pub struct WindowsPrincipal {
pub sid: Arc<str>,
pub pid: Option<u32>,
}Expand description
A principal the kernel proved, on a Windows named pipe.
The client’s token SID, read through ImpersonateNamedPipeClient on the
serving side and captured once at connect time
(docs/research/ipc.md §3.3, [0010 §4.4]). The same two rules as
LocalPrincipal: the credential is the one taken at connect, and the
PID is an observation that MUST NOT be authorized on — GetNamedPipe ClientProcessId reports it and nothing signs it.
A separate type rather than a third field set on LocalPrincipal,
because a SID and a uid are not comparable values and a caller that
authorizes on one must be made to say which. The SID is an Arc<str>
rather than a String so that a PeerIdentity stays a refcount bump
to clone: it is copied into every incoming transfer’s metadata, and a
string allocation there would be one per message.
Fields§
§sid: Arc<str>The account SID in its string form (S-1-5-21-...).
pid: Option<u32>The client process id, where the pipe reports one. An observation only.