From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 3385 invoked by alias); 27 Jan 2019 12:21:02 -0000 Mailing-List: contact cygwin-cvs-help@cygwin.com; run by ezmlm Precedence: bulk List-Id: List-Subscribe: List-Post: List-Help: , Sender: cygwin-cvs-owner@cygwin.com Received: (qmail 3325 invoked by uid 9078); 27 Jan 2019 12:21:01 -0000 Date: Sun, 27 Jan 2019 12:21:00 -0000 Message-ID: <20190127122101.3317.qmail@sourceware.org> Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Corinna Vinschen To: cygwin-cvs@sourceware.org Subject: [newlib-cygwin] Cygwin: fork: restrict parent handle perms and drop handle after use X-Act-Checkin: newlib-cygwin X-Git-Author: Corinna Vinschen X-Git-Refname: refs/heads/master X-Git-Oldrev: 0fb497165f8545470624012315aeaf37333c1ea2 X-Git-Newrev: 69cc7a068656b5c6ef07ca079a213f801e02e650 X-SW-Source: 2019-q1/txt/msg00104.txt.bz2 https://sourceware.org/git/gitweb.cgi?p=newlib-cygwin.git;h=69cc7a068656b5c6ef07ca079a213f801e02e650 commit 69cc7a068656b5c6ef07ca079a213f801e02e650 Author: Corinna Vinschen Date: Sun Jan 27 13:15:15 2019 +0100 Cygwin: fork: restrict parent handle perms and drop handle after use Signed-off-by: Corinna Vinschen Diff: --- winsup/cygwin/dcrt0.cc | 3 ++- winsup/cygwin/fork.cc | 2 ++ winsup/cygwin/sigproc.cc | 5 +++-- 3 files changed, 7 insertions(+), 3 deletions(-) diff --git a/winsup/cygwin/dcrt0.cc b/winsup/cygwin/dcrt0.cc index af5eaac..cf2a08e 100644 --- a/winsup/cygwin/dcrt0.cc +++ b/winsup/cygwin/dcrt0.cc @@ -637,7 +637,8 @@ child_info_fork::handle_fork () bool child_info_spawn::get_parent_handle () { - parent = OpenProcess (PROCESS_VM_READ, false, parent_winpid); + parent = OpenProcess (PROCESS_QUERY_LIMITED_INFORMATION, FALSE, + parent_winpid); moreinfo->myself_pinfo = NULL; return !!parent; } diff --git a/winsup/cygwin/fork.cc b/winsup/cygwin/fork.cc index 6813446..d8c4ac4 100644 --- a/winsup/cygwin/fork.cc +++ b/winsup/cygwin/fork.cc @@ -203,6 +203,8 @@ frok::child (volatile char * volatile here) rd_proc_pipe that would be an invalid handle. In the case of wr_proc_pipe it would be == my_wr_proc_pipe. Both would be bad. */ ch.rd_proc_pipe = ch.wr_proc_pipe = NULL; + CloseHandle (hParent); + hParent = NULL; cygwin_finished_initializing = true; return 0; } diff --git a/winsup/cygwin/sigproc.cc b/winsup/cygwin/sigproc.cc index 92fa5ea..45e9482 100644 --- a/winsup/cygwin/sigproc.cc +++ b/winsup/cygwin/sigproc.cc @@ -814,8 +814,9 @@ child_info::child_info (unsigned in_cb, child_info_types chtype, allow the child to duplicate handles from the parent to itself. */ parent = NULL; if (!DuplicateHandle (GetCurrentProcess (), GetCurrentProcess (), - GetCurrentProcess (), &parent, 0, true, - DUPLICATE_SAME_ACCESS)) + GetCurrentProcess (), &parent, + PROCESS_DUP_HANDLE | PROCESS_VM_READ + | PROCESS_QUERY_LIMITED_INFORMATION, TRUE, 0)) system_printf ("couldn't create handle to myself for child, %E"); }