ubusd_acl: event listen access list support
authorHans Dedecker <dedeckeh@gmail.com>
Wed, 3 Oct 2018 13:36:17 +0000 (15:36 +0200)
committerHans Dedecker <dedeckeh@gmail.com>
Sat, 6 Oct 2018 18:39:34 +0000 (20:39 +0200)
Adds event listen access list support in ubus via the "listen" keyword

Example of a json file:

{
    "user": "superuser",
    "listen": [ "network.*" ],
}

Signed-off-by: Koen Dergent <koen.cj.dergent@gmail.com>
Signed-off-by: Hans Dedecker <dedeckeh@gmail.com>
ubusd_acl.c
ubusd_acl.h
ubusd_event.c

index fc11993ec583c759e2757b0118a4c4e40abf0860..992d0ea299366e25b7ee765207bcad208607c8e0 100644 (file)
@@ -51,6 +51,7 @@ struct ubusd_acl_obj {
        struct blob_attr *priv;
        bool subscribe;
        bool publish;
+       bool listen;
 };
 
 struct ubusd_acl_file {
@@ -132,6 +133,11 @@ ubusd_acl_check(struct ubus_client *cl, const char *obj,
                                return 0;
                        break;
 
+               case UBUS_ACL_LISTEN:
+                       if (acl->listen)
+                               return 0;
+                       break;
+
                case UBUS_ACL_ACCESS:
                        if (acl->methods) {
                                struct blob_attr *cur;
@@ -279,6 +285,13 @@ ubusd_acl_add_publish(struct ubusd_acl_file *file, const char *obj)
        o->publish = true;
 }
 
+static void ubusd_acl_add_listen(struct ubusd_acl_file *file, const char *obj)
+{
+       struct ubusd_acl_obj *o = ubusd_acl_alloc_obj(file, obj);
+
+       o->listen = true;
+}
+
 enum {
        ACL_USER,
        ACL_GROUP,
@@ -286,6 +299,7 @@ enum {
        ACL_PUBLISH,
        ACL_SUBSCRIBE,
        ACL_INHERIT,
+       ACL_LISTEN,
        __ACL_MAX
 };
 
@@ -296,6 +310,7 @@ static const struct blobmsg_policy acl_policy[__ACL_MAX] = {
        [ACL_PUBLISH] = { .name = "publish", .type = BLOBMSG_TYPE_ARRAY },
        [ACL_SUBSCRIBE] = { .name = "subscribe", .type = BLOBMSG_TYPE_ARRAY },
        [ACL_INHERIT] = { .name = "inherit", .type = BLOBMSG_TYPE_ARRAY },
+       [ACL_LISTEN] = { .name= "listen", .type = BLOBMSG_TYPE_ARRAY },
 };
 
 static void
@@ -327,6 +342,11 @@ ubusd_acl_file_add(struct ubusd_acl_file *file)
                blobmsg_for_each_attr(cur, tb[ACL_PUBLISH], rem)
                        if (blobmsg_type(cur) == BLOBMSG_TYPE_STRING)
                                ubusd_acl_add_publish(file, blobmsg_get_string(cur));
+
+       if (tb[ACL_LISTEN])
+               blobmsg_for_each_attr(cur, tb[ACL_LISTEN], rem)
+                       if (blobmsg_type(cur) == BLOBMSG_TYPE_STRING)
+                               ubusd_acl_add_listen(file, blobmsg_get_string(cur));
 }
 
 static void
index c5dfd8a9b3d553d00e48c206a53dee33893ac422..a6a6a30907c48d12281b06acb979f67d63cb0b12 100644 (file)
@@ -18,6 +18,7 @@ enum ubusd_acl_type {
        UBUS_ACL_PUBLISH,
        UBUS_ACL_SUBSCRIBE,
        UBUS_ACL_ACCESS,
+       UBUS_ACL_LISTEN,
 };
 
 int ubusd_acl_check(struct ubus_client *cl, const char *obj, const char *method, enum ubusd_acl_type type);
index f07f8267869b3806125b279f67d95f45e10c7ee0..6e612a19070b19a2a65577a3143aefeeeab532d9 100644 (file)
@@ -88,6 +88,9 @@ static int ubusd_alloc_event_pattern(struct ubus_client *cl, struct blob_attr *m
                len--;
        }
 
+       if (pattern[0] && ubusd_acl_check(cl, pattern, NULL, UBUS_ACL_LISTEN))
+               return UBUS_STATUS_PERMISSION_DENIED;
+
        ev = calloc(1, sizeof(*ev) + len + 1);
        if (!ev)
                return UBUS_STATUS_NO_DATA;