libbb: compile capability code only if FEATURE_SETPRIV_CAPABILITIES or RUN_INIT
authorDenys Vlasenko <vda.linux@googlemail.com>
Wed, 21 Feb 2018 19:13:39 +0000 (20:13 +0100)
committerDenys Vlasenko <vda.linux@googlemail.com>
Wed, 21 Feb 2018 19:13:39 +0000 (20:13 +0100)
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
include/libbb.h
libbb/capability.c
util-linux/switch_root.c

index c02621d9495ef93dd70ee508b91d904d3af5db67..f1ab1ca6f5ae449bbd521f425bfff031f6222574 100644 (file)
@@ -1488,6 +1488,7 @@ extern void run_shell(const char *shell, int loginshell, const char **args) NORE
  */
 const char *get_shell_name(void) FAST_FUNC;
 
+#if ENABLE_FEATURE_SETPRIV_CAPABILITIES || ENABLE_RUN_INIT
 unsigned cap_name_to_number(const char *cap) FAST_FUNC;
 void printf_cap(const char *pfx, unsigned cap_no) FAST_FUNC;
 void drop_capability(int cap_ordinal) FAST_FUNC;
@@ -1499,9 +1500,7 @@ struct caps { \
        struct __user_cap_data_struct data[2]; \
 }
 void getcaps(void *caps) FAST_FUNC;
-
-unsigned cap_name_to_number(const char *name) FAST_FUNC;
-void printf_cap(const char *pfx, unsigned cap_no) FAST_FUNC;
+#endif
 
 #if ENABLE_SELINUX
 extern void renew_current_security_context(void) FAST_FUNC;
index f60062bfc5acbef857cc70236673e25799ba05bd..6587dcbf7ce57b4131c905e321e7016d986cc05d 100644 (file)
@@ -3,7 +3,8 @@
  *
  * Licensed under GPLv2 or later, see file LICENSE in this source tree.
  */
-//kbuild:lib-$(CONFIG_PLATFORM_LINUX) += capability.o
+//kbuild:lib-$(CONFIG_FEATURE_SETPRIV_CAPABILITIES) += capability.o
+//kbuild:lib-$(CONFIG_RUN_INIT) += capability.o
 
 #include <linux/capability.h>
 // #include <sys/capability.h>
index 2d1802b79029c3c6b5f20e21a3ebe1b641aabf3b..947dd0cdc15e95ac9d98a7db53f5807d3687af7d 100644 (file)
 #include <sys/mount.h>
 #if ENABLE_RUN_INIT
 # include <sys/prctl.h>
+# ifndef PR_CAPBSET_READ
+# define PR_CAPBSET_READ 23
+# endif
+# ifndef PR_CAPBSET_DROP
+# define PR_CAPBSET_DROP 24
+# endif
 # include <linux/capability.h>
 // #include <sys/capability.h>
 // This header is in libcap, but the functions are in libc.