]>
Commit | Line | Data |
---|---|---|
61d0578b LP |
1 | /* SPDX-License-Identifier: LGPL-2.1+ */ |
2 | ||
3 | #include "alloc-util.h" | |
4 | #include "btrfs-util.h" | |
5 | #include "bus-common-errors.h" | |
269e4d2d | 6 | #include "bus-polkit.h" |
61d0578b LP |
7 | #include "fd-util.h" |
8 | #include "io-util.h" | |
9 | #include "machine-image.h" | |
204f52e3 | 10 | #include "missing_capability.h" |
61d0578b LP |
11 | #include "portable.h" |
12 | #include "portabled-bus.h" | |
13 | #include "portabled-image-bus.h" | |
14 | #include "portabled-image.h" | |
15 | #include "portabled.h" | |
16 | #include "strv.h" | |
17 | #include "user-util.h" | |
18 | ||
19 | static int property_get_pool_path( | |
20 | sd_bus *bus, | |
21 | const char *path, | |
22 | const char *interface, | |
23 | const char *property, | |
24 | sd_bus_message *reply, | |
25 | void *userdata, | |
26 | sd_bus_error *error) { | |
27 | ||
28 | assert(bus); | |
29 | assert(reply); | |
30 | ||
31 | return sd_bus_message_append(reply, "s", "/var/lib/portables"); | |
32 | } | |
33 | ||
34 | static int property_get_pool_usage( | |
35 | sd_bus *bus, | |
36 | const char *path, | |
37 | const char *interface, | |
38 | const char *property, | |
39 | sd_bus_message *reply, | |
40 | void *userdata, | |
41 | sd_bus_error *error) { | |
42 | ||
43 | _cleanup_close_ int fd = -1; | |
44 | uint64_t usage = (uint64_t) -1; | |
45 | ||
46 | assert(bus); | |
47 | assert(reply); | |
48 | ||
49 | fd = open("/var/lib/portables", O_RDONLY|O_CLOEXEC|O_DIRECTORY); | |
50 | if (fd >= 0) { | |
51 | BtrfsQuotaInfo q; | |
52 | ||
53 | if (btrfs_subvol_get_subtree_quota_fd(fd, 0, &q) >= 0) | |
54 | usage = q.referenced; | |
55 | } | |
56 | ||
57 | return sd_bus_message_append(reply, "t", usage); | |
58 | } | |
59 | ||
60 | static int property_get_pool_limit( | |
61 | sd_bus *bus, | |
62 | const char *path, | |
63 | const char *interface, | |
64 | const char *property, | |
65 | sd_bus_message *reply, | |
66 | void *userdata, | |
67 | sd_bus_error *error) { | |
68 | ||
69 | _cleanup_close_ int fd = -1; | |
70 | uint64_t size = (uint64_t) -1; | |
71 | ||
72 | assert(bus); | |
73 | assert(reply); | |
74 | ||
75 | fd = open("/var/lib/portables", O_RDONLY|O_CLOEXEC|O_DIRECTORY); | |
76 | if (fd >= 0) { | |
77 | BtrfsQuotaInfo q; | |
78 | ||
79 | if (btrfs_subvol_get_subtree_quota_fd(fd, 0, &q) >= 0) | |
80 | size = q.referenced_max; | |
81 | } | |
82 | ||
83 | return sd_bus_message_append(reply, "t", size); | |
84 | } | |
85 | ||
86 | static int property_get_profiles( | |
87 | sd_bus *bus, | |
88 | const char *path, | |
89 | const char *interface, | |
90 | const char *property, | |
91 | sd_bus_message *reply, | |
92 | void *userdata, | |
93 | sd_bus_error *error) { | |
94 | ||
95 | _cleanup_strv_free_ char **l = NULL; | |
96 | int r; | |
97 | ||
98 | assert(bus); | |
99 | assert(reply); | |
100 | ||
101 | r = portable_get_profiles(&l); | |
102 | if (r < 0) | |
103 | return r; | |
104 | ||
105 | return sd_bus_message_append_strv(reply, l); | |
106 | } | |
107 | ||
108 | static int method_get_image(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
109 | _cleanup_free_ char *p = NULL; | |
110 | Manager *m = userdata; | |
111 | const char *name; | |
112 | Image *image; | |
113 | int r; | |
114 | ||
115 | assert(message); | |
116 | assert(m); | |
117 | ||
118 | r = sd_bus_message_read(message, "s", &name); | |
119 | if (r < 0) | |
120 | return r; | |
121 | ||
122 | r = bus_image_acquire(m, message, name, NULL, BUS_IMAGE_REFUSE_BY_PATH, NULL, &image, error); | |
123 | if (r < 0) | |
124 | return r; | |
125 | ||
126 | r = bus_image_path(image, &p); | |
127 | if (r < 0) | |
128 | return r; | |
129 | ||
130 | return sd_bus_reply_method_return(message, "o", p); | |
131 | } | |
132 | ||
133 | static int method_list_images(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
134 | _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL; | |
b07ec5a1 | 135 | _cleanup_hashmap_free_ Hashmap *images = NULL; |
61d0578b LP |
136 | Manager *m = userdata; |
137 | Image *image; | |
61d0578b LP |
138 | int r; |
139 | ||
140 | assert(message); | |
141 | assert(m); | |
142 | ||
b07ec5a1 | 143 | images = hashmap_new(&image_hash_ops); |
61d0578b LP |
144 | if (!images) |
145 | return -ENOMEM; | |
146 | ||
147 | r = manager_image_cache_discover(m, images, error); | |
148 | if (r < 0) | |
149 | return r; | |
150 | ||
151 | r = sd_bus_message_new_method_return(message, &reply); | |
152 | if (r < 0) | |
153 | return r; | |
154 | ||
155 | r = sd_bus_message_open_container(reply, 'a', "(ssbtttso)"); | |
156 | if (r < 0) | |
157 | return r; | |
158 | ||
90e74a66 | 159 | HASHMAP_FOREACH(image, images) { |
61d0578b LP |
160 | _cleanup_(sd_bus_error_free) sd_bus_error error_state = SD_BUS_ERROR_NULL; |
161 | PortableState state = _PORTABLE_STATE_INVALID; | |
162 | _cleanup_free_ char *p = NULL; | |
163 | ||
164 | r = bus_image_path(image, &p); | |
165 | if (r < 0) | |
166 | return r; | |
167 | ||
168 | r = portable_get_state( | |
169 | sd_bus_message_get_bus(message), | |
170 | image->path, | |
171 | 0, | |
172 | &state, | |
173 | &error_state); | |
174 | if (r < 0) | |
175 | log_debug_errno(r, "Failed to get state of image '%s', ignoring: %s", | |
176 | image->path, bus_error_message(&error_state, r)); | |
177 | ||
178 | r = sd_bus_message_append(reply, "(ssbtttso)", | |
179 | image->name, | |
180 | image_type_to_string(image->type), | |
181 | image->read_only, | |
182 | image->crtime, | |
183 | image->mtime, | |
184 | image->usage, | |
185 | portable_state_to_string(state), | |
186 | p); | |
187 | if (r < 0) | |
188 | return r; | |
189 | } | |
190 | ||
191 | r = sd_bus_message_close_container(reply); | |
192 | if (r < 0) | |
193 | return r; | |
194 | ||
195 | return sd_bus_send(NULL, reply, NULL); | |
196 | } | |
197 | ||
198 | static int redirect_method_to_image( | |
199 | Manager *m, | |
200 | sd_bus_message *message, | |
201 | sd_bus_error *error, | |
202 | int (*method)(Manager *m, sd_bus_message *message, const char *name_or_path, Image *image, sd_bus_error* error)) { | |
203 | ||
204 | const char *name_or_path; | |
205 | int r; | |
206 | ||
207 | assert(m); | |
208 | assert(message); | |
209 | assert(method); | |
210 | ||
211 | r = sd_bus_message_read(message, "s", &name_or_path); | |
212 | if (r < 0) | |
213 | return r; | |
214 | ||
215 | return method(m, message, name_or_path, NULL, error); | |
216 | } | |
217 | ||
218 | static int method_get_image_os_release(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
219 | return redirect_method_to_image(userdata, message, error, bus_image_common_get_os_release); | |
220 | } | |
221 | ||
222 | static int method_get_image_metadata(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
223 | return redirect_method_to_image(userdata, message, error, bus_image_common_get_metadata); | |
224 | } | |
225 | ||
226 | static int method_get_image_state(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
227 | const char *name_or_path; | |
228 | PortableState state; | |
229 | int r; | |
230 | ||
231 | assert(message); | |
232 | ||
233 | r = sd_bus_message_read(message, "s", &name_or_path); | |
234 | if (r < 0) | |
235 | return r; | |
236 | ||
237 | r = portable_get_state( | |
238 | sd_bus_message_get_bus(message), | |
239 | name_or_path, | |
240 | 0, | |
241 | &state, | |
242 | error); | |
243 | if (r < 0) | |
244 | return r; | |
245 | ||
246 | return sd_bus_reply_method_return(message, "s", portable_state_to_string(state)); | |
247 | } | |
248 | ||
249 | static int method_attach_image(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
250 | return redirect_method_to_image(userdata, message, error, bus_image_common_attach); | |
251 | } | |
252 | ||
253 | static int method_detach_image(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
254 | PortableChange *changes = NULL; | |
255 | Manager *m = userdata; | |
256 | size_t n_changes = 0; | |
257 | const char *name_or_path; | |
258 | int r, runtime; | |
259 | ||
260 | assert(message); | |
261 | assert(m); | |
262 | ||
263 | /* Note that we do not redirect detaching to the image object here, because we want to allow that users can | |
264 | * detach already deleted images too, in case the user already deleted an image before properly detaching | |
265 | * it. */ | |
266 | ||
267 | r = sd_bus_message_read(message, "sb", &name_or_path, &runtime); | |
268 | if (r < 0) | |
269 | return r; | |
270 | ||
271 | r = bus_verify_polkit_async( | |
272 | message, | |
273 | CAP_SYS_ADMIN, | |
274 | "org.freedesktop.portable1.attach-images", | |
275 | NULL, | |
276 | false, | |
277 | UID_INVALID, | |
278 | &m->polkit_registry, | |
279 | error); | |
280 | if (r < 0) | |
281 | return r; | |
282 | if (r == 0) | |
283 | return 1; /* Will call us back */ | |
284 | ||
285 | r = portable_detach( | |
286 | sd_bus_message_get_bus(message), | |
287 | name_or_path, | |
288 | runtime ? PORTABLE_RUNTIME : 0, | |
289 | &changes, | |
290 | &n_changes, | |
291 | error); | |
292 | if (r < 0) | |
293 | goto finish; | |
294 | ||
295 | r = reply_portable_changes(message, changes, n_changes); | |
296 | ||
297 | finish: | |
298 | portable_changes_free(changes, n_changes); | |
299 | return r; | |
300 | } | |
301 | ||
302 | static int method_remove_image(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
303 | return redirect_method_to_image(userdata, message, error, bus_image_common_remove); | |
304 | } | |
305 | ||
306 | static int method_mark_image_read_only(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
307 | return redirect_method_to_image(userdata, message, error, bus_image_common_mark_read_only); | |
308 | } | |
309 | ||
310 | static int method_set_image_limit(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
311 | return redirect_method_to_image(userdata, message, error, bus_image_common_set_limit); | |
312 | } | |
313 | ||
314 | static int method_set_pool_limit(sd_bus_message *message, void *userdata, sd_bus_error *error) { | |
315 | Manager *m = userdata; | |
316 | uint64_t limit; | |
317 | int r; | |
318 | ||
319 | assert(message); | |
320 | ||
321 | r = sd_bus_message_read(message, "t", &limit); | |
322 | if (r < 0) | |
323 | return r; | |
324 | if (!FILE_SIZE_VALID_OR_INFINITY(limit)) | |
325 | return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "New limit out of range"); | |
326 | ||
327 | r = bus_verify_polkit_async( | |
328 | message, | |
329 | CAP_SYS_ADMIN, | |
330 | "org.freedesktop.portable1.manage-images", | |
331 | NULL, | |
332 | false, | |
333 | UID_INVALID, | |
334 | &m->polkit_registry, | |
335 | error); | |
336 | if (r < 0) | |
337 | return r; | |
338 | if (r == 0) | |
339 | return 1; /* Will call us back */ | |
340 | ||
341 | (void) btrfs_qgroup_set_limit("/var/lib/portables", 0, limit); | |
342 | ||
343 | r = btrfs_subvol_set_subtree_quota_limit("/var/lib/portables", 0, limit); | |
344 | if (r == -ENOTTY) | |
345 | return sd_bus_error_setf(error, SD_BUS_ERROR_NOT_SUPPORTED, "Quota is only supported on btrfs."); | |
346 | if (r < 0) | |
347 | return sd_bus_error_set_errnof(error, r, "Failed to adjust quota limit: %m"); | |
348 | ||
349 | return sd_bus_reply_method_return(message, NULL); | |
350 | } | |
351 | ||
352 | const sd_bus_vtable manager_vtable[] = { | |
353 | SD_BUS_VTABLE_START(0), | |
354 | SD_BUS_PROPERTY("PoolPath", "s", property_get_pool_path, 0, 0), | |
355 | SD_BUS_PROPERTY("PoolUsage", "t", property_get_pool_usage, 0, 0), | |
356 | SD_BUS_PROPERTY("PoolLimit", "t", property_get_pool_limit, 0, 0), | |
357 | SD_BUS_PROPERTY("Profiles", "as", property_get_profiles, 0, 0), | |
358 | SD_BUS_METHOD("GetImage", "s", "o", method_get_image, SD_BUS_VTABLE_UNPRIVILEGED), | |
359 | SD_BUS_METHOD("ListImages", NULL, "a(ssbtttso)", method_list_images, SD_BUS_VTABLE_UNPRIVILEGED), | |
360 | SD_BUS_METHOD("GetImageOSRelease", "s", "a{ss}", method_get_image_os_release, SD_BUS_VTABLE_UNPRIVILEGED), | |
61d0578b | 361 | SD_BUS_METHOD("GetImageMetadata", "sas", "saya{say}", method_get_image_metadata, SD_BUS_VTABLE_UNPRIVILEGED), |
3aeeafb4 | 362 | SD_BUS_METHOD("GetImageState", "s", "s", method_get_image_state, SD_BUS_VTABLE_UNPRIVILEGED), |
61d0578b LP |
363 | SD_BUS_METHOD("AttachImage", "sassbs", "a(sss)", method_attach_image, SD_BUS_VTABLE_UNPRIVILEGED), |
364 | SD_BUS_METHOD("DetachImage", "sb", "a(sss)", method_detach_image, SD_BUS_VTABLE_UNPRIVILEGED), | |
365 | SD_BUS_METHOD("RemoveImage", "s", NULL, method_remove_image, SD_BUS_VTABLE_UNPRIVILEGED), | |
366 | SD_BUS_METHOD("MarkImageReadOnly", "sb", NULL, method_mark_image_read_only, SD_BUS_VTABLE_UNPRIVILEGED), | |
367 | SD_BUS_METHOD("SetImageLimit", "st", NULL, method_set_image_limit, SD_BUS_VTABLE_UNPRIVILEGED), | |
368 | SD_BUS_METHOD("SetPoolLimit", "t", NULL, method_set_pool_limit, SD_BUS_VTABLE_UNPRIVILEGED), | |
369 | SD_BUS_VTABLE_END | |
370 | }; | |
371 | ||
372 | int reply_portable_changes(sd_bus_message *m, const PortableChange *changes, size_t n_changes) { | |
373 | _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL; | |
374 | size_t i; | |
375 | int r; | |
376 | ||
377 | assert(m); | |
378 | assert(changes || n_changes == 0); | |
379 | ||
380 | r = sd_bus_message_new_method_return(m, &reply); | |
381 | if (r < 0) | |
382 | return r; | |
383 | ||
384 | r = sd_bus_message_open_container(reply, 'a', "(sss)"); | |
385 | if (r < 0) | |
386 | return r; | |
387 | ||
388 | for (i = 0; i < n_changes; i++) { | |
389 | r = sd_bus_message_append(reply, "(sss)", | |
390 | portable_change_type_to_string(changes[i].type), | |
391 | changes[i].path, | |
392 | changes[i].source); | |
393 | if (r < 0) | |
394 | return r; | |
395 | } | |
396 | ||
397 | r = sd_bus_message_close_container(reply); | |
398 | if (r < 0) | |
399 | return r; | |
400 | ||
401 | return sd_bus_send(NULL, reply, NULL); | |
402 | } |