The hook socket (<root>/hook.sock, internal/hookd/hookd.go, Serve) trusts the repository id, user id and key scope in each request. Any process that can connect can ask for a push decision as any user and trigger post-receive side effects as them. Its only protection is the data directory's permissions; the socket itself is created with the process umask and no explicit mode.
chmod 0600the socket afterListen.- Check the peer's uid with
SO_PEERCRED(Linux) and refuse other users. - Consider a per-push token passed to the hook in its environment, so a request must name a receive-pack the daemon started.
referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews
2026-09-28 05:43 UTC