Skip to main content

ControlToken

Struct ControlToken 

Source
pub struct ControlToken(/* private fields */);
Expand description

A shared secret that proves a control-channel caller is this same user.

§Why this exists

On Unix the daemon asks the kernel which uid is on the other end of the socket and refuses anything that is not its own - see the peer check in the unix module. Windows offers an equivalent, but reaching it means calling ImpersonateNamedPipeClient and comparing security identifiers through raw FFI, and this workspace is unsafe_code = "forbid" from top to bottom. So the Windows control channel served every connection it accepted: anyone who could reach the pipe could spawn a tool-executing agent and answer its approval prompts.

A token closes that without any of the FFI. The daemon writes a fresh random secret into its own directory, readable only by the owner, and refuses any connection that cannot quote it. A caller who can read the file is a caller who can already read config.toml - so the token grants nothing that was not already reachable, which is exactly the property wanted.

It is required on every platform, not only Windows. One protocol is easier to reason about than two, the extra round trip on a local socket is unmeasurable, and on Unix it is defence in depth behind the uid check rather than a replacement for it.

Implementations§

Source§

impl ControlToken

Source

pub fn path(dir: &Path) -> PathBuf

The token file beside the control socket.

Source

pub fn pid_path(dir: &Path) -> PathBuf

Where the daemon records its own process id.

So lev daemon stop has a way through when the control channel does not answer - a wedged daemon, or a token file that went missing. Without it the only recovery was pkill, and the advice to “restart it” was advice that could not work: restart stops before it starts, and the stop was the part that failed.

Source

pub fn write_pid(dir: &Path) -> Result<()>

Record this process as the running daemon.

Source

pub fn read_pid(dir: &Path) -> Option<u32>

The recorded daemon pid, if one was written and still parses.

Source

pub fn create(dir: &Path) -> Result<Self>

Generate a fresh token and write it owner-only.

Called at bind, so a restarted daemon invalidates every previous token - a stale one cannot be replayed against the new process.

Source

pub fn load(dir: &Path) -> Result<Self>

Read the token a running daemon wrote.

Source

pub fn matches(&self, presented: &str) -> bool

Whether presented is this token, compared in constant time.

Constant time because the comparison is against a secret and the caller controls the input: a byte-at-a-time early return leaks the prefix, and a local attacker can retry without limit.

Source

pub fn expose(&self) -> &str

The token itself, for a client that is about to present it.

Trait Implementations§

Source§

impl Clone for ControlToken

Source§

fn clone(&self) -> ControlToken

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ControlToken

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Never render the secret: this type ends up inside daemon state that other code may reasonably want to {:?}.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> ConditionalSend for T
where T: Send,

Source§

impl<T> Downcast for T
where T: Any,

Source§

fn into_any(self: Box<T>) -> Box<dyn Any>

Converts Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>, which can then be downcast into Box<dyn ConcreteType> where ConcreteType implements Trait.
Source§

fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>

Converts Rc<Trait> (where Trait: Downcast) to Rc<Any>, which can then be further downcast into Rc<ConcreteType> where ConcreteType implements Trait.
Source§

fn as_any(&self) -> &(dyn Any + 'static)

Converts &Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &Any’s vtable from &Trait’s.
Source§

fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)

Converts &mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &mut Any’s vtable from &mut Trait’s.
Source§

impl<T> DowncastSend for T
where T: Any + Send,

Source§

fn into_any_send(self: Box<T>) -> Box<dyn Any + Send>

Converts Box<Trait> (where Trait: DowncastSend) to Box<dyn Any + Send>, which can then be downcast into Box<ConcreteType> where ConcreteType implements Trait.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoResult<T> for T

Source§

fn into_result(self) -> Result<T, RunSystemError>

Converts this type into the system output type.
Source§

impl<A> Is for A
where A: Any,

Source§

fn is<T>() -> bool
where T: Any,

Checks if the current type “is” another type, using a TypeId equality comparison. This is most useful in the context of generic logic. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> TypeData for T
where T: 'static + Send + Sync + Clone,

Source§

fn clone_type_data(&self) -> Box<dyn TypeData>

Creates a type-erased clone of this value.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more