]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/core/dbus-scope.c
78196a1a08c90cbf19289e3d6fa7b5831f2c1808
[thirdparty/systemd.git] / src / core / dbus-scope.c
1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
2
3 #include "alloc-util.h"
4 #include "bus-common-errors.h"
5 #include "bus-get-properties.h"
6 #include "dbus-cgroup.h"
7 #include "dbus-kill.h"
8 #include "dbus-manager.h"
9 #include "dbus-scope.h"
10 #include "dbus-unit.h"
11 #include "dbus-util.h"
12 #include "dbus.h"
13 #include "scope.h"
14 #include "selinux-access.h"
15 #include "unit.h"
16
17 int bus_scope_method_abandon(sd_bus_message *message, void *userdata, sd_bus_error *error) {
18 Scope *s = ASSERT_PTR(userdata);
19 int r;
20
21 assert(message);
22
23 r = mac_selinux_unit_access_check(UNIT(s), message, "stop", error);
24 if (r < 0)
25 return r;
26
27 r = bus_verify_manage_units_async(UNIT(s)->manager, message, error);
28 if (r < 0)
29 return r;
30 if (r == 0)
31 return 1; /* No authorization for now, but the async polkit stuff will call us again when it has it */
32
33 r = scope_abandon(s);
34 if (r == -ESTALE)
35 return sd_bus_error_setf(error, BUS_ERROR_SCOPE_NOT_RUNNING, "Scope %s is not running, cannot abandon.", UNIT(s)->id);
36 if (r < 0)
37 return r;
38
39 return sd_bus_reply_method_return(message, NULL);
40 }
41
42 static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_result, scope_result, ScopeResult);
43 static BUS_DEFINE_SET_TRANSIENT_PARSE(oom_policy, OOMPolicy, oom_policy_from_string);
44
45 const sd_bus_vtable bus_scope_vtable[] = {
46 SD_BUS_VTABLE_START(0),
47 SD_BUS_PROPERTY("Controller", "s", NULL, offsetof(Scope, controller), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
48 SD_BUS_PROPERTY("TimeoutStopUSec", "t", bus_property_get_usec, offsetof(Scope, timeout_stop_usec), SD_BUS_VTABLE_PROPERTY_CONST),
49 SD_BUS_PROPERTY("Result", "s", property_get_result, offsetof(Scope, result), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
50 SD_BUS_PROPERTY("RuntimeMaxUSec", "t", bus_property_get_usec, offsetof(Scope, runtime_max_usec), SD_BUS_VTABLE_PROPERTY_CONST),
51 SD_BUS_PROPERTY("RuntimeRandomizedExtraUSec", "t", bus_property_get_usec, offsetof(Scope, runtime_rand_extra_usec), SD_BUS_VTABLE_PROPERTY_CONST),
52 SD_BUS_PROPERTY("OOMPolicy", "s", bus_property_get_oom_policy, offsetof(Scope, oom_policy), SD_BUS_VTABLE_PROPERTY_CONST),
53 SD_BUS_SIGNAL("RequestStop", NULL, 0),
54 SD_BUS_METHOD("Abandon", NULL, NULL, bus_scope_method_abandon, SD_BUS_VTABLE_UNPRIVILEGED),
55 SD_BUS_VTABLE_END
56 };
57
58 static int bus_scope_set_transient_property(
59 Scope *s,
60 const char *name,
61 sd_bus_message *message,
62 UnitWriteFlags flags,
63 sd_bus_error *error) {
64
65 Unit *u = UNIT(s);
66 int r;
67
68 assert(s);
69 assert(name);
70 assert(message);
71
72 flags |= UNIT_PRIVATE;
73
74 if (streq(name, "TimeoutStopUSec"))
75 return bus_set_transient_usec(u, name, &s->timeout_stop_usec, message, flags, error);
76
77 if (streq(name, "RuntimeMaxUSec"))
78 return bus_set_transient_usec(u, name, &s->runtime_max_usec, message, flags, error);
79
80 if (streq(name, "RuntimeRandomizedExtraUSec"))
81 return bus_set_transient_usec(u, name, &s->runtime_rand_extra_usec, message, flags, error);
82
83 if (streq(name, "OOMPolicy"))
84 return bus_set_transient_oom_policy(u, name, &s->oom_policy, message, flags, error);
85
86 if (streq(name, "PIDs")) {
87 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
88 unsigned n = 0;
89
90 r = sd_bus_message_enter_container(message, 'a', "u");
91 if (r < 0)
92 return r;
93
94 for (;;) {
95 _cleanup_(pidref_done) PidRef pidref = PIDREF_NULL;
96 uint32_t upid;
97 pid_t pid;
98
99 r = sd_bus_message_read(message, "u", &upid);
100 if (r < 0)
101 return r;
102 if (r == 0)
103 break;
104
105 if (upid == 0) {
106 if (!creds) {
107 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_PID, &creds);
108 if (r < 0)
109 return r;
110 }
111
112 r = sd_bus_creds_get_pid(creds, &pid);
113 if (r < 0)
114 return r;
115 } else
116 pid = (uid_t) upid;
117
118 r = pidref_set_pid(&pidref, pid);
119 if (r < 0)
120 return r;
121
122 r = unit_pid_attachable(u, &pidref, error);
123 if (r < 0)
124 return r;
125
126 if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
127 r = unit_watch_pidref(u, &pidref, /* exclusive= */ false);
128 if (r < 0 && r != -EEXIST)
129 return r;
130 }
131
132 n++;
133 }
134
135 r = sd_bus_message_exit_container(message);
136 if (r < 0)
137 return r;
138
139 return n <= 0 ? -EINVAL : 1;
140 }
141
142 if (streq(name, "PIDFDs")) {
143 unsigned n = 0;
144
145 r = sd_bus_message_enter_container(message, 'a', "h");
146 if (r < 0)
147 return r;
148
149 for (;;) {
150 _cleanup_(pidref_done) PidRef pidref = PIDREF_NULL;
151 int fd;
152
153 r = sd_bus_message_read(message, "h", &fd);
154 if (r < 0)
155 return r;
156 if (r == 0)
157 break;
158
159 r = pidref_set_pidfd(&pidref, fd);
160 if (r < 0)
161 return r;
162
163 r = unit_pid_attachable(u, &pidref, error);
164 if (r < 0)
165 return r;
166
167 if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
168 r = unit_watch_pidref(u, &pidref, /* exclusive= */ false);
169 if (r < 0 && r != -EEXIST)
170 return r;
171 }
172
173 n++;
174 }
175
176 r = sd_bus_message_exit_container(message);
177 if (r < 0)
178 return r;
179
180 return n <= 0 ? -EINVAL : 1;
181 }
182
183 if (streq(name, "Controller")) {
184 const char *controller;
185
186 /* We can't support direct connections with this, as direct connections know no service or unique name
187 * concept, but the Controller field stores exactly that. */
188 if (sd_bus_message_get_bus(message) != u->manager->api_bus)
189 return sd_bus_error_set(error, SD_BUS_ERROR_NOT_SUPPORTED, "Sorry, Controller= logic only supported via the bus.");
190
191 r = sd_bus_message_read(message, "s", &controller);
192 if (r < 0)
193 return r;
194
195 if (!isempty(controller) && !sd_bus_service_name_is_valid(controller))
196 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Controller '%s' is not a valid bus name.", controller);
197
198 if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
199 r = free_and_strdup(&s->controller, empty_to_null(controller));
200 if (r < 0)
201 return r;
202 }
203
204 return 1;
205 }
206
207 return 0;
208 }
209
210 int bus_scope_set_property(
211 Unit *u,
212 const char *name,
213 sd_bus_message *message,
214 UnitWriteFlags flags,
215 sd_bus_error *error) {
216
217 Scope *s = SCOPE(u);
218 int r;
219
220 assert(s);
221 assert(name);
222 assert(message);
223
224 r = bus_cgroup_set_property(u, &s->cgroup_context, name, message, flags, error);
225 if (r != 0)
226 return r;
227
228 if (u->load_state == UNIT_STUB) {
229 /* While we are created we still accept PIDs */
230
231 r = bus_scope_set_transient_property(s, name, message, flags, error);
232 if (r != 0)
233 return r;
234
235 r = bus_kill_context_set_transient_property(u, &s->kill_context, name, message, flags, error);
236 if (r != 0)
237 return r;
238
239 if (streq(name, "User"))
240 return bus_set_transient_user_relaxed(u, name, &s->user, message, flags, error);
241
242 if (streq(name, "Group"))
243 return bus_set_transient_user_relaxed(u, name, &s->group, message, flags, error);
244 }
245
246 return 0;
247 }
248
249 int bus_scope_commit_properties(Unit *u) {
250 assert(u);
251
252 unit_realize_cgroup(u);
253
254 return 0;
255 }
256
257 int bus_scope_send_request_stop(Scope *s) {
258 _cleanup_(sd_bus_message_unrefp) sd_bus_message *m = NULL;
259 _cleanup_free_ char *p = NULL;
260 int r;
261
262 assert(s);
263
264 if (!s->controller)
265 return 0;
266
267 p = unit_dbus_path(UNIT(s));
268 if (!p)
269 return -ENOMEM;
270
271 r = sd_bus_message_new_signal(
272 UNIT(s)->manager->api_bus,
273 &m,
274 p,
275 "org.freedesktop.systemd1.Scope",
276 "RequestStop");
277 if (r < 0)
278 return r;
279
280 return sd_bus_send_to(UNIT(s)->manager->api_bus, m, s->controller, NULL);
281 }
282
283 static int on_controller_gone(sd_bus_track *track, void *userdata) {
284 Scope *s = userdata;
285
286 assert(track);
287
288 if (s->controller) {
289 log_unit_debug(UNIT(s), "Controller %s disappeared from bus.", s->controller);
290 unit_add_to_dbus_queue(UNIT(s));
291 s->controller = mfree(s->controller);
292 }
293
294 s->controller_track = sd_bus_track_unref(s->controller_track);
295
296 return 0;
297 }
298
299 int bus_scope_track_controller(Scope *s) {
300 int r;
301
302 assert(s);
303
304 if (!s->controller || s->controller_track)
305 return 0;
306
307 r = sd_bus_track_new(UNIT(s)->manager->api_bus, &s->controller_track, on_controller_gone, s);
308 if (r < 0)
309 return r;
310
311 r = sd_bus_track_add_name(s->controller_track, s->controller);
312 if (r < 0) {
313 s->controller_track = sd_bus_track_unref(s->controller_track);
314 return r;
315 }
316
317 return 0;
318 }