Files
fips/src/gateway
Johnathan Corgan 2517d20751 Create the control socket and its directory with a restrictive mode
bind(2) creates the socket inode with 0777 & ~umask, so under a permissive
umask the control socket was world-accessible for the window between the
bind and the chmod to 0770 that followed it. The parent directory was
worse than a window: create_dir_all takes the same 0777 & ~umask and
nothing ever set a mode on it, so the directory holding the socket stayed
world-writable for the life of the host, and a world-writable parent lets
an unprivileged account plant an entry at the socket path.

Add a small shared helper that binds under a umask masking the "other"
bits and creates directories with an explicit 0750. The socket ends at the
mode it always did, with the existing chmod and chown left as the
authority on it, and 0750 is what the systemd unit and the FreeBSD rc
script already apply to the runtime directory, so no packaged deployment
sees a different mode. The umask is held across the bind alone, and it
only clears bits, so anything else created in that window comes out more
restrictive rather than less. Both the daemon and gateway control sockets
go through the helper; the duplicated bind sequences stay as they are.

The window between the stale-socket probe and the bind is documented at
both sites rather than closed: reaching it needs write access to the
socket's parent directory, which the packaged layouts give to root alone,
and an account holding it can deny the daemon its socket more simply by
squatting the path first.
2026-08-23 11:45:30 +01:00
..
2026-04-09 16:53:32 +00:00
2026-04-10 08:47:02 +00:00