Set CLOEXEC flag to prevent leaking descriptors

Both the new initctl API and the new pidfile watcher plugin failed to
set CLOEXEC on their sockets.  This caused forked-off and exec()'d
children to inherit all these descriptors.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit is contained in:
Joachim Nilsson
2016-04-24 10:52:39 +02:00
parent da76cf4f75
commit 439d9df122
2 changed files with 2 additions and 2 deletions
+1 -1
View File
@@ -346,7 +346,7 @@ int api_init(uev_ctx_t *ctx)
.sun_path = INIT_SOCKET,
};
sd = socket(AF_UNIX, SOCK_STREAM, 0);
sd = socket(AF_UNIX, SOCK_STREAM | SOCK_CLOEXEC, 0);
if (-1 == sd) {
_pe("Failed starting external API socket");
return 1;
+1 -1
View File
@@ -104,7 +104,7 @@ static plugin_t plugin = {
PLUGIN_INIT(plugin_init)
{
pidfile_ctx.fd = inotify_init();
pidfile_ctx.fd = inotify_init1(IN_NONBLOCK | IN_CLOEXEC);
if (pidfile_ctx.fd < 0) {
_pe("inotify_init()");
return;