Skip to main content

peer_credentials

Function peer_credentials 

Source
pub fn peer_credentials(stream: &UnixStream) -> Result<LocalPrincipal, Error>
Expand description

The credentials the kernel attributes to the peer of stream.

This is the whole of a local peer’s identity: there is no key, no certificate and nothing the peer asserts about itself — the kernel says what it is, which is why it can be trusted at all (decisions/0010 §4.4, §4.5).

Taken at accept or connect time, which is when SO_PEERCRED captures them; they are not re-read per message, and re-reading would not help: the values are a snapshot of the peer as it was when the socket was created (docs/research/ipc.md §1.5). The pid is an Option because macOS’s LOCAL_PEERCRED reports none, and because a pid is an observation — it may be reused — rather than an identity.

A protocol that uses this as an authorization input should say so explicitly: libzmq’s ZMQ_IPC_FILTER_UID/_GID/_PID did exactly this and are deprecated in favour of ZAP, which is a decision about where authorization lives and not about whether the kernel’s answer is true (docs/research/zeromq.md §10).