From b852402f67b22a3a850ce4eb1305a3ce5898d128 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 17 Mar 2026 15:48:40 +0900 Subject: ext: move syscall wrappers from container These are generally useful, and none of them are container-specific. Syscalls subtle to use and requiring container-specific setup remains in container. Signed-off-by: Ophestra --- container/capability.go | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) (limited to 'container/capability.go') diff --git a/container/capability.go b/container/capability.go index 3ea9d028..1d98ec4b 100644 --- a/container/capability.go +++ b/container/capability.go @@ -3,6 +3,8 @@ package container import ( "syscall" "unsafe" + + "hakurei.app/ext" ) const ( @@ -51,15 +53,15 @@ func capset(hdrp *capHeader, datap *[2]capData) error { // capBoundingSetDrop drops a capability from the calling thread's capability bounding set. func capBoundingSetDrop(cap uintptr) error { - return Prctl(syscall.PR_CAPBSET_DROP, cap, 0) + return ext.Prctl(syscall.PR_CAPBSET_DROP, cap, 0) } // capAmbientClearAll clears the ambient capability set of the calling thread. func capAmbientClearAll() error { - return Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_CLEAR_ALL, 0) + return ext.Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_CLEAR_ALL, 0) } // capAmbientRaise adds to the ambient capability set of the calling thread. func capAmbientRaise(cap uintptr) error { - return Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_RAISE, cap) + return ext.Prctl(PR_CAP_AMBIENT, PR_CAP_AMBIENT_RAISE, cap) } -- cgit v1.3.1