Skip to content

Conversation

@sivizius
Copy link

@sivizius sivizius commented Nov 25, 2025

  1. Harmonise spelling of »UNIX domain socket« as per https://man7.org/linux/man-pages/man7/unix.7.html
  2. Allow abstract names in various places, prefixed with @, which is used by systemd, https://man7.org/linux/man-pages/man8/ss.8.html, etc.

@sivizius sivizius force-pushed the abstract-unix-sockets branch 2 times, most recently from 5e661b8 to fd94b73 Compare November 26, 2025 12:32
@zgttotev
Copy link

Sorry if this is the wrong place but I was looking for X11 forwarding support to a local abstract socket per the patch in Fedora: https://src.fedoraproject.org/rpms/openssh/blob/f43/f/0007-openssh-7.2p2-x11.patch
This PR seems to add support for an @ prefixed path to connect_local_xsocket_path but its caller connect_local_xsocket never tries an abstract socket (like it does in the Fedora patch). Would this be something you'd be willing to add?

@zgttotev
Copy link

Appears there is prior art on this subject I'm just uncovering. https://tstarling.com/blog/2016/06/x11-security-isolation/ points to Bug 1789 which attempted to add this support but was unsuccessful due to security concerns.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants