Bind the daemon unix sockets owner-only so a permissive umask cannot expose them

This commit is contained in:
Viktor Liu
2026-09-16 11:20:11 +02:00
parent 5da30d9132
commit a9669d8f63
4 changed files with 69 additions and 0 deletions
@@ -4,6 +4,7 @@ package cmd
import (
"fmt"
"net"
"golang.org/x/sys/windows"
@@ -47,6 +48,14 @@ func checkAllowGroupSet([]string) error { return nil }
// afterwards. See allowedPipeSDDL.
func applySocketAccess(string, []string) error { return nil }
// listenUnixPrivate binds a Unix socket. Windows has no umask, and a Unix
// socket there carries no mode the daemon could narrow, so there is nothing to
// do beyond binding it. A restriction on this transport is refused before it
// gets here: see listenOnAddress.
func listenUnixPrivate(address string) (net.Listener, error) {
return net.Listen("unix", address)
}
// allowedPipeSDDL renders the security descriptor for the daemon control pipe.
// An empty principal list yields the descriptor that lets any local caller
// connect.