mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-07 22:19:08 +02:00
Clean up comments
This commit is contained in:
+2
-8
@@ -268,16 +268,9 @@ func FlagNameToEnvVar(cmdFlag string, prefix string) string {
|
||||
return prefix + upper
|
||||
}
|
||||
|
||||
// DialClientGRPCServer returns client connection to the daemon server.
|
||||
// daemonDialTarget returns the gRPC dial target and base options for the daemon
|
||||
// address, handling the npipe scheme (Windows named pipe, via a context dialer)
|
||||
// and unix/tcp. It sets insecure transport credentials but NOT WithBlock, so it
|
||||
// serves both the blocking CLI dial and the JSON gateway's lazy client.
|
||||
//
|
||||
// The daemon reads the caller's kernel identity from the transport (SO_PEERCRED
|
||||
// on a Unix socket, the client token on a Windows named pipe), so the client
|
||||
// stays insecure. gRPC's resolver does not understand Windows named pipes, hence
|
||||
// the context dialer.
|
||||
// and unix/tcp.
|
||||
func daemonDialTarget(addr string) (string, []grpc.DialOption) {
|
||||
opts := []grpc.DialOption{grpc.WithTransportCredentials(insecure.NewCredentials())}
|
||||
target := strings.TrimPrefix(addr, "tcp://")
|
||||
@@ -291,6 +284,7 @@ func daemonDialTarget(addr string) (string, []grpc.DialOption) {
|
||||
return target, opts
|
||||
}
|
||||
|
||||
// DialClientGRPCServer returns client connection to the daemon server.
|
||||
func DialClientGRPCServer(ctx context.Context, addr string, opts ...grpc.DialOption) (*grpc.ClientConn, error) {
|
||||
ctx, cancel := context.WithTimeout(ctx, time.Second*10)
|
||||
defer cancel()
|
||||
|
||||
@@ -22,11 +22,7 @@ import (
|
||||
)
|
||||
|
||||
// daemonServerOptions installs peer-identity transport credentials and the
|
||||
// authorization interceptor on the daemon ipc. Identity is only available
|
||||
// over a Unix socket (SO_PEERCRED) or a Windows named pipe (client token).
|
||||
// Over TCP, or on platforms without a peer-credential primitive, the daemon
|
||||
// runs without per-caller authorization and warns (no interceptor, so it does
|
||||
// not deny everyone).
|
||||
// authorization interceptor on the daemon ipc if supported.
|
||||
func daemonServerOptions(network string, interceptor *ipcauth.Interceptor) []grpc.ServerOption {
|
||||
creds := ipcauth.NewTransportCredentials()
|
||||
if creds == nil {
|
||||
|
||||
@@ -23,8 +23,8 @@ import (
|
||||
type jsonPeerCtxKey struct{}
|
||||
|
||||
// jsonConnContext reads the connecting HTTP client's identity from the JSON
|
||||
// socket (peercred) and stashes it so it can be forwarded to the daemon. The
|
||||
// gateway re-dials the daemon as the daemon's own identity, so without this the
|
||||
// socket and stashes it so it can be forwarded to the daemon. The gateway
|
||||
// re-dials the daemon as the daemon's own identity, so without this the
|
||||
// daemon would see every JSON request as privileged.
|
||||
func jsonConnContext(ctx context.Context, c net.Conn) context.Context {
|
||||
id, err := ipcauth.ConnIdentity(c)
|
||||
|
||||
@@ -13,10 +13,7 @@ import (
|
||||
)
|
||||
|
||||
// listenNamedPipe creates the daemon control named pipe with a permissive,
|
||||
// local-only SDDL. Any local caller may connect, on par with the Unix
|
||||
// socket's 0666, and the per-RPC interceptor authorizes. ListenPipe fails
|
||||
// if the pipe already exists (first-instance semantics), which prevents a
|
||||
// squatting process from pre-creating it.
|
||||
// local-only SDDL. Any local caller may connect, like Unix socket with 0666.
|
||||
func listenNamedPipe(path string) (net.Listener, error) {
|
||||
return winio.ListenPipe(path, &winio.PipeConfig{
|
||||
SecurityDescriptor: ipcauth.DefaultPipeSDDL(),
|
||||
|
||||
@@ -19,8 +19,7 @@ const (
|
||||
windowsPipeDaemonAddr = "npipe://netbird"
|
||||
|
||||
// legacyWindowsDaemonAddr is the loopback-TCP address the Windows daemon used
|
||||
// before named-pipe support. TCP exposes no peer-identity primitive, so the
|
||||
// authorization interceptor cannot run over it.
|
||||
// before named-pipe support.
|
||||
legacyWindowsDaemonAddr = "tcp://127.0.0.1:41731"
|
||||
)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user