[Bug #1222790] Set reuse-address and close-on-exec flags on the HTTP listening socket

This commit is contained in:
Andrew M. Kuchling 2005-12-04 15:07:41 +00:00
parent cf6b7c99d9
commit 3a97605500
2 changed files with 14 additions and 1 deletions

View File

@ -104,7 +104,7 @@ from xmlrpclib import Fault
import SocketServer import SocketServer
import BaseHTTPServer import BaseHTTPServer
import sys import sys
import os import os, fcntl
def resolve_dotted_attribute(obj, attr, allow_dotted_names=True): def resolve_dotted_attribute(obj, attr, allow_dotted_names=True):
"""resolve_dotted_attribute(a, 'b.c.d') => a.b.c.d """resolve_dotted_attribute(a, 'b.c.d') => a.b.c.d
@ -465,6 +465,8 @@ class SimpleXMLRPCServer(SocketServer.TCPServer,
from SimpleXMLRPCDispatcher to change this behavior. from SimpleXMLRPCDispatcher to change this behavior.
""" """
allow_reuse_address = True
def __init__(self, addr, requestHandler=SimpleXMLRPCRequestHandler, def __init__(self, addr, requestHandler=SimpleXMLRPCRequestHandler,
logRequests=1): logRequests=1):
self.logRequests = logRequests self.logRequests = logRequests
@ -472,6 +474,14 @@ class SimpleXMLRPCServer(SocketServer.TCPServer,
SimpleXMLRPCDispatcher.__init__(self) SimpleXMLRPCDispatcher.__init__(self)
SocketServer.TCPServer.__init__(self, addr, requestHandler) SocketServer.TCPServer.__init__(self, addr, requestHandler)
# [Bug #1222790] If possible, set close-on-exec flag; if a
# method spawns a subprocess, the subprocess shouldn't have
# the listening socket open.
if hasattr(fcntl, 'FD_CLOEXEC'):
flags = fcntl.fcntl(self.fileno(), fcntl.F_GETFD)
flags |= fcntl.FD_CLOEXEC
fcntl.fcntl(self.fileno(), fcntl.F_SETFD, flags)
class CGIXMLRPCRequestHandler(SimpleXMLRPCDispatcher): class CGIXMLRPCRequestHandler(SimpleXMLRPCDispatcher):
"""Simple handler for XML-RPC data passed through CGI.""" """Simple handler for XML-RPC data passed through CGI."""

View File

@ -448,6 +448,9 @@ Library
disables recursive traversal through instance attributes, which can disables recursive traversal through instance attributes, which can
be exploited in various ways. be exploited in various ways.
- Bug #1222790: in SimpleXMLRPCServer, set the reuse-address and close-on-exec
flags on the HTTP listening socket.
- Bug #1110478: Revert os.environ.update to do putenv again. - Bug #1110478: Revert os.environ.update to do putenv again.
- Bug #1103844: fix distutils.install.dump_dirs() with negated options. - Bug #1103844: fix distutils.install.dump_dirs() with negated options.