aboutsummaryrefslogtreecommitdiffhomepage
path: root/container/capability.go
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-08-21 21:59:07 +0900
committerOphestra <cat@gensokyo.uk>2025-08-22 19:27:31 +0900
commit09d284498109b847da0da1e2c5f883268a7f2d46 (patch)
tree3784dee4b4e4ec97a95cb222c70d05463ae640ef /container/capability.go
parentd500d6e55917e12a3f98b39cf0d29b6c96de9667 (diff)
container/init: wrap syscall helper functions
This allows tests to stub all kernel behaviour, enabling measurement of all function call arguments and error injection. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/capability.go')
-rw-r--r--container/capability.go47
1 files changed, 45 insertions, 2 deletions
diff --git a/container/capability.go b/container/capability.go
index fda2fb2a..f41bffa7 100644
--- a/container/capability.go
+++ b/container/capability.go
@@ -37,9 +37,52 @@ func capToIndex(cap uintptr) uintptr { return cap >> 5 }
func capToMask(cap uintptr) uint32 { return 1 << uint(cap&31) }
func capset(hdrp *capHeader, datap *[2]capData) error {
- if _, _, errno := syscall.Syscall(syscall.SYS_CAPSET,
+ r, _, errno := syscall.Syscall(
+ syscall.SYS_CAPSET,
uintptr(unsafe.Pointer(hdrp)),
- uintptr(unsafe.Pointer(&datap[0])), 0); errno != 0 {
+ uintptr(unsafe.Pointer(&datap[0])), 0,
+ )
+ if r != 0 {
+ return errno
+ }
+ return nil
+}
+
+// capBoundingSetDrop drops a capability from the calling thread's capability bounding set.
+func capBoundingSetDrop(cap uintptr) error {
+ r, _, errno := syscall.Syscall(
+ syscall.SYS_PRCTL,
+ syscall.PR_CAPBSET_DROP,
+ cap, 0,
+ )
+ if r != 0 {
+ return errno
+ }
+ return nil
+}
+
+// capAmbientClearAll clears the ambient capability set of the calling thread.
+func capAmbientClearAll() error {
+ r, _, errno := syscall.Syscall(
+ syscall.SYS_PRCTL,
+ PR_CAP_AMBIENT,
+ PR_CAP_AMBIENT_CLEAR_ALL, 0,
+ )
+ if r != 0 {
+ return errno
+ }
+ return nil
+}
+
+// capAmbientRaise adds to the ambient capability set of the calling thread.
+func capAmbientRaise(cap uintptr) error {
+ r, _, errno := syscall.Syscall(
+ syscall.SYS_PRCTL,
+ PR_CAP_AMBIENT,
+ PR_CAP_AMBIENT_RAISE,
+ cap,
+ )
+ if r != 0 {
return errno
}
return nil