-
Notifications
You must be signed in to change notification settings - Fork 233
/
capability.go
79 lines (65 loc) · 1.72 KB
/
capability.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
// This file is part of the program "NoiseTorch-ng".
// Please see the LICENSE file for copyright information.
package main
import (
"log"
"os"
"os/exec"
"github.com/syndtr/gocapability/capability"
)
func getCurrentCaps() *capability.Capabilities {
caps, err := capability.NewPid2(0)
if err != nil {
log.Fatalf("Could not get self caps: %+v\n", err)
}
err = caps.Load()
if err != nil {
log.Fatalf("Could not load self caps: %+v\n", err)
}
return &caps
}
func getSelfFileCaps() *capability.Capabilities {
self, err := os.Executable()
log.Printf("Getting caps for: %s\n", self)
if err != nil {
log.Fatalf("Could not get path to own executable: %+v\n", err)
}
caps, err := capability.NewFile2(self)
if err != nil {
log.Fatalf("Could not get file caps: %+v\n", err)
}
err = caps.Load()
if err != nil {
log.Fatalf("Could not load file caps: %+v\n", err)
}
return &caps
}
func hasCapSysResource(caps *capability.Capabilities) bool {
return (*caps).Get(capability.EFFECTIVE, capability.CAP_SYS_RESOURCE)
}
func makeBinarySetcapped() error {
fileCaps := *getSelfFileCaps()
if !hasCapSysResource(&fileCaps) {
fileCaps.Set(capability.EFFECTIVE|capability.PERMITTED|capability.INHERITABLE, capability.CAP_SYS_RESOURCE)
err := fileCaps.Apply(capability.EFFECTIVE | capability.PERMITTED | capability.INHERITABLE)
if err != nil {
return err
}
}
return nil
}
func pkexecSetcapSelf() error {
self, err := os.Executable()
if err != nil {
log.Fatalf("Couldn't find path to own binary\n")
return err
}
cmd := exec.Command("pkexec", self, "-setcap")
log.Printf("Calling: %s\n", cmd.String())
err = cmd.Run()
if err != nil {
log.Printf("Couldn't setcap self as root: %v\n", err)
return err
}
return nil
}