#include <signal.h>
#include <arpa/inet.h>
#include <mqueue.h>
+#include <attr/xattr.h>
#include "unit.h"
#include "socket.h"
free(s->bind_to_device);
s->bind_to_device = NULL;
+ free(s->smack);
+ free(s->smack_ip_in);
+ free(s->smack_ip_out);
+
+ free(s->socket_user);
+ s->socket_user = NULL;
+
+ free(s->socket_group);
+ s->socket_group = NULL;
+
unit_unwatch_timer(u, &s->timer_watch);
}
if (!socket_needs_mount(s, m->where))
return 0;
- if ((r = unit_add_two_dependencies(UNIT(s), UNIT_AFTER, UNIT_REQUIRES, UNIT(m), true)) < 0)
+ r = unit_add_two_dependencies(UNIT(s), UNIT_AFTER, UNIT_REQUIRES, UNIT(m), true);
+ if (r < 0)
return r;
return 0;
assert(s);
- LIST_FOREACH(units_by_type, other, UNIT(s)->manager->units_by_type[UNIT_MOUNT])
- if ((r = socket_add_one_mount_link(s, MOUNT(other))) < 0)
+ LIST_FOREACH(units_by_type, other, UNIT(s)->manager->units_by_type[UNIT_MOUNT]) {
+ r = socket_add_one_mount_link(s, MOUNT(other));
+ if (r < 0)
return r;
+ }
return 0;
}
int r;
assert(s);
- if (UNIT(s)->manager->running_as == MANAGER_SYSTEM) {
+ if (UNIT(s)->manager->running_as == SYSTEMD_SYSTEM) {
if ((r = unit_add_dependency_by_name(UNIT(s), UNIT_BEFORE, SPECIAL_SOCKETS_TARGET, NULL, true)) < 0)
return r;
prefix, yes_no(s->pass_sec),
prefix, strna(s->tcp_congestion));
+ if (s->socket_user)
+ fprintf(f,
+ "SocketUser: %s\n",
+ s->socket_user);
+
+ if (s->socket_group)
+ fprintf(f,
+ "SocketGroup: %s\n",
+ s->socket_group);
+
if (s->control_pid > 0)
fprintf(f,
"%sControl PID: %lu\n",
"%sMessageQueueMessageSize: %li\n",
prefix, s->mq_msgsize);
+ if (s->smack)
+ fprintf(f,
+ "%sSmackLabel: %s\n",
+ prefix, s->smack);
+
+ if (s->smack_ip_in)
+ fprintf(f,
+ "%sSmackLabelIPIn: %s\n",
+ prefix, s->smack_ip_in);
+
+ if (s->smack_ip_out)
+ fprintf(f,
+ "%sSmackLabelIPOut: %s\n",
+ prefix, s->smack_ip_out);
+
LIST_FOREACH(port, p, s->ports) {
if (p->type == SOCKET_SOCKET) {
}
static void socket_apply_socket_options(Socket *s, int fd) {
+ uid_t uid = 0;
+ gid_t gid = 0;
+
assert(s);
assert(fd >= 0);
if (s->tcp_congestion)
if (setsockopt(fd, SOL_TCP, TCP_CONGESTION, s->tcp_congestion, strlen(s->tcp_congestion)+1) < 0)
log_warning("TCP_CONGESTION failed: %m");
+
+ if (s->smack_ip_in)
+ if (fsetxattr(fd, "security.SMACK64IPIN", s->smack_ip_in, strlen(s->smack_ip_in), 0) < 0)
+ log_error("fsetxattr(\"security.SMACK64IPIN\"): %m");
+
+ if (s->smack_ip_out)
+ if (fsetxattr(fd, "security.SMACK64IPOUT", s->smack_ip_out, strlen(s->smack_ip_out), 0) < 0)
+ log_error("fsetxattr(\"security.SMACK64IPOUT\"): %m");
+
+ if (s->socket_user &&
+ get_user_creds((const char **)&s->socket_user, &uid,
+ NULL, NULL, NULL) < 0) {
+ log_warning("failed to lookup user: %s", s->socket_user);
+ }
+
+ if (s->socket_group &&
+ get_group_creds((const char **)&s->socket_group, &gid) < 0) {
+ log_warning("failed to lookup group: %s", s->socket_group);
+ }
+
+ if ((uid != 0 || gid != 0) && fchown(fd, uid, gid) < 0) {
+ log_warning("failed to change ownership of socket");
+ }
}
static void socket_apply_fifo_options(Socket *s, int fd) {
if (s->pipe_size > 0)
if (fcntl(fd, F_SETPIPE_SZ, s->pipe_size) < 0)
log_warning("F_SETPIPE_SZ: %m");
+
+ if (s->smack)
+ if (fsetxattr(fd, "security.SMACK64", s->smack, strlen(s->smack), 0) < 0)
+ log_error("fsetxattr(\"security.SMACK64\"): %m");
}
static int fifo_address_create(
const char *path,
mode_t directory_mode,
mode_t socket_mode,
+ const char *socket_user,
+ const char *socket_group,
int *_fd) {
int fd = -1, r = 0;
struct stat st;
mode_t old_mask;
+ uid_t uid = 0;
+ gid_t gid = 0;
assert(path);
assert(_fd);
goto fail;
}
- if ((fd = open(path, O_RDWR|O_CLOEXEC|O_NOCTTY|O_NONBLOCK|O_NOFOLLOW)) < 0) {
+ fd = open(path, O_RDWR|O_CLOEXEC|O_NOCTTY|O_NONBLOCK|O_NOFOLLOW);
+ if (fd < 0) {
r = -errno;
goto fail;
}
goto fail;
}
+ if (socket_user &&
+ get_user_creds(&socket_user, &uid, NULL, NULL, NULL) < 0) {
+ r = -errno;
+ log_error("failed to lookup user: %s", socket_user);
+ goto fail;
+ }
+
+ if (socket_group &&
+ get_group_creds(&socket_group, &gid) < 0) {
+ r = -errno;
+ log_error("failed to lookup group: %s", socket_group);
+ goto fail;
+ }
+
if (!S_ISFIFO(st.st_mode) ||
(st.st_mode & 0777) != (socket_mode & ~old_mask) ||
- st.st_uid != getuid() ||
- st.st_gid != getgid()) {
+ st.st_uid != uid ||
+ st.st_gid != gid) {
r = -EEXIST;
goto fail;
}
+ if ((uid != 0 || gid != 0) && fchown(fd, uid, gid) < 0) {
+ r = -errno;
+ log_error("failed to changed ownership of FIFO: %s", path);
+ goto fail;
+ }
+
*_fd = fd;
return 0;
p->path,
s->directory_mode,
s->socket_mode,
+ s->socket_user,
+ s->socket_group,
&p->fd)) < 0)
goto rollback;