WFM, but one thing:

> 1. We will use bogo-IP numbers for client UDS connections

As long as we get VCL access to the accept socket name, we should not need the
uds socket path. But we should have a way to differentiate between
/untrusted/external.socket and /highly/secure/internal.socket


P.S. FTR I can't quite follow the "UDS is hackisch" argument, but that
discussion would not get us anywhere.

