1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
3 #include "alloc-util.h"
4 #include "bus-common-errors.h"
5 #include "bus-get-properties.h"
6 #include "dbus-cgroup.h"
8 #include "dbus-scope.h"
10 #include "dbus-util.h"
13 #include "selinux-access.h"
16 int bus_scope_method_abandon(sd_bus_message
*message
, void *userdata
, sd_bus_error
*error
) {
23 r
= mac_selinux_unit_access_check(UNIT(s
), message
, "stop", error
);
27 r
= bus_verify_manage_units_async(UNIT(s
)->manager
, message
, error
);
31 return 1; /* No authorization for now, but the async polkit stuff will call us again when it has it */
35 return sd_bus_error_setf(error
, BUS_ERROR_SCOPE_NOT_RUNNING
, "Scope %s is not running, cannot abandon.", UNIT(s
)->id
);
39 return sd_bus_reply_method_return(message
, NULL
);
42 static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_result
, scope_result
, ScopeResult
);
44 const sd_bus_vtable bus_scope_vtable
[] = {
45 SD_BUS_VTABLE_START(0),
46 SD_BUS_PROPERTY("Controller", "s", NULL
, offsetof(Scope
, controller
), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE
),
47 SD_BUS_PROPERTY("TimeoutStopUSec", "t", bus_property_get_usec
, offsetof(Scope
, timeout_stop_usec
), SD_BUS_VTABLE_PROPERTY_CONST
),
48 SD_BUS_PROPERTY("Result", "s", property_get_result
, offsetof(Scope
, result
), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE
),
49 SD_BUS_PROPERTY("RuntimeMaxUSec", "t", bus_property_get_usec
, offsetof(Scope
, runtime_max_usec
), SD_BUS_VTABLE_PROPERTY_CONST
),
50 SD_BUS_PROPERTY("RuntimeRandomizedExtraUSec", "t", bus_property_get_usec
, offsetof(Scope
, runtime_rand_extra_usec
), SD_BUS_VTABLE_PROPERTY_CONST
),
51 SD_BUS_SIGNAL("RequestStop", NULL
, 0),
52 SD_BUS_METHOD("Abandon", NULL
, NULL
, bus_scope_method_abandon
, SD_BUS_VTABLE_UNPRIVILEGED
),
56 static int bus_scope_set_transient_property(
59 sd_bus_message
*message
,
61 sd_bus_error
*error
) {
70 flags
|= UNIT_PRIVATE
;
72 if (streq(name
, "TimeoutStopUSec"))
73 return bus_set_transient_usec(u
, name
, &s
->timeout_stop_usec
, message
, flags
, error
);
75 if (streq(name
, "RuntimeMaxUSec"))
76 return bus_set_transient_usec(u
, name
, &s
->runtime_max_usec
, message
, flags
, error
);
78 if (streq(name
, "RuntimeRandomizedExtraUSec"))
79 return bus_set_transient_usec(u
, name
, &s
->runtime_rand_extra_usec
, message
, flags
, error
);
81 if (streq(name
, "PIDs")) {
82 _cleanup_(sd_bus_creds_unrefp
) sd_bus_creds
*creds
= NULL
;
85 r
= sd_bus_message_enter_container(message
, 'a', "u");
93 r
= sd_bus_message_read(message
, "u", &upid
);
101 r
= sd_bus_query_sender_creds(message
, SD_BUS_CREDS_PID
, &creds
);
106 r
= sd_bus_creds_get_pid(creds
, &pid
);
112 r
= unit_pid_attachable(u
, pid
, error
);
116 if (!UNIT_WRITE_FLAGS_NOOP(flags
)) {
117 r
= unit_watch_pid(u
, pid
, false);
118 if (r
< 0 && r
!= -EEXIST
)
125 r
= sd_bus_message_exit_container(message
);
134 } else if (streq(name
, "Controller")) {
135 const char *controller
;
137 /* We can't support direct connections with this, as direct connections know no service or unique name
138 * concept, but the Controller field stores exactly that. */
139 if (sd_bus_message_get_bus(message
) != u
->manager
->api_bus
)
140 return sd_bus_error_set(error
, SD_BUS_ERROR_NOT_SUPPORTED
, "Sorry, Controller= logic only supported via the bus.");
142 r
= sd_bus_message_read(message
, "s", &controller
);
146 if (!isempty(controller
) && !sd_bus_service_name_is_valid(controller
))
147 return sd_bus_error_setf(error
, SD_BUS_ERROR_INVALID_ARGS
, "Controller '%s' is not a valid bus name.", controller
);
149 if (!UNIT_WRITE_FLAGS_NOOP(flags
)) {
150 r
= free_and_strdup(&s
->controller
, empty_to_null(controller
));
161 int bus_scope_set_property(
164 sd_bus_message
*message
,
165 UnitWriteFlags flags
,
166 sd_bus_error
*error
) {
175 r
= bus_cgroup_set_property(u
, &s
->cgroup_context
, name
, message
, flags
, error
);
179 if (u
->load_state
== UNIT_STUB
) {
180 /* While we are created we still accept PIDs */
182 r
= bus_scope_set_transient_property(s
, name
, message
, flags
, error
);
186 r
= bus_kill_context_set_transient_property(u
, &s
->kill_context
, name
, message
, flags
, error
);
190 if (streq(name
, "User"))
191 return bus_set_transient_user_relaxed(u
, name
, &s
->user
, message
, flags
, error
);
193 if (streq(name
, "Group"))
194 return bus_set_transient_user_relaxed(u
, name
, &s
->group
, message
, flags
, error
);
200 int bus_scope_commit_properties(Unit
*u
) {
203 unit_realize_cgroup(u
);
208 int bus_scope_send_request_stop(Scope
*s
) {
209 _cleanup_(sd_bus_message_unrefp
) sd_bus_message
*m
= NULL
;
210 _cleanup_free_
char *p
= NULL
;
218 p
= unit_dbus_path(UNIT(s
));
222 r
= sd_bus_message_new_signal(
223 UNIT(s
)->manager
->api_bus
,
226 "org.freedesktop.systemd1.Scope",
231 return sd_bus_send_to(UNIT(s
)->manager
->api_bus
, m
, s
->controller
, NULL
);
234 static int on_controller_gone(sd_bus_track
*track
, void *userdata
) {
240 log_unit_debug(UNIT(s
), "Controller %s disappeared from bus.", s
->controller
);
241 unit_add_to_dbus_queue(UNIT(s
));
242 s
->controller
= mfree(s
->controller
);
245 s
->controller_track
= sd_bus_track_unref(s
->controller_track
);
250 int bus_scope_track_controller(Scope
*s
) {
255 if (!s
->controller
|| s
->controller_track
)
258 r
= sd_bus_track_new(UNIT(s
)->manager
->api_bus
, &s
->controller_track
, on_controller_gone
, s
);
262 r
= sd_bus_track_add_name(s
->controller_track
, s
->controller
);
264 s
->controller_track
= sd_bus_track_unref(s
->controller_track
);