hookd: authenticate the hook socket !494

merged merged by cmc on 2026-09-28 21:50 UTC · krz/gitbay:hook-socket-auth into main

Discussion

cmc

The hook socket authenticates its caller.

  • hook.sock is mode 0600. On Linux, hookd refuses a peer whose uid (SO_PEERCRED) is not the daemon's.
  • sshd mints a push token for each receive-pack (migration 0063 push_tokens, stored as a SHA-256 hash, 24-hour expiry, deleted when receive-pack returns, swept by retention) and passes it to the hook in GITBAY_PUSH_TOKEN. hookd refuses a request without a live token matching its repository, account and scope.
  • Architecture 03/04 and Known-Gaps; CHANGELOG.

Deploy with no push in flight: a receive-pack started by the old daemon has no token, and its post-receive is refused by the new one.

Stacked on the mirror MR (mirror-pin-address).

Closes #282