1 Star 0 Fork 1

mysnapcore/mysnapd

forked from tupelo-shen/mysnapd 
加入 Gitee
与超过 1400万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
文件
克隆/下载
polkit.go 4.49 KB
一键复制 编辑 原始数据 按行查看 历史
tupelo-shen 提交于 2022-11-08 09:25 +08:00 . fix: interfaces commit
// -*- Mode: Go; indent-tabs-mode: t -*-
/*
* Copyright (C) 2021 Canonical Ltd
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 3 as
* published by the Free Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*
*/
package builtin
import (
"bytes"
"fmt"
"io/ioutil"
"path/filepath"
"strings"
"gitee.com/mysnapcore/mysnapd/interfaces"
"gitee.com/mysnapcore/mysnapd/interfaces/polkit"
"gitee.com/mysnapcore/mysnapd/osutil"
"gitee.com/mysnapcore/mysnapd/polkit/validate"
"gitee.com/mysnapcore/mysnapd/snap"
)
const polkitSummary = `allows access to polkitd to check authorisation`
const polkitBaseDeclarationPlugs = `
polkit:
allow-installation: false
deny-auto-connection: true
`
const polkitBaseDeclarationSlots = `
polkit:
allow-installation:
slot-snap-type:
- core
deny-auto-connection: true
`
const polkitConnectedPlugAppArmor = `
# Description: Can talk to polkitd's CheckAuthorization API
#include <abstractions/dbus-strict>
dbus (send)
bus=system
path="/org/freedesktop/PolicyKit1/Authority"
interface="org.freedesktop.PolicyKit1.Authority"
member="{,Cancel}CheckAuthorization"
peer=(name="org.freedesktop.PolicyKit1", label=unconfined),
dbus (send)
bus=system
path="/org/freedesktop/PolicyKit1/Authority"
interface="org.freedesktop.DBus.Properties"
peer=(name="org.freedesktop.PolicyKit1", label=unconfined),
dbus (send)
bus=system
path="/org/freedesktop/PolicyKit1/Authority"
interface="org.freedesktop.DBus.Introspectable"
member="Introspect"
peer=(name="org.freedesktop.PolicyKit1", label=unconfined),
`
type polkitInterface struct {
commonInterface
}
func (iface *polkitInterface) getActionPrefix(attribs interfaces.Attrer) (string, error) {
var prefix string
if err := attribs.Attr("action-prefix", &prefix); err != nil {
return "", err
}
if err := interfaces.ValidateDBusBusName(prefix); err != nil {
return "", fmt.Errorf("plug has invalid action-prefix: %q", prefix)
}
return prefix, nil
}
func loadPolkitPolicy(filename, actionPrefix string) (polkit.Policy, error) {
content, err := ioutil.ReadFile(filename)
if err != nil {
return nil, fmt.Errorf(`cannot read file %q: %v`, filename, err)
}
// Check that the file content is a valid polkit policy file
actionIDs, err := validate.ValidatePolicy(bytes.NewReader(content))
if err != nil {
return nil, fmt.Errorf(`cannot validate policy file %q: %v`, filename, err)
}
// Check that the action IDs in the policy file match the action prefix
for _, id := range actionIDs {
if id != actionPrefix && !strings.HasPrefix(id, actionPrefix+".") {
return nil, fmt.Errorf(`policy file %q contains unexpected action ID %q`, filename, id)
}
}
return polkit.Policy(content), nil
}
func (iface *polkitInterface) PolkitConnectedPlug(spec *polkit.Specification, plug *interfaces.ConnectedPlug, slot *interfaces.ConnectedSlot) error {
actionPrefix, err := iface.getActionPrefix(plug)
if err != nil {
return err
}
mountDir := plug.Snap().MountDir()
policyFiles, err := filepath.Glob(filepath.Join(mountDir, "meta", "polkit", plug.Name()+".*.policy"))
if err != nil {
return err
}
if len(policyFiles) == 0 {
return fmt.Errorf("cannot find any policy files for plug %q", plug.Name())
}
for _, filename := range policyFiles {
suffix := strings.TrimSuffix(filepath.Base(filename), ".policy")
policy, err := loadPolkitPolicy(filename, actionPrefix)
if err != nil {
return err
}
if err := spec.AddPolicy(suffix, policy); err != nil {
return err
}
}
return nil
}
func (iface *polkitInterface) BeforePreparePlug(plug *snap.PlugInfo) error {
_, err := iface.getActionPrefix(plug)
return err
}
func init() {
registerIface(&polkitInterface{
commonInterface{
name: "polkit",
summary: polkitSummary,
implicitOnCore: osutil.IsExecutable("/usr/libexec/polkitd"),
implicitOnClassic: true,
baseDeclarationPlugs: polkitBaseDeclarationPlugs,
baseDeclarationSlots: polkitBaseDeclarationSlots,
connectedPlugAppArmor: polkitConnectedPlugAppArmor,
},
})
}
Loading...
马建仓 AI 助手
尝试更多
代码解读
代码找茬
代码优化
Go
1
https://gitee.com/mysnapcore/mysnapd.git
git@gitee.com:mysnapcore/mysnapd.git
mysnapcore
mysnapd
mysnapd
v0.1.0

搜索帮助