Jorge Lucangeli Obes | 24b2913 | 2016-10-27 10:33:03 -0400 | [diff] [blame] | 1 | // Copyright (C) 2016 The Android Open Source Project |
| 2 | // |
| 3 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 4 | // you may not use this file except in compliance with the License. |
| 5 | // You may obtain a copy of the License at |
| 6 | // |
| 7 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 8 | // |
| 9 | // Unless required by applicable law or agreed to in writing, software |
| 10 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 11 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 12 | // See the License for the specific language governing permissions and |
| 13 | // limitations under the License. |
| 14 | |
Jorge Lucangeli Obes | f3f824e | 2016-12-15 12:13:38 -0500 | [diff] [blame] | 15 | #ifndef _INIT_CAPABILITIES_H |
| 16 | #define _INIT_CAPABILITIES_H |
| 17 | |
Luis Hector Chavez | 519e5f0 | 2017-06-29 09:50:30 -0700 | [diff] [blame] | 18 | #include <sys/capability.h> |
Jorge Lucangeli Obes | 24b2913 | 2016-10-27 10:33:03 -0400 | [diff] [blame] | 19 | |
| 20 | #include <bitset> |
| 21 | #include <string> |
Luis Hector Chavez | 519e5f0 | 2017-06-29 09:50:30 -0700 | [diff] [blame] | 22 | #include <type_traits> |
Jorge Lucangeli Obes | 24b2913 | 2016-10-27 10:33:03 -0400 | [diff] [blame] | 23 | |
Tom Cherry | 81f5d3e | 2017-06-22 12:53:17 -0700 | [diff] [blame] | 24 | namespace android { |
| 25 | namespace init { |
| 26 | |
Luis Hector Chavez | 519e5f0 | 2017-06-29 09:50:30 -0700 | [diff] [blame] | 27 | struct CapDeleter { |
| 28 | void operator()(cap_t caps) const { cap_free(caps); } |
| 29 | }; |
| 30 | |
Jorge Lucangeli Obes | 24b2913 | 2016-10-27 10:33:03 -0400 | [diff] [blame] | 31 | using CapSet = std::bitset<CAP_LAST_CAP + 1>; |
Luis Hector Chavez | 519e5f0 | 2017-06-29 09:50:30 -0700 | [diff] [blame] | 32 | using ScopedCaps = std::unique_ptr<std::remove_pointer<cap_t>::type, CapDeleter>; |
Jorge Lucangeli Obes | 24b2913 | 2016-10-27 10:33:03 -0400 | [diff] [blame] | 33 | |
| 34 | int LookupCap(const std::string& cap_name); |
Jorge Lucangeli Obes | f3f824e | 2016-12-15 12:13:38 -0500 | [diff] [blame] | 35 | bool CapAmbientSupported(); |
| 36 | unsigned int GetLastValidCap(); |
Jorge Lucangeli Obes | 24b2913 | 2016-10-27 10:33:03 -0400 | [diff] [blame] | 37 | bool SetCapsForExec(const CapSet& to_keep); |
Luis Hector Chavez | 94fb5b0 | 2017-11-16 15:52:00 -0800 | [diff] [blame] | 38 | bool DropInheritableCaps(); |
Jorge Lucangeli Obes | f3f824e | 2016-12-15 12:13:38 -0500 | [diff] [blame] | 39 | |
Tom Cherry | 81f5d3e | 2017-06-22 12:53:17 -0700 | [diff] [blame] | 40 | } // namespace init |
| 41 | } // namespace android |
| 42 | |
Jorge Lucangeli Obes | f3f824e | 2016-12-15 12:13:38 -0500 | [diff] [blame] | 43 | #endif // _INIT_CAPABILITIES_H |