Move Linux's no_new_privs call into os_calls
This helps keep the application code free of platform-specific cruft. Also remove a needless #include<sys/prctl.h> from sesman/session_list.c.
This commit is contained in:
@@ -53,6 +53,9 @@
|
||||
#include <sys/stat.h>
|
||||
#include <sys/ipc.h>
|
||||
#include <sys/shm.h>
|
||||
#if defined(HAVE_SYS_PRCTL_H)
|
||||
#include <sys/prctl.h>
|
||||
#endif
|
||||
#include <dlfcn.h>
|
||||
#include <arpa/inet.h>
|
||||
#include <netdb.h>
|
||||
@@ -3954,3 +3957,19 @@ g_tcp6_bind_address(int sck, const char *port, const char *address)
|
||||
return -1;
|
||||
#endif
|
||||
}
|
||||
|
||||
/*****************************************************************************/
|
||||
/* returns error, zero is success, non zero is error */
|
||||
/* only works in linux */
|
||||
int
|
||||
g_no_new_privs(void)
|
||||
{
|
||||
#if defined(HAVE_SYS_PRCTL_H) && defined(PR_SET_NO_NEW_PRIVS)
|
||||
/*
|
||||
* PR_SET_NO_NEW_PRIVS requires Linux kernel 3.5 and newer.
|
||||
*/
|
||||
return prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0);
|
||||
#else
|
||||
return 0;
|
||||
#endif
|
||||
}
|
||||
|
||||
@@ -333,6 +333,7 @@ int g_tcp4_socket(void);
|
||||
int g_tcp4_bind_address(int sck, const char *port, const char *address);
|
||||
int g_tcp6_socket(void);
|
||||
int g_tcp6_bind_address(int sck, const char *port, const char *address);
|
||||
int g_no_new_privs(void);
|
||||
|
||||
/* glib-style wrappers */
|
||||
#define g_new(struct_type, n_structs) \
|
||||
|
||||
Reference in New Issue
Block a user