Local control channel: unprivileged users can trigger --force-update via the running service
This commit is contained in:
@@ -0,0 +1,61 @@
|
||||
// Package control exposes a local-only command channel into a running
|
||||
// gpu-turnstile service: a named pipe on Windows, a unix socket on Linux.
|
||||
// It lets unprivileged local users ask the service to do privileged work
|
||||
// that is safe to offer — currently triggering an update check, whose
|
||||
// payload is signature-verified regardless of who asks. The channel never
|
||||
// accepts data beyond a one-word command, and the server rate-limits
|
||||
// triggers, so the worst a local user can cause is a cheap, throttled
|
||||
// check and a GPU-idle-gated restart onto a signed binary.
|
||||
//
|
||||
// Protocol: the client writes one command line, the server answers with
|
||||
// one reply line ("OK ..." or "ERR ...") and hangs up.
|
||||
package control
|
||||
|
||||
import (
|
||||
"bufio"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// CmdUpdateNow asks the service to check for, stage and (once the GPU is
|
||||
// idle) restart onto a signed update immediately.
|
||||
const CmdUpdateNow = "update-now"
|
||||
|
||||
// ErrUnavailable means no running service offers the control channel.
|
||||
var ErrUnavailable = errors.New("control channel unavailable")
|
||||
|
||||
// Handler answers one command; the returned string is sent back as one
|
||||
// line. It must start with "OK " or "ERR ".
|
||||
type Handler func(cmd string) string
|
||||
|
||||
// serveConn runs the line protocol on one accepted connection.
|
||||
func serveConn(c io.ReadWriteCloser, h Handler) {
|
||||
defer c.Close()
|
||||
line, err := bufio.NewReader(io.LimitReader(c, 4096)).ReadString('\n')
|
||||
cmd := strings.TrimSpace(line)
|
||||
if cmd == "" {
|
||||
if err != nil {
|
||||
return
|
||||
}
|
||||
fmt.Fprintln(c, "ERR empty command")
|
||||
return
|
||||
}
|
||||
fmt.Fprintln(c, h(cmd))
|
||||
}
|
||||
|
||||
// readReply writes cmd and reads the server's one-line reply.
|
||||
func readReply(c io.ReadWriteCloser, cmd string) (string, error) {
|
||||
if _, err := fmt.Fprintln(c, cmd); err != nil {
|
||||
return "", err
|
||||
}
|
||||
// The server hangs up after its reply; a broken-pipe error after the
|
||||
// last byte still leaves the reply in the buffer.
|
||||
data, _ := io.ReadAll(io.LimitReader(c, 4096))
|
||||
line := strings.TrimSpace(string(data))
|
||||
if line == "" {
|
||||
return "", ErrUnavailable
|
||||
}
|
||||
return line, nil
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
//go:build linux
|
||||
|
||||
package control
|
||||
|
||||
import (
|
||||
"context"
|
||||
"log/slog"
|
||||
"net"
|
||||
"os"
|
||||
"time"
|
||||
)
|
||||
|
||||
// sockPath lives in the unit's RuntimeDirectory; mode 0666 lets every
|
||||
// local user ask, nothing can reach it from off the machine.
|
||||
const sockPath = "/run/gpu-turnstile/control.sock"
|
||||
|
||||
// Serve starts the socket listener in the background and returns; only a
|
||||
// setup failure is reported. Each client connection is answered in its own
|
||||
// goroutine.
|
||||
func Serve(ctx context.Context, h Handler, log *slog.Logger) error {
|
||||
os.Remove(sockPath) // stale socket from a previous run
|
||||
ln, err := net.Listen("unix", sockPath)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.Chmod(sockPath, 0o666); err != nil {
|
||||
ln.Close()
|
||||
return err
|
||||
}
|
||||
go func() {
|
||||
<-ctx.Done()
|
||||
ln.Close()
|
||||
}()
|
||||
go func() {
|
||||
for {
|
||||
c, err := ln.Accept()
|
||||
if err != nil {
|
||||
return // shutting down
|
||||
}
|
||||
go serveConn(c, h)
|
||||
}
|
||||
}()
|
||||
return nil
|
||||
}
|
||||
|
||||
// Ask sends one command to the running service and returns its reply.
|
||||
func Ask(cmd string) (string, error) {
|
||||
c, err := net.DialTimeout("unix", sockPath, 2*time.Second)
|
||||
if err != nil {
|
||||
return "", ErrUnavailable
|
||||
}
|
||||
defer c.Close()
|
||||
return readReply(c, cmd)
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
//go:build !windows && !linux
|
||||
|
||||
package control
|
||||
|
||||
import (
|
||||
"context"
|
||||
"log/slog"
|
||||
)
|
||||
|
||||
// Serve is a no-op on platforms without a control channel.
|
||||
func Serve(ctx context.Context, h Handler, log *slog.Logger) error {
|
||||
return ErrUnavailable
|
||||
}
|
||||
|
||||
// Ask always reports the channel as unavailable.
|
||||
func Ask(cmd string) (string, error) {
|
||||
return "", ErrUnavailable
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
package control
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestRoundTrip(t *testing.T) {
|
||||
server, client := net.Pipe()
|
||||
go serveConn(server, func(cmd string) string {
|
||||
if cmd != CmdUpdateNow {
|
||||
return "ERR unknown command: " + cmd
|
||||
}
|
||||
return "OK v0.2.2 is up to date"
|
||||
})
|
||||
reply, err := readReply(client, CmdUpdateNow)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if reply != "OK v0.2.2 is up to date" {
|
||||
t.Fatalf("reply = %q", reply)
|
||||
}
|
||||
|
||||
server2, client2 := net.Pipe()
|
||||
go serveConn(server2, func(cmd string) string { return "ERR unknown command: " + cmd })
|
||||
reply, err = readReply(client2, "bogus")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !strings.HasPrefix(reply, "ERR ") {
|
||||
t.Fatalf("reply = %q, want ERR prefix", reply)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEmptyReplyIsUnavailable(t *testing.T) {
|
||||
server, client := net.Pipe()
|
||||
go serveConn(server, func(cmd string) string {
|
||||
server.Close() // hang up without answering
|
||||
return ""
|
||||
})
|
||||
if _, err := readReply(client, CmdUpdateNow); !errors.Is(err, ErrUnavailable) {
|
||||
t.Fatalf("err = %v, want ErrUnavailable", err)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,112 @@
|
||||
//go:build windows
|
||||
|
||||
package control
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"os"
|
||||
"unsafe"
|
||||
|
||||
"golang.org/x/sys/windows"
|
||||
)
|
||||
|
||||
// pipePath is a kernel-local named pipe: no TCP, no firewall prompt.
|
||||
const pipePath = `\\.\pipe\gpu-turnstile`
|
||||
|
||||
// sddlPipe grants full access to Administrators, SYSTEM and the pipe owner,
|
||||
// and read+write to authenticated users — except network logons, so the
|
||||
// pipe cannot be reached from another machine over SMB.
|
||||
const sddlPipe = "D:(D;;GRGW;;;NU)(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;OW)(A;;GRGW;;;AU)"
|
||||
|
||||
var (
|
||||
procConvertSDDL = windows.NewLazySystemDLL("advapi32.dll").
|
||||
NewProc("ConvertStringSecurityDescriptorToSecurityDescriptorW")
|
||||
procWaitNamedPipe = windows.NewLazySystemDLL("kernel32.dll").
|
||||
NewProc("WaitNamedPipeW")
|
||||
)
|
||||
|
||||
func waitNamedPipe(name *uint16, timeout uint32) error {
|
||||
r, _, err := procWaitNamedPipe.Call(uintptr(unsafe.Pointer(name)), uintptr(timeout))
|
||||
if r == 0 {
|
||||
return err
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func securityAttributesFromSDDL(sddl string) (*windows.SecurityAttributes, error) {
|
||||
s, err := windows.UTF16PtrFromString(sddl)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
var sd *uint16 // SECURITY_DESCRIPTOR*, kept for the process lifetime
|
||||
r, _, callErr := procConvertSDDL.Call(
|
||||
uintptr(unsafe.Pointer(s)), 1, /* SDDL_REVISION_1 */
|
||||
uintptr(unsafe.Pointer(&sd)), 0)
|
||||
if r == 0 {
|
||||
return nil, fmt.Errorf("invalid SDDL: %w", callErr)
|
||||
}
|
||||
sa := &windows.SecurityAttributes{
|
||||
Length: uint32(unsafe.Sizeof(windows.SecurityAttributes{})),
|
||||
SecurityDescriptor: (*windows.SECURITY_DESCRIPTOR)(unsafe.Pointer(sd)),
|
||||
}
|
||||
return sa, nil
|
||||
}
|
||||
|
||||
// Serve starts the pipe listener in the background and returns; only a
|
||||
// setup failure is reported. Each client connection is answered in its own
|
||||
// goroutine. On shutdown the process exit reaps everything.
|
||||
func Serve(ctx context.Context, h Handler, log *slog.Logger) error {
|
||||
sa, err := securityAttributesFromSDDL(sddlPipe)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
name, err := windows.UTF16PtrFromString(pipePath)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
go func() {
|
||||
for ctx.Err() == nil {
|
||||
pipe, err := windows.CreateNamedPipe(name,
|
||||
windows.PIPE_ACCESS_DUPLEX,
|
||||
windows.PIPE_TYPE_BYTE|windows.PIPE_READMODE_BYTE|windows.PIPE_WAIT,
|
||||
16, 4096, 4096, 0, sa)
|
||||
if err != nil {
|
||||
log.Warn("control channel stopped", "err", err)
|
||||
return
|
||||
}
|
||||
go func() {
|
||||
// Blocks until a client connects; on process exit the
|
||||
// handle goes away with everything else.
|
||||
if err := windows.ConnectNamedPipe(pipe, nil); err != nil {
|
||||
windows.CloseHandle(pipe)
|
||||
return
|
||||
}
|
||||
f := os.NewFile(uintptr(pipe), pipePath)
|
||||
serveConn(f, h) // closes f, and with it the pipe handle
|
||||
}()
|
||||
}
|
||||
}()
|
||||
return nil
|
||||
}
|
||||
|
||||
// Ask sends one command to the running service and returns its reply.
|
||||
func Ask(cmd string) (string, error) {
|
||||
name, err := windows.UTF16PtrFromString(pipePath)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
if err := waitNamedPipe(name, 2000); err != nil {
|
||||
return "", ErrUnavailable
|
||||
}
|
||||
handle, err := windows.CreateFile(name,
|
||||
windows.GENERIC_READ|windows.GENERIC_WRITE, 0, nil,
|
||||
windows.OPEN_EXISTING, 0, 0)
|
||||
if err != nil {
|
||||
return "", ErrUnavailable
|
||||
}
|
||||
f := os.NewFile(uintptr(handle), pipePath)
|
||||
defer f.Close()
|
||||
return readReply(f, cmd)
|
||||
}
|
||||
@@ -95,6 +95,8 @@ RestartSec=5s
|
||||
|
||||
DynamicUser=yes
|
||||
StateDirectory=%s
|
||||
RuntimeDirectory=%s
|
||||
RuntimeDirectoryMode=0755
|
||||
%sProtectSystem=strict
|
||||
ProtectHome=yes
|
||||
PrivateTmp=yes
|
||||
@@ -117,7 +119,7 @@ SystemCallErrorNumber=EPERM
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
`, exePath, configPath, Name, bind)
|
||||
`, exePath, configPath, Name, Name, bind)
|
||||
}
|
||||
|
||||
// copyFile copies src to dst, creating dst with the given mode.
|
||||
|
||||
@@ -17,6 +17,7 @@ func TestRenderUnit(t *testing.T) {
|
||||
"WantedBy=multi-user.target",
|
||||
"DynamicUser=yes",
|
||||
"StateDirectory=gpu-turnstile",
|
||||
"RuntimeDirectory=gpu-turnstile",
|
||||
"ProtectSystem=strict",
|
||||
"NoNewPrivileges=yes",
|
||||
"RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6",
|
||||
|
||||
Reference in New Issue
Block a user