Expand description
The contract every custom hook in this server runs under: one script, a
cleared environment, JSON on stdin, an exit code for the verdict.
Three subsystems delegate to an operator-supplied script —
signer::custom (issue/revoke/crl/renewal_info),
filter::custom (connection/identifiers) and
notify::custom (one event). They differ in what
they put in the environment, what they do with stdout, and how they read the
exit code. They differ in nothing else.
What they shared was a security contract — clear the environment so a
script cannot read the RFC 2136 TSIG secret or the SMTP password, restore a
minimal PATH, kill the child when its deadline passes, and bound how much
it may write ([MAX_SCRIPT_OUTPUT_BYTES]) — written out three times, token
for token. That is exactly the kind of thing that has to exist once: a
hardening applied to one copy is silently absent from the other two, and
nobody reviewing one of them can tell.
Structs§
- Script
Hook - An operator-supplied script, and the budget it runs under.
- Script
Outcome - What a script answered, plus whether it ever read the question.
Enums§
- Script
Error - Why a script produced no verdict at all — as opposed to producing one this
caller did not like, which is
ScriptOutcome’s business. - Script
Stdin - What to hand the script on stdin.