summary refs log tree commit diff
path: root/src/nm-dbus-manager.c
diff options
context:
space:
mode:
authorMichael Biebl <biebl@debian.org>2020-04-11 21:28:04 +0200
committerMichael Biebl <biebl@debian.org>2020-04-11 21:28:04 +0200
commit1e5977b62f896e844b548c3007ace9e1dfa7f9ed (patch)
tree7a7416ed410e72b6200f3d860fd315ec11cc106b /src/nm-dbus-manager.c
parentb012fa6e1d808e0736c009799c62d835cbfcc1dd (diff)
New upstream version 1.23.90 upstream/1.23.90
Diffstat (limited to 'src/nm-dbus-manager.c')
-rw-r--r--src/nm-dbus-manager.c70
1 files changed, 67 insertions, 3 deletions
diff --git a/src/nm-dbus-manager.c b/src/nm-dbus-manager.c
index 3f6f8115..239e06e1 100644
--- a/src/nm-dbus-manager.c
+++ b/src/nm-dbus-manager.c
@@ -19,6 +19,7 @@
 #include "nm-std-aux/nm-dbus-compat.h"
 #include "nm-dbus-object.h"
 #include "NetworkManagerUtils.h"
+#include "nm-libnm-core-intern/nm-auth-subject.h"
 
 /* The base path for our GDBusObjectManagerServers.  They do not contain
  * "NetworkManager" because GDBusObjectManagerServer requires that all
@@ -523,7 +524,7 @@ _get_caller_info_ensure (NMDBusManager *self,
 	gint64 now_ns;
 	gsize num;
 
-#define CALLER_INFO_MAX_AGE   (NM_UTILS_NS_PER_SECOND * 1)
+#define CALLER_INFO_MAX_AGE   (NM_UTILS_NSEC_PER_SEC * 1)
 
 	/* Linear search the cache for the sender.
 	 *
@@ -564,7 +565,7 @@ _get_caller_info_ensure (NMDBusManager *self,
 		}
 	}
 
-	now_ns = nm_utils_get_monotonic_timestamp_ns ();
+	now_ns = nm_utils_get_monotonic_timestamp_nsec ();
 
 	if (   ensure_uid
 	    && (now_ns - caller_info->uid_checked_at) > CALLER_INFO_MAX_AGE) {
@@ -1630,7 +1631,7 @@ dispose (GObject *object)
 	nm_assert (!priv->objects_by_path || g_hash_table_size (priv->objects_by_path) == 0);
 	nm_assert (c_list_is_empty (&priv->objects_lst_head));
 
-	g_clear_pointer (&priv->objects_by_path, g_hash_table_destroy);
+	nm_clear_pointer (&priv->objects_by_path, g_hash_table_destroy);
 
 	c_list_for_each_entry_safe (s, s_safe, &priv->private_servers_lst_head, private_servers_lst)
 		private_server_free (s);
@@ -1669,3 +1670,66 @@ nm_dbus_manager_class_init (NMDBusManagerClass *klass)
 	                  0, NULL, NULL, NULL,
 	                  G_TYPE_NONE, 1, G_TYPE_POINTER);
 }
+
+static NMAuthSubject *
+_new_unix_process (GDBusMethodInvocation *context,
+                   GDBusConnection *connection,
+                   GDBusMessage *message)
+{
+	NMAuthSubject *self;
+	const char *dbus_sender = NULL;
+	gulong uid = 0;
+	gulong pid = 0;
+	gboolean success;
+
+	g_return_val_if_fail (context || (connection && message), NULL);
+
+	if (context) {
+		success = nm_dbus_manager_get_caller_info (nm_dbus_manager_get (),
+		                                           context,
+		                                           &dbus_sender,
+		                                           &uid,
+		                                           &pid);
+	} else {
+		nm_assert (message);
+		success = nm_dbus_manager_get_caller_info_from_message (nm_dbus_manager_get (),
+		                                                        connection,
+		                                                        message,
+		                                                        &dbus_sender,
+		                                                        &uid,
+		                                                        &pid);
+	}
+
+	if (!success)
+		return NULL;
+
+	g_return_val_if_fail (dbus_sender && *dbus_sender, NULL);
+	/* polkit glib library stores uid and pid as int. There might be some
+	 * pitfalls if the id ever happens to be larger then that. Just assert against
+	 * it here. */
+	g_return_val_if_fail (uid <= MIN (G_MAXINT, G_MAXINT32), NULL);
+	g_return_val_if_fail (pid > 0 && pid <= MIN (G_MAXINT, G_MAXINT32), NULL);
+
+	self = nm_auth_subject_new_unix_process (dbus_sender, pid, uid);
+
+	if (nm_auth_subject_get_subject_type (self) != NM_AUTH_SUBJECT_TYPE_UNIX_PROCESS) {
+		/* this most likely happened because the process is gone (start_time==0).
+		 * Either that is not assert-worthy, or constructed() already asserted.
+		 * Just return NULL. */
+		g_clear_object (&self);
+	}
+	return self;
+}
+
+NMAuthSubject *
+nm_dbus_manager_new_auth_subject_from_context (GDBusMethodInvocation *context)
+{
+	return _new_unix_process (context, NULL, NULL);
+}
+
+NMAuthSubject *
+nm_dbus_manager_new_auth_subject_from_message (GDBusConnection *connection,
+                                               GDBusMessage *message)
+{
+	return _new_unix_process (NULL, connection, message);
+}