cgroup-network does not allow softlinks either
Costa Tsaousis (ktsaou) committed
Apr 19, 2018 at 00:02 UTC
bdd44009c10745ce1b926ea250bae265df0d29dd
2 files changed
+15
-4
src/cgroup-network.c
+11
-3
@@ -163,7 +163,7 @@ static void continue_as_child(void) {
163
int proc_pid_fd(const char *prefix, const char *ns, pid_t pid) {
164
char filename[FILENAME_MAX + 1];
165
snprintfz(filename, FILENAME_MAX, "%s/proc/%d/%s", prefix?prefix:"", (int)pid, ns);
166
- int fd = open(filename, O_RDONLY);
166
+ int fd = open(filename, procfile_open_flags);
167
168
if(fd == -1)
169
error("Cannot open file '%s'", filename);
@@ -270,9 +270,15 @@ int switch_namespace(const char *prefix, pid_t pid) {
270
}
271
272
pid_t read_pid_from_cgroup_file(const char *filename) {
273
- FILE *fp = fopen(filename, "r");
273
+ int fd = open(filename, procfile_open_flags);
274
+ if(fd == -1) {
275
+ error("Cannot open file '%s'.", filename);
276
+ return 0;
277
+ }
278
+
279
+ FILE *fp = fdopen(fd, "r");
280
if(!fp) {
275
- error("Cannot read file '%s'.", filename);
281
+ error("Cannot open file '%s'.", filename);
282
return 0;
283
}
284
@@ -586,6 +592,8 @@ int main(int argc, char **argv) {
592
program_version = VERSION;
593
error_log_syslog = 0;
594
595
+ // since cgroup-network runs as root, prevent it from opening symbolic links
596
+ procfile_open_flags = O_RDONLY|O_NOFOLLOW;
597
598
// ------------------------------------------------------------------------
599
// make sure NETDATA_HOST_PREFIX is safe
src/common.c
+4
-1
@@ -1362,7 +1362,10 @@ int recursively_delete_dir(const char *path, const char *reason) {
1362
1363
static int is_virtual_filesystem(const char *path, char **reason) {
1364
1365
-#ifdef __Linux__
1365
+#if defined(__APPLE__) || defined(__FreeBSD__)
1366
+ (void)path;
1367
+ (void)reason;
1368
+#else
1369
struct statfs stat;
1370
// stat.f_fsid.__val[0] is a file system id
1371
// stat.f_fsid.__val[1] is the inode