diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-07-03 02:59:43 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-07-03 02:59:43 +0900 |
| commit | 1b5ecd9eaf3289d164d8ed1bce6013e0e4ef8e86 (patch) | |
| tree | 047fe5fabdfb37d5c0088f7f572cebc8b13853bb /syscall.go | |
| parent | 82561d62b66f17c05604e87f18187bb3a91f00d2 (diff) | |
container: move out of toplevel
This allows slightly easier use of the vanity url. This also provides some disambiguation between low level containers and hakurei app containers.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'syscall.go')
| -rw-r--r-- | syscall.go | 81 |
1 files changed, 0 insertions, 81 deletions
diff --git a/syscall.go b/syscall.go deleted file mode 100644 index 4b22c23b..00000000 --- a/syscall.go +++ /dev/null @@ -1,81 +0,0 @@ -package hakurei - -import ( - "syscall" - "unsafe" -) - -const ( - O_PATH = 0x200000 - - PR_SET_NO_NEW_PRIVS = 0x26 - - CAP_SYS_ADMIN = 0x15 - CAP_SETPCAP = 0x8 -) - -const ( - SUID_DUMP_DISABLE = iota - SUID_DUMP_USER -) - -func SetDumpable(dumpable uintptr) error { - // linux/sched/coredump.h - if _, _, errno := syscall.Syscall(syscall.SYS_PRCTL, syscall.PR_SET_DUMPABLE, dumpable, 0); errno != 0 { - return errno - } - - return nil -} - -const ( - _LINUX_CAPABILITY_VERSION_3 = 0x20080522 - - PR_CAP_AMBIENT = 0x2f - PR_CAP_AMBIENT_RAISE = 0x2 - PR_CAP_AMBIENT_CLEAR_ALL = 0x4 -) - -type ( - capHeader struct { - version uint32 - pid int32 - } - - capData struct { - effective uint32 - permitted uint32 - inheritable uint32 - } -) - -// See CAP_TO_INDEX in linux/capability.h: -func capToIndex(cap uintptr) uintptr { return cap >> 5 } - -// See CAP_TO_MASK in linux/capability.h: -func capToMask(cap uintptr) uint32 { return 1 << uint(cap&31) } - -func capset(hdrp *capHeader, datap *[2]capData) error { - if _, _, errno := syscall.Syscall(syscall.SYS_CAPSET, - uintptr(unsafe.Pointer(hdrp)), - uintptr(unsafe.Pointer(&datap[0])), 0); errno != 0 { - return errno - } - return nil -} - -// IgnoringEINTR makes a function call and repeats it if it returns an -// EINTR error. This appears to be required even though we install all -// signal handlers with SA_RESTART: see #22838, #38033, #38836, #40846. -// Also #20400 and #36644 are issues in which a signal handler is -// installed without setting SA_RESTART. None of these are the common case, -// but there are enough of them that it seems that we can't avoid -// an EINTR loop. -func IgnoringEINTR(fn func() error) error { - for { - err := fn() - if err != syscall.EINTR { - return err - } - } -} |
