• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

systemd / systemd / 19555332179

20 Nov 2025 07:10PM UTC coverage: 72.661% (+0.1%) from 72.548%
19555332179

push

github

web-flow
apparmor: move dlopen() into mac_apparmor_use() check (#39826)

This mirrors what we do for mac_selinux_use(), which also loads
libselinux.

309032 of 425304 relevant lines covered (72.66%)

1136602.94 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

85.19
/src/basic/socket-util.h
1
/* SPDX-License-Identifier: LGPL-2.1-or-later */
2
#pragma once
3

4
#include <linux/if_ether.h>
5
#include <linux/if_infiniband.h>
6
#include <linux/if_packet.h>
7
#include <linux/netlink.h>
8
#include <linux/vm_sockets.h>
9
#include <netinet/in.h>
10
#include <sys/socket.h>
11
#include <sys/un.h>
12

13
#include "basic-forward.h"
14
#include "memory-util.h"
15
#include "missing-network.h"
16

17
union sockaddr_union {
18
        /* The minimal, abstract version */
19
        struct sockaddr sa;
20

21
        /* The libc provided version that allocates "enough room" for every protocol */
22
        struct sockaddr_storage storage;
23

24
        /* Protocol-specific implementations */
25
        struct sockaddr_in in;
26
        struct sockaddr_in6 in6;
27
        struct sockaddr_un un;
28
        struct sockaddr_nl nl;
29
        struct sockaddr_ll ll;
30
        struct sockaddr_vm vm;
31

32
        /* Ensure there is enough space to store Infiniband addresses */
33
        uint8_t ll_buffer[offsetof(struct sockaddr_ll, sll_addr) + CONST_MAX(ETH_ALEN, INFINIBAND_ALEN)];
34

35
        /* Ensure there is enough space after the AF_UNIX sun_path for one more NUL byte, just to be sure that the path
36
         * component is always followed by at least one NUL byte. */
37
        uint8_t un_buffer[sizeof(struct sockaddr_un) + 1];
38
};
39

40
#define SUN_PATH_LEN (sizeof(((struct sockaddr_un){}).sun_path))
41

42
typedef struct SocketAddress {
43
        union sockaddr_union sockaddr;
44

45
        /* We store the size here explicitly due to the weird
46
         * sockaddr_un semantics for abstract sockets */
47
        socklen_t size;
48

49
        /* Socket type, i.e. SOCK_STREAM, SOCK_DGRAM, ... */
50
        int type;
51

52
        /* Socket protocol, IPPROTO_xxx, usually 0, except for netlink */
53
        int protocol;
54
} SocketAddress;
55

56
#define socket_address_family(a) ((a)->sockaddr.sa.sa_family)
57

58
const char* socket_address_type_to_string(int t) _const_;
59
int socket_address_type_from_string(const char *s) _pure_;
60

61
int sockaddr_un_unlink(const struct sockaddr_un *sa);
62

63
static inline int socket_address_unlink(const SocketAddress *a) {
247✔
64
        return socket_address_family(a) == AF_UNIX ? sockaddr_un_unlink(&a->sockaddr.un) : 0;
247✔
65
}
66

67
bool socket_address_can_accept(const SocketAddress *a) _pure_;
68

69
int socket_address_verify(const SocketAddress *a, bool strict) _pure_;
70
int socket_address_print(const SocketAddress *a, char **p);
71
bool socket_address_matches_fd(const SocketAddress *a, int fd);
72

73
bool socket_address_equal(const SocketAddress *a, const SocketAddress *b) _pure_;
74

75
const char* socket_address_get_path(const SocketAddress *a);
76

77
bool socket_ipv6_is_supported(void);
78
bool socket_ipv6_is_enabled(void);
79

80
int sockaddr_port(const struct sockaddr *_sa, unsigned *port);
81
const union in_addr_union *sockaddr_in_addr(const struct sockaddr *sa);
82
int sockaddr_set_in_addr(union sockaddr_union *u, int family, const union in_addr_union *a, uint16_t port);
83

84
int sockaddr_pretty(const struct sockaddr *_sa, socklen_t salen, bool translate_ipv6, bool include_port, char **ret);
85
int getpeername_pretty(int fd, bool include_port, char **ret);
86
int getsockname_pretty(int fd, char **ret);
87

88
int socknameinfo_pretty(const struct sockaddr *sa, socklen_t salen, char **_ret);
89

90
int netlink_family_to_string_alloc(int b, char **s);
91
int netlink_family_from_string(const char *s) _pure_;
92

93
bool sockaddr_equal(const union sockaddr_union *a, const union sockaddr_union *b);
94

95
int fd_set_sndbuf(int fd, size_t n, bool increase);
96
static inline int fd_inc_sndbuf(int fd, size_t n) {
370,965✔
97
        return fd_set_sndbuf(fd, n, true);
370,965✔
98
}
99
int fd_set_rcvbuf(int fd, size_t n, bool increase);
100
static inline int fd_increase_rxbuf(int fd, size_t n) {
27,420✔
101
        return fd_set_rcvbuf(fd, n, true);
27,420✔
102
}
103

104
int ip_tos_to_string_alloc(int i, char **s);
105
int ip_tos_from_string(const char *s);
106

107
typedef enum {
108
        IFNAME_VALID_ALTERNATIVE = 1 << 0, /* Allow "altnames" too */
109
        IFNAME_VALID_NUMERIC     = 1 << 1, /* Allow decimal formatted ifindexes too */
110
        IFNAME_VALID_SPECIAL     = 1 << 2, /* Allow the special names "all" and "default" */
111
        _IFNAME_VALID_ALL        = IFNAME_VALID_ALTERNATIVE | IFNAME_VALID_NUMERIC | IFNAME_VALID_SPECIAL,
112
} IfnameValidFlags;
113
bool ifname_valid_char(char a) _const_;
114
bool ifname_valid_full(const char *p, IfnameValidFlags flags) _pure_;
115
static inline bool ifname_valid(const char *p) {
5,692✔
116
        return ifname_valid_full(p, 0);
5,692✔
117
}
118
bool address_label_valid(const char *p) _pure_;
119

120
int getpeercred(int fd, struct ucred *ucred);
121
int getpeersec(int fd, char **ret);
122
int getpeergroups(int fd, gid_t **ret);
123
int getpeerpidfd(int fd);
124
int getpeerpidref(int fd, PidRef *ret);
125

126
ssize_t send_many_fds_iov_sa(
127
                int transport_fd,
128
                int *fds_array, size_t n_fds_array,
129
                const struct iovec *iov, size_t iovlen,
130
                const struct sockaddr *sa, socklen_t len,
131
                int flags);
132
static inline ssize_t send_many_fds_iov(
1✔
133
                int transport_fd,
134
                int *fds_array, size_t n_fds_array,
135
                const struct iovec *iov, size_t iovlen,
136
                int flags) {
137

138
        return send_many_fds_iov_sa(transport_fd, fds_array, n_fds_array, iov, iovlen, NULL, 0, flags);
1✔
139
}
140
static inline int send_many_fds(
141
                int transport_fd,
142
                int *fds_array,
143
                size_t n_fds_array,
144
                int flags) {
145

146
        return send_many_fds_iov_sa(transport_fd, fds_array, n_fds_array, NULL, 0, NULL, 0, flags);
147
}
148
ssize_t send_one_fd_iov_sa(
149
                int transport_fd,
150
                int fd,
151
                const struct iovec *iov, size_t iovlen,
152
                const struct sockaddr *sa, socklen_t len,
153
                int flags);
154
int send_one_fd_sa(int transport_fd,
155
                   int fd,
156
                   const struct sockaddr *sa, socklen_t len,
157
                   int flags);
158
#define send_one_fd_iov(transport_fd, fd, iov, iovlen, flags) send_one_fd_iov_sa(transport_fd, fd, iov, iovlen, NULL, 0, flags)
159
#define send_one_fd(transport_fd, fd, flags) send_one_fd_iov_sa(transport_fd, fd, NULL, 0, NULL, 0, flags)
160
ssize_t receive_one_fd_iov(int transport_fd, struct iovec *iov, size_t iovlen, int flags, int *ret_fd);
161
int receive_one_fd(int transport_fd, int flags);
162
ssize_t receive_many_fds_iov(int transport_fd, struct iovec *iov, size_t iovlen, int **ret_fds_array, size_t *ret_n_fds_array, int flags);
163
int receive_many_fds(int transport_fd, int **ret_fds_array, size_t *ret_n_fds_array, int flags);
164

165
ssize_t next_datagram_size_fd(int fd);
166

167
int flush_accept(int fd);
168
ssize_t flush_mqueue(int fd);
169

170
#define CMSG_FOREACH(cmsg, mh)                                          \
171
        for ((cmsg) = CMSG_FIRSTHDR(mh); (cmsg); (cmsg) = CMSG_NXTHDR((mh), (cmsg)))
172

173
/* Returns the cmsghdr's data pointer, but safely cast to the specified type. Does two alignment checks: one
174
 * at compile time, that the requested type has a smaller or same alignment as 'struct cmsghdr', and one
175
 * during runtime, that the actual pointer matches the alignment too. This is supposed to catch cases such as
176
 * 'struct timeval' is embedded into 'struct cmsghdr' on architectures where the alignment of the former is 8
177
 * bytes (because of a 64-bit time_t), but of the latter is 4 bytes (because size_t is 32 bits), such as
178
 * riscv32. */
179
#define CMSG_TYPED_DATA(cmsg, type)                                     \
180
        ({                                                              \
181
                struct cmsghdr *_cmsg = (cmsg);                         \
182
                assert_cc(alignof(type) <= alignof(struct cmsghdr));    \
183
                _cmsg ? CAST_ALIGN_PTR(type, CMSG_DATA(_cmsg)) : (type*) NULL; \
184
        })
185

186
struct cmsghdr* cmsg_find(struct msghdr *mh, int level, int type, socklen_t length);
187
void* cmsg_find_and_copy_data(struct msghdr *mh, int level, int type, void *buf, size_t buf_len);
188

189
/* Type-safe, dereferencing version of cmsg_find() */
190
#define CMSG_FIND_DATA(mh, level, type, ctype)                          \
191
        CMSG_TYPED_DATA(cmsg_find(mh, level, type, CMSG_LEN(sizeof(ctype))), ctype)
192

193
/* Type-safe version of cmsg_find_and_copy_data() */
194
#define CMSG_FIND_AND_COPY_DATA(mh, level, type, ctype)             \
195
        (ctype*) cmsg_find_and_copy_data(mh, level, type, &(ctype){}, sizeof(ctype))
196

197
/* Resolves to a type that can carry cmsghdr structures. Make sure things are properly aligned, i.e. the type
198
 * itself is placed properly in memory and the size is also aligned to what's appropriate for "cmsghdr"
199
 * structures. */
200
#define CMSG_BUFFER_TYPE(size)                                          \
201
        union {                                                         \
202
                struct cmsghdr cmsghdr;                                 \
203
                uint8_t buf[size];                                      \
204
                uint8_t align_check[(size) >= CMSG_SPACE(0) &&          \
205
                                    (size) == CMSG_ALIGN(size) ? 1 : -1]; \
206
        }
207

208
size_t sockaddr_ll_len(const struct sockaddr_ll *sa);
209

210
size_t sockaddr_un_len(const struct sockaddr_un *sa);
211

212
size_t sockaddr_len(const union sockaddr_union *sa);
213

214
int socket_ioctl_fd(void);
215

216
int sockaddr_un_set_path(struct sockaddr_un *ret, const char *path);
217

218
static inline int setsockopt_int(int fd, int level, int optname, int value) {
1,051,768✔
219
        if (setsockopt(fd, level, optname, &value, sizeof(value)) < 0)
1,051,768✔
220
                return -errno;
68,369✔
221

222
        return 0;
223
}
224

225
int getsockopt_int(int fd, int level, int optname, int *ret);
226

227
int socket_bind_to_ifname(int fd, const char *ifname);
228
int socket_bind_to_ifindex(int fd, int ifindex);
229

230
int socket_autobind(int fd, char **ret_name);
231

232
/* glibc duplicates timespec/timeval on certain 32-bit arches, once in 32-bit and once in 64-bit.
233
 * See __convert_scm_timestamps() in glibc source code. Hence, we need additional buffer space for them
234
 * to prevent truncating control msg (recvmsg() MSG_CTRUNC). */
235
#define CMSG_SPACE_TIMEVAL                                              \
236
        (CMSG_SPACE(sizeof(struct timeval)) + CMSG_SPACE(2 * sizeof(uint64_t)))
237
#define CMSG_SPACE_TIMESPEC                                             \
238
        (CMSG_SPACE(sizeof(struct timespec)) + CMSG_SPACE(2 * sizeof(uint64_t)))
239

240
ssize_t recvmsg_safe(int sockfd, struct msghdr *msg, int flags);
241

242
int socket_get_family(int fd);
243
int socket_set_recvpktinfo(int fd, int af, bool b);
244
int socket_set_unicast_if(int fd, int af, int ifi);
245

246
int socket_set_option(int fd, int af, int opt_ipv4, int opt_ipv6, int val);
247
static inline int socket_set_recverr(int fd, int af, bool b) {
13,221✔
248
        return socket_set_option(fd, af, IP_RECVERR, IPV6_RECVERR, b);
13,221✔
249
}
250
static inline int socket_set_recvttl(int fd, int af, bool b) {
1,482✔
251
        return socket_set_option(fd, af, IP_RECVTTL, IPV6_RECVHOPLIMIT, b);
1,482✔
252
}
253
static inline int socket_set_ttl(int fd, int af, int ttl) {
1,089✔
254
        return socket_set_option(fd, af, IP_TTL, IPV6_UNICAST_HOPS, ttl);
1,089✔
255
}
256
static inline int socket_set_freebind(int fd, int af, bool b) {
6✔
257
        return socket_set_option(fd, af, IP_FREEBIND, IPV6_FREEBIND, b);
6✔
258
}
259
static inline int socket_set_transparent(int fd, int af, bool b) {
×
260
        return socket_set_option(fd, af, IP_TRANSPARENT, IPV6_TRANSPARENT, b);
×
261
}
262
static inline int socket_set_recvfragsize(int fd, int af, bool b) {
13,422✔
263
        return socket_set_option(fd, af, IP_RECVFRAGSIZE, IPV6_RECVFRAGSIZE, b);
13,422✔
264
}
265

266
int socket_get_mtu(int fd, int af, size_t *ret);
267

268
/* an initializer for struct ucred that initialized all fields to the invalid value appropriate for each */
269
#define UCRED_INVALID { .pid = 0, .uid = UID_INVALID, .gid = GID_INVALID }
270

271
int connect_unix_path(int fd, int dir_fd, const char *path);
272

273
static inline bool VSOCK_CID_IS_REGULAR(unsigned cid) {
×
274
        /* 0, 1, 2, UINT32_MAX are special, refuse those */
275
        return cid > 2 && cid < UINT32_MAX;
×
276
}
277

278
int vsock_parse_port(const char *s, unsigned *ret);
279
int vsock_parse_cid(const char *s, unsigned *ret);
280

281
/* Parses AF_UNIX and AF_VSOCK addresses. AF_INET[6] require some netlink calls, so it cannot be in
282
 * src/basic/ and is done from 'socket_local_address from src/shared/. Return -EPROTO in case of
283
 * protocol mismatch. */
284
int socket_address_parse_unix(SocketAddress *ret_address, const char *s);
285
int socket_address_parse_vsock(SocketAddress *ret_address, const char *s);
286
int socket_address_equal_unix(const char *a, const char *b);
287

288
/* libc's SOMAXCONN is defined to 128 or 4096 (at least on glibc). But actually, the value can be much
289
 * larger. In our codebase we want to set it to the max usually, since nowadays socket memory is properly
290
 * tracked by memcg, and hence we don't need to enforce extra limits here. Moreover, the kernel caps it to
291
 * /proc/sys/net/core/somaxconn anyway, thus by setting this to unbounded we just make that sysctl file
292
 * authoritative. */
293
#define SOMAXCONN_DELUXE INT_MAX
294

295
int vsock_get_local_cid(unsigned *ret);
296

297
int netlink_socket_get_multicast_groups(int fd, size_t *ret_len, uint32_t **ret_groups);
298

299
int socket_get_cookie(int fd, uint64_t *ret);
300

301
void cmsg_close_all(struct msghdr *mh);
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc