mirror of
https://github.com/troglobit/finit.git
synced 2026-10-02 14:02:52 +07:00
Set CLOEXEC flag to prevent leaking descriptors
Both the new initctl API and the new pidfile watcher plugin failed to set CLOEXEC on their sockets. This caused forked-off and exec()'d children to inherit all these descriptors. Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit is contained in:
@@ -346,7 +346,7 @@ int api_init(uev_ctx_t *ctx)
|
||||
.sun_path = INIT_SOCKET,
|
||||
};
|
||||
|
||||
sd = socket(AF_UNIX, SOCK_STREAM, 0);
|
||||
sd = socket(AF_UNIX, SOCK_STREAM | SOCK_CLOEXEC, 0);
|
||||
if (-1 == sd) {
|
||||
_pe("Failed starting external API socket");
|
||||
return 1;
|
||||
|
||||
+1
-1
@@ -104,7 +104,7 @@ static plugin_t plugin = {
|
||||
|
||||
PLUGIN_INIT(plugin_init)
|
||||
{
|
||||
pidfile_ctx.fd = inotify_init();
|
||||
pidfile_ctx.fd = inotify_init1(IN_NONBLOCK | IN_CLOEXEC);
|
||||
if (pidfile_ctx.fd < 0) {
|
||||
_pe("inotify_init()");
|
||||
return;
|
||||
|
||||
Reference in New Issue
Block a user