diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-07-07 13:47:05 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-07-07 13:47:13 +0900 |
| commit | ddfcc51b913a70da48102f64e18b34579dc3611c (patch) | |
| tree | 72023b935557ae8f25ec1b62add00d0b671c6841 /container/capability.go | |
| parent | 8ebedbd88ae2cf0da1c787fa456455065b7dc3a2 (diff) | |
container: move capset implementation
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container/capability.go')
| -rw-r--r-- | container/capability.go | 45 |
1 files changed, 45 insertions, 0 deletions
diff --git a/container/capability.go b/container/capability.go new file mode 100644 index 00000000..7c36ce9e --- /dev/null +++ b/container/capability.go @@ -0,0 +1,45 @@ +package container + +import ( + "syscall" + "unsafe" +) + +const ( + _LINUX_CAPABILITY_VERSION_3 = 0x20080522 + + PR_CAP_AMBIENT = 0x2f + PR_CAP_AMBIENT_RAISE = 0x2 + PR_CAP_AMBIENT_CLEAR_ALL = 0x4 + + CAP_SYS_ADMIN = 0x15 + CAP_SETPCAP = 0x8 +) + +type ( + capHeader struct { + version uint32 + pid int32 + } + + capData struct { + effective uint32 + permitted uint32 + inheritable uint32 + } +) + +// See CAP_TO_INDEX in linux/capability.h: +func capToIndex(cap uintptr) uintptr { return cap >> 5 } + +// See CAP_TO_MASK in linux/capability.h: +func capToMask(cap uintptr) uint32 { return 1 << uint(cap&31) } + +func capset(hdrp *capHeader, datap *[2]capData) error { + if _, _, errno := syscall.Syscall(syscall.SYS_CAPSET, + uintptr(unsafe.Pointer(hdrp)), + uintptr(unsafe.Pointer(&datap[0])), 0); errno != 0 { + return errno + } + return nil +} |
