vishalmishra434 / rpms / openssh

Forked from rpms/openssh 3 months ago
Clone
Jan F. Chadima 313100
diff -up openssh-5.3p1/channels.c.cloexec openssh-5.3p1/channels.c
Jan F. Chadima 606b55
--- openssh-5.3p1/channels.c.cloexec	2010-01-25 17:25:58.000000000 +0100
Jan F. Chadima 606b55
+++ openssh-5.3p1/channels.c	2010-01-25 17:26:01.000000000 +0100
Tomáš Mráz 9e5c6e
@@ -60,6 +60,7 @@
Tomáš Mráz 9e5c6e
 #include <termios.h>
Tomáš Mráz 9e5c6e
 #include <unistd.h>
Tomáš Mráz 9e5c6e
 #include <stdarg.h>
Tomáš Mráz 9e5c6e
+#include <fcntl.h>
Tomáš Mráz 9e5c6e
 
Tomáš Mráz 9e5c6e
 #include "openbsd-compat/sys-queue.h"
Tomáš Mráz 9e5c6e
 #include "xmalloc.h"
Tomáš Mráz 9e5c6e
@@ -230,6 +231,18 @@ channel_register_fds(Channel *c, int rfd
Tomáš Mráz 9e5c6e
 
Tomáš Mráz 9e5c6e
 	/* XXX set close-on-exec -markus */
Tomáš Mráz 9e5c6e
 
Tomáš Mráz 9e5c6e
+	if (rfd != -1) {
Tomáš Mráz 9e5c6e
+		fcntl(rfd, F_SETFD, FD_CLOEXEC);
Tomáš Mráz 9e5c6e
+	}
Tomáš Mráz 9e5c6e
+
Tomáš Mráz 9e5c6e
+	if (wfd != -1 && wfd != rfd) {
Tomáš Mráz 9e5c6e
+		fcntl(wfd, F_SETFD, FD_CLOEXEC);
Tomáš Mráz 9e5c6e
+	}
Tomáš Mráz 9e5c6e
+
Tomáš Mráz 9e5c6e
+	if (efd != -1 && efd != rfd && efd != wfd) {
Tomáš Mráz 9e5c6e
+		fcntl(efd, F_SETFD, FD_CLOEXEC);
Tomáš Mráz 9e5c6e
+	}
Tomáš Mráz 9e5c6e
+
Tomáš Mráz 9e5c6e
 	c->rfd = rfd;
Tomáš Mráz 9e5c6e
 	c->wfd = wfd;
Tomáš Mráz 9e5c6e
 	c->sock = (rfd == wfd) ? rfd : -1;
Jan F. Chadima 313100
diff -up openssh-5.3p1/sshconnect2.c.cloexec openssh-5.3p1/sshconnect2.c
Jan F. Chadima 606b55
--- openssh-5.3p1/sshconnect2.c.cloexec	2010-01-25 17:25:58.000000000 +0100
Jan F. Chadima 606b55
+++ openssh-5.3p1/sshconnect2.c	2010-01-25 17:26:01.000000000 +0100
Jan F. Chadima 313100
@@ -39,6 +39,7 @@
Tomáš Mráz 077dad
 #include <stdio.h>
Tomáš Mráz 077dad
 #include <string.h>
Tomáš Mráz 077dad
 #include <unistd.h>
Tomáš Mráz 077dad
+#include <fcntl.h>
Tomáš Mráz 93a474
 #if defined(HAVE_STRNVIS) && defined(HAVE_VIS_H)
Tomáš Mráz 93a474
 #include <vis.h>
Tomáš Mráz 93a474
 #endif
Jan F. Chadima 313100
@@ -1512,6 +1513,7 @@ ssh_keysign(Key *key, u_char **sigp, u_i
Tomáš Mráz 077dad
 		return -1;
Tomáš Mráz 077dad
 	}
Tomáš Mráz 077dad
 	if (pid == 0) {
Tomáš Mráz 077dad
+		fcntl(packet_get_connection_in(), F_SETFD, 0); /* keep the socket on exec */
Tomáš Mráz 077dad
 		permanently_drop_suid(getuid());
Tomáš Mráz 077dad
 		close(from[0]);
Tomáš Mráz 077dad
 		if (dup2(from[1], STDOUT_FILENO) < 0)
Jan F. Chadima 313100
diff -up openssh-5.3p1/sshconnect.c.cloexec openssh-5.3p1/sshconnect.c
Jan F. Chadima 313100
--- openssh-5.3p1/sshconnect.c.cloexec	2009-06-21 10:53:53.000000000 +0200
Jan F. Chadima 606b55
+++ openssh-5.3p1/sshconnect.c	2010-01-25 17:26:01.000000000 +0100
Tomáš Mráz 2cb0e7
@@ -38,6 +38,7 @@
Tomáš Mráz 2cb0e7
 #include <stdlib.h>
Tomáš Mráz 2cb0e7
 #include <string.h>
Tomáš Mráz 2cb0e7
 #include <unistd.h>
Tomáš Mráz 2cb0e7
+#include <fcntl.h>
Tomáš Mráz 2cb0e7
 
Tomáš Mráz 2cb0e7
 #include "xmalloc.h"
Tomáš Mráz 2cb0e7
 #include "key.h"
Jan F. Chadima 313100
@@ -191,8 +192,11 @@ ssh_create_socket(int privileged, struct
Tomáš Mráz 2cb0e7
 		return sock;
Tomáš Mráz 2cb0e7
 	}
Tomáš Mráz 2cb0e7
 	sock = socket(ai->ai_family, ai->ai_socktype, ai->ai_protocol);
Tomáš Mráz 2cb0e7
-	if (sock < 0)
Tomáš Mráz 2cb0e7
+	if (sock < 0) {
Tomáš Mráz 2cb0e7
 		error("socket: %.100s", strerror(errno));
Tomáš Mráz 2cb0e7
+		return -1;
Tomáš Mráz 2cb0e7
+	}
Tomáš Mráz 2cb0e7
+	fcntl(sock, F_SETFD, FD_CLOEXEC);
Tomáš Mráz 2cb0e7
 
Tomáš Mráz 2cb0e7
 	/* Bind the socket to an alternative local IP address */
Tomáš Mráz 2cb0e7
 	if (options.bind_address == NULL)
Jan F. Chadima 313100
diff -up openssh-5.3p1/sshd.c.cloexec openssh-5.3p1/sshd.c
Jan F. Chadima 606b55
--- openssh-5.3p1/sshd.c.cloexec	2010-01-25 17:25:55.000000000 +0100
Jan F. Chadima 606b55
+++ openssh-5.3p1/sshd.c	2010-01-25 18:29:23.000000000 +0100
Jan F. Chadima 606b55
@@ -1756,6 +1756,10 @@ main(int ac, char **av)
Jan F. Chadima 606b55
 		    sock_in, sock_out, newsock, startup_pipe, config_s[0]);
Jan F. Chadima 606b55
 	}
Jan F. Chadima 606b55
 
Jan F. Chadima 606b55
+	/* set fd cloexec on io/sockets to avoid to forward them to childern */
Jan F. Chadima 606b55
+	fcntl(sock_out, F_SETFD, FD_CLOEXEC);
Jan F. Chadima 606b55
+	fcntl(sock_in, F_SETFD, FD_CLOEXEC);
Jan F. Chadima 606b55
+
Jan F. Chadima 606b55
 	/*
Jan F. Chadima 606b55
 	 * Disable the key regeneration alarm.  We will not regenerate the
Jan F. Chadima 606b55
 	 * key since we are no longer in a position to give it to anyone. We