HomeClusterLabs Projects

High: pacemakerd vs. IPC/procfs confused deputy authenticity issue (3/4)

Description

High: pacemakerd vs. IPC/procfs confused deputy authenticity issue (3/4)

[3/4: other daemons to authenticate IPC servers of fellow processes]

Now that CVE-2018-16877 issue alone is still only partially covered
based on the preceding commits in the set, put the server-by-client
authentication (enabled and 1/3 and partially sported in 2/3) into
practice widely amongst the communicating pacemaker child daemons and
towards CPG API provided by 3rd party but principally using the same
underlying IPC mechanism facilitated by libqb, and consequently close
the remaining "big gap".

As a small justification to introducing yet another "return
value" int variable, type-correctness is restored for those
that shall be cs_error_t to begin with.

Details

Provenance
Jan Pokorný <jpokorny@redhat.com>Authored on Apr 15 2019, 6:13 PM
Parents
rP970736b1c7ad: High: pacemakerd vs. IPC/procfs confused deputy authenticity issue (2/4)
Branches
Unknown
Tags
Unknown

Event Timeline