Bug #67383 [Opn->Dup]: exec() leaks file and socket descriptors to called program

From: Date: Mon, 21 Jul 2014 11:54:20 +0000
Subject: Bug #67383 [Opn->Dup]: exec() leaks file and socket descriptors to called program
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186760@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67383&edit=1 ID: 67383 Updated by: langemeijer@php.net Reported by: langemeijer@php.net Summary: exec() leaks file and socket descriptors to called program -Status: Open +Status: Duplicate Type: Bug Package: *General Issues Operating System: linux PHP Version: Irrelevant Block user comment: N Private report: N New Comment: This is a duplicate of bug #67383 (Which contains a patch that should be merged by someone!) Previous Comments: ------------------------------------------------------------------------ [2014-07-21 11:54:20] langemeijer@php.net Related To: Bug #67383 ------------------------------------------------------------------------ [2014-06-05 11:25:42] langemeijer@php.net Description: ------------ PHP doesn't sanitize opened file descriptors opened by PHP itself before executing a program. This should be fixed by opening all sockets with SOCK_CLOEXEC and all run a fcntl(file, F_SETFD, FD_CLOEXEC); on all newly opened filedescriptors SOCK_CLOEXEC and FD_CLOEXEC cause exec() to close the descriptors in the fork()ed child process. Note that this is similar, but not identical to bug #38915, bug #15529 and bug #20302 which are about file descriptors and sockets opened by Apache. Note that my patch also sets SOCK_CLOEXEC on the fastcgi listening socket and other similar usages of sockets. The patch was generated on php-src master branch. I'm happy to do some more work on it if any of you feel this is required. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67383&edit=1

« previous php.bugs (#186760) next »