DashboardopencodePrivileged PTY launch boundary

Privileged PTY launch boundary

Category: architecture
Confidence: 1.00
ID: 01a0b3c3-5ec0-7853-9704-244575a7cca5
Project ID: c0425955-02bc-4c17-9af2-b114c00077e7
Cross-project: No
Recalled in other projects: 0
Source session: 1NVyZh8FhrP3Z3Yh1
Created: 2026-09-08 04:21:04
Updated: 2026-09-18 09:05:20

Content

Authenticate the connection lifetime with a pidfd and reassert identity immediately before StartTransientUnit: verify exact UID/GID, active systemd MainPID, InvocationID, and service cgroup, keeping the CLOEXEC pidfd open through launch. Peer credentials alone do not authenticate the current connection holder. Generate supervisor-owned names matching opencode-pty-[0-9a-f]{32}.service. Accept no client environment or systemd property names; the launcher must clearenv() and set only approved variables. Use go-systemd v22.5.0 on Go 1.22 and direct D-Bus Unix-FD properties, passing one duplex PTY stream and the approved cwd descriptor; avoid systemd-run and hand-written D-Bus transport.

Move to: