feat: use privileged sockets
This commit is contained in:
parent
6d0826f319
commit
fd2dc23fac
6 changed files with 186 additions and 42 deletions
|
|
@ -2,11 +2,14 @@ use color_eyre::eyre::Context;
|
|||
use color_eyre::Result;
|
||||
use launch_pad::process::Process;
|
||||
use launch_pad::ProcessKey;
|
||||
use std::os::fd::{OwnedFd, RawFd};
|
||||
use std::os::fd::{IntoRawFd, OwnedFd, RawFd};
|
||||
use std::os::unix::net::UnixStream;
|
||||
use std::sync::{Arc, Mutex};
|
||||
use tokio::sync::mpsc;
|
||||
use tracing::Instrument;
|
||||
|
||||
use crate::comp::create_privileged_socket;
|
||||
|
||||
pub fn create_socket() -> Result<(OwnedFd, OwnedFd)> {
|
||||
// Create a new pair of unnamed Unix sockets
|
||||
let (sock_1, sock_2) = UnixStream::pair().wrap_err("failed to create socket pair")?;
|
||||
|
|
@ -28,20 +31,28 @@ pub fn notifications_process(
|
|||
span: tracing::Span,
|
||||
cmd: &'static str,
|
||||
key: Arc<Mutex<Option<ProcessKey>>>,
|
||||
env_vars: Vec<(String, String)>,
|
||||
mut env_vars: Vec<(String, String)>,
|
||||
fd: RawFd,
|
||||
restart_span: tracing::Span,
|
||||
restart_cmd: &'static str,
|
||||
restart_key: Arc<Mutex<Option<ProcessKey>>>,
|
||||
restart_env_vars: Vec<(String, String)>,
|
||||
restart_fd: RawFd,
|
||||
socket_tx: mpsc::UnboundedSender<Vec<tokio::net::UnixStream>>,
|
||||
) -> Process {
|
||||
env_vars.retain(|v| &v.0 != "WAYLAND_SOCKET");
|
||||
|
||||
let stdout_span = span.clone();
|
||||
let stderr_span = span.clone();
|
||||
let mut sockets = Vec::with_capacity(1);
|
||||
let (env_vars, privileged_fd) = create_privileged_socket(&mut sockets, &env_vars).unwrap();
|
||||
_ = socket_tx.send(sockets);
|
||||
let env_clone = env_vars.clone();
|
||||
let socket_tx_clone = socket_tx.clone();
|
||||
let privileged_fd = privileged_fd.into_raw_fd();
|
||||
Process::new()
|
||||
.with_executable(cmd)
|
||||
.with_fds(move || vec![fd])
|
||||
.with_fds(move || vec![privileged_fd, fd])
|
||||
.with_on_stdout(move |_, _, line| {
|
||||
let stdout_span = stdout_span.clone();
|
||||
async move {
|
||||
|
|
@ -56,7 +67,7 @@ pub fn notifications_process(
|
|||
}
|
||||
.instrument(stderr_span)
|
||||
})
|
||||
.with_on_exit(move |pman, _, _, will_restart| {
|
||||
.with_on_exit(move |pman, my_key, _, will_restart| {
|
||||
// force restart of notifications / panel when the other exits
|
||||
let new_process = notifications_process(
|
||||
restart_span.clone(),
|
||||
|
|
@ -69,13 +80,37 @@ pub fn notifications_process(
|
|||
key.clone(),
|
||||
env_clone.clone(),
|
||||
fd,
|
||||
socket_tx_clone.clone(),
|
||||
);
|
||||
let restart_key = restart_key.clone();
|
||||
let socket_tx_clone = socket_tx_clone.clone();
|
||||
|
||||
let env_clone = env_clone.clone();
|
||||
let mut pman_clone = pman.clone();
|
||||
async move {
|
||||
if will_restart {
|
||||
let mut sockets = Vec::with_capacity(1);
|
||||
let (env_vars, new_fd) =
|
||||
create_privileged_socket(&mut sockets, &env_clone).unwrap();
|
||||
|
||||
let new_fd = new_fd.into_raw_fd();
|
||||
|
||||
if let Err(why) = socket_tx_clone.send(sockets) {
|
||||
error!(?why, "Failed to send the privileged socket");
|
||||
}
|
||||
if let Err(why) = pman_clone.update_process_env(&my_key, env_vars).await {
|
||||
error!(?why, "Failed to update environment variables");
|
||||
}
|
||||
if let Err(why) = pman_clone
|
||||
.update_process_fds(&my_key, move || vec![new_fd, fd])
|
||||
.await
|
||||
{
|
||||
error!(?why, "Failed to update fds");
|
||||
}
|
||||
|
||||
let Some(old) = restart_key.lock().unwrap().clone() else {
|
||||
error!("Couldn't stop previous invocation of {}", cmd);
|
||||
return;
|
||||
error!("Couldn't stop previous invocation of {}", cmd);
|
||||
return;
|
||||
};
|
||||
_ = pman.stop_process(old).await;
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue