unblock and unignore SIGPIPE

Blocked and ignored signals -- but not caught signals -- are inherited across exec. Some callers with sloppy signal-handling behavior can call git with SIGPIPE blocked or ignored, even non-deterministically. When SIGPIPE is blocked or ignored, several git commands can run indefinitely, ignoring EPIPE returns from write() calls, even when the process that called them has gone away. Our specific case involved a pipe of git diff-tree output to a script that reads a limited amount of diff data. In an ideal world, git would never be called with SIGPIPE blocked or ignored. But in the real world, several real potential callers, including Perl, Apache, and Unicorn, sometimes spawn subprocesses with SIGPIPE ignored. It is easier and more productive to harden git against this mistake than to clean it up in every potential parent process. Signed-off-by: Patrick Reynolds <patrick.reynolds@github.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Reynolds committed Sep 18, 2014 at 11:57 UTC 7559a1be8a0afb10df41d25e4cf4c5285a5faef1
2 files changed +44
git.c
+22
@@ -592,6 +592,26 @@ static int run_argv(int *argcp, const char ***argv)
592 return done_alias;
593 }
594
595 +/*
596 + * Many parts of Git have subprograms communicate via pipe, expect the
597 + * upstream of a pipe to die with SIGPIPE when the downstream of a
598 + * pipe does not need to read all that is written. Some third-party
599 + * programs that ignore or block SIGPIPE for their own reason forget
600 + * to restore SIGPIPE handling to the default before spawning Git and
601 + * break this carefully orchestrated machinery.
602 + *
603 + * Restore the way SIGPIPE is handled to default, which is what we
604 + * expect.
605 + */
606 +static void restore_sigpipe_to_default(void)
607 +{
608 + sigset_t unblock;
609 +
610 + sigemptyset(&unblock);
611 + sigaddset(&unblock, SIGPIPE);
612 + sigprocmask(SIG_UNBLOCK, &unblock, NULL);
613 + signal(SIGPIPE, SIG_DFL);
614 +}
615
616 int main(int argc, char **av)
617 {
@@ -611,6 +631,8 @@ int main(int argc, char **av)
631 */
632 sanitize_stdfds();
633
634 + restore_sigpipe_to_default();
635 +
636 git_setup_gettext();
637
638 trace_command_performance(argv);
t/t0005-signals.sh
+22
@@ -27,4 +27,26 @@ test_expect_success !MINGW 'signals are propagated using shell convention' '
27 test_expect_code 143 git sigterm
28 '
29
30 +large_git () {
31 + for i in $(test_seq 1 100)
32 + do
33 + git diff --cached --binary || return
34 + done
35 +}
36 +
37 +test_expect_success 'create blob' '
38 + test-genrandom foo 16384 >file &&
39 + git add file
40 +'
41 +
42 +test_expect_success 'a constipated git dies with SIGPIPE' '
43 + OUT=$( ((large_git; echo $? 1>&3) | :) 3>&1 )
44 + test "$OUT" -eq 141
45 +'
46 +
47 +test_expect_success 'a constipated git dies with SIGPIPE even if parent ignores it' '
48 + OUT=$( ((trap "" PIPE; large_git; echo $? 1>&3) | :) 3>&1 )
49 + test "$OUT" -eq 141
50 +'
51 +
52 test_done