1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2014 Daniel Mack
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU Lesser General Public License as published by
10 the Free Software Foundation; either version 2.1 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Lesser General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
22 #include <sys/socket.h>
24 #include <sys/types.h>
36 #include "bus-internal.h"
37 #include "bus-message.h"
39 #include "bus-internal.h"
43 #include "capability.h"
45 #include <bus-proxyd/bus-policy.h>
47 static int make_name_request(sd_bus *bus,
49 sd_bus_message **ret) {
52 sd_bus_message *m = NULL;
54 r = sd_bus_message_new_method_call(bus, &m, "org.freedesktop.DBus", "/org/freedesktop/DBus", "org.freedesktop.DBus", "RequestName");
58 r = sd_bus_message_append_basic(m, 's', name);
63 sd_bus_message_rewind(m, true);
69 int main(int argc, char *argv[]) {
73 struct ucred ucred = {};
74 _cleanup_bus_close_unref_ sd_bus *bus = NULL;;
76 assert_se(sd_bus_default_system(&bus) >= 0);
78 /* Fake pid for policy checks */
82 assert_se(policy_load(&p, STRV_MAKE("test/bus-policy/ownerships.conf")) == 0);
84 assert_se(make_name_request(bus, "org.test.test1", &m) == 0);
86 assert_se(policy_check(&p, m, &ucred) == true);
88 assert_se(policy_check(&p, m, &ucred) == true);
89 assert_se(sd_bus_message_unref(m) == 0);
91 assert_se(make_name_request(bus, "org.test.test2", &m) == 0);
93 assert_se(policy_check(&p, m, &ucred) == true);
95 assert_se(policy_check(&p, m, &ucred) == false);
96 assert_se(sd_bus_message_unref(m) == 0);
98 assert_se(make_name_request(bus, "org.test.test3", &m) == 0);
100 assert_se(policy_check(&p, m, &ucred) == false);
102 assert_se(policy_check(&p, m, &ucred) == false);
103 assert_se(sd_bus_message_unref(m) == 0);
105 assert_se(make_name_request(bus, "org.test.test4", &m) == 0);
107 assert_se(policy_check(&p, m, &ucred) == false);
109 assert_se(policy_check(&p, m, &ucred) == true);
110 assert_se(sd_bus_message_unref(m) == 0);
115 assert_se(policy_load(&p, STRV_MAKE("test/bus-policy/signals.conf")) == 0);
117 assert_se(sd_bus_message_new_signal(bus, &m, "/an/object/path", "bli.bla.blubb", "Name") == 0);
119 assert_se(policy_check(&p, m, &ucred) == true);
122 assert_se(policy_check(&p, m, &ucred) == false);
123 assert_se(sd_bus_message_unref(m) == 0);
128 assert_se(policy_load(&p, STRV_MAKE("test/bus-policy/methods.conf")) == 0);
131 assert_se(sd_bus_message_new_method_call(bus, &m, "org.foo.bar", "/an/object/path", "bli.bla.blubb", "Member") == 0);
132 assert_se(policy_check(&p, m, &ucred) == false);
134 assert_se(sd_bus_message_new_method_call(bus, &m, "org.test.test1", "/an/object/path", "bli.bla.blubb", "Member") == 0);
135 assert_se(policy_check(&p, m, &ucred) == false);
138 assert_se(sd_bus_message_new_method_call(bus, &m, "org.test.test1", "/an/object/path", "org.test.int1", "Member") == 0);
139 assert_se(policy_check(&p, m, &ucred) == true);
141 assert_se(sd_bus_message_new_method_call(bus, &m, "org.test.test1", "/an/object/path", "org.test.int2", "Member") == 0);
142 assert_se(policy_check(&p, m, &ucred) == true);
146 /* User and groups */
147 assert_se(policy_load(&p, STRV_MAKE("test/bus-policy/hello.conf")) == 0);
148 assert_se(sd_bus_message_new_method_call(bus, &m, "org.freedesktop.DBus", "/org/freedesktop/DBus", "org.freedesktop.DBus", "Hello") == 0);
152 assert_se(policy_check(&p, m, &ucred) == true);
155 assert_se(policy_check(&p, m, &ucred) == false);
159 assert_se(policy_check(&p, m, &ucred) == false);