diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-11-10 20:31:26 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-11-10 20:31:26 +0900 |
| commit | d7e0104ae4da25f455630aae044adf165201c9b5 (patch) | |
| tree | 2c976540d5007cc5e49c272d15868df72bfb5250 /internal/outcome | |
| parent | bb92e3ada9ddbf315a50f2ec4b8bdafb05df7d3d (diff) | |
treewide: reject impossible user-supplied fd
These are all trusted user input, however this check reduces the likelihood of hard to debug errors.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/outcome')
| -rw-r--r-- | internal/outcome/main.go | 13 |
1 files changed, 13 insertions, 0 deletions
diff --git a/internal/outcome/main.go b/internal/outcome/main.go index a32d220a..1f02fafb 100644 --- a/internal/outcome/main.go +++ b/internal/outcome/main.go @@ -4,13 +4,26 @@ import ( "context" "log" "time" + _ "unsafe" // for go:linkname "hakurei.app/hst" "hakurei.app/message" ) +// IsPollDescriptor reports whether fd is the descriptor being used by the poller. +// +//go:linkname IsPollDescriptor internal/poll.IsPollDescriptor +func IsPollDescriptor(fd uintptr) bool + // Main runs an app according to [hst.Config] and terminates. Main does not return. func Main(ctx context.Context, msg message.Msg, config *hst.Config, fd int) { + // avoids runtime internals or standard streams + if fd >= 0 { + if IsPollDescriptor(uintptr(fd)) || fd < 3 { + log.Fatalf("invalid identifier fd %d", fd) + } + } + var id hst.ID if err := hst.NewInstanceID(&id); err != nil { log.Fatal(err.Error()) |
