pub fn peer_credentials(stream: &UnixStream) -> Result<LocalPrincipal, Error>Expand description
The credentials the kernel attributes to the peer of stream.
This is the whole of a local peer’s identity: there is no key, no certificate and nothing the peer asserts about itself — the kernel says what it is, which is why it can be trusted at all (decisions/0010 §4.4, §4.5).
Taken at accept or connect time, which is when SO_PEERCRED captures
them; they are not re-read per message, and re-reading would not help:
the values are a snapshot of the peer as it was when the socket was
created (docs/research/ipc.md §1.5). The pid is an Option because
macOS’s LOCAL_PEERCRED reports none, and because a pid is an
observation — it may be reused — rather than an identity.
A protocol that uses this as an authorization input should say so
explicitly: libzmq’s ZMQ_IPC_FILTER_UID/_GID/_PID did exactly this
and are deprecated in favour of ZAP, which is a decision about where
authorization lives and not about whether the kernel’s answer is true
(docs/research/zeromq.md §10).