Unverified Commit 1291d99a by Christian Brauner Committed by Stéphane Graber

autotools: check for cap_get_file

parent 723935d6
...@@ -368,7 +368,9 @@ AM_CONDITIONAL([ENABLE_CAP], [test "x$enable_capabilities" = "xyes"]) ...@@ -368,7 +368,9 @@ AM_CONDITIONAL([ENABLE_CAP], [test "x$enable_capabilities" = "xyes"])
AM_COND_IF([ENABLE_CAP], AM_COND_IF([ENABLE_CAP],
[AC_CHECK_HEADER([sys/capability.h],[],[AC_MSG_ERROR([You must install the libcap development package in order to compile lxc])]) [AC_CHECK_HEADER([sys/capability.h],[],[AC_MSG_ERROR([You must install the libcap development package in order to compile lxc])])
AC_CHECK_LIB(cap,cap_set_proc,[],[AC_MSG_ERROR([You must install the libcap development package in order to compile lxc])]) AC_CHECK_LIB(cap,cap_set_proc,[],[AC_MSG_ERROR([You must install the libcap development package in order to compile lxc])])
AC_SUBST([CAP_LIBS], [-lcap])]) # Test whether we support getting file capabilities via cap_get_file().
AC_CHECK_LIB(cap,cap_get_file, AC_DEFINE(LIBCAP_SUPPORTS_FILE_CAPABILITIES,1,[Have cap_get_file]),[],[])
AC_SUBST([CAP_LIBS], [-lcap])])
# HAVE_SCMP_FILTER_CTX=1 will tell us we have libseccomp api >= 1.0.0 # HAVE_SCMP_FILTER_CTX=1 will tell us we have libseccomp api >= 1.0.0
OLD_CFLAGS="$CFLAGS" OLD_CFLAGS="$CFLAGS"
......
...@@ -225,10 +225,7 @@ static bool lxc_cap_is_set(cap_t caps, cap_value_t cap, cap_flag_t flag) ...@@ -225,10 +225,7 @@ static bool lxc_cap_is_set(cap_t caps, cap_value_t cap, cap_flag_t flag)
bool lxc_file_cap_is_set(const char *path, cap_value_t cap, cap_flag_t flag) bool lxc_file_cap_is_set(const char *path, cap_value_t cap, cap_flag_t flag)
{ {
/* Android's bionic currently seems to lack support for cap_get_file(). */ #if LIBCAP_SUPPORTS_FILE_CAPABILITIES
#if IS_BIONIC
return true;
#else
bool cap_is_set; bool cap_is_set;
cap_t caps; cap_t caps;
...@@ -247,6 +244,9 @@ bool lxc_file_cap_is_set(const char *path, cap_value_t cap, cap_flag_t flag) ...@@ -247,6 +244,9 @@ bool lxc_file_cap_is_set(const char *path, cap_value_t cap, cap_flag_t flag)
cap_is_set = lxc_cap_is_set(caps, cap, flag); cap_is_set = lxc_cap_is_set(caps, cap, flag);
cap_free(caps); cap_free(caps);
return cap_is_set; return cap_is_set;
#else
errno = ENODATA;
return false;
#endif #endif
} }
......
...@@ -3254,7 +3254,7 @@ static int idmaptool_on_path_and_privileged(const char *binary, cap_value_t cap) ...@@ -3254,7 +3254,7 @@ static int idmaptool_on_path_and_privileged(const char *binary, cap_value_t cap)
goto cleanup; goto cleanup;
} }
#if HAVE_LIBCAP && !IS_BIONIC #if HAVE_LIBCAP && LIBCAP_SUPPORTS_FILE_CAPABILITIES
/* Check if it has the CAP_SETUID capability. */ /* Check if it has the CAP_SETUID capability. */
if ((cap & CAP_SETUID) && if ((cap & CAP_SETUID) &&
lxc_file_cap_is_set(path, CAP_SETUID, CAP_EFFECTIVE) && lxc_file_cap_is_set(path, CAP_SETUID, CAP_EFFECTIVE) &&
...@@ -3275,6 +3275,10 @@ static int idmaptool_on_path_and_privileged(const char *binary, cap_value_t cap) ...@@ -3275,6 +3275,10 @@ static int idmaptool_on_path_and_privileged(const char *binary, cap_value_t cap)
goto cleanup; goto cleanup;
} }
#else #else
/* If we cannot check for file capabilities we need to give the benefit
* of the doubt. Otherwise we might fail even though all the necessary
* file capabilities are set.
*/
DEBUG("Cannot check for file capabilites as full capability support is " DEBUG("Cannot check for file capabilites as full capability support is "
"missing. Manual intervention needed."); "missing. Manual intervention needed.");
fret = 1; fret = 1;
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment