17056
|
1 |
/jds/bin/diff -uprN nautilus-2.26.3.old/libnautilus-private/Makefile.am nautilus-2.26.3/libnautilus-private/Makefile.am
|
|
2 |
--- nautilus-2.26.3.old/libnautilus-private/Makefile.am 2009-04-20 11:57:19.000000000 +0100
|
|
3 |
+++ nautilus-2.26.3/libnautilus-private/Makefile.am 2009-07-13 11:41:43.040463000 +0100
|
|
4 |
@@ -124,6 +124,8 @@ libnautilus_private_la_SOURCES = \
|
|
5 |
nautilus-lib-self-check-functions.h \
|
9060
|
6 |
nautilus-link.c \
|
|
7 |
nautilus-link.h \
|
|
8 |
+ nautilus-lockdown.c \
|
|
9 |
+ nautilus-lockdown.h \
|
|
10 |
nautilus-marshal.c \
|
|
11 |
nautilus-marshal.h \
|
|
12 |
nautilus-merged-directory.c \
|
17056
|
13 |
/jds/bin/diff -uprN nautilus-2.26.3.old/libnautilus-private/nautilus-directory-async.c nautilus-2.26.3/libnautilus-private/nautilus-directory-async.c
|
|
14 |
--- nautilus-2.26.3.old/libnautilus-private/nautilus-directory-async.c 2009-05-13 12:30:32.000000000 +0100
|
|
15 |
+++ nautilus-2.26.3/libnautilus-private/nautilus-directory-async.c 2009-07-13 11:41:43.043014000 +0100
|
|
16 |
@@ -856,6 +857,10 @@ should_skip_file (NautilusDirectory *dir
|
9060
|
17 |
return TRUE;
|
|
18 |
}
|
|
19 |
|
17056
|
20 |
+ if (nautilus_lockdown_is_forbidden_file(directory, info)) {
|
|
21 |
+ return TRUE;
|
|
22 |
+ }
|
|
23 |
+
|
9060
|
24 |
return FALSE;
|
|
25 |
}
|
17056
|
26 |
|
|
27 |
/jds/bin/diff -uprN nautilus-2.26.3.old/libnautilus-private/nautilus-directory.c nautilus-2.26.3/libnautilus-private/nautilus-directory.c
|
|
28 |
--- nautilus-2.26.3.old/libnautilus-private/nautilus-directory.c 2009-04-20 11:57:19.000000000 +0100
|
|
29 |
+++ nautilus-2.26.3/libnautilus-private/nautilus-directory.c 2009-07-13 11:41:43.045220000 +0100
|
|
30 |
@@ -342,6 +342,7 @@ add_preferences_callbacks (void)
|
9060
|
31 |
eel_preferences_add_callback (NAUTILUS_PREFERENCES_SHOW_BACKUP_FILES,
|
|
32 |
filtering_changed_callback,
|
|
33 |
NULL);
|
|
34 |
+ nautilus_lockdown_notify_add(filtering_changed_callback, NULL) ;
|
|
35 |
eel_preferences_add_callback (NAUTILUS_PREFERENCES_SHOW_TEXT_IN_ICONS,
|
|
36 |
async_data_preference_changed_callback,
|
|
37 |
NULL);
|
17056
|
38 |
/jds/bin/diff -uprN nautilus-2.26.3.old/libnautilus-private/nautilus-file.c nautilus-2.26.3/libnautilus-private/nautilus-file.c
|
|
39 |
--- nautilus-2.26.3.old/libnautilus-private/nautilus-file.c 2009-07-13 11:38:13.506664000 +0100
|
|
40 |
+++ nautilus-2.26.3/libnautilus-private/nautilus-file.c 2009-07-13 11:41:43.048782000 +0100
|
|
41 |
@@ -47,6 +47,7 @@
|
9060
|
42 |
#include "nautilus-users-groups-cache.h"
|
|
43 |
#include "nautilus-vfs-file.h"
|
|
44 |
#include "nautilus-saved-search-file.h"
|
|
45 |
+#include "nautilus-lockdown.h"
|
|
46 |
#include <eel/eel-debug.h>
|
|
47 |
#include <eel/eel-glib-extensions.h>
|
|
48 |
#include <eel/eel-gtk-extensions.h>
|
17056
|
49 |
@@ -2814,7 +2815,8 @@ nautilus_file_should_show (NautilusFile
|
|
50 |
return TRUE;
|
|
51 |
} else {
|
|
52 |
return (show_hidden || (!nautilus_file_is_hidden_file (file) && !is_file_hidden (file))) &&
|
|
53 |
- (show_backup || !nautilus_file_is_backup_file (file)) &&
|
|
54 |
+ (show_backup || !nautilus_file_is_backup_file (file) &&
|
|
55 |
+ !nautilus_lockdown_is_forbidden_nautilus_file(file)) &&
|
|
56 |
(show_foreign || !(nautilus_file_is_in_desktop (file) && nautilus_file_is_foreign_link (file)));
|
|
57 |
}
|
9060
|
58 |
}
|
17056
|
59 |
/jds/bin/diff -uprN nautilus-2.26.3.old/libnautilus-private/nautilus-lockdown.c nautilus-2.26.3/libnautilus-private/nautilus-lockdown.c
|
|
60 |
--- nautilus-2.26.3.old/libnautilus-private/nautilus-lockdown.c 1970-01-01 01:00:00.000000000 +0100
|
|
61 |
+++ nautilus-2.26.3/libnautilus-private/nautilus-lockdown.c 2009-07-13 11:41:43.050482000 +0100
|
|
62 |
@@ -0,0 +1,332 @@
|
9060
|
63 |
+/* -*- Mode: C; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 8 -*- */
|
|
64 |
+/*
|
|
65 |
+ * Copyright (C) 2004 Sun Microsystems, Inc.
|
|
66 |
+ *
|
|
67 |
+ * This program is free software; you can redistribute it and/or
|
|
68 |
+ * modify it under the terms of the GNU General Public License as
|
|
69 |
+ * published by the Free Software Foundation; either version 2 of the
|
|
70 |
+ * License, or (at your option) any later version.
|
|
71 |
+ *
|
|
72 |
+ * This program is distributed in the hope that it will be useful, but
|
|
73 |
+ * WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
74 |
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
75 |
+ * General Public License for more details.
|
|
76 |
+ *
|
|
77 |
+ * You should have received a copy of the GNU General Public License
|
|
78 |
+ * along with this program; if not, write to the Free Software
|
|
79 |
+ * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
|
|
80 |
+ * 02111-1307, USA.
|
|
81 |
+ *
|
|
82 |
+ * Authors:
|
|
83 |
+ * Matt Keenan <[email protected]>
|
|
84 |
+ * Mark McLoughlin <[email protected]>
|
|
85 |
+ */
|
|
86 |
+
|
|
87 |
+#include <config.h>
|
|
88 |
+
|
|
89 |
+#include "nautilus-lockdown.h"
|
|
90 |
+#include "nautilus-global-preferences.h"
|
|
91 |
+#include "nautilus-program-choosing.h"
|
|
92 |
+#include <eel/eel-preferences.h>
|
17056
|
93 |
+#include <eel/eel-string.h>
|
9060
|
94 |
+#include <libgnome/gnome-desktop-item.h>
|
|
95 |
+
|
|
96 |
+#include <string.h>
|
|
97 |
+
|
|
98 |
+#define N_LISTENERS 3
|
|
99 |
+
|
|
100 |
+typedef struct {
|
|
101 |
+ guint initialized : 1;
|
|
102 |
+ guint disable_command_line : 1;
|
|
103 |
+ guint restrict_application_launching : 1;
|
|
104 |
+
|
17056
|
105 |
+ char** allowed_applications;
|
9060
|
106 |
+
|
|
107 |
+ guint listeners [N_LISTENERS];
|
|
108 |
+
|
|
109 |
+ GSList *closures;
|
|
110 |
+} NautilusLockdown ;
|
|
111 |
+
|
|
112 |
+const gchar *command_line_execs[] = {
|
|
113 |
+ "/usr/bin/gnome-terminal",
|
|
114 |
+ "/usr/bin/xterm",
|
|
115 |
+};
|
|
116 |
+#define NUMBER_COMMAND_LINE_EXECS 2
|
|
117 |
+
|
|
118 |
+static NautilusLockdown nautilus_lockdown = { 0, };
|
|
119 |
+
|
|
120 |
+
|
|
121 |
+static inline void
|
|
122 |
+nautilus_lockdown_invoke_closures (NautilusLockdown *lockdown)
|
|
123 |
+{
|
|
124 |
+ GSList *l;
|
|
125 |
+
|
|
126 |
+ for (l = lockdown->closures; l; l = l->next)
|
|
127 |
+ g_closure_invoke (l->data, NULL, 0, NULL, NULL);
|
|
128 |
+}
|
|
129 |
+
|
|
130 |
+static void
|
|
131 |
+disable_command_line_notify (NautilusLockdown *lockdown)
|
|
132 |
+{
|
|
133 |
+ lockdown->disable_command_line =
|
|
134 |
+ eel_preferences_get_boolean(
|
|
135 |
+ NAUTILUS_PREFERENCES_DISABLE_COMMANDLINE) ;
|
|
136 |
+ nautilus_lockdown_invoke_closures (lockdown);
|
|
137 |
+}
|
|
138 |
+
|
|
139 |
+static void
|
|
140 |
+restrict_application_launching_notify (NautilusLockdown *lockdown)
|
|
141 |
+{
|
|
142 |
+ lockdown->restrict_application_launching =
|
|
143 |
+ eel_preferences_get_boolean (
|
|
144 |
+ NAUTILUS_PREFERENCES_RESTRICT_APP_LAUNCHING);
|
|
145 |
+ nautilus_lockdown_invoke_closures (lockdown);
|
|
146 |
+}
|
|
147 |
+
|
|
148 |
+static void
|
|
149 |
+allowed_applications_notify (NautilusLockdown *lockdown)
|
|
150 |
+{
|
17056
|
151 |
+ g_strfreev(lockdown->allowed_applications) ;
|
9060
|
152 |
+ lockdown->allowed_applications =
|
17056
|
153 |
+ eel_preferences_get_string_array(
|
9060
|
154 |
+ NAUTILUS_PREFERENCES_ALLOWED_APPLICATIONS) ;
|
|
155 |
+ nautilus_lockdown_invoke_closures (lockdown);
|
|
156 |
+}
|
|
157 |
+
|
|
158 |
+static gboolean
|
|
159 |
+nautilus_lockdown_load_bool (NautilusLockdown *lockdown,
|
|
160 |
+ const char *key,
|
|
161 |
+ EelPreferencesCallback notify_func)
|
|
162 |
+{
|
|
163 |
+ gboolean retval = eel_preferences_get_boolean (key);
|
|
164 |
+
|
|
165 |
+ eel_preferences_add_callback(key, notify_func, lockdown) ;
|
|
166 |
+ return retval;
|
|
167 |
+}
|
|
168 |
+
|
17056
|
169 |
+static char**
|
9060
|
170 |
+nautilus_lockdown_load_allowed_applications (NautilusLockdown *lockdown)
|
|
171 |
+{
|
17056
|
172 |
+ char **retval;
|
9060
|
173 |
+
|
17056
|
174 |
+ retval = eel_preferences_get_string_array(
|
9060
|
175 |
+ NAUTILUS_PREFERENCES_ALLOWED_APPLICATIONS) ;
|
|
176 |
+ eel_preferences_add_callback(NAUTILUS_PREFERENCES_ALLOWED_APPLICATIONS,
|
|
177 |
+ allowed_applications_notify, lockdown) ;
|
|
178 |
+ return retval;
|
|
179 |
+}
|
|
180 |
+
|
|
181 |
+void
|
|
182 |
+nautilus_lockdown_init (void)
|
|
183 |
+{
|
|
184 |
+ nautilus_lockdown.disable_command_line =
|
|
185 |
+ nautilus_lockdown_load_bool (
|
|
186 |
+ &nautilus_lockdown,
|
|
187 |
+ NAUTILUS_PREFERENCES_DISABLE_COMMANDLINE,
|
|
188 |
+ disable_command_line_notify);
|
|
189 |
+ nautilus_lockdown.restrict_application_launching =
|
|
190 |
+ nautilus_lockdown_load_bool (
|
|
191 |
+ &nautilus_lockdown,
|
|
192 |
+ NAUTILUS_PREFERENCES_RESTRICT_APP_LAUNCHING,
|
|
193 |
+ restrict_application_launching_notify) ;
|
|
194 |
+ nautilus_lockdown.allowed_applications =
|
|
195 |
+ nautilus_lockdown_load_allowed_applications (
|
|
196 |
+ &nautilus_lockdown) ;
|
|
197 |
+ nautilus_lockdown.initialized = TRUE;
|
|
198 |
+}
|
|
199 |
+
|
|
200 |
+void
|
|
201 |
+nautilus_lockdown_finalize (void)
|
|
202 |
+{
|
|
203 |
+ GSList *l = NULL ;
|
|
204 |
+
|
|
205 |
+ g_assert (nautilus_lockdown.initialized == TRUE);
|
|
206 |
+ eel_preferences_remove_callback(
|
|
207 |
+ NAUTILUS_PREFERENCES_DISABLE_COMMANDLINE,
|
|
208 |
+ disable_command_line_notify,
|
|
209 |
+ &nautilus_lockdown) ;
|
|
210 |
+ eel_preferences_remove_callback(
|
|
211 |
+ NAUTILUS_PREFERENCES_RESTRICT_APP_LAUNCHING,
|
|
212 |
+ restrict_application_launching_notify,
|
|
213 |
+ &nautilus_lockdown) ;
|
|
214 |
+ eel_preferences_remove_callback(
|
|
215 |
+ NAUTILUS_PREFERENCES_ALLOWED_APPLICATIONS,
|
|
216 |
+ allowed_applications_notify,
|
|
217 |
+ &nautilus_lockdown) ;
|
17056
|
218 |
+ g_strfreev(nautilus_lockdown.allowed_applications) ;
|
9060
|
219 |
+ for (l = nautilus_lockdown.closures; l; l = l->next) {
|
|
220 |
+ g_closure_unref (l->data);
|
|
221 |
+ }
|
|
222 |
+ g_slist_free (nautilus_lockdown.closures);
|
|
223 |
+ nautilus_lockdown.closures = NULL;
|
|
224 |
+ nautilus_lockdown.initialized = FALSE;
|
|
225 |
+}
|
|
226 |
+
|
|
227 |
+gboolean
|
|
228 |
+nautilus_lockdown_is_command_line_disabled (void)
|
|
229 |
+{
|
|
230 |
+ g_assert (nautilus_lockdown.initialized == TRUE);
|
|
231 |
+ return nautilus_lockdown.disable_command_line;
|
|
232 |
+}
|
|
233 |
+
|
|
234 |
+gboolean
|
|
235 |
+nautilus_lockdown_is_app_launching_restricted (void)
|
|
236 |
+{
|
|
237 |
+ g_assert (nautilus_lockdown.initialized == TRUE);
|
|
238 |
+ return nautilus_lockdown.restrict_application_launching;
|
|
239 |
+}
|
|
240 |
+
|
17056
|
241 |
+char**
|
9060
|
242 |
+nautilus_lockdown_get_allowed_apps (void)
|
|
243 |
+{
|
|
244 |
+ g_assert (nautilus_lockdown.initialized == TRUE);
|
|
245 |
+ return nautilus_lockdown.allowed_applications;
|
|
246 |
+}
|
|
247 |
+
|
|
248 |
+static GClosure *
|
|
249 |
+nautilus_lockdown_notify_find (GSList *closures,
|
|
250 |
+ GCallback callback_func,
|
|
251 |
+ gpointer user_data)
|
|
252 |
+{
|
|
253 |
+ GSList *l;
|
|
254 |
+
|
|
255 |
+ for (l = closures; l; l = l->next) {
|
|
256 |
+ GCClosure *cclosure = l->data;
|
|
257 |
+ GClosure *closure = l->data;
|
|
258 |
+
|
|
259 |
+ if (closure->data == user_data &&
|
|
260 |
+ cclosure->callback == callback_func)
|
|
261 |
+ return closure;
|
|
262 |
+ }
|
|
263 |
+
|
|
264 |
+ return NULL;
|
|
265 |
+}
|
|
266 |
+
|
|
267 |
+static void
|
|
268 |
+marshal_user_data (GClosure *closure,
|
|
269 |
+ GValue *return_value,
|
|
270 |
+ guint n_param_values,
|
|
271 |
+ const GValue *param_values,
|
|
272 |
+ gpointer invocation_hint,
|
|
273 |
+ gpointer marshal_data)
|
|
274 |
+{
|
|
275 |
+ GCClosure *cclosure = (GCClosure*) closure;
|
|
276 |
+
|
|
277 |
+ g_return_if_fail (cclosure->callback != NULL);
|
|
278 |
+ g_return_if_fail (n_param_values == 0);
|
|
279 |
+
|
|
280 |
+ ((void (*) (gpointer *))cclosure->callback) (closure->data);
|
|
281 |
+}
|
|
282 |
+
|
|
283 |
+void
|
|
284 |
+nautilus_lockdown_notify_add (GCallback callback_func,
|
|
285 |
+ gpointer user_data)
|
|
286 |
+{
|
|
287 |
+ GClosure *closure;
|
|
288 |
+
|
|
289 |
+ g_assert (nautilus_lockdown_notify_find (nautilus_lockdown.closures,
|
|
290 |
+ callback_func,
|
|
291 |
+ user_data) == NULL);
|
|
292 |
+ closure = g_cclosure_new (callback_func, user_data, NULL);
|
|
293 |
+ g_closure_set_marshal (closure, marshal_user_data);
|
|
294 |
+ nautilus_lockdown.closures = g_slist_append (nautilus_lockdown.closures,
|
|
295 |
+ closure);
|
|
296 |
+}
|
|
297 |
+
|
|
298 |
+void
|
|
299 |
+nautilus_lockdown_notify_remove (GCallback callback_func,
|
|
300 |
+ gpointer user_data)
|
|
301 |
+{
|
|
302 |
+ GClosure *closure;
|
|
303 |
+
|
|
304 |
+ closure = nautilus_lockdown_notify_find (nautilus_lockdown.closures,
|
|
305 |
+ callback_func,
|
|
306 |
+ user_data);
|
|
307 |
+ g_assert (closure != NULL);
|
|
308 |
+ nautilus_lockdown.closures = g_slist_remove (nautilus_lockdown.closures,
|
|
309 |
+ closure);
|
|
310 |
+ g_closure_unref (closure);
|
|
311 |
+}
|
|
312 |
+
|
|
313 |
+static gboolean nautilus_lockdown_is_forbidden_uri(const char *uri)
|
|
314 |
+{
|
|
315 |
+ GnomeDesktopItem *item = NULL ;
|
|
316 |
+ GError *error = NULL ;
|
|
317 |
+ const char *command = NULL ;
|
|
318 |
+ gboolean ret_code = FALSE ;
|
|
319 |
+
|
|
320 |
+ item = gnome_desktop_item_new_from_uri(uri, 0, &error) ;
|
|
321 |
+ if (error != NULL) {
|
|
322 |
+ g_error_free(error) ;
|
|
323 |
+ return ret_code ;
|
|
324 |
+ }
|
|
325 |
+ command = gnome_desktop_item_get_string(item, GNOME_DESKTOP_ITEM_EXEC) ;
|
|
326 |
+ if (command == NULL) { return ret_code ; }
|
|
327 |
+ return nautilus_lockdown_is_forbidden_command(command) ;
|
|
328 |
+}
|
|
329 |
+
|
|
330 |
+static const char *GNOME_APP_MIME = "application/x-gnome-app-info" ;
|
|
331 |
+static const char *DESKTOP_MIME = "application/x-desktop" ;
|
|
332 |
+
|
|
333 |
+gboolean nautilus_lockdown_is_forbidden_file(NautilusDirectory *directory,
|
17056
|
334 |
+ GFileInfo *file)
|
9060
|
335 |
+{
|
17056
|
336 |
+ const char *mime_type = g_file_info_get_content_type(file) ;
|
9060
|
337 |
+
|
|
338 |
+ if (nautilus_lockdown.restrict_application_launching &&
|
|
339 |
+ mime_type != NULL &&
|
|
340 |
+ (strcmp(mime_type, GNOME_APP_MIME) == 0 ||
|
|
341 |
+ strcmp(mime_type, DESKTOP_MIME) == 0)) {
|
17056
|
342 |
+ return nautilus_lockdown_is_forbidden_command(
|
|
343 |
+ nautilus_directory_get_file_uri(directory, g_file_info_get_name(file)));
|
9060
|
344 |
+ }
|
|
345 |
+ return FALSE ;
|
|
346 |
+}
|
|
347 |
+
|
|
348 |
+gboolean nautilus_lockdown_is_forbidden_nautilus_file(NautilusFile *file)
|
|
349 |
+{
|
|
350 |
+ if (nautilus_lockdown.restrict_application_launching &&
|
|
351 |
+ (nautilus_file_is_mime_type(file, GNOME_APP_MIME) ||
|
|
352 |
+ nautilus_file_is_mime_type(file, DESKTOP_MIME))) {
|
|
353 |
+ return nautilus_lockdown_is_forbidden_uri(nautilus_file_get_uri(file)) ;
|
|
354 |
+ }
|
|
355 |
+ return FALSE ;
|
|
356 |
+}
|
|
357 |
+
|
|
358 |
+gboolean nautilus_lockdown_is_forbidden_command(const char *command)
|
|
359 |
+{
|
|
360 |
+ char *commandCopy = NULL ;
|
|
361 |
+ char *program = NULL ;
|
17056
|
362 |
+ char *allowed_app;
|
11595
|
363 |
+ gboolean retCode = FALSE ;
|
9060
|
364 |
+
|
|
365 |
+ if (!nautilus_lockdown.restrict_application_launching) { return retCode ; }
|
|
366 |
+ commandCopy = g_shell_unquote(command, NULL) ;
|
|
367 |
+ if (commandCopy == NULL) { commandCopy = g_strdup(command) ; }
|
|
368 |
+ strtok(commandCopy, " ") ;
|
|
369 |
+ if (g_path_is_absolute(commandCopy)) {
|
|
370 |
+ program = commandCopy ;
|
|
371 |
+ }
|
|
372 |
+ else {
|
|
373 |
+ char *stripped = g_path_get_basename(commandCopy) ;
|
|
374 |
+
|
|
375 |
+ program = g_find_program_in_path(stripped) ;
|
|
376 |
+ g_free(stripped) ;
|
|
377 |
+ g_free(commandCopy) ;
|
|
378 |
+ }
|
17056
|
379 |
+ retCode = TRUE;
|
9060
|
380 |
+ if (program != NULL) {
|
17056
|
381 |
+ int i = 0;
|
|
382 |
+ allowed_app = nautilus_lockdown.allowed_applications[i];
|
|
383 |
+ while (allowed_app != NULL) {
|
|
384 |
+ if (!strcmp(allowed_app, program)) {
|
|
385 |
+ retCode = FALSE;
|
|
386 |
+ break;
|
|
387 |
+ }
|
|
388 |
+ allowed_app = nautilus_lockdown.allowed_applications[++i];
|
|
389 |
+ }
|
9060
|
390 |
+ g_free(program) ;
|
|
391 |
+ }
|
|
392 |
+ return retCode ;
|
|
393 |
+}
|
|
394 |
+
|
17056
|
395 |
/jds/bin/diff -uprN nautilus-2.26.3.old/libnautilus-private/nautilus-lockdown.h nautilus-2.26.3/libnautilus-private/nautilus-lockdown.h
|
|
396 |
--- nautilus-2.26.3.old/libnautilus-private/nautilus-lockdown.h 1970-01-01 01:00:00.000000000 +0100
|
|
397 |
+++ nautilus-2.26.3/libnautilus-private/nautilus-lockdown.h 2009-07-13 11:41:43.050917000 +0100
|
|
398 |
@@ -0,0 +1,54 @@
|
12144
|
399 |
+/* -*- Mode: C; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 8 -*- */
|
|
400 |
+/*
|
|
401 |
+ * Copyright (C) 2004 Sun Microsystems, Inc.
|
|
402 |
+ *
|
|
403 |
+ * This program is free software; you can redistribute it and/or
|
|
404 |
+ * modify it under the terms of the GNU General Public License as
|
|
405 |
+ * published by the Free Software Foundation; either version 2 of the
|
|
406 |
+ * License, or (at your option) any later version.
|
|
407 |
+ *
|
|
408 |
+ * This program is distributed in the hope that it will be useful, but
|
|
409 |
+ * WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
410 |
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
411 |
+ * General Public License for more details.
|
|
412 |
+ *
|
|
413 |
+ * You should have received a copy of the GNU General Public License
|
|
414 |
+ * along with this program; if not, write to the Free Software
|
|
415 |
+ * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
|
|
416 |
+ * 02111-1307, USA.
|
|
417 |
+ *
|
|
418 |
+ * Authors:
|
|
419 |
+ * Matt Keenan <[email protected]>
|
|
420 |
+ * Mark McLoughlin <[email protected]>
|
|
421 |
+ */
|
|
422 |
+
|
|
423 |
+#ifndef __NAUTILUS_LOCKDOWN_H__
|
|
424 |
+#define __NAUTILUS_LOCKDOWN_H__
|
|
425 |
+
|
|
426 |
+#include <libgnomevfs/gnome-vfs.h>
|
|
427 |
+#include <glib.h>
|
|
428 |
+#include <glib-object.h>
|
|
429 |
+#include "nautilus-directory.h"
|
|
430 |
+
|
|
431 |
+G_BEGIN_DECLS
|
|
432 |
+
|
|
433 |
+void nautilus_lockdown_init (void);
|
|
434 |
+void nautilus_lockdown_finalize (void);
|
|
435 |
+
|
|
436 |
+void nautilus_lockdown_notify_add (GCallback callback_func,
|
|
437 |
+ gpointer user_data);
|
|
438 |
+void nautilus_lockdown_notify_remove (GCallback callback_func,
|
|
439 |
+ gpointer user_data);
|
|
440 |
+
|
|
441 |
+gboolean nautilus_lockdown_is_command_line_disabled(void) ;
|
|
442 |
+gboolean nautilus_lockdown_is_app_launching_restricted(void) ;
|
17056
|
443 |
+char** nautilus_lockdown_get_allowed_apps(void) ;
|
12144
|
444 |
+
|
|
445 |
+gboolean nautilus_lockdown_is_forbidden_file(NautilusDirectory *directory,
|
17056
|
446 |
+ GFileInfo *file) ;
|
12144
|
447 |
+gboolean nautilus_lockdown_is_forbidden_nautilus_file(NautilusFile *file) ;
|
|
448 |
+gboolean nautilus_lockdown_is_forbidden_command(const char *command) ;
|
|
449 |
+
|
|
450 |
+G_END_DECLS
|
|
451 |
+
|
|
452 |
+#endif /* __NAUTILUS_LOCKDOWN_H__ */
|
17056
|
453 |
/jds/bin/diff -uprN nautilus-2.26.3.old/src/file-manager/fm-directory-view.c nautilus-2.26.3/src/file-manager/fm-directory-view.c
|
|
454 |
--- nautilus-2.26.3.old/src/file-manager/fm-directory-view.c 2009-05-18 20:44:27.000000000 +0100
|
|
455 |
+++ nautilus-2.26.3/src/file-manager/fm-directory-view.c 2009-07-13 11:41:43.055406000 +0100
|
|
456 |
@@ -314,6 +314,7 @@ static void reset_update_interval
|
|
457 |
static void schedule_idle_display_of_pending_files (FMDirectoryView *view);
|
|
458 |
static void unschedule_display_of_pending_files (FMDirectoryView *view);
|
|
459 |
static void disconnect_model_handlers (FMDirectoryView *view);
|
|
460 |
+static void lockdown_changed_callback (gpointer context);
|
|
461 |
static void metadata_for_directory_as_file_ready_callback (NautilusFile *file,
|
|
462 |
gpointer callback_data);
|
|
463 |
static void metadata_for_files_in_directory_ready_callback (NautilusDirectory *directory,
|
|
464 |
@@ -9575,6 +9579,15 @@ fm_directory_view_handle_uri_list_drop (
|
|
465 |
g_free (container_uri);
|
|
466 |
}
|
|
467 |
|
|
468 |
+static void lockdown_changed_callback(gpointer context)
|
|
469 |
+{
|
|
470 |
+ FMDirectoryView *directory_view = FM_DIRECTORY_VIEW(context) ;
|
|
471 |
+
|
|
472 |
+ if (directory_view != NULL && directory_view->details->model != NULL) {
|
|
473 |
+ load_directory(directory_view, directory_view->details->model) ;
|
|
474 |
+ }
|
|
475 |
+}
|
|
476 |
+
|
|
477 |
void
|
|
478 |
fm_directory_view_handle_text_drop (FMDirectoryView *view,
|
|
479 |
const char *text,
|
|
480 |
/jds/bin/diff -uprN nautilus-2.26.3.old/src/file-manager/fm-tree-model.c nautilus-2.26.3/src/file-manager/fm-tree-model.c
|
|
481 |
--- nautilus-2.26.3.old/src/file-manager/fm-tree-model.c 2009-04-20 11:57:20.000000000 +0100
|
|
482 |
+++ nautilus-2.26.3/src/file-manager/fm-tree-model.c 2009-07-13 11:41:43.056901000 +0100
|
|
483 |
@@ -38,6 +38,8 @@
|
|
484 |
#include <gtk/gtk.h>
|
|
485 |
#include <string.h>
|
|
486 |
|
|
487 |
+#include <libnautilus-private/nautilus-lockdown.h>
|
|
488 |
+
|
|
489 |
enum {
|
|
490 |
ROW_LOADED,
|
|
491 |
LAST_SIGNAL
|
|
492 |
@@ -1707,6 +1709,14 @@ fm_tree_model_set_show_hidden_files (FMT
|
|
493 |
schedule_monitoring_update (model);
|
|
494 |
}
|
|
495 |
|
|
496 |
+void fm_tree_model_refresh_permissions(FMTreeModel *model)
|
|
497 |
+{
|
|
498 |
+ g_return_if_fail(FM_IS_TREE_MODEL(model)) ;
|
|
499 |
+ stop_monitoring(model) ;
|
|
500 |
+ destroy_by_function(model, nautilus_lockdown_is_forbidden_nautilus_file) ;
|
|
501 |
+ schedule_monitoring_update(model) ;
|
|
502 |
+}
|
|
503 |
+
|
|
504 |
static gboolean
|
|
505 |
file_is_not_directory (NautilusFile *file)
|
|
506 |
{
|
|
507 |
/jds/bin/diff -uprN nautilus-2.26.3.old/src/file-manager/fm-tree-view.c nautilus-2.26.3/src/file-manager/fm-tree-view.c
|
|
508 |
--- nautilus-2.26.3.old/src/file-manager/fm-tree-view.c 2009-05-18 20:44:27.000000000 +0100
|
|
509 |
+++ nautilus-2.26.3/src/file-manager/fm-tree-view.c 2009-07-13 11:41:43.059783000 +0100
|
|
510 |
@@ -1485,6 +1485,7 @@ update_filtering_from_preferences (FMTre
|
|
511 |
fm_tree_model_set_show_only_directories
|
|
512 |
(view->details->child_model,
|
|
513 |
eel_preferences_get_boolean (NAUTILUS_PREFERENCES_TREE_SHOW_ONLY_DIRECTORIES));
|
|
514 |
+ fm_tree_model_refresh_permissions(view->details->child_model) ;
|
|
515 |
}
|
|
516 |
|
|
517 |
static void
|
|
518 |
@@ -1543,6 +1544,7 @@ fm_tree_view_init (FMTreeView *view)
|
|
519 |
filtering_changed_callback, view, G_OBJECT (view));
|
|
520 |
eel_preferences_add_callback_while_alive (NAUTILUS_PREFERENCES_SHOW_BACKUP_FILES,
|
|
521 |
filtering_changed_callback, view, G_OBJECT (view));
|
|
522 |
+ nautilus_lockdown_notify_add (filtering_changed_callback, view);
|
|
523 |
eel_preferences_add_callback_while_alive (NAUTILUS_PREFERENCES_TREE_SHOW_ONLY_DIRECTORIES,
|
|
524 |
filtering_changed_callback, view, G_OBJECT (view));
|
|
525 |
|
|
526 |
@@ -1610,6 +1612,8 @@ fm_tree_view_finalize (GObject *object)
|
|
527 |
|
|
528 |
view = FM_TREE_VIEW (object);
|
|
529 |
|
|
530 |
+ nautilus_lockdown_notify_remove (filtering_changed_callback, view);
|
|
531 |
+
|
|
532 |
g_free (view->details);
|
12144
|
533 |
|
17056
|
534 |
G_OBJECT_CLASS (parent_class)->finalize (object);
|
|
535 |
/jds/bin/diff -uprN nautilus-2.26.3.old/src/nautilus-window-menus.c nautilus-2.26.3/src/nautilus-window-menus.c
|
|
536 |
--- nautilus-2.26.3.old/src/nautilus-window-menus.c 2009-05-18 20:44:27.000000000 +0100
|
|
537 |
+++ nautilus-2.26.3/src/nautilus-window-menus.c 2009-07-13 11:41:43.061038000 +0100
|
|
538 |
@@ -49,6 +49,7 @@
|
|
539 |
#include <libnautilus-private/nautilus-global-preferences.h>
|
|
540 |
#include <libnautilus-private/nautilus-icon-names.h>
|
|
541 |
#include <libnautilus-private/nautilus-ui-utilities.h>
|
|
542 |
+#include <libnautilus-private/nautilus-lockdown.h>
|
|
543 |
#include <libnautilus-private/nautilus-module.h>
|
|
544 |
#include <libnautilus-private/nautilus-undo-manager.h>
|
|
545 |
#include <libnautilus-private/nautilus-search-directory.h>
|
|
546 |
@@ -1021,6 +1022,34 @@ add_extension_menu_items (NautilusWindow
|
|
547 |
}
|
|
548 |
}
|
11234
|
549 |
|
17056
|
550 |
+static gboolean
|
|
551 |
+load_extension_menus_idle(gpointer context)
|
|
552 |
+{
|
|
553 |
+ NautilusWindow *window = NAUTILUS_WINDOW(context);
|
|
554 |
+
|
|
555 |
+ nautilus_window_load_extension_menus(window);
|
|
556 |
+ return FALSE;
|
|
557 |
+}
|
|
558 |
+
|
|
559 |
+static void
|
|
560 |
+lockdown_changed_callback(gpointer context)
|
|
561 |
+{
|
|
562 |
+ NautilusWindow *window = NAUTILUS_WINDOW(context);
|
|
563 |
+ g_idle_add(load_extension_menus_idle, window);
|
|
564 |
+}
|
|
565 |
+
|
|
566 |
+void
|
|
567 |
+nautilus_window_menus_lockdown_notify_remove (NautilusWindow *window)
|
|
568 |
+{
|
|
569 |
+ nautilus_lockdown_notify_remove(lockdown_changed_callback, window);
|
|
570 |
+}
|
|
571 |
+
|
|
572 |
+void
|
|
573 |
+nautilus_window_menus_lockdown_notify_add (NautilusWindow *window)
|
|
574 |
+{
|
|
575 |
+ nautilus_lockdown_notify_add(lockdown_changed_callback, window);
|
|
576 |
+}
|
|
577 |
+
|
|
578 |
void
|
|
579 |
nautilus_window_load_extension_menus (NautilusWindow *window)
|
|
580 |
{
|
|
581 |
/jds/bin/diff -uprN nautilus-2.26.3.old/src/nautilus-window.c nautilus-2.26.3/src/nautilus-window.c
|
|
582 |
--- nautilus-2.26.3.old/src/nautilus-window.c 2009-04-20 11:57:20.000000000 +0100
|
|
583 |
+++ nautilus-2.26.3/src/nautilus-window.c 2009-07-13 11:41:43.064214000 +0100
|
|
584 |
@@ -629,6 +629,8 @@ nautilus_window_finalize (GObject *objec
|
|
585 |
|
|
586 |
g_object_unref (window->details->ui_manager);
|
|
587 |
|
|
588 |
+ nautilus_window_menus_lockdown_notify_remove(window);
|
|
589 |
+
|
|
590 |
G_OBJECT_CLASS (nautilus_window_parent_class)->finalize (object);
|
|
591 |
}
|
|
592 |
|
|
593 |
/jds/bin/diff -uprN nautilus-2.26.3.old/src/nautilus-main.c nautilus-2.26.3/src/nautilus-main.c
|
|
594 |
--- nautilus-2.26.3.old/src/nautilus-main.c 2009-05-18 20:44:27.000000000 +0100
|
|
595 |
+++ nautilus-2.26.3/src/nautilus-main.c 2009-07-13 11:41:43.077497000 +0100
|
|
596 |
@@ -464,6 +465,7 @@ main (int argc, char *argv[])
|
|
597 |
(NAUTILUS_PREFERENCES_DESKTOP_IS_HOME_DIR, TRUE);
|
|
598 |
}
|
|
599 |
|
|
600 |
+ nautilus_lockdown_init ();
|
|
601 |
application = NULL;
|
|
602 |
|
|
603 |
/* Do either the self-check or the real work. */
|
|
604 |
@@ -525,6 +527,7 @@ main (int argc, char *argv[])
|
|
605 |
g_object_unref (application);
|
|
606 |
}
|
|
607 |
|
|
608 |
+ nautilus_lockdown_finalize ();
|
|
609 |
eel_debug_shut_down ();
|
|
610 |
|
|
611 |
nautilus_application_save_accel_map (NULL);
|
|
612 |
/jds/bin/diff -uprN nautilus-2.26.3.old/libnautilus-private/nautilus-program-choosing.c nautilus-2.26.3/libnautilus-private/nautilus-program-choosing.c
|
|
613 |
--- nautilus-2.26.3.old/libnautilus-private/nautilus-program-choosing.c 2009-04-20 11:57:19.000000000 +0100
|
|
614 |
+++ nautilus-2.26.3/libnautilus-private/nautilus-program-choosing.c 2009-07-13 11:41:43.078947000 +0100
|
|
615 |
@@ -158,6 +158,22 @@ nautilus_launch_application (GAppInfo *a
|
|
616 |
eel_g_list_free_deep (uris);
|
|
617 |
}
|
15621
|
618 |
|
|
619 |
+static gboolean
|
|
620 |
+command_is_allowed (const char *full_command)
|
|
621 |
+{
|
17056
|
622 |
+ gboolean allowed = !nautilus_lockdown_is_forbidden_command(full_command);
|
|
623 |
+ if (!allowed) {
|
15621
|
624 |
+ eel_show_error_dialog
|
17056
|
625 |
+ /* SUN_BRANDING */
|
|
626 |
+ (_("Sorry, This is a restricted application which "
|
|
627 |
+ "you may not run."),
|
|
628 |
+ /* SUN_BRANDING */
|
|
629 |
+ _("Restricted Application"),
|
|
630 |
+ NULL);
|
|
631 |
+ }
|
|
632 |
+ return allowed;
|
15621
|
633 |
+}
|
17056
|
634 |
+
|
|
635 |
void
|
|
636 |
nautilus_launch_application_by_uri (GAppInfo *application,
|
|
637 |
GList *uris,
|
|
638 |
@@ -335,8 +351,22 @@ nautilus_launch_application_from_command
|
|
639 |
}
|
15621
|
640 |
}
|
|
641 |
|
|
642 |
+ if (!command_is_allowed (command_string)) {
|
|
643 |
+ g_free (full_command);
|
|
644 |
+ return;
|
|
645 |
+ }
|
|
646 |
+
|
|
647 |
if (use_terminal) {
|
|
648 |
- eel_gnome_open_terminal_on_screen (full_command, screen);
|
|
649 |
+ if (!nautilus_lockdown_is_command_line_disabled ()) {
|
|
650 |
+ eel_gnome_open_terminal_on_screen (full_command, screen);
|
|
651 |
+ } else {
|
|
652 |
+ eel_show_error_dialog
|
|
653 |
+ /* SUN_BRANDING */
|
|
654 |
+ (_("Sorry, this command requires a terminal "),
|
|
655 |
+ /* SUN_BRANDING */
|
|
656 |
+ _("Terminal access is restricted."),
|
|
657 |
+ NULL);
|
|
658 |
+ }
|
|
659 |
} else {
|
17056
|
660 |
gdk_spawn_command_line_on_screen (screen, full_command, NULL);
|
15621
|
661 |
}
|
17056
|
662 |
@@ -387,6 +417,10 @@ nautilus_launch_desktop_file (GdkScreen
|
|
663 |
parent_window);
|
|
664 |
return;
|
|
665 |
}
|
15621
|
666 |
+
|
17056
|
667 |
+ if (!command_is_allowed (g_app_info_get_executable (app_info))) {
|
15621
|
668 |
+ return;
|
|
669 |
+ }
|
17056
|
670 |
|
|
671 |
/* count the number of uris with local paths */
|
|
672 |
count = 0;
|
|
673 |
diff -ruN nautilus-2.27.4.orig/libnautilus-private/nautilus-directory-async.c nautilus-2.27.4/libnautilus-private/nautilus-directory-async.c
|
|
674 |
--- nautilus-2.27.4.orig/libnautilus-private/nautilus-directory-async.c 2009-07-23 15:47:20.972324079 +0100
|
|
675 |
+++ nautilus-2.27.4/libnautilus-private/nautilus-directory-async.c 2009-07-23 15:48:27.250174766 +0100
|
|
676 |
@@ -32,6 +32,7 @@
|
|
677 |
#include "nautilus-signaller.h"
|
|
678 |
#include "nautilus-global-preferences.h"
|
|
679 |
#include "nautilus-link.h"
|
|
680 |
+#include "nautilus-lockdown.h"
|
|
681 |
#include "nautilus-marshal.h"
|
|
682 |
#include <eel/eel-glib-extensions.h>
|
|
683 |
#include <eel/eel-string.h>
|
|
684 |
diff -ruN nautilus-2.27.4.orig/src/nautilus-main.c nautilus-2.27.4/src/nautilus-main.c
|
|
685 |
--- nautilus-2.27.4.orig/src/nautilus-main.c 2009-07-23 15:47:20.959902926 +0100
|
|
686 |
+++ nautilus-2.27.4/src/nautilus-main.c 2009-07-23 15:49:22.737922718 +0100
|
|
687 |
@@ -47,6 +47,7 @@
|
|
688 |
#include <gio/gdesktopappinfo.h>
|
|
689 |
#include <libnautilus-private/nautilus-debug-log.h>
|
|
690 |
#include <libnautilus-private/nautilus-global-preferences.h>
|
|
691 |
+#include <libnautilus-private/nautilus-lockdown.h>
|
|
692 |
#include <libnautilus-private/nautilus-lib-self-check-functions.h>
|
|
693 |
#include <libnautilus-private/nautilus-icon-names.h>
|
|
694 |
#include <libxml/parser.h>
|
|
695 |
diff -ruN nautilus-2.27.91.orig/libnautilus-private/nautilus-global-preferences.h nautilus-2.27.91/libnautilus-private/nautilus-global-preferences.h
|
|
696 |
--- nautilus-2.27.91.orig/libnautilus-private/nautilus-global-preferences.h 2009-08-25 14:16:47.618321840 +0100
|
|
697 |
+++ nautilus-2.27.91/libnautilus-private/nautilus-global-preferences.h 2009-08-25 14:17:34.366770658 +0100
|
|
698 |
@@ -228,6 +228,9 @@
|
|
699 |
#define NAUTILUS_PREFERENCES_DESKTOP_NETWORK_VISIBLE "desktop/network_icon_visible"
|
|
700 |
#define NAUTILUS_PREFERENCES_DESKTOP_NETWORK_NAME "desktop/network_icon_name"
|
|
701 |
#define NAUTILUS_PREFERENCES_DESKTOP_PRIMARY_SCREEN "desktop/primary_screen"
|
|
702 |
+#define NAUTILUS_PREFERENCES_DISABLE_COMMANDLINE "/desktop/gnome/lockdown/disable_command_line"
|
|
703 |
+#define NAUTILUS_PREFERENCES_RESTRICT_APP_LAUNCHING "/desktop/gnome/lockdown/restrict_application_launching"
|
|
704 |
+#define NAUTILUS_PREFERENCES_ALLOWED_APPLICATIONS "/desktop/gnome/lockdown/allowed_applications"
|
|
705 |
|
|
706 |
/* Lockdown */
|
|
707 |
#define NAUTILUS_PREFERENCES_LOCKDOWN_COMMAND_LINE "/desktop/gnome/lockdown/disable_command_line"
|
|
708 |
diff -ruN nautilus-2.27.91.orig/src/file-manager/fm-directory-view.c nautilus-2.27.91/src/file-manager/fm-directory-view.c
|
|
709 |
--- nautilus-2.27.91.orig/src/file-manager/fm-directory-view.c 2009-08-25 14:16:47.523491404 +0100
|
|
710 |
+++ nautilus-2.27.91/src/file-manager/fm-directory-view.c 2009-08-25 14:20:03.740747515 +0100
|
|
711 |
@@ -1943,6 +1943,7 @@
|
|
712 |
sort_directories_first_changed_callback, view);
|
|
713 |
eel_preferences_add_callback (NAUTILUS_PREFERENCES_LOCKDOWN_COMMAND_LINE,
|
|
714 |
lockdown_disable_command_line_changed_callback, view);
|
|
715 |
+ nautilus_lockdown_notify_add (lockdown_changed_callback, view);
|
17055
|
716 |
}
|
|
717 |
|
|
718 |
static void
|
17056
|
719 |
@@ -2059,6 +2060,7 @@
|
|
720 |
sort_directories_first_changed_callback, view);
|
|
721 |
eel_preferences_remove_callback (NAUTILUS_PREFERENCES_LOCKDOWN_COMMAND_LINE,
|
|
722 |
lockdown_disable_command_line_changed_callback, view);
|
|
723 |
+ nautilus_lockdown_notify_remove (lockdown_changed_callback, view);
|
17055
|
724 |
|
17056
|
725 |
unschedule_pop_up_location_context_menu (view);
|
|
726 |
if (view->details->location_popup_event != NULL) {
|
17505
|
727 |
diff -ruN nautilus-2.29.2.orig/src/nautilus-window.c nautilus-2.29.2/src/nautilus-window.c
|
|
728 |
--- nautilus-2.29.2.orig/src/nautilus-window.c 2010-02-01 22:58:18.483524915 +0000
|
|
729 |
+++ nautilus-2.29.2/src/nautilus-window.c 2010-02-01 23:00:45.641679123 +0000
|
|
730 |
@@ -629,7 +629,7 @@
|
|
731 |
|
|
732 |
slot = nautilus_window_open_slot (window->details->active_pane, 0);
|
|
733 |
nautilus_window_set_active_slot (window, slot);
|
|
734 |
-
|
|
735 |
+ nautilus_window_menus_lockdown_notify_add (window);
|
|
736 |
return object;
|
|
737 |
}
|
|
738 |
|
|
739 |
diff -ruN nautilus-2.29.2.orig/src/nautilus-window-private.h nautilus-2.29.2/src/nautilus-window-private.h
|
|
740 |
--- nautilus-2.29.2.orig/src/nautilus-window-private.h 2010-02-01 23:01:51.066830219 +0000
|
|
741 |
+++ nautilus-2.29.2/src/nautilus-window-private.h 2010-02-01 23:02:35.249306426 +0000
|
|
742 |
@@ -160,6 +160,8 @@
|
|
743 |
const char *status);
|
|
744 |
void nautilus_window_load_view_as_menus (NautilusWindow *window);
|
|
745 |
void nautilus_window_load_extension_menus (NautilusWindow *window);
|
|
746 |
+void nautilus_window_menus_lockdown_notify_add (NautilusWindow *window);
|
|
747 |
+void nautilus_window_menus_lockdown_notify_remove (NautilusWindow *window);
|
|
748 |
void nautilus_window_initialize_menus (NautilusWindow *window);
|
|
749 |
void nautilus_window_remove_trash_monitor_callback (NautilusWindow *window);
|
|
750 |
NautilusWindowPane *nautilus_window_get_next_pane (NautilusWindow *window);
|