Files
finit/libink/marshal.h
T
Joachim Wiberg 63aabaa6df libink/dbus: identify the caller behind a broker
On the local bus SO_PEERCRED says who is calling and the kernel is the
one saying it.  Behind a broker one connection carries every caller,
so that credential describes dbus-daemon and nothing else, and every
privileged method was refused there, root included.

Ask the bus driver instead.  libink parks the call and hands us the
sender; we ask GetConnectionUnixUser and answer when the reply lands,
through the same event loop as everything else.  Nothing blocks:
blocking in PID 1 is why libuEv exists.  That needs calls libink can
make on a connection it already has, so it gained those too.

Answers are cached, since a bus never reuses a unique name while it
runs.  Not across a restart though: a new dbus-daemon numbers from
scratch and :1.7 becomes somebody else, so the cache goes when the
broker does.  A sender name too long to key on is refused rather than
truncated, two callers sharing a truncated key would share an
identity.

Privilege is no longer uid 0 alone.  The socket is already owned by
the --with-group group, so refusing its members every method that
changes anything left a wheel user able to open the bus and unable to
reboot.  Both gates now say the same thing.

Group membership needs NSS, which the C library loads with dlopen(),
so the lookup is compiled out where Finit is built to link statically.
That leaves such a build root-only, which is worth saying out loud
rather than leaving to be discovered.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:06 +02:00

64 lines
2.8 KiB
C

/* libink — D-Bus body marshalling (writer side).
*
* Copyright (c) 2026 Joachim Wiberg <troglobit@gmail.com>
* SPDX-License-Identifier: MIT
*/
#ifndef LIBINK_MARSHAL_H_
#define LIBINK_MARSHAL_H_
#include <stdarg.h>
#include <stddef.h>
#include <stdint.h>
#include <sys/types.h>
/* struct link_writer is defined in ink.h (public). Field layout is
* "opaque" per the public contract; this file's helpers manipulate
* the fields directly. */
#include "link.h"
void __w_init (struct link_writer *w, uint8_t *buf, size_t cap);
ssize_t __w_finish(struct link_writer *w);
void __w_byte (struct link_writer *w, uint8_t v);
void __w_bool (struct link_writer *w, int v);
void __w_u32 (struct link_writer *w, uint32_t v);
void __w_string (struct link_writer *w, const char *s); /* "s" */
void __w_path (struct link_writer *w, const char *s); /* "o" */
void __w_sig (struct link_writer *w, const char *s); /* "g" */
void __w_variant_string(struct link_writer *w, const char *s); /* "v" containing "s" */
/* element_sig_first_char drives the alignment padding inserted
* between the array length prefix and the first element. */
void __w_array_begin (struct link_writer *w, char element_sig_first_char);
void __w_array_end (struct link_writer *w);
void __w_struct_begin(struct link_writer *w);
void __w_struct_end (struct link_writer *w);
/* ---- reader ----
*
* Reads from a message body pointer + length, advancing a cursor.
* struct link_reader is defined in link.h (public, opaque); the
* helpers here manipulate the fields directly. */
void __r_init (struct link_reader *r, const uint8_t *body, size_t len);
int __r_byte (struct link_reader *r, uint8_t *out);
int __r_bool (struct link_reader *r, int *out);
int __r_u32 (struct link_reader *r, uint32_t *out);
int __r_string(struct link_reader *r, const char **out); /* "s" */
int __r_path (struct link_reader *r, const char **out); /* "o" */
int __r_variant_begin (struct link_reader *r, char *type); /* sig header, cursor at value */
int __r_skip_basic (struct link_reader *r, char type); /* skip one basic value */
int __r_variant_string(struct link_reader *r, const char **out); /* "v" containing "s" */
int __r_variant_u32 (struct link_reader *r, uint32_t *out); /* "v" containing "u" */
int __r_align (struct link_reader *r, size_t n); /* skip to n-byte boundary */
int __r_array_begin(struct link_reader *r, size_t *out_end);
int __r_done (const struct link_reader *r);
/* Marshal varargs into `body` (capacity `cap`) according to `sig`.
* Returns the marshalled length, or -1 on overflow or an unsupported
* type code. Shared by the synchronous client and the asynchronous
* connection-side call. */
ssize_t __marshal_va(uint8_t *body, size_t cap, const char *sig, va_list ap);
#endif /* LIBINK_MARSHAL_H_ */