Files
orchard/internal/command/localnetworkhelper/localnetworkhelper.go
T
Nikolay Edigaryev abcfee677d Work around Sequoia's "Local Network" permission with a helper process (#302)
* Work around Sequoia's "Local Network" permission with a helper process

* README.md: macOS 15 (Sequoia) warning

* Make "orchard dev" unix-specific too, otherwise Release fails

* Fix typo in "localNetworkHerlper"

* Slightly improve the macOS 15 (Sequoia) note

* orchard worker run: better documentation for --user

* Make sure privilege dropping is the first step we do in runWorker()
2025-04-10 18:01:19 +04:00

32 lines
860 B
Go

//go:build unix
package localnetworkhelper
import (
"github.com/cirruslabs/chacha/pkg/localnetworkhelper"
"github.com/spf13/cobra"
)
func NewCommand() *cobra.Command {
cmd := &cobra.Command{
Use: localnetworkhelper.CommandName,
Short: "Run the macOS \"Local Network\" permission helper process",
Hidden: true,
RunE: func(cmd *cobra.Command, args []string) error {
// In localnetworkhelper.New(), a macOS "Local Network"
// permission helper process is spawned and receives
// its socketpair(2) end via ExtraFiles field of Golang's
// exec.Cmd[1].
//
// This socketpair(2) end becomes FD number 3 here,
// according to the ExtraFiles documentation[1]:
//
// >If non-nil, entry i becomes file descriptor 3+i.
//
// [1]: https://pkg.go.dev/os/exec#Cmd
return localnetworkhelper.Serve(3)
},
}
return cmd
}