This file is part of systemd.
Copyright 2010 Lennart Poettering
+ Copyright 2013 Daniel Mack
+ Copyright 2014 Kay Sievers
+ Copyright 2015 David Herrmann
systemd is free software; you can redistribute it and/or modify it
under the terms of the GNU Lesser General Public License as published by
#include <unistd.h>
#include <string.h>
#include <errno.h>
-#include <sys/poll.h>
+#include <poll.h>
+#include <sys/prctl.h>
#include <stddef.h>
#include <getopt.h>
+#include <pthread.h>
#include "log.h"
#include "util.h"
+#include "hashmap.h"
#include "socket-util.h"
#include "sd-daemon.h"
#include "sd-bus.h"
#include "bus-message.h"
#include "bus-util.h"
#include "build.h"
+#include "strv.h"
+#include "def.h"
+#include "capability.h"
+#include "bus-control.h"
+#include "smack-util.h"
+#include "set.h"
+#include "bus-xml-policy.h"
+#include "driver.h"
+#include "proxy.h"
+#include "synthesize.h"
+
+static char *arg_address = NULL;
+static char **arg_configuration = NULL;
+
+typedef struct {
+ int fd;
+ SharedPolicy *policy;
+ uid_t bus_uid;
+} ClientContext;
+
+static ClientContext *client_context_free(ClientContext *c) {
+ if (!c)
+ return NULL;
+
+ safe_close(c->fd);
+ free(c);
+
+ return NULL;
+}
+
+DEFINE_TRIVIAL_CLEANUP_FUNC(ClientContext*, client_context_free);
+
+static int client_context_new(ClientContext **out) {
+ _cleanup_(client_context_freep) ClientContext *c = NULL;
+
+ c = new0(ClientContext, 1);
+ if (!c)
+ return log_oom();
+
+ c->fd = -1;
+
+ *out = c;
+ c = NULL;
+ return 0;
+}
+
+static void *run_client(void *userdata) {
+ _cleanup_(client_context_freep) ClientContext *c = userdata;
+ _cleanup_(proxy_freep) Proxy *p = NULL;
+ char comm[16];
+ int r;
+
+ r = proxy_new(&p, c->fd, c->fd, arg_address);
+ if (r < 0)
+ goto exit;
-#define DEFAULT_BUS_PATH "unix:path=/run/dbus/system_bus_socket"
+ c->fd = -1;
+
+ /* set comm to "p$PIDu$UID" and suffix with '*' if truncated */
+ r = snprintf(comm, sizeof(comm), "p" PID_FMT "u" UID_FMT, p->local_creds.pid, p->local_creds.uid);
+ if (r >= (ssize_t)sizeof(comm))
+ comm[sizeof(comm) - 2] = '*';
+ (void) prctl(PR_SET_NAME, comm);
+
+ r = proxy_set_policy(p, c->policy, arg_configuration);
+ if (r < 0)
+ goto exit;
+
+ r = proxy_hello_policy(p, c->bus_uid);
+ if (r < 0)
+ goto exit;
+
+ r = proxy_run(p);
+
+exit:
+ return NULL;
+}
+
+static int loop_clients(int accept_fd, uid_t bus_uid) {
+ _cleanup_(shared_policy_freep) SharedPolicy *sp = NULL;
+ pthread_attr_t attr;
+ int r;
+
+ r = pthread_attr_init(&attr);
+ if (r < 0) {
+ r = log_error_errno(errno, "Cannot initialize pthread attributes: %m");
+ goto exit;
+ }
+
+ r = pthread_attr_setdetachstate(&attr, PTHREAD_CREATE_DETACHED);
+ if (r < 0) {
+ r = log_error_errno(errno, "Cannot mark pthread attributes as detached: %m");
+ goto exit_attr;
+ }
+
+ r = shared_policy_new(&sp);
+ if (r < 0)
+ goto exit_attr;
+
+ for (;;) {
+ ClientContext *c;
+ pthread_t tid;
+ int fd;
+
+ fd = accept4(accept_fd, NULL, NULL, SOCK_NONBLOCK | SOCK_CLOEXEC);
+ if (fd < 0) {
+ if (errno == EAGAIN || errno == EINTR)
+ continue;
+
+ r = log_error_errno(errno, "accept4() failed: %m");
+ break;
+ }
+
+ r = client_context_new(&c);
+ if (r < 0) {
+ log_oom();
+ close(fd);
+ continue;
+ }
+
+ c->fd = fd;
+ c->policy = sp;
+ c->bus_uid = bus_uid;
+
+ r = pthread_create(&tid, &attr, run_client, c);
+ if (r < 0) {
+ log_error("Cannot spawn thread: %m");
+ client_context_free(c);
+ continue;
+ }
+ }
-const char *arg_bus_path = DEFAULT_BUS_PATH;
+exit_attr:
+ pthread_attr_destroy(&attr);
+exit:
+ return r;
+}
static int help(void) {
printf("%s [OPTIONS...]\n\n"
- "STDIO or socket-activatable proxy to a given DBus endpoint.\n\n"
- " -h --help Show this help\n"
- " --version Show package version\n"
- " --bus-path=PATH Path to the kernel bus (default: %s)\n",
- program_invocation_short_name, DEFAULT_BUS_PATH);
+ "DBus proxy server.\n\n"
+ " -h --help Show this help\n"
+ " --version Show package version\n"
+ " --configuration=PATH Configuration file or directory\n"
+ " --machine=MACHINE Connect to specified machine\n"
+ " --address=ADDRESS Connect to the bus specified by ADDRESS\n"
+ " (default: " DEFAULT_SYSTEM_BUS_ADDRESS ")\n",
+ program_invocation_short_name);
return 0;
}
enum {
ARG_VERSION = 0x100,
+ ARG_ADDRESS,
+ ARG_CONFIGURATION,
+ ARG_MACHINE,
};
static const struct option options[] = {
- { "help", no_argument, NULL, 'h' },
- { "bus-path", required_argument, NULL, 'p' },
- { NULL, 0, NULL, 0 }
+ { "help", no_argument, NULL, 'h' },
+ { "version", no_argument, NULL, ARG_VERSION },
+ { "address", required_argument, NULL, ARG_ADDRESS },
+ { "configuration", required_argument, NULL, ARG_CONFIGURATION },
+ { "machine", required_argument, NULL, ARG_MACHINE },
+ {},
};
- int c;
+ int c, r;
assert(argc >= 0);
assert(argv);
- while ((c = getopt_long(argc, argv, "hsup:", options, NULL)) >= 0) {
+ while ((c = getopt_long(argc, argv, "h", options, NULL)) >= 0)
switch (c) {
puts(SYSTEMD_FEATURES);
return 0;
- case '?':
- return -EINVAL;
+ case ARG_ADDRESS: {
+ char *a;
- case 'p':
- arg_bus_path = optarg;
- break;
+ a = strdup(optarg);
+ if (!a)
+ return log_oom();
- default:
- log_error("Unknown option code %c", c);
- return -EINVAL;
+ free(arg_address);
+ arg_address = a;
+ break;
}
- }
- return 1;
-}
-
-int main(int argc, char *argv[]) {
- _cleanup_bus_unref_ sd_bus *a = NULL, *b = NULL;
- sd_id128_t server_id;
- bool is_unix;
- int r, in_fd, out_fd;
-
- log_set_target(LOG_TARGET_JOURNAL_OR_KMSG);
- log_parse_environment();
- log_open();
-
- r = parse_argv(argc, argv);
- if (r <= 0)
- goto finish;
-
- r = sd_listen_fds(0);
- if (r == 0) {
- in_fd = STDIN_FILENO;
- out_fd = STDOUT_FILENO;
- } else if (r == 1) {
- in_fd = SD_LISTEN_FDS_START;
- out_fd = SD_LISTEN_FDS_START;
- } else {
- log_error("Illegal number of file descriptors passed\n");
- goto finish;
- }
-
- is_unix =
- sd_is_socket(in_fd, AF_UNIX, 0, 0) > 0 &&
- sd_is_socket(out_fd, AF_UNIX, 0, 0) > 0;
-
- r = sd_bus_new(&a);
- if (r < 0) {
- log_error("Failed to allocate bus: %s", strerror(-r));
- goto finish;
- }
-
- r = sd_bus_set_address(a, arg_bus_path);
- if (r < 0) {
- log_error("Failed to set address to connect to: %s", strerror(-r));
- goto finish;
- }
+ case ARG_CONFIGURATION:
+ r = strv_extend(&arg_configuration, optarg);
+ if (r < 0)
+ return log_oom();
+ break;
- r = sd_bus_negotiate_fds(a, is_unix);
- if (r < 0) {
- log_error("Failed to set FD negotiation: %s", strerror(-r));
- goto finish;
- }
+ case ARG_MACHINE: {
+ _cleanup_free_ char *e = NULL;
+ char *a;
- r = sd_bus_start(a);
- if (r < 0) {
- log_error("Failed to start bus client: %s", strerror(-r));
- goto finish;
- }
+ e = bus_address_escape(optarg);
+ if (!e)
+ return log_oom();
- r = sd_bus_get_server_id(a, &server_id);
- if (r < 0) {
- log_error("Failed to get server ID: %s", strerror(-r));
- goto finish;
- }
+#ifdef ENABLE_KDBUS
+ a = strjoin("x-machine-kernel:machine=", e, ";x-machine-unix:machine=", e, NULL);
+#else
+ a = strjoin("x-machine-unix:machine=", e, NULL);
+#endif
+ if (!a)
+ return log_oom();
- r = sd_bus_new(&b);
- if (r < 0) {
- log_error("Failed to allocate bus: %s", strerror(-r));
- goto finish;
- }
+ free(arg_address);
+ arg_address = a;
- r = sd_bus_set_fd(b, in_fd, out_fd);
- if (r < 0) {
- log_error("Failed to set fds: %s", strerror(-r));
- goto finish;
- }
+ break;
+ }
- r = sd_bus_set_server(b, 1, server_id);
- if (r < 0) {
- log_error("Failed to set server mode: %s", strerror(-r));
- goto finish;
- }
+ case '?':
+ return -EINVAL;
- r = sd_bus_negotiate_fds(b, is_unix);
- if (r < 0) {
- log_error("Failed to set FD negotiation: %s", strerror(-r));
- goto finish;
- }
+ default:
+ assert_not_reached("Unhandled option");
+ }
- r = sd_bus_set_anonymous(b, true);
- if (r < 0) {
- log_error("Failed to set anonymous authentication: %s", strerror(-r));
- goto finish;
+ if (argc > optind) {
+ log_error("Too many arguments");
+ return -EINVAL;
}
- r = sd_bus_start(b);
- if (r < 0) {
- log_error("Failed to start bus client: %s", strerror(-r));
- goto finish;
+ if (!arg_address) {
+ arg_address = strdup(DEFAULT_SYSTEM_BUS_ADDRESS);
+ if (!arg_address)
+ return log_oom();
}
- for (;;) {
- _cleanup_bus_message_unref_ sd_bus_message *m = NULL;
- int events_a, events_b, fd;
- uint64_t timeout_a, timeout_b, t;
- struct timespec _ts, *ts;
-
- r = sd_bus_process(a, &m);
- if (r < 0) {
- log_error("Failed to process bus a: %s", strerror(-r));
- goto finish;
- }
-
- if (m) {
- r = sd_bus_send(b, m, NULL);
- if (r < 0) {
- log_error("Failed to send message: %s", strerror(-r));
- goto finish;
- }
- }
-
- if (r > 0)
- continue;
-
- r = sd_bus_process(b, &m);
- if (r < 0) {
- /* treat 'connection reset by peer' as clean exit condition */
- if (r == -ECONNRESET)
- r = 0;
-
- goto finish;
- }
-
- if (m) {
- r = sd_bus_send(a, m, NULL);
- if (r < 0) {
- log_error("Failed to send message: %s", strerror(-r));
- goto finish;
- }
- }
+ return 1;
+}
- if (r > 0)
- continue;
+int main(int argc, char *argv[]) {
+ const char *user = "systemd-bus-proxy";
+ int r, accept_fd;
+ uid_t uid, bus_uid;
+ gid_t gid;
- fd = sd_bus_get_fd(a);
- if (fd < 0) {
- log_error("Failed to get fd: %s", strerror(-r));
- goto finish;
- }
+ log_set_target(LOG_TARGET_JOURNAL_OR_KMSG);
+ log_parse_environment();
+ log_open();
- events_a = sd_bus_get_events(a);
- if (events_a < 0) {
- log_error("Failed to get events mask: %s", strerror(-r));
- goto finish;
- }
+ bus_uid = getuid();
- r = sd_bus_get_timeout(a, &timeout_a);
+ if (geteuid() == 0) {
+ r = get_user_creds(&user, &uid, &gid, NULL, NULL);
if (r < 0) {
- log_error("Failed to get timeout: %s", strerror(-r));
- goto finish;
- }
-
- events_b = sd_bus_get_events(b);
- if (events_b < 0) {
- log_error("Failed to get events mask: %s", strerror(-r));
+ log_error_errno(r, "Cannot resolve user name %s: %m", user);
goto finish;
}
- r = sd_bus_get_timeout(b, &timeout_b);
+ r = drop_privileges(uid, gid, 1ULL << CAP_IPC_OWNER);
if (r < 0) {
- log_error("Failed to get timeout: %s", strerror(-r));
+ log_error_errno(r, "Cannot drop privileges: %m");
goto finish;
}
+ }
- t = timeout_a;
- if (t == (uint64_t) -1 || (timeout_b != (uint64_t) -1 && timeout_b < timeout_a))
- t = timeout_b;
-
- if (t == (uint64_t) -1)
- ts = NULL;
- else {
- usec_t nw;
-
- nw = now(CLOCK_MONOTONIC);
- if (t > nw)
- t -= nw;
- else
- t = 0;
-
- ts = timespec_store(&_ts, t);
- }
+ r = parse_argv(argc, argv);
+ if (r <= 0)
+ goto finish;
- {
- struct pollfd p[3] = {
- {.fd = fd, .events = events_a, },
- {.fd = STDIN_FILENO, .events = events_b & POLLIN, },
- {.fd = STDOUT_FILENO, .events = events_b & POLLOUT, }};
+ r = sd_listen_fds(0);
+ if (r != 1) {
+ log_error("Illegal number of file descriptors passed");
+ goto finish;
+ }
- r = ppoll(p, ELEMENTSOF(p), ts, NULL);
- }
- if (r < 0) {
- log_error("ppoll() failed: %m");
- goto finish;
- }
+ accept_fd = SD_LISTEN_FDS_START;
+ r = fd_nonblock(accept_fd, false);
+ if (r < 0) {
+ log_error_errno(r, "Cannot mark accept-fd non-blocking: %m");
+ goto finish;
}
- r = 0;
+ r = loop_clients(accept_fd, bus_uid);
finish:
+ sd_notify(false,
+ "STOPPING=1\n"
+ "STATUS=Shutting down.");
+
+ strv_free(arg_configuration);
+ free(arg_address);
+
return r < 0 ? EXIT_FAILURE : EXIT_SUCCESS;
}