dbus: gate the bus socket like INIT_SOCKET

The D-Bus socket was bound world read/write, on the reasoning that
SO_PEERCRED authorizes each method anyway.  That leaves the read-only
surface open to every local user, and it quietly ignores --with-group:
a system that restricts initctl to the wheel group still handed the
same service state to anyone who asked over the bus.

Bind it 0660 and chown it to the configured group, the same gate the
fallback socket has always had.  libink takes the mode as an argument
rather than assuming one, since who may connect is the embedder's
policy, not the library's.

The mode is applied at bind(), so there is no window where the socket
is more permissive than intended.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit is contained in:
Joachim Wiberg
2026-08-13 10:14:48 +02:00
parent c71ccce742
commit d710a23513
6 changed files with 33 additions and 10 deletions
+5 -1
View File
@@ -90,7 +90,11 @@ typedef struct {
/* ---------- server / connection lifecycle ---------- */
int link_server_new (link_server_t **server, const char *path);
/* Bind a listening socket at `path` with file mode `mode`, e.g. 0660
* to keep it to root and one group. The mode is applied at bind(),
* so the socket is never briefly more permissive than asked; setting
* the owning group afterwards is the caller's job. */
int link_server_new (link_server_t **server, const char *path, mode_t mode);
void link_server_free (link_server_t *server);
int link_server_get_fd(const link_server_t *server);