goldwarden/agent/sockets/callingcontext.go

85 lines
2.0 KiB
Go
Raw Normal View History

2023-07-17 04:23:26 +03:00
package sockets
import (
"net"
"os/user"
"time"
2023-07-17 04:23:26 +03:00
gops "github.com/mitchellh/go-ps"
"inet.af/peercred"
)
type CallingContext struct {
UserName string
ProcessName string
ParentProcessName string
GrandParentProcessName string
2023-09-12 19:56:35 +03:00
ProcessPid int
ParentProcessPid int
GrandParentProcessPid int
2023-07-17 04:23:26 +03:00
}
func GetCallingContext(connection net.Conn) CallingContext {
creds, err := peercred.Get(connection)
errorContext := CallingContext{
UserName: "unknown user",
ProcessName: "unknown process",
ParentProcessName: "unknown parent",
GrandParentProcessName: "unknown grandparent",
ProcessPid: time.Now().UTC().Nanosecond(),
ParentProcessPid: time.Now().UTC().Nanosecond(),
GrandParentProcessPid: time.Now().UTC().Nanosecond(),
}
2023-07-17 04:23:26 +03:00
if err != nil {
return errorContext
2023-07-17 04:23:26 +03:00
}
pid, _ := creds.PID()
process, err := gops.FindProcess(pid)
if err != nil {
return errorContext
}
if process == nil {
return errorContext
}
2023-09-19 23:27:03 +03:00
// git is epheremal and spawns ssh-keygen and ssh so we need to anchor to git
if process.Executable() == "ssh-keygen" || process.Executable() == "ssh" {
p, e := gops.FindProcess(process.PPid())
if p.Executable() == "git" && e == nil {
process, err = p, e
pid = process.Pid()
}
2023-09-19 23:14:03 +03:00
}
uid, _ := creds.UserID()
2023-07-17 04:23:26 +03:00
ppid := process.PPid()
if err != nil {
return errorContext
2023-07-17 04:23:26 +03:00
}
2023-09-12 03:54:46 +03:00
2023-07-17 04:23:26 +03:00
parentProcess, err := gops.FindProcess(ppid)
if err != nil {
return errorContext
2023-07-17 04:23:26 +03:00
}
parentParentProcess, err := gops.FindProcess(parentProcess.PPid())
if err != nil {
return errorContext
2023-07-17 04:23:26 +03:00
}
username, err := user.LookupId(uid)
if err != nil {
return errorContext
2023-07-17 04:23:26 +03:00
}
return CallingContext{
UserName: username.Username,
ProcessName: process.Executable(),
ParentProcessName: parentProcess.Executable(),
GrandParentProcessName: parentParentProcess.Executable(),
2023-09-12 19:56:35 +03:00
ProcessPid: pid,
ParentProcessPid: ppid,
GrandParentProcessPid: parentParentProcess.PPid(),
2023-07-17 04:23:26 +03:00
}
}