hookd: restrict and authenticate the hook socket #282

closed cmc opened this on 2026-09-28 04:33 UTC · control security

Discussion

cmc 2026-09-28 04:33 UTC

The hook socket (<root>/hook.sock, internal/hookd/hookd.go, Serve) trusts the repository id, user id and key scope in each request. Any process that can connect can ask for a push decision as any user and trigger post-receive side effects as them. Its only protection is the data directory's permissions; the socket itself is created with the process umask and no explicit mode.

  • chmod 0600 the socket after Listen.
  • Check the peer's uid with SO_PEERCRED (Linux) and refuse other users.
  • Consider a per-push token passed to the hook in its environment, so a request must name a receive-pack the daemon started.

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

closed by cmc in commit 5c2215b845: sshd: mint a push token per receive-pack; hook sends it

2026-09-28 21:50 UTC

referenced in commit 135af80d08 by cmc: hookd: 0600 socket, peer uid check, push token required

2026-09-28 21:50 UTC

referenced in commit c40a116572 by cmc: store: push tokens for receive-pack

2026-09-28 21:50 UTC