aboutsummaryrefslogtreecommitdiffhomepage
path: root/container/capability.go
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2026-03-17 15:48:40 +0900
committerOphestra <cat@gensokyo.uk>2026-03-17 15:48:40 +0900
commitb852402f67b22a3a850ce4eb1305a3ce5898d128 (patch)
tree76ca77ab869198d5327e9557d8db897c0d6ec356 /container/capability.go
parent6d015a949e27f20c86409c7d78053f0b0493f165 (diff)
ext: move syscall wrappers from container
These are generally useful, and none of them are container-specific. Syscalls subtle to use and requiring container-specific setup remains in container. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/capability.go')
-rw-r--r--container/capability.go8
1 files changed, 5 insertions, 3 deletions
diff --git a/container/capability.go b/container/capability.go
index 3ea9d028..1d98ec4b 100644
--- a/container/capability.go
+++ b/container/capability.go
@@ -3,6 +3,8 @@ package container
import (
"syscall"
"unsafe"
+
+ "hakurei.app/ext"
)
const (
@@ -51,15 +53,15 @@ func capset(hdrp *capHeader, datap *[2]capData) error {
// capBoundingSetDrop drops a capability from the calling thread's capability bounding set.
func capBoundingSetDrop(cap uintptr) error {
- return Prctl(syscall.PR_CAPBSET_DROP, cap, 0)
+ return ext.Prctl(syscall.PR_CAPBSET_DROP, cap, 0)
}
// capAmbientClearAll clears the ambient capability set of the calling thread.
func capAmbientClearAll() error {
- return Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_CLEAR_ALL, 0)
+ return ext.Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_CLEAR_ALL, 0)
}
// capAmbientRaise adds to the ambient capability set of the calling thread.
func capAmbientRaise(cap uintptr) error {
- return Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_RAISE, cap)
+ return ext.Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_RAISE, cap)
}