mirror of
https://gitlab.com/redhat/centos-stream/rpms/conmon.git
synced 2026-07-03 20:01:15 +00:00
Reset create_pid after waitpid to prevent signaling unrelated processes
After the synchronous waitpid(create_pid) succeeds, create_pid was never reset to -1. If the PID was later reused by another process, on_sig_exit() would send SIGTERM to that unrelated process. Resolves: RHEL-178025
This commit is contained in:
@@ -0,0 +1,32 @@
|
|||||||
|
From 8596fc6462efa2bd0db47485931cfcd704ca0637 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Jindrich Novy <jnovy@redhat.com>
|
||||||
|
Date: Thu, 21 May 2026 09:38:48 +0200
|
||||||
|
Subject: [PATCH] Reset create_pid after waitpid to prevent signaling unrelated
|
||||||
|
processes
|
||||||
|
|
||||||
|
After the synchronous waitpid(create_pid) succeeds, create_pid was
|
||||||
|
never reset to -1. If the PID was later reused by another process,
|
||||||
|
on_sig_exit() would send SIGTERM to that unrelated process.
|
||||||
|
|
||||||
|
Resolves: RHEL-178025
|
||||||
|
|
||||||
|
Signed-off-by: Jindrich Novy <jnovy@redhat.com>
|
||||||
|
---
|
||||||
|
src/conmon.c | 1 +
|
||||||
|
1 file changed, 1 insertion(+)
|
||||||
|
|
||||||
|
diff --git a/src/conmon.c b/src/conmon.c
|
||||||
|
index 0abbd17d..24a7da18 100644
|
||||||
|
--- a/src/conmon.c
|
||||||
|
+++ b/src/conmon.c
|
||||||
|
@@ -360,6 +360,7 @@ int main(int argc, char *argv[])
|
||||||
|
}
|
||||||
|
pexitf("Failed to wait for `runtime %s`", opt_exec ? "exec" : "create");
|
||||||
|
}
|
||||||
|
+ create_pid = -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* For exec operations, a non-zero runtime exit status reflects the exit status of the exec'd command,
|
||||||
|
--
|
||||||
|
2.49.0
|
||||||
|
|
||||||
+7
-1
@@ -17,11 +17,13 @@ Name: conmon
|
|||||||
Epoch: 3
|
Epoch: 3
|
||||||
Version: 2.2.1
|
Version: 2.2.1
|
||||||
License: Apache-2.0
|
License: Apache-2.0
|
||||||
Release: 1%{?dist}
|
Release: 2%{?dist}
|
||||||
Summary: OCI container runtime monitor
|
Summary: OCI container runtime monitor
|
||||||
URL: https://github.com/containers/%{name}
|
URL: https://github.com/containers/%{name}
|
||||||
# Tarball fetched from upstream
|
# Tarball fetched from upstream
|
||||||
Source0: %{url}/archive/v%{version}.tar.gz
|
Source0: %{url}/archive/v%{version}.tar.gz
|
||||||
|
# https://github.com/containers/conmon/pull/659
|
||||||
|
Patch0001: 0001-Reset-create_pid-after-waitpid-to-prevent-signaling-.patch
|
||||||
%if %{with docs}
|
%if %{with docs}
|
||||||
BuildRequires: go-md2man
|
BuildRequires: go-md2man
|
||||||
%endif
|
%endif
|
||||||
@@ -70,6 +72,10 @@ sed -i 's/install.bin: bin\/conmon/install.bin:/' Makefile
|
|||||||
%endif
|
%endif
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Mon Jun 22 2026 Jindrich Novy <jnovy@redhat.com> - 3:2.2.1-2
|
||||||
|
- reset create_pid after waitpid to prevent signaling unrelated processes
|
||||||
|
- Resolves: RHEL-178025
|
||||||
|
|
||||||
* Thu Feb 12 2026 Jindrich Novy <jnovy@redhat.com> - 3:2.2.1-1
|
* Thu Feb 12 2026 Jindrich Novy <jnovy@redhat.com> - 3:2.2.1-1
|
||||||
- update to https://github.com/containers/conmon/releases/tag/v2.2.1
|
- update to https://github.com/containers/conmon/releases/tag/v2.2.1
|
||||||
- enable RELRO
|
- enable RELRO
|
||||||
|
|||||||
Reference in New Issue
Block a user