Skip to content

feat: activate owner-only Unix capture IPC - #65

Merged
kev1n77 merged 2 commits into
mainfrom
codex/macos-unix-ipc-acl
Jul 21, 2026
Merged

kev1n77 merged 2 commits into
mainfrom
codex/macos-unix-ipc-acl

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 21, 2026

Copy link
Copy Markdown
Owner

Summary

  • activate POSIX Unix-domain capture IPC on macOS and Linux while retaining loopback TCP on Windows
  • create the socket inside an eUID-owned 0700 directory, enforce 0600 socket mode, reject symlink/wrong-owner paths, and remove the socket on listener drop
  • verify every Unix connection against kernel-reported peer eUID and launched sidecar PID before reading authenticated frames
  • add Rust and Tauri-level coverage and update security, threat-model, and progress documentation

Verification

  • cargo fmt --all -- --check
  • git diff --check
  • cargo test -p codeischeap-capture-ipc --all-targets (12 passed)
  • cargo clippy -p codeischeap-capture-ipc --all-targets -- -D warnings
  • python -m unittest discover -s sidecars/mitmproxy/tests -v (24 passed, 2 Unix-only tests skipped on Windows)

Local environment note

A full Tauri/workspace rebuild is not available on this Windows machine because the installed Git Perl lacks Locale::Maketext::Simple, which is required by the vendored OpenSSL/SQLCipher build. Cross-platform CI is the authoritative native build check.

@kev1n77
kev1n77 merged commit 7fa5273 into main Jul 21, 2026
9 checks passed
@kev1n77
kev1n77 deleted the codex/macos-unix-ipc-acl branch July 21, 2026 05:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant