Validate UID of proxy Unix Domain Socket Peers

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Fixed
    • Priority: Major - P3
    • 8.3.0-rc0
    • Affects Version/s: None
    • Component/s: None
    • None
    • Networking & Observability
    • Fully Compatible
    • N&O 2026-03-02, N&O 2026-03-16
    • 200
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      When a client connects over the proxy Unix Domain Socket, we must validate that it corresponds to a trusted client if the unixProxySocketCheckPermissions parameter is enabled. We may do this by inspecting its SO_PEERCRED object. A trusted client possesses the same UID as the Server, proving that it has access to the same on-disk secrets as the server.

      We should reject all would-be clients of the proxy UDS.

            Assignee:
            Sergei Bazhenov
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: