From 439d9df122c91a884883815c2d755f50f076bc36 Mon Sep 17 00:00:00 2001 From: Joachim Nilsson Date: Sun, 24 Apr 2016 10:49:31 +0200 Subject: [PATCH] Set CLOEXEC flag to prevent leaking descriptors Both the new initctl API and the new pidfile watcher plugin failed to set CLOEXEC on their sockets. This caused forked-off and exec()'d children to inherit all these descriptors. Signed-off-by: Joachim Nilsson --- api.c | 2 +- plugins/pidfile.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/api.c b/api.c index 03ceec34..37725dd0 100644 --- a/api.c +++ b/api.c @@ -346,7 +346,7 @@ int api_init(uev_ctx_t *ctx) .sun_path = INIT_SOCKET, }; - sd = socket(AF_UNIX, SOCK_STREAM, 0); + sd = socket(AF_UNIX, SOCK_STREAM | SOCK_CLOEXEC, 0); if (-1 == sd) { _pe("Failed starting external API socket"); return 1; diff --git a/plugins/pidfile.c b/plugins/pidfile.c index 7fdb4f6e..f9db3126 100644 --- a/plugins/pidfile.c +++ b/plugins/pidfile.c @@ -104,7 +104,7 @@ static plugin_t plugin = { PLUGIN_INIT(plugin_init) { - pidfile_ctx.fd = inotify_init(); + pidfile_ctx.fd = inotify_init1(IN_NONBLOCK | IN_CLOEXEC); if (pidfile_ctx.fd < 0) { _pe("inotify_init()"); return;