Repository navigation
fix(data-transfer): launch via deepin-security-loader to avoid polkit… - #784
Conversation
Reviewer's GuideThe PR changes Linux startup to use deepin-security-loader when supported, reports the process D-Bus identity so lastore can register its allow-caller whitelist without polkit prompts, and retains direct-launch compatibility through a packaged /usr/bin launcher and updated Qt DBus/debian packaging. Sequence diagram for security-loader startup and lastore authorizationsequenceDiagram
participant Launcher as deepin-data-transfer
participant Loader as deepin-security-loader
participant App as data-transfer
participant Bus as D-Bus system bus
participant Lastore as com.deepin.lastore
Launcher->>Loader: exec --group deepin-daemon REAL_BIN
Loader->>App: start with --fd1 and --fd2
App->>Bus: QDBusConnection::systemBus().baseService()
Bus-->>App: UniqueName
App->>Loader: initSecurityLoaderReport JSON
Loader->>Lastore: SetAllowCaller whitelist registration
Lastore-->>Loader: Result
Loader-->>App: JSON result
App->>Lastore: InstallPackage
Lastore-->>App: installation without polkit prompt
Flow diagram for Linux data-transfer launch fallbackflowchart TD
Start(["Start deepin-data-transfer"]) --> LoaderCheck{"security-loader executable?"}
LoaderCheck -->|No| Direct["exec real binary directly"]
LoaderCheck -->|Yes| DbusVersion["Read installed dbus version"]
DbusVersion --> VersionCheck{"Version >= 1.12.20.17-deepin1?"}
VersionCheck -->|No| Direct
VersionCheck -->|Yes| Secure["exec security-loader with deepin-daemon group"]
Secure --> RealBin["/usr/libexec/deepin/deepin-data-transfer"]
Direct --> RealBin
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="src/apps/data-transfer/main.cpp" line_range="49-50" />
<code_context>
+ if (args.at(i) != QLatin1String("--fd1") && args.at(i) != QLatin1String("--fd2"))
+ continue;
+ // toInt() 解析失败会返回 0(即 stdin),必须校验,避免误把标准输入当作管道 fd
+ bool ok = false;
+ const int fd = args.at(i + 1).toInt(&ok);
+ if (!ok)
+ continue;
+ if (args.at(i) == QLatin1String("--fd1"))
+ fd1 = fd;
</code_context>
<issue_to_address>
**nitpick (bug_risk):** The parser accepts fd value 0 even though the comment says standard input must be rejected; an invocation containing `--fd1 0` therefore treats stdin as the loader report pipe and writes the JSON handshake to it instead of rejecting the malformed loader arguments.
**Triggers:** When the process receives a malformed or user-supplied `--fd1 0` argument.
**Suggested fix:** Require the parsed descriptor to be a valid non-standard descriptor, for example by rejecting values less than 3 before assigning fd1 or fd2.
```suggestion
if (!ok || fd < 3)
continue;
```
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
| if (!ok) | ||
| continue; |
There was a problem hiding this comment.
nitpick (bug_risk): The parser accepts fd value 0 even though the comment says standard input must be rejected; an invocation containing --fd1 0 therefore treats stdin as the loader report pipe and writes the JSON handshake to it instead of rejecting the malformed loader arguments.
Triggers: When the process receives a malformed or user-supplied --fd1 0 argument.
Suggested fix: Require the parsed descriptor to be a valid non-standard descriptor, for example by rejecting values less than 3 before assigning fd1 or fd2.
| if (!ok) | |
| continue; | |
| if (!ok || fd < 3) | |
| continue; |
… prompt on app installation - Add initSecurityLoaderReport() in main.cpp: when started by deepin-security-loader (--fd1/--fd2 passed), report the system bus unique name and the com.deepin.lastore service list to the loader in JSON so it registers the lastore allow-caller whitelist on our behalf, making InstallPackage free of polkit authentication - Call the report before any early-exit branch (including single-instance failure), otherwise the loader times out and kills the process, which shows up as a crash on startup - Add launcher script /usr/bin/deepin-data-transfer: start the real binary /usr/libexec/deepin/deepin-data-transfer through deepin-security-loader with the deepin-daemon group when available (dbus >= 1.12.20.17-deepin1), otherwise fall back to direct launch with the historical polkit behavior - Enable Qt DBus component/linking and install the real binary to libexec/deepin with the launcher taking over /usr/bin - Update debian packaging: install the libexec binary and add Recommends: deepin-security-loader 修复(data-transfer): 经 deepin-security-loader 启动以避免安装应用时弹出 polkit 鉴权框 - main.cpp 新增 initSecurityLoaderReport():经 deepin-security-loader 启动(带 --fd1/--fd2 参数)时,将 system bus 唯一连接名和 com.deepin.lastore 服务列表以 JSON 回报给 loader,由其代为注册 lastore 的 allow-caller 白名单,使 InstallPackage 等接口免 polkit 鉴权 - 回报调用置于任何提前退出分支(含单例失败)之前,否则 loader 会超时结束子进程,表现为启动闪退 - 新增启动脚本 /usr/bin/deepin-data-transfer:环境满足(dbus >= 1.12.20.17-deepin1)时经 deepin-security-loader 附加 deepin-daemon 组启动真实二进制 /usr/libexec/deepin/deepin-data-transfer,否则回退直接启动,鉴权行为与历史一致 - 启用 Qt DBus 组件与链接,真实二进制安装至 libexec/deepin,/usr/bin 由启动脚本接管 - 更新 debian 打包:安装 libexec 二进制并增加 Recommends: deepin-security-loader Log: 数据迁移工具经 deepin-security-loader 附加 deepin-daemon 组启动并回报 bus 连接名,实现 lastore 安装接口免鉴权,修复迁移三方应用时弹出密码认证框的问题 Bug: https://pms.uniontech.com/bug-view-375325.html
c6d28a9 to
d078f85
Compare
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: pppanghu77, re2zero The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/merge |
… prompt on app installation
修复(data-transfer): 经 deepin-security-loader 启动以避免安装应用时弹出 polkit 鉴权框
Log: 数据迁移工具经 deepin-security-loader 附加 deepin-daemon 组启动并回报 bus 连接名,实现 lastore 安装接口免鉴权,修复迁移三方应用时弹出密码认证框的问题
Bug: https://pms.uniontech.com/bug-view-375325.html
Summary by Sourcery
Start data transfer via deepin-security-loader when available to enable password-free lastore application installation while preserving the historical polkit fallback.
Bug Fixes:
Enhancements:
Build: