2 * Copyright (C) 2017 by <assafgordon@gmail.com>
4 * Licensed under GPLv2 or later, see file LICENSE in this source tree.
6 //kbuild:lib-$(CONFIG_FEATURE_SETPRIV_CAPABILITIES) += capability.o
7 //kbuild:lib-$(CONFIG_RUN_INIT) += capability.o
9 #include <linux/capability.h>
10 // #include <sys/capability.h>
11 // This header is in libcap, but the functions are in libc.
12 // Comment in the header says this above capset/capget:
13 /* system calls - look to libc for function to system call mapping */
14 extern int capset(cap_user_header_t header, cap_user_data_t data);
15 extern int capget(cap_user_header_t header, const cap_user_data_t data);
16 // so for bbox, let's just repeat the declarations.
17 // This way, libcap needs not be installed in build environment.
20 static const char *const capabilities[] = {
61 unsigned FAST_FUNC cap_name_to_number(const char *cap)
65 if ((sscanf(cap, "cap_%u", &n)) == 1) {
69 for (i = 0; i < ARRAY_SIZE(capabilities); i++) {
70 if (strcasecmp(capabilities[i], cap) != 0)
73 bb_error_msg_and_die("unknown capability '%s'", cap);
77 bb_error_msg_and_die("unknown capability '%s'", cap);
81 void FAST_FUNC printf_cap(const char *pfx, unsigned cap_no)
83 if (cap_no < ARRAY_SIZE(capabilities)) {
84 printf("%s%s", pfx, capabilities[cap_no]);
87 printf("%scap_%u", pfx, cap_no);
92 void FAST_FUNC getcaps(void *arg)
94 static const uint8_t versions[] = {
95 _LINUX_CAPABILITY_U32S_3, /* = 2 (fits into byte) */
96 _LINUX_CAPABILITY_U32S_2, /* = 2 */
97 _LINUX_CAPABILITY_U32S_1, /* = 1 */
100 struct caps *caps = arg;
102 caps->header.pid = 0;
103 for (i = 0; i < ARRAY_SIZE(versions); i++) {
104 caps->header.version = versions[i];
105 if (capget(&caps->header, NULL) == 0)
108 bb_simple_perror_msg_and_die("capget");
111 switch (caps->header.version) {
112 case _LINUX_CAPABILITY_VERSION_1:
113 caps->u32s = _LINUX_CAPABILITY_U32S_1;
115 case _LINUX_CAPABILITY_VERSION_2:
116 caps->u32s = _LINUX_CAPABILITY_U32S_2;
118 case _LINUX_CAPABILITY_VERSION_3:
119 caps->u32s = _LINUX_CAPABILITY_U32S_3;
122 bb_error_msg_and_die("unsupported capability version");
125 if (capget(&caps->header, caps->data) != 0)
126 bb_simple_perror_msg_and_die("capget");