mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-15 19:29:08 +02:00
Accept bare marker protocols, reject msb_right framebuffers, split the policy row conversion
This commit is contained in:
@@ -2096,9 +2096,9 @@ func (s *Server) RespondApproval(ctx context.Context, msg *proto.RespondApproval
|
||||
id, ok := ipcauth.CallerIdentity(ctx)
|
||||
if !ok {
|
||||
log.Warnf("refusing approval response for %s: the caller's identity cannot be verified on this control channel", msg.GetRequestId())
|
||||
return nil, gstatus.Errorf(codes.PermissionDenied,
|
||||
"answering a connection approval requires a control channel that carries the caller's identity. "+
|
||||
"Reinstall the service on a socket that does: %s", reinstallCommand())
|
||||
// Same envelope as the privileged-config refusals, so the CLI and the UI
|
||||
// present the guidance instead of a raw gRPC error: see privilegeError.
|
||||
return nil, privilegeError(unidentifiableCallerSummary(), reinstallCommand())
|
||||
}
|
||||
log.Infof("approval response for %s from caller %s: accept=%t view_only=%t",
|
||||
msg.GetRequestId(), id, msg.GetAccept(), msg.GetViewOnly())
|
||||
|
||||
@@ -233,6 +233,15 @@ func unidentifiedSummary(action string) string {
|
||||
"Reinstall the service on a socket that carries the caller's identity.", capitalize(action), ipcauth.PrivilegedActor())
|
||||
}
|
||||
|
||||
// unidentifiableCallerSummary covers an operation that needs to know who is
|
||||
// asking rather than a privileged caller, so unlike unidentifiedSummary it does
|
||||
// not name root: elevating would not help, only moving the daemon onto a socket
|
||||
// that carries the caller's identity.
|
||||
func unidentifiableCallerSummary() string {
|
||||
return "Answering a connection approval requires a control channel that carries the caller's identity, " +
|
||||
"and the daemon's current socket does not. Reinstall the service on one that does."
|
||||
}
|
||||
|
||||
// reinstallCommand is the command that moves the daemon onto a socket whose
|
||||
// callers can be identified.
|
||||
func reinstallCommand() string {
|
||||
|
||||
Reference in New Issue
Block a user