Documentation
¶
Index ¶
- func NewAccessControlHandler(acm AccessControl) accesscontrolv1connect.AccessControlServiceHandler
- func NewRequester(info ProcessInfo, si SigningInfo) *accesscontrolv1.Requester
- type AccessControl
- type Anchor
- type AuthorizeRequest
- type CheckAccessRequest
- type CodeStatus
- type ProcessInfo
- type ProcessNode
- type SigningIdentity
- type SigningInfo
- type SigningInfoBase
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func NewAccessControlHandler ¶
func NewAccessControlHandler(acm AccessControl) accesscontrolv1connect.AccessControlServiceHandler
NewAccessControlHandler adapts an ACM implementation to the generated connect handler interface.
func NewRequester ¶
func NewRequester(info ProcessInfo, si SigningInfo) *accesscontrolv1.Requester
NewRequester encodes the caller's identity into its canonical wire form, the inverse of the connect handler's decoding.
Types ¶
type AccessControl ¶
type AccessControl interface {
CheckAccess(ctx context.Context, req CheckAccessRequest) (bool, error)
Authorize(ctx context.Context, req AuthorizeRequest) (secrets.AuthorizeResponse, error)
}
type Anchor ¶
type Anchor uint8
Anchor classifies the root a process's code-signing certificate chain reaches. Values are ordered by increasing trust, so callers may gate on a minimum (e.g. Anchor >= AnchorAppleGeneric).
const ( AnchorNone Anchor = iota // unsigned AnchorAdHoc // ad-hoc: a cdhash but no certificate (Homebrew formula, dev build) AnchorOther // signed with a chain that does not reach an Apple root AnchorAppleGeneric // Developer ID or Mac App Store AnchorApplePlatform // Apple's own platform binaries )
type AuthorizeRequest ¶
type AuthorizeRequest struct {
Patterns []secrets.Pattern
ProcessInfo
SigningInfo
}
type CheckAccessRequest ¶
type CheckAccessRequest struct {
secrets.Pattern
ProcessInfo
SigningInfo
}
type CodeStatus ¶
type CodeStatus uint32
CodeStatus is a bitmask of the dynamic SecCodeStatus flags reported in kSecCodeInfoStatus. The values are fixed by Apple's <Security/SecCode.h>; they are not ours to renumber.
const ( // StatusValid: signature is dynamically valid; cleared if the process was // tampered/invalidated at runtime (e.g. code injection). StatusValid CodeStatus = 0x0001 // StatusHard: kernel refuses to page in invalid pages, so tampered code // will not silently run. StatusHard CodeStatus = 0x0100 // StatusKill: process is killed if it ever becomes invalid. StatusKill CodeStatus = 0x0200 // StatusDebugged: a debugger is/was attached — a red flag for a secrets // connection. StatusDebugged CodeStatus = 0x1000_0000 )
type ProcessInfo ¶
type ProcessNode ¶
type ProcessNode struct {
PID int
// Start is the process start token in µs since epoch
// (p_starttime sec*1e6 + µs). Together with PID it forms an instance
// identity that survives PID reuse.
Start int64
// UID is the target process's effective uid.
UID int
// Comm is the kernel's process name (p_comm, 16 characters max, no root permissions required).
Comm string
// Exe is the executable path exactly as the kernel reports it (proc_pidpath).
Exe string
// RealExe is Exe with symlinks resolved, falling back to Exe.
RealExe string
// Mtime is the modification time of RealExe, UTC.
Mtime time.Time
// Args is the process argv via sysctl(KERN_PROCARGS2). Same-uid only
// and best-effort: nil when unreadable. Self-reported by the process.
Args []string
}
ProcessNode is one process in the ancestry chain.
type SigningIdentity ¶
type SigningIdentity struct {
SigningInfoBase
// TeamID is the Apple-assigned Team Identifier (kSecCodeInfoTeamIdentifier),
// Apple guarantees this is unique per developer account.
TeamID string
// Identifier is the code signing identifier (kSecCodeInfoIdentifier),
// typically the bundle ID, e.g. "com.docker.docker". Use to pin a specific
// application within a team.
Identifier string
// Organization is the company name from the leaf certificate subject.O,
// e.g. "Docker Inc". Human-readable but NOT guaranteed unique or immutable,
// so suitable for display/logging rather than as a sole trust key.
Organization string
// BundleName is the app name from the signed Info.plist
// (CFBundleDisplayName, falling back to CFBundleName), e.g.
// "Docker Desktop". Empty when the binary embeds no Info.plist.
// Display-only: not unique, chosen by the signer.
BundleName string
// CommonName is the leaf certificate subject.CN, e.g.
// "Developer ID Application: Docker Inc (<team-id>)". Contains the company
// name and TeamID as embedded display text.
CommonName string
// CDHash is the code directory hash (kSecCodeInfoUnique), the exact identity
// of this specific binary build, hex-encoded. Use to pin an exact build.
CDHash string
// Status is the dynamic code signing status word (kSecCodeInfoStatus) — the
// kernel's live view of the signature, as opposed to the static on-disk
// signature. See CodeStatus for the individual flags. Validity is already
// enforced by SecCodeCheckValidityWithErrors, so this is primarily
// corroborating/diagnostic (notably the Debugged flag).
Status CodeStatus
// Anchor classifies the root the certificate chain reaches.
Anchor Anchor
}
SigningIdentity is the verified code-signing identity of a single process.
type SigningInfo ¶
type SigningInfo struct {
// Root is the code-signing identity of the outermost recorded ancestor.
Root *SigningIdentity
// Leaf is the code-signing identity of the process that connected to
// the socket (last chain element).
Leaf *SigningIdentity
// Chain is the leaf's process ancestry ordered root to leaf. For a single-node
// chain Root and Leaf describe the same process.
Chain []ProcessNode
}
SigningInfo describes the code-signing identity of the requesting process and its process ancestry.
type SigningInfoBase ¶
type SigningInfoBase struct {
SignedByDocker bool
}