From 98c8e9f8b198c85e8edb607c62cf3df338c4e29e Mon Sep 17 00:00:00 2001 From: Joachim Nilsson Date: Fri, 22 Apr 2016 14:31:51 +0200 Subject: [PATCH] Fix leaking descriptors, use CLOEXEC The signal and timer fd's used in libuEv were not created properly with the CLOEXEC flag. Hence, all forked off children calling exec*() could access all file descriptor, sockets, etc., used by the parent process. Signed-off-by: Joachim Nilsson --- signal.c | 2 +- timer.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/signal.c b/signal.c index 8384d6b..6e32797 100644 --- a/signal.c +++ b/signal.c @@ -52,7 +52,7 @@ int uev_signal_init(uev_ctx_t *ctx, uev_t *w, uev_cb_t *cb, void *arg, int signo w->fd = -1; sigemptyset(&mask); - fd = signalfd(-1, &mask, SFD_NONBLOCK); + fd = signalfd(-1, &mask, SFD_NONBLOCK | SFD_CLOEXEC); if (fd < 0) return -1; diff --git a/timer.c b/timer.c index 052183f..8de9bf2 100644 --- a/timer.c +++ b/timer.c @@ -67,7 +67,7 @@ int uev_timer_init(uev_ctx_t *ctx, uev_t *w, uev_cb_t *cb, void *arg, int timeou { int fd; - fd = timerfd_create(CLOCK_MONOTONIC, TFD_NONBLOCK); + fd = timerfd_create(CLOCK_MONOTONIC, TFD_NONBLOCK | TFD_CLOEXEC); if (fd < 0) return -1;