mirror of
https://github.com/rwinkhart/rcw.git
synced 2026-08-28 04:46:42 -04:00
Close listener when daemon is killed due to failed RPC auth
This commit is contained in:
@@ -61,7 +61,7 @@ func Start(passphrase string) {
|
|||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
// use a goroutine to check the client's identity
|
// use a goroutine to check the client's identity
|
||||||
go handleConn(conn)
|
go handleConn(conn, sigChan)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -71,7 +71,7 @@ func Start(passphrase string) {
|
|||||||
// The passphrase is only returned if the client's executable hash matches the daemon's hash
|
// The passphrase is only returned if the client's executable hash matches the daemon's hash
|
||||||
// and if the request is coming from the same user.
|
// and if the request is coming from the same user.
|
||||||
// This ensures that only the binary the daemon is embedded in can retrieve the passphrase.
|
// This ensures that only the binary the daemon is embedded in can retrieve the passphrase.
|
||||||
func handleConn(conn net.Conn) {
|
func handleConn(conn net.Conn, sigChan chan os.Signal) {
|
||||||
ucred := peercred.Get(conn)
|
ucred := peercred.Get(conn)
|
||||||
|
|
||||||
// check if the RPC call is coming from an identical binary and from the same user
|
// check if the RPC call is coming from an identical binary and from the same user
|
||||||
@@ -84,6 +84,6 @@ func handleConn(conn net.Conn) {
|
|||||||
// log the client's path, and kill the daemon
|
// log the client's path, and kill the daemon
|
||||||
conn.Close()
|
conn.Close()
|
||||||
log.Printf("Request received from invalid client: PID(%d), UID(%s), Path(%s)", ucred.PID, ucred.UID, callingBinPath) // TODO log to file
|
log.Printf("Request received from invalid client: PID(%d), UID(%s), Path(%s)", ucred.PID, ucred.UID, callingBinPath) // TODO log to file
|
||||||
os.Exit(2)
|
sigChan <- syscall.SIGTERM
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -83,13 +83,13 @@ func Start(passphrase string) {
|
|||||||
timer.Reset(3 * time.Minute)
|
timer.Reset(3 * time.Minute)
|
||||||
|
|
||||||
// use a goroutine to check the client's identity
|
// use a goroutine to check the client's identity
|
||||||
go handleConn(conn)
|
go handleConn(conn, sigChan)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// handleConn verifies the identity of the client.
|
// handleConn verifies the identity of the client.
|
||||||
// It gets the PID of the client process and verifies it's running the same binary
|
// It gets the PID of the client process and verifies it's running the same binary
|
||||||
func handleConn(conn net.Conn) {
|
func handleConn(conn net.Conn, sigChan chan os.Signal) {
|
||||||
ucred := peercred.Get(conn)
|
ucred := peercred.Get(conn)
|
||||||
|
|
||||||
// get server SID (UID)
|
// get server SID (UID)
|
||||||
@@ -107,6 +107,7 @@ func handleConn(conn net.Conn) {
|
|||||||
// log the client's path, and kill the daemon
|
// log the client's path, and kill the daemon
|
||||||
conn.Close()
|
conn.Close()
|
||||||
log.Printf("Request received from invalid client: PID(%d), UID(%s), Path(%s)", ucred.PID, ucred.UID, callingBinPath) // TODO log to file
|
log.Printf("Request received from invalid client: PID(%d), UID(%s), Path(%s)", ucred.PID, ucred.UID, callingBinPath) // TODO log to file
|
||||||
|
sigChan <- syscall.SIGTERM
|
||||||
os.Exit(2)
|
os.Exit(2)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user