chiark / gitweb /
bus-proxy: tell Coverity we don't care about these return values
[elogind.git] / src / bus-proxyd / bus-proxyd.c
index ce2a20bb89cfce1644d607155fd7ea9426ccef74..e07761aeb937cc261cbee9f5bc8ec10ae18682c1 100644 (file)
@@ -4,6 +4,9 @@
   This file is part of systemd.
 
   Copyright 2010 Lennart Poettering
+  Copyright 2013 Daniel Mack
+  Copyright 2014 Kay Sievers
+  Copyright 2015 David Herrmann
 
   systemd is free software; you can redistribute it and/or modify it
   under the terms of the GNU Lesser General Public License as published by
 #include <unistd.h>
 #include <string.h>
 #include <errno.h>
-#include <sys/poll.h>
+#include <poll.h>
+#include <sys/prctl.h>
 #include <stddef.h>
 #include <getopt.h>
+#include <pthread.h>
 
 #include "log.h"
 #include "util.h"
+#include "hashmap.h"
 #include "socket-util.h"
 #include "sd-daemon.h"
 #include "sd-bus.h"
 #include "bus-message.h"
 #include "bus-util.h"
 #include "build.h"
+#include "strv.h"
+#include "def.h"
+#include "capability.h"
+#include "bus-control.h"
+#include "smack-util.h"
+#include "set.h"
+#include "bus-xml-policy.h"
+#include "driver.h"
+#include "proxy.h"
+#include "synthesize.h"
+
+static char *arg_address = NULL;
+static char **arg_configuration = NULL;
+
+typedef struct {
+        int fd;
+        SharedPolicy *policy;
+        uid_t bus_uid;
+} ClientContext;
+
+static ClientContext *client_context_free(ClientContext *c) {
+        if (!c)
+                return NULL;
+
+        close(c->fd);
+        free(c);
+
+        return NULL;
+}
 
-#ifdef ENABLE_KDBUS
-const char *arg_address = "kernel:path=/dev/kdbus/0-system/bus;unix:path=/run/dbus/system_bus_socket";
-#else
-const char *arg_address = "unix:path=/run/dbus/system_bus_socket";
-#endif
+DEFINE_TRIVIAL_CLEANUP_FUNC(ClientContext*, client_context_free);
+
+static int client_context_new(ClientContext **out) {
+        _cleanup_(client_context_freep) ClientContext *c = NULL;
+
+        c = new0(ClientContext, 1);
+        if (!c)
+                return log_oom();
+
+        c->fd = -1;
+
+        *out = c;
+        c = NULL;
+        return 0;
+}
+
+static void *run_client(void *userdata) {
+        _cleanup_(client_context_freep) ClientContext *c = userdata;
+        _cleanup_(proxy_freep) Proxy *p = NULL;
+        char comm[16];
+        int r;
+
+        r = proxy_new(&p, c->fd, c->fd, arg_address);
+        if (r < 0)
+                goto exit;
+
+        /* set comm to "p$PIDu$UID" and suffix with '*' if truncated */
+        r = snprintf(comm, sizeof(comm), "p" PID_FMT "u" UID_FMT, p->local_creds.pid, p->local_creds.uid);
+        if (r >= (ssize_t)sizeof(comm))
+                comm[sizeof(comm) - 2] = '*';
+        (void) prctl(PR_SET_NAME, comm);
+
+        r = proxy_set_policy(p, c->policy, arg_configuration);
+        if (r < 0)
+                goto exit;
+
+        r = proxy_hello_policy(p, c->bus_uid);
+        if (r < 0)
+                goto exit;
+
+        r = proxy_run(p);
+
+exit:
+        return NULL;
+}
+
+static int loop_clients(int accept_fd, uid_t bus_uid) {
+        _cleanup_(shared_policy_freep) SharedPolicy *sp = NULL;
+        pthread_attr_t attr;
+        int r;
+
+        r = pthread_attr_init(&attr);
+        if (r < 0) {
+                r = log_error_errno(errno, "Cannot initialize pthread attributes: %m");
+                goto exit;
+        }
+
+        r = pthread_attr_setdetachstate(&attr, PTHREAD_CREATE_DETACHED);
+        if (r < 0) {
+                r = log_error_errno(errno, "Cannot mark pthread attributes as detached: %m");
+                goto exit_attr;
+        }
+
+        r = shared_policy_new(&sp);
+        if (r < 0)
+                goto exit_attr;
+
+        for (;;) {
+                ClientContext *c;
+                pthread_t tid;
+                int fd;
+
+                fd = accept4(accept_fd, NULL, NULL, SOCK_NONBLOCK | SOCK_CLOEXEC);
+                if (fd < 0) {
+                        if (errno == EAGAIN || errno == EINTR)
+                                continue;
+
+                        r = log_error_errno(errno, "accept4() failed: %m");
+                        break;
+                }
+
+                r = client_context_new(&c);
+                if (r < 0) {
+                        log_oom();
+                        close(fd);
+                        continue;
+                }
+
+                c->fd = fd;
+                c->policy = sp;
+                c->bus_uid = bus_uid;
+
+                r = pthread_create(&tid, &attr, run_client, c);
+                if (r < 0) {
+                        log_error("Cannot spawn thread: %m");
+                        client_context_free(c);
+                        continue;
+                }
+        }
+
+exit_attr:
+        pthread_attr_destroy(&attr);
+exit:
+        return r;
+}
 
 static int help(void) {
 
         printf("%s [OPTIONS...]\n\n"
-               "Connect STDIO or a socket to a given bus address.\n\n"
-               "  -h --help              Show this help\n"
-               "     --version           Show package version\n"
-               "     --address=ADDRESS   Connect to bus specified by address\n",
+               "DBus proxy server.\n\n"
+               "  -h --help               Show this help\n"
+               "     --version            Show package version\n"
+               "     --configuration=PATH Configuration file or directory\n"
+               "     --machine=MACHINE    Connect to specified machine\n"
+               "     --address=ADDRESS    Connect to the bus specified by ADDRESS\n"
+               "                          (default: " DEFAULT_SYSTEM_BUS_ADDRESS ")\n",
                program_invocation_short_name);
 
         return 0;
@@ -63,21 +201,25 @@ static int parse_argv(int argc, char *argv[]) {
         enum {
                 ARG_VERSION = 0x100,
                 ARG_ADDRESS,
+                ARG_CONFIGURATION,
+                ARG_MACHINE,
         };
 
         static const struct option options[] = {
-                { "help",       no_argument,       NULL, 'h'            },
-                { "version",    no_argument,       NULL, ARG_VERSION    },
-                { "address",    required_argument, NULL, ARG_ADDRESS    },
-                { NULL,         0,                 NULL, 0              }
+                { "help",            no_argument,       NULL, 'h'                 },
+                { "version",         no_argument,       NULL, ARG_VERSION         },
+                { "address",         required_argument, NULL, ARG_ADDRESS         },
+                { "configuration",   required_argument, NULL, ARG_CONFIGURATION   },
+                { "machine",         required_argument, NULL, ARG_MACHINE         },
+                {},
         };
 
-        int c;
+        int c, r;
 
         assert(argc >= 0);
         assert(argv);
 
-        while ((c = getopt_long(argc, argv, "hsup:", options, NULL)) >= 0) {
+        while ((c = getopt_long(argc, argv, "h", options, NULL)) >= 0)
 
                 switch (c) {
 
@@ -90,9 +232,45 @@ static int parse_argv(int argc, char *argv[]) {
                         puts(SYSTEMD_FEATURES);
                         return 0;
 
-                case ARG_ADDRESS:
-                        arg_address = optarg;
+                case ARG_ADDRESS: {
+                        char *a;
+
+                        a = strdup(optarg);
+                        if (!a)
+                                return log_oom();
+
+                        free(arg_address);
+                        arg_address = a;
+                        break;
+                }
+
+                case ARG_CONFIGURATION:
+                        r = strv_extend(&arg_configuration, optarg);
+                        if (r < 0)
+                                return log_oom();
+                        break;
+
+                case ARG_MACHINE: {
+                        _cleanup_free_ char *e = NULL;
+                        char *a;
+
+                        e = bus_address_escape(optarg);
+                        if (!e)
+                                return log_oom();
+
+#ifdef ENABLE_KDBUS
+                        a = strjoin("x-machine-kernel:machine=", e, ";x-machine-unix:machine=", e, NULL);
+#else
+                        a = strjoin("x-machine-unix:machine=", e, NULL);
+#endif
+                        if (!a)
+                                return log_oom();
+
+                        free(arg_address);
+                        arg_address = a;
+
                         break;
+                }
 
                 case '?':
                         return -EINVAL;
@@ -100,214 +278,73 @@ static int parse_argv(int argc, char *argv[]) {
                 default:
                         assert_not_reached("Unhandled option");
                 }
+
+        if (argc > optind) {
+                log_error("Too many arguments");
+                return -EINVAL;
+        }
+
+        if (!arg_address) {
+                arg_address = strdup(DEFAULT_SYSTEM_BUS_ADDRESS);
+                if (!arg_address)
+                        return log_oom();
         }
 
         return 1;
 }
 
 int main(int argc, char *argv[]) {
-        _cleanup_bus_unref_ sd_bus *a = NULL, *b = NULL;
-        sd_id128_t server_id;
-        bool is_unix;
-        int r, in_fd, out_fd;
+        const char *user = "systemd-bus-proxy";
+        int r, accept_fd;
+        uid_t uid, bus_uid;
+        gid_t gid;
 
         log_set_target(LOG_TARGET_JOURNAL_OR_KMSG);
         log_parse_environment();
         log_open();
 
-        r = parse_argv(argc, argv);
-        if (r <= 0)
-                goto finish;
-
-        r = sd_listen_fds(0);
-        if (r == 0) {
-                in_fd = STDIN_FILENO;
-                out_fd = STDOUT_FILENO;
-        } else if (r == 1) {
-                in_fd = SD_LISTEN_FDS_START;
-                out_fd = SD_LISTEN_FDS_START;
-        } else {
-                log_error("Illegal number of file descriptors passed\n");
-                goto finish;
-        }
-
-        is_unix =
-                sd_is_socket(in_fd, AF_UNIX, 0, 0) > 0 &&
-                sd_is_socket(out_fd, AF_UNIX, 0, 0) > 0;
+        bus_uid = getuid();
 
-        r = sd_bus_new(&a);
-        if (r < 0) {
-                log_error("Failed to allocate bus: %s", strerror(-r));
-                goto finish;
-        }
-
-        r = sd_bus_set_address(a, arg_address);
-        if (r < 0) {
-                log_error("Failed to set address to connect to: %s", strerror(-r));
-                goto finish;
-        }
-
-        r = sd_bus_negotiate_fds(a, is_unix);
-        if (r < 0) {
-                log_error("Failed to set FD negotiation: %s", strerror(-r));
-                goto finish;
-        }
-
-        r = sd_bus_start(a);
-        if (r < 0) {
-                log_error("Failed to start bus client: %s", strerror(-r));
-                goto finish;
-        }
-
-        r = sd_bus_get_server_id(a, &server_id);
-        if (r < 0) {
-                log_error("Failed to get server ID: %s", strerror(-r));
-                goto finish;
-        }
-
-        r = sd_bus_new(&b);
-        if (r < 0) {
-                log_error("Failed to allocate bus: %s", strerror(-r));
-                goto finish;
-        }
-
-        r = sd_bus_set_fd(b, in_fd, out_fd);
-        if (r < 0) {
-                log_error("Failed to set fds: %s", strerror(-r));
-                goto finish;
-        }
+        if (geteuid() == 0) {
+                r = get_user_creds(&user, &uid, &gid, NULL, NULL);
+                if (r < 0) {
+                        log_error_errno(r, "Cannot resolve user name %s: %m", user);
+                        goto finish;
+                }
 
-        r = sd_bus_set_server(b, 1, server_id);
-        if (r < 0) {
-                log_error("Failed to set server mode: %s", strerror(-r));
-                goto finish;
+                r = drop_privileges(uid, gid, 1ULL << CAP_IPC_OWNER);
+                if (r < 0) {
+                        log_error_errno(r, "Cannot drop privileges: %m");
+                        goto finish;
+                }
         }
 
-        r = sd_bus_negotiate_fds(b, is_unix);
-        if (r < 0) {
-                log_error("Failed to set FD negotiation: %s", strerror(-r));
+        r = parse_argv(argc, argv);
+        if (r <= 0)
                 goto finish;
-        }
 
-        r = sd_bus_set_anonymous(b, true);
-        if (r < 0) {
-                log_error("Failed to set anonymous authentication: %s", strerror(-r));
+        r = sd_listen_fds(0);
+        if (r != 1) {
+                log_error("Illegal number of file descriptors passed");
                 goto finish;
         }
 
-        r = sd_bus_start(b);
+        accept_fd = SD_LISTEN_FDS_START;
+        r = fd_nonblock(accept_fd, false);
         if (r < 0) {
-                log_error("Failed to start bus client: %s", strerror(-r));
+                log_error_errno(r, "Cannot mark accept-fd non-blocking: %m");
                 goto finish;
         }
 
-        for (;;) {
-                _cleanup_bus_message_unref_ sd_bus_message *m = NULL;
-                int events_a, events_b, fd;
-                uint64_t timeout_a, timeout_b, t;
-                struct timespec _ts, *ts;
-
-                r = sd_bus_process(a, &m);
-                if (r < 0) {
-                        log_error("Failed to process bus a: %s", strerror(-r));
-                        goto finish;
-                }
-
-                if (m) {
-                        r = sd_bus_send(b, m, NULL);
-                        if (r < 0) {
-                                log_error("Failed to send message: %s", strerror(-r));
-                                goto finish;
-                        }
-                }
-
-                if (r > 0)
-                        continue;
-
-                r = sd_bus_process(b, &m);
-                if (r < 0) {
-                        /* treat 'connection reset by peer' as clean exit condition */
-                        if (r == -ECONNRESET)
-                                r = 0;
-
-                        goto finish;
-                }
-
-                if (m) {
-                        r = sd_bus_send(a, m, NULL);
-                        if (r < 0) {
-                                log_error("Failed to send message: %s", strerror(-r));
-                                goto finish;
-                        }
-                }
-
-                if (r > 0)
-                        continue;
-
-                fd = sd_bus_get_fd(a);
-                if (fd < 0) {
-                        log_error("Failed to get fd: %s", strerror(-r));
-                        goto finish;
-                }
-
-                events_a = sd_bus_get_events(a);
-                if (events_a < 0) {
-                        log_error("Failed to get events mask: %s", strerror(-r));
-                        goto finish;
-                }
-
-                r = sd_bus_get_timeout(a, &timeout_a);
-                if (r < 0) {
-                        log_error("Failed to get timeout: %s", strerror(-r));
-                        goto finish;
-                }
-
-                events_b = sd_bus_get_events(b);
-                if (events_b < 0) {
-                        log_error("Failed to get events mask: %s", strerror(-r));
-                        goto finish;
-                }
-
-                r = sd_bus_get_timeout(b, &timeout_b);
-                if (r < 0) {
-                        log_error("Failed to get timeout: %s", strerror(-r));
-                        goto finish;
-                }
-
-                t = timeout_a;
-                if (t == (uint64_t) -1 || (timeout_b != (uint64_t) -1 && timeout_b < timeout_a))
-                        t = timeout_b;
-
-                if (t == (uint64_t) -1)
-                        ts = NULL;
-                else {
-                        usec_t nw;
-
-                        nw = now(CLOCK_MONOTONIC);
-                        if (t > nw)
-                                t -= nw;
-                        else
-                                t = 0;
+        r = loop_clients(accept_fd, bus_uid);
 
-                        ts = timespec_store(&_ts, t);
-                }
-
-                {
-                        struct pollfd p[3] = {
-                                {.fd = fd,            .events = events_a, },
-                                {.fd = STDIN_FILENO,  .events = events_b & POLLIN, },
-                                {.fd = STDOUT_FILENO, .events = events_b & POLLOUT, }};
-
-                        r = ppoll(p, ELEMENTSOF(p), ts, NULL);
-                }
-                if (r < 0) {
-                        log_error("ppoll() failed: %m");
-                        goto finish;
-                }
-        }
+finish:
+        sd_notify(false,
+                  "STOPPING=1\n"
+                  "STATUS=Shutting down.");
 
-        r = 0;
+        strv_free(arg_configuration);
+        free(arg_address);
 
-finish:
         return r < 0 ? EXIT_FAILURE : EXIT_SUCCESS;
 }