From nobody Wed Sep 09 08:35:25 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hfvJZ3ZMQz6rj2P for ; Wed, 09 Sep 2026 08:35:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hfvJZ2Hgjz4Nqd for ; Wed, 09 Sep 2026 08:35:26 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788942926; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Uz/zuJGLmX3hOGSF+KXuaOBs07HMN4X2TF0xxcFxDQA=; b=qTFj4R1yEx4pFxvPkcMR5UesCCX8Z3EHYZRXLiNYkkOefN974NmYUUzL5UOUku3kPWG9+2 rq9sUovooA8Q7kWNeMUrl41OFZfMAE1a2oAg6v+UShXQ9BiLOjollr+zT+GdPEH4s5oq4j mL7Smf52Sr1fFk2Gd8ughTm/xtjorEpulq/RuW+IZUt4CBzyL3F2qmcmZMtuxWfo+kYzKH jCkgk0pPZX+cligZHt6Vi7TCyCDffyBMEZi5KmoyjOdyY2nsxagfE/kT/Ats5Q2+BRpxJ7 8UcTdmkID9BpVd/WmnSIZIiXcptAOSUhqM11S5Qc7U6AFKKzK9MSAPksN/fEBg== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1788942926; b=gmREY02GXsIEDEu24wZoNgmI1WxDCU8Fi2c8dDsWpz3VxflVIG51JAf2ExrYdK8BrkhV3y dMFt1W+4kXbDaCQgr1BW3J0g3nDdzLRN3HGrZvsjGV6Mm+sqGRbp2NTY4JaU+8cToAB+BA S95ov9mfH4nmj7U81my/4Rof21SXPLk1t9enXIiv8iWVjlCpb/Cwth9oZ9B53b1r7S3bA0 FDOpzk24SpWck8WUsiSebrraIb6ijG08pWtbbI5XVSyZXjZlKc0DAoXv7VpTjJP8ooST+S v8qQTj/uY/bzHWptKA1T6mFZqnjuDXcAidBLlPwE57rbeVE7zBukXLbASplBZQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788942926; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Uz/zuJGLmX3hOGSF+KXuaOBs07HMN4X2TF0xxcFxDQA=; b=wPnFhgQfRb4Fiop6QJ2D80dIP6qOeMOw3oIaw8a+YZdG1gulbqKxtcq4nq42CrxPYz9eFa a/jUwSsGJ1f9f9GqJgioqe1BSDaaZ37SkRAmvCIGx+fWZpDn+cGIdDZKHzQKmlAkXG8soK 4KAfaaI+jvUg9fsNJZw6fkXKdHcZb5jO5BOvc7iWdCxW1hduoK1M8RkyWx1IgfXsUichpd 0RBQAiW1OLC7ayji1QDMA9JiS4g9e9dR19zf2tYe0NLgSWQXNX91nrzfFJOHqlULFzCwDw zEmXMYEEKFTAzR1uyfgS4CZ5pK4cCOBMnQdfjOCIEIkgFvBxnM3uMUOfp1Lelw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hfvJY51TbzpxR for ; Wed, 09 Sep 2026 08:35:25 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 18fe6 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Wed, 09 Sep 2026 08:35:25 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org Cc: Baptiste Daroussin From: Mark Johnston Subject: git: 8cf005884326 - stable/15 - syslogd: reap pipe children on config reload List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: 8cf005884326fd15324bc484867c0a947607cb45 Auto-Submitted: auto-generated Date: Wed, 09 Sep 2026 08:35:25 +0000 Message-Id: <6aa11a4d.18fe6.5115ec0f@gitrepo.freebsd.org> The branch stable/15 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=8cf005884326fd15324bc484867c0a947607cb45 commit 8cf005884326fd15324bc484867c0a947607cb45 Author: Baptiste Daroussin AuthorDate: 2026-09-02 08:51:42 +0000 Commit: Mark Johnston CommitDate: 2026-09-09 08:34:33 +0000 syslogd: reap pipe children on config reload On SIGHUP reload, closelogfiles() frees each F_PIPE filed even when its pipe process is still running. close_filed() sets f_type to F_UNUSED before the check, so the condition f_type != F_PIPE is always true and the filed is freed while its process descriptor is still on the dead queue and registered in the kqueue. When the child later exits, the NOTE_EXIT handler dereferences the freed filed (use-after-free) and never closes the process descriptor, leaving the pipe child as a persistent zombie. Capture whether the filed is a pipe with an active process descriptor before calling close_filed(), and defer the free in that case so the NOTE_EXIT handler can reap the child and free the filed. Reviewed by: markj Fixes: 95381c0139d6 (syslogd: Use process descriptors) Differential Revision: https://reviews.freebsd.org/D59319 (cherry picked from commit 1a669b66ddb4748c24116e32dcb51eabaf4859ed) --- usr.sbin/syslogd/syslogd.c | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/usr.sbin/syslogd/syslogd.c b/usr.sbin/syslogd/syslogd.c index 8589f3ae9a12..13626eff44cb 100644 --- a/usr.sbin/syslogd/syslogd.c +++ b/usr.sbin/syslogd/syslogd.c @@ -2547,6 +2547,7 @@ void closelogfiles(void) { struct filed *f; + bool defer_free; while (!STAILQ_EMPTY(&fhead)) { f = STAILQ_FIRST(&fhead); @@ -2556,6 +2557,13 @@ closelogfiles(void) if (f->f_prevcount) fprintlog_successive(f, 0); + /* + * If a piped process is running, then defer the filed + * cleanup until it exits. close_filed() below sets + * f_type to F_UNUSED, so capture this before calling it. + */ + defer_free = (f->f_type == F_PIPE && f->f_procdesc != -1); + switch (f->f_type) { case F_FILE: case F_FORW: @@ -2583,11 +2591,7 @@ closelogfiles(void) free(f->f_prop_filter); } - /* - * If a piped process is running, then defer the filed - * cleanup until it exits. - */ - if (f->f_type != F_PIPE || f->f_procdesc == -1) + if (!defer_free) free(f); } }