aboutsummaryrefslogtreecommitdiff
path: root/capability.go
blob: 759bb7a4f6c01290b3ed154973e79b3dc0a0ec89 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
package main

import (
	"log"
	"os"
	"os/exec"

	"github.com/syndtr/gocapability/capability"
)

func getCurrentCaps() *capability.Capabilities {
	caps, err := capability.NewPid2(0)
	if err != nil {
		log.Fatalf("Could not get self caps: %+v\n", err)
	}

	err = caps.Load()
	if err != nil {
		log.Fatalf("Could not load self caps: %+v\n", err)
	}

	return &caps
}

func getSelfFileCaps() *capability.Capabilities {
	self, err := os.Executable()
	log.Printf("Getting caps for: %s\n", self)
	if err != nil {
		log.Fatalf("Could not get path to own executable: %+v\n", err)
	}
	caps, err := capability.NewFile2(self)
	if err != nil {
		log.Fatalf("Could not get file caps: %+v\n", err)
	}

	err = caps.Load()
	if err != nil {
		log.Fatalf("Could not load file caps: %+v\n", err)
	}

	return &caps
}

func hasCapSysResource(caps *capability.Capabilities) bool {
	return (*caps).Get(capability.EFFECTIVE, capability.CAP_SYS_RESOURCE)
}

func makeBinarySetcapped() error {
	fileCaps := *getSelfFileCaps()
	if !hasCapSysResource(&fileCaps) {
		fileCaps.Set(capability.EFFECTIVE|capability.PERMITTED|capability.INHERITABLE, capability.CAP_SYS_RESOURCE)
		err := fileCaps.Apply(capability.EFFECTIVE | capability.PERMITTED | capability.INHERITABLE)
		if err != nil {
			return err
		}
	}
	return nil
}

func pkexecSetcapSelf() error {
	self, err := os.Executable()
	if err != nil {
		log.Fatalf("Couldn't find path to own binary\n")
		return err
	}

	cmd := exec.Command("pkexec", self, "-setcap")
	log.Printf("Calling: %s\n", cmd.String())
	err = cmd.Run()
	if err != nil {
		log.Printf("Couldn't setcap self as root: %v\n", err)
		return err
	}

	return nil
}