Skip to content

fix(daemon): allow CAP_CHOWN for operator IPC socket - #149

Merged
gRoussac merged 1 commit into
Interchouette-ITC:devfrom
Interchouette:fix/daemon-cap-chown-ipc-socket
Sep 16, 2026
Merged

gRoussac merged 1 commit into
Interchouette-ITC:devfrom
Interchouette:fix/daemon-cap-chown-ipc-socket

Conversation

@Interchouette

Copy link
Copy Markdown
Member

Summary

  • Add CAP_CHOWN to interfired.service so the daemon can chown the Unix IPC socket to group interfire after bind.
  • Without it, interfired exits immediately, /run/interfire/interfired.sock never stays up, and clients get a missing-socket error.
  • Document the capability in packaging notes.

Test plan

  • Install rebuilt .deb on a host with OpenSnitch stopped
  • systemctl is-active interfired.service stays active (not crash-loop activating)
  • Session user in group interfire (newgrp or re-login): interfirectl ping and interfirectl status work without sudo
  • Fresh install still defaults to enforcement=paused

Without CAP_CHOWN the daemon cannot chown the Unix socket to group
interfire after bind, so interfired exits and clients see a missing
socket.

Co-authored-by: Cursor <cursoragent@cursor.com>
@codecov

codecov Bot commented Sep 16, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@gRoussac
gRoussac merged commit f4a460b into Interchouette-ITC:dev Sep 16, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants