From: Guillaume Marcais Date: 2004-05-20T03:41:26+09:00 Subject: Re: RCR: UNIX credentials So, should we implement a UNIXSocket#getpeerid method, using getpeerid() or SO_PEERCRED, depending on what's available? The way of doing things with getpeerid seems more natural than SCM_CREDS. I'll resumit an RCR. Guillaume. On Wed, 2004-05-19 at 10:16, Tanaka Akira wrote: > In article <1084926982.2388.130.camel@comp>, > Guillaume Marcais writes: > > > The Linux system provide a mechanism to send UNIX credentials as > > ancilary data (the same way as you can pass file descriptors, > > implemented in Ruby as send_io). Other UNIX implementation I believe > > offer similar mechanism. > > I surveyed the feature sometime ago. > Unfortunately it is not so portable. > > 1. SCM_CREDS and getpeerid. > > There are 2 kind of interfaces. > SCM_CREDS: a client must send a credential explicitly. > getpeerid: a client doesn't need to send a credential. > > 2. getpeerid > > As far as I know, following system has getpeerid or similar. > > FreeBSD 4.6 (LOCAL_PEERCRED, http://www.freebsd.org/cgi/cvsweb.cgi/src/lib/libc/gen/getpeereid.3) > OpenBSD 3.0 (http://www.openbsd.org/cgi-bin/man.cgi?query=getpeereid&sektion=2) > Linux (socket(7): getsockopt SO_PEERCRED) > MacOS X (http://www.hmug.org/man/3/getpeereid.html) > > DJB recommends getpeerid. > http://cr.yp.to/docs/secureipc.html > > 2. SCM_CREDS > > As far as I know, following system has SCM_CREDS or similar. > However, credential information varies on each system. > > FreeBSD 3.0 (recvmsg(2): SCM_CREDS: pid, uid, euid, gid, supp groups) > NetBSD 1.4.0 (unix(4): LOCAL_CREDS, SCM_CREDS: uid, euid, gid, egid, supp groups: http://www.netbsd.org/Changes/changes-1.4.html) > OpenBSD 2.5 (SCM_CREDS: uid, euid, gid, egid, supp groups) > Linux (unix(7): SCM_CREDENTIALS: pid, uid, gid) > > 3. send_io/recv_io may be usable for authentication. > > See: Secure UNIX Programming FAQ > 4.4) How do I authenticate a non-parent process? > http://www.whitefang.com/sup/secure-faq.html > -- > Tanaka Akira >