]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/core/dbus.c
bab4a1a81b6e89ff24bc642e0cd79a49ccc7a2b9
[thirdparty/systemd.git] / src / core / dbus.c
1 /* SPDX-License-Identifier: LGPL-2.1+ */
2
3 #include <errno.h>
4 #include <sys/epoll.h>
5 #include <unistd.h>
6
7 #include "sd-bus.h"
8
9 #include "alloc-util.h"
10 #include "bus-common-errors.h"
11 #include "bus-error.h"
12 #include "bus-internal.h"
13 #include "bus-util.h"
14 #include "dbus-automount.h"
15 #include "dbus-cgroup.h"
16 #include "dbus-device.h"
17 #include "dbus-execute.h"
18 #include "dbus-job.h"
19 #include "dbus-kill.h"
20 #include "dbus-manager.h"
21 #include "dbus-mount.h"
22 #include "dbus-path.h"
23 #include "dbus-scope.h"
24 #include "dbus-service.h"
25 #include "dbus-slice.h"
26 #include "dbus-socket.h"
27 #include "dbus-swap.h"
28 #include "dbus-target.h"
29 #include "dbus-timer.h"
30 #include "dbus-unit.h"
31 #include "dbus.h"
32 #include "fd-util.h"
33 #include "fs-util.h"
34 #include "log.h"
35 #include "missing.h"
36 #include "mkdir.h"
37 #include "process-util.h"
38 #include "selinux-access.h"
39 #include "serialize.h"
40 #include "service.h"
41 #include "special.h"
42 #include "string-util.h"
43 #include "strv.h"
44 #include "strxcpyx.h"
45 #include "user-util.h"
46
47 #define CONNECTIONS_MAX 4096
48
49 static void destroy_bus(Manager *m, sd_bus **bus);
50
51 int bus_send_pending_reload_message(Manager *m) {
52 int r;
53
54 assert(m);
55
56 if (!m->pending_reload_message)
57 return 0;
58
59 /* If we cannot get rid of this message we won't dispatch any D-Bus messages, so that we won't end up wanting
60 * to queue another message. */
61
62 r = sd_bus_send(NULL, m->pending_reload_message, NULL);
63 if (r < 0)
64 log_warning_errno(r, "Failed to send queued message, ignoring: %m");
65
66 m->pending_reload_message = sd_bus_message_unref(m->pending_reload_message);
67
68 return 0;
69 }
70
71 int bus_forward_agent_released(Manager *m, const char *path) {
72 int r;
73
74 assert(m);
75 assert(path);
76
77 if (!MANAGER_IS_SYSTEM(m))
78 return 0;
79
80 if (!m->system_bus)
81 return 0;
82
83 /* If we are running a system instance we forward the agent message on the system bus, so that the user
84 * instances get notified about this, too */
85
86 r = sd_bus_emit_signal(m->system_bus,
87 "/org/freedesktop/systemd1/agent",
88 "org.freedesktop.systemd1.Agent",
89 "Released",
90 "s", path);
91 if (r < 0)
92 return log_debug_errno(r, "Failed to propagate agent release message: %m");
93
94 return 1;
95 }
96
97 static int signal_agent_released(sd_bus_message *message, void *userdata, sd_bus_error *error) {
98 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
99 Manager *m = userdata;
100 const char *cgroup;
101 uid_t sender_uid;
102 int r;
103
104 assert(message);
105 assert(m);
106
107 /* only accept org.freedesktop.systemd1.Agent from UID=0 */
108 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_EUID, &creds);
109 if (r < 0)
110 return r;
111
112 r = sd_bus_creds_get_euid(creds, &sender_uid);
113 if (r < 0 || sender_uid != 0)
114 return 0;
115
116 /* parse 'cgroup-empty' notification */
117 r = sd_bus_message_read(message, "s", &cgroup);
118 if (r < 0) {
119 bus_log_parse_error(r);
120 return 0;
121 }
122
123 manager_notify_cgroup_empty(m, cgroup);
124 return 0;
125 }
126
127 static int signal_disconnected(sd_bus_message *message, void *userdata, sd_bus_error *error) {
128 Manager *m = userdata;
129 sd_bus *bus;
130
131 assert(message);
132 assert(m);
133 assert_se(bus = sd_bus_message_get_bus(message));
134
135 if (bus == m->api_bus)
136 bus_done_api(m);
137 if (bus == m->system_bus)
138 bus_done_system(m);
139
140 if (set_remove(m->private_buses, bus)) {
141 log_debug("Got disconnect on private connection.");
142 destroy_bus(m, &bus);
143 }
144
145 return 0;
146 }
147
148 static int signal_activation_request(sd_bus_message *message, void *userdata, sd_bus_error *ret_error) {
149 _cleanup_(sd_bus_error_free) sd_bus_error error = SD_BUS_ERROR_NULL;
150 _cleanup_(sd_bus_message_unrefp) sd_bus_message *reply = NULL;
151 Manager *m = userdata;
152 const char *name;
153 Unit *u;
154 int r;
155
156 assert(message);
157 assert(m);
158
159 r = sd_bus_message_read(message, "s", &name);
160 if (r < 0) {
161 bus_log_parse_error(r);
162 return 0;
163 }
164
165 if (manager_unit_inactive_or_pending(m, SPECIAL_DBUS_SERVICE) ||
166 manager_unit_inactive_or_pending(m, SPECIAL_DBUS_SOCKET)) {
167 r = sd_bus_error_setf(&error, BUS_ERROR_SHUTTING_DOWN, "Refusing activation, D-Bus is shutting down.");
168 goto failed;
169 }
170
171 r = manager_load_unit(m, name, NULL, &error, &u);
172 if (r < 0)
173 goto failed;
174
175 if (u->refuse_manual_start) {
176 r = sd_bus_error_setf(&error, BUS_ERROR_ONLY_BY_DEPENDENCY, "Operation refused, %s may be requested by dependency only (it is configured to refuse manual start/stop).", u->id);
177 goto failed;
178 }
179
180 r = manager_add_job(m, JOB_START, u, JOB_REPLACE, &error, NULL);
181 if (r < 0)
182 goto failed;
183
184 /* Successfully queued, that's it for us */
185 return 0;
186
187 failed:
188 if (!sd_bus_error_is_set(&error))
189 sd_bus_error_set_errno(&error, r);
190
191 log_debug("D-Bus activation failed for %s: %s", name, bus_error_message(&error, r));
192
193 r = sd_bus_message_new_signal(sd_bus_message_get_bus(message), &reply, "/org/freedesktop/systemd1", "org.freedesktop.systemd1.Activator", "ActivationFailure");
194 if (r < 0) {
195 bus_log_create_error(r);
196 return 0;
197 }
198
199 r = sd_bus_message_append(reply, "sss", name, error.name, error.message);
200 if (r < 0) {
201 bus_log_create_error(r);
202 return 0;
203 }
204
205 r = sd_bus_send_to(NULL, reply, "org.freedesktop.DBus", NULL);
206 if (r < 0)
207 return log_error_errno(r, "Failed to respond with to bus activation request: %m");
208
209 return 0;
210 }
211
212 #if HAVE_SELINUX
213 static int mac_selinux_filter(sd_bus_message *message, void *userdata, sd_bus_error *error) {
214 Manager *m = userdata;
215 const char *verb, *path;
216 Unit *u = NULL;
217 Job *j;
218 int r;
219
220 assert(message);
221
222 /* Our own method calls are all protected individually with
223 * selinux checks, but the built-in interfaces need to be
224 * protected too. */
225
226 if (sd_bus_message_is_method_call(message, "org.freedesktop.DBus.Properties", "Set"))
227 verb = "reload";
228 else if (sd_bus_message_is_method_call(message, "org.freedesktop.DBus.Introspectable", NULL) ||
229 sd_bus_message_is_method_call(message, "org.freedesktop.DBus.Properties", NULL) ||
230 sd_bus_message_is_method_call(message, "org.freedesktop.DBus.ObjectManager", NULL) ||
231 sd_bus_message_is_method_call(message, "org.freedesktop.DBus.Peer", NULL))
232 verb = "status";
233 else
234 return 0;
235
236 path = sd_bus_message_get_path(message);
237
238 if (object_path_startswith("/org/freedesktop/systemd1", path)) {
239 r = mac_selinux_access_check(message, verb, error);
240 if (r < 0)
241 return r;
242
243 return 0;
244 }
245
246 if (streq_ptr(path, "/org/freedesktop/systemd1/unit/self")) {
247 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
248 pid_t pid;
249
250 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_PID, &creds);
251 if (r < 0)
252 return 0;
253
254 r = sd_bus_creds_get_pid(creds, &pid);
255 if (r < 0)
256 return 0;
257
258 u = manager_get_unit_by_pid(m, pid);
259 } else {
260 r = manager_get_job_from_dbus_path(m, path, &j);
261 if (r >= 0)
262 u = j->unit;
263 else
264 manager_load_unit_from_dbus_path(m, path, NULL, &u);
265 }
266 if (!u)
267 return 0;
268
269 r = mac_selinux_unit_access_check(u, message, verb, error);
270 if (r < 0)
271 return r;
272
273 return 0;
274 }
275 #endif
276
277 static int bus_job_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
278 Manager *m = userdata;
279 Job *j;
280 int r;
281
282 assert(bus);
283 assert(path);
284 assert(interface);
285 assert(found);
286 assert(m);
287
288 r = manager_get_job_from_dbus_path(m, path, &j);
289 if (r < 0)
290 return 0;
291
292 *found = j;
293 return 1;
294 }
295
296 static int find_unit(Manager *m, sd_bus *bus, const char *path, Unit **unit, sd_bus_error *error) {
297 Unit *u = NULL; /* just to appease gcc, initialization is not really necessary */
298 int r;
299
300 assert(m);
301 assert(bus);
302 assert(path);
303
304 if (streq_ptr(path, "/org/freedesktop/systemd1/unit/self")) {
305 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
306 sd_bus_message *message;
307 pid_t pid;
308
309 message = sd_bus_get_current_message(bus);
310 if (!message)
311 return 0;
312
313 r = sd_bus_query_sender_creds(message, SD_BUS_CREDS_PID, &creds);
314 if (r < 0)
315 return r;
316
317 r = sd_bus_creds_get_pid(creds, &pid);
318 if (r < 0)
319 return r;
320
321 u = manager_get_unit_by_pid(m, pid);
322 if (!u)
323 return 0;
324 } else {
325 r = manager_load_unit_from_dbus_path(m, path, error, &u);
326 if (r < 0)
327 return 0;
328 assert(u);
329 }
330
331 *unit = u;
332 return 1;
333 }
334
335 static int bus_unit_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
336 Manager *m = userdata;
337
338 assert(bus);
339 assert(path);
340 assert(interface);
341 assert(found);
342 assert(m);
343
344 return find_unit(m, bus, path, (Unit**) found, error);
345 }
346
347 static int bus_unit_interface_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
348 Manager *m = userdata;
349 Unit *u;
350 int r;
351
352 assert(bus);
353 assert(path);
354 assert(interface);
355 assert(found);
356 assert(m);
357
358 r = find_unit(m, bus, path, &u, error);
359 if (r <= 0)
360 return r;
361
362 if (!streq_ptr(interface, unit_dbus_interface_from_type(u->type)))
363 return 0;
364
365 *found = u;
366 return 1;
367 }
368
369 static int bus_unit_cgroup_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
370 Manager *m = userdata;
371 Unit *u;
372 int r;
373
374 assert(bus);
375 assert(path);
376 assert(interface);
377 assert(found);
378 assert(m);
379
380 r = find_unit(m, bus, path, &u, error);
381 if (r <= 0)
382 return r;
383
384 if (!streq_ptr(interface, unit_dbus_interface_from_type(u->type)))
385 return 0;
386
387 if (!UNIT_HAS_CGROUP_CONTEXT(u))
388 return 0;
389
390 *found = u;
391 return 1;
392 }
393
394 static int bus_cgroup_context_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
395 Manager *m = userdata;
396 CGroupContext *c;
397 Unit *u;
398 int r;
399
400 assert(bus);
401 assert(path);
402 assert(interface);
403 assert(found);
404 assert(m);
405
406 r = find_unit(m, bus, path, &u, error);
407 if (r <= 0)
408 return r;
409
410 if (!streq_ptr(interface, unit_dbus_interface_from_type(u->type)))
411 return 0;
412
413 c = unit_get_cgroup_context(u);
414 if (!c)
415 return 0;
416
417 *found = c;
418 return 1;
419 }
420
421 static int bus_exec_context_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
422 Manager *m = userdata;
423 ExecContext *c;
424 Unit *u;
425 int r;
426
427 assert(bus);
428 assert(path);
429 assert(interface);
430 assert(found);
431 assert(m);
432
433 r = find_unit(m, bus, path, &u, error);
434 if (r <= 0)
435 return r;
436
437 if (!streq_ptr(interface, unit_dbus_interface_from_type(u->type)))
438 return 0;
439
440 c = unit_get_exec_context(u);
441 if (!c)
442 return 0;
443
444 *found = c;
445 return 1;
446 }
447
448 static int bus_kill_context_find(sd_bus *bus, const char *path, const char *interface, void *userdata, void **found, sd_bus_error *error) {
449 Manager *m = userdata;
450 KillContext *c;
451 Unit *u;
452 int r;
453
454 assert(bus);
455 assert(path);
456 assert(interface);
457 assert(found);
458 assert(m);
459
460 r = find_unit(m, bus, path, &u, error);
461 if (r <= 0)
462 return r;
463
464 if (!streq_ptr(interface, unit_dbus_interface_from_type(u->type)))
465 return 0;
466
467 c = unit_get_kill_context(u);
468 if (!c)
469 return 0;
470
471 *found = c;
472 return 1;
473 }
474
475 static int bus_job_enumerate(sd_bus *bus, const char *path, void *userdata, char ***nodes, sd_bus_error *error) {
476 _cleanup_strv_free_ char **l = NULL;
477 Manager *m = userdata;
478 unsigned k = 0;
479 Iterator i;
480 Job *j;
481
482 l = new0(char*, hashmap_size(m->jobs)+1);
483 if (!l)
484 return -ENOMEM;
485
486 HASHMAP_FOREACH(j, m->jobs, i) {
487 l[k] = job_dbus_path(j);
488 if (!l[k])
489 return -ENOMEM;
490
491 k++;
492 }
493
494 assert(hashmap_size(m->jobs) == k);
495
496 *nodes = TAKE_PTR(l);
497
498 return k;
499 }
500
501 static int bus_unit_enumerate(sd_bus *bus, const char *path, void *userdata, char ***nodes, sd_bus_error *error) {
502 _cleanup_strv_free_ char **l = NULL;
503 Manager *m = userdata;
504 unsigned k = 0;
505 Iterator i;
506 Unit *u;
507
508 l = new0(char*, hashmap_size(m->units)+1);
509 if (!l)
510 return -ENOMEM;
511
512 HASHMAP_FOREACH(u, m->units, i) {
513 l[k] = unit_dbus_path(u);
514 if (!l[k])
515 return -ENOMEM;
516
517 k++;
518 }
519
520 *nodes = TAKE_PTR(l);
521
522 return k;
523 }
524
525 static int bus_setup_api_vtables(Manager *m, sd_bus *bus) {
526 UnitType t;
527 int r;
528
529 assert(m);
530 assert(bus);
531
532 #if HAVE_SELINUX
533 r = sd_bus_add_filter(bus, NULL, mac_selinux_filter, m);
534 if (r < 0)
535 return log_error_errno(r, "Failed to add SELinux access filter: %m");
536 #endif
537
538 r = sd_bus_add_object_vtable(bus, NULL, "/org/freedesktop/systemd1", "org.freedesktop.systemd1.Manager", bus_manager_vtable, m);
539 if (r < 0)
540 return log_error_errno(r, "Failed to register Manager vtable: %m");
541
542 r = sd_bus_add_fallback_vtable(bus, NULL, "/org/freedesktop/systemd1/job", "org.freedesktop.systemd1.Job", bus_job_vtable, bus_job_find, m);
543 if (r < 0)
544 return log_error_errno(r, "Failed to register Job vtable: %m");
545
546 r = sd_bus_add_node_enumerator(bus, NULL, "/org/freedesktop/systemd1/job", bus_job_enumerate, m);
547 if (r < 0)
548 return log_error_errno(r, "Failed to add job enumerator: %m");
549
550 r = sd_bus_add_fallback_vtable(bus, NULL, "/org/freedesktop/systemd1/unit", "org.freedesktop.systemd1.Unit", bus_unit_vtable, bus_unit_find, m);
551 if (r < 0)
552 return log_error_errno(r, "Failed to register Unit vtable: %m");
553
554 r = sd_bus_add_node_enumerator(bus, NULL, "/org/freedesktop/systemd1/unit", bus_unit_enumerate, m);
555 if (r < 0)
556 return log_error_errno(r, "Failed to add job enumerator: %m");
557
558 for (t = 0; t < _UNIT_TYPE_MAX; t++) {
559 const char *interface;
560
561 assert_se(interface = unit_dbus_interface_from_type(t));
562
563 r = sd_bus_add_fallback_vtable(bus, NULL, "/org/freedesktop/systemd1/unit", interface, unit_vtable[t]->bus_vtable, bus_unit_interface_find, m);
564 if (r < 0)
565 return log_error_errno(r, "Failed to register type specific vtable for %s: %m", interface);
566
567 if (unit_vtable[t]->cgroup_context_offset > 0) {
568 r = sd_bus_add_fallback_vtable(bus, NULL, "/org/freedesktop/systemd1/unit", interface, bus_unit_cgroup_vtable, bus_unit_cgroup_find, m);
569 if (r < 0)
570 return log_error_errno(r, "Failed to register control group unit vtable for %s: %m", interface);
571
572 r = sd_bus_add_fallback_vtable(bus, NULL, "/org/freedesktop/systemd1/unit", interface, bus_cgroup_vtable, bus_cgroup_context_find, m);
573 if (r < 0)
574 return log_error_errno(r, "Failed to register control group vtable for %s: %m", interface);
575 }
576
577 if (unit_vtable[t]->exec_context_offset > 0) {
578 r = sd_bus_add_fallback_vtable(bus, NULL, "/org/freedesktop/systemd1/unit", interface, bus_exec_vtable, bus_exec_context_find, m);
579 if (r < 0)
580 return log_error_errno(r, "Failed to register execute vtable for %s: %m", interface);
581 }
582
583 if (unit_vtable[t]->kill_context_offset > 0) {
584 r = sd_bus_add_fallback_vtable(bus, NULL, "/org/freedesktop/systemd1/unit", interface, bus_kill_vtable, bus_kill_context_find, m);
585 if (r < 0)
586 return log_error_errno(r, "Failed to register kill vtable for %s: %m", interface);
587 }
588 }
589
590 return 0;
591 }
592
593 static int bus_setup_disconnected_match(Manager *m, sd_bus *bus) {
594 int r;
595
596 assert(m);
597 assert(bus);
598
599 r = sd_bus_match_signal_async(
600 bus,
601 NULL,
602 "org.freedesktop.DBus.Local",
603 "/org/freedesktop/DBus/Local",
604 "org.freedesktop.DBus.Local",
605 "Disconnected",
606 signal_disconnected, NULL, m);
607 if (r < 0)
608 return log_error_errno(r, "Failed to request match for Disconnected message: %m");
609
610 return 0;
611 }
612
613 static int bus_on_connection(sd_event_source *s, int fd, uint32_t revents, void *userdata) {
614 _cleanup_(sd_bus_close_unrefp) sd_bus *bus = NULL;
615 _cleanup_close_ int nfd = -1;
616 Manager *m = userdata;
617 sd_id128_t id;
618 int r;
619
620 assert(s);
621 assert(m);
622
623 nfd = accept4(fd, NULL, NULL, SOCK_NONBLOCK|SOCK_CLOEXEC);
624 if (nfd < 0) {
625 log_warning_errno(errno, "Failed to accept private connection, ignoring: %m");
626 return 0;
627 }
628
629 if (set_size(m->private_buses) >= CONNECTIONS_MAX) {
630 log_warning("Too many concurrent connections, refusing");
631 return 0;
632 }
633
634 r = set_ensure_allocated(&m->private_buses, NULL);
635 if (r < 0) {
636 log_oom();
637 return 0;
638 }
639
640 r = sd_bus_new(&bus);
641 if (r < 0) {
642 log_warning_errno(r, "Failed to allocate new private connection bus: %m");
643 return 0;
644 }
645
646 (void) sd_bus_set_description(bus, "private-bus-connection");
647
648 r = sd_bus_set_fd(bus, nfd, nfd);
649 if (r < 0) {
650 log_warning_errno(r, "Failed to set fd on new connection bus: %m");
651 return 0;
652 }
653
654 nfd = -1;
655
656 r = bus_check_peercred(bus);
657 if (r < 0) {
658 log_warning_errno(r, "Incoming private connection from unprivileged client, refusing: %m");
659 return 0;
660 }
661
662 assert_se(sd_id128_randomize(&id) >= 0);
663
664 r = sd_bus_set_server(bus, 1, id);
665 if (r < 0) {
666 log_warning_errno(r, "Failed to enable server support for new connection bus: %m");
667 return 0;
668 }
669
670 r = sd_bus_negotiate_creds(bus, 1,
671 SD_BUS_CREDS_PID|SD_BUS_CREDS_UID|
672 SD_BUS_CREDS_EUID|SD_BUS_CREDS_EFFECTIVE_CAPS|
673 SD_BUS_CREDS_SELINUX_CONTEXT);
674 if (r < 0) {
675 log_warning_errno(r, "Failed to enable credentials for new connection: %m");
676 return 0;
677 }
678
679 r = sd_bus_set_sender(bus, "org.freedesktop.systemd1");
680 if (r < 0) {
681 log_warning_errno(r, "Failed to set direct connection sender: %m");
682 return 0;
683 }
684
685 r = sd_bus_start(bus);
686 if (r < 0) {
687 log_warning_errno(r, "Failed to start new connection bus: %m");
688 return 0;
689 }
690
691 r = sd_bus_attach_event(bus, m->event, SD_EVENT_PRIORITY_NORMAL);
692 if (r < 0) {
693 log_warning_errno(r, "Failed to attach new connection bus to event loop: %m");
694 return 0;
695 }
696
697 r = bus_setup_disconnected_match(m, bus);
698 if (r < 0)
699 return 0;
700
701 r = bus_setup_api_vtables(m, bus);
702 if (r < 0) {
703 log_warning_errno(r, "Failed to set up API vtables on new connection bus: %m");
704 return 0;
705 }
706
707 r = set_put(m->private_buses, bus);
708 if (r < 0) {
709 log_warning_errno(r, "Failed to add new connection bus to set: %m");
710 return 0;
711 }
712
713 bus = NULL;
714
715 log_debug("Accepted new private connection.");
716
717 return 0;
718 }
719
720 static int manager_dispatch_sync_bus_names(sd_event_source *es, void *userdata) {
721 _cleanup_strv_free_ char **names = NULL;
722 Manager *m = userdata;
723 const char *name;
724 Iterator i;
725 Unit *u;
726 int r;
727
728 assert(es);
729 assert(m);
730 assert(m->sync_bus_names_event_source == es);
731
732 /* First things first, destroy the defer event so that we aren't triggered again */
733 m->sync_bus_names_event_source = sd_event_source_unref(m->sync_bus_names_event_source);
734
735 /* Let's see if there's anything to do still? */
736 if (!m->api_bus)
737 return 0;
738 if (hashmap_isempty(m->watch_bus))
739 return 0;
740
741 /* OK, let's sync up the names. Let's see which names are currently on the bus. */
742 r = sd_bus_list_names(m->api_bus, &names, NULL);
743 if (r < 0)
744 return log_error_errno(r, "Failed to get initial list of names: %m");
745
746 /* We have to synchronize the current bus names with the
747 * list of active services. To do this, walk the list of
748 * all units with bus names. */
749 HASHMAP_FOREACH_KEY(u, name, m->watch_bus, i) {
750 Service *s = SERVICE(u);
751
752 assert(s);
753
754 if (!streq_ptr(s->bus_name, name)) {
755 log_unit_warning(u, "Bus name has changed from %s → %s, ignoring.", s->bus_name, name);
756 continue;
757 }
758
759 /* Check if a service's bus name is in the list of currently
760 * active names */
761 if (strv_contains(names, name)) {
762 _cleanup_(sd_bus_creds_unrefp) sd_bus_creds *creds = NULL;
763 const char *unique;
764
765 /* If it is, determine its current owner */
766 r = sd_bus_get_name_creds(m->api_bus, name, SD_BUS_CREDS_UNIQUE_NAME, &creds);
767 if (r < 0) {
768 log_full_errno(r == -ENXIO ? LOG_DEBUG : LOG_ERR, r, "Failed to get bus name owner %s: %m", name);
769 continue;
770 }
771
772 r = sd_bus_creds_get_unique_name(creds, &unique);
773 if (r < 0) {
774 log_full_errno(r == -ENXIO ? LOG_DEBUG : LOG_ERR, r, "Failed to get unique name for %s: %m", name);
775 continue;
776 }
777
778 /* Now, let's compare that to the previous bus owner, and
779 * if it's still the same, all is fine, so just don't
780 * bother the service. Otherwise, the name has apparently
781 * changed, so synthesize a name owner changed signal. */
782
783 if (!streq_ptr(unique, s->bus_name_owner))
784 UNIT_VTABLE(u)->bus_name_owner_change(u, name, s->bus_name_owner, unique);
785 } else {
786 /* So, the name we're watching is not on the bus.
787 * This either means it simply hasn't appeared yet,
788 * or it was lost during the daemon reload.
789 * Check if the service has a stored name owner,
790 * and synthesize a name loss signal in this case. */
791
792 if (s->bus_name_owner)
793 UNIT_VTABLE(u)->bus_name_owner_change(u, name, s->bus_name_owner, NULL);
794 }
795 }
796
797 return 0;
798 }
799
800 int manager_enqueue_sync_bus_names(Manager *m) {
801 int r;
802
803 assert(m);
804
805 /* Enqueues a request to synchronize the bus names in a later event loop iteration. The callers generally don't
806 * want us to invoke ->bus_name_owner_change() unit calls from their stack frames as this might result in event
807 * dispatching on its own creating loops, hence we simply create a defer event for the event loop and exit. */
808
809 if (m->sync_bus_names_event_source)
810 return 0;
811
812 r = sd_event_add_defer(m->event, &m->sync_bus_names_event_source, manager_dispatch_sync_bus_names, m);
813 if (r < 0)
814 return log_error_errno(r, "Failed to create bus name synchronization event: %m");
815
816 r = sd_event_source_set_priority(m->sync_bus_names_event_source, SD_EVENT_PRIORITY_IDLE);
817 if (r < 0)
818 return log_error_errno(r, "Failed to set event priority: %m");
819
820 r = sd_event_source_set_enabled(m->sync_bus_names_event_source, SD_EVENT_ONESHOT);
821 if (r < 0)
822 return log_error_errno(r, "Failed to set even to oneshot: %m");
823
824 (void) sd_event_source_set_description(m->sync_bus_names_event_source, "manager-sync-bus-names");
825 return 0;
826 }
827
828 static int bus_setup_api(Manager *m, sd_bus *bus) {
829 Iterator i;
830 char *name;
831 Unit *u;
832 int r;
833
834 assert(m);
835 assert(bus);
836
837 /* Let's make sure we have enough credential bits so that we can make security and selinux decisions */
838 r = sd_bus_negotiate_creds(bus, 1,
839 SD_BUS_CREDS_PID|SD_BUS_CREDS_UID|
840 SD_BUS_CREDS_EUID|SD_BUS_CREDS_EFFECTIVE_CAPS|
841 SD_BUS_CREDS_SELINUX_CONTEXT);
842 if (r < 0)
843 log_warning_errno(r, "Failed to enable credential passing, ignoring: %m");
844
845 r = bus_setup_api_vtables(m, bus);
846 if (r < 0)
847 return r;
848
849 HASHMAP_FOREACH_KEY(u, name, m->watch_bus, i) {
850 r = unit_install_bus_match(u, bus, name);
851 if (r < 0)
852 log_error_errno(r, "Failed to subscribe to NameOwnerChanged signal for '%s': %m", name);
853 }
854
855 r = sd_bus_match_signal_async(
856 bus,
857 NULL,
858 "org.freedesktop.DBus",
859 "/org/freedesktop/DBus",
860 "org.freedesktop.systemd1.Activator",
861 "ActivationRequest",
862 signal_activation_request, NULL, m);
863 if (r < 0)
864 log_warning_errno(r, "Failed to subscribe to activation signal: %m");
865
866 /* Allow replacing of our name, to ease implementation of reexecution, where we keep the old connection open
867 * until after the new connection is set up and the name installed to allow clients to synchronously wait for
868 * reexecution to finish */
869 r = sd_bus_request_name_async(bus, NULL, "org.freedesktop.systemd1", SD_BUS_NAME_REPLACE_EXISTING|SD_BUS_NAME_ALLOW_REPLACEMENT, NULL, NULL);
870 if (r < 0)
871 return log_error_errno(r, "Failed to request name: %m");
872
873 log_debug("Successfully connected to API bus.");
874
875 return 0;
876 }
877
878 int bus_init_api(Manager *m) {
879 _cleanup_(sd_bus_close_unrefp) sd_bus *bus = NULL;
880 int r;
881
882 if (m->api_bus)
883 return 0;
884
885 /* The API and system bus is the same if we are running in system mode */
886 if (MANAGER_IS_SYSTEM(m) && m->system_bus)
887 bus = sd_bus_ref(m->system_bus);
888 else {
889 if (MANAGER_IS_SYSTEM(m))
890 r = sd_bus_open_system_with_description(&bus, "bus-api-system");
891 else
892 r = sd_bus_open_user_with_description(&bus, "bus-api-user");
893 if (r < 0)
894 return log_error_errno(r, "Failed to connect to API bus: %m");
895
896 r = sd_bus_attach_event(bus, m->event, SD_EVENT_PRIORITY_NORMAL);
897 if (r < 0)
898 return log_error_errno(r, "Failed to attach API bus to event loop: %m");
899
900 r = bus_setup_disconnected_match(m, bus);
901 if (r < 0)
902 return r;
903 }
904
905 r = bus_setup_api(m, bus);
906 if (r < 0)
907 return log_error_errno(r, "Failed to set up API bus: %m");
908
909 m->api_bus = TAKE_PTR(bus);
910
911 r = manager_enqueue_sync_bus_names(m);
912 if (r < 0)
913 return r;
914
915 return 0;
916 }
917
918 static int bus_setup_system(Manager *m, sd_bus *bus) {
919 int r;
920
921 assert(m);
922 assert(bus);
923
924 /* if we are a user instance we get the Released message via the system bus */
925 if (MANAGER_IS_USER(m)) {
926 r = sd_bus_match_signal_async(
927 bus,
928 NULL,
929 NULL,
930 "/org/freedesktop/systemd1/agent",
931 "org.freedesktop.systemd1.Agent",
932 "Released",
933 signal_agent_released, NULL, m);
934 if (r < 0)
935 log_warning_errno(r, "Failed to request Released match on system bus: %m");
936 }
937
938 log_debug("Successfully connected to system bus.");
939 return 0;
940 }
941
942 int bus_init_system(Manager *m) {
943 _cleanup_(sd_bus_close_unrefp) sd_bus *bus = NULL;
944 int r;
945
946 if (m->system_bus)
947 return 0;
948
949 /* The API and system bus is the same if we are running in system mode */
950 if (MANAGER_IS_SYSTEM(m) && m->api_bus)
951 bus = sd_bus_ref(m->api_bus);
952 else {
953 r = sd_bus_open_system_with_description(&bus, "bus-system");
954 if (r < 0)
955 return log_error_errno(r, "Failed to connect to system bus: %m");
956
957 r = sd_bus_attach_event(bus, m->event, SD_EVENT_PRIORITY_NORMAL);
958 if (r < 0)
959 return log_error_errno(r, "Failed to attach system bus to event loop: %m");
960
961 r = bus_setup_disconnected_match(m, bus);
962 if (r < 0)
963 return r;
964 }
965
966 r = bus_setup_system(m, bus);
967 if (r < 0)
968 return log_error_errno(r, "Failed to set up system bus: %m");
969
970 m->system_bus = TAKE_PTR(bus);
971
972 return 0;
973 }
974
975 int bus_init_private(Manager *m) {
976 _cleanup_close_ int fd = -1;
977 union sockaddr_union sa = {};
978 sd_event_source *s;
979 int r, salen;
980
981 assert(m);
982
983 if (m->private_listen_fd >= 0)
984 return 0;
985
986 if (MANAGER_IS_SYSTEM(m)) {
987
988 /* We want the private bus only when running as init */
989 if (getpid_cached() != 1)
990 return 0;
991
992 salen = sockaddr_un_set_path(&sa.un, "/run/systemd/private");
993 } else {
994 const char *e, *joined;
995
996 e = secure_getenv("XDG_RUNTIME_DIR");
997 if (!e)
998 return log_error_errno(SYNTHETIC_ERRNO(EHOSTDOWN),
999 "XDG_RUNTIME_DIR is not set, refusing.");
1000
1001 joined = strjoina(e, "/systemd/private");
1002 salen = sockaddr_un_set_path(&sa.un, joined);
1003 }
1004 if (salen < 0)
1005 return log_error_errno(salen, "Can't set path for AF_UNIX socket to bind to: %m");
1006
1007 (void) mkdir_parents_label(sa.un.sun_path, 0755);
1008 (void) sockaddr_un_unlink(&sa.un);
1009
1010 fd = socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0);
1011 if (fd < 0)
1012 return log_error_errno(errno, "Failed to allocate private socket: %m");
1013
1014 r = bind(fd, &sa.sa, salen);
1015 if (r < 0)
1016 return log_error_errno(errno, "Failed to bind private socket: %m");
1017
1018 r = listen(fd, SOMAXCONN);
1019 if (r < 0)
1020 return log_error_errno(errno, "Failed to make private socket listening: %m");
1021
1022 /* Generate an inotify event in case somebody waits for this socket to appear using inotify() */
1023 (void) touch(sa.un.sun_path);
1024
1025 r = sd_event_add_io(m->event, &s, fd, EPOLLIN, bus_on_connection, m);
1026 if (r < 0)
1027 return log_error_errno(r, "Failed to allocate event source: %m");
1028
1029 (void) sd_event_source_set_description(s, "bus-connection");
1030
1031 m->private_listen_fd = TAKE_FD(fd);
1032 m->private_listen_event_source = s;
1033
1034 log_debug("Successfully created private D-Bus server.");
1035
1036 return 0;
1037 }
1038
1039 static void destroy_bus(Manager *m, sd_bus **bus) {
1040 Iterator i;
1041 Unit *u;
1042 Job *j;
1043
1044 assert(m);
1045 assert(bus);
1046
1047 if (!*bus)
1048 return;
1049
1050 /* Make sure all bus slots watching names are released. */
1051 HASHMAP_FOREACH(u, m->watch_bus, i) {
1052 if (!u->match_bus_slot)
1053 continue;
1054
1055 if (sd_bus_slot_get_bus(u->match_bus_slot) != *bus)
1056 continue;
1057
1058 u->match_bus_slot = sd_bus_slot_unref(u->match_bus_slot);
1059 }
1060
1061 /* Get rid of tracked clients on this bus */
1062 if (m->subscribed && sd_bus_track_get_bus(m->subscribed) == *bus)
1063 m->subscribed = sd_bus_track_unref(m->subscribed);
1064
1065 HASHMAP_FOREACH(j, m->jobs, i)
1066 if (j->bus_track && sd_bus_track_get_bus(j->bus_track) == *bus)
1067 j->bus_track = sd_bus_track_unref(j->bus_track);
1068
1069 HASHMAP_FOREACH(u, m->units, i)
1070 if (u->bus_track && sd_bus_track_get_bus(u->bus_track) == *bus)
1071 u->bus_track = sd_bus_track_unref(u->bus_track);
1072
1073 /* Get rid of queued message on this bus */
1074 if (m->pending_reload_message && sd_bus_message_get_bus(m->pending_reload_message) == *bus)
1075 m->pending_reload_message = sd_bus_message_unref(m->pending_reload_message);
1076
1077 /* Possibly flush unwritten data, but only if we are
1078 * unprivileged, since we don't want to sync here */
1079 if (!MANAGER_IS_SYSTEM(m))
1080 sd_bus_flush(*bus);
1081
1082 /* And destroy the object */
1083 sd_bus_close(*bus);
1084 *bus = sd_bus_unref(*bus);
1085 }
1086
1087 void bus_done_api(Manager *m) {
1088 destroy_bus(m, &m->api_bus);
1089 }
1090
1091 void bus_done_system(Manager *m) {
1092 destroy_bus(m, &m->system_bus);
1093 }
1094
1095 void bus_done_private(Manager *m) {
1096 sd_bus *b;
1097
1098 assert(m);
1099
1100 while ((b = set_steal_first(m->private_buses)))
1101 destroy_bus(m, &b);
1102
1103 m->private_buses = set_free(m->private_buses);
1104
1105 m->private_listen_event_source = sd_event_source_unref(m->private_listen_event_source);
1106 m->private_listen_fd = safe_close(m->private_listen_fd);
1107 }
1108
1109 void bus_done(Manager *m) {
1110 assert(m);
1111
1112 bus_done_api(m);
1113 bus_done_system(m);
1114 bus_done_private(m);
1115
1116 assert(!m->subscribed);
1117
1118 m->deserialized_subscribed = strv_free(m->deserialized_subscribed);
1119 bus_verify_polkit_async_registry_free(m->polkit_registry);
1120 }
1121
1122 int bus_fdset_add_all(Manager *m, FDSet *fds) {
1123 Iterator i;
1124 sd_bus *b;
1125 int fd;
1126
1127 assert(m);
1128 assert(fds);
1129
1130 /* When we are about to reexecute we add all D-Bus fds to the
1131 * set to pass over to the newly executed systemd. They won't
1132 * be used there however, except thatt they are closed at the
1133 * very end of deserialization, those making it possible for
1134 * clients to synchronously wait for systemd to reexec by
1135 * simply waiting for disconnection */
1136
1137 if (m->api_bus) {
1138 fd = sd_bus_get_fd(m->api_bus);
1139 if (fd >= 0) {
1140 fd = fdset_put_dup(fds, fd);
1141 if (fd < 0)
1142 return fd;
1143 }
1144 }
1145
1146 SET_FOREACH(b, m->private_buses, i) {
1147 fd = sd_bus_get_fd(b);
1148 if (fd >= 0) {
1149 fd = fdset_put_dup(fds, fd);
1150 if (fd < 0)
1151 return fd;
1152 }
1153 }
1154
1155 /* We don't offer any APIs on the system bus (well, unless it
1156 * is the same as the API bus) hence we don't bother with it
1157 * here */
1158
1159 return 0;
1160 }
1161
1162 int bus_foreach_bus(
1163 Manager *m,
1164 sd_bus_track *subscribed2,
1165 int (*send_message)(sd_bus *bus, void *userdata),
1166 void *userdata) {
1167
1168 Iterator i;
1169 sd_bus *b;
1170 int r, ret = 0;
1171
1172 /* Send to all direct buses, unconditionally */
1173 SET_FOREACH(b, m->private_buses, i) {
1174
1175 /* Don't bother with enqueing these messages to clients that haven't started yet */
1176 if (sd_bus_is_ready(b) <= 0)
1177 continue;
1178
1179 r = send_message(b, userdata);
1180 if (r < 0)
1181 ret = r;
1182 }
1183
1184 /* Send to API bus, but only if somebody is subscribed */
1185 if (m->api_bus &&
1186 (sd_bus_track_count(m->subscribed) > 0 ||
1187 sd_bus_track_count(subscribed2) > 0)) {
1188 r = send_message(m->api_bus, userdata);
1189 if (r < 0)
1190 ret = r;
1191 }
1192
1193 return ret;
1194 }
1195
1196 void bus_track_serialize(sd_bus_track *t, FILE *f, const char *prefix) {
1197 const char *n;
1198
1199 assert(f);
1200 assert(prefix);
1201
1202 for (n = sd_bus_track_first(t); n; n = sd_bus_track_next(t)) {
1203 int c, j;
1204
1205 c = sd_bus_track_count_name(t, n);
1206 for (j = 0; j < c; j++)
1207 (void) serialize_item(f, prefix, n);
1208 }
1209 }
1210
1211 int bus_track_coldplug(Manager *m, sd_bus_track **t, bool recursive, char **l) {
1212 int r = 0;
1213
1214 assert(m);
1215 assert(t);
1216
1217 if (strv_isempty(l))
1218 return 0;
1219
1220 if (!m->api_bus)
1221 return 0;
1222
1223 if (!*t) {
1224 r = sd_bus_track_new(m->api_bus, t, NULL, NULL);
1225 if (r < 0)
1226 return r;
1227 }
1228
1229 r = sd_bus_track_set_recursive(*t, recursive);
1230 if (r < 0)
1231 return r;
1232
1233 return bus_track_add_name_many(*t, l);
1234 }
1235
1236 int bus_verify_manage_units_async(Manager *m, sd_bus_message *call, sd_bus_error *error) {
1237 return bus_verify_polkit_async(call, CAP_SYS_ADMIN, "org.freedesktop.systemd1.manage-units", NULL, false, UID_INVALID, &m->polkit_registry, error);
1238 }
1239
1240 int bus_verify_manage_unit_files_async(Manager *m, sd_bus_message *call, sd_bus_error *error) {
1241 return bus_verify_polkit_async(call, CAP_SYS_ADMIN, "org.freedesktop.systemd1.manage-unit-files", NULL, false, UID_INVALID, &m->polkit_registry, error);
1242 }
1243
1244 int bus_verify_reload_daemon_async(Manager *m, sd_bus_message *call, sd_bus_error *error) {
1245 return bus_verify_polkit_async(call, CAP_SYS_ADMIN, "org.freedesktop.systemd1.reload-daemon", NULL, false, UID_INVALID, &m->polkit_registry, error);
1246 }
1247
1248 int bus_verify_set_environment_async(Manager *m, sd_bus_message *call, sd_bus_error *error) {
1249 return bus_verify_polkit_async(call, CAP_SYS_ADMIN, "org.freedesktop.systemd1.set-environment", NULL, false, UID_INVALID, &m->polkit_registry, error);
1250 }
1251
1252 uint64_t manager_bus_n_queued_write(Manager *m) {
1253 uint64_t c = 0;
1254 Iterator i;
1255 sd_bus *b;
1256 int r;
1257
1258 /* Returns the total number of messages queued for writing on all our direct and API busses. */
1259
1260 SET_FOREACH(b, m->private_buses, i) {
1261 uint64_t k;
1262
1263 r = sd_bus_get_n_queued_write(b, &k);
1264 if (r < 0)
1265 log_debug_errno(r, "Failed to query queued messages for private bus: %m");
1266 else
1267 c += k;
1268 }
1269
1270 if (m->api_bus) {
1271 uint64_t k;
1272
1273 r = sd_bus_get_n_queued_write(m->api_bus, &k);
1274 if (r < 0)
1275 log_debug_errno(r, "Failed to query queued messages for API bus: %m");
1276 else
1277 c += k;
1278 }
1279
1280 return c;
1281 }
1282
1283 static void vtable_dump_bus_properties(FILE *f, const sd_bus_vtable *table) {
1284 const sd_bus_vtable *i;
1285
1286 for (i = table; i->type != _SD_BUS_VTABLE_END; i++) {
1287 if (!IN_SET(i->type, _SD_BUS_VTABLE_PROPERTY, _SD_BUS_VTABLE_WRITABLE_PROPERTY) ||
1288 (i->flags & (SD_BUS_VTABLE_DEPRECATED | SD_BUS_VTABLE_HIDDEN)) != 0)
1289 continue;
1290
1291 fprintf(f, "%s\n", i->x.property.member);
1292 }
1293 }
1294
1295 void dump_bus_properties(FILE *f) {
1296 assert(f);
1297
1298 vtable_dump_bus_properties(f, bus_automount_vtable);
1299 vtable_dump_bus_properties(f, bus_cgroup_vtable);
1300 vtable_dump_bus_properties(f, bus_device_vtable);
1301 vtable_dump_bus_properties(f, bus_exec_vtable);
1302 vtable_dump_bus_properties(f, bus_job_vtable);
1303 vtable_dump_bus_properties(f, bus_kill_vtable);
1304 vtable_dump_bus_properties(f, bus_manager_vtable);
1305 vtable_dump_bus_properties(f, bus_mount_vtable);
1306 vtable_dump_bus_properties(f, bus_path_vtable);
1307 vtable_dump_bus_properties(f, bus_scope_vtable);
1308 vtable_dump_bus_properties(f, bus_service_vtable);
1309 vtable_dump_bus_properties(f, bus_slice_vtable);
1310 vtable_dump_bus_properties(f, bus_socket_vtable);
1311 vtable_dump_bus_properties(f, bus_swap_vtable);
1312 vtable_dump_bus_properties(f, bus_target_vtable);
1313 vtable_dump_bus_properties(f, bus_timer_vtable);
1314 vtable_dump_bus_properties(f, bus_unit_vtable);
1315 vtable_dump_bus_properties(f, bus_unit_cgroup_vtable);
1316 }