diff --git a/util/shm.c b/util/shm.c index e0d84e8e7..6fddebbb8 100644 --- a/util/shm.c +++ b/util/shm.c @@ -3,6 +3,7 @@ #include #include #include +#include #include #include #include @@ -73,6 +74,14 @@ bool allocate_shm_file_pair(size_t size, int *rw_fd_ptr, int *ro_fd_ptr) { shm_unlink(name); + // Make sure the file cannot be re-opened in read-write mode (e.g. via + // "/proc/self/fd/" on Linux) + if (fchmod(rw_fd, 0) != 0) { + close(rw_fd); + close(ro_fd); + return false; + } + int ret; do { ret = ftruncate(rw_fd, size);