ret = lxc_caps_last_cap(&last_cap);
if (ret)
- return ret;
+ return syserror_ret(ret, "%d - Failed to drop capabilities", ret);
for (__u32 cap = 0; cap <= last_cap; cap++) {
if (ctx->capability_mask & (1LL << cap))
if (prctl(PR_CAPBSET_DROP, prctl_arg(cap), prctl_arg(0),
prctl_arg(0), prctl_arg(0)))
- return log_error_errno(-1, errno, "Failed to drop capability %d", cap);
+ return syserror("Failed to drop capability %d", cap);
TRACE("Dropped capability %d", cap);
}
{
__do_close int fd = -EBADF;
+ if (!cap)
+ return ret_errno(EINVAL);
+
+ *cap = 0;
+
/*
* Try to get the maximum capability over the kernel interface
* introduced in v3.2.
0);
if (fd >= 0) {
ssize_t ret;
- unsigned res;
- char buf[INTTYPE_TO_STRLEN(__u32)] = {0};
+ unsigned int res;
+ char buf[INTTYPE_TO_STRLEN(unsigned int)] = {0};
ret = lxc_read_nointr(fd, buf, STRARRAYLEN(buf));
if (ret <= 0)
- return ret_errno(EINVAL);
+ return syserror_set(EINVAL, "Failed to read \"/proc/sys/kernel/cap_last_cap\"");
- ret = lxc_safe_uint(buf, &res);
+ ret = lxc_safe_uint(lxc_trim_whitespace_in_place(buf), &res);
if (ret < 0)
- return ret;
+ return syserror("Failed to parse unsigned integer %s", buf);
*cap = (__u32)res;
} else {
while (prctl(PR_CAPBSET_READ, prctl_arg(cur_cap)) >= 0)
cur_cap++;
- *cap = cur_cap - 1;
+ if (cur_cap)
+ *cap = cur_cap - 1;
}
return 0;
static int ret = -1;
static __u32 last_cap = 0;
+ if (!cap)
+ return ret_errno(EINVAL);
+
if (ret < 0) {
ret = __caps_last_cap(&last_cap);
if (ret)