Ask the operating system for privileges when a guarded SSH setting is changed

This commit is contained in:
Viktor Liu
2026-08-05 14:16:34 +02:00
parent 6526fc2bec
commit 6495ad8687
41 changed files with 3105 additions and 96 deletions
+14
View File
@@ -0,0 +1,14 @@
package daemonaddr
import "strings"
// CarriesIdentity reports whether the control channel at addr conveys the
// connecting process's identity to the daemon. A Unix socket carries peer
// credentials and a named pipe carries the client's token; loopback TCP carries
// neither, so on such an address the daemon cannot authorize a privileged
// operation for anybody. A client uses this to tell whether becoming privileged
// would get it anywhere: on an identity-less address it would not, and the only
// way forward is to move the daemon onto one that carries identity.
func CarriesIdentity(addr string) bool {
return strings.HasPrefix(addr, "unix://") || strings.HasPrefix(addr, pipeScheme)
}
@@ -0,0 +1,27 @@
package daemonaddr
import "testing"
func TestCarriesIdentity(t *testing.T) {
tests := []struct {
addr string
want bool
}{
{"unix:///var/run/netbird.sock", true},
{"unix:///var/run/netbird/default.sock", true},
{"npipe://netbird", true},
{`npipe://\\.\pipe\ProtectedPrefix\Administrators\netbird`, true},
{"tcp://127.0.0.1:41731", false},
{"tcp://localhost:41731", false},
{"", false},
{"/var/run/netbird.sock", false},
}
for _, tt := range tests {
t.Run(tt.addr, func(t *testing.T) {
if got := CarriesIdentity(tt.addr); got != tt.want {
t.Errorf("CarriesIdentity(%q) = %v, want %v", tt.addr, got, tt.want)
}
})
}
}