From 5b9d99011b2fdcd9c5640aef1af4523ee60f51a9 Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Fri, 5 Mar 2021 10:44:01 +0100 Subject: [PATCH] Fix long-standing bug in reset of rlimits between reconf While skimming through the results of the latest Coverity Scan, I discovered that that the reset logic of global rlimits was broken. This it seems to have been since its first introduction in Finit. We fix this by reading initial rlimits at bootstrap, then for each reconf, including the first, we seed global rlimits with the initial ones -- thus resetting between each reconf. Signed-off-by: Joachim Wiberg --- src/conf.c | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/src/conf.c b/src/conf.c index c1633dc6..938f1c6b 100644 --- a/src/conf.c +++ b/src/conf.c @@ -47,6 +47,7 @@ int logfile_size_max = 200000; /* 200 kB */ int logfile_count_max = 5; +struct rlimit initial_rlimit[RLIMIT_NLIMITS]; struct rlimit global_rlimit[RLIMIT_NLIMITS]; struct conf_change { @@ -625,12 +626,9 @@ int conf_reload(void) tty_mark(); /* - * Get current global limits, which may be overridden from both - * finit.conf, for Finit and its services like getty+watchdogd, - * and *.conf in finit.d/, for each service(s) listed there. + * Reset global rlimit to bootstrap values from conf_init(). */ - for (int i = 0; i < RLIMIT_NLIMITS; i++) - getrlimit(i, &global_rlimit[i]); + memcpy(global_rlimit, initial_rlimit, sizeof(global_rlimit)); if (rescue) { int rc; @@ -887,8 +885,11 @@ int conf_init(uev_ctx_t *ctx) * finit.conf, for Finit and its services like getty+watchdogd, * and *.conf in finit.d/, for each service(s) listed there. */ - for (int i = 0; i < RLIMIT_NLIMITS; i++) - getrlimit(i, &global_rlimit[i]); + for (int i = 0; i < RLIMIT_NLIMITS; i++) { + if (getrlimit(i, &initial_rlimit[i])) + logit(LOG_WARNING, "rlimit: Failed reading setting %s: %s", + rlim2str(i), strerror(errno)); + } /* prepare /etc watcher */ fd = iwatch_init(&iw_conf);