ReferenceEvery page

panel-brokerd(8)

panel privileged operations broker

Name

panel-brokerd — panel privileged operations broker

Synopsis

panel-brokerd [-v] [-f file] [-caller user:module]

Description

panel-brokerd performs the operations the rest of the panel is not privileged to perform. It is started by panel-masterd(8) and is not ordinarily run by hand.

It listens on a unix socket and identifies each caller by asking the kernel which account connected, rather than by any token the caller presents. A caller may invoke verbs in its own module's namespace and verbs under core, and nothing else.

The set of operations is fixed at compile time. Installing a module does not add code here; it only makes the broker willing to route existing verbs to that module's account. Each verb declares the filesystem access it requires. Started by panel-masterd(8), the broker confines itself with Landlock to those paths and a list of its own: it may run programs under /usr but not write them, and may not write /usr/local/sbin or the upgrade directory at all. It then checks that it cannot write sbin_dir, and logs the result. broker_unveil no turns the confinement off. A broker started by hand is not confined.

Installing a module's packages and upgrading the panel are done by panel-installd(8), which the broker asks; with no master, the broker does them itself. Once confined, it runs ifup(8) and ifdown(8) through systemd-run(1), so a DHCP client they start is not confined with it.

For the household page of panel-api(8), it restarts the internet connection (the uplink taken down and up, the same way) and restarts the machine, by a systemd-run(1) timer five seconds on so the answer is sent first. Only panel-api(8) may ask for either. It keeps the devices whose internet is paused, in paused.json beside the firewall's state, and the router's firewall drops what they send; an entry for “everyone” drops everything the home network sends through the router, by one rule; panel-api(8) decides who may pause or resume which device or person, and pauses by the household's schedules as “(schedule)” and by their daily internet time as “(allowance)”. For the daily internet time it counts what the devices panel-api(8) asks about send to the internet, by hardware address, in the nftables table panel_usage, after the firewall's chains; the table is loaded again when those devices change, and taken away when there are none.

At start, where net.ipv4.ping_group_range lets no group open an unprivileged ICMP socket (Linux's own “1 0”), it sets it to “0 0”, root's group only, for the net module's echoes, and writes /etc/sysctl.d/90-panel-ping.conf so it holds after a restart. A range somebody else set is left as it is.

It writes the Wi-Fi access point's hostapd.conf whole from the Wi-Fi page's settings, unmasks and enables hostapd, unblocks the radio with rfkill unblock wlan, and gives the radio the home network's address in the interfaces file when it is that network's port. A change is applied with three minutes to join the Wi-Fi again and keep it, and is put back at once if hostapd does not start or the radio does not come up as an access point.

It keeps the WireGuard tunnel's private key and its peers' preshared keys: no answer carries them, and a tunnel model sent back to be rendered or committed has its keys put in from the stored tunnel, matched by public key, or from a key it has just made or read, held in memory for ten minutes.

Every call is recorded, naming the person on whose behalf it was made rather than the daemon that relayed it. Verbs marked as high volume are counted and summarised instead, since a stream of routine reads would otherwise bury what matters. Refusals and failures are always recorded in full. The trail is kept separately from the panel database, which the broker does not open.

The options are as follows:

-caller user:module
Permit user to call verbs as module. May be given more than once. Supplied by the supervisor; overrides broker_callers.
-f file
Read configuration from file.
-v
Print the version and exit.

Files

/var/run/panel/broker.sock
/var/run/panel/installer.sock
/var/log/panel/broker-audit.log

See also

panel.conf(5), panel-api(8), panel-installd(8), panel-masterd(8)