From 3cd79f2cffe1d032dcc76652345374f535dc4936 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Mon, 21 Sep 2026 05:54:14 -1000 Subject: Fail cleanly when a filter cannot run A filter program that could not be run answered with two responses, and a filter that exited without reading its input ended cgit with the page half written. --- source/cache.c | 3 +++ 1 file changed, 3 insertions(+) (limited to 'source/cache.c') diff --git a/source/cache.c b/source/cache.c index 28558b1..8123e5e 100644 --- a/source/cache.c +++ b/source/cache.c @@ -314,6 +314,9 @@ static int fill_slot(struct cache_slot *slot) slot->saved_stdout = dup(STDOUT_FILENO); if (slot->saved_stdout == -1) return errno; + // A filter program that outlives the request must not hold the client + // connection open. + fcntl(slot->saved_stdout, F_SETFD, FD_CLOEXEC); if (dup2(slot->lock_fd, STDOUT_FILENO) == -1) return errno; -- cgit v2.8.0