Received: by 2002:a05:6a10:1287:0:0:0:0 with SMTP id d7csp318658pxv; Thu, 22 Jul 2021 00:24:28 -0700 (PDT) X-Google-Smtp-Source: ABdhPJx/Ps6cXisfUqjauoXiRxYaZEPU338a+g2z006KTsyGPKn067z5m82BhOw8pUFvaax4H7/B X-Received: by 2002:a05:6638:1490:: with SMTP id j16mr9705377jak.27.1626938668294; Thu, 22 Jul 2021 00:24:28 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1626938668; cv=none; d=google.com; s=arc-20160816; b=CS1eb2456/gn9a0ArSsfpM3tnCHRXXTbfTq7/6IPl+GClk077cIgJZfvZfl384bg7E r1qz7UM+/mPK3wUzmFV0LvEVGH9Ar8P18srhghEVvsHWlwcEftJ4ZzcBL6DJ0gFwcuND lEdcMbwExsLJtKji+SsHeEBp/FzWWCJ6Zrmjs3Z/Bai43BVQOkaR7WryEItFKOO+qkBq ISu8JMyH/RTO0YSZQN8L8I8Tf6NOwb0uvbjRTIeoU/RfFjKJpIv8wO4TU1mfyIw+Av/R 7myqaLDG2dznHoZ7Dc6y9DEkt5cq64F0Ae+AUrxZW10IGdwZEsypHuooqjyAytHWYzpb kS3Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:from:subject:mime-version:message-id:date :dkim-signature; bh=AblpCmnKzckPdtK44G8+vJzcvH8pwpD8NBRq+/0+0ak=; b=xujdf4/DcoOxws4RKcGuAEQ6ArKvXtiyy3kCkTnmTiwekaRSO6qR+A/RoOY9hSb84G 4J1snsyv8EFcb3dF+/wD0A0cbV6CDuQ4b2lpy7O7T7WJY7bJZ8M3/5wAbb0C4r5dZvYW yVwsQsBwXEYg2limTPp/v5u/W49eUq0AohEiQ/911iqtN8HCkU92LNkIZMgFV0kdWuyC JzY3UT0/U3C/1uhZnTy+zeYCIHJHeqIiR32MfGtEAHxfMSmZ/Sb/P94DGe+ss6i7uUBM 4zCSpjHFfTRqVQWaZKpWHZ5hrRIDds9pByR81xqei7LWlbpqL1jCd5IhkqIdv/1OfDIl ryOQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b="Fv7RG/nh"; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id q21si20721598jat.69.2021.07.22.00.23.57; Thu, 22 Jul 2021 00:24:28 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b="Fv7RG/nh"; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229955AbhGVGmw (ORCPT + 99 others); Thu, 22 Jul 2021 02:42:52 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60732 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229573AbhGVGmw (ORCPT ); Thu, 22 Jul 2021 02:42:52 -0400 Received: from mail-qt1-x849.google.com (mail-qt1-x849.google.com [IPv6:2607:f8b0:4864:20::849]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 8B884C061575 for ; Thu, 22 Jul 2021 00:23:27 -0700 (PDT) Received: by mail-qt1-x849.google.com with SMTP id d9-20020ac84e290000b0290256a44e9034so2882160qtw.22 for ; Thu, 22 Jul 2021 00:23:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:message-id:mime-version:subject:from:to:cc; bh=AblpCmnKzckPdtK44G8+vJzcvH8pwpD8NBRq+/0+0ak=; b=Fv7RG/nhjzg1BKDOHp46ELeyciHTQce/32Yrdua8669BegBJgp9/rb46mRGACcHSsU /OXm5iq2ThABLNeFfufVwHj2cChs8kU18Am+GJAGeQ4lmysujKBmGbwKmBZ7/PRnhk9z 4a0ZP4W2Eopl9fHjIK0R4RETHkZhlWOYsQWs8xwVCb9GnNHyenXF7rZ02UQVMnFxxald DAfYk4Bmm+jZp2ocXTtFI57dtTMKKFfgwfov9QVsCRosT1zFtMbYzJen+5BuuLT+CqX0 jicUOoBknyRNRzvfD4q6kWYdiD4OeZ5QnmqXUm9cUurn5juGOiomBJ+1G9eW2SVgbpiA zOrA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:message-id:mime-version:subject:from:to:cc; bh=AblpCmnKzckPdtK44G8+vJzcvH8pwpD8NBRq+/0+0ak=; b=ns2Oan7zahb8VllbtHFhxFuuKodYMySIBW60t1urAS+J287AUNvW7tptL4agFnB1xo C9+Gm46fcqysdUCZSm4zzlVdD+LPjMgZ9zLCHKJRD630XJJZoZqwawYpQ8qwCZ6/xDWm kqUVYhpPqVkJF/y7z21yA1B8VD6cac09Td1+7Gw0gCtRmLUev7nal4UN+Ch+7CsKbFJ3 Z9W7JMWGDLjGh3GAl1GoOxB1swnRwFC2CG4bRTbGkUgdWjgWtgoBPIjaFc38aSZPIRAi DbYtSPFQw19M4BndrsalKClPBQMDt6j8/i4b3cMeDiiEFzuRQqWDteBDsRd+iT4vMzJD dNdQ== X-Gm-Message-State: AOAM532Mr3qRfkSGwbILb/p+8BmU+Z4YNv+1yXnfv5hBIpUO3Hrc04wN +wFq/na6Sv9iMKvLZziTWc/+LsP5BBn6R6GUHHtod8bIKgM2xdwUwJT+eIKgs/FtS59MXHdTd+V TZ96+dCkQrFil0q6iuDTnKh7No6AKJDPbu0C+eLioT79GtW/U8vkuYWlp8wkmIUfsxrNRkVjloY BEjApE3D7oYzM= X-Received: from howardchung-p920.tpe.corp.google.com ([2401:fa00:1:10:69a3:595f:8267:f7e0]) (user=howardchung job=sendgmr) by 2002:a05:6214:20ac:: with SMTP id 12mr40004808qvd.7.1626938606217; Thu, 22 Jul 2021 00:23:26 -0700 (PDT) Date: Thu, 22 Jul 2021 15:23:10 +0800 Message-Id: <20210722072321.1225119-1-howardchung@google.com> Mime-Version: 1.0 X-Mailer: git-send-email 2.32.0.402.g57bb445576-goog Subject: [Bluez PATCH v2 00/11] Hi manintainers, From: Howard Chung To: linux-bluetooth@vger.kernel.org, luiz.dentz@gmail.com Cc: Yun-Hao Chung Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org From: Yun-Hao Chung This series is to 1. Implement a few methods in core so that a plugin can have control of allowing / disallowing certain service connections. 2. Implement the AdminPolicy plugin. The plugin provides interfaces AdminPolicySet and AdminPolicyStatus. For each policy, users should set the value thorugh AdminPolicySet and query the current setting through AdminPolicyStatus. We separeted these two interfaces so that developers can assign different groups of users to these interfaces. Currently the only policy is ServiceAllowList, which make bluez only allow a list of service by specified their UUIDs, but the plugin is also expected to provide more controls over other bluez behaviors. Since the second part is a plugin, it might not be necessary to land in upstream tree. Thanks. Changes in v2: - Move bt_uuid_hash and bt_uuid_equal functions to adapter.c. - Modify the criteria to say a device is `Affected` from any-of-uuid to any-of-auto-connect-profile. - Remove the code to remove/reprobe disallowed/allowed profiles, instead, check if the service is allowed in bt_io_accept connect_cb. - Fix a typo in emit_property_change in plugin/admin_policy.c:set_service_allowlist - Instead of using device_state_cb, utilize D-BUS client to watch device added/removed. - Add a document in doc/ Yun-Hao Chung (11): core: add is_allowed property in btd_service core: add adapter and device allowed_uuid functions profiles: ignore incoming connection of not allowed service plugins: new plugin plugins/admin_policy: add admin_policy adapter driver plugins/admin_policy: add ServiceAllowList method plugins/admin_policy: add ServiceAllowList property plugins/admin_policy: listen for device add and remove plugins/admin_policy: add AffectedByPolicy property plugins/admin_policy: persist policy settings doc: add description of admin policy Makefile.plugins | 5 + Makefile.tools | 1 + bootstrap-configure | 1 + configure.ac | 4 + doc/admin-policy-api.txt | 65 ++++ plugins/admin_policy.c | 653 +++++++++++++++++++++++++++++++++++++++ profiles/audio/a2dp.c | 6 + profiles/audio/avctp.c | 7 + profiles/health/mcap.c | 10 +- profiles/input/server.c | 10 + src/adapter.c | 90 ++++++ src/adapter.h | 8 + src/device.c | 64 +++- src/device.h | 2 + src/profile.c | 12 + src/service.c | 33 ++ src/service.h | 2 + 17 files changed, 971 insertions(+), 2 deletions(-) create mode 100644 doc/admin-policy-api.txt create mode 100644 plugins/admin_policy.c -- 2.32.0.402.g57bb445576-goog