aboutsummaryrefslogtreecommitdiffhomepage
path: root/container
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-08-21 00:33:46 +0900
committerOphestra <cat@gensokyo.uk>2025-08-21 00:33:46 +0900
commit5b73316ae03cd56161de65be25a3b716d9ba7d78 (patch)
tree77922ab5e1f16a9f057270097ca2b273a359561f /container
parent5d8a2199b6c8dc5f75b529a39d196c6cb14c98c2 (diff)
container/syscall: doc comments from manpages
These are pulled straight from the manpages. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'container')
-rw-r--r--container/syscall.go13
1 files changed, 8 insertions, 5 deletions
diff --git a/container/syscall.go b/container/syscall.go
index 8fb41e7d..20ac068d 100644
--- a/container/syscall.go
+++ b/container/syscall.go
@@ -4,11 +4,7 @@ import (
"syscall"
)
-const (
- SUID_DUMP_DISABLE = iota
- SUID_DUMP_USER
-)
-
+// SetPtracer allows processes to ptrace(2) the calling process.
func SetPtracer(pid uintptr) error {
_, _, errno := syscall.Syscall(syscall.SYS_PRCTL, syscall.PR_SET_PTRACER, pid, 0)
if errno == 0 {
@@ -17,6 +13,12 @@ func SetPtracer(pid uintptr) error {
return errno
}
+const (
+ SUID_DUMP_DISABLE = iota
+ SUID_DUMP_USER
+)
+
+// SetDumpable sets the "dumpable" attribute of the calling process.
func SetDumpable(dumpable uintptr) error {
// linux/sched/coredump.h
if _, _, errno := syscall.Syscall(syscall.SYS_PRCTL, syscall.PR_SET_DUMPABLE, dumpable, 0); errno != 0 {
@@ -26,6 +28,7 @@ func SetDumpable(dumpable uintptr) error {
return nil
}
+// SetNoNewPrivs sets the calling thread's no_new_privs attribute.
func SetNoNewPrivs() error {
_, _, errno := syscall.Syscall(syscall.SYS_PRCTL, PR_SET_NO_NEW_PRIVS, 1, 0)
if errno == 0 {