1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2011 Lennart Poettering
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU Lesser General Public License as published by
10 the Free Software Foundation; either version 2.1 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Lesser General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
22 #include <sys/types.h>
27 #include "dbus-common.h"
40 DBusMessage *m = NULL, *reply = NULL;
41 const char *system_bus_name = "system-bus-name", *name = "name", *cancel_id = "";
42 uint32_t flags = interactive ? 1 : 0;
43 DBusMessageIter iter_msg, iter_struct, iter_array, iter_dict, iter_variant;
45 dbus_bool_t authorized = FALSE, challenge = FALSE;
53 sender = dbus_message_get_sender(request);
57 ul = dbus_bus_get_unix_user(c, sender, error);
58 if (ul == (unsigned long) -1)
61 /* Shortcut things for root, to avoid the PK roundtrip and dependency */
67 m = dbus_message_new_method_call(
68 "org.freedesktop.PolicyKit1",
69 "/org/freedesktop/PolicyKit1/Authority",
70 "org.freedesktop.PolicyKit1.Authority",
71 "CheckAuthorization");
75 dbus_message_iter_init_append(m, &iter_msg);
77 if (!dbus_message_iter_open_container(&iter_msg, DBUS_TYPE_STRUCT, NULL, &iter_struct) ||
78 !dbus_message_iter_append_basic(&iter_struct, DBUS_TYPE_STRING, &system_bus_name) ||
79 !dbus_message_iter_open_container(&iter_struct, DBUS_TYPE_ARRAY, "{sv}", &iter_array) ||
80 !dbus_message_iter_open_container(&iter_array, DBUS_TYPE_DICT_ENTRY, NULL, &iter_dict) ||
81 !dbus_message_iter_append_basic(&iter_dict, DBUS_TYPE_STRING, &name) ||
82 !dbus_message_iter_open_container(&iter_dict, DBUS_TYPE_VARIANT, "s", &iter_variant) ||
83 !dbus_message_iter_append_basic(&iter_variant, DBUS_TYPE_STRING, &sender) ||
84 !dbus_message_iter_close_container(&iter_dict, &iter_variant) ||
85 !dbus_message_iter_close_container(&iter_array, &iter_dict) ||
86 !dbus_message_iter_close_container(&iter_struct, &iter_array) ||
87 !dbus_message_iter_close_container(&iter_msg, &iter_struct) ||
88 !dbus_message_iter_append_basic(&iter_msg, DBUS_TYPE_STRING, &action) ||
89 !dbus_message_iter_open_container(&iter_msg, DBUS_TYPE_ARRAY, "{ss}", &iter_array) ||
90 !dbus_message_iter_close_container(&iter_msg, &iter_array) ||
91 !dbus_message_iter_append_basic(&iter_msg, DBUS_TYPE_UINT32, &flags) ||
92 !dbus_message_iter_append_basic(&iter_msg, DBUS_TYPE_STRING, &cancel_id)) {
97 reply = dbus_connection_send_with_reply_and_block(c, m, -1, error);
100 /* Treat no PK available as access denied */
101 if (dbus_error_has_name(error, DBUS_ERROR_SERVICE_UNKNOWN)) {
103 dbus_error_free(error);
111 if (!dbus_message_iter_init(reply, &iter_msg) ||
112 dbus_message_iter_get_arg_type(&iter_msg) != DBUS_TYPE_STRUCT) {
117 dbus_message_iter_recurse(&iter_msg, &iter_struct);
119 if (dbus_message_iter_get_arg_type(&iter_struct) != DBUS_TYPE_BOOLEAN) {
124 dbus_message_iter_get_basic(&iter_struct, &authorized);
126 if (!dbus_message_iter_next(&iter_struct) ||
127 dbus_message_iter_get_arg_type(&iter_struct) != DBUS_TYPE_BOOLEAN) {
132 dbus_message_iter_get_basic(&iter_struct, &challenge);
136 else if (_challenge) {
137 *_challenge = !!challenge;
144 dbus_message_unref(m);
147 dbus_message_unref(reply);