summaryrefslogtreecommitdiff
path: root/pkg/libcontainer/capabilities/capabilities.go
blob: 4b81e708c7034c0ec92de9c5fd2486ebb4733d02 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
package capabilities

import (
	"github.com/dotcloud/docker/pkg/libcontainer"
	"github.com/syndtr/gocapability/capability"
	"os"
)

// DropCapabilities drops capabilities for the current process based
// on the container's configuration.
func DropCapabilities(container *libcontainer.Container) error {
	if drop := getCapabilitiesMask(container); len(drop) > 0 {
		c, err := capability.NewPid(os.Getpid())
		if err != nil {
			return err
		}
		c.Unset(capability.CAPS|capability.BOUNDS, drop...)

		if err := c.Apply(capability.CAPS | capability.BOUNDS); err != nil {
			return err
		}
	}
	return nil
}

// getCapabilitiesMask returns the specific cap mask values for the libcontainer types
func getCapabilitiesMask(container *libcontainer.Container) []capability.Cap {
	drop := []capability.Cap{}
	for _, c := range container.CapabilitiesMask {
		if !c.Enabled {
			drop = append(drop, c.Value)
		}
	}
	return drop
}