aboutsummaryrefslogtreecommitdiffhomepage
path: root/syscall.go
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-07-03 02:59:43 +0900
committerOphestra <cat@gensokyo.uk>2025-07-03 02:59:43 +0900
commit1b5ecd9eaf3289d164d8ed1bce6013e0e4ef8e86 (patch)
tree047fe5fabdfb37d5c0088f7f572cebc8b13853bb /syscall.go
parent82561d62b66f17c05604e87f18187bb3a91f00d2 (diff)
container: move out of toplevel
This allows slightly easier use of the vanity url. This also provides some disambiguation between low level containers and hakurei app containers. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'syscall.go')
-rw-r--r--syscall.go81
1 files changed, 0 insertions, 81 deletions
diff --git a/syscall.go b/syscall.go
deleted file mode 100644
index 4b22c23b..00000000
--- a/syscall.go
+++ /dev/null
@@ -1,81 +0,0 @@
-package hakurei
-
-import (
- "syscall"
- "unsafe"
-)
-
-const (
- O_PATH = 0x200000
-
- PR_SET_NO_NEW_PRIVS = 0x26
-
- CAP_SYS_ADMIN = 0x15
- CAP_SETPCAP = 0x8
-)
-
-const (
- SUID_DUMP_DISABLE = iota
- SUID_DUMP_USER
-)
-
-func SetDumpable(dumpable uintptr) error {
- // linux/sched/coredump.h
- if _, _, errno := syscall.Syscall(syscall.SYS_PRCTL, syscall.PR_SET_DUMPABLE, dumpable, 0); errno != 0 {
- return errno
- }
-
- return nil
-}
-
-const (
- _LINUX_CAPABILITY_VERSION_3 = 0x20080522
-
- PR_CAP_AMBIENT = 0x2f
- PR_CAP_AMBIENT_RAISE = 0x2
- PR_CAP_AMBIENT_CLEAR_ALL = 0x4
-)
-
-type (
- capHeader struct {
- version uint32
- pid int32
- }
-
- capData struct {
- effective uint32
- permitted uint32
- inheritable uint32
- }
-)
-
-// See CAP_TO_INDEX in linux/capability.h:
-func capToIndex(cap uintptr) uintptr { return cap >> 5 }
-
-// See CAP_TO_MASK in linux/capability.h:
-func capToMask(cap uintptr) uint32 { return 1 << uint(cap&31) }
-
-func capset(hdrp *capHeader, datap *[2]capData) error {
- if _, _, errno := syscall.Syscall(syscall.SYS_CAPSET,
- uintptr(unsafe.Pointer(hdrp)),
- uintptr(unsafe.Pointer(&datap[0])), 0); errno != 0 {
- return errno
- }
- return nil
-}
-
-// IgnoringEINTR makes a function call and repeats it if it returns an
-// EINTR error. This appears to be required even though we install all
-// signal handlers with SA_RESTART: see #22838, #38033, #38836, #40846.
-// Also #20400 and #36644 are issues in which a signal handler is
-// installed without setting SA_RESTART. None of these are the common case,
-// but there are enough of them that it seems that we can't avoid
-// an EINTR loop.
-func IgnoringEINTR(fn func() error) error {
- for {
- err := fn()
- if err != syscall.EINTR {
- return err
- }
- }
-}