]>
git.ipfire.org Git - thirdparty/pdns.git/blob - pdns/capabilities.cc
2 * This file is part of PowerDNS or dnsdist.
3 * Copyright -- PowerDNS.COM B.V. and its contributors
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of version 2 of the GNU General Public License as
7 * published by the Free Software Foundation.
9 * In addition, for the avoidance of any doubt, permission is granted to
10 * link this program with OpenSSL and to (re)distribute the binaries
11 * produced as the result of such linking.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
29 #include <sys/capability.h>
32 #include "capabilities.hh"
35 void dropCapabilities(std::set
<std::string
> capabilitiesToKeep
)
38 cap_t caps
= cap_get_proc();
39 if (caps
!= nullptr) {
42 if (!capabilitiesToKeep
.empty()) {
43 std::vector
<cap_value_t
> toKeep
;
44 toKeep
.reserve(capabilitiesToKeep
.size());
46 for (const auto& capToKeep
: capabilitiesToKeep
) {
48 int res
= cap_from_name(capToKeep
.c_str(), &value
);
51 throw std::runtime_error("Unable to convert capability name '" + capToKeep
+ "': " + stringerror());
53 toKeep
.push_back(value
);
56 if (cap_set_flag(caps
, CAP_EFFECTIVE
, toKeep
.size(), toKeep
.data(), CAP_SET
) != 0) {
58 throw std::runtime_error("Unable to set effective flag capabilities: " + stringerror());
61 if (cap_set_flag(caps
, CAP_PERMITTED
, toKeep
.size(), toKeep
.data(), CAP_SET
) != 0) {
63 throw std::runtime_error("Unable to set permitted flag capabilities: " + stringerror());
67 if (cap_set_proc(caps
) != 0) {
69 throw std::runtime_error("Unable to drop capabilities: " + stringerror());
74 #endif /* HAVE_LIBCAP */