]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/core/dbus-scope.c
sd-bus: make name validation functions public
[thirdparty/systemd.git] / src / core / dbus-scope.c
CommitLineData
53e1b683 1/* SPDX-License-Identifier: LGPL-2.1+ */
6c12b52e 2
b5efdb8a 3#include "alloc-util.h"
96aad8d1 4#include "bus-common-errors.h"
b5efdb8a
LP
5#include "bus-internal.h"
6#include "bus-util.h"
1d22e906
LP
7#include "dbus-cgroup.h"
8#include "dbus-kill.h"
9#include "dbus-scope.h"
b5efdb8a 10#include "dbus-unit.h"
0fb0fffa 11#include "dbus-util.h"
b5efdb8a
LP
12#include "dbus.h"
13#include "scope.h"
14#include "selinux-access.h"
15#include "unit.h"
6c12b52e 16
c20076a8 17int bus_scope_method_abandon(sd_bus_message *message, void *userdata, sd_bus_error *error) {
a911bb9a 18 Scope *s = userdata;
4e2f8d27 19 int r;
a911bb9a 20
a911bb9a
LP
21 assert(message);
22 assert(s);
23
1d22e906
LP
24 r = mac_selinux_unit_access_check(UNIT(s), message, "stop", error);
25 if (r < 0)
26 return r;
27
28 r = bus_verify_manage_units_async(UNIT(s)->manager, message, error);
283868e1
SW
29 if (r < 0)
30 return r;
31 if (r == 0)
32 return 1; /* No authorization for now, but the async polkit stuff will call us again when it has it */
33
4e2f8d27 34 r = scope_abandon(s);
4e2f8d27
LP
35 if (r == -ESTALE)
36 return sd_bus_error_setf(error, BUS_ERROR_SCOPE_NOT_RUNNING, "Scope %s is not running, cannot abandon.", UNIT(s)->id);
1d22e906
LP
37 if (r < 0)
38 return r;
4e2f8d27
LP
39
40 return sd_bus_reply_method_return(message, NULL);
a911bb9a
LP
41}
42
718db961 43static BUS_DEFINE_PROPERTY_GET_ENUM(property_get_result, scope_result, ScopeResult);
6c12b52e 44
718db961
LP
45const sd_bus_vtable bus_scope_vtable[] = {
46 SD_BUS_VTABLE_START(0),
371c0b79 47 SD_BUS_PROPERTY("Controller", "s", NULL, offsetof(Scope, controller), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
556089dc 48 SD_BUS_PROPERTY("TimeoutStopUSec", "t", bus_property_get_usec, offsetof(Scope, timeout_stop_usec), SD_BUS_VTABLE_PROPERTY_CONST),
718db961 49 SD_BUS_PROPERTY("Result", "s", property_get_result, offsetof(Scope, result), SD_BUS_VTABLE_PROPERTY_EMITS_CHANGE),
9ed7de60 50 SD_BUS_PROPERTY("RuntimeMaxUSec", "t", bus_property_get_usec, offsetof(Scope, runtime_max_usec), SD_BUS_VTABLE_PROPERTY_CONST),
2d4a39e7 51 SD_BUS_SIGNAL("RequestStop", NULL, 0),
c20076a8 52 SD_BUS_METHOD("Abandon", NULL, NULL, bus_scope_method_abandon, SD_BUS_VTABLE_UNPRIVILEGED),
718db961
LP
53 SD_BUS_VTABLE_END
54};
6c12b52e 55
9f2e86af 56static int bus_scope_set_transient_property(
6c12b52e
LP
57 Scope *s,
58 const char *name,
718db961 59 sd_bus_message *message,
2e59b241 60 UnitWriteFlags flags,
718db961 61 sd_bus_error *error) {
6c12b52e 62
ef71cc77 63 Unit *u = UNIT(s);
6c12b52e
LP
64 int r;
65
6c12b52e 66 assert(s);
718db961
LP
67 assert(name);
68 assert(message);
6c12b52e 69
2e59b241
LP
70 flags |= UNIT_PRIVATE;
71
0fb0fffa 72 if (streq(name, "TimeoutStopUSec"))
ef71cc77 73 return bus_set_transient_usec(u, name, &s->timeout_stop_usec, message, flags, error);
0fb0fffa 74
9ed7de60
PW
75 if (streq(name, "RuntimeMaxUSec"))
76 return bus_set_transient_usec(u, name, &s->runtime_max_usec, message, flags, error);
77
6c12b52e 78 if (streq(name, "PIDs")) {
6592b975 79 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
294a90cc 80 unsigned n = 0;
6c12b52e 81
718db961
LP
82 r = sd_bus_message_enter_container(message, 'a', "u");
83 if (r < 0)
84 return r;
6c12b52e 85
6592b975
LP
86 for (;;) {
87 uint32_t upid;
88 pid_t pid;
89
90 r = sd_bus_message_read(message, "u", &upid);
91 if (r < 0)
92 return r;
93 if (r == 0)
94 break;
95
96 if (upid == 0) {
97 if (!creds) {
98 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_PID, &creds);
99 if (r < 0)
100 return r;
101 }
102
103 r = sd_bus_creds_get_pid(creds, &pid);
104 if (r < 0)
105 return r;
106 } else
107 pid = (uid_t) upid;
6c12b52e 108
ef71cc77 109 r = unit_pid_attachable(u, pid, error);
6592b975
LP
110 if (r < 0)
111 return r;
6c12b52e 112
2e59b241 113 if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
ef71cc77 114 r = unit_watch_pid(u, pid, false);
adb3a45d
LP
115 if (r < 0 && r != -EEXIST)
116 return r;
117 }
6c12b52e 118
adb3a45d 119 n++;
6c12b52e 120 }
718db961
LP
121
122 r = sd_bus_message_exit_container(message);
123 if (r < 0)
124 return r;
6c12b52e 125
adb3a45d 126 if (n <= 0)
6c12b52e
LP
127 return -EINVAL;
128
129 return 1;
cc23f9f1 130
2d4a39e7
LP
131 } else if (streq(name, "Controller")) {
132 const char *controller;
2d4a39e7 133
f2c49c86
LP
134 /* We can't support direct connections with this, as direct connections know no service or unique name
135 * concept, but the Controller field stores exactly that. */
ef71cc77 136 if (sd_bus_message_get_bus(message) != u->manager->api_bus)
f2c49c86
LP
137 return sd_bus_error_setf(error, SD_BUS_ERROR_NOT_SUPPORTED, "Sorry, Controller= logic only supported via the bus.");
138
2d4a39e7
LP
139 r = sd_bus_message_read(message, "s", &controller);
140 if (r < 0)
141 return r;
142
143 if (!isempty(controller) && !service_name_is_valid(controller))
144 return sd_bus_error_setf(error, SD_BUS_ERROR_INVALID_ARGS, "Controller '%s' is not a valid bus name.", controller);
145
2e59b241
LP
146 if (!UNIT_WRITE_FLAGS_NOOP(flags)) {
147 r = free_and_strdup(&s->controller, empty_to_null(controller));
148 if (r < 0)
149 return r;
2d4a39e7
LP
150 }
151
cc23f9f1 152 return 1;
6c12b52e
LP
153 }
154
155 return 0;
156}
157
158int bus_scope_set_property(
159 Unit *u,
160 const char *name,
718db961 161 sd_bus_message *message,
2e59b241 162 UnitWriteFlags flags,
718db961 163 sd_bus_error *error) {
6c12b52e
LP
164
165 Scope *s = SCOPE(u);
166 int r;
167
718db961 168 assert(s);
6c12b52e 169 assert(name);
718db961 170 assert(message);
6c12b52e 171
2e59b241 172 r = bus_cgroup_set_property(u, &s->cgroup_context, name, message, flags, error);
6c12b52e
LP
173 if (r != 0)
174 return r;
175
176 if (u->load_state == UNIT_STUB) {
177 /* While we are created we still accept PIDs */
178
2e59b241 179 r = bus_scope_set_transient_property(s, name, message, flags, error);
6c12b52e
LP
180 if (r != 0)
181 return r;
a6c0353b 182
2e59b241 183 r = bus_kill_context_set_transient_property(u, &s->kill_context, name, message, flags, error);
a6c0353b
LP
184 if (r != 0)
185 return r;
6c12b52e
LP
186 }
187
188 return 0;
189}
190
191int bus_scope_commit_properties(Unit *u) {
192 assert(u);
193
5af88058 194 unit_invalidate_cgroup_members_masks(u);
6c12b52e 195 unit_realize_cgroup(u);
bc432dc7 196
6c12b52e
LP
197 return 0;
198}
2d4a39e7
LP
199
200int bus_scope_send_request_stop(Scope *s) {
4afd3348 201 _cleanup_(sd_bus_message_unrefp) sd_bus_message *m = NULL;
2d4a39e7
LP
202 _cleanup_free_ char *p = NULL;
203 int r;
204
205 assert(s);
206
207 if (!s->controller)
208 return 0;
209
210 p = unit_dbus_path(UNIT(s));
211 if (!p)
212 return -ENOMEM;
213
214 r = sd_bus_message_new_signal(
215 UNIT(s)->manager->api_bus,
151b9b96 216 &m,
2d4a39e7
LP
217 p,
218 "org.freedesktop.systemd1.Scope",
151b9b96 219 "RequestStop");
2d4a39e7
LP
220 if (r < 0)
221 return r;
222
f4b0fb23 223 return sd_bus_send_to(UNIT(s)->manager->api_bus, m, s->controller, NULL);
2d4a39e7 224}
371c0b79
LP
225
226static int on_controller_gone(sd_bus_track *track, void *userdata) {
227 Scope *s = userdata;
228
229 assert(track);
230
231 if (s->controller) {
232 log_unit_debug(UNIT(s), "Controller %s disappeared from bus.", s->controller);
233 unit_add_to_dbus_queue(UNIT(s));
234 s->controller = mfree(s->controller);
235 }
236
237 s->controller_track = sd_bus_track_unref(s->controller_track);
238
239 return 0;
240}
241
242int bus_scope_track_controller(Scope *s) {
243 int r;
244
245 assert(s);
246
247 if (!s->controller || s->controller_track)
248 return 0;
249
250 r = sd_bus_track_new(UNIT(s)->manager->api_bus, &s->controller_track, on_controller_gone, s);
251 if (r < 0)
252 return r;
253
254 r = sd_bus_track_add_name(s->controller_track, s->controller);
255 if (r < 0) {
256 s->controller_track = sd_bus_track_unref(s->controller_track);
257 return r;
258 }
259
260 return 0;
261}