Ensure commonly used file descriptors are close-on-exec

This commit is contained in:
matt335672
2023-01-17 10:55:19 +00:00
parent adb7476187
commit f08355a325
4 changed files with 18 additions and 2 deletions
+2
View File
@@ -1721,6 +1721,8 @@ g_create_wait_obj(const char *name)
close(fds[1]);
return 0;
}
g_file_set_cloexec(fds[0], 1);
g_file_set_cloexec(fds[1], 1);
return (fds[1] << 16) | fds[0];
#endif
}
+7
View File
@@ -355,6 +355,7 @@ trans_check_wait_objs(struct trans *self)
in_trans->type1 = TRANS_TYPE_SERVER;
in_trans->status = TRANS_STATUS_UP;
in_trans->is_term = self->is_term;
g_file_set_cloexec(in_sck, 1);
g_sck_set_non_blocking(in_sck);
if (self->trans_conn_in(self, in_trans) != 0)
{
@@ -796,6 +797,7 @@ trans_connect(struct trans *self, const char *server, const char *port,
}
/* Try to connect asynchronously */
g_file_set_cloexec(self->sck, 1);
g_tcp_set_non_blocking(self->sck);
error = f_connect(self->sck, server, port);
if (error == 0)
@@ -881,6 +883,7 @@ trans_listen_address(struct trans *self, const char *port, const char *address)
return 1;
}
g_file_set_cloexec(self->sck, 1);
g_tcp_set_non_blocking(self->sck);
if (g_tcp_bind_address(self->sck, port, address) == 0)
@@ -905,6 +908,7 @@ trans_listen_address(struct trans *self, const char *port, const char *address)
return 1;
}
g_file_set_cloexec(self->sck, 1);
g_tcp_set_non_blocking(self->sck);
if (g_tcp_local_bind(self->sck, port) == 0)
@@ -928,6 +932,7 @@ trans_listen_address(struct trans *self, const char *port, const char *address)
return 1;
}
g_file_set_cloexec(self->sck, 1);
g_tcp_set_non_blocking(self->sck);
if (g_sck_vsock_bind_address(self->sck, port, address) == 0)
@@ -947,6 +952,7 @@ trans_listen_address(struct trans *self, const char *port, const char *address)
{
return 1;
}
g_file_set_cloexec(self->sck, 1);
g_tcp_set_non_blocking(self->sck);
if (g_tcp4_bind_address(self->sck, port, address) == 0)
{
@@ -965,6 +971,7 @@ trans_listen_address(struct trans *self, const char *port, const char *address)
{
return 1;
}
g_file_set_cloexec(self->sck, 1);
g_tcp_set_non_blocking(self->sck);
if (g_tcp6_bind_address(self->sck, port, address) == 0)
{
+4
View File
@@ -101,6 +101,10 @@ lock_uds(const char *sockname)
g_file_close(fd);
fd = -1;
}
else
{
(void)g_file_set_cloexec(fd, 1);
}
}
}
+5 -2
View File
@@ -1020,9 +1020,12 @@ session_start(struct auth_info *auth_info,
{
/**
* We're now forked from the main sesman process, so we
* can close file descriptors that we no longer need */
* can close file descriptors that we no longer need
*
* Set FD_CLOEXEC on the FD used to send our status back to
* sesman, as our sub-processes shouldn't be able to see it */
g_file_close(fd[0]);
g_file_set_cloexec(fd[1], 1);
sesman_close_all(0);