]>
Commit | Line | Data |
---|---|---|
f12666f2 RG |
1 | /* |
2 | * This file is part of PowerDNS or dnsdist. | |
3 | * Copyright -- PowerDNS.COM B.V. and its contributors | |
4 | * | |
5 | * This program is free software; you can redistribute it and/or modify | |
6 | * it under the terms of version 2 of the GNU General Public License as | |
7 | * published by the Free Software Foundation. | |
8 | * | |
9 | * In addition, for the avoidance of any doubt, permission is granted to | |
10 | * link this program with OpenSSL and to (re)distribute the binaries | |
11 | * produced as the result of such linking. | |
12 | * | |
13 | * This program is distributed in the hope that it will be useful, | |
14 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
15 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
16 | * GNU General Public License for more details. | |
17 | * | |
18 | * You should have received a copy of the GNU General Public License | |
19 | * along with this program; if not, write to the Free Software | |
20 | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. | |
21 | */ | |
22 | ||
23 | #include "config.h" | |
24 | ||
25 | #include <cstring> | |
26 | #include <stdexcept> | |
27 | ||
28 | #ifdef HAVE_LIBCAP | |
29 | #include <sys/capability.h> | |
30 | #endif | |
31 | ||
32 | #include "capabilities.hh" | |
33 | ||
34 | void dropCapabilities() | |
35 | { | |
36 | #ifdef HAVE_LIBCAP | |
37 | cap_t caps = cap_get_proc(); | |
38 | if (caps != nullptr) { | |
39 | cap_clear(caps); | |
40 | ||
41 | if (cap_set_proc(caps) != 0) { | |
42 | cap_free(caps); | |
43 | throw std::runtime_error("Unable to drop capabilities: " + std::string(strerror(errno))); | |
44 | } | |
45 | ||
46 | cap_free(caps); | |
47 | } | |
48 | #endif /* HAVE_LIBCAP */ | |
49 | } |