]>
git.ipfire.org Git - thirdparty/pdns.git/blob - pdns/capabilities.cc
2 * This file is part of PowerDNS or dnsdist.
3 * Copyright -- PowerDNS.COM B.V. and its contributors
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of version 2 of the GNU General Public License as
7 * published by the Free Software Foundation.
9 * In addition, for the avoidance of any doubt, permission is granted to
10 * link this program with OpenSSL and to (re)distribute the binaries
11 * produced as the result of such linking.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
29 #include <sys/capability.h>
30 #include <sys/prctl.h>
33 #include "capabilities.hh"
36 bool dropCapabilities([[maybe_unused
]] std::set
<std::string
> capabilitiesToKeep
)
39 cap_t caps
= cap_get_proc();
40 if (caps
!= nullptr) {
43 if (!capabilitiesToKeep
.empty()) {
44 std::vector
<cap_value_t
> toKeep
;
45 toKeep
.reserve(capabilitiesToKeep
.size());
47 for (const auto& capToKeep
: capabilitiesToKeep
) {
49 int res
= cap_from_name(capToKeep
.c_str(), &value
);
52 throw std::runtime_error("Unable to convert capability name '" + capToKeep
+ "': " + stringerror());
54 toKeep
.push_back(value
);
57 if (cap_set_flag(caps
, CAP_EFFECTIVE
, toKeep
.size(), toKeep
.data(), CAP_SET
) != 0) {
59 throw std::runtime_error("Unable to set effective flag capabilities: " + stringerror());
62 if (cap_set_flag(caps
, CAP_PERMITTED
, toKeep
.size(), toKeep
.data(), CAP_SET
) != 0) {
64 throw std::runtime_error("Unable to set permitted flag capabilities: " + stringerror());
68 if (cap_set_proc(caps
) != 0) {
73 throw std::runtime_error("Unable to drop capabilities: " + stringerror());
79 #endif /* HAVE_LIBCAP */
83 bool dropCapabilitiesAfterSwitchingIDs()
86 #ifdef PR_SET_KEEPCAPS
87 if (prctl(PR_SET_KEEPCAPS
, 0, 0, 0, 0) == 0) {
90 #endif /* PR_SET_KEEPCAPS */
94 #endif /* HAVE_LIBCAP */
97 bool keepCapabilitiesAfterSwitchingIDs()
100 #ifdef PR_SET_KEEPCAPS
101 if (prctl(PR_SET_KEEPCAPS
, 1, 0, 0, 0) == 0) {
104 #endif /* PR_SET_KEEPCAPS */
108 #endif /* HAVE_LIBCAP */