r = sd_bus_message_read(message, "h", &fd);
430 if (r < 0)
431 return r;
432
433 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
434 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You must be in control of this session to set tty");
435
436 assert(fd >= 0);
437
438 flags = fcntl(fd, F_GETFL, 0);
439 if (flags < 0)
440 return -errno;
441 if ((flags & O_ACCMODE) != O_RDWR)
442 return -EACCES;
443 if (FLAGS_SET(flags, O_PATH))
444 return -ENOTTY;
445
446 r = getttyname_malloc(fd, &q);
447 if (r < 0)
448 return r;
449
450 r = session_set_tty(s, q);
451 if (r < 0)
452 return r;
453
454 return sd_bus_reply_method_return(message, NULL);
455}
456
19070062 457static int method_take_device(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 458 Session *s = ASSERT_PTR(userdata);
cc377381 459 uint32_t major, minor;
360179ea 460 _cleanup_(session_device_freep) SessionDevice *sd = NULL;
cc377381
LP
461 dev_t dev;
462 int r;
de07ab16 463
cc377381 464 assert(message);
de07ab16 465
cc377381
LP
466 r = sd_bus_message_read(message, "uu", &major, &minor);
467 if (r < 0)
ebcf1f97 468 return r;
cc377381 469
fa583ab1 470 if (!DEVICE_MAJOR_VALID(major) || !DEVICE_MINOR_VALID(minor))
1b09b81c 471 return sd_bus_error_set(error, SD_BUS_ERROR_INVALID_ARGS, "Device major/minor is not valid.");
fa583ab1 472
cc377381 473 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 474 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
cc377381
LP
475
476 dev = makedev(major, minor);
477 sd = hashmap_get(s->devices, &dev);
478 if (sd)
479 /* We don't allow retrieving a device multiple times.
480 * The related ReleaseDevice call is not ref-counted.
481 * The caller should use dup() if it requires more
482 * than one fd (it would be functionally
483 * equivalent). */
1b09b81c 484 return sd_bus_error_set(error, BUS_ERROR_DEVICE_IS_TAKEN, "Device already taken");
cc377381 485
aed24c4c 486 r = session_device_new(s, dev, true, &sd);
cc377381 487 if (r < 0)
ebcf1f97 488 return r;
de07ab16 489
aed24c4c
FB
490 r = session_device_save(sd);
491 if (r < 0)
360179ea 492 return r;
aed24c4c 493
df2d202e 494 r = sd_bus_reply_method_return(message, "hb", sd->fd, !sd->active);
cc377381 495 if (r < 0)
360179ea 496 return r;
aed24c4c
FB
497
498 session_save(s);
360179ea 499 TAKE_PTR(sd);
118ecf32 500
360179ea 501 return 1;
cc377381 502}
118ecf32 503
19070062 504static int method_release_device(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 505 Session *s = ASSERT_PTR(userdata);
cc377381
LP
506 uint32_t major, minor;
507 SessionDevice *sd;
508 dev_t dev;
509 int r;
118ecf32 510
cc377381 511 assert(message);
118ecf32 512
cc377381
LP
513 r = sd_bus_message_read(message, "uu", &major, &minor);
514 if (r < 0)
ebcf1f97 515 return r;
118ecf32 516
fa583ab1 517 if (!DEVICE_MAJOR_VALID(major) || !DEVICE_MINOR_VALID(minor))
1b09b81c 518 return sd_bus_error_set(error, SD_BUS_ERROR_INVALID_ARGS, "Device major/minor is not valid.");
fa583ab1 519
cc377381 520 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 521 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
118ecf32 522
cc377381
LP
523 dev = makedev(major, minor);
524 sd = hashmap_get(s->devices, &dev);
525 if (!sd)
1b09b81c 526 return sd_bus_error_set(error, BUS_ERROR_DEVICE_NOT_TAKEN, "Device not taken");
118ecf32 527
cc377381 528 session_device_free(sd);
aed24c4c
FB
529 session_save(s);
530
df2d202e 531 return sd_bus_reply_method_return(message, NULL);
cc377381 532}
118ecf32 533
19070062 534static int method_pause_device_complete(sd_bus_message *message, void *userdata, sd_bus_error *error) {
99534007 535 Session *s = ASSERT_PTR(userdata);
cc377381
LP
536 uint32_t major, minor;
537 SessionDevice *sd;
538 dev_t dev;
539 int r;
118ecf32 540
cc377381 541 assert(message);
bef422ae 542
cc377381
LP
543 r = sd_bus_message_read(message, "uu", &major, &minor);
544 if (r < 0)
ebcf1f97 545 return r;
cc377381 546
fa583ab1 547 if (!DEVICE_MAJOR_VALID(major) || !DEVICE_MINOR_VALID(minor))
1b09b81c 548 return sd_bus_error_set(error, SD_BUS_ERROR_INVALID_ARGS, "Device major/minor is not valid.");
fa583ab1 549
cc377381 550 if (!session_is_controller(s, sd_bus_message_get_sender(message)))
1b09b81c 551 return sd_bus_error_set(error, BUS_ERROR_NOT_IN_CONTROL, "You are not in control of this session");
bef422ae 552
cc377381
LP
553 dev = makedev(major, minor);
554 sd = hashmap_get(s->devices, &dev);
555 if (!sd)
1b09b81c 556 return sd_bus_error_set(error, BUS_ERROR_DEVICE_NOT_TAKEN, "Device not taken");
bef422ae 557
cc377381 558 session_device_complete_pause(sd);
bef422ae 559
df2d202e 560 return sd_bus_reply_method_return(message, NULL);
3f49d45a
LP
561}
562
2a66c2a1
LP
563static int method_set_brightness(sd_bus_message *message, void *userdata, sd_bus_error *error) {
564 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
565 _cleanup_(sd_device_unrefp) sd_device *d = NULL;
566 const char *subsystem, *name, *seat;
99534007 567 Session *s = ASSERT_PTR(userdata);
2a66c2a1
LP
568 uint32_t brightness;
569 uid_t uid;
570 int r;
571
572 assert(message);
2a66c2a1
LP
573
574 r = sd_bus_message_read(message, "ssu", &subsystem, &name, &brightness);
575 if (r < 0)
576 return r;
577
578 if (!STR_IN_SET(subsystem, "backlight", "leds"))
579 return sd_bus_error_setf(error, SD_BUS_ERROR_NOT_SUPPORTED, "Subsystem type %s not supported, must be one of 'backlight' or 'leds'.", subsystem);
580 if (!filename_is_valid(name))
581 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Not a valid device name %s, refusing.", name);
582
583 if (!s->seat)
1b09b81c 584 return sd_bus_error_set(error, BUS_ERROR_NOT_YOUR_DEVICE, "Your session has no seat, refusing.");
2a66c2a1 585 if (s->seat->active != s)
1b09b81c 586 return sd_bus_error_set(error, BUS_ERROR_NOT_YOUR_DEVICE, "Session is not in foreground, refusing.");
2a66c2a1
LP
587
588 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
589 if (r < 0)
590 return r;
591
592 r = sd_bus_creds_get_euid(creds, &uid);
593 if (r < 0)
594 return r;
595
22c902fa 596 if (uid != 0 && uid != s->user->user_record->uid)
1b09b81c 597 return sd_bus_error_set(error, SD_BUS_ERROR_ACCESS_DENIED, "Only owner of session may change brightness.");
2a66c2a1
LP
598
599 r = sd_device_new_from_subsystem_sysname(&d, subsystem, name);
600 if (r < 0)
601 return sd_bus_error_set_errnof(error, r, "Failed to open device %s:%s: %m", subsystem, name);
602
603 if (sd_device_get_property_value(d, "ID_SEAT", &seat) >= 0 && !streq_ptr(seat, s->seat->id))
604 return sd_bus_error_setf(error, BUS_ERROR_NOT_YOUR_DEVICE, "Device %s:%s does not belong to your seat %s, refusing.", subsystem, name, s->seat->id);
605
606 r = manager_write_brightness(s->manager, d, brightness, message);
607 if (r < 0)
608 return r;
609
610 return 1;
611}
612
c2b178d3 613static int session_object_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
3b92c086
LP
614 _cleanup_free_ char *e = NULL;
615 sd_bus_message *message;
99534007 616 Manager *m = ASSERT_PTR(userdata);
cc377381 617 Session *session;
3b92c086 618 const char *p;
927b1649 619 int r;
3f49d45a 620
cc377381
LP
621 assert(bus);
622 assert(path);
623 assert(interface);
624 assert(found);
3f49d45a 625
3b92c086
LP
626 p = startswith(path, "/org/freedesktop/login1/session/");
627 if (!p)
628 return 0;
3f49d45a 629
3b92c086
LP
630 e = bus_label_unescape(p);
631 if (!e)
632 return -ENOMEM;
927b1649 633
3b92c086 634 message = sd_bus_get_current_message(bus);
927b1649 635
3b92c086
LP
636 r = manager_get_session_from_creds(m, message, e, error, &session);
637 if (r == -ENXIO) {
638 sd_bus_error_free(error);
639 return 0;
927b1649 640 }
3b92c086
LP
641 if (r < 0)
642 return r;
3f49d45a 643
cc377381
LP
644 *found = session;
645 return 1;
3f49d45a
LP
646}
647
3f49d45a 648char *session_bus_path(Session *s) {
9444b1f2 649 _cleanup_free_ char *t = NULL;
3f49d45a
LP
650
651 assert(s);
652
a6278b88 653 t = bus_label_escape(s->id);
3f49d45a
LP
654 if (!t)
655 return NULL;
656
b910cc72 657 return strjoin("/org/freedesktop/login1/session/", t);
3f49d45a 658}
da119395 659
c2b178d3 660static int session_node_enumerator(sd_bus *bus, const char *path, void *userdata, char ***nodes, sd_bus_error *error) {
cc377381 661 _cleanup_strv_free_ char **l = NULL;
ca56b0a6 662 sd_bus_message *message;
cc377381
LP
663 Manager *m = userdata;
664 Session *session;
cc377381
LP
665 int r;
666
667 assert(bus);
668 assert(path);
669 assert(nodes);
670
90e74a66 671 HASHMAP_FOREACH(session, m->sessions) {
cc377381
LP
672 char *p;
673
674 p = session_bus_path(session);
675 if (!p)
676 return -ENOMEM;
677
6e18964d
ZJS
678 r = strv_consume(&l, p);
679 if (r < 0)
cc377381 680 return r;
cc377381
LP
681 }
682
ca56b0a6
DH
683 message = sd_bus_get_current_message(bus);
684 if (message) {
4afd3348 685 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
ca56b0a6 686
3b92c086 687 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_SESSION|SD_BUS_CREDS_OWNER_UID|SD_BUS_CREDS_AUGMENT, &creds);
ca56b0a6 688 if (r >= 0) {
3b92c086
LP
689 bool may_auto = false;
690 const char *name;
691
ca56b0a6
DH
692 r = sd_bus_creds_get_session(creds, &name);
693 if (r >= 0) {
694 session = hashmap_get(m->sessions, name);
695 if (session) {
696 r = strv_extend(&l, "/org/freedesktop/login1/session/self");
697 if (r < 0)
698 return r;
3b92c086
LP
699
700 may_auto = true;
701 }
702 }
703
704 if (!may_auto) {
705 uid_t uid;
706
707 r = sd_bus_creds_get_owner_uid(creds, &uid);
708 if (r >= 0) {
709 User *user;
710
711 user = hashmap_get(m->users, UID_TO_PTR(uid));
712 may_auto = user && user->display;
ca56b0a6
DH
713 }
714 }
3b92c086
LP
715
716 if (may_auto) {
717 r = strv_extend(&l, "/org/freedesktop/login1/session/auto");
718 if (r < 0)
719 return r;
720 }
ca56b0a6
DH
721 }
722 }
b298e984 723
1cc6c93a 724 *nodes = TAKE_PTR(l);
cc377381
LP
725 return 1;
726}
727
da119395 728int session_send_signal(Session *s, bool new_session) {
ce0fc5f5 729 _cleanup_free_ char *p = NULL;
da119395
LP
730
731 assert(s);
732
da119395
LP
733 p = session_bus_path(s);
734 if (!p)
4654e558 735 return -ENOMEM;
da119395 736
cc377381
LP
737 return sd_bus_emit_signal(
738 s->manager->bus,
739 "/org/freedesktop/login1",
740 "org.freedesktop.login1.Manager",
741 new_session ? "SessionNew" : "SessionRemoved",
742 "so", s->id, p);
da119395 743}
9418f147 744
cc377381 745int session_send_changed(Session *s, const char *properties, ...) {
ce0fc5f5 746 _cleanup_free_ char *p = NULL;
cc377381 747 char **l;
9418f147
LP
748
749 assert(s);
750
ed18b08b
LP
751 if (!s->started)
752 return 0;
753
9418f147
LP
754 p = session_bus_path(s);
755 if (!p)
756 return -ENOMEM;
757
cc377381 758 l = strv_from_stdarg_alloca(properties);
9418f147 759
cc377381 760 return sd_bus_emit_properties_changed_strv(s->manager->bus, p, "org.freedesktop.login1.Session", l);
9418f147 761}
88e3dc90
LP
762
763int session_send_lock(Session *s, bool lock) {
ce0fc5f5 764 _cleanup_free_ char *p = NULL;
88e3dc90
LP
765
766 assert(s);
767
768 p = session_bus_path(s);
769 if (!p)
770 return -ENOMEM;
771
cc377381
LP
772 return sd_bus_emit_signal(
773 s->manager->bus,
774 p,
775 "org.freedesktop.login1.Session",
776 lock ? "Lock" : "Unlock",
777 NULL);
88e3dc90 778}
7ba64386
LP
779
780int session_send_lock_all(Manager *m, bool lock) {
781 Session *session;
7ba64386
LP
782 int r = 0;
783
784 assert(m);
785
90e74a66 786 HASHMAP_FOREACH(session, m->sessions) {
7ba64386
LP
787 int k;
788
789 k = session_send_lock(session, lock);
790 if (k < 0)
791 r = k;
792 }
793
794 return r;
795}
fb6becb4 796
b1951bc8
LP
797static bool session_ready(Session *s) {
798 assert(s);
799
800 /* Returns true when the session is ready, i.e. all jobs we enqueued for it are done (regardless if successful or not) */
801
802 return !s->scope_job &&
803 !s->user->service_job;
804}
805
cc377381 806int session_send_create_reply(Session *s, sd_bus_error *error) {
4afd3348 807 _cleanup_(sd_bus_message_unrefp) sd_bus_message *c = NULL;
254d1313 808 _cleanup_close_ int fifo_fd = -EBADF;
cc377381 809 _cleanup_free_ char *p = NULL;
76f2191d 810 int r;
fb6becb4
LP
811
812 assert(s);
813
b1951bc8 814 /* This is called after the session scope and the user service were successfully created, and finishes where
dd9b67aa 815 * bus_manager_create_session() left off. */
cba38758 816
cc377381
LP
817 if (!s->create_message)
818 return 0;
fb6becb4 819
b1951bc8 820 if (!sd_bus_error_is_set(error) && !session_ready(s))
dd9b67aa
LP
821 return 0;
822
1b88ed3b 823 c = TAKE_PTR(s->create_message);
cc377381 824 if (error)
df2d202e 825 return sd_bus_reply_method_error(c, error);
fb6becb4 826
cc377381
LP
827 fifo_fd = session_create_fifo(s);
828 if (fifo_fd < 0)
829 return fifo_fd;
fb6becb4 830
76f2191d
MS
831 r = session_watch_pidfd(s);
832 if (r < 0)
833 return r;
834
b1951bc8 835 /* Update the session state file before we notify the client about the result. */
38fdcbed
TA
836 session_save(s);
837
cc377381
LP
838 p = session_bus_path(s);
839 if (!p)
840 return -ENOMEM;
fb6becb4 841
5a330cda 842 log_debug("Sending reply about created session: "
236af516
DH
843 "id=%s object_path=%s uid=%u runtime_path=%s "
844 "session_fd=%d seat=%s vtnr=%u",
5a330cda
ZJS
845 s->id,
846 p,
22c902fa 847 (uint32_t) s->user->user_record->uid,
5a330cda
ZJS
848 s->user->runtime_path,
849 fifo_fd,
850 s->seat ? s->seat->id : "",
851 (uint32_t) s->vtnr);
852
cc377381 853 return sd_bus_reply_method_return(
baae0358 854 c, "soshusub",
cc377381
LP
855 s->id,
856 p,
857 s->user->runtime_path,
858 fifo_fd,
22c902fa 859 (uint32_t) s->user->user_record->uid,
cc377381
LP
860 s->seat ? s->seat->id : "",
861 (uint32_t) s->vtnr,
862 false);
fb6becb4 863}
c2b178d3
ZJS
864
865static const sd_bus_vtable session_vtable[] = {
866 SD_BUS_VTABLE_START(0),
867
868 SD_BUS_PROPERTY("Id", "s", NULL, offsetof(Session, id), SD_BUS_VTABLE_PROPERTY_CONST),
869 SD_BUS_PROPERTY("User", "(uo)", property_get_user, 0, SD_BUS_VTABLE_PROPERTY_CONST),
870 SD_BUS_PROPERTY("Name", "s", property_get_name, 0, SD_BUS_VTABLE_PROPERTY_CONST),
871 BUS_PROPERTY_DUAL_TIMESTAMP("Timestamp", offsetof(Session, timestamp), SD_BUS_VTABLE_PROPERTY_CONST),
872 SD_BUS_PROPERTY("VTNr", "u", NULL, offsetof(Session, vtnr), SD_BUS_VTABLE_PROPERTY_CONST),
873 SD_BUS_PROPERTY("Seat", "(so)", property_get_seat, 0, SD_BUS_VTABLE_PROPERTY_CONST),
f1e02423 874 SD_BUS_PROPERTY("TTY", "s", NULL, offsetof(Session, tty), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
236cb016 875 SD_BUS_PROPERTY("Display", "s", NULL, offsetof(Session, display), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
c2b178d3
ZJS
876 SD_BUS_PROPERTY("Remote", "b", bus_property_get_bool, offsetof(Session, remote), SD_BUS_VTABLE_PROPERTY_CONST),
877 SD_BUS_PROPERTY("RemoteHost", "s", NULL, offsetof(Session, remote_host), SD_BUS_VTABLE_PROPERTY_CONST),
878 SD_BUS_PROPERTY("RemoteUser", "s", NULL, offsetof(Session, remote_user), SD_BUS_VTABLE_PROPERTY_CONST),
879 SD_BUS_PROPERTY("Service", "s", NULL, offsetof(Session, service), SD_BUS_VTABLE_PROPERTY_CONST),
880 SD_BUS_PROPERTY("Desktop", "s", NULL, offsetof(Session, desktop), SD_BUS_VTABLE_PROPERTY_CONST),
881 SD_BUS_PROPERTY("Scope", "s", NULL, offsetof(Session, scope), SD_BUS_VTABLE_PROPERTY_CONST),
89bad70f 882 SD_BUS_PROPERTY("Leader", "u", bus_property_get_pid, offsetof(Session, leader.pid), SD_BUS_VTABLE_PROPERTY_CONST),
c2b178d3
ZJS
883 SD_BUS_PROPERTY("Audit", "u", NULL, offsetof(Session, audit_id), SD_BUS_VTABLE_PROPERTY_CONST),
884 SD_BUS_PROPERTY("Type", "s", property_get_type, offsetof(Session, type), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
885 SD_BUS_PROPERTY("Class", "s", property_get_class, offsetof(Session, class), SD_BUS_VTABLE_PROPERTY_CONST),
886 SD_BUS_PROPERTY("Active", "b", property_get_active, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
887 SD_BUS_PROPERTY("State", "s", property_get_state, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
888 SD_BUS_PROPERTY("IdleHint", "b", property_get_idle_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
889 SD_BUS_PROPERTY("IdleSinceHint", "t", property_get_idle_since_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
890 SD_BUS_PROPERTY("IdleSinceHintMonotonic", "t", property_get_idle_since_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
891 SD_BUS_PROPERTY("LockedHint", "b", property_get_locked_hint, 0, SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
892
893 SD_BUS_METHOD("Terminate",
894 NULL,
895 NULL,
896 bus_session_method_terminate,
897 SD_BUS_VTABLE_UNPRIVILEGED),
898 SD_BUS_METHOD("Activate",
899 NULL,
900 NULL,
901 bus_session_method_activate,
902 SD_BUS_VTABLE_UNPRIVILEGED),
903 SD_BUS_METHOD("Lock",
904 NULL,
905 NULL,
906 bus_session_method_lock,
907 SD_BUS_VTABLE_UNPRIVILEGED),
908 SD_BUS_METHOD("Unlock",
909 NULL,
910 NULL,
911 bus_session_method_lock,
912 SD_BUS_VTABLE_UNPRIVILEGED),
a6293b05
NK
913 SD_BUS_METHOD_WITH_ARGS("SetIdleHint",
914 SD_BUS_ARGS("b", idle),
915 SD_BUS_NO_RESULT,
916 method_set_idle_hint,
917 SD_BUS_VTABLE_UNPRIVILEGED),
918 SD_BUS_METHOD_WITH_ARGS("SetLockedHint",
919 SD_BUS_ARGS("b", locked),
920 SD_BUS_NO_RESULT,
921 method_set_locked_hint,
922 SD_BUS_VTABLE_UNPRIVILEGED),
923 SD_BUS_METHOD_WITH_ARGS("Kill",
924 SD_BUS_ARGS("s", who, "i", signal_number),
925 SD_BUS_NO_RESULT,
926 bus_session_method_kill,
927 SD_BUS_VTABLE_UNPRIVILEGED),
928 SD_BUS_METHOD_WITH_ARGS("TakeControl",
929 SD_BUS_ARGS("b", force),
930 SD_BUS_NO_RESULT,
931 method_take_control,
932 SD_BUS_VTABLE_UNPRIVILEGED),
c2b178d3
ZJS
933 SD_BUS_METHOD("ReleaseControl",
934 NULL,
935 NULL,
936 method_release_control,
937 SD_BUS_VTABLE_UNPRIVILEGED),
a6293b05
NK
938 SD_BUS_METHOD_WITH_ARGS("SetType",
939 SD_BUS_ARGS("s", type),
940 SD_BUS_NO_RESULT,
941 method_set_type,
942 SD_BUS_VTABLE_UNPRIVILEGED),
4885d749
DT
943 SD_BUS_METHOD_WITH_ARGS("SetDisplay",
944 SD_BUS_ARGS("s", display),
945 SD_BUS_NO_RESULT,
946 method_set_display,
947 SD_BUS_VTABLE_UNPRIVILEGED),
092e6cd1
TK
948 SD_BUS_METHOD_WITH_ARGS("SetTTY",
949 SD_BUS_ARGS("h", tty_fd),
950 SD_BUS_NO_RESULT,
951 method_set_tty,
952 SD_BUS_VTABLE_UNPRIVILEGED),
a6293b05
NK
953 SD_BUS_METHOD_WITH_ARGS("TakeDevice",
954 SD_BUS_ARGS("u", major, "u", minor),
955 SD_BUS_RESULT("h", fd, "b", inactive),
956 method_take_device,
957 SD_BUS_VTABLE_UNPRIVILEGED),
958 SD_BUS_METHOD_WITH_ARGS("ReleaseDevice",
959 SD_BUS_ARGS("u", major, "u", minor),
960 SD_BUS_NO_RESULT,
961 method_release_device,
962 SD_BUS_VTABLE_UNPRIVILEGED),
963 SD_BUS_METHOD_WITH_ARGS("PauseDeviceComplete",
964 SD_BUS_ARGS("u", major, "u", minor),
965 SD_BUS_NO_RESULT,
966 method_pause_device_complete,
967 SD_BUS_VTABLE_UNPRIVILEGED),
968 SD_BUS_METHOD_WITH_ARGS("SetBrightness",
969 SD_BUS_ARGS("s", subsystem, "s", name, "u", brightness),
970 SD_BUS_NO_RESULT,
971 method_set_brightness,
972 SD_BUS_VTABLE_UNPRIVILEGED),
973
974 SD_BUS_SIGNAL_WITH_ARGS("PauseDevice",
975 SD_BUS_ARGS("u", major, "u", minor, "s", type),
976 0),
977 SD_BUS_SIGNAL_WITH_ARGS("ResumeDevice",
978 SD_BUS_ARGS("u", major, "u", minor, "h", fd),
979 0),
c2b178d3
ZJS
980 SD_BUS_SIGNAL("Lock", NULL, 0),
981 SD_BUS_SIGNAL("Unlock", NULL, 0),
982
983 SD_BUS_VTABLE_END
984};
985
986const BusObjectImplementation session_object = {
987 "/org/freedesktop/login1/session",
988 "org.freedesktop.login1.Session",
989 .fallback_vtables = BUS_FALLBACK_VTABLES({session_vtable, session_object_find}),
990 .node_enumerator = session_node_enumerator,
991};