mirror of
https://sourceware.org/git/glibc.git
synced 2024-11-27 11:43:34 +08:00
882d6e17bc
This patch adds a way to close a range of file descriptors on posix_spawn as a new file action. The API is similar to the one provided by Solaris 11 [1], where the file action causes the all open file descriptors greater than or equal to input on to be closed when the new process is spawned. The function posix_spawn_file_actions_addclosefrom_np is safe to be implemented by iterating over /proc/self/fd, since the Linux spawni.c helper process does not use CLONE_FILES, so its has own file descriptor table and any failure (in /proc operation) aborts the process creation and returns an error to the caller. I am aware that this file action might be redundant to the current approach of POSIX in promoting O_CLOEXEC in more interfaces. However O_CLOEXEC is still not the default and for some specific usages, the caller needs to close all possible file descriptors to avoid them leaking. Some examples are CPython (discussed in BZ#10353) and OpenJDK jspawnhelper [2] (where OpenJDK spawns a helper process to exactly closes all file descriptors). Most likely any environment which calls functions that might open file descriptor under the hood and aim to use posix_spawn might face the same requirement. Checked on x86_64-linux-gnu and i686-linux-gnu on kernel 5.11 and 4.15. [1] https://docs.oracle.com/cd/E36784_01/html/E36874/posix-spawn-file-actions-addclosefrom-np-3c.html [2] https://github.com/openjdk/jdk/blob/master/src/java.base/unix/native/libjava/childproc.c#L82
89 lines
2.2 KiB
C
89 lines
2.2 KiB
C
/* Internal definitions for posix_spawn functionality.
|
|
Copyright (C) 2000-2021 Free Software Foundation, Inc.
|
|
This file is part of the GNU C Library.
|
|
|
|
The GNU C Library is free software; you can redistribute it and/or
|
|
modify it under the terms of the GNU Lesser General Public
|
|
License as published by the Free Software Foundation; either
|
|
version 2.1 of the License, or (at your option) any later version.
|
|
|
|
The GNU C Library is distributed in the hope that it will be useful,
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
Lesser General Public License for more details.
|
|
|
|
You should have received a copy of the GNU Lesser General Public
|
|
License along with the GNU C Library; if not, see
|
|
<https://www.gnu.org/licenses/>. */
|
|
|
|
#ifndef _SPAWN_INT_H
|
|
#define _SPAWN_INT_H
|
|
|
|
#include <spawn.h>
|
|
#include <spawn_int_def.h>
|
|
#include <stdbool.h>
|
|
|
|
/* Data structure to contain the action information. */
|
|
struct __spawn_action
|
|
{
|
|
enum
|
|
{
|
|
spawn_do_close,
|
|
spawn_do_dup2,
|
|
spawn_do_open,
|
|
spawn_do_chdir,
|
|
spawn_do_fchdir,
|
|
spawn_do_closefrom,
|
|
} tag;
|
|
|
|
union
|
|
{
|
|
struct
|
|
{
|
|
int fd;
|
|
} close_action;
|
|
struct
|
|
{
|
|
int fd;
|
|
int newfd;
|
|
} dup2_action;
|
|
struct
|
|
{
|
|
int fd;
|
|
char *path;
|
|
int oflag;
|
|
mode_t mode;
|
|
} open_action;
|
|
struct
|
|
{
|
|
char *path;
|
|
} chdir_action;
|
|
struct
|
|
{
|
|
int fd;
|
|
} fchdir_action;
|
|
struct
|
|
{
|
|
int from;
|
|
} closefrom_action;
|
|
} action;
|
|
};
|
|
|
|
#define SPAWN_XFLAGS_USE_PATH 0x1
|
|
#define SPAWN_XFLAGS_TRY_SHELL 0x2
|
|
|
|
extern int __posix_spawn_file_actions_realloc (posix_spawn_file_actions_t *
|
|
file_actions)
|
|
attribute_hidden;
|
|
|
|
extern int __spawni (pid_t *pid, const char *path,
|
|
const posix_spawn_file_actions_t *file_actions,
|
|
const posix_spawnattr_t *attrp, char *const argv[],
|
|
char *const envp[], int xflags) attribute_hidden;
|
|
|
|
/* Return true if FD falls into the range valid for file descriptors.
|
|
The check in this form is mandated by POSIX. */
|
|
bool __spawn_valid_fd (int fd) attribute_hidden;
|
|
|
|
#endif /* _SPAWN_INT_H */
|