1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2013 Lennart Poettering
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU Lesser General Public License as published by
10 the Free Software Foundation; either version 2.1 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Lesser General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
26 #include "process-util.h"
27 #include "bus-internal.h"
28 #include "bus-socket.h"
29 #include "bus-container.h"
31 int bus_container_connect_socket(sd_bus *b) {
32 _cleanup_close_ int pidnsfd = -1, mntnsfd = -1, usernsfd = -1, rootfd = -1;
38 assert(b->input_fd < 0);
39 assert(b->output_fd < 0);
40 assert(b->nspid > 0 || b->machine);
43 r = container_get_leader(b->machine, &b->nspid);
48 r = namespace_open(b->nspid, &pidnsfd, &mntnsfd, NULL, &usernsfd, &rootfd);
52 b->input_fd = socket(b->sockaddr.sa.sa_family, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0);
56 b->output_fd = b->input_fd;
67 r = namespace_enter(pidnsfd, mntnsfd, -1, usernsfd, rootfd);
71 /* We just changed PID namespace, however it will only
72 * take effect on the children we now fork. Hence,
73 * let's fork another time, and connect from this
74 * grandchild, so that SO_PEERCRED of our connection
75 * comes from a process from within the container, and
76 * not outside of it */
82 if (grandchild == 0) {
84 r = connect(b->input_fd, &b->sockaddr.sa, b->sockaddr_size);
86 if (errno == EINPROGRESS)
95 r = wait_for_terminate(grandchild, &si);
99 if (si.si_code != CLD_EXITED)
105 r = wait_for_terminate(child, &si);
109 if (si.si_code != CLD_EXITED)
112 if (si.si_status == 1)
115 if (si.si_status != EXIT_SUCCESS)
118 return bus_socket_start_auth(b);
121 int bus_container_connect_kernel(sd_bus *b) {
122 _cleanup_close_pair_ int pair[2] = { -1, -1 };
123 _cleanup_close_ int pidnsfd = -1, mntnsfd = -1, usernsfd = -1, rootfd = -1;
125 struct cmsghdr cmsghdr;
126 uint8_t buf[CMSG_SPACE(sizeof(int))];
130 .iov_base = &error_buf,
131 .iov_len = sizeof(error_buf),
134 .msg_control = &control,
135 .msg_controllen = sizeof(control),
139 struct cmsghdr *cmsg;
146 assert(b->input_fd < 0);
147 assert(b->output_fd < 0);
148 assert(b->nspid > 0 || b->machine);
151 r = container_get_leader(b->machine, &b->nspid);
156 r = namespace_open(b->nspid, &pidnsfd, &mntnsfd, NULL, &usernsfd, &rootfd);
160 if (socketpair(AF_UNIX, SOCK_DGRAM, 0, pair) < 0)
170 pair[0] = safe_close(pair[0]);
172 r = namespace_enter(pidnsfd, mntnsfd, -1, usernsfd, rootfd);
176 /* We just changed PID namespace, however it will only
177 * take effect on the children we now fork. Hence,
178 * let's fork another time, and connect from this
179 * grandchild, so that kdbus only sees the credentials
180 * of this process which comes from within the
181 * container, and not outside of it */
187 if (grandchild == 0) {
188 fd = open(b->kernel, O_RDWR|O_NOCTTY|O_CLOEXEC);
190 /* Try to send error up */
192 (void) write(pair[1], &error_buf, sizeof(error_buf));
196 cmsg = CMSG_FIRSTHDR(&mh);
197 cmsg->cmsg_level = SOL_SOCKET;
198 cmsg->cmsg_type = SCM_RIGHTS;
199 cmsg->cmsg_len = CMSG_LEN(sizeof(int));
200 memcpy(CMSG_DATA(cmsg), &fd, sizeof(int));
202 mh.msg_controllen = cmsg->cmsg_len;
204 if (sendmsg(pair[1], &mh, MSG_NOSIGNAL) < 0)
210 r = wait_for_terminate(grandchild, &si);
214 if (si.si_code != CLD_EXITED)
220 pair[1] = safe_close(pair[1]);
222 r = wait_for_terminate(child, &si);
226 n = recvmsg(pair[0], &mh, MSG_NOSIGNAL|MSG_CMSG_CLOEXEC);
230 CMSG_FOREACH(cmsg, &mh) {
231 if (cmsg->cmsg_level == SOL_SOCKET && cmsg->cmsg_type == SCM_RIGHTS) {
237 fds = (int*) CMSG_DATA(cmsg);
238 n_fds = (cmsg->cmsg_len - CMSG_LEN(0)) / sizeof(int);
241 close_many(fds, n_fds);
249 /* If there's an fd passed, we are good. */
251 b->input_fd = b->output_fd = fd;
252 return bus_kernel_take_fd(b);
255 /* If there's an error passed, use it */
256 if (n == sizeof(error_buf) && error_buf > 0)
259 /* Otherwise, we have no clue */