chiark / gitweb /
dbus: listen on private sockets in user mode too
[elogind.git] / src / logind-session.c
1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
2
3 /***
4   This file is part of systemd.
5
6   Copyright 2011 Lennart Poettering
7
8   systemd is free software; you can redistribute it and/or modify it
9   under the terms of the GNU General Public License as published by
10   the Free Software Foundation; either version 2 of the License, or
11   (at your option) any later version.
12
13   systemd is distributed in the hope that it will be useful, but
14   WITHOUT ANY WARRANTY; without even the implied warranty of
15   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16   General Public License for more details.
17
18   You should have received a copy of the GNU General Public License
19   along with systemd; If not, see <http://www.gnu.org/licenses/>.
20 ***/
21
22 #include <errno.h>
23 #include <string.h>
24 #include <unistd.h>
25 #include <sys/epoll.h>
26 #include <fcntl.h>
27
28 #include "logind-session.h"
29 #include "strv.h"
30 #include "util.h"
31 #include "cgroup-util.h"
32
33 #define IDLE_THRESHOLD_USEC (5*USEC_PER_MINUTE)
34
35 Session* session_new(Manager *m, User *u, const char *id) {
36         Session *s;
37
38         assert(m);
39         assert(id);
40
41         s = new0(Session, 1);
42         if (!s)
43                 return NULL;
44
45         s->state_file = strappend("/run/systemd/sessions/", id);
46         if (!s->state_file) {
47                 free(s);
48                 return NULL;
49         }
50
51         s->id = file_name_from_path(s->state_file);
52
53         if (hashmap_put(m->sessions, s->id, s) < 0) {
54                 free(s->id);
55                 free(s);
56                 return NULL;
57         }
58
59         s->manager = m;
60         s->fifo_fd = -1;
61         s->user = u;
62
63         LIST_PREPEND(Session, sessions_by_user, u->sessions, s);
64
65         return s;
66 }
67
68 void session_free(Session *s) {
69         assert(s);
70
71         if (s->in_gc_queue)
72                 LIST_REMOVE(Session, gc_queue, s->manager->session_gc_queue, s);
73
74         if (s->user) {
75                 LIST_REMOVE(Session, sessions_by_user, s->user->sessions, s);
76
77                 if (s->user->display == s)
78                         s->user->display = NULL;
79         }
80
81         if (s->seat) {
82                 if (s->seat->active == s)
83                         s->seat->active = NULL;
84
85                 LIST_REMOVE(Session, sessions_by_seat, s->seat->sessions, s);
86         }
87
88         if (s->cgroup_path)
89                 hashmap_remove(s->manager->cgroups, s->cgroup_path);
90
91         free(s->cgroup_path);
92         strv_free(s->controllers);
93
94         free(s->tty);
95         free(s->display);
96         free(s->remote_host);
97         free(s->remote_user);
98         free(s->service);
99
100         hashmap_remove(s->manager->sessions, s->id);
101
102         session_remove_fifo(s);
103
104         free(s->state_file);
105         free(s);
106 }
107
108 int session_save(Session *s) {
109         FILE *f;
110         int r = 0;
111         char *temp_path;
112
113         assert(s);
114
115         if (!s->started)
116                 return 0;
117
118         r = safe_mkdir("/run/systemd/sessions", 0755, 0, 0);
119         if (r < 0)
120                 goto finish;
121
122         r = fopen_temporary(s->state_file, &f, &temp_path);
123         if (r < 0)
124                 goto finish;
125
126         assert(s->user);
127
128         fchmod(fileno(f), 0644);
129
130         fprintf(f,
131                 "# This is private data. Do not parse.\n"
132                 "UID=%lu\n"
133                 "USER=%s\n"
134                 "ACTIVE=%i\n"
135                 "REMOTE=%i\n"
136                 "KILL_PROCESSES=%i\n",
137                 (unsigned long) s->user->uid,
138                 s->user->name,
139                 session_is_active(s),
140                 s->remote,
141                 s->kill_processes);
142
143         if (s->type >= 0)
144                 fprintf(f,
145                         "TYPE=%s\n",
146                         session_type_to_string(s->type));
147
148         if (s->cgroup_path)
149                 fprintf(f,
150                         "CGROUP=%s\n",
151                         s->cgroup_path);
152
153         if (s->fifo_path)
154                 fprintf(f,
155                         "FIFO=%s\n",
156                         s->fifo_path);
157
158         if (s->seat)
159                 fprintf(f,
160                         "SEAT=%s\n",
161                         s->seat->id);
162
163         if (s->tty)
164                 fprintf(f,
165                         "TTY=%s\n",
166                         s->tty);
167
168         if (s->display)
169                 fprintf(f,
170                         "DISPLAY=%s\n",
171                         s->display);
172
173         if (s->remote_host)
174                 fprintf(f,
175                         "REMOTE_HOST=%s\n",
176                         s->remote_host);
177
178         if (s->remote_user)
179                 fprintf(f,
180                         "REMOTE_USER=%s\n",
181                         s->remote_user);
182
183         if (s->service)
184                 fprintf(f,
185                         "SERVICE=%s\n",
186                         s->service);
187
188         if (s->seat && seat_is_vtconsole(s->seat))
189                 fprintf(f,
190                         "VTNR=%i\n",
191                         s->vtnr);
192
193         if (s->leader > 0)
194                 fprintf(f,
195                         "LEADER=%lu\n",
196                         (unsigned long) s->leader);
197
198         if (s->audit_id > 0)
199                 fprintf(f,
200                         "AUDIT=%llu\n",
201                         (unsigned long long) s->audit_id);
202
203         fflush(f);
204
205         if (ferror(f) || rename(temp_path, s->state_file) < 0) {
206                 r = -errno;
207                 unlink(s->state_file);
208                 unlink(temp_path);
209         }
210
211         fclose(f);
212         free(temp_path);
213
214 finish:
215         if (r < 0)
216                 log_error("Failed to save session data for %s: %s", s->id, strerror(-r));
217
218         return r;
219 }
220
221 int session_load(Session *s) {
222         char *remote = NULL,
223                 *kill_processes = NULL,
224                 *seat = NULL,
225                 *vtnr = NULL,
226                 *leader = NULL,
227                 *audit_id = NULL,
228                 *type = NULL;
229
230         int k, r;
231
232         assert(s);
233
234         r = parse_env_file(s->state_file, NEWLINE,
235                            "REMOTE",         &remote,
236                            "KILL_PROCESSES", &kill_processes,
237                            "CGROUP",         &s->cgroup_path,
238                            "FIFO",           &s->fifo_path,
239                            "SEAT",           &seat,
240                            "TTY",            &s->tty,
241                            "DISPLAY",        &s->display,
242                            "REMOTE_HOST",    &s->remote_host,
243                            "REMOTE_USER",    &s->remote_user,
244                            "SERVICE",        &s->service,
245                            "VTNR",           &vtnr,
246                            "LEADER",         &leader,
247                            "TYPE",           &type,
248                            NULL);
249
250         if (r < 0)
251                 goto finish;
252
253         if (remote) {
254                 k = parse_boolean(remote);
255                 if (k >= 0)
256                         s->remote = k;
257         }
258
259         if (kill_processes) {
260                 k = parse_boolean(kill_processes);
261                 if (k >= 0)
262                         s->kill_processes = k;
263         }
264
265         if (seat && !s->seat) {
266                 Seat *o;
267
268                 o = hashmap_get(s->manager->seats, seat);
269                 if (o)
270                         seat_attach_session(o, s);
271         }
272
273         if (vtnr && s->seat && seat_is_vtconsole(s->seat)) {
274                 int v;
275
276                 k = safe_atoi(vtnr, &v);
277                 if (k >= 0 && v >= 1)
278                         s->vtnr = v;
279         }
280
281         if (leader) {
282                 pid_t pid;
283
284                 k = parse_pid(leader, &pid);
285                 if (k >= 0 && pid >= 1) {
286                         s->leader = pid;
287
288                         audit_session_from_pid(pid, &s->audit_id);
289                 }
290         }
291
292         if (type) {
293                 SessionType t;
294
295                 t = session_type_from_string(type);
296                 if (t >= 0)
297                         s->type = t;
298         }
299
300         if (s->fifo_path) {
301                 int fd;
302
303                 /* If we open an unopened pipe for reading we will not
304                    get an EOF. to trigger an EOF we hence open it for
305                    reading, but close it right-away which then will
306                    trigger the EOF. */
307
308                 fd = session_create_fifo(s);
309                 if (fd >= 0)
310                         close_nointr_nofail(fd);
311         }
312
313
314 finish:
315         free(remote);
316         free(kill_processes);
317         free(seat);
318         free(vtnr);
319         free(leader);
320         free(audit_id);
321
322         return r;
323 }
324
325 int session_activate(Session *s) {
326         int r;
327         Session *old_active;
328
329         assert(s);
330
331         if (s->vtnr < 0)
332                 return -ENOTSUP;
333
334         if (!s->seat)
335                 return -ENOTSUP;
336
337         if (s->seat->active == s)
338                 return 0;
339
340         assert(seat_is_vtconsole(s->seat));
341
342         r = chvt(s->vtnr);
343         if (r < 0)
344                 return r;
345
346         old_active = s->seat->active;
347         s->seat->active = s;
348
349         return seat_apply_acls(s->seat, old_active);
350 }
351
352 static int session_link_x11_socket(Session *s) {
353         char *t, *f, *c;
354         size_t k;
355
356         assert(s);
357         assert(s->user);
358         assert(s->user->runtime_path);
359
360         if (s->user->display)
361                 return 0;
362
363         if (!s->display || !display_is_local(s->display))
364                 return 0;
365
366         k = strspn(s->display+1, "0123456789");
367         f = new(char, sizeof("/tmp/.X11-unix/X") + k);
368         if (!f) {
369                 log_error("Out of memory");
370                 return -ENOMEM;
371         }
372
373         c = stpcpy(f, "/tmp/.X11-unix/X");
374         memcpy(c, s->display+1, k);
375         c[k] = 0;
376
377         if (access(f, F_OK) < 0) {
378                 log_warning("Session %s has display %s with nonexisting socket %s.", s->id, s->display, f);
379                 free(f);
380                 return -ENOENT;
381         }
382
383         t = strappend(s->user->runtime_path, "/display");
384         if (!t) {
385                 log_error("Out of memory");
386                 free(f);
387                 return -ENOMEM;
388         }
389
390         if (link(f, t) < 0) {
391                 if (errno == EEXIST) {
392                         unlink(t);
393
394                         if (link(f, t) >= 0)
395                                 goto done;
396                 }
397
398                 if (symlink(f, t) < 0) {
399
400                         if (errno == EEXIST) {
401                                 unlink(t);
402
403                                 if (symlink(f, t) >= 0)
404                                         goto done;
405                         }
406
407                         log_error("Failed to link %s to %s: %m", f, t);
408                         free(f);
409                         free(t);
410                         return -errno;
411                 }
412         }
413
414 done:
415         log_info("Linked %s to %s.", f, t);
416         free(f);
417         free(t);
418
419         s->user->display = s;
420
421         return 0;
422 }
423
424 static int session_create_one_group(Session *s, const char *controller, const char *path) {
425         int r;
426
427         assert(s);
428         assert(controller);
429         assert(path);
430
431         if (s->leader > 0) {
432                 r = cg_create_and_attach(controller, path, s->leader);
433                 if (r < 0)
434                         r = cg_create(controller, path);
435         } else
436                 r = cg_create(controller, path);
437
438         if (r < 0)
439                 return r;
440
441         r = cg_set_task_access(controller, path, 0644, s->user->uid, s->user->gid);
442         if (r >= 0)
443                 r = cg_set_group_access(controller, path, 0755, s->user->uid, s->user->gid);
444
445         return r;
446 }
447
448 static int session_create_cgroup(Session *s) {
449         char **k;
450         char *p;
451         int r;
452
453         assert(s);
454         assert(s->user);
455         assert(s->user->cgroup_path);
456
457         if (!s->cgroup_path) {
458                 if (asprintf(&p, "%s/%s", s->user->cgroup_path, s->id) < 0) {
459                         log_error("Out of memory");
460                         return -ENOMEM;
461                 }
462         } else
463                 p = s->cgroup_path;
464
465         r = session_create_one_group(s, SYSTEMD_CGROUP_CONTROLLER, p);
466         if (r < 0) {
467                 log_error("Failed to create "SYSTEMD_CGROUP_CONTROLLER":%s: %s", p, strerror(-r));
468                 free(p);
469                 s->cgroup_path = NULL;
470                 return r;
471         }
472
473         s->cgroup_path = p;
474
475         STRV_FOREACH(k, s->controllers) {
476
477                 if (strv_contains(s->reset_controllers, *k))
478                         continue;
479
480                 r = session_create_one_group(s, *k, p);
481                 if (r < 0)
482                         log_warning("Failed to create %s:%s: %s", *k, p, strerror(-r));
483         }
484
485         STRV_FOREACH(k, s->manager->controllers) {
486
487                 if (strv_contains(s->reset_controllers, *k) ||
488                     strv_contains(s->manager->reset_controllers, *k) ||
489                     strv_contains(s->controllers, *k))
490                         continue;
491
492                 r = session_create_one_group(s, *k, p);
493                 if (r < 0)
494                         log_warning("Failed to create %s:%s: %s", *k, p, strerror(-r));
495         }
496
497         if (s->leader > 0) {
498
499                 STRV_FOREACH(k, s->reset_controllers) {
500                         r = cg_attach(*k, "/", s->leader);
501                         if (r < 0)
502                                 log_warning("Failed to reset controller %s: %s", *k, strerror(-r));
503
504                 }
505
506                 STRV_FOREACH(k, s->manager->reset_controllers) {
507
508                         if (strv_contains(s->reset_controllers, *k) ||
509                             strv_contains(s->controllers, *k))
510                                 continue;
511
512                         r = cg_attach(*k, "/", s->leader);
513                         if (r < 0)
514                                 log_warning("Failed to reset controller %s: %s", *k, strerror(-r));
515
516                 }
517         }
518
519         hashmap_put(s->manager->cgroups, s->cgroup_path, s);
520
521         return 0;
522 }
523
524 int session_start(Session *s) {
525         int r;
526
527         assert(s);
528         assert(s->user);
529
530         if (s->started)
531                 return 0;
532
533         r = user_start(s->user);
534         if (r < 0)
535                 return r;
536
537         log_info("New session %s of user %s.", s->id, s->user->name);
538
539         /* Create cgroup */
540         r = session_create_cgroup(s);
541         if (r < 0)
542                 return r;
543
544         /* Create X11 symlink */
545         session_link_x11_socket(s);
546
547         dual_timestamp_get(&s->timestamp);
548
549         if (s->seat)
550                 seat_read_active_vt(s->seat);
551
552         s->started = true;
553
554         /* Save session data */
555         session_save(s);
556         user_save(s->user);
557
558         session_send_signal(s, true);
559
560         if (s->seat) {
561                 seat_save(s->seat);
562
563                 if (s->seat->active == s)
564                         seat_send_changed(s->seat, "Sessions\0ActiveSession\0");
565                 else
566                         seat_send_changed(s->seat, "Sessions\0");
567         }
568
569         user_send_changed(s->user, "Sessions\0");
570
571         return 0;
572 }
573
574 static bool session_shall_kill(Session *s) {
575         assert(s);
576
577         if (!s->kill_processes)
578                 return false;
579
580         if (strv_contains(s->manager->kill_exclude_users, s->user->name))
581                 return false;
582
583         if (strv_isempty(s->manager->kill_only_users))
584                 return true;
585
586         return strv_contains(s->manager->kill_only_users, s->user->name);
587 }
588
589 static int session_kill_cgroup(Session *s) {
590         int r;
591         char **k;
592
593         assert(s);
594
595         if (!s->cgroup_path)
596                 return 0;
597
598         cg_trim(SYSTEMD_CGROUP_CONTROLLER, s->cgroup_path, false);
599
600         if (session_shall_kill(s)) {
601
602                 r = cg_kill_recursive_and_wait(SYSTEMD_CGROUP_CONTROLLER, s->cgroup_path, true);
603                 if (r < 0)
604                         log_error("Failed to kill session cgroup: %s", strerror(-r));
605
606         } else {
607                 r = cg_is_empty_recursive(SYSTEMD_CGROUP_CONTROLLER, s->cgroup_path, true);
608                 if (r < 0)
609                         log_error("Failed to check session cgroup: %s", strerror(-r));
610                 else if (r > 0) {
611                         r = cg_delete(SYSTEMD_CGROUP_CONTROLLER, s->cgroup_path);
612                         if (r < 0)
613                                 log_error("Failed to delete session cgroup: %s", strerror(-r));
614                 } else
615                         r = -EBUSY;
616         }
617
618         STRV_FOREACH(k, s->user->manager->controllers)
619                 cg_trim(*k, s->cgroup_path, true);
620
621         hashmap_remove(s->manager->cgroups, s->cgroup_path);
622
623         free(s->cgroup_path);
624         s->cgroup_path = NULL;
625
626         return r;
627 }
628
629 static int session_unlink_x11_socket(Session *s) {
630         char *t;
631         int r;
632
633         assert(s);
634         assert(s->user);
635
636         if (s->user->display != s)
637                 return 0;
638
639         s->user->display = NULL;
640
641         t = strappend(s->user->runtime_path, "/display");
642         if (!t) {
643                 log_error("Out of memory");
644                 return -ENOMEM;
645         }
646
647         r = unlink(t);
648         free(t);
649
650         return r < 0 ? -errno : 0;
651 }
652
653 int session_stop(Session *s) {
654         int r = 0, k;
655
656         assert(s);
657
658         if (s->started)
659                 log_info("Removed session %s.", s->id);
660
661         /* Kill cgroup */
662         k = session_kill_cgroup(s);
663         if (k < 0)
664                 r = k;
665
666         /* Remove X11 symlink */
667         session_unlink_x11_socket(s);
668
669         unlink(s->state_file);
670         session_add_to_gc_queue(s);
671         user_add_to_gc_queue(s->user);
672
673         if (s->started)
674                 session_send_signal(s, false);
675
676         if (s->seat) {
677                 if (s->seat->active == s)
678                         seat_set_active(s->seat, NULL);
679
680                 seat_send_changed(s->seat, "Sessions\0");
681         }
682
683         user_send_changed(s->user, "Sessions\0");
684
685         s->started = false;
686
687         return r;
688 }
689
690 bool session_is_active(Session *s) {
691         assert(s);
692
693         if (!s->seat)
694                 return true;
695
696         return s->seat->active == s;
697 }
698
699 int session_get_idle_hint(Session *s, dual_timestamp *t) {
700         char *p;
701         struct stat st;
702         usec_t u, n;
703         bool b;
704         int k;
705
706         assert(s);
707
708         if (s->idle_hint) {
709                 if (t)
710                         *t = s->idle_hint_timestamp;
711
712                 return s->idle_hint;
713         }
714
715         if (isempty(s->tty))
716                 goto dont_know;
717
718         if (s->tty[0] != '/') {
719                 p = strappend("/dev/", s->tty);
720                 if (!p)
721                         return -ENOMEM;
722         } else
723                 p = NULL;
724
725         if (!startswith(p ? p : s->tty, "/dev/")) {
726                 free(p);
727                 goto dont_know;
728         }
729
730         k = lstat(p ? p : s->tty, &st);
731         free(p);
732
733         if (k < 0)
734                 goto dont_know;
735
736         u = timespec_load(&st.st_atim);
737         n = now(CLOCK_REALTIME);
738         b = u + IDLE_THRESHOLD_USEC < n;
739
740         if (t)
741                 dual_timestamp_from_realtime(t, u + b ? IDLE_THRESHOLD_USEC : 0);
742
743         return b;
744
745 dont_know:
746         if (t)
747                 *t = s->idle_hint_timestamp;
748
749         return 0;
750 }
751
752 void session_set_idle_hint(Session *s, bool b) {
753         assert(s);
754
755         if (s->idle_hint == b)
756                 return;
757
758         s->idle_hint = b;
759         dual_timestamp_get(&s->idle_hint_timestamp);
760
761         session_send_changed(s,
762                              "IdleHint\0"
763                              "IdleSinceHint\0"
764                              "IdleSinceHintMonotonic\0");
765
766         if (s->seat)
767                 seat_send_changed(s->seat,
768                                   "IdleHint\0"
769                                   "IdleSinceHint\0"
770                                   "IdleSinceHintMonotonic\0");
771
772         user_send_changed(s->user,
773                           "IdleHint\0"
774                           "IdleSinceHint\0"
775                           "IdleSinceHintMonotonic\0");
776
777         manager_send_changed(s->manager,
778                              "IdleHint\0"
779                              "IdleSinceHint\0"
780                              "IdleSinceHintMonotonic\0");
781 }
782
783 int session_create_fifo(Session *s) {
784         int r;
785
786         assert(s);
787
788         /* Create FIFO */
789         if (!s->fifo_path) {
790                 r = safe_mkdir("/run/systemd/sessions", 0755, 0, 0);
791                 if (r < 0)
792                         return r;
793
794                 if (asprintf(&s->fifo_path, "/run/systemd/sessions/%s.ref", s->id) < 0)
795                         return -ENOMEM;
796
797                 if (mkfifo(s->fifo_path, 0600) < 0 && errno != EEXIST)
798                         return -errno;
799         }
800
801         /* Open reading side */
802         if (s->fifo_fd < 0) {
803                 struct epoll_event ev;
804
805                 s->fifo_fd = open(s->fifo_path, O_RDONLY|O_CLOEXEC|O_NDELAY);
806                 if (s->fifo_fd < 0)
807                         return -errno;
808
809                 r = hashmap_put(s->manager->fifo_fds, INT_TO_PTR(s->fifo_fd + 1), s);
810                 if (r < 0)
811                         return r;
812
813                 zero(ev);
814                 ev.events = 0;
815                 ev.data.u32 = FD_FIFO_BASE + s->fifo_fd;
816
817                 if (epoll_ctl(s->manager->epoll_fd, EPOLL_CTL_ADD, s->fifo_fd, &ev) < 0)
818                         return -errno;
819         }
820
821         /* Open writing side */
822         r = open(s->fifo_path, O_WRONLY|O_CLOEXEC|O_NDELAY);
823         if (r < 0)
824                 return -errno;
825
826         return r;
827 }
828
829 void session_remove_fifo(Session *s) {
830         assert(s);
831
832         if (s->fifo_fd >= 0) {
833                 assert_se(hashmap_remove(s->manager->fifo_fds, INT_TO_PTR(s->fifo_fd + 1)) == s);
834                 assert_se(epoll_ctl(s->manager->epoll_fd, EPOLL_CTL_DEL, s->fifo_fd, NULL) == 0);
835                 close_nointr_nofail(s->fifo_fd);
836                 s->fifo_fd = -1;
837         }
838
839         if (s->fifo_path) {
840                 unlink(s->fifo_path);
841                 free(s->fifo_path);
842                 s->fifo_path = NULL;
843         }
844 }
845
846 int session_check_gc(Session *s, bool drop_not_started) {
847         int r;
848
849         assert(s);
850
851         if (drop_not_started && !s->started)
852                 return 0;
853
854         if (s->fifo_fd >= 0) {
855
856                 r = pipe_eof(s->fifo_fd);
857                 if (r < 0)
858                         return r;
859
860                 if (r == 0)
861                         return 1;
862         }
863
864         if (s->cgroup_path) {
865
866                 r = cg_is_empty_recursive(SYSTEMD_CGROUP_CONTROLLER, s->cgroup_path, false);
867                 if (r < 0)
868                         return r;
869
870                 if (r <= 0)
871                         return 1;
872         }
873
874         return 0;
875 }
876
877 void session_add_to_gc_queue(Session *s) {
878         assert(s);
879
880         if (s->in_gc_queue)
881                 return;
882
883         LIST_PREPEND(Session, gc_queue, s->manager->session_gc_queue, s);
884         s->in_gc_queue = true;
885 }
886
887 static const char* const session_type_table[_SESSION_TYPE_MAX] = {
888         [SESSION_TTY] = "tty",
889         [SESSION_X11] = "x11",
890         [SESSION_UNSPECIFIED] = "unspecified"
891 };
892
893 DEFINE_STRING_TABLE_LOOKUP(session_type, SessionType);