mirror of
https://github.com/troglobit/finit.git
synced 2026-10-02 14:02:52 +07:00
On the local bus SO_PEERCRED says who is calling and the kernel is the one saying it. Behind a broker one connection carries every caller, so that credential describes dbus-daemon and nothing else, and every privileged method was refused there, root included. Ask the bus driver instead. libink parks the call and hands us the sender; we ask GetConnectionUnixUser and answer when the reply lands, through the same event loop as everything else. Nothing blocks: blocking in PID 1 is why libuEv exists. That needs calls libink can make on a connection it already has, so it gained those too. Answers are cached, since a bus never reuses a unique name while it runs. Not across a restart though: a new dbus-daemon numbers from scratch and :1.7 becomes somebody else, so the cache goes when the broker does. A sender name too long to key on is refused rather than truncated, two callers sharing a truncated key would share an identity. Privilege is no longer uid 0 alone. The socket is already owned by the --with-group group, so refusing its members every method that changes anything left a wheel user able to open the bus and unable to reboot. Both gates now say the same thing. Group membership needs NSS, which the C library loads with dlopen(), so the lookup is compiled out where Finit is built to link statically. That leaves such a build root-only, which is worth saying out loud rather than leaving to be discovered. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
64 lines
2.8 KiB
C
64 lines
2.8 KiB
C
/* libink — D-Bus body marshalling (writer side).
|
|
*
|
|
* Copyright (c) 2026 Joachim Wiberg <troglobit@gmail.com>
|
|
* SPDX-License-Identifier: MIT
|
|
*/
|
|
#ifndef LIBINK_MARSHAL_H_
|
|
#define LIBINK_MARSHAL_H_
|
|
|
|
#include <stdarg.h>
|
|
#include <stddef.h>
|
|
#include <stdint.h>
|
|
#include <sys/types.h>
|
|
|
|
/* struct link_writer is defined in ink.h (public). Field layout is
|
|
* "opaque" per the public contract; this file's helpers manipulate
|
|
* the fields directly. */
|
|
#include "link.h"
|
|
|
|
void __w_init (struct link_writer *w, uint8_t *buf, size_t cap);
|
|
ssize_t __w_finish(struct link_writer *w);
|
|
|
|
void __w_byte (struct link_writer *w, uint8_t v);
|
|
void __w_bool (struct link_writer *w, int v);
|
|
void __w_u32 (struct link_writer *w, uint32_t v);
|
|
void __w_string (struct link_writer *w, const char *s); /* "s" */
|
|
void __w_path (struct link_writer *w, const char *s); /* "o" */
|
|
void __w_sig (struct link_writer *w, const char *s); /* "g" */
|
|
void __w_variant_string(struct link_writer *w, const char *s); /* "v" containing "s" */
|
|
|
|
/* element_sig_first_char drives the alignment padding inserted
|
|
* between the array length prefix and the first element. */
|
|
void __w_array_begin (struct link_writer *w, char element_sig_first_char);
|
|
void __w_array_end (struct link_writer *w);
|
|
|
|
void __w_struct_begin(struct link_writer *w);
|
|
void __w_struct_end (struct link_writer *w);
|
|
|
|
/* ---- reader ----
|
|
*
|
|
* Reads from a message body pointer + length, advancing a cursor.
|
|
* struct link_reader is defined in link.h (public, opaque); the
|
|
* helpers here manipulate the fields directly. */
|
|
void __r_init (struct link_reader *r, const uint8_t *body, size_t len);
|
|
int __r_byte (struct link_reader *r, uint8_t *out);
|
|
int __r_bool (struct link_reader *r, int *out);
|
|
int __r_u32 (struct link_reader *r, uint32_t *out);
|
|
int __r_string(struct link_reader *r, const char **out); /* "s" */
|
|
int __r_path (struct link_reader *r, const char **out); /* "o" */
|
|
int __r_variant_begin (struct link_reader *r, char *type); /* sig header, cursor at value */
|
|
int __r_skip_basic (struct link_reader *r, char type); /* skip one basic value */
|
|
int __r_variant_string(struct link_reader *r, const char **out); /* "v" containing "s" */
|
|
int __r_variant_u32 (struct link_reader *r, uint32_t *out); /* "v" containing "u" */
|
|
int __r_align (struct link_reader *r, size_t n); /* skip to n-byte boundary */
|
|
int __r_array_begin(struct link_reader *r, size_t *out_end);
|
|
int __r_done (const struct link_reader *r);
|
|
|
|
/* Marshal varargs into `body` (capacity `cap`) according to `sig`.
|
|
* Returns the marshalled length, or -1 on overflow or an unsupported
|
|
* type code. Shared by the synchronous client and the asynchronous
|
|
* connection-side call. */
|
|
ssize_t __marshal_va(uint8_t *body, size_t cap, const char *sig, va_list ap);
|
|
|
|
#endif /* LIBINK_MARSHAL_H_ */
|