mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 11:38:24 +00:00
bind(2) creates the socket inode with 0777 & ~umask, so under a permissive umask the control socket was world-accessible for the window between the bind and the chmod to 0770 that followed it. The parent directory was worse than a window: create_dir_all takes the same 0777 & ~umask and nothing ever set a mode on it, so the directory holding the socket stayed world-writable for the life of the host, and a world-writable parent lets an unprivileged account plant an entry at the socket path. Add a small shared helper that binds under a umask masking the "other" bits and creates directories with an explicit 0750. The socket ends at the mode it always did, with the existing chmod and chown left as the authority on it, and 0750 is what the systemd unit and the FreeBSD rc script already apply to the runtime directory, so no packaged deployment sees a different mode. The umask is held across the bind alone, and it only clears bits, so anything else created in that window comes out more restrictive rather than less. Both the daemon and gateway control sockets go through the helper; the duplicated bind sequences stay as they are. The window between the stale-socket probe and the bind is documented at both sites rather than closed: reaching it needs write access to the socket's parent directory, which the packaged layouts give to root alone, and an account holding it can deny the daemon its socket more simply by squatting the path first.