代码拉取完成,页面将自动刷新
同步操作将从 tupelo-shen/mysnapd 强制同步,此操作会覆盖自 Fork 仓库以来所做的任何修改,且无法恢复!!!
确定后同步将在后台操作,完成时将刷新页面,请耐心等待。
// -*- Mode: Go; indent-tabs-mode: t -*-
/*
* Copyright (C) 2021 Canonical Ltd
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 3 as
* published by the Free Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*
*/
package builtin
import (
"bytes"
"fmt"
"io/ioutil"
"path/filepath"
"strings"
"gitee.com/mysnapcore/mysnapd/interfaces"
"gitee.com/mysnapcore/mysnapd/interfaces/polkit"
"gitee.com/mysnapcore/mysnapd/osutil"
"gitee.com/mysnapcore/mysnapd/polkit/validate"
"gitee.com/mysnapcore/mysnapd/snap"
)
const polkitSummary = `allows access to polkitd to check authorisation`
const polkitBaseDeclarationPlugs = `
polkit:
allow-installation: false
deny-auto-connection: true
`
const polkitBaseDeclarationSlots = `
polkit:
allow-installation:
slot-snap-type:
- core
deny-auto-connection: true
`
const polkitConnectedPlugAppArmor = `
# Description: Can talk to polkitd's CheckAuthorization API
#include <abstractions/dbus-strict>
dbus (send)
bus=system
path="/org/freedesktop/PolicyKit1/Authority"
interface="org.freedesktop.PolicyKit1.Authority"
member="{,Cancel}CheckAuthorization"
peer=(name="org.freedesktop.PolicyKit1", label=unconfined),
dbus (send)
bus=system
path="/org/freedesktop/PolicyKit1/Authority"
interface="org.freedesktop.DBus.Properties"
peer=(name="org.freedesktop.PolicyKit1", label=unconfined),
dbus (send)
bus=system
path="/org/freedesktop/PolicyKit1/Authority"
interface="org.freedesktop.DBus.Introspectable"
member="Introspect"
peer=(name="org.freedesktop.PolicyKit1", label=unconfined),
`
type polkitInterface struct {
commonInterface
}
func (iface *polkitInterface) getActionPrefix(attribs interfaces.Attrer) (string, error) {
var prefix string
if err := attribs.Attr("action-prefix", &prefix); err != nil {
return "", err
}
if err := interfaces.ValidateDBusBusName(prefix); err != nil {
return "", fmt.Errorf("plug has invalid action-prefix: %q", prefix)
}
return prefix, nil
}
func loadPolkitPolicy(filename, actionPrefix string) (polkit.Policy, error) {
content, err := ioutil.ReadFile(filename)
if err != nil {
return nil, fmt.Errorf(`cannot read file %q: %v`, filename, err)
}
// Check that the file content is a valid polkit policy file
actionIDs, err := validate.ValidatePolicy(bytes.NewReader(content))
if err != nil {
return nil, fmt.Errorf(`cannot validate policy file %q: %v`, filename, err)
}
// Check that the action IDs in the policy file match the action prefix
for _, id := range actionIDs {
if id != actionPrefix && !strings.HasPrefix(id, actionPrefix+".") {
return nil, fmt.Errorf(`policy file %q contains unexpected action ID %q`, filename, id)
}
}
return polkit.Policy(content), nil
}
func (iface *polkitInterface) PolkitConnectedPlug(spec *polkit.Specification, plug *interfaces.ConnectedPlug, slot *interfaces.ConnectedSlot) error {
actionPrefix, err := iface.getActionPrefix(plug)
if err != nil {
return err
}
mountDir := plug.Snap().MountDir()
policyFiles, err := filepath.Glob(filepath.Join(mountDir, "meta", "polkit", plug.Name()+".*.policy"))
if err != nil {
return err
}
if len(policyFiles) == 0 {
return fmt.Errorf("cannot find any policy files for plug %q", plug.Name())
}
for _, filename := range policyFiles {
suffix := strings.TrimSuffix(filepath.Base(filename), ".policy")
policy, err := loadPolkitPolicy(filename, actionPrefix)
if err != nil {
return err
}
if err := spec.AddPolicy(suffix, policy); err != nil {
return err
}
}
return nil
}
func (iface *polkitInterface) BeforePreparePlug(plug *snap.PlugInfo) error {
_, err := iface.getActionPrefix(plug)
return err
}
func init() {
registerIface(&polkitInterface{
commonInterface{
name: "polkit",
summary: polkitSummary,
implicitOnCore: osutil.IsExecutable("/usr/libexec/polkitd"),
implicitOnClassic: true,
baseDeclarationPlugs: polkitBaseDeclarationPlugs,
baseDeclarationSlots: polkitBaseDeclarationSlots,
connectedPlugAppArmor: polkitConnectedPlugAppArmor,
},
})
}
此处可能存在不合适展示的内容,页面不予展示。您可通过相关编辑功能自查并修改。
如您确认内容无涉及 不当用语 / 纯广告导流 / 暴力 / 低俗色情 / 侵权 / 盗版 / 虚假 / 无价值内容或违法国家有关法律法规的内容,可点击提交进行申诉,我们将尽快为您处理。