]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
machine: introduce io.system.Machine.{CopyFrom, CopyTo} methods
authorIvan Kruglov <mail@ikruglov.com>
Thu, 24 Oct 2024 10:19:56 +0000 (12:19 +0200)
committerIvan Kruglov <mail@ikruglov.com>
Mon, 6 Jan 2025 13:51:57 +0000 (14:51 +0100)
src/machine/machine-varlink.c
src/machine/machine-varlink.h
src/machine/machined-varlink.c
src/shared/varlink-io.systemd.Machine.c

index 4e5362783b669659fb244a97bcaf9c916184fe74..e932711311b2d6c26a8fda9f19327908781e070e 100644 (file)
@@ -7,6 +7,7 @@
 #include "sd-varlink.h"
 
 #include "bus-polkit.h"
+#include "copy.h"
 #include "fd-util.h"
 #include "hostname-util.h"
 #include "json-util.h"
@@ -825,3 +826,96 @@ int vl_method_bind_mount(sd_varlink *link, sd_json_variant *parameters, sd_varli
 
         return sd_varlink_reply(link, NULL);
 }
+
+typedef struct MachineCopyParameters {
+        const char *name;
+        PidRef pidref;
+        const char *src;
+        const char *dest;
+        bool replace;
+} MachineCopyParameters;
+
+static void machine_copy_paramaters_done(MachineCopyParameters *p) {
+        assert(p);
+
+        pidref_done(&p->pidref);
+}
+
+static int copy_done(Operation *operation, int ret, sd_bus_error *error) {
+        assert(operation);
+        assert(operation->link);
+
+        if (ERRNO_IS_PRIVILEGE(ret))
+                return sd_varlink_error(operation->link, SD_VARLINK_ERROR_PERMISSION_DENIED, NULL);
+        if (ERRNO_IS_NEG_NOT_SUPPORTED(ret))
+                return sd_varlink_error(operation->link, "io.systemd.Machine.NotSupported", NULL);
+        if (ret < 0)
+                return sd_varlink_error_errno(operation->link, ret);
+
+        return sd_varlink_reply(operation->link, NULL);
+}
+
+int vl_method_copy_internal(sd_varlink *link, sd_json_variant *parameters, sd_varlink_method_flags_t flags, void *userdata, bool copy_from) {
+        static const sd_json_dispatch_field dispatch_table[] = {
+                VARLINK_DISPATCH_MACHINE_LOOKUP_FIELDS(MachineCopyParameters),
+                { "source",      SD_JSON_VARIANT_STRING,  json_dispatch_const_path, offsetof(MachineCopyParameters, src),     SD_JSON_MANDATORY },
+                { "destination", SD_JSON_VARIANT_STRING,  json_dispatch_const_path, offsetof(MachineCopyParameters, dest),    0                 },
+                { "replace",     SD_JSON_VARIANT_BOOLEAN, sd_json_dispatch_stdbool, offsetof(MachineCopyParameters, replace), 0                 },
+                VARLINK_DISPATCH_POLKIT_FIELD,
+                {}
+        };
+
+        int r;
+        Manager *manager = ASSERT_PTR(userdata);
+        _cleanup_(machine_copy_paramaters_done) MachineCopyParameters p = {
+                .pidref = PIDREF_NULL
+        };
+
+        assert(link);
+        assert(parameters);
+
+        if (manager->n_operations >= OPERATIONS_MAX)
+                return sd_varlink_error(link, "io.systemd.MachineImage.TooManyOperations", NULL);
+
+        r = sd_varlink_dispatch(link, parameters, dispatch_table, &p);
+        if (r != 0)
+                return r;
+
+        /* There is no need for extra validation since json_dispatch_path() does path_is_valid() and path_is_absolute().*/
+        const char *dest = p.dest ?: p.src;
+        const char *container_path = copy_from ? p.src : dest;
+        const char *host_path = copy_from ? dest : p.src;
+        CopyFlags copy_flags = COPY_REFLINK|COPY_MERGE|COPY_HARDLINKS;
+        copy_flags |= p.replace ? COPY_REPLACE : 0;
+
+        Machine *machine;
+        r = lookup_machine_by_name_or_pidref(link, manager, p.name, &p.pidref, &machine);
+        if (r == -ESRCH)
+                return sd_varlink_error(link, "io.systemd.Machine.NoSuchMachine", NULL);
+        if (r != 0)
+                return r;
+
+        if (machine->class != MACHINE_CONTAINER)
+                return sd_varlink_error(link, "io.systemd.Machine.NotSupported", NULL);
+
+        r = varlink_verify_polkit_async(
+                        link,
+                        manager->bus,
+                        "org.freedesktop.machine1.manage-machines",
+                        (const char**) STRV_MAKE("name", machine->name,
+                                                 "verb", "copy",
+                                                 "src", p.src,
+                                                 "dest", dest),
+                        &manager->polkit_registry);
+        if (r <= 0)
+                return r;
+
+        Operation *op;
+        r = machine_copy_from_to(manager, machine, host_path, container_path, copy_from, copy_flags, &op);
+        if (r < 0)
+                return r;
+
+        operation_attach_varlink_reply(op, link);
+        op->done = copy_done;
+        return 1;
+}
index 401d8f5c6829178e0c1c5a5066be0c9dd7ec182c..bd80cb2653c93716228af77480e7e86cccd6fe41 100644 (file)
@@ -28,3 +28,4 @@ int vl_method_open(sd_varlink *link, sd_json_variant *parameters, sd_varlink_met
 int vl_method_map_from(sd_varlink *link, sd_json_variant *parameters, sd_varlink_method_flags_t flags, void *userdata);
 int vl_method_map_to(sd_varlink *link, sd_json_variant *parameters, sd_varlink_method_flags_t flags, void *userdata);
 int vl_method_bind_mount(sd_varlink *link, sd_json_variant *parameters, sd_varlink_method_flags_t flags, void *userdata);
+int vl_method_copy_internal(sd_varlink *link, sd_json_variant *parameters, sd_varlink_method_flags_t flags, void *userdata, bool copy_from);
index 68b31cf262d626b7e7803c76ce39c3ee2f36a2a8..e0de3aca012cdaad5ff597532ddc75e295fb5750 100644 (file)
@@ -591,6 +591,14 @@ static int vl_method_terminate(sd_varlink *link, sd_json_variant *parameters, sd
         return lookup_machine_and_call_method(link, parameters, flags, userdata, vl_method_terminate_internal);
 }
 
+static int vl_method_copy_from(sd_varlink *link, sd_json_variant *parameters, sd_varlink_method_flags_t flags, void *userdata) {
+        return vl_method_copy_internal(link, parameters, flags, userdata, /* copy_from = */ true);
+}
+
+static int vl_method_copy_to(sd_varlink *link, sd_json_variant *parameters, sd_varlink_method_flags_t flags, void *userdata) {
+        return vl_method_copy_internal(link, parameters, flags, userdata, /* copy_from = */ false);
+}
+
 static int list_image_one_and_maybe_read_metadata(sd_varlink *link, Image *image, bool more, AcquireMetadata am) {
         int r;
 
@@ -775,6 +783,8 @@ static int manager_varlink_init_machine(Manager *m) {
                         "io.systemd.Machine.MapFrom",     vl_method_map_from,
                         "io.systemd.Machine.MapTo",       vl_method_map_to,
                         "io.systemd.Machine.BindMount",   vl_method_bind_mount,
+                        "io.systemd.Machine.CopyFrom",    vl_method_copy_from,
+                        "io.systemd.Machine.CopyTo",      vl_method_copy_to,
                         "io.systemd.MachineImage.List",   vl_method_list_images,
                         "io.systemd.MachineImage.Update", vl_method_update_image,
                         "io.systemd.MachineImage.Clone",  vl_method_clone_image,
index 05a20bc4280c6a6d3cc1bcdc42009a06b916b685..1953f2fc612df4105fc6e6c05a9f0724793567ae 100644 (file)
@@ -159,6 +159,26 @@ static SD_VARLINK_DEFINE_METHOD(
                 SD_VARLINK_FIELD_COMMENT("The destination mount point shall be created first, if it is missing"),
                 SD_VARLINK_DEFINE_INPUT(mkdir, SD_VARLINK_BOOL, SD_VARLINK_NULLABLE));
 
+static SD_VARLINK_DEFINE_METHOD(
+                CopyFrom,
+                VARLINK_DEFINE_MACHINE_LOOKUP_AND_POLKIT_INPUT_FIELDS,
+                SD_VARLINK_FIELD_COMMENT("The absolute path to source directory/file in the container"),
+                SD_VARLINK_DEFINE_INPUT(source, SD_VARLINK_STRING, 0),
+                SD_VARLINK_FIELD_COMMENT("The absolute path to destination directory/file on the host. If null, it's equal to 'source'."),
+                SD_VARLINK_DEFINE_INPUT(destination, SD_VARLINK_STRING, SD_VARLINK_NULLABLE),
+                SD_VARLINK_FIELD_COMMENT("If true the destination will be replaced"),
+                SD_VARLINK_DEFINE_INPUT(replace, SD_VARLINK_BOOL, SD_VARLINK_NULLABLE));
+
+static SD_VARLINK_DEFINE_METHOD(
+                CopyTo,
+                VARLINK_DEFINE_MACHINE_LOOKUP_AND_POLKIT_INPUT_FIELDS,
+                SD_VARLINK_FIELD_COMMENT("The absolute path to source directory/file on the host"),
+                SD_VARLINK_DEFINE_INPUT(source, SD_VARLINK_STRING, 0),
+                SD_VARLINK_FIELD_COMMENT("The absolute path to destination directory/file in the container. If null, it's equal to 'source'"),
+                SD_VARLINK_DEFINE_INPUT(destination, SD_VARLINK_STRING, SD_VARLINK_NULLABLE),
+                SD_VARLINK_FIELD_COMMENT("If true the destination will be replaced"),
+                SD_VARLINK_DEFINE_INPUT(replace, SD_VARLINK_BOOL, SD_VARLINK_NULLABLE));
+
 static SD_VARLINK_DEFINE_ERROR(NoSuchMachine);
 static SD_VARLINK_DEFINE_ERROR(MachineExists);
 static SD_VARLINK_DEFINE_ERROR(NoPrivateNetworking);
@@ -201,6 +221,10 @@ SD_VARLINK_DEFINE_INTERFACE(
                 &vl_method_MapTo,
                 SD_VARLINK_SYMBOL_COMMENT("Bind mounts a file or directory from the host into the container"),
                 &vl_method_BindMount,
+                SD_VARLINK_SYMBOL_COMMENT("Copy files or directories from a container into the host"),
+                &vl_method_CopyFrom,
+                SD_VARLINK_SYMBOL_COMMENT("Copy files or directories from the host into a container"),
+                &vl_method_CopyTo,
                 SD_VARLINK_SYMBOL_COMMENT("No matching machine currently running"),
                 &vl_error_NoSuchMachine,
                 &vl_error_MachineExists,