Re: /dev/stderr gets unlinked 8]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 15 Mar 2006, Denis Vlasenko wrote:

> On Wednesday 15 March 2006 15:14, Andreas Schwab wrote:
>> Stefan Seyfried <[email protected]> writes:
>>
>>> any good daemon closes stdout, stderr, stdin
>>
>> A real good daemon would redirect them to /dev/null.
>
> Yeah, yeah, let's first close stderr, and then proceed and
> add some code to handle command line --log=file, and to do
> logging to that file.
>
> Why good ol' fprintf(stderr,...) isn't enough? Why do you
> want to complicate things?
>
> What's so hard in doing "daemon 2>/dev/null &" if you don't
> want to save log?
> --
> vda

The daemon needs to have the standard input closed as well as
any I/O connection to a possible terminal. Just closing
standard input, allows a dup() in rogue code to recreate it.
Basically, file-descriptors 0, 1, and 2, need to be USED and
used for something else (like open /dev/null or open "/").
That's how you prevent rogue code, inserted via overflow or
other means, from obtaining control of your system.
Good daemons also use system services to write messages to
log files. They don't make their own, which is one of the
reasons why early versions of `sendmail` were not considered
"good" daemons.

Cheers,
Dick Johnson
Penguin : Linux version 2.6.15.4 on an i686 machine (5589.54 BogoMips).
Warning : 98.36% of all statistics are fiction, book release in April.
_


****************************************************************
The information transmitted in this message is confidential and may be privileged.  Any review, retransmission, dissemination, or other use of this information by persons or entities other than the intended recipient is prohibited.  If you are not the intended recipient, please notify Analogic Corporation immediately - by replying to this message or by sending an email to [email protected] - and destroy all copies of this information, including any attachments, without reading or disclosing them.

Thank you.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[Index of Archives]     [Kernel Newbies]     [Netfilter]     [Bugtraq]     [Photo]     [Stuff]     [Gimp]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Video 4 Linux]     [Linux for the blind]     [Linux Resources]
  Powered by Linux