Hi,

During the fork+exec implementation, daemon(3) was moved after
proc_init().  As a consequence httpd(8) and relayd(8) child processes
do not detach from the terminal anymore.  Dup /dev/null to the stdio
file descriptors in the children.

ok?

bluhm

Index: usr.sbin/httpd/httpd.c
===================================================================
RCS file: /data/mirror/openbsd/cvs/src/usr.sbin/httpd/httpd.c,v
retrieving revision 1.67
diff -u -p -r1.67 httpd.c
--- usr.sbin/httpd/httpd.c      28 May 2017 10:37:26 -0000      1.67
+++ usr.sbin/httpd/httpd.c      31 Aug 2018 20:17:34 -0000
@@ -215,7 +215,7 @@ main(int argc, char *argv[])
        }
 
        /* only the parent returns */
-       proc_init(ps, procs, nitems(procs), argc0, argv, proc_id);
+       proc_init(ps, procs, nitems(procs), debug, argc0, argv, proc_id);
 
        log_procinit("parent");
        if (!debug && daemon(1, 0) == -1)
Index: usr.sbin/httpd/httpd.h
===================================================================
RCS file: /data/mirror/openbsd/cvs/src/usr.sbin/httpd/httpd.h,v
retrieving revision 1.139
diff -u -p -r1.139 httpd.h
--- usr.sbin/httpd/httpd.h      19 Aug 2018 18:03:35 -0000      1.139
+++ usr.sbin/httpd/httpd.h      31 Aug 2018 20:18:12 -0000
@@ -780,7 +780,7 @@ __dead void fatalx(const char *, ...)
 /* proc.c */
 enum privsep_procid
            proc_getid(struct privsep_proc *, unsigned int, const char *);
-void    proc_init(struct privsep *, struct privsep_proc *, unsigned int,
+void    proc_init(struct privsep *, struct privsep_proc *, unsigned int, int,
            int, char **, enum privsep_procid);
 void    proc_kill(struct privsep *);
 void    proc_connect(struct privsep *);
Index: usr.sbin/httpd/proc.c
===================================================================
RCS file: /data/mirror/openbsd/cvs/src/usr.sbin/httpd/proc.c,v
retrieving revision 1.37
diff -u -p -r1.37 proc.c
--- usr.sbin/httpd/proc.c       28 May 2017 10:37:26 -0000      1.37
+++ usr.sbin/httpd/proc.c       31 Aug 2018 20:17:09 -0000
@@ -29,13 +29,14 @@
 #include <string.h>
 #include <errno.h>
 #include <signal.h>
+#include <paths.h>
 #include <pwd.h>
 #include <event.h>
 #include <imsg.h>
 
 #include "httpd.h"
 
-void    proc_exec(struct privsep *, struct privsep_proc *, unsigned int,
+void    proc_exec(struct privsep *, struct privsep_proc *, unsigned int, int,
            int, char **);
 void    proc_setup(struct privsep *, struct privsep_proc *, unsigned int);
 void    proc_open(struct privsep *, int, int);
@@ -80,7 +81,7 @@ proc_getid(struct privsep_proc *procs, u
 
 void
 proc_exec(struct privsep *ps, struct privsep_proc *procs, unsigned int nproc,
-    int argc, char **argv)
+    int debug, int argc, char **argv)
 {
        unsigned int             proc, nargc, i, proc_i;
        char                    **nargv;
@@ -141,6 +142,16 @@ proc_exec(struct privsep *ps, struct pri
                                } else if (fcntl(fd, F_SETFD, 0) == -1)
                                        fatal("fcntl");
 
+                               /* Daemons detach from terminal. */
+                               if (!debug && (fd =
+                                   open(_PATH_DEVNULL, O_RDWR, 0)) != -1) {
+                                       (void)dup2(fd, STDIN_FILENO);
+                                       (void)dup2(fd, STDOUT_FILENO);
+                                       (void)dup2(fd, STDERR_FILENO);
+                                       if (fd > 2)
+                                               (void)close(fd);
+                               }
+
                                execvp(argv[0], nargv);
                                fatal("%s: execvp", __func__);
                                break;
@@ -191,7 +202,7 @@ proc_connect(struct privsep *ps)
 
 void
 proc_init(struct privsep *ps, struct privsep_proc *procs, unsigned int nproc,
-    int argc, char **argv, enum privsep_procid proc_id)
+    int debug, int argc, char **argv, enum privsep_procid proc_id)
 {
        struct privsep_proc     *p = NULL;
        struct privsep_pipes    *pa, *pb;
@@ -231,7 +242,7 @@ proc_init(struct privsep *ps, struct pri
                }
 
                /* Engage! */
-               proc_exec(ps, procs, nproc, argc, argv);
+               proc_exec(ps, procs, nproc, debug, argc, argv);
                return;
        }
 
Index: usr.sbin/relayd/proc.c
===================================================================
RCS file: /data/mirror/openbsd/cvs/src/usr.sbin/relayd/proc.c,v
retrieving revision 1.39
diff -u -p -r1.39 proc.c
--- usr.sbin/relayd/proc.c      28 May 2017 10:39:15 -0000      1.39
+++ usr.sbin/relayd/proc.c      31 Aug 2018 20:25:23 -0000
@@ -29,13 +29,14 @@
 #include <string.h>
 #include <errno.h>
 #include <signal.h>
+#include <paths.h>
 #include <pwd.h>
 #include <event.h>
 #include <imsg.h>
 
 #include "relayd.h"
 
-void    proc_exec(struct privsep *, struct privsep_proc *, unsigned int,
+void    proc_exec(struct privsep *, struct privsep_proc *, unsigned int, int,
            int, char **);
 void    proc_setup(struct privsep *, struct privsep_proc *, unsigned int);
 void    proc_open(struct privsep *, int, int);
@@ -80,7 +81,7 @@ proc_getid(struct privsep_proc *procs, u
 
 void
 proc_exec(struct privsep *ps, struct privsep_proc *procs, unsigned int nproc,
-    int argc, char **argv)
+    int debug, int argc, char **argv)
 {
        unsigned int             proc, nargc, i, proc_i;
        char                    **nargv;
@@ -141,6 +142,16 @@ proc_exec(struct privsep *ps, struct pri
                                } else if (fcntl(fd, F_SETFD, 0) == -1)
                                        fatal("fcntl");
 
+                               /* Daemons detach from terminal. */
+                               if (!debug && (fd =
+                                   open(_PATH_DEVNULL, O_RDWR, 0)) != -1) {
+                                       (void)dup2(fd, STDIN_FILENO);
+                                       (void)dup2(fd, STDOUT_FILENO);
+                                       (void)dup2(fd, STDERR_FILENO);
+                                       if (fd > 2)
+                                               (void)close(fd);
+                               }
+
                                execvp(argv[0], nargv);
                                fatal("%s: execvp", __func__);
                                break;
@@ -191,7 +202,7 @@ proc_connect(struct privsep *ps)
 
 void
 proc_init(struct privsep *ps, struct privsep_proc *procs, unsigned int nproc,
-    int argc, char **argv, enum privsep_procid proc_id)
+    int debug, int argc, char **argv, enum privsep_procid proc_id)
 {
        struct privsep_proc     *p = NULL;
        struct privsep_pipes    *pa, *pb;
@@ -231,7 +242,7 @@ proc_init(struct privsep *ps, struct pri
                }
 
                /* Engage! */
-               proc_exec(ps, procs, nproc, argc, argv);
+               proc_exec(ps, procs, nproc, debug, argc, argv);
                return;
        }
 
Index: usr.sbin/relayd/relayd.c
===================================================================
RCS file: /data/mirror/openbsd/cvs/src/usr.sbin/relayd/relayd.c,v
retrieving revision 1.172
diff -u -p -r1.172 relayd.c
--- usr.sbin/relayd/relayd.c    6 Aug 2018 17:31:31 -0000       1.172
+++ usr.sbin/relayd/relayd.c    31 Aug 2018 20:24:08 -0000
@@ -212,7 +212,7 @@ main(int argc, char *argv[])
                ps->ps_title[proc_id] = title;
 
        /* only the parent returns */
-       proc_init(ps, procs, nitems(procs), argc0, argv, proc_id);
+       proc_init(ps, procs, nitems(procs), debug, argc0, argv, proc_id);
 
        log_procinit("parent");
        if (!debug && daemon(1, 0) == -1)
Index: usr.sbin/relayd/relayd.h
===================================================================
RCS file: /data/mirror/openbsd/cvs/src/usr.sbin/relayd/relayd.h,v
retrieving revision 1.250
diff -u -p -r1.250 relayd.h
--- usr.sbin/relayd/relayd.h    6 Aug 2018 17:31:31 -0000       1.250
+++ usr.sbin/relayd/relayd.h    31 Aug 2018 20:25:59 -0000
@@ -1383,7 +1383,7 @@ __dead void fatalx(const char *, ...)
 enum privsep_procid
            proc_getid(struct privsep_proc *, unsigned int, const char *);
 int     proc_flush_imsg(struct privsep *, enum privsep_procid, int);
-void    proc_init(struct privsep *, struct privsep_proc *, unsigned int,
+void    proc_init(struct privsep *, struct privsep_proc *, unsigned int, int,
            int, char **, enum privsep_procid);
 void    proc_kill(struct privsep *);
 void    proc_connect(struct privsep *);

Reply via email to