Hello,
Thanks for the earlier reply. Following your suggestion, the rework uses the
Linux socket option instead of the fstat approach:
getsockopt(fd, SOL_SOCKET, SO_PEERCRED, &ucred, &len)
struct ucred { pid_t pid; uid_t uid; gid_t gid; }
pflocal records the peer's uid/gid and returns them from S_socket_getopt;
io_stat/fstat are unchanged. The series also sets the credentials on the
connecting socket and on both socketpair() ends, and declares SO_PEERCRED /
struct ucred (under __USE_GNU, like Linux) in a separate glibc header patch.
SO_PEERCRED value: I used 0x1009. What is the process to get this value
agreed? Should I send the glibc header patch first?
Credential timing. Linux records the credentials in effect at
connect(2)/listen(2)/socketpair(2). The Hurd socket takes the uid/gid from
the protid used to create it, so a process that changes uid/gid between
socket() and connect() is reported with its old identity, and a listening
socket's uid is fixed at socket() rather than listen(). The socket RPCs
carry the socket port, not the caller's auth, so connect()-time sampling
would need glibc to pass the caller's identity or a protocol change.
Thanks,
David