Files
webmin/systemd/save_manual.cgi
Ilia Ross d94000afbd Add Systemd Services and Units module
This PR adds a standalone Systemd Services and Units module for managing systemd units across system and user scopes.

The module keeps systemd-specific behavior separate from the legacy Bootup and Shutdown module and is implemented as standalone `strict`/`warnings` Perl code rather than depending on its existing init helpers. Those helpers intentionally smooth over multiple init systems, while this module keeps systemd-specific file handling, user-manager behavior, ACL checks, and control operations explicit, scoped, and easier to audit.

It includes:

- Tabbed views for services, timers, sockets, paths, targets, storage, resources, devices, and user units
- Guided creation and editing for common unit types, with contextual fields, validation, and help
- User-scoped unit management with linger support and safe handling of home-directory unit files
- Runtime actions for start, stop, restart, enable, disable, status, logs, properties, dependencies, and system-unit mask/unmask
- Drop-in override inventory plus create, edit, and delete flows
- Manual unit-file editing with daemon reload reminders and actions
- Configurable module behavior, visible tabs, display options, and post-create navigation
- Comprehensive ACL controls for system/user scopes, actions, manual edits, drop-ins, linger, reload, backup, and user filters
- Safe Webmin user support through a scoped safe ACL preset
- Virtualmin integration for granting domain owners access to their own systemd user units
- Tests for unit generation, safety checks, ACL behavior, user-unit handling, backup coverage, and Perl::Critic compatibility

A companion Virtualmin PR adds template integration so domain owners can be granted scoped access to their own systemd user units when this module is installed.
2026-06-12 20:55:28 +02:00

35 lines
1.0 KiB
Perl
Executable File

#!/usr/local/bin/perl
# Save a raw systemd unit file selected by edit_manual.cgi.
use strict;
use warnings;
require './systemd-lib.pl'; ## no critic
our (%access, %in, %text);
ReadParseMime();
error_setup($text{'manual_err'});
# The posted path must still be in the discovered allowlist at save time.
my $info = manual_unit_file($in{'file'});
$info || error($text{'manual_efile'});
systemd_can_manual(\%access, $info) ||
systemd_acl_error($info->{'scope'} eq 'user' ?
'pmanual_user' : 'pmanual');
my ($ok, $err) = write_manual_unit_file($info, $in{'data'});
$ok || error($err || $text{'manual_ewrite'});
# User-unit edits include the owner so the log parser can render context.
if ($info->{'scope'} eq 'user') {
mark_user_units_changed($info->{'user'});
webmin_log("manual", "systemd-user", $info->{'file'},
{ 'user' => $info->{'user'} });
redirect("index.cgi?scope=user&unituser=".urlize($info->{'user'}));
}
else {
mark_units_changed();
webmin_log("manual", "systemd", $info->{'file'});
redirect("");
}