feat(daemon): integrate deepin-security-loader trust mechanism - #258
Conversation
Add trust_client for process whitelist negotiation with deepin-security-loader, switch to RelayEventListener, and launch daemon via loader with forking service type and PID file tracking. 集成 deepin-security-loader 进程信任机制,新增 trust_client 进行 白名单协商;切换到 RelayEventListener;daemon 通过 loader 启动, service 改为 forking 模式并使用 PID 文件跟踪;日志切换到 syslog 避免 loader 关闭 stdout 后丢失;fs_event 字段统一为 path,rename 跟踪改用 unordered_map;新增 trust_client 单元测试框架。 Log: 集成 deepin-security-loader 信任机制并重构事件处理 PMS: BUG-370779 Influence: daemon 现在通过 deepin-security-loader 启动并进行进程白名单 协商,事件监听切换为中继模式,日志改用 syslog,影响 daemon 启动流程、 事件处理和日志输出方式。
Reviewer's GuideThe daemon is reworked for deepin-security-loader integration: startup now negotiates process trust over injected file descriptors, filesystem events arrive through a relay listener, event data and rename correlation are refactored, and systemd deployment/logging are updated for loader-managed forking execution with opt-in protocol tests. Sequence diagram for loader trust negotiation and daemon startupsequenceDiagram
participant Loader as deepin-security-loader
participant Daemon as deepin-anything-daemon
participant DBus as SystemBus
Loader->>Daemon: exec with --fd1 and --fd2
Daemon->>Daemon: write_pid_file()
Daemon->>DBus: g_bus_get_sync()
Daemon->>Daemon: parse_trust_fds()
Daemon->>Loader: JSON trust request via request_fd
Daemon->>Daemon: read_balanced_json()
Loader-->>Daemon: JSON response via response_fd
Daemon->>Daemon: request_dbus_trust()
alt Result is true
Daemon->>Daemon: start relay event listener
else Result is false or request fails
Daemon-->>Loader: exit APP_QUIT_CODE
end
Sequence diagram for relay event delivery and server restart handlingsequenceDiagram
participant Server as deepin-anything-server
participant Relay as RelayEventListener
participant Handler as default_event_handler
participant DBus as SystemBus
Relay->>Server: event_relay_receiver_new()
Relay->>Server: event_relay_receiver_get_fd()
Relay->>Relay: relay_event_listener_start()
Server-->>Relay: filesystem events over relay channel
Relay->>Relay: event_relay_receiver_receive()
Relay->>Handler: callback(user_data, fs_event)
Handler->>Handler: convert_fs_event()
Handler->>Handler: filter_event()
alt relay connection lost
Relay->>DBus: get_bus_name_owner()
DBus-->>Relay: current unique bus owner
Relay->>Relay: on_restart_check()
Relay-->>Handler: quit_callback(user_data)
end
Flow diagram for filesystem event conversion and rename correlationflowchart TD
A[fs_event received] --> B{Mount or unmount?}
B -- Yes --> C[mount_info_update]
B -- No --> D{Rename-from event?}
D -- Yes --> E[Store path in rename_from_ by cookie]
D -- No --> F{Rename-to event?}
F -- Yes --> G{Matching cookie found?}
G -- Yes --> H[Build source and destination paths]
G -- No --> I[Ignore unmatched rename-to event]
F -- No --> J[Build event from event.path]
H --> K[filter_event]
J --> K
K --> L{Under lower filesystem mount?}
L -- Yes --> M[Drop event]
L -- No --> N[Process filesystem event]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 3 issues
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="src/daemon/src/core/relay_event_listener.cpp" line_range="164-165" />
<code_context>
+ fs_event evt;
+ memset(&evt, 0, sizeof(evt));
+
+ EventReceiveResult result = event_relay_receiver_receive(
+ listener->receiver, &evt, sizeof(evt));
+
+ switch (result) {
</code_context>
<issue_to_address>
**issue (bug_risk):** The relay listener receives a `dispatch_event_t` wire record directly into the expanded `fs_event` structure, but the structures have different layouts: the relay payload contains action, cookie, and path, while `fs_event` inserts `seq`, `major`, and `minor` before `path`. Consequently the client reads part of the path as device metadata and reads the path from the wrong offset, so events are corrupted or discarded.
**Triggers:** When the daemon receives any event through the relay channel.
**Suggested fix:** Receive into `dispatch_event_t` and explicitly map its action, cookie, and path into `fs_event`, or make the relay wire format match `fs_event` exactly.
</issue_to_address>
### Comment 2
<location path="src/daemon/src/core/relay_event_listener.cpp" line_range="209" />
<code_context>
+ }
+
+ listener->loop = g_main_loop_new(listener->context, FALSE);
+ g_main_context_push_thread_default(listener->context);
+
+ int sock_fd = -1;
</code_context>
<issue_to_address>
**issue (bug_risk):** The return value of `g_main_loop_new` is not checked before `g_main_loop_run(listener->loop)`. If loop allocation fails, the listener still installs sources and later calls `g_main_loop_run` with a null loop, causing a crash instead of reporting startup failure.
**Triggers:** When GLib cannot allocate the listener main loop.
**Suggested fix:** Check `listener->loop` immediately after creation, signal startup failure, and clean up the context without starting the loop.
</issue_to_address>
### Comment 3
<location path="src/daemon/src/main.cpp" line_range="80-82" />
<code_context>
+ return false;
+ }
+
+ pid_file.write(QByteArray::number(QCoreApplication::applicationPid()));
+ pid_file.close();
+ spdlog::info("PID file written: {}", pid_path.toStdString());
+ return true;
+}
</code_context>
<issue_to_address>
**issue (bug_risk):** The PID file write result is ignored, so the service continues even when the PID file cannot be created or written. With `Type=forking` and `PIDFile=`, systemd then cannot reliably identify the daemon and can leave startup tracking or stop/restart behavior broken.
**Triggers:** When `$XDG_RUNTIME_DIR` is missing or the PID file cannot be opened or written.
**Suggested fix:** Treat failure to create or write the PID file as a startup error, and verify the `QFile::write` return value before proceeding.
</issue_to_address>
deepin pr auto review🤖 AI 代码审查报告📊 总体评价
🔍 详细分析1. 语法逻辑 ❌评价: 需改进 ❌ 不通过 潜在问题:
建议: 1.修复 erase 条件:将 event->act 改为 event_with_full_path->act,或在 RENAME_TO 匹配成功后立即 erase 2. 代码质量 ✅评价: 良好 ✅ 通过 潜在问题:
建议: 考虑提取公共逻辑到独立工具模块或基类中,减少重复代码维护成本 3. 代码性能 ✅评价: 良好 ✅ 通过 潜在问题:
建议: 1.read_balanced_json 使用缓冲区批量读取(如 char buf[256]),减少系统调用次数 4. 代码安全 🔒评价: 优秀 ✅ 通过
安全漏洞详情:
建议: 在 parse_trust_fds 中添加 fd 上限校验(如 fd < 0 || fd > 1024),防止异常 fd 值导致不可预期行为 💡 改进建议代码示例// 修复1: rename_from_ 映射清理 - default_event_handler.cpp
// 将 erase 条件从检查 event->act 改为检查 event_with_full_path->act
if (event_with_full_path->act == ACT_RENAME_FILE ||
event_with_full_path->act == ACT_RENAME_FOLDER) {
rename_from_.erase(event->cookie);
}
// 修复2: RENAME_TO 未匹配时处理 - default_event_handler.cpp
case ACT_RENAME_TO_FILE:
case ACT_RENAME_TO_FOLDER:
if (auto search = rename_from_.find(event->cookie);
search != rename_from_.end()) {
event_with_full_path->act = event->act == ACT_RENAME_TO_FILE
? ACT_RENAME_FILE : ACT_RENAME_FOLDER;
event_with_full_path->dst = event->path;
event_with_full_path->src = rename_from_[event->cookie];
} else {
// 未找到匹配的 RENAME_FROM,跳过此事件
spdlog::warn("RENAME_TO without matching FROM, cookie: {}", event->cookie);
return true;
}
break;
// 修复3: event_listener.cpp 使用 g_slice_new0 零初始化
fs_event *evt = g_slice_new0(fs_event); // 替代 g_slice_new本报告由 AI 代码审查工具自动生成 |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: max-lvs, wangrong1069 The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/merge |
|
This pr cannot be merged! (status: unknown) |
Add trust_client for process whitelist negotiation with deepin-security-loader, switch to RelayEventListener, and launch daemon via loader with forking service type and PID file tracking.
集成 deepin-security-loader 进程信任机制,新增 trust_client 进行 白名单协商;切换到 RelayEventListener;daemon 通过 loader 启动,
service 改为 forking 模式并使用 PID 文件跟踪;日志切换到 syslog
避免 loader 关闭 stdout 后丢失;fs_event 字段统一为 path,rename 跟踪改用 unordered_map;新增 trust_client 单元测试框架。
Log: 集成 deepin-security-loader 信任机制并重构事件处理
PMS: BUG-370779
Influence: daemon 现在通过 deepin-security-loader 启动并进行进程白名单 协商,事件监听切换为中继模式,日志改用 syslog,影响 daemon 启动流程、
事件处理和日志输出方式。
Summary by Sourcery
Integrate deepin-security-loader trust enforcement and relay-based event handling into the daemon lifecycle.
New Features:
Bug Fixes:
Enhancements:
Build:
Deployment:
Tests: