mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-02 02:38:51 -04:00
128 lines
4.5 KiB
Go
128 lines
4.5 KiB
Go
// Package ipcauth provides the kernel-authenticated identity of a local IPC
|
|
// (gRPC) caller and the transport credentials that surface it into the gRPC
|
|
// context, so the daemon can authorize individual RPCs by caller identity.
|
|
//
|
|
// On Unix the identity is read from the kernel via SO_PEERCRED (Linux) or
|
|
// LOCAL_PEERCRED (Darwin/FreeBSD). On Windows it is derived from the
|
|
// named-pipe client token. Platforms without a peer-identity primitive get no
|
|
// credentials, and every consumer must fail closed when no identity is
|
|
// available.
|
|
package ipcauth
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"slices"
|
|
|
|
"google.golang.org/grpc/credentials"
|
|
"google.golang.org/grpc/peer"
|
|
)
|
|
|
|
// Well-known Windows SIDs that identify a fully privileged principal.
|
|
const (
|
|
sidLocalSystem = "S-1-5-18" // NT AUTHORITY\SYSTEM
|
|
sidLocalService = "S-1-5-19" // NT AUTHORITY\LOCAL SERVICE
|
|
sidNetworkService = "S-1-5-20" // NT AUTHORITY\NETWORK SERVICE
|
|
sidAdministrators = "S-1-5-32-544" // BUILTIN\Administrators
|
|
)
|
|
|
|
// Identity is the kernel-authenticated identity of a local IPC caller. The
|
|
// zero value is not a valid identity: consumers must only use one obtained
|
|
// with a true ok/nil error return.
|
|
type Identity struct {
|
|
// UID and GID are the caller's Unix user ID and primary group ID. Both are
|
|
// zero on Windows, where SID is authoritative instead.
|
|
UID uint32
|
|
GID uint32
|
|
|
|
// SID is the caller's Windows security identifier, empty on Unix.
|
|
SID string
|
|
|
|
// Groups holds the caller's Windows group SIDs, captured from the client
|
|
// token at handshake time. Only groups that are enabled and not
|
|
// deny-only are captured, so a group listed here is one the caller can
|
|
// actually exercise. Empty on Unix.
|
|
Groups []string
|
|
|
|
// Elevated reports whether the Windows client token is elevated (running
|
|
// as administrator, or an administrator with UAC turned off). Always false
|
|
// on Unix, where privilege is uid 0.
|
|
Elevated bool
|
|
|
|
// PID is the caller's process ID where the platform reports it (Linux's
|
|
// SO_PEERCRED), and 0 where it does not. It identifies the daemon's own
|
|
// process dialling itself, which is what the JSON gateway does, and is never
|
|
// used to grant anything.
|
|
PID int32
|
|
}
|
|
|
|
// IsWindows reports whether this identity is a Windows principal (SID-based)
|
|
// rather than a Unix uid/gid principal.
|
|
func (i Identity) IsWindows() bool {
|
|
return i.SID != ""
|
|
}
|
|
|
|
// IsPrivileged reports whether the caller is the platform's administrative
|
|
// principal, which is what the daemon requires for changes that cross the
|
|
// user-to-root boundary.
|
|
//
|
|
// On Windows the decision comes from the caller's token rather than from
|
|
// account names or group RIDs: an elevated token, one of the service accounts
|
|
// the daemon itself may run as, or a token with BUILTIN\Administrators
|
|
// enabled. A UAC-filtered administrator has that group marked deny-only, and
|
|
// deny-only groups are dropped when the identity is captured, so such a
|
|
// caller is correctly reported as unprivileged. Domain group memberships
|
|
// (Domain Admins and friends) are deliberately not consulted: they say
|
|
// nothing about what this token may do on this machine.
|
|
func (i Identity) IsPrivileged() bool {
|
|
if !i.IsWindows() {
|
|
return i.UID == 0
|
|
}
|
|
|
|
if i.Elevated {
|
|
return true
|
|
}
|
|
|
|
switch i.SID {
|
|
case sidLocalSystem, sidLocalService, sidNetworkService:
|
|
return true
|
|
}
|
|
|
|
return slices.Contains(i.Groups, sidAdministrators)
|
|
}
|
|
|
|
// String renders the identity for audit logs and denial messages.
|
|
func (i Identity) String() string {
|
|
if i.IsWindows() {
|
|
return fmt.Sprintf("sid=%s elevated=%t", i.SID, i.Elevated)
|
|
}
|
|
return fmt.Sprintf("uid=%d gid=%d", i.UID, i.GID)
|
|
}
|
|
|
|
// AuthInfo carries the peer Identity as a gRPC credentials.AuthInfo so
|
|
// handlers can retrieve it from the request context via IdentityFromContext.
|
|
type AuthInfo struct {
|
|
credentials.CommonAuthInfo
|
|
Identity Identity
|
|
}
|
|
|
|
// AuthType identifies the authentication scheme.
|
|
func (AuthInfo) AuthType() string { return "netbird-ipc-peercred" }
|
|
|
|
// IdentityFromContext extracts the caller's kernel-authenticated identity from
|
|
// the gRPC peer context. The second return value is false when no IPC
|
|
// transport credentials were negotiated, which happens on a TCP daemon socket
|
|
// and on platforms without a peer-identity primitive. Callers MUST fail closed
|
|
// in that case.
|
|
func IdentityFromContext(ctx context.Context) (Identity, bool) {
|
|
p, ok := peer.FromContext(ctx)
|
|
if !ok {
|
|
return Identity{}, false
|
|
}
|
|
info, ok := p.AuthInfo.(AuthInfo)
|
|
if !ok {
|
|
return Identity{}, false
|
|
}
|
|
return info.Identity, true
|
|
}
|