Skip to content

fix(data-transfer): launch via deepin-security-loader to avoid polkit… - #784

Merged
deepin-bot[bot] merged 1 commit into
linuxdeepin:release/v20from
pppanghu77:release/v20
Sep 1, 2026
Merged

deepin-bot[bot] merged 1 commit into
linuxdeepin:release/v20from
pppanghu77:release/v20

Conversation

@pppanghu77

@pppanghu77 pppanghu77 commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

… prompt on app installation

  • Add initSecurityLoaderReport() in main.cpp: when started by deepin-security-loader (--fd1/--fd2 passed), report the system bus unique name and the com.deepin.lastore service list to the loader in JSON so it registers the lastore allow-caller whitelist on our behalf, making InstallPackage free of polkit authentication
  • Call the report before any early-exit branch (including single-instance failure), otherwise the loader times out and kills the process, which shows up as a crash on startup
  • Add launcher script /usr/bin/deepin-data-transfer: start the real binary /usr/libexec/deepin/deepin-data-transfer through deepin-security-loader with the deepin-daemon group when available (dbus >= 1.12.20.17-deepin1), otherwise fall back to direct launch with the historical polkit behavior
  • Enable Qt DBus component/linking and install the real binary to libexec/deepin with the launcher taking over /usr/bin
  • Update debian packaging: install the libexec binary and add Recommends: deepin-security-loader

修复(data-transfer): 经 deepin-security-loader 启动以避免安装应用时弹出 polkit 鉴权框

  • main.cpp 新增 initSecurityLoaderReport():经 deepin-security-loader 启动(带 --fd1/--fd2 参数)时,将 system bus 唯一连接名和 com.deepin.lastore 服务列表以 JSON 回报给 loader,由其代为注册 lastore 的 allow-caller 白名单,使 InstallPackage 等接口免 polkit 鉴权
  • 回报调用置于任何提前退出分支(含单例失败)之前,否则 loader 会超时结束子进程,表现为启动闪退
  • 新增启动脚本 /usr/bin/deepin-data-transfer:环境满足(dbus >= 1.12.20.17-deepin1)时经 deepin-security-loader 附加 deepin-daemon 组启动真实二进制 /usr/libexec/deepin/deepin-data-transfer,否则回退直接启动,鉴权行为与历史一致
  • 启用 Qt DBus 组件与链接,真实二进制安装至 libexec/deepin,/usr/bin 由启动脚本接管
  • 更新 debian 打包:安装 libexec 二进制并增加 Recommends: deepin-security-loader

Log: 数据迁移工具经 deepin-security-loader 附加 deepin-daemon 组启动并回报 bus 连接名,实现 lastore 安装接口免鉴权,修复迁移三方应用时弹出密码认证框的问题
Bug: https://pms.uniontech.com/bug-view-375325.html

Summary by Sourcery

Start data transfer via deepin-security-loader when available to enable password-free lastore application installation while preserving the historical polkit fallback.

Bug Fixes:

  • Launch data transfer through deepin-security-loader when supported so lastore installation operations no longer trigger polkit authentication prompts.
  • Report the data transfer process identity to deepin-security-loader before startup exit paths, preventing loader timeouts and apparent startup crashes.

Enhancements:

  • Separate the Linux launcher from the application binary, placing the binary in libexec and retaining direct-launch fallback on unsupported systems.
  • Add Qt DBus support for registering the loader communication and lastore service access.

Build:

  • Update packaging to install the libexec binary and launcher, and recommend deepin-security-loader.

@sourcery-ai

sourcery-ai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Reviewer's Guide

The PR changes Linux startup to use deepin-security-loader when supported, reports the process D-Bus identity so lastore can register its allow-caller whitelist without polkit prompts, and retains direct-launch compatibility through a packaged /usr/bin launcher and updated Qt DBus/debian packaging.

Sequence diagram for security-loader startup and lastore authorization

sequenceDiagram
    participant Launcher as deepin-data-transfer
    participant Loader as deepin-security-loader
    participant App as data-transfer
    participant Bus as D-Bus system bus
    participant Lastore as com.deepin.lastore

    Launcher->>Loader: exec --group deepin-daemon REAL_BIN
    Loader->>App: start with --fd1 and --fd2
    App->>Bus: QDBusConnection::systemBus().baseService()
    Bus-->>App: UniqueName
    App->>Loader: initSecurityLoaderReport JSON
    Loader->>Lastore: SetAllowCaller whitelist registration
    Lastore-->>Loader: Result
    Loader-->>App: JSON result
    App->>Lastore: InstallPackage
    Lastore-->>App: installation without polkit prompt
Loading

Flow diagram for Linux data-transfer launch fallback

flowchart TD
    Start(["Start deepin-data-transfer"]) --> LoaderCheck{"security-loader executable?"}
    LoaderCheck -->|No| Direct["exec real binary directly"]
    LoaderCheck -->|Yes| DbusVersion["Read installed dbus version"]
    DbusVersion --> VersionCheck{"Version >= 1.12.20.17-deepin1?"}
    VersionCheck -->|No| Direct
    VersionCheck -->|Yes| Secure["exec security-loader with deepin-daemon group"]
    Secure --> RealBin["/usr/libexec/deepin/deepin-data-transfer"]
    Direct --> RealBin
Loading

File-Level Changes

Change Details Files
Reports the application's D-Bus identity to deepin-security-loader before normal startup can exit.
  • Detects loader-provided --fd1/--fd2 descriptors on Linux.
  • Builds and writes the system-bus unique name plus the com.deepin.lastore allow-caller destination as compact JSON.
  • Optionally polls the result pipe and logs registration status.
  • Runs the report before single-instance checks and other early-exit paths.
src/apps/data-transfer/main.cpp
Routes Linux launches through a security-loader when the required runtime support is available, while preserving a direct-launch fallback.
  • Adds a launcher that checks loader availability and the minimum dbus package version.
  • Starts the real executable through deepin-security-loader with the deepin-daemon group when supported.
  • Falls back to the historical direct executable invocation otherwise.
src/apps/data-transfer/res/linux/deepin-data-transfer.sh
Separates the Linux executable from its public launcher and enables the D-Bus dependencies required by the new startup protocol.
  • Links the Qt DBus component on Linux.
  • Installs the real binary under libexec/deepin and the launcher under /usr/bin.
  • Keeps Windows installation behavior unchanged.
src/apps/data-transfer/CMakeLists.txt
Updates Debian packaging for the new executable layout and optional loader integration.
  • Installs the libexec binary.
  • Adds deepin-security-loader as a recommended package.
debian/deepin-data-transfer.install
debian/control

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="src/apps/data-transfer/main.cpp" line_range="49-50" />
<code_context>
+        if (args.at(i) != QLatin1String("--fd1") && args.at(i) != QLatin1String("--fd2"))
+            continue;
+        // toInt() 解析失败会返回 0(即 stdin),必须校验,避免误把标准输入当作管道 fd
+        bool ok = false;
+        const int fd = args.at(i + 1).toInt(&ok);
+        if (!ok)
+            continue;
+        if (args.at(i) == QLatin1String("--fd1"))
+            fd1 = fd;
</code_context>
<issue_to_address>
**nitpick (bug_risk):** The parser accepts fd value 0 even though the comment says standard input must be rejected; an invocation containing `--fd1 0` therefore treats stdin as the loader report pipe and writes the JSON handshake to it instead of rejecting the malformed loader arguments.

**Triggers:** When the process receives a malformed or user-supplied `--fd1 0` argument.

**Suggested fix:** Require the parsed descriptor to be a valid non-standard descriptor, for example by rejecting values less than 3 before assigning fd1 or fd2.

```suggestion
        if (!ok || fd < 3)
            continue;
```
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Comment on lines +49 to +50
if (!ok)
continue;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nitpick (bug_risk): The parser accepts fd value 0 even though the comment says standard input must be rejected; an invocation containing --fd1 0 therefore treats stdin as the loader report pipe and writes the JSON handshake to it instead of rejecting the malformed loader arguments.

Triggers: When the process receives a malformed or user-supplied --fd1 0 argument.

Suggested fix: Require the parsed descriptor to be a valid non-standard descriptor, for example by rejecting values less than 3 before assigning fd1 or fd2.

Suggested change
if (!ok)
continue;
if (!ok || fd < 3)
continue;

… prompt on app installation

- Add initSecurityLoaderReport() in main.cpp: when started by deepin-security-loader (--fd1/--fd2 passed), report the system bus unique name and the com.deepin.lastore service list to the loader in JSON so it registers the lastore allow-caller whitelist on our behalf, making InstallPackage free of polkit authentication
- Call the report before any early-exit branch (including single-instance failure), otherwise the loader times out and kills the process, which shows up as a crash on startup
- Add launcher script /usr/bin/deepin-data-transfer: start the real binary /usr/libexec/deepin/deepin-data-transfer through deepin-security-loader with the deepin-daemon group when available (dbus >= 1.12.20.17-deepin1), otherwise fall back to direct launch with the historical polkit behavior
- Enable Qt DBus component/linking and install the real binary to libexec/deepin with the launcher taking over /usr/bin
- Update debian packaging: install the libexec binary and add Recommends: deepin-security-loader

修复(data-transfer): 经 deepin-security-loader 启动以避免安装应用时弹出 polkit 鉴权框

- main.cpp 新增 initSecurityLoaderReport():经 deepin-security-loader 启动(带 --fd1/--fd2 参数)时,将 system bus 唯一连接名和 com.deepin.lastore 服务列表以 JSON 回报给 loader,由其代为注册 lastore 的 allow-caller 白名单,使 InstallPackage 等接口免 polkit 鉴权
- 回报调用置于任何提前退出分支(含单例失败)之前,否则 loader 会超时结束子进程,表现为启动闪退
- 新增启动脚本 /usr/bin/deepin-data-transfer:环境满足(dbus >= 1.12.20.17-deepin1)时经 deepin-security-loader 附加 deepin-daemon 组启动真实二进制 /usr/libexec/deepin/deepin-data-transfer,否则回退直接启动,鉴权行为与历史一致
- 启用 Qt DBus 组件与链接,真实二进制安装至 libexec/deepin,/usr/bin 由启动脚本接管
- 更新 debian 打包:安装 libexec 二进制并增加 Recommends: deepin-security-loader

Log: 数据迁移工具经 deepin-security-loader 附加 deepin-daemon 组启动并回报 bus 连接名,实现 lastore 安装接口免鉴权,修复迁移三方应用时弹出密码认证框的问题
Bug: https://pms.uniontech.com/bug-view-375325.html
@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: pppanghu77, re2zero

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@pppanghu77

Copy link
Copy Markdown
Contributor Author

/merge

@deepin-bot
deepin-bot Bot merged commit a9a4af5 into linuxdeepin:release/v20 Sep 1, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants