Clean up comments

This commit is contained in:
Theodor S. Midtlien
2026-07-24 14:57:21 +02:00
parent 57f9cbe5ff
commit 0137876618
23 changed files with 55 additions and 103 deletions
+2 -8
View File
@@ -268,16 +268,9 @@ func FlagNameToEnvVar(cmdFlag string, prefix string) string {
return prefix + upper
}
// DialClientGRPCServer returns client connection to the daemon server.
// daemonDialTarget returns the gRPC dial target and base options for the daemon
// address, handling the npipe scheme (Windows named pipe, via a context dialer)
// and unix/tcp. It sets insecure transport credentials but NOT WithBlock, so it
// serves both the blocking CLI dial and the JSON gateway's lazy client.
//
// The daemon reads the caller's kernel identity from the transport (SO_PEERCRED
// on a Unix socket, the client token on a Windows named pipe), so the client
// stays insecure. gRPC's resolver does not understand Windows named pipes, hence
// the context dialer.
// and unix/tcp.
func daemonDialTarget(addr string) (string, []grpc.DialOption) {
opts := []grpc.DialOption{grpc.WithTransportCredentials(insecure.NewCredentials())}
target := strings.TrimPrefix(addr, "tcp://")
@@ -291,6 +284,7 @@ func daemonDialTarget(addr string) (string, []grpc.DialOption) {
return target, opts
}
// DialClientGRPCServer returns client connection to the daemon server.
func DialClientGRPCServer(ctx context.Context, addr string, opts ...grpc.DialOption) (*grpc.ClientConn, error) {
ctx, cancel := context.WithTimeout(ctx, time.Second*10)
defer cancel()
+1 -5
View File
@@ -22,11 +22,7 @@ import (
)
// daemonServerOptions installs peer-identity transport credentials and the
// authorization interceptor on the daemon ipc. Identity is only available
// over a Unix socket (SO_PEERCRED) or a Windows named pipe (client token).
// Over TCP, or on platforms without a peer-credential primitive, the daemon
// runs without per-caller authorization and warns (no interceptor, so it does
// not deny everyone).
// authorization interceptor on the daemon ipc if supported.
func daemonServerOptions(network string, interceptor *ipcauth.Interceptor) []grpc.ServerOption {
creds := ipcauth.NewTransportCredentials()
if creds == nil {
+2 -2
View File
@@ -23,8 +23,8 @@ import (
type jsonPeerCtxKey struct{}
// jsonConnContext reads the connecting HTTP client's identity from the JSON
// socket (peercred) and stashes it so it can be forwarded to the daemon. The
// gateway re-dials the daemon as the daemon's own identity, so without this the
// socket and stashes it so it can be forwarded to the daemon. The gateway
// re-dials the daemon as the daemon's own identity, so without this the
// daemon would see every JSON request as privileged.
func jsonConnContext(ctx context.Context, c net.Conn) context.Context {
id, err := ipcauth.ConnIdentity(c)
+1 -4
View File
@@ -13,10 +13,7 @@ import (
)
// listenNamedPipe creates the daemon control named pipe with a permissive,
// local-only SDDL. Any local caller may connect, on par with the Unix
// socket's 0666, and the per-RPC interceptor authorizes. ListenPipe fails
// if the pipe already exists (first-instance semantics), which prevents a
// squatting process from pre-creating it.
// local-only SDDL. Any local caller may connect, like Unix socket with 0666.
func listenNamedPipe(path string) (net.Listener, error) {
return winio.ListenPipe(path, &winio.PipeConfig{
SecurityDescriptor: ipcauth.DefaultPipeSDDL(),
+1 -2
View File
@@ -19,8 +19,7 @@ const (
windowsPipeDaemonAddr = "npipe://netbird"
// legacyWindowsDaemonAddr is the loopback-TCP address the Windows daemon used
// before named-pipe support. TCP exposes no peer-identity primitive, so the
// authorization interceptor cannot run over it.
// before named-pipe support.
legacyWindowsDaemonAddr = "tcp://127.0.0.1:41731"
)