|
|
a60cd7 |
From d2dcaeddfe015d3fee3817737e1bae72f1ad3316 Mon Sep 17 00:00:00 2001
|
|
|
a60cd7 |
From: Jakub Filak <jfilak@redhat.com>
|
|
|
a60cd7 |
Date: Wed, 1 Jul 2015 13:38:57 +0200
|
|
|
a60cd7 |
Subject: [PATCH] cli: enable polkit authentication on command line
|
|
|
a60cd7 |
|
|
|
a60cd7 |
This patch will allow users to work with all problems without the need
|
|
|
a60cd7 |
to run abrt-cli under root account.
|
|
|
a60cd7 |
|
|
|
a60cd7 |
The polkit aget will run in a separate thread and will interact with a
|
|
|
a60cd7 |
user via STDOUT and STDIN, so we should not introduce new threads using
|
|
|
a60cd7 |
STDIN or STDOUT and all D-Bus calls should be synchronous.
|
|
|
a60cd7 |
|
|
|
a60cd7 |
http://www.freedesktop.org/software/polkit/docs/latest/ref-authentication-agent-api.html
|
|
|
a60cd7 |
|
|
|
a60cd7 |
Related: #1224984
|
|
|
a60cd7 |
|
|
|
a60cd7 |
Signed-off-by: Jakub Filak <jfilak@redhat.com>
|
|
|
a60cd7 |
|
|
|
a60cd7 |
Conflicts:
|
|
|
a60cd7 |
src/cli/Makefile.am
|
|
|
a60cd7 |
---
|
|
|
a60cd7 |
configure.ac | 1 +
|
|
|
a60cd7 |
doc/abrt-cli.txt | 11 +++++++++--
|
|
|
a60cd7 |
src/cli/Makefile.am | 2 ++
|
|
|
a60cd7 |
src/cli/abrt-cli-core.c | 50 +++++++++++++++++++++++++++++++++++++++++++++++--
|
|
|
a60cd7 |
src/cli/abrt-cli-core.h | 9 ++++++++-
|
|
|
a60cd7 |
src/cli/abrt-cli.c | 15 ++++++++++++++-
|
|
|
a60cd7 |
6 files changed, 82 insertions(+), 6 deletions(-)
|
|
|
a60cd7 |
|
|
|
a60cd7 |
diff --git a/configure.ac b/configure.ac
|
|
|
a60cd7 |
index d65bf54..56b8ad8 100644
|
|
|
a60cd7 |
--- a/configure.ac
|
|
|
a60cd7 |
+++ b/configure.ac
|
|
|
a60cd7 |
@@ -104,6 +104,7 @@ PKG_CHECK_MODULES([NSS], [nss])
|
|
|
a60cd7 |
PKG_CHECK_MODULES([LIBREPORT], [libreport])
|
|
|
a60cd7 |
PKG_CHECK_MODULES([LIBREPORT_GTK], [libreport-gtk])
|
|
|
a60cd7 |
PKG_CHECK_MODULES([POLKIT], [polkit-gobject-1])
|
|
|
a60cd7 |
+PKG_CHECK_MODULES([POLKIT_AGENT], [polkit-agent-1])
|
|
|
a60cd7 |
PKG_CHECK_MODULES([GIO], [gio-2.0])
|
|
|
a60cd7 |
PKG_CHECK_MODULES([SATYR], [satyr])
|
|
|
a60cd7 |
PKG_CHECK_MODULES([LIBSELINUX], [libselinux])
|
|
|
a60cd7 |
diff --git a/doc/abrt-cli.txt b/doc/abrt-cli.txt
|
|
|
a60cd7 |
index 399b5fd..0f18784 100644
|
|
|
a60cd7 |
--- a/doc/abrt-cli.txt
|
|
|
a60cd7 |
+++ b/doc/abrt-cli.txt
|
|
|
a60cd7 |
@@ -7,6 +7,8 @@ abrt-cli - List, remove, print, analyze, report problems
|
|
|
a60cd7 |
|
|
|
a60cd7 |
SYNOPSIS
|
|
|
a60cd7 |
--------
|
|
|
a60cd7 |
+'abrt-cli' [--authenticate] COMMAND [COMMAND OPTIONS]
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
'abrt-cli' list [-vn] [--detailed] [--since NUM] [--until NUM] [DIR]...
|
|
|
a60cd7 |
|
|
|
a60cd7 |
'abrt-cli' remove [-v] DIR...
|
|
|
a60cd7 |
@@ -19,8 +21,13 @@ SYNOPSIS
|
|
|
a60cd7 |
|
|
|
a60cd7 |
'abrt-cli' process [-v] [--since NUM] DIR...
|
|
|
a60cd7 |
|
|
|
a60cd7 |
-OPTIONS
|
|
|
a60cd7 |
--------
|
|
|
a60cd7 |
+GLOBAL OPTIONS
|
|
|
a60cd7 |
+--------------
|
|
|
a60cd7 |
+-a,--authenticate::
|
|
|
a60cd7 |
+ Enable PolicyKit authentication to be able to work with the system problems
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+COMMAND OPTIONS
|
|
|
a60cd7 |
+---------------
|
|
|
a60cd7 |
-v,--verbose::
|
|
|
a60cd7 |
Be more verbose. Can be given multiple times.
|
|
|
a60cd7 |
|
|
|
a60cd7 |
diff --git a/src/cli/Makefile.am b/src/cli/Makefile.am
|
|
|
a60cd7 |
index 9fff5b3..a7c76ef 100644
|
|
|
a60cd7 |
--- a/src/cli/Makefile.am
|
|
|
a60cd7 |
+++ b/src/cli/Makefile.am
|
|
|
a60cd7 |
@@ -17,6 +17,7 @@ abrt_cli_CFLAGS = \
|
|
|
a60cd7 |
-I$(srcdir)/../include \
|
|
|
a60cd7 |
-I$(srcdir)/../lib \
|
|
|
a60cd7 |
$(LIBREPORT_CFLAGS) \
|
|
|
a60cd7 |
+ $(POLKIT_AGENT_CFLAGS) \
|
|
|
a60cd7 |
-DWORKFLOWS_DIR=\"${WORKFLOWS_DIR}\"
|
|
|
a60cd7 |
|
|
|
a60cd7 |
if SUGGEST_AUTOREPORTING
|
|
|
a60cd7 |
@@ -24,6 +25,7 @@ abrt_cli_CFLAGS += -DSUGGEST_AUTOREPORTING=1
|
|
|
a60cd7 |
endif
|
|
|
a60cd7 |
|
|
|
a60cd7 |
abrt_cli_LDADD = \
|
|
|
a60cd7 |
+ $(POLKIT_AGENT_LIBS) \
|
|
|
a60cd7 |
$(LIBREPORT_LIBS) \
|
|
|
a60cd7 |
../lib/libabrt.la
|
|
|
a60cd7 |
|
|
|
a60cd7 |
diff --git a/src/cli/abrt-cli-core.c b/src/cli/abrt-cli-core.c
|
|
|
a60cd7 |
index 46acd01..ca49dbd 100644
|
|
|
a60cd7 |
--- a/src/cli/abrt-cli-core.c
|
|
|
a60cd7 |
+++ b/src/cli/abrt-cli-core.c
|
|
|
a60cd7 |
@@ -20,6 +20,17 @@
|
|
|
a60cd7 |
#include "libabrt.h"
|
|
|
a60cd7 |
#include "abrt-cli-core.h"
|
|
|
a60cd7 |
|
|
|
a60cd7 |
+/* It is not possible to include polkitagent.h without the following define.
|
|
|
a60cd7 |
+ * Check out the included header file.
|
|
|
a60cd7 |
+ */
|
|
|
a60cd7 |
+#define POLKIT_AGENT_I_KNOW_API_IS_SUBJECT_TO_CHANGE
|
|
|
a60cd7 |
+#include <polkitagent/polkitagent.h>
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+int g_cli_authenticate;
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+static PolkitAgentListener *s_local_polkit_agent = NULL;
|
|
|
a60cd7 |
+static gpointer s_local_agent_handle = NULL;
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
/* Vector of problems: */
|
|
|
a60cd7 |
/* problem_data_vector[i] = { "name" = { "content", CD_FLAG_foo_bits } } */
|
|
|
a60cd7 |
|
|
|
a60cd7 |
@@ -41,7 +52,7 @@ vector_of_problem_data_t *new_vector_of_problem_data(void)
|
|
|
a60cd7 |
|
|
|
a60cd7 |
vector_of_problem_data_t *fetch_crash_infos(void)
|
|
|
a60cd7 |
{
|
|
|
a60cd7 |
- GList *problems = get_problems_over_dbus(/*don't authorize*/false);
|
|
|
a60cd7 |
+ GList *problems = get_problems_over_dbus(g_cli_authenticate);
|
|
|
a60cd7 |
if (problems == ERR_PTR)
|
|
|
a60cd7 |
return NULL;
|
|
|
a60cd7 |
|
|
|
a60cd7 |
@@ -97,7 +108,7 @@ char *find_problem_by_hash(const char *hash, GList *problems)
|
|
|
a60cd7 |
char *hash2dirname(const char *hash)
|
|
|
a60cd7 |
{
|
|
|
a60cd7 |
/* Try loading by dirname hash */
|
|
|
a60cd7 |
- GList *problems = get_problems_over_dbus(/*don't authorize*/false);
|
|
|
a60cd7 |
+ GList *problems = get_problems_over_dbus(g_cli_authenticate);
|
|
|
a60cd7 |
if (problems == ERR_PTR)
|
|
|
a60cd7 |
return NULL;
|
|
|
a60cd7 |
|
|
|
a60cd7 |
@@ -112,3 +123,38 @@ char *hash2dirname_if_necessary(const char *input)
|
|
|
a60cd7 |
{
|
|
|
a60cd7 |
return isxdigit_str(input) ? hash2dirname(input) : xstrdup(input);
|
|
|
a60cd7 |
}
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+void initialize_polkit_agent(void)
|
|
|
a60cd7 |
+{
|
|
|
a60cd7 |
+ GError *error = NULL;
|
|
|
a60cd7 |
+ PolkitSubject *subject = polkit_unix_process_new_for_owner(
|
|
|
a60cd7 |
+ getpid(),
|
|
|
a60cd7 |
+ /*start time from /proc*/0,
|
|
|
a60cd7 |
+ getuid());
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+ s_local_polkit_agent = polkit_agent_text_listener_new(NULL, &error);
|
|
|
a60cd7 |
+ if (s_local_polkit_agent == NULL)
|
|
|
a60cd7 |
+ {
|
|
|
a60cd7 |
+ error_msg_and_die("polkit_agent_text_listener_new: %s (%s, %d)\n",
|
|
|
a60cd7 |
+ error->message, g_quark_to_string (error->domain), error->code);
|
|
|
a60cd7 |
+ }
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+ s_local_agent_handle = polkit_agent_listener_register(s_local_polkit_agent,
|
|
|
a60cd7 |
+ POLKIT_AGENT_REGISTER_FLAGS_RUN_IN_THREAD, subject, NULL, NULL, &error);
|
|
|
a60cd7 |
+ if (s_local_agent_handle == NULL)
|
|
|
a60cd7 |
+ {
|
|
|
a60cd7 |
+ error_msg_and_die("polkit_agent_listener_register: %s (%s, %d)\n",
|
|
|
a60cd7 |
+ error->message, g_quark_to_string (error->domain), error->code);
|
|
|
a60cd7 |
+ }
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+ g_object_unref(subject);
|
|
|
a60cd7 |
+}
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+void uninitialize_polkit_agent(void)
|
|
|
a60cd7 |
+{
|
|
|
a60cd7 |
+ if (s_local_agent_handle != NULL)
|
|
|
a60cd7 |
+ polkit_agent_listener_unregister(s_local_agent_handle);
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
+ if (s_local_polkit_agent != NULL)
|
|
|
a60cd7 |
+ g_object_unref(s_local_polkit_agent);
|
|
|
a60cd7 |
+}
|
|
|
a60cd7 |
diff --git a/src/cli/abrt-cli-core.h b/src/cli/abrt-cli-core.h
|
|
|
a60cd7 |
index d69d463..e2456e6 100644
|
|
|
a60cd7 |
--- a/src/cli/abrt-cli-core.h
|
|
|
a60cd7 |
+++ b/src/cli/abrt-cli-core.h
|
|
|
a60cd7 |
@@ -22,6 +22,10 @@
|
|
|
a60cd7 |
|
|
|
a60cd7 |
#include "problem_api.h"
|
|
|
a60cd7 |
|
|
|
a60cd7 |
+/* Use authenticate D-Bus methods. The authentication requires a polkit agent
|
|
|
a60cd7 |
+ * to finish an authenticated method successfully. */
|
|
|
a60cd7 |
+extern int g_cli_authenticate;
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
typedef GPtrArray vector_of_problem_data_t;
|
|
|
a60cd7 |
|
|
|
a60cd7 |
problem_data_t *get_problem_data(vector_of_problem_data_t *vector, unsigned i);
|
|
|
a60cd7 |
@@ -37,6 +41,9 @@ char *hash2dirname(const char *hash);
|
|
|
a60cd7 |
/* If input looks like a hash, returns malloced string, or NULL if not found.
|
|
|
a60cd7 |
* Otherwise returns a copy of the input. */
|
|
|
a60cd7 |
char *hash2dirname_if_necessary(const char *input);
|
|
|
a60cd7 |
-
|
|
|
a60cd7 |
+/* Initialize a new polkit text agent in a new thread */
|
|
|
a60cd7 |
+void initialize_polkit_agent(void);
|
|
|
a60cd7 |
+/* Uninitialize the polkit text agent */
|
|
|
a60cd7 |
+void uninitialize_polkit_agent(void);
|
|
|
a60cd7 |
|
|
|
a60cd7 |
#endif /* ABRT_CLI_CORE_H_ */
|
|
|
a60cd7 |
diff --git a/src/cli/abrt-cli.c b/src/cli/abrt-cli.c
|
|
|
a60cd7 |
index 8e19081..f45523e 100644
|
|
|
a60cd7 |
--- a/src/cli/abrt-cli.c
|
|
|
a60cd7 |
+++ b/src/cli/abrt-cli.c
|
|
|
a60cd7 |
@@ -19,6 +19,7 @@
|
|
|
a60cd7 |
|
|
|
a60cd7 |
#include "libabrt.h"
|
|
|
a60cd7 |
#include "builtin-cmd.h"
|
|
|
a60cd7 |
+#include "abrt-cli-core.h"
|
|
|
a60cd7 |
|
|
|
a60cd7 |
#define USAGE_OPTS_WIDTH 16
|
|
|
a60cd7 |
#define USAGE_GAP 2
|
|
|
a60cd7 |
@@ -75,6 +76,10 @@ static unsigned handle_internal_options(int argc, const char **argv, const char
|
|
|
a60cd7 |
{
|
|
|
a60cd7 |
return skip + argc;
|
|
|
a60cd7 |
}
|
|
|
a60cd7 |
+ else if (strcmp(cmd, "-a") == 0 || strcmp(cmd, "--authenticate") == 0)
|
|
|
a60cd7 |
+ {
|
|
|
a60cd7 |
+ g_cli_authenticate = 1;
|
|
|
a60cd7 |
+ }
|
|
|
a60cd7 |
else
|
|
|
a60cd7 |
error_msg_and_die("%s", usage);
|
|
|
a60cd7 |
|
|
|
a60cd7 |
@@ -122,7 +127,7 @@ int main(int argc, const char **argv)
|
|
|
a60cd7 |
argc--;
|
|
|
a60cd7 |
|
|
|
a60cd7 |
const char *abrt_cli_usage_string = _(
|
|
|
a60cd7 |
- "Usage: abrt-cli [--version] COMMAND [DIR]..."
|
|
|
a60cd7 |
+ "Usage: abrt-cli [--authenticate] [--version] COMMAND [DIR]..."
|
|
|
a60cd7 |
);
|
|
|
a60cd7 |
|
|
|
a60cd7 |
const struct cmd_struct commands[] = {
|
|
|
a60cd7 |
@@ -141,8 +146,16 @@ int main(int argc, const char **argv)
|
|
|
a60cd7 |
argc -= skip;
|
|
|
a60cd7 |
argv += skip;
|
|
|
a60cd7 |
if (argc > 0)
|
|
|
a60cd7 |
+ {
|
|
|
a60cd7 |
+ if (g_cli_authenticate)
|
|
|
a60cd7 |
+ initialize_polkit_agent();
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
handle_internal_command(argc, argv, commands);
|
|
|
a60cd7 |
|
|
|
a60cd7 |
+ if (g_cli_authenticate)
|
|
|
a60cd7 |
+ uninitialize_polkit_agent();
|
|
|
a60cd7 |
+ }
|
|
|
a60cd7 |
+
|
|
|
a60cd7 |
/* user didn't specify command; print out help */
|
|
|
a60cd7 |
printf("%s\n\n", abrt_cli_usage_string);
|
|
|
a60cd7 |
list_cmds_help(commands);
|
|
|
a60cd7 |
--
|
|
|
a60cd7 |
2.4.3
|
|
|
a60cd7 |
|