]> git.ipfire.org Git - thirdparty/dovecot/core.git/commitdiff
lib-master: Make sure stdin/stdout/stderr fds are open.
authorTimo Sirainen <timo.sirainen@dovecot.fi>
Mon, 14 Nov 2016 13:48:20 +0000 (14:48 +0100)
committerTimo Sirainen <timo.sirainen@dovecot.fi>
Tue, 15 Nov 2016 20:20:55 +0000 (22:20 +0200)
We'll just open /dev/null for them if they don't already exist.

src/lib-master/master-service.c

index 2a00c35a4c94c816a20a4def61ffc43b1336aa47..fb01df63322cbd1cb780d8e43ab0897b197878c2 100644 (file)
@@ -20,6 +20,7 @@
 #include "master-service-settings.h"
 
 #include <unistd.h>
+#include <fcntl.h>
 #include <sys/stat.h>
 #include <syslog.h>
 
@@ -166,6 +167,28 @@ master_service_init(const char *name, enum master_service_flags flags,
                fd_debug_verify_leaks(MASTER_LISTEN_FD_FIRST + count, 1024);
        }
 #endif
+       /* Make sure stdin, stdout and stderr fds exist. We especially rely on
+          stderr being available and a lot of code doesn't like fd being 0.
+          We'll open /dev/null as write-only also for stdin, since if any
+          reads are attempted from it we'll want them to fail. */
+       for (int fd = 0; fd <= 2; fd++) {
+               struct stat st;
+
+               if (fstat(fd, &st) < 0 && errno == EBADF) {
+                       int null_fd = open("/dev/null", O_WRONLY);
+                       if (null_fd == -1)
+                               i_fatal("Can't open /dev/null: %m");
+                       else if (null_fd != fd) {
+                               /* we don't really expect this to happen.
+                                  POSIX guarantees that open() returns the
+                                  lowest numbered fd. So this would only mean
+                                  that fstat() returned EBADF for a fd that
+                                  actually existed. */
+                               if (close(null_fd) < 0)
+                                       i_error("close(/dev/null) failed: %m");
+                       }
+               }
+       }
        if ((flags & MASTER_SERVICE_FLAG_STANDALONE) == 0) {
                /* make sure we can dump core, at least until
                   privileges are dropped. (i'm not really sure why this