Skip to content

chore: disable direct D-Bus service execution - #54

Merged
deepin-bot[bot] merged 1 commit into
linuxdeepin:masterfrom
mhduiy:service
Jan 26, 2026
Merged

deepin-bot[bot] merged 1 commit into
linuxdeepin:masterfrom
mhduiy:service

Conversation

@mhduiy

@mhduiy mhduiy commented Jan 26, 2026 •

Copy link
Copy Markdown
Contributor

Changed the D-Bus service file to disable direct execution via deepin- service-manager.
The Exec line now points to /usr/bin/false, ensuring the service can only be started via its systemd unit.
This change centralizes service management through systemd, improving consistency and control over the service lifecycle.

Influence:

  1. Verify the org.deepin.dde.XSettings1 D-Bus service is not directly executable
  2. Confirm the service starts correctly via its systemd service unit (org.deepin.dde.XSettings1.service)
  3. Ensure D-Bus activation still works through systemd integration
  4. Test that applications relying on this D-Bus interface continue to function normally

chore: 禁用直接 D-Bus 服务执行

修改了 D-Bus 服务文件,禁止通过 deepin-service-manager 直接执行。
现在 Exec 行指向 /usr/bin/false,确保该服务只能通过其 systemd 单元启动。 此更改通过 systemd 集中管理服务,提高了服务生命周期管理的一致性和控
制力。

Influence:

  1. 验证 org.deepin.dde.XSettings1 D-Bus 服务无法直接执行
  2. 确认服务能通过其 systemd 服务单元 (org.deepin.dde.XSettings1.service) 正确启动
  3. 确保通过 systemd 集成的 D-Bus 激活仍然有效
  4. 测试依赖此 D-Bus 接口的应用程序是否继续正常运行

Summary by Sourcery

Enhancements:

  • Disable direct execution of the org.deepin.dde.XSettings1 D-Bus service so it can only be started via its systemd service unit.

Changed the D-Bus service file to disable direct execution via deepin-
service-manager.
The Exec line now points to /usr/bin/false, ensuring the service can
only be started via its systemd unit.
This change centralizes service management through systemd, improving
consistency and control over the service lifecycle.

Influence:
1. Verify the org.deepin.dde.XSettings1 D-Bus service is not directly
executable
2. Confirm the service starts correctly via its systemd service unit
(org.deepin.dde.XSettings1.service)
3. Ensure D-Bus activation still works through systemd integration
4. Test that applications relying on this D-Bus interface continue to
function normally

chore: 禁用直接 D-Bus 服务执行

修改了 D-Bus 服务文件,禁止通过 deepin-service-manager 直接执行。
现在 Exec 行指向 /usr/bin/false,确保该服务只能通过其 systemd 单元启动。
此更改通过 systemd 集中管理服务,提高了服务生命周期管理的一致性和控
制力。

Influence:
1. 验证 org.deepin.dde.XSettings1 D-Bus 服务无法直接执行
2. 确认服务能通过其 systemd 服务单元 (org.deepin.dde.XSettings1.service)
正确启动
3. 确保通过 systemd 集成的 D-Bus 激活仍然有效
4. 测试依赖此 D-Bus 接口的应用程序是否继续正常运行
@sourcery-ai

sourcery-ai Bot commented Jan 26, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This PR modifies the org.deepin.dde.XSettings1 D-Bus service file so the service can no longer be launched directly and must instead be managed and activated via its systemd unit, centralizing lifecycle control in systemd.

File-Level Changes

Change Details Files
Prevent direct execution of the org.deepin.dde.XSettings1 D-Bus service and enforce startup via systemd unit.
  • Update the D-Bus service Exec directive to point to /usr/bin/false so deepin-service-manager cannot start the service directly
  • Rely on the corresponding systemd unit (org.deepin.dde.XSettings1.service) for D-Bus activation and service lifecycle management
src/plugin-qt/xsettings/misc/dbus/org.deepin.dde.XSettings1.service

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@deepin-ci-robot

Copy link
Copy Markdown

deepin pr auto review

这段代码是一个 D-Bus 服务配置文件(.service 文件)的修改。这个文件通常位于 /usr/share/dbus-1/system-services/ 或类似路径下,用于告诉 D-Bus 守护进程当收到特定名称的请求时,应该启动哪个可执行文件。

以下是对该 diff 的详细审查和改进意见:

1. 语法逻辑审查

  • 变更内容:将 Exec 指令从启动 deepin-service-manager 修改为 /usr/bin/false。
  • 逻辑分析:
    • /usr/bin/false 是一个系统命令,它不执行任何操作并立即返回退出码 1(表示失败)。
    • 在 D-Bus 服务配置中,如果 Exec 指定的命令立即退出并返回失败,D-Bus 守护进程会认为该服务无法启动,从而拒绝该服务名的激活请求。
    • 结论:从逻辑上讲,这个修改的目的是禁用该 D-Bus 服务的自动激活。语法本身是正确的,符合 D-Bus 配置文件的格式要求。

2. 代码质量

  • 意图明确性:虽然 /usr/bin/false 能达到禁用服务的目的,但其可读性不如注释或明确的禁用机制。对于不熟悉 D-Bus 行为或 Unix 命令的开发者来说,直接看到 false 可能会感到困惑(是写错了?还是故意为之?)。
  • 建议:
    • 如果这是临时禁用,建议在文件中添加注释说明原因。
    • 如果是永久移除该服务,更好的做法通常是直接删除此服务文件,或者通过包管理系统移除,而不是留一个指向 false 的“僵尸”配置。

3. 代码性能

  • 影响:当有客户端尝试请求 org.deepin.dde.XSettings1 服务时,D-Bus 会尝试 fork 并执行 /usr/bin/false。这会消耗极少的系统资源(一次进程创建和退化的开销)。
  • 评价:性能影响微乎其微,可以忽略不计。

4. 代码安全

  • 安全性:将 Exec 指向 /usr/bin/false 是安全的。它防止了潜在的 deepin-service-manager 漏洞被利用(如果该管理器存在漏洞且该服务不应被外部触发的话)。它确保了没有任何实际的服务代码被运行。
  • 潜在风险:
    • 如果系统中有其他组件强依赖于该 D-Bus 服务能够自动启动并正常工作,那么这个修改会导致那些组件功能失效(例如无法获取设置,日志中报错等)。
    • 需要确认修改后的行为是否符合系统架构设计的预期(即该服务是否确实不再需要通过 D-Bus 激活)。

总结与改进建议

这个修改的核心意图是禁用 org.deepin.dde.XSettings1 的 D-Bus 自动激活功能。

改进建议:

  1. 增加注释(推荐):为了提高代码可维护性,建议在文件中添加注释,解释为什么将其指向 false。

    [D-BUS Service]
    Name=org.deepin.dde.XSettings1
    + # Disabled: Service activation is handled differently or no longer needed.
    - Exec=/usr/bin/deepin-service-manager -n org.deepin.dde.XSettings1
    + Exec=/usr/bin/false
    SystemdService=org.deepin.dde.XSettings1.service
  2. 检查 Systemd 集成:注意文件中保留了 SystemdService=org.deepin.dde.XSettings1.service。

    • 这意味着虽然 D-Bus 自己不会启动成功(因为 Exec 返回 false),但如果 systemd 单元文件存在且被启用,D-Bus 可能会尝试通过 systemd 的总线激活机制来拉起服务。
    • 如果目标是彻底禁用:请确保对应的 systemd 单元文件(/usr/lib/systemd/system/org.deepin.dde.XSettings1.service)也被禁用或修改,否则 D-Bus 的行为可能会变得复杂(取决于 D-Bus 的版本和配置,它可能会回退到 systemd 激活,或者直接报错)。
    • 如果 systemd 单元文件中的 ExecStart 也是有效的,那么仅仅修改 D-Bus 的 .service 文件可能无法完全阻止服务运行。
  3. 替代方案:如果目标是彻底移除,直接删除该文件通常比将其指向 false 更干净,前提是包管理器允许这样做且不会在更新时被覆盖。

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: 18202781743, caixr23, mhduiy

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@mhduiy

mhduiy commented Jan 26, 2026

Copy link
Copy Markdown
Contributor Author

/forcemerge

@deepin-bot

deepin-bot Bot commented Jan 26, 2026

Copy link
Copy Markdown

This pr force merged! (status: blocked)

@deepin-bot
deepin-bot Bot merged commit 72a6cbf into linuxdeepin:master Jan 26, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants