socket.c revision 62bc4efc7a617791d43f4e6cbef857554e6dbe2e
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek/*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek This file is part of systemd.
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek Copyright 2010 Lennart Poettering
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek systemd is free software; you can redistribute it and/or modify it
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek under the terms of the GNU Lesser General Public License as published by
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek the Free Software Foundation; either version 2.1 of the License, or
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek (at your option) any later version.
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek systemd is distributed in the hope that it will be useful, but
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek WITHOUT ANY WARRANTY; without even the implied warranty of
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek Lesser General Public License for more details.
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek You should have received a copy of the GNU Lesser General Public License
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek along with systemd; If not, see <http://www.gnu.org/licenses/>.
26687bf8a907009dedcff79346860ed41511405eOleksii Shevchukstatic const UnitActiveState state_translation_table[_SOCKET_STATE_MAX] = {
e150e82097211f09b911c7784a89ef9efed713caMichał Bartoszkiewicz [SOCKET_START_CHOWN] = UNIT_ACTIVATING,
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek [SOCKET_START_POST] = UNIT_ACTIVATING,
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering [SOCKET_STOP_PRE_SIGTERM] = UNIT_DEACTIVATING,
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering [SOCKET_STOP_PRE_SIGKILL] = UNIT_DEACTIVATING,
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering [SOCKET_FINAL_SIGTERM] = UNIT_DEACTIVATING,
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering [SOCKET_FINAL_SIGKILL] = UNIT_DEACTIVATING,
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poetteringstatic int socket_dispatch_io(sd_event_source *source, int fd, uint32_t revents, void *userdata);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poetteringstatic int socket_dispatch_timer(sd_event_source *source, usec_t usec, void *userdata);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek assert(u->load_state == UNIT_STUB);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering s->timeout_usec = u->manager->default_timeout_start_usec;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek s->exec_context.std_output = u->manager->default_std_output;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek s->exec_context.std_error = u->manager->default_std_error;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek s->control_command_id = _SOCKET_EXEC_COMMAND_INVALID;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic void socket_unwatch_control_pid(Socket *s) {
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering unit_unwatch_pid(UNIT(s), s->control_pid);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic void socket_cleanup_fd_list(SocketPort *p) {
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering close_many(p->auxiliary_fds, p->n_auxiliary_fds);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering p->auxiliary_fds = mfree(p->auxiliary_fds);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekvoid socket_free_ports(Socket *s) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek while ((p = s->ports)) {
670b110c3b59dfa335ac43065b2038400d1d04a9Zbigniew Jędrzejewski-Szmek s->exec_runtime = exec_runtime_unref(s->exec_runtime);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering exec_command_free_array(s->exec_command, _SOCKET_EXEC_COMMAND_MAX);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering s->tcp_congestion = mfree(s->tcp_congestion);
670b110c3b59dfa335ac43065b2038400d1d04a9Zbigniew Jędrzejewski-Szmek s->bind_to_device = mfree(s->bind_to_device);
670b110c3b59dfa335ac43065b2038400d1d04a9Zbigniew Jędrzejewski-Szmek s->smack_ip_in = mfree(s->smack_ip_in);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering s->smack_ip_out = mfree(s->smack_ip_out);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering s->timer_event_source = sd_event_source_unref(s->timer_event_source);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering s->timer_event_source = sd_event_source_unref(s->timer_event_source);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering r = sd_event_source_set_time(s->timer_event_source, now(CLOCK_MONOTONIC) + s->timeout_usec);
670b110c3b59dfa335ac43065b2038400d1d04a9Zbigniew Jędrzejewski-Szmek return sd_event_source_set_enabled(s->timer_event_source, SD_EVENT_ONESHOT);
0fb398316c6705dfc168733361650fdb6824896dLennart Poettering now(CLOCK_MONOTONIC) + s->timeout_usec, 0,
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek (void) sd_event_source_set_description(s->timer_event_source, "socket-timer");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekint socket_instantiate_service(Socket *s) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek _cleanup_free_ char *prefix = NULL, *name = NULL;
56f64d95763a799ba4475daf44d8e9f72a1bd474Michal Schmidt /* This fills in s->service if it isn't filled in yet. For
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * Accept=yes sockets we create the next connection service
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * here. For Accept=no this is mostly a NOP since the service
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * is figured out at load time anyway. */
0fb398316c6705dfc168733361650fdb6824896dLennart Poettering r = unit_name_to_prefix(UNIT(s)->id, &prefix);
23ad4dd8844c582929115a11ed2830a1371568d6Jan Alexander Steffens (heftig) if (asprintf(&name, "%s@%u.service", prefix, s->n_accepted) < 0)
23ad4dd8844c582929115a11ed2830a1371568d6Jan Alexander Steffens (heftig) r = manager_load_unit(UNIT(s)->manager, name, NULL, NULL, &u);
56f64d95763a799ba4475daf44d8e9f72a1bd474Michal Schmidt return unit_add_two_dependencies(UNIT(s), UNIT_BEFORE, UNIT_TRIGGERS, u, false);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic bool have_non_accept_socket(Socket *s) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek LIST_FOREACH(port, p, s->ports) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (!socket_address_can_accept(&p->address))
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic int socket_add_mount_links(Socket *s) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek LIST_FOREACH(port, p, s->ports) {
de0671ee7fe465e108f62dcbbbe9366f81dd9e9aZbigniew Jędrzejewski-Szmek path = socket_address_get_path(&p->address);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek else if (IN_SET(p->type, SOCKET_FIFO, SOCKET_SPECIAL, SOCKET_USB_FUNCTION))
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = unit_require_mounts_for(UNIT(s), path);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic int socket_add_device_link(Socket *s) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (!s->bind_to_device || streq(s->bind_to_device, "lo"))
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek t = strjoina("/sys/subsystem/net/devices/", s->bind_to_device);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek return unit_add_node_link(UNIT(s), t, false, UNIT_BINDS_TO);
ea69bd41c5923f4f278a09bb7d8cb1abcfa122e1Lennart Poetteringstatic int socket_add_default_dependencies(Socket *s) {
fc55baee9964a118afbddbf82b8e667a0ad80b99Zbigniew Jędrzejewski-Szmek r = unit_add_dependency_by_name(UNIT(s), UNIT_BEFORE, SPECIAL_SOCKETS_TARGET, NULL, true);
fc55baee9964a118afbddbf82b8e667a0ad80b99Zbigniew Jędrzejewski-Szmek if (UNIT(s)->manager->running_as == MANAGER_SYSTEM) {
fc55baee9964a118afbddbf82b8e667a0ad80b99Zbigniew Jędrzejewski-Szmek r = unit_add_two_dependencies_by_name(UNIT(s), UNIT_AFTER, UNIT_REQUIRES, SPECIAL_SYSINIT_TARGET, NULL, true);
fc55baee9964a118afbddbf82b8e667a0ad80b99Zbigniew Jędrzejewski-Szmek return unit_add_two_dependencies_by_name(UNIT(s), UNIT_BEFORE, UNIT_CONFLICTS, SPECIAL_SHUTDOWN_TARGET, NULL, true);
fc55baee9964a118afbddbf82b8e667a0ad80b99Zbigniew Jędrzejewski-Szmek_pure_ static bool socket_has_exec(Socket *s) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek for (i = 0; i < _SOCKET_EXEC_COMMAND_MAX; i++)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = unit_load_related_unit(u, ".service", &x);
26687bf8a907009dedcff79346860ed41511405eOleksii Shevchuk r = unit_add_two_dependencies(u, UNIT_BEFORE, UNIT_TRIGGERS, UNIT_DEREF(s->service), true);
26687bf8a907009dedcff79346860ed41511405eOleksii Shevchuk r = unit_add_exec_dependencies(u, &s->exec_context);
63c8666b824e8762ffb73647e1caee165dfbc868Zbigniew Jędrzejewski-Szmekstatic const char *socket_find_symlink_target(Socket *s) {
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering const char *f = NULL;
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering if (p->address.sockaddr.un.sun_path[0] != 0)
63c8666b824e8762ffb73647e1caee165dfbc868Zbigniew Jędrzejewski-Szmek f = p->address.sockaddr.un.sun_path;
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_unit_error(UNIT(s), "Unit lacks Listen setting. Refusing.");
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering if (s->accept && have_non_accept_socket(s)) {
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_unit_error(UNIT(s), "Unit configured for accepting sockets, but sockets are non-accepting. Refusing.");
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering if (s->accept && s->max_connections <= 0) {
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_unit_error(UNIT(s), "MaxConnection= setting too small. Refusing.");
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering if (s->accept && UNIT_DEREF(s->service)) {
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_unit_error(UNIT(s), "Explicit service configuration for accepting socket units not supported. Refusing.");
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering if (s->exec_context.pam_name && s->kill_context.kill_mode != KILL_CONTROL_GROUP) {
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_unit_error(UNIT(s), "Unit has PAM enabled. Kill mode must be set to 'control-group'. Refusing.");
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering if (!strv_isempty(s->symlinks) && !socket_find_symlink_target(s)) {
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_unit_error(UNIT(s), "Unit has symlinks set but none or more than one node in the file system. Refusing.");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (u->load_state == UNIT_LOADED) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* This is a new unit? Then let's add in some extras */
2678031a179a9b91fc799f8ef951a548c66c4b49Lennart Poettering_const_ static const char* listen_lookup(int family, int type) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek return "ListenNetlink";
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek return "ListenStream";
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek return "ListenDatagram";
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek else if (type == SOCK_SEQPACKET)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek return "ListenSequentialPacket";
fa6ac76083b8ffc1309876459f54f9f0e2843731Lennart Poettering assert_not_reached("Unknown socket type");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic void socket_dump(Unit *u, FILE *f, const char *prefix) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek char time_string[FORMAT_TIMESPAN_MAX];
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek prefix2 = strjoina(prefix, "\t");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sSocket State: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sResult: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sBindIPv6Only: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sBacklog: %u\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sSocketMode: %04o\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sDirectoryMode: %04o\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sKeepAlive: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sNoDelay: %s\n"
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering "%sFreeBind: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sTransparent: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sBroadcast: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sPassCredentials: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sPassSecurity: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sTCPCongestion: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sRemoveOnStop: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sWritable: %s\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sFDName: %s\n"
26687bf8a907009dedcff79346860ed41511405eOleksii Shevchuk "%sSELinuxContextFromNet: %s\n",
d07f7b9ef2835c290d6beadebd17d15308608eeaLennart Poettering prefix, socket_state_to_string(s->state),
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek prefix, socket_result_to_string(s->result),
26687bf8a907009dedcff79346860ed41511405eOleksii Shevchuk prefix, socket_address_bind_ipv6_only_to_string(s->bind_ipv6_only),
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek prefix, strna(s->tcp_congestion),
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek prefix, yes_no(s->remove_on_stop),
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek prefix, yes_no(s->selinux_context_from_net));
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sBindToDevice: %s\n",
d07f7b9ef2835c290d6beadebd17d15308608eeaLennart Poettering "%sAccepted: %u\n"
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek "%sNConnections: %u\n"
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sMaxConnections: %u\n",
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek "%sPriority: %i\n",
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sReceiveBuffer: %zu\n",
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek "%sSendBuffer: %zu\n",
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering "%sIPTOS: %i\n",
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sIPTTL: %i\n",
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sPipeSize: %zu\n",
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sMessageQueueMaxMessages: %li\n",
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek "%sMessageQueueMessageSize: %li\n",
63c372cb9df3bee01e3bf8cd7f96f336bddda846Lennart Poettering "%sReusePort: %s\n",
9bdbc2e2ec523dbefe1c1c7e164b5544aff0b185Lukas Nykryn "%sSmackLabel: %s\n",
3a83211689bdf4ab617a4fb79e11980c50918123Shawn Landden "%sSmackLabelIPIn: %s\n",
3a83211689bdf4ab617a4fb79e11980c50918123Shawn Landden "%sSmackLabelIPOut: %s\n",
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (!isempty(s->user) || !isempty(s->group))
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sOwnerUser: %s\n"
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering "%sOwnerGroup: %s\n",
7027ff61a34a12487712b382a061c654acc3a679Lennart Poettering "%sKeepAliveTimeSec: %s\n",
de0671ee7fe465e108f62dcbbbe9366f81dd9e9aZbigniew Jędrzejewski-Szmek prefix, format_timespan(time_string, FORMAT_TIMESPAN_MAX, s->keep_alive_time, USEC_PER_SEC));
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek "%sKeepAliveIntervalSec: %s\n",
e9174f29c7e3ee45137537b126458718913a3ec5Lennart Poettering prefix, format_timespan(time_string, FORMAT_TIMESPAN_MAX, s->keep_alive_interval, USEC_PER_SEC));
63c372cb9df3bee01e3bf8cd7f96f336bddda846Lennart Poettering "%sKeepAliveProbes: %u\n",
63c372cb9df3bee01e3bf8cd7f96f336bddda846Lennart Poettering "%sDeferAcceptSec: %s\n",
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering prefix, format_timespan(time_string, FORMAT_TIMESPAN_MAX, s->defer_accept, USEC_PER_SEC));
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering const char *t;
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering r = socket_address_print(&p->address, &k);
19cace379f3f680d3201cd257ab3ca6708b2d45dLennart Poettering fprintf(f, "%s%s: %s\n", prefix, listen_lookup(socket_address_family(&p->address), p->address.type), t);
19cace379f3f680d3201cd257ab3ca6708b2d45dLennart Poettering fprintf(f, "%sListenSpecial: %s\n", prefix, p->path);
19cace379f3f680d3201cd257ab3ca6708b2d45dLennart Poettering fprintf(f, "%sListenUSBFunction: %s\n", prefix, p->path);
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering fprintf(f, "%sListenMessageQueue: %s\n", prefix, p->path);
19cace379f3f680d3201cd257ab3ca6708b2d45dLennart Poettering fprintf(f, "%sListenFIFO: %s\n", prefix, p->path);
19cace379f3f680d3201cd257ab3ca6708b2d45dLennart Poettering exec_context_dump(&s->exec_context, f, prefix);
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering kill_context_dump(&s->kill_context, f, prefix);
63c372cb9df3bee01e3bf8cd7f96f336bddda846Lennart Poettering for (c = 0; c < _SOCKET_EXEC_COMMAND_MAX; c++) {
ae018d9bc900d6355dea4af05119b49c67945184Lennart Poettering prefix, socket_exec_command_to_string(c));
63c372cb9df3bee01e3bf8cd7f96f336bddda846Lennart Poettering exec_command_dump_list(s->exec_command[c], f, prefix2);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic int instance_from_socket(int fd, unsigned nr, char **instance) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (getsockname(fd, &local.sa, &l) < 0)
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek a = ntohl(local.in.sin_addr.s_addr),
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek b = ntohl(remote.in.sin_addr.s_addr);
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek "%u-%u.%u.%u.%u:%u-%u.%u.%u.%u:%u",
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek a >> 24, (a >> 16) & 0xFF, (a >> 8) & 0xFF, a & 0xFF,
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek b >> 24, (b >> 16) & 0xFF, (b >> 8) & 0xFF, b & 0xFF,
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek static const unsigned char ipv4_prefix[] = {
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek if (memcmp(&local.in6.sin6_addr, ipv4_prefix, sizeof(ipv4_prefix)) == 0 &&
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek memcmp(&remote.in6.sin6_addr, ipv4_prefix, sizeof(ipv4_prefix)) == 0) {
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek *a = local.in6.sin6_addr.s6_addr+12,
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek "%u-%u.%u.%u.%u:%u-%u.%u.%u.%u:%u",
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek ntohs(remote.in6.sin6_port)) < 0)
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek char a[INET6_ADDRSTRLEN], b[INET6_ADDRSTRLEN];
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek "%u-%s:%u-%s:%u",
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek inet_ntop(AF_INET6, &local.in6.sin6_addr, a, sizeof(a)),
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek inet_ntop(AF_INET6, &remote.in6.sin6_addr, b, sizeof(b)),
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek ntohs(remote.in6.sin6_port)) < 0)
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek } else if (k == -ENODATA) {
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek /* This handles the case where somebody is
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek * connecting from another pid/uid namespace
de0671ee7fe465e108f62dcbbbe9366f81dd9e9aZbigniew Jędrzejewski-Szmek * (e.g. from outside of our container). */
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmek assert_not_reached("Unhandled socket type.");
968f319679d9069af037240d0c3bcd126181cdacZbigniew Jędrzejewski-Szmekstatic void socket_close_fds(Socket *s) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek LIST_FOREACH(port, p, s->ports) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek p->event_source = sd_event_source_unref(p->event_source);
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering /* One little note: we should normally not delete any
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering * sockets in the file system here! After all some
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * other process we spawned might still have a
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * reference of this fd and wants to continue to use
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * it. Therefore we delete sockets in the file system
da4993920cdf5527b8528f0a483b54ab3cbc1971Kay Sievers * before we create a new one, not after we stopped
40adcda869bda55f44b57fd3a2bd71d006dfb51bLennart Poettering * using one! */
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek socket_address_unlink(&p->address);
b6fa25552e538eca207072e12d223e3523b21a19Evgeny Vereshchaginstatic void socket_apply_socket_options(Socket *s, int fd) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_KEEPALIVE, &b, sizeof(b)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_KEEPALIVE failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek int value = s->keep_alive_time / USEC_PER_SEC;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_TCP, TCP_KEEPIDLE, &value, sizeof(value)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "TCP_KEEPIDLE failed: %m");
d07f7b9ef2835c290d6beadebd17d15308608eeaLennart Poettering int value = s->keep_alive_interval / USEC_PER_SEC;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_TCP, TCP_KEEPINTVL, &value, sizeof(value)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "TCP_KEEPINTVL failed: %m");
3b3154df7e2773332bb814e167187367a0ccae4aLennart Poettering if (setsockopt(fd, SOL_TCP, TCP_KEEPCNT, &value, sizeof(value)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "TCP_KEEPCNT failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek int value = s->defer_accept / USEC_PER_SEC;
7027ff61a34a12487712b382a061c654acc3a679Lennart Poettering if (setsockopt(fd, SOL_TCP, TCP_DEFER_ACCEPT, &value, sizeof(value)) < 0)
7fd1b19bc9e9f5574f2877936b8ac267c7706947Harald Hoyer log_unit_warning_errno(UNIT(s), errno, "TCP_DEFER_ACCEPT failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (s->socket_protocol == IPPROTO_SCTP) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SCTP, SCTP_NODELAY, &b, sizeof(b)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SCTP_NODELAY failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_TCP, TCP_NODELAY, &b, sizeof(b)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "TCP_NODELAY failed: %m");
2f5df74a5ec135ab2baebf26af6f088e5b4b8205Holger Hans Peter Freyther if (setsockopt(fd, SOL_SOCKET, SO_BROADCAST, &one, sizeof(one)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_BROADCAST failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_PASSCRED, &one, sizeof(one)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_PASSCRED failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_PASSSEC, &one, sizeof(one)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_PASSSEC failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_PRIORITY, &s->priority, sizeof(s->priority)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_PRIORITY failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek int value = (int) s->receive_buffer;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* We first try with SO_RCVBUFFORCE, in case we have the perms for that */
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering if (setsockopt(fd, SOL_SOCKET, SO_RCVBUFFORCE, &value, sizeof(value)) < 0)
db91ea32aa223d1b087d99811226a9c59a1bb281Zbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_RCVBUF, &value, sizeof(value)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_RCVBUF failed: %m");
db91ea32aa223d1b087d99811226a9c59a1bb281Zbigniew Jędrzejewski-Szmek int value = (int) s->send_buffer;
db91ea32aa223d1b087d99811226a9c59a1bb281Zbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_SNDBUFFORCE, &value, sizeof(value)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_SNDBUF, &value, sizeof(value)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_SNDBUF failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, SOL_SOCKET, SO_MARK, &s->mark, sizeof(s->mark)) < 0)
caa2f4c0c9613b2e02aafa308c8fb092576014a9Zbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "SO_MARK failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (setsockopt(fd, IPPROTO_IP, IP_TOS, &s->ip_tos, sizeof(s->ip_tos)) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "IP_TOS failed: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = setsockopt(fd, IPPROTO_IP, IP_TTL, &s->ip_ttl, sizeof(s->ip_ttl));
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek x = setsockopt(fd, IPPROTO_IPV6, IPV6_UNICAST_HOPS, &s->ip_ttl, sizeof(s->ip_ttl));
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering if (r < 0 && x < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "IP_TTL/IPV6_UNICAST_HOPS failed: %m");
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering if (setsockopt(fd, SOL_TCP, TCP_CONGESTION, s->tcp_congestion, strlen(s->tcp_congestion)+1) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "TCP_CONGESTION failed: %m");
433dd100442e8197868def975c6fd38b48dc6439Lukas Nykryn r = mac_smack_apply_fd(fd, SMACK_ATTR_IPIN, s->smack_ip_in);
e40ec7aec5e64cd0cfa5fc556d6a9747229b5794Zbigniew Jędrzejewski-Szmek log_unit_error_errno(UNIT(s), r, "mac_smack_apply_ip_in_fd: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = mac_smack_apply_fd(fd, SMACK_ATTR_IPOUT, s->smack_ip_out);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_error_errno(UNIT(s), r, "mac_smack_apply_ip_out_fd: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic void socket_apply_fifo_options(Socket *s, int fd) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (fcntl(fd, F_SETPIPE_SZ, s->pipe_size) < 0)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_warning_errno(UNIT(s), errno, "Setting pipe size failed, ignoring: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = mac_smack_apply_fd(fd, SMACK_ATTR_ACCESS, s->smack);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek log_unit_error_errno(UNIT(s), r, "SMACK relabelling failed, ignoring: %m");
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek mkdir_parents_label(path, directory_mode);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering r = mac_selinux_create_file_prepare(path, S_IFIFO);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* Enforce the right access mode for the fifo */
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek old_mask = umask(~ socket_mode);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* Include the original umask in our mask */
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek (void) umask(~socket_mode | old_mask);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek fd = open(path, O_RDWR | O_CLOEXEC | O_NOCTTY | O_NONBLOCK | O_NOFOLLOW);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek mac_selinux_create_file_clear();
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek (st.st_mode & 0777) != (socket_mode & ~old_mask) ||
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek mac_selinux_create_file_clear();
fbb634117d0b0ebd5b105e65b141e75ae9af7f8fLennart Poetteringstatic int special_address_create(const char *path, bool writable) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek fd = open(path, (writable ? O_RDWR : O_RDONLY)|O_CLOEXEC|O_NOCTTY|O_NONBLOCK|O_NOFOLLOW);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* Check whether this is a /proc, /sys or /dev file or char device */
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (!S_ISREG(st.st_mode) && !S_ISCHR(st.st_mode))
253f59dff9c93ee1d2c33444b5715e42bc1c6889Lennart Poetteringstatic int usbffs_address_create(const char *path) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek fd = open(path, O_RDWR|O_CLOEXEC|O_NOCTTY|O_NONBLOCK|O_NOFOLLOW);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* Check whether this is a regular file (ffs endpoint)*/
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering /* Enforce the right access mode for the mq */
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering /* Include the original umask in our mask */
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering fd = mq_open(path, O_RDONLY|O_CLOEXEC|O_NONBLOCK|O_CREAT, mq_mode, attr);
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering if ((st.st_mode & 0777) != (mq_mode & ~old_mask) ||
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering const char *p;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek p = socket_find_symlink_target(s);
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poetteringstatic int usbffs_write_descs(int fd, Service *s) {
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering if (!s->usb_function_descriptors || !s->usb_function_strings)
875c2e220e2611165e09051c4747971811f1de58Lennart Poettering r = copy_file_fd(s->usb_function_descriptors, fd, false);
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering return copy_file_fd(s->usb_function_strings, fd, false);
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poetteringstatic int usbffs_select_ep(const struct dirent *d) {
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering return d->d_name[0] != '.' && !streq(d->d_name, "ep0");
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poetteringstatic int usbffs_dispatch_eps(SocketPort *p) {
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering _cleanup_free_ struct dirent **ent = NULL;
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering int r, i, n, k;
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering r = scandir(path, &ent, usbffs_select_ep, alphasort);
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering for (i = 0; i < n; ++i) {
a315ac4e076c4ce7ce3e5c95792cf916d5e918c5Lennart Poettering ep = path_make_absolute(ent[i]->d_name, path);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek close_many(p->auxiliary_fds, k);
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering p->auxiliary_fds = mfree(p->auxiliary_fds);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic int socket_open_fds(Socket *s) {
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering _cleanup_(mac_selinux_freep) char *label = NULL;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* Figure out label, if we don't it know
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering * yet. We do it once, for the first
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering * socket where we need this and
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * remember it for the rest. */
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* Get it from the network label */
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = mac_selinux_get_our_label(&label);
4daf54a851e4fb7ed1a13c3117bba12528fd2c7fZbigniew Jędrzejewski-Szmek if (r < 0 && r != -EOPNOTSUPP)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek /* Get it from the executable we are about to start */
72c0a2c255b172ebbb2a2b7dab7c9aec4c9582d9Lennart Poettering SERVICE(UNIT_DEREF(s->service))->exec_command[SERVICE_EXEC_START]) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = mac_selinux_get_create_label_from_exe(SERVICE(UNIT_DEREF(s->service))->exec_command[SERVICE_EXEC_START]->path, &label);
151b9b9662a90455262ce575a8a8ae74bf4ff336Lennart Poettering if (r < 0 && r != -EPERM && r != -EOPNOTSUPP)
151b9b9662a90455262ce575a8a8ae74bf4ff336Lennart Poettering /* Apply the socket protocol */
151b9b9662a90455262ce575a8a8ae74bf4ff336Lennart Poettering if (p->socket->socket_protocol == IPPROTO_SCTP)
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering p->address.protocol = p->socket->socket_protocol;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (p->socket->socket_protocol == IPPROTO_UDPLITE)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek p->address.protocol = p->socket->socket_protocol;
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek socket_apply_socket_options(s, p->fd);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek p->fd = special_address_create(p->path, s->writable);
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering if (p->fd < 0) {
26687bf8a907009dedcff79346860ed41511405eOleksii Shevchuk r = usbffs_write_descs(p->fd, SERVICE(UNIT_DEREF(s->service)));
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poetteringstatic void socket_unwatch_fds(Socket *s) {
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering r = sd_event_source_set_enabled(p->event_source, SD_EVENT_OFF);
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering log_unit_debug_errno(UNIT(s), r, "Failed to disable event source: %m");
26687bf8a907009dedcff79346860ed41511405eOleksii Shevchuk r = sd_event_source_set_enabled(p->event_source, SD_EVENT_ON);
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering r = sd_event_add_io(UNIT(s)->manager->event, &p->event_source, p->fd, EPOLLIN, socket_dispatch_io, p);
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering (void) sd_event_source_set_description(p->event_source, "socket-port-io");
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_unit_warning_errno(UNIT(s), r, "Failed to watch listening fds: %m");
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poetteringstatic void socket_set_state(Socket *s, SocketState state) {
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering s->timer_event_source = sd_event_source_unref(s->timer_event_source);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek s->control_command_id = _SOCKET_EXEC_COMMAND_INVALID;
e150e82097211f09b911c7784a89ef9efed713caMichał Bartoszkiewicz log_unit_debug(UNIT(s), "Changed %s -> %s", socket_state_to_string(old_state), socket_state_to_string(state));
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek unit_notify(UNIT(s), state_translation_table[old_state], state_translation_table[state], true);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic int socket_coldplug(Unit *u) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek assert(s->state == SOCKET_DEAD);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (s->deserialized_state == s->state)
b1389b0d0805392570085acc7cb10eafcf885405Zbigniew Jędrzejewski-Szmek pid_is_unwaited(s->control_pid) &&
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = unit_watch_pid(UNIT(s), s->control_pid);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (s->deserialized_state == SOCKET_LISTENING) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek socket_set_state(s, s->deserialized_state);
03ee5c38cb0da193dd08733fb4c0c2809cee6a99Lennart Poetteringstatic int socket_spawn(Socket *s, ExecCommand *c, pid_t *_pid) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = unit_full_printf_strv(UNIT(s), c->argv, &argv);
13790add4bf648fed816361794d8277a75253410Lennart Poettering exec_params.environment = UNIT(s)->manager->environment;
13790add4bf648fed816361794d8277a75253410Lennart Poettering exec_params.confirm_spawn = UNIT(s)->manager->confirm_spawn;
13790add4bf648fed816361794d8277a75253410Lennart Poettering exec_params.cgroup_supported = UNIT(s)->manager->cgroup_supported;
13790add4bf648fed816361794d8277a75253410Lennart Poettering exec_params.cgroup_path = UNIT(s)->cgroup_path;
13790add4bf648fed816361794d8277a75253410Lennart Poettering exec_params.cgroup_delegate = s->cgroup_context.delegate;
13790add4bf648fed816361794d8277a75253410Lennart Poettering exec_params.runtime_prefix = manager_get_runtime_prefix(UNIT(s)->manager);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = unit_watch_pid(UNIT(s), pid);
875c2e220e2611165e09051c4747971811f1de58Lennart Poettering /* FIXME: we need to do something here */
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering s->timer_event_source = sd_event_source_unref(s->timer_event_source);
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poetteringstatic int socket_chown(Socket *s, pid_t *_pid) {
f9a810bedacf1da7c505c1786a2416d592665926Lennart Poettering /* We have to resolve the user names out-of-process, hence
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek * let's fork here. It's messy, but well, what can we do? */
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek (void) default_signals(SIGNALS_CRASH_HANDLER, SIGNALS_IGNORE, -1);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek (void) ignore_signals(SIGPIPE, -1);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = get_user_creds(&user, &uid, &gid, NULL, NULL);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek r = get_group_creds(&group, &gid);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek LIST_FOREACH(port, p, s->ports) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek path = socket_address_get_path(&p->address);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek else if (p->type == SOCKET_FIFO)
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek if (chown(path, uid, gid) < 0) {
0c24bb2346b6b6232d67aacd5236b56ea4989de4Lennart Poettering log_error_errno(r, "Failed to chown socket at step %s: %m", exit_status_to_string(ret, EXIT_STATUS_SYSTEMD));
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek s->timer_event_source = sd_event_source_unref(s->timer_event_source);
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmekstatic void socket_enter_dead(Socket *s, SocketResult f) {
d025f1e4dca8fc1436aff76f9e6185fe3e728daaZbigniew Jędrzejewski-Szmek exec_runtime_destroy(s->exec_runtime);
3e044c492e3ebe64f4e3175c94f9db8a62557b82Markus Elfring s->exec_runtime = exec_runtime_unref(s->exec_runtime);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering exec_context_destroy_runtime_directory(&s->exec_context, manager_get_runtime_prefix(UNIT(s)->manager));
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering socket_set_state(s, s->result != SOCKET_SUCCESS ? SOCKET_FAILED : SOCKET_DEAD);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poetteringstatic void socket_enter_signal(Socket *s, SocketState state, SocketResult f);
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poetteringstatic void socket_enter_stop_post(Socket *s, SocketResult f) {
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering s->control_command_id = SOCKET_EXEC_STOP_POST;
8580d1f73db36e9383e674e388b4fb55828c0c66Lennart Poettering s->control_command = s->exec_command[SOCKET_EXEC_STOP_POST];
goto fail;
fail:
assert(s);
if (f != SOCKET_SUCCESS)
s->result = f;
r = unit_kill_context(
UNIT(s),
&s->kill_context,
s->control_pid,
goto fail;
r = socket_arm_timer(s);
goto fail;
fail:
assert(s);
if (f != SOCKET_SUCCESS)
s->result = f;
if (s->control_command) {
goto fail;
fail:
assert(s);
r = socket_watch_fds(s);
goto fail;
fail:
assert(s);
if (s->control_command) {
goto fail;
fail:
assert(s);
r = socket_open_fds(s);
goto fail;
goto fail;
fail:
assert(s);
if (s->control_command) {
goto fail;
fail:
assert(s);
if (cfd >= 0)
socket_close_fds(s);
r = socket_open_fds(s);
r = socket_watch_fds(s);
if (cfd < 0) {
Iterator i;
bool pending = false;
pending = true;
if (!pending) {
r = -ENOENT;
goto fail;
r = manager_add_job(UNIT(s)->manager, JOB_START, UNIT_DEREF(s->service), JOB_REPLACE, &error, NULL);
goto fail;
r = socket_instantiate_service(s);
goto fail;
if (r != -ENOTCONN)
goto fail;
goto fail;
goto fail;
goto fail;
s->n_accepted ++;
goto fail;
s->n_connections ++;
goto fail;
fail:
log_unit_warning(UNIT(s), "Failed to queue service startup job (Maybe the service file is missing or not a %s unit?): %s",
assert(s);
goto fail;
fail:
assert(s);
return -EAGAIN;
return -ENOENT;
return -EBUSY;
s->reset_cpu_usage = true;
assert(s);
return -EAGAIN;
SocketPort *p;
assert(u);
assert(f);
if (s->control_pid > 0)
if (s->control_command_id >= 0)
int copy;
if (p->fd < 0)
if (copy < 0)
return copy;
assert(u);
if (state < 0)
SocketResult f;
else if (f != SOCKET_SUCCESS)
s->result = f;
s->n_accepted += k;
if (id < 0)
SocketPort *p;
SocketPort *p;
SocketPort *p;
SocketPort *p;
if (sscanf(value, "%i %i %n", &fd, &type, &skip) < 2 || fd < 0 || type < 0 || !fdset_contains(fds, fd))
SocketPort *p;
SocketPort *p;
SocketPort *p;
assert(u);
Iterator i;
int fd;
if (p->fd >= 0)
assert(u);
assert(u);
assert(p);
switch (p->type) {
case SOCKET_SOCKET:
case SOCK_STREAM:
case SOCK_DGRAM:
case SOCK_SEQPACKET:
case SOCK_RAW:
return NULL;
case SOCKET_SPECIAL:
case SOCKET_MQUEUE:
case SOCKET_FIFO:
case SOCKET_USB_FUNCTION:
return NULL;
assert(u);
return s->n_connections > 0;
assert(p);
log_unit_error(UNIT(p->socket), "Got POLLHUP on a listening socket. The service probably invoked shutdown() on it, and should better not do that.");
goto fail;
if (cfd < 0) {
goto fail;
fail:
SocketResult f;
assert(s);
s->control_pid = 0;
f = SOCKET_SUCCESS;
if (s->control_command) {
f = SOCKET_SUCCESS;
if (f != SOCKET_SUCCESS)
s->result = f;
if (s->control_command &&
f == SOCKET_SUCCESS) {
socket_run_next(s);
switch (s->state) {
case SOCKET_START_PRE:
if (f == SOCKET_SUCCESS)
case SOCKET_START_CHOWN:
if (f == SOCKET_SUCCESS)
socket_enter_stop_pre(s, f);
case SOCKET_START_POST:
if (f == SOCKET_SUCCESS)
socket_enter_stop_pre(s, f);
case SOCKET_STOP_PRE:
case SOCKET_STOP_PRE_SIGTERM:
case SOCKET_STOP_PRE_SIGKILL:
socket_enter_stop_post(s, f);
case SOCKET_STOP_POST:
case SOCKET_FINAL_SIGTERM:
case SOCKET_FINAL_SIGKILL:
socket_enter_dead(s, f);
assert(s);
switch (s->state) {
case SOCKET_START_PRE:
case SOCKET_START_CHOWN:
case SOCKET_START_POST:
case SOCKET_STOP_PRE:
case SOCKET_STOP_PRE_SIGTERM:
case SOCKET_STOP_PRE_SIGKILL:
case SOCKET_STOP_POST:
case SOCKET_FINAL_SIGTERM:
case SOCKET_FINAL_SIGKILL:
int *rfds, k = 0, n = 0;
SocketPort *p;
assert(s);
if (p->fd >= 0)
n += p->n_auxiliary_fds;
if (!rfds)
return -ENOMEM;
if (p->fd >= 0)
for (i = 0; i < p->n_auxiliary_fds; ++i)
assert(k == n);
assert(s);
assert(s);
log_unit_debug(UNIT(s), "Got notified about service death (failed permanently: %s)", yes_no(failed_permanent));
if (failed_permanent)
assert(s);
s->n_connections--;
assert(u);
s->accept)
socket_notify_service_dead(s, false);
if (!s->timer_event_source)
assert(s);
if (s->fdname)
return s->fdname;
.sections =
.finished_start_job = {
.finished_stop_job = {