feat: authenticate Windows command launcher and signal helper
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
package windows
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
)
|
||||
|
||||
// Wire payloads are JSON only inside the authenticated private pipe. The
|
||||
// outer frame still supplies a bounded binary length, generation and digest;
|
||||
// JSON keeps the launcher mode stateless and makes malformed-field rejection
|
||||
// explicit rather than relying on Go's gob type registry.
|
||||
type launcherHello struct {
|
||||
PID uint32 `json:"pid"`
|
||||
Creation uint64 `json:"creation"`
|
||||
SessionID uint32 `json:"session_id"`
|
||||
Effective string `json:"effective_sid"`
|
||||
}
|
||||
|
||||
type launcherRequest struct {
|
||||
ApplicationName string `json:"application_name"`
|
||||
CommandLine string `json:"command_line"`
|
||||
WorkingDirectory string `json:"working_directory"`
|
||||
Environment []uint16 `json:"environment"`
|
||||
}
|
||||
|
||||
type launcherShellPrepared struct {
|
||||
PID uint32 `json:"pid"`
|
||||
Creation uint64 `json:"creation"`
|
||||
}
|
||||
|
||||
type signalHelperRequest struct {
|
||||
PID uint32 `json:"pid"`
|
||||
Creation uint64 `json:"creation"`
|
||||
SessionID uint32 `json:"session_id"`
|
||||
}
|
||||
|
||||
type signalHelperResult struct {
|
||||
Delivered bool `json:"delivered"`
|
||||
Detail string `json:"detail"`
|
||||
}
|
||||
|
||||
func marshalLauncherPayload(value any) ([]byte, error) {
|
||||
payload, err := json.Marshal(value)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if len(payload) > launcherMaxFrameBytes {
|
||||
return nil, fmt.Errorf("launcher payload exceeds %d bytes", launcherMaxFrameBytes)
|
||||
}
|
||||
return payload, nil
|
||||
}
|
||||
|
||||
func unmarshalLauncherPayload(payload []byte, target any) error {
|
||||
if len(payload) == 0 || len(payload) > launcherMaxFrameBytes {
|
||||
return fmt.Errorf("launcher payload length %d is invalid", len(payload))
|
||||
}
|
||||
return json.Unmarshal(payload, target)
|
||||
}
|
||||
Reference in New Issue
Block a user