]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/network/networkd-manager-bus.c
polkit: simplify bus_verify_polkit_async() + drop auth-by-cap dbus feature
[thirdparty/systemd.git] / src / network / networkd-manager-bus.c
CommitLineData
db9ecf05 1/* SPDX-License-Identifier: LGPL-2.1-or-later */
e331e246 2
071712b2 3#include <net/if.h>
f39dbf28 4#include <netinet/in.h>
7f06b3e1 5#include <sys/capability.h>
071712b2 6
b5efdb8a 7#include "alloc-util.h"
071712b2 8#include "bus-common-errors.h"
7695e2cb 9#include "bus-message-util.h"
269e4d2d 10#include "bus-polkit.h"
6e194652 11#include "networkd-dhcp-server-bus.h"
f8da534e 12#include "networkd-dhcp4-bus.h"
13#include "networkd-dhcp6-bus.h"
54a16efe 14#include "networkd-json.h"
7f3c07ad 15#include "networkd-link-bus.h"
37d577c8 16#include "networkd-link.h"
79a59fa5 17#include "networkd-manager-bus.h"
23f53b99 18#include "networkd-manager.h"
6e194652 19#include "networkd-network-bus.h"
37d577c8 20#include "path-util.h"
51517f9e 21#include "strv.h"
7f06b3e1 22#include "user-util.h"
e331e246 23
37d577c8
YW
24static int method_list_links(sd_bus_message *message, void *userdata, sd_bus_error *error) {
25 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
26 Manager *manager = userdata;
37d577c8
YW
27 Link *link;
28 int r;
29
30 r = sd_bus_message_new_method_return(message, &reply);
31 if (r < 0)
32 return r;
33
34 r = sd_bus_message_open_container(reply, 'a', "(iso)");
35 if (r < 0)
36 return r;
37
6eab614d 38 HASHMAP_FOREACH(link, manager->links_by_index) {
37d577c8
YW
39 _cleanup_free_ char *path = NULL;
40
41 path = link_bus_path(link);
42 if (!path)
43 return -ENOMEM;
44
45 r = sd_bus_message_append(
46 reply, "(iso)",
47 link->ifindex,
48 link->ifname,
49 empty_to_root(path));
50 if (r < 0)
51 return r;
52 }
53
54 r = sd_bus_message_close_container(reply);
55 if (r < 0)
56 return r;
57
58 return sd_bus_send(NULL, reply, NULL);
59}
60
071712b2
YW
61static int method_get_link_by_name(sd_bus_message *message, void *userdata, sd_bus_error *error) {
62 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
63 _cleanup_free_ char *path = NULL;
64 Manager *manager = userdata;
65 const char *name;
071712b2 66 Link *link;
f0ad7aed 67 int r;
071712b2
YW
68
69 r = sd_bus_message_read(message, "s", &name);
70 if (r < 0)
71 return r;
72
f0ad7aed 73 if (link_get_by_name(manager, name, &link) < 0)
071712b2
YW
74 return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_LINK, "Link %s not known", name);
75
76 r = sd_bus_message_new_method_return(message, &reply);
77 if (r < 0)
78 return r;
79
80 path = link_bus_path(link);
81 if (!path)
82 return -ENOMEM;
83
84 r = sd_bus_message_append(reply, "io", link->ifindex, empty_to_root(path));
85 if (r < 0)
86 return r;
87
88 return sd_bus_send(NULL, reply, NULL);
89}
90
91static int method_get_link_by_index(sd_bus_message *message, void *userdata, sd_bus_error *error) {
92 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
93 _cleanup_free_ char *path = NULL;
94 Manager *manager = userdata;
7695e2cb 95 int ifindex, r;
071712b2 96 Link *link;
071712b2 97
7695e2cb 98 r = bus_message_read_ifindex(message, error, &ifindex);
071712b2
YW
99 if (r < 0)
100 return r;
101
6eab614d
YW
102 r = link_get_by_index(manager, ifindex, &link);
103 if (r < 0)
7695e2cb 104 return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_LINK, "Link %i not known", ifindex);
071712b2
YW
105
106 r = sd_bus_message_new_method_return(message, &reply);
107 if (r < 0)
108 return r;
109
110 path = link_bus_path(link);
111 if (!path)
112 return -ENOMEM;
113
114 r = sd_bus_message_append(reply, "so", link->ifname, empty_to_root(path));
115 if (r < 0)
116 return r;
117
118 return sd_bus_send(NULL, reply, NULL);
119}
120
15761549
YW
121static int call_link_method(Manager *m, sd_bus_message *message, sd_bus_message_handler_t handler, sd_bus_error *error) {
122 int ifindex, r;
123 Link *l;
124
125 assert(m);
126 assert(message);
127 assert(handler);
128
7695e2cb 129 r = bus_message_read_ifindex(message, error, &ifindex);
15761549
YW
130 if (r < 0)
131 return r;
132
6eab614d
YW
133 r = link_get_by_index(m, ifindex, &l);
134 if (r < 0)
15761549
YW
135 return sd_bus_error_setf(error, BUS_ERROR_NO_SUCH_LINK, "Link %i not known", ifindex);
136
137 return handler(message, l, error);
138}
139
140static int bus_method_set_link_ntp_servers(sd_bus_message *message, void *userdata, sd_bus_error *error) {
141 return call_link_method(userdata, message, bus_link_method_set_ntp_servers, error);
142}
143
144static int bus_method_set_link_dns_servers(sd_bus_message *message, void *userdata, sd_bus_error *error) {
145 return call_link_method(userdata, message, bus_link_method_set_dns_servers, error);
146}
147
4e11ddfd
YW
148static int bus_method_set_link_dns_servers_ex(sd_bus_message *message, void *userdata, sd_bus_error *error) {
149 return call_link_method(userdata, message, bus_link_method_set_dns_servers_ex, error);
150}
151
15761549
YW
152static int bus_method_set_link_domains(sd_bus_message *message, void *userdata, sd_bus_error *error) {
153 return call_link_method(userdata, message, bus_link_method_set_domains, error);
154}
155
156static int bus_method_set_link_default_route(sd_bus_message *message, void *userdata, sd_bus_error *error) {
157 return call_link_method(userdata, message, bus_link_method_set_default_route, error);
158}
159
160static int bus_method_set_link_llmnr(sd_bus_message *message, void *userdata, sd_bus_error *error) {
161 return call_link_method(userdata, message, bus_link_method_set_llmnr, error);
162}
163
164static int bus_method_set_link_mdns(sd_bus_message *message, void *userdata, sd_bus_error *error) {
165 return call_link_method(userdata, message, bus_link_method_set_mdns, error);
166}
167
168static int bus_method_set_link_dns_over_tls(sd_bus_message *message, void *userdata, sd_bus_error *error) {
169 return call_link_method(userdata, message, bus_link_method_set_dns_over_tls, error);
170}
171
172static int bus_method_set_link_dnssec(sd_bus_message *message, void *userdata, sd_bus_error *error) {
173 return call_link_method(userdata, message, bus_link_method_set_dnssec, error);
174}
175
176static int bus_method_set_link_dnssec_negative_trust_anchors(sd_bus_message *message, void *userdata, sd_bus_error *error) {
177 return call_link_method(userdata, message, bus_link_method_set_dnssec_negative_trust_anchors, error);
178}
179
180static int bus_method_revert_link_ntp(sd_bus_message *message, void *userdata, sd_bus_error *error) {
181 return call_link_method(userdata, message, bus_link_method_revert_ntp, error);
182}
183
184static int bus_method_revert_link_dns(sd_bus_message *message, void *userdata, sd_bus_error *error) {
185 return call_link_method(userdata, message, bus_link_method_revert_dns, error);
186}
187
ae65d7db
YW
188static int bus_method_renew_link(sd_bus_message *message, void *userdata, sd_bus_error *error) {
189 return call_link_method(userdata, message, bus_link_method_renew, error);
190}
191
90867f6a
SS
192static int bus_method_force_renew_link(sd_bus_message *message, void *userdata, sd_bus_error *error) {
193 return call_link_method(userdata, message, bus_link_method_force_renew, error);
194}
195
99b8517c
YW
196static int bus_method_reconfigure_link(sd_bus_message *message, void *userdata, sd_bus_error *error) {
197 return call_link_method(userdata, message, bus_link_method_reconfigure, error);
198}
199
7f06b3e1
YW
200static int bus_method_reload(sd_bus_message *message, void *userdata, sd_bus_error *error) {
201 Manager *manager = userdata;
7f06b3e1
YW
202 int r;
203
7b36fb9f
LP
204 r = bus_verify_polkit_async(
205 message,
206 "org.freedesktop.network1.reload",
207 /* details= */ NULL,
208 &manager->polkit_registry,
209 error);
7f06b3e1
YW
210 if (r < 0)
211 return r;
212 if (r == 0)
213 return 1; /* Polkit will call us back */
214
0e07cdb0 215 r = manager_reload(manager);
e272b621
YW
216 if (r < 0)
217 return r;
218
7f06b3e1
YW
219 return sd_bus_reply_method_return(message, NULL);
220}
221
54a16efe
YW
222static int bus_method_describe_link(sd_bus_message *message, void *userdata, sd_bus_error *error) {
223 return call_link_method(userdata, message, bus_link_method_describe, error);
224}
225
226static int bus_method_describe(sd_bus_message *message, void *userdata, sd_bus_error *error) {
227 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
228 _cleanup_(json_variant_unrefp) JsonVariant *v = NULL;
229 _cleanup_free_ char *text = NULL;
99534007 230 Manager *manager = ASSERT_PTR(userdata);
54a16efe
YW
231 int r;
232
233 assert(message);
54a16efe
YW
234
235 r = manager_build_json(manager, &v);
236 if (r < 0)
237 return log_error_errno(r, "Failed to build JSON data: %m");
238
239 r = json_variant_format(v, 0, &text);
240 if (r < 0)
241 return log_error_errno(r, "Failed to format JSON data: %m");
242
243 r = sd_bus_message_new_method_return(message, &reply);
244 if (r < 0)
245 return r;
246
247 r = sd_bus_message_append(reply, "s", text);
248 if (r < 0)
249 return r;
250
251 return sd_bus_send(NULL, reply, NULL);
252}
253
f2ef8b28
LP
254static int property_get_namespace_id(
255 sd_bus *bus,
256 const char *path,
257 const char *interface,
258 const char *property,
259 sd_bus_message *reply,
260 void *userdata,
261 sd_bus_error *error) {
262
263 uint64_t id = 0;
264 struct stat st;
265
266 assert(bus);
267 assert(reply);
268
269 /* Returns our own network namespace ID, i.e. the inode number of /proc/self/ns/net. This allows
270 * unprivileged clients to determine whether they are in the same network namespace as us (note that
271 * access to that path is restricted, thus they can't check directly unless privileged). */
272
273 if (stat("/proc/self/ns/net", &st) < 0) {
274 log_warning_errno(errno, "Failed to stat network namespace, ignoring: %m");
275 id = 0;
276 } else
277 id = st.st_ino;
278
279 return sd_bus_message_append(reply, "t", id);
280}
281
6e194652 282static const sd_bus_vtable manager_vtable[] = {
e331e246
TG
283 SD_BUS_VTABLE_START(0),
284
285 SD_BUS_PROPERTY("OperationalState", "s", property_get_operational_state, offsetof(Manager, operational_state), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
7f3c07ad
YW
286 SD_BUS_PROPERTY("CarrierState", "s", property_get_carrier_state, offsetof(Manager, carrier_state), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
287 SD_BUS_PROPERTY("AddressState", "s", property_get_address_state, offsetof(Manager, address_state), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
8430841b
L
288 SD_BUS_PROPERTY("IPv4AddressState", "s", property_get_address_state, offsetof(Manager, ipv4_address_state), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
289 SD_BUS_PROPERTY("IPv6AddressState", "s", property_get_address_state, offsetof(Manager, ipv6_address_state), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
bcdcc596 290 SD_BUS_PROPERTY("OnlineState", "s", property_get_online_state, offsetof(Manager, online_state), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
f2ef8b28 291 SD_BUS_PROPERTY("NamespaceId", "t", property_get_namespace_id, 0, SD_BUS_VTABLE_PROPERTY_CONST),
e331e246 292
23c32ff8
YW
293 SD_BUS_METHOD_WITH_ARGS("ListLinks",
294 SD_BUS_NO_ARGS,
295 SD_BUS_RESULT("a(iso)", links),
296 method_list_links,
297 SD_BUS_VTABLE_UNPRIVILEGED),
298 SD_BUS_METHOD_WITH_ARGS("GetLinkByName",
299 SD_BUS_ARGS("s", name),
300 SD_BUS_RESULT("i", ifindex, "o", path),
301 method_get_link_by_name,
302 SD_BUS_VTABLE_UNPRIVILEGED),
303 SD_BUS_METHOD_WITH_ARGS("GetLinkByIndex",
304 SD_BUS_ARGS("i", ifindex),
305 SD_BUS_RESULT("s", name, "o", path),
306 method_get_link_by_index,
307 SD_BUS_VTABLE_UNPRIVILEGED),
308 SD_BUS_METHOD_WITH_ARGS("SetLinkNTP",
309 SD_BUS_ARGS("i", ifindex, "as", servers),
310 SD_BUS_NO_RESULT,
311 bus_method_set_link_ntp_servers,
312 SD_BUS_VTABLE_UNPRIVILEGED),
313 SD_BUS_METHOD_WITH_ARGS("SetLinkDNS",
314 SD_BUS_ARGS("i", ifindex, "a(iay)", addresses),
315 SD_BUS_NO_RESULT,
316 bus_method_set_link_dns_servers,
317 SD_BUS_VTABLE_UNPRIVILEGED),
318 SD_BUS_METHOD_WITH_ARGS("SetLinkDNSEx",
319 SD_BUS_ARGS("i", ifindex, "a(iayqs)", addresses),
320 SD_BUS_NO_RESULT,
321 bus_method_set_link_dns_servers_ex,
322 SD_BUS_VTABLE_UNPRIVILEGED),
323 SD_BUS_METHOD_WITH_ARGS("SetLinkDomains",
324 SD_BUS_ARGS("i", ifindex, "a(sb)", domains),
325 SD_BUS_NO_RESULT,
326 bus_method_set_link_domains,
327 SD_BUS_VTABLE_UNPRIVILEGED),
328 SD_BUS_METHOD_WITH_ARGS("SetLinkDefaultRoute",
329 SD_BUS_ARGS("i", ifindex, "b", enable),
330 SD_BUS_NO_RESULT,
331 bus_method_set_link_default_route,
332 SD_BUS_VTABLE_UNPRIVILEGED),
333 SD_BUS_METHOD_WITH_ARGS("SetLinkLLMNR",
334 SD_BUS_ARGS("i", ifindex, "s", mode),
335 SD_BUS_NO_RESULT,
336 bus_method_set_link_llmnr,
337 SD_BUS_VTABLE_UNPRIVILEGED),
338 SD_BUS_METHOD_WITH_ARGS("SetLinkMulticastDNS",
339 SD_BUS_ARGS("i", ifindex, "s", mode),
340 SD_BUS_NO_RESULT,
341 bus_method_set_link_mdns,
342 SD_BUS_VTABLE_UNPRIVILEGED),
343 SD_BUS_METHOD_WITH_ARGS("SetLinkDNSOverTLS",
344 SD_BUS_ARGS("i", ifindex, "s", mode),
345 SD_BUS_NO_RESULT,
346 bus_method_set_link_dns_over_tls,
347 SD_BUS_VTABLE_UNPRIVILEGED),
348 SD_BUS_METHOD_WITH_ARGS("SetLinkDNSSEC",
349 SD_BUS_ARGS("i", ifindex, "s", mode),
350 SD_BUS_NO_RESULT,
351 bus_method_set_link_dnssec,
352 SD_BUS_VTABLE_UNPRIVILEGED),
353 SD_BUS_METHOD_WITH_ARGS("SetLinkDNSSECNegativeTrustAnchors",
354 SD_BUS_ARGS("i", ifindex, "as", names),
355 SD_BUS_NO_RESULT,
356 bus_method_set_link_dnssec_negative_trust_anchors,
357 SD_BUS_VTABLE_UNPRIVILEGED),
358 SD_BUS_METHOD_WITH_ARGS("RevertLinkNTP",
359 SD_BUS_ARGS("i", ifindex),
360 SD_BUS_NO_RESULT,
361 bus_method_revert_link_ntp,
362 SD_BUS_VTABLE_UNPRIVILEGED),
363 SD_BUS_METHOD_WITH_ARGS("RevertLinkDNS",
364 SD_BUS_ARGS("i", ifindex),
365 SD_BUS_NO_RESULT,
366 bus_method_revert_link_dns,
367 SD_BUS_VTABLE_UNPRIVILEGED),
368 SD_BUS_METHOD_WITH_ARGS("RenewLink",
369 SD_BUS_ARGS("i", ifindex),
370 SD_BUS_NO_RESULT,
371 bus_method_renew_link,
372 SD_BUS_VTABLE_UNPRIVILEGED),
373 SD_BUS_METHOD_WITH_ARGS("ForceRenewLink",
374 SD_BUS_ARGS("i", ifindex),
375 SD_BUS_NO_RESULT,
376 bus_method_force_renew_link,
377 SD_BUS_VTABLE_UNPRIVILEGED),
378 SD_BUS_METHOD_WITH_ARGS("ReconfigureLink",
379 SD_BUS_ARGS("i", ifindex),
380 SD_BUS_NO_RESULT,
381 bus_method_reconfigure_link,
382 SD_BUS_VTABLE_UNPRIVILEGED),
383 SD_BUS_METHOD_WITH_ARGS("Reload",
384 SD_BUS_NO_ARGS,
385 SD_BUS_NO_RESULT,
386 bus_method_reload,
387 SD_BUS_VTABLE_UNPRIVILEGED),
54a16efe
YW
388 SD_BUS_METHOD_WITH_ARGS("DescribeLink",
389 SD_BUS_ARGS("i", ifindex),
390 SD_BUS_RESULT("s", json),
391 bus_method_describe_link,
392 SD_BUS_VTABLE_UNPRIVILEGED),
393 SD_BUS_METHOD_WITH_ARGS("Describe",
394 SD_BUS_NO_ARGS,
395 SD_BUS_RESULT("s", json),
396 bus_method_describe,
397 SD_BUS_VTABLE_UNPRIVILEGED),
37d577c8 398
e331e246
TG
399 SD_BUS_VTABLE_END
400};
401
46606fdd 402int manager_send_changed_strv(Manager *manager, char **properties) {
e331e246 403 assert(manager);
46606fdd 404 assert(properties);
e331e246 405
5dbec9bd 406 if (sd_bus_is_ready(manager->bus) <= 0)
46606fdd 407 return 0;
e331e246
TG
408
409 return sd_bus_emit_properties_changed_strv(
410 manager->bus,
411 "/org/freedesktop/network1",
412 "org.freedesktop.network1.Manager",
46606fdd
YW
413 properties);
414}
6e194652
YW
415
416const BusObjectImplementation manager_object = {
417 "/org/freedesktop/network1",
418 "org.freedesktop.network1.Manager",
419 .vtables = BUS_VTABLES(manager_vtable),
53dff954
YW
420 .children = BUS_IMPLEMENTATIONS(
421 &link_object, /* This is the main implementation for /org/freedesktop/network1/link,
422 * and must be earlier than the dhcp objects below. */
423 &dhcp_server_object,
424 &dhcp_client_object,
425 &dhcp6_client_object,
426 &network_object),
6e194652 427};