lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 4 Jun 2013 12:01:14 +0400 From: Andrey Vagin <avagin@...nvz.org> To: Stephen Hemminger <stephen@...workplumber.org> Cc: netdev@...r.kernel.org, Andrey Vagin <avagin@...nvz.org> Subject: [PATCH] ip: set the close-on-exec flag for descriptors Otherwise a program executed by "ip netns exec" has two extra descriptors. $ ip netns exec test /bin/bash $ lsof -p $$ ... bash 817 root 0u CHR 136,0 0t0 3 /dev/pts/0 bash 817 root 1u CHR 136,0 0t0 3 /dev/pts/0 bash 817 root 2u CHR 136,0 0t0 3 /dev/pts/0 bash 817 root 3u sock 0,6 0t0 13386 protocol: NETLINK bash 817 root 4r REG 0,3 0 4026532155 net bash 817 root 255u CHR 136,0 0t0 3 /dev/pts/0 Cc: Stephen Hemminger <stephen@...workplumber.org> Reported-by: Dilip Daya <dilip.daya@...com> Acked-by: Cyrill Gorcunov <gorcunov@...nvz.org> Signed-off-by: Andrey Vagin <avagin@...nvz.org> --- ip/ipnetns.c | 2 +- lib/libnetlink.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/ip/ipnetns.c b/ip/ipnetns.c index c9bc20a..fa2b681 100644 --- a/ip/ipnetns.c +++ b/ip/ipnetns.c @@ -150,7 +150,7 @@ static int netns_exec(int argc, char **argv) name = argv[0]; cmd = argv[1]; snprintf(net_path, sizeof(net_path), "%s/%s", NETNS_RUN_DIR, name); - netns = open(net_path, O_RDONLY); + netns = open(net_path, O_RDONLY | O_CLOEXEC); if (netns < 0) { fprintf(stderr, "Cannot open network namespace \"%s\": %s\n", name, strerror(errno)); diff --git a/lib/libnetlink.c b/lib/libnetlink.c index b17e1aa..9e2a795 100644 --- a/lib/libnetlink.c +++ b/lib/libnetlink.c @@ -43,7 +43,7 @@ int rtnl_open_byproto(struct rtnl_handle *rth, unsigned subscriptions, memset(rth, 0, sizeof(*rth)); - rth->fd = socket(AF_NETLINK, SOCK_RAW, protocol); + rth->fd = socket(AF_NETLINK, SOCK_RAW | SOCK_CLOEXEC, protocol); if (rth->fd < 0) { perror("Cannot open netlink socket"); return -1; -- 1.8.2 -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@...r.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists