diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-11-10 20:31:26 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-11-10 20:31:26 +0900 |
| commit | d7e0104ae4da25f455630aae044adf165201c9b5 (patch) | |
| tree | 2c976540d5007cc5e49c272d15868df72bfb5250 /cmd | |
| parent | bb92e3ada9ddbf315a50f2ec4b8bdafb05df7d3d (diff) | |
treewide: reject impossible user-supplied fd
These are all trusted user input, however this check reduces the likelihood of hard to debug errors.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'cmd')
| -rw-r--r-- | cmd/hakurei/parse.go | 12 |
1 files changed, 11 insertions, 1 deletions
diff --git a/cmd/hakurei/parse.go b/cmd/hakurei/parse.go index 5362fffe..266eb47f 100644 --- a/cmd/hakurei/parse.go +++ b/cmd/hakurei/parse.go @@ -11,6 +11,7 @@ import ( "syscall" "hakurei.app/hst" + "hakurei.app/internal/outcome" "hakurei.app/internal/store" "hakurei.app/message" ) @@ -53,14 +54,23 @@ func tryFd(msg message.Msg, name string) io.ReadCloser { } return nil } else { + if v < 3 { // reject standard streams + return nil + } + msg.Verbosef("trying config stream from %d", v) fd := uintptr(v) if _, _, errno := syscall.Syscall(syscall.SYS_FCNTL, fd, syscall.F_GETFD, 0); errno != 0 { - if errors.Is(errno, syscall.EBADF) { + if errors.Is(errno, syscall.EBADF) { // reject bad fd return nil } log.Fatalf("cannot get fd %d: %v", fd, errno) } + + if outcome.IsPollDescriptor(fd) { // reject runtime internals + log.Fatalf("invalid config stream %d", fd) + } + return os.NewFile(fd, strconv.Itoa(v)) } } |
