aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-07-07 13:47:05 +0900
committerOphestra <cat@gensokyo.uk>2025-07-07 13:47:13 +0900
commitddfcc51b913a70da48102f64e18b34579dc3611c (patch)
tree72023b935557ae8f25ec1b62add00d0b671c6841
parent8ebedbd88ae2cf0da1c787fa456455065b7dc3a2 (diff)
container: move capset implementation
Signed-off-by: Ophestra <cat@gensokyo.uk>
-rw-r--r--container/capability.go45
-rw-r--r--container/syscall.go42
2 files changed, 45 insertions, 42 deletions
diff --git a/container/capability.go b/container/capability.go
new file mode 100644
index 00000000..7c36ce9e
--- /dev/null
+++ b/container/capability.go
@@ -0,0 +1,45 @@
+package container
+
+import (
+ "syscall"
+ "unsafe"
+)
+
+const (
+ _LINUX_CAPABILITY_VERSION_3 = 0x20080522
+
+ PR_CAP_AMBIENT = 0x2f
+ PR_CAP_AMBIENT_RAISE = 0x2
+ PR_CAP_AMBIENT_CLEAR_ALL = 0x4
+
+ CAP_SYS_ADMIN = 0x15
+ CAP_SETPCAP = 0x8
+)
+
+type (
+ capHeader struct {
+ version uint32
+ pid int32
+ }
+
+ capData struct {
+ effective uint32
+ permitted uint32
+ inheritable uint32
+ }
+)
+
+// See CAP_TO_INDEX in linux/capability.h:
+func capToIndex(cap uintptr) uintptr { return cap >> 5 }
+
+// See CAP_TO_MASK in linux/capability.h:
+func capToMask(cap uintptr) uint32 { return 1 << uint(cap&31) }
+
+func capset(hdrp *capHeader, datap *[2]capData) error {
+ if _, _, errno := syscall.Syscall(syscall.SYS_CAPSET,
+ uintptr(unsafe.Pointer(hdrp)),
+ uintptr(unsafe.Pointer(&datap[0])), 0); errno != 0 {
+ return errno
+ }
+ return nil
+}
diff --git a/container/syscall.go b/container/syscall.go
index c30aa8f3..075da89a 100644
--- a/container/syscall.go
+++ b/container/syscall.go
@@ -2,12 +2,6 @@ package container
import (
"syscall"
- "unsafe"
-)
-
-const (
- CAP_SYS_ADMIN = 0x15
- CAP_SETPCAP = 0x8
)
const (
@@ -24,42 +18,6 @@ func SetDumpable(dumpable uintptr) error {
return nil
}
-const (
- _LINUX_CAPABILITY_VERSION_3 = 0x20080522
-
- PR_CAP_AMBIENT = 0x2f
- PR_CAP_AMBIENT_RAISE = 0x2
- PR_CAP_AMBIENT_CLEAR_ALL = 0x4
-)
-
-type (
- capHeader struct {
- version uint32
- pid int32
- }
-
- capData struct {
- effective uint32
- permitted uint32
- inheritable uint32
- }
-)
-
-// See CAP_TO_INDEX in linux/capability.h:
-func capToIndex(cap uintptr) uintptr { return cap >> 5 }
-
-// See CAP_TO_MASK in linux/capability.h:
-func capToMask(cap uintptr) uint32 { return 1 << uint(cap&31) }
-
-func capset(hdrp *capHeader, datap *[2]capData) error {
- if _, _, errno := syscall.Syscall(syscall.SYS_CAPSET,
- uintptr(unsafe.Pointer(hdrp)),
- uintptr(unsafe.Pointer(&datap[0])), 0); errno != 0 {
- return errno
- }
- return nil
-}
-
// IgnoringEINTR makes a function call and repeats it if it returns an
// EINTR error. This appears to be required even though we install all
// signal handlers with SA_RESTART: see #22838, #38033, #38836, #40846.