Compare commits
27 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
57efd4bc2c | ||
|
|
3841494977 | ||
|
|
7d2dc21766 | ||
|
|
c778acb9b6 | ||
|
|
b314d2836f | ||
|
|
3e46c35d57 | ||
|
|
e50a9a834e | ||
|
|
2d7827722c | ||
|
|
d4daf5c72d | ||
|
|
c424d3171a | ||
|
|
4fe8b15f87 | ||
|
|
1d5d75ed59 | ||
|
|
5057f0cd10 | ||
|
|
24ef02c520 | ||
|
|
2e2911fb6d | ||
|
|
6f91fcbc5f | ||
|
|
3d5ccd04ae | ||
|
|
60065d487c | ||
|
|
9f3a9a3cd7 | ||
|
|
6e1f9b5dcf | ||
|
|
798cc68dc1 | ||
|
|
d46b0c4bb9 | ||
|
|
138da7918a | ||
|
|
bd74dec52f | ||
|
|
c9018b3ea2 | ||
|
|
5a3c09b944 | ||
|
|
3ba8798fc9 |
14 changed files with 1091 additions and 6 deletions
1
.gitignore
vendored
Normal file
1
.gitignore
vendored
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
libcap-1.10.tar.bz2
|
||||||
6
Makefile
6
Makefile
|
|
@ -1,6 +0,0 @@
|
||||||
# Makefile for source rpm: libcap
|
|
||||||
# $Id$
|
|
||||||
NAME := libcap
|
|
||||||
SPECFILE = $(firstword $(wildcard *.spec))
|
|
||||||
|
|
||||||
include ../common/Makefile.common
|
|
||||||
264
capfaq-0.2.txt
Normal file
264
capfaq-0.2.txt
Normal file
|
|
@ -0,0 +1,264 @@
|
||||||
|
This is the Linux kernel capabilities FAQ
|
||||||
|
|
||||||
|
Its history, to the extent that I am able to reconstruct it is that
|
||||||
|
v2.0 was posted to the Linux kernel list on 1999/04/02 by Boris
|
||||||
|
Tobotras. Thanks to Denis Ducamp for forwarding me a copy.
|
||||||
|
|
||||||
|
Cheers
|
||||||
|
|
||||||
|
Andrew
|
||||||
|
|
||||||
|
Linux Capabilities FAQ 0.2
|
||||||
|
==========================
|
||||||
|
|
||||||
|
1) What is a capability?
|
||||||
|
|
||||||
|
The name "capabilities" as used in the Linux kernel can be confusing.
|
||||||
|
First there are Capabilities as defined in computer science. A
|
||||||
|
capability is a token used by a process to prove that it is allowed to
|
||||||
|
do an operation on an object. The capability identifies the object
|
||||||
|
and the operations allowed on that object. A file descriptor is a
|
||||||
|
capability. You create the file descriptor with the "open" call and
|
||||||
|
request read or write permissions. Later, when doing a read or write
|
||||||
|
operation, the kernel uses the file descriptor as an index into a
|
||||||
|
data structure that indicates what operations are allowed. This is an
|
||||||
|
efficient way to check permissions. The necessary data structures are
|
||||||
|
created once during the "open" call. Later read and write calls only
|
||||||
|
have to do a table lookup. Operations on capabilities include copying
|
||||||
|
capabilities, transferring capabilities between processes, modifying a
|
||||||
|
capability, and revoking a capability. Modifying a capability can be
|
||||||
|
something like taking a read-write filedescriptor and making it
|
||||||
|
read-only. A capability often has a notion of an "owner" which is
|
||||||
|
able to invalidate all copies and derived versions of a capability.
|
||||||
|
Entire OSes are based on this "capability" model, with varying degrees
|
||||||
|
of purity. There are other ways of implementing capabilities than the
|
||||||
|
file descriptor model - traditionally special hardware has been used,
|
||||||
|
but modern systems also use the memory management unit of the CPU.
|
||||||
|
|
||||||
|
Then there is something quite different called "POSIX capabilities"
|
||||||
|
which is what Linux uses. These capabilities are a partitioning of
|
||||||
|
the all powerful root privilege into a set of distinct privileges (but
|
||||||
|
look at securelevel emulation to find out that this isn't necessary
|
||||||
|
the whole truth). Users familiar with VMS or "Trusted" versions of
|
||||||
|
other UNIX variants will know this under the name "privileges". The
|
||||||
|
name "capabilities" comes from the now defunct POSIX draft 1003.1e
|
||||||
|
which used this name.
|
||||||
|
|
||||||
|
2) So what is a "POSIX capability"?
|
||||||
|
|
||||||
|
A process has three sets of bitmaps called the inheritable(I),
|
||||||
|
permitted(P), and effective(E) capabilities. Each capability is
|
||||||
|
implemented as a bit in each of these bitmaps which is either set or
|
||||||
|
unset. When a process tries to do a privileged operation, the
|
||||||
|
operating system will check the appropriate bit in the effective set
|
||||||
|
of the process (instead of checking whether the effective uid of the
|
||||||
|
process i 0 as is normally done). For example, when a process tries
|
||||||
|
to set the clock, the Linux kernel will check that the process has the
|
||||||
|
CAP_SYS_TIME bit (which is currently bit 25) set in its effective set.
|
||||||
|
|
||||||
|
The permitted set of the process indicates the capabilities the
|
||||||
|
process can use. The process can have capabilities set in the
|
||||||
|
permitted set that are not in the effective set. This indicates that
|
||||||
|
the process has temporarily disabled this capability. A process is
|
||||||
|
allowed to set a bit in its effective set only if it is available in
|
||||||
|
the permitted set. The distinction between effective and permitted
|
||||||
|
exists so that processes can "bracket" operations that need privilege.
|
||||||
|
|
||||||
|
The inheritable capabilities are the capabilities of the current
|
||||||
|
process that should be inherited by a program executed by the current
|
||||||
|
process. The permitted set of a process is masked against the
|
||||||
|
inheritable set during exec(). Nothing special happens during fork()
|
||||||
|
or clone(). Child processes and threads are given an exact copy of
|
||||||
|
the capabilities of the parent process.
|
||||||
|
|
||||||
|
3) What about other entities in the system? Users, Groups, Files?
|
||||||
|
|
||||||
|
Files have capabilities. Conceptually they have the same three
|
||||||
|
bitmaps that processes have, but to avoid confusion we call them by
|
||||||
|
other names. Only executable files have capabilities, libraries don't
|
||||||
|
have capabilities (yet). The three sets are called the allowed set,
|
||||||
|
the forced set, and the effective set.
|
||||||
|
|
||||||
|
The allowed set indicates what capabilities the executable is allowed
|
||||||
|
to receive from an execing process. This means that during exec(),
|
||||||
|
the capabilities of the old process are first masked against a set
|
||||||
|
which indicates what the process gives away (the inheritable set of
|
||||||
|
the process), and then they are masked against a set which indicates
|
||||||
|
what capabilities the new process image is allowed to receive (the
|
||||||
|
allowed set of the executable).
|
||||||
|
|
||||||
|
The forced set is a set of capabilities created out of thin air and
|
||||||
|
given to the process after execing the executable. The forced set is
|
||||||
|
similar in nature to the setuid feature. In fact, the setuid bit from
|
||||||
|
the filesystem is "read" as a full forced set by the kernel.
|
||||||
|
|
||||||
|
The effective set indicates which bits in the permitted set of the new
|
||||||
|
process should be transferred to the effective set of the new process.
|
||||||
|
The effective set is best thought of as a "capability aware" set. It
|
||||||
|
should consist of only 1s if the executable is capability-dumb, or
|
||||||
|
only 0s if the executable is capability-smart. Since the effective
|
||||||
|
set consists of only 0s or only 1s, the filesystem can implement this
|
||||||
|
set using a single bit.
|
||||||
|
|
||||||
|
NOTE: Filesystem support for capabilities is not part of Linux 2.2.
|
||||||
|
|
||||||
|
Users and Groups don't have associated capabilities from the kernel's
|
||||||
|
point of view, but it is entirely reasonable to associate users or
|
||||||
|
groups with capabilities. By letting the "login" program set some
|
||||||
|
capabilities it is possible to make role users such as a backup user
|
||||||
|
that will have the CAP_DAC_READ_SEARCH capability and be able to do
|
||||||
|
backups. This could also be implemented as a PAM module, but nobody
|
||||||
|
has implemented one yet.
|
||||||
|
|
||||||
|
4) What capabilities exist?
|
||||||
|
|
||||||
|
The capabilities available in Linux are listed and documented in the
|
||||||
|
file /usr/src/linux/include/linux/capability.h.
|
||||||
|
|
||||||
|
5) Are Linux capabilities hierarchical?
|
||||||
|
|
||||||
|
No, you cannot make a "subcapability" out of a Linux capability as in
|
||||||
|
capability-based OSes.
|
||||||
|
|
||||||
|
6) How can I use capabilities to make sure Mr. Evil Luser (eluser)
|
||||||
|
can't exploit my "suid" programs?
|
||||||
|
|
||||||
|
This is the general outline of how this works given filesystem
|
||||||
|
capability support exists. First, you have a PAM module that sets the
|
||||||
|
inheritable capabilities of the login-shell of eluser. Then for all
|
||||||
|
"suid" programs on the system, you decide what capabilities they need
|
||||||
|
and set the _allowed_ set of the executable to that set of
|
||||||
|
capabilities. The capability rules
|
||||||
|
|
||||||
|
new permitted = forced | (allowed & inheritable)
|
||||||
|
|
||||||
|
means that you should be careful about setting forced capabilities on
|
||||||
|
executables. In a few cases, this can be useful though. For example
|
||||||
|
the login program needs to set the inheritable set of the new user and
|
||||||
|
therefore needs an almost full permitted set. So if you want eluser
|
||||||
|
to be able to run login and log in as a different user, you will have
|
||||||
|
to set some forced bits on that executable.
|
||||||
|
|
||||||
|
7) What about passing capabilities between processes?
|
||||||
|
|
||||||
|
Currently this is done by the system call "setcap" which can set the
|
||||||
|
capabilities of another process. This requires the CAP_SETPCAP
|
||||||
|
capability which you really only want to grant a _few_ processes.
|
||||||
|
CAP_SETPCAP was originally intended as a workaround to be able to
|
||||||
|
implement filesystem support for capabilities using a daemon outside
|
||||||
|
the kernel.
|
||||||
|
|
||||||
|
There has been discussions about implementing socket-level capability
|
||||||
|
passing. This means that you can pass a capability over a socket. No
|
||||||
|
support for this exists in the official kernel yet.
|
||||||
|
|
||||||
|
8) I see securelevel has been removed from 2.2 and are superceeded by
|
||||||
|
capabilities. How do I emulate securelevel using capabilities?
|
||||||
|
|
||||||
|
The setcap system call can remove a capability from _all_ processes on
|
||||||
|
the system in one atomic operation. The setcap utility from the
|
||||||
|
libcap distribution will do this for you. The utility requires the
|
||||||
|
CAP_SETPCAP privilege to do this. The CAP_SETPCAP capability is not
|
||||||
|
enabled by default.
|
||||||
|
|
||||||
|
libcap is available from
|
||||||
|
ftp://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.2/
|
||||||
|
|
||||||
|
9) I noticed that the capability.h file lacks some capabilities that
|
||||||
|
are needed to fully emulate 2.0 securelevel. Is there a patch for
|
||||||
|
this?
|
||||||
|
|
||||||
|
Actually yes - funny you should ask :-). The problem with 2.0
|
||||||
|
securelevel is that they for example stop root from accessing block
|
||||||
|
devices. At the same time they restrict the use of iopl. These two
|
||||||
|
changes are fundamentally different. Blocking access to block devices
|
||||||
|
means restricting something that usually isn't restricted.
|
||||||
|
Restricting access to the use of iopl on the other hand means
|
||||||
|
restricting (blocking) access to something that is already blocked.
|
||||||
|
Emulating the parts of 2.0 securelevel that restricts things that are
|
||||||
|
normally not restricted means that the capabilites in the kernel has
|
||||||
|
to have a set of capabilities that are usually _on_ for a normal
|
||||||
|
process (note that this breaks the explanation that capabilities are a
|
||||||
|
partitioning of the root privileges). There is an experimental patch at
|
||||||
|
|
||||||
|
ftp://ftp.guardian.no/pub/free/linux/capabilities/patch-cap-exp-1
|
||||||
|
|
||||||
|
which implements a set of capabilities with the "CAP_USER" prefix:
|
||||||
|
|
||||||
|
cap_user_sock - allowed to use socket()
|
||||||
|
cap_user_dev - allowed to open char/block devices
|
||||||
|
cap_user_fifo - allowed to use pipes
|
||||||
|
|
||||||
|
These should be enough to emulate 2.0 securelevel (tell me if we need
|
||||||
|
something more).
|
||||||
|
|
||||||
|
10) Seems I need a CAP_SETPCAP capability that I don't have to make use
|
||||||
|
of capabilities. How do I enable this capability?
|
||||||
|
|
||||||
|
Change the definition of CAP_INIT_EFF_SET and CAP_INIT_INH_SET to the
|
||||||
|
following in include/linux/capability.h:
|
||||||
|
|
||||||
|
#define CAP_INIT_EFF_SET { ~0 }
|
||||||
|
#define CAP_INIT_INH_SET { ~0 }
|
||||||
|
|
||||||
|
This will start init with a full capability set and not with
|
||||||
|
CAP_SETPCAP removed.
|
||||||
|
|
||||||
|
11) How do I start a process with a limited set of capabilities?
|
||||||
|
|
||||||
|
Get the libcap library and use the execcap utility. The following
|
||||||
|
example starts the update daemon with only the CAP_SYS_ADMIN
|
||||||
|
capability.
|
||||||
|
|
||||||
|
execcap 'cap_sys_admin=eip' update
|
||||||
|
|
||||||
|
12) How do I start a process with a limited set of capabilities under
|
||||||
|
another uid?
|
||||||
|
|
||||||
|
Use the sucap utility which changes uid from root without loosing any
|
||||||
|
capabilities. Normally all capabilities are cleared when changing uid
|
||||||
|
from root. The sucap utility requires the CAP_SETPCAP capability.
|
||||||
|
The following example starts updated under uid updated and gid updated
|
||||||
|
with CAP_SYS_ADMIN raised in the Effective set.
|
||||||
|
|
||||||
|
sucap updated updated execcap 'cap_sys_admin=eip' update
|
||||||
|
|
||||||
|
[ Sucap is currently available from
|
||||||
|
ftp://ftp.guardian.no/pub/free/linux/capabilities/sucap.c. Put it in
|
||||||
|
the progs directory of libcap to compile.]
|
||||||
|
|
||||||
|
13) What are the "capability rules"
|
||||||
|
|
||||||
|
The capability rules are the rules used to set the capabilities of the
|
||||||
|
new process image after an exec. They work like this:
|
||||||
|
|
||||||
|
pI' = pI
|
||||||
|
(***) pP' = fP | (fI & pI)
|
||||||
|
pE' = pP' & fE [NB. fE is 0 or ~0]
|
||||||
|
|
||||||
|
I=Inheritable, P=Permitted, E=Effective // p=process, f=file
|
||||||
|
' indicates post-exec().
|
||||||
|
|
||||||
|
Now to make sense of the equations think of fP as the Forced set of
|
||||||
|
the executable, and fI as the Allowed set of the executable. Notice
|
||||||
|
how the Inheritable set isn't touched at all during exec().
|
||||||
|
|
||||||
|
14) What are the laws for setting capability bits in the Inheritable,
|
||||||
|
Permitted, and Effective sets?
|
||||||
|
|
||||||
|
Bits can be transferred from Permitted to either Effective or
|
||||||
|
Inheritable set.
|
||||||
|
|
||||||
|
Bits can be removed from all sets.
|
||||||
|
|
||||||
|
15) Where is the standard on which the Linux capabilities are based?
|
||||||
|
|
||||||
|
There used to be a POSIX draft called POSIX.6 and later POSIX 1003.1e.
|
||||||
|
However after the committee had spent over 10 years, POSIX decided
|
||||||
|
that enough is enough and dropped the draft. There will therefore not
|
||||||
|
be a POSIX standard covering security anytime soon. This may lead to
|
||||||
|
that the POSIX draft is available for free, however.
|
||||||
|
|
||||||
|
--
|
||||||
|
Best regards, -- Boris.
|
||||||
|
|
||||||
13
libcap-1.10-audit.patch
Normal file
13
libcap-1.10-audit.patch
Normal file
|
|
@ -0,0 +1,13 @@
|
||||||
|
--- libcap-1.10/libcap/include/sys/capability.h.audit 2007-02-23 23:18:15.000000000 +0100
|
||||||
|
+++ libcap-1.10/libcap/include/sys/capability.h 2007-02-23 23:18:54.000000000 +0100
|
||||||
|
@@ -302,6 +302,10 @@
|
||||||
|
|
||||||
|
#define CAP_LEASE 28
|
||||||
|
|
||||||
|
+#define CAP_AUDIT_WRITE 29
|
||||||
|
+
|
||||||
|
+#define CAP_AUDIT_CONTROL 30
|
||||||
|
+
|
||||||
|
#endif /* !_LINUX_CAPABILITY_H */
|
||||||
|
|
||||||
|
|
||||||
460
libcap-1.10-debian.patch
Normal file
460
libcap-1.10-debian.patch
Normal file
|
|
@ -0,0 +1,460 @@
|
||||||
|
--- libcap-1.10/Makefile.debian 1999-04-18 00:16:31.000000000 +0200
|
||||||
|
+++ libcap-1.10/Makefile 2007-02-21 14:56:33.000000000 +0100
|
||||||
|
@@ -3,17 +3,20 @@
|
||||||
|
#
|
||||||
|
# Makefile for libcap
|
||||||
|
|
||||||
|
+ifndef topdir
|
||||||
|
topdir=$(shell pwd)
|
||||||
|
-include Make.Rules
|
||||||
|
+endif
|
||||||
|
+include $(topdir)/Make.Rules
|
||||||
|
+DESTDIR=
|
||||||
|
|
||||||
|
#
|
||||||
|
# flags
|
||||||
|
#
|
||||||
|
|
||||||
|
all install clean: %: %-here
|
||||||
|
- make -C libcap $(MAKE_DEFS) $@
|
||||||
|
- make -C progs $(MAKE_DEFS) $@
|
||||||
|
- make -C doc $(MAKE_DEFS) $@
|
||||||
|
+ make -C $(topdir)/libcap $(MAKE_DEFS) $@
|
||||||
|
+ make -C $(topdir)/progs $(MAKE_DEFS) $@
|
||||||
|
+ make -C $(topdir)/doc $(MAKE_DEFS) $@
|
||||||
|
|
||||||
|
all-here:
|
||||||
|
|
||||||
|
--- libcap-1.10/Make.Rules.debian 1999-11-18 07:06:02.000000000 +0100
|
||||||
|
+++ libcap-1.10/Make.Rules 2007-02-21 14:56:33.000000000 +0100
|
||||||
|
@@ -8,7 +8,7 @@
|
||||||
|
|
||||||
|
# common 'packaging' directoty
|
||||||
|
|
||||||
|
-FAKEROOT=
|
||||||
|
+FAKEROOT=$(DESTDIR)
|
||||||
|
|
||||||
|
# Autoconf-style prefixes are activated when $(prefix) is defined.
|
||||||
|
# Otherwise binaries and libraraies are installed in /{lib,sbin}/,
|
||||||
|
@@ -18,13 +18,13 @@
|
||||||
|
exec_prefix=$(prefix)
|
||||||
|
lib_prefix=$(exec_prefix)
|
||||||
|
inc_prefix=$(lib_prefix)
|
||||||
|
-man_prefix=$(prefix)
|
||||||
|
+man_prefix=$(prefix)/share
|
||||||
|
else
|
||||||
|
prefix=/usr
|
||||||
|
exec_prefix=
|
||||||
|
lib_prefix=$(exec_prefix)
|
||||||
|
inc_prefix=$(prefix)
|
||||||
|
-man_prefix=$(prefix)
|
||||||
|
+man_prefix=$(prefix)/share
|
||||||
|
endif
|
||||||
|
|
||||||
|
# Target directories
|
||||||
|
--- libcap-1.10/libcap/cap_sys.c.debian 1999-04-18 00:16:31.000000000 +0200
|
||||||
|
+++ libcap-1.10/libcap/cap_sys.c 2007-02-21 14:56:33.000000000 +0100
|
||||||
|
@@ -11,6 +11,8 @@
|
||||||
|
#define __LIBRARY__
|
||||||
|
#include <linux/unistd.h>
|
||||||
|
|
||||||
|
+/* glibc >= 2.1 knows capset/capget. no need to define it here */
|
||||||
|
+/*
|
||||||
|
_syscall2(int, capget,
|
||||||
|
cap_user_header_t, header,
|
||||||
|
cap_user_data_t, data)
|
||||||
|
@@ -18,6 +20,7 @@
|
||||||
|
_syscall2(int, capset,
|
||||||
|
cap_user_header_t, header,
|
||||||
|
const cap_user_data_t, data)
|
||||||
|
+*/
|
||||||
|
|
||||||
|
/*
|
||||||
|
* $Log: cap_sys.c,v $
|
||||||
|
--- libcap-1.10/libcap/Makefile.debian 2007-02-21 14:56:33.000000000 +0100
|
||||||
|
+++ libcap-1.10/libcap/Makefile 2007-02-21 14:56:33.000000000 +0100
|
||||||
|
@@ -24,12 +24,14 @@
|
||||||
|
#
|
||||||
|
# defines
|
||||||
|
#
|
||||||
|
+ifndef topdir
|
||||||
|
topdir=$(shell pwd)/..
|
||||||
|
-include ../Make.Rules
|
||||||
|
+endif
|
||||||
|
+include $(topdir)/Make.Rules
|
||||||
|
#
|
||||||
|
# Library version
|
||||||
|
#
|
||||||
|
-LIBNAME=libcap.so
|
||||||
|
+LIBNAME=libcap
|
||||||
|
#
|
||||||
|
|
||||||
|
FILES=cap_alloc cap_proc cap_extint cap_flag cap_text cap_sys
|
||||||
|
@@ -39,10 +41,11 @@
|
||||||
|
|
||||||
|
INCLS=libcap.h cap_names.h $(INCS)
|
||||||
|
OBJS=$(addsuffix .o, $(FILES))
|
||||||
|
-MAJLIBNAME=$(LIBNAME).$(VERSION)
|
||||||
|
+LOBJS=$(addsuffix .lo, $(FILES))
|
||||||
|
+MAJLIBNAME=$(LIBNAME).so.$(VERSION)
|
||||||
|
MINLIBNAME=$(MAJLIBNAME).$(MINOR)
|
||||||
|
|
||||||
|
-all: $(MINLIBNAME)
|
||||||
|
+all: $(MINLIBNAME) $(LIBNAME).a
|
||||||
|
|
||||||
|
_makenames: _makenames.c cap_names.sed
|
||||||
|
$(CC) $(CFLAGS) $(LDFLAGS) $< -o $@
|
||||||
|
@@ -51,30 +54,38 @@
|
||||||
|
./_makenames > cap_names.h
|
||||||
|
|
||||||
|
cap_names.sed: Makefile /usr/include/linux/capability.h
|
||||||
|
- @echo "=> making cap_names.c from <linux/capability.h>"
|
||||||
|
- @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define \([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
-# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
+cap_names.sed: Makefile include/sys/capability.h
|
||||||
|
+ @echo "=> making cap_names.c from <sys/capability.h>"
|
||||||
|
+ @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define \([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < include/sys/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
+# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
|
||||||
|
-$(MINLIBNAME): $(OBJS)
|
||||||
|
- $(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||||
|
+$(LIBNAME).a: $(OBJS)
|
||||||
|
+ ar cruv $(LIBNAME).a $(OBJS)
|
||||||
|
+
|
||||||
|
+$(MINLIBNAME): $(LOBJS)
|
||||||
|
+ $(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -fPIC -o $@ $(LOBJS)
|
||||||
|
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||||
|
- ln -sf $(MAJLIBNAME) $(LIBNAME)
|
||||||
|
+ ln -sf $(MAJLIBNAME) $(LIBNAME).so
|
||||||
|
|
||||||
|
%.o: %.c $(INCLS)
|
||||||
|
$(CC) $(CFLAGS) -fpic -c $< -o $@
|
||||||
|
|
||||||
|
+%.lo: %.c $(INCLS)
|
||||||
|
+ $(CC) $(CFLAGS) -c $< -o $@
|
||||||
|
+
|
||||||
|
install: all
|
||||||
|
mkdir -p -m 0755 $(INCDIR)/sys
|
||||||
|
install -m 0644 include/sys/capability.h $(INCDIR)/sys
|
||||||
|
mkdir -p -m 0755 $(LIBDIR)
|
||||||
|
+ install -m 0644 $(LIBNAME).a $(LIBDIR)
|
||||||
|
install -m 0644 $(MINLIBNAME) $(LIBDIR)/$(MINLIBNAME)
|
||||||
|
ln -sf $(MINLIBNAME) $(LIBDIR)/$(MAJLIBNAME)
|
||||||
|
- ln -sf $(MAJLIBNAME) $(LIBDIR)/$(LIBNAME)
|
||||||
|
+ ln -sf $(MAJLIBNAME) $(LIBDIR)/$(LIBNAME).so
|
||||||
|
-/sbin/ldconfig
|
||||||
|
|
||||||
|
clean:
|
||||||
|
$(LOCALCLEAN)
|
||||||
|
- rm -f $(OBJS) $(LIBNAME)*
|
||||||
|
+ rm -f $(OBJS) $(LOBJS) $(LIBNAME).a $(LIBNAME).so*
|
||||||
|
rm -f cap_names.h cap_names.sed _makenames
|
||||||
|
cd include/sys && $(LOCALCLEAN)
|
||||||
|
|
||||||
|
--- libcap-1.10/libcap/_makenames.c.debian 1999-05-14 06:46:15.000000000 +0200
|
||||||
|
+++ libcap-1.10/libcap/_makenames.c 2007-02-21 14:56:33.000000000 +0100
|
||||||
|
@@ -9,7 +9,7 @@
|
||||||
|
|
||||||
|
#include <stdio.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
-#include <linux/capability.h>
|
||||||
|
+#include <sys/capability.h>
|
||||||
|
|
||||||
|
/*
|
||||||
|
* #include 'sed' generated array
|
||||||
|
--- libcap-1.10/libcap/include/sys/capability.h.debian 2007-02-21 14:56:45.000000000 +0100
|
||||||
|
+++ libcap-1.10/libcap/include/sys/capability.h 2007-02-21 14:58:18.000000000 +0100
|
||||||
|
@@ -24,14 +24,286 @@
|
||||||
|
#include <stdint.h>
|
||||||
|
|
||||||
|
/*
|
||||||
|
- * Make sure we can be included from userland by preventing
|
||||||
|
- * capability.h from including other kernel headers
|
||||||
|
- */
|
||||||
|
-#define _LINUX_TYPES_H
|
||||||
|
-#define _LINUX_FS_H
|
||||||
|
-typedef unsigned int __u32;
|
||||||
|
+ * This is <linux/capability.h>
|
||||||
|
+ *
|
||||||
|
+ * Andrew G. Morgan <morgan@transmeta.com>
|
||||||
|
+ * Alexander Kjeldaas <astor@guardian.no>
|
||||||
|
+ * with help from Aleph1, Roland Buresund and Andrew Main.
|
||||||
|
+ *
|
||||||
|
+ * See here for the libcap library ("POSIX draft" compliance):
|
||||||
|
+ *
|
||||||
|
+ * ftp://linux.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.2/
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
+#ifndef _LINUX_CAPABILITY_H
|
||||||
|
+#define _LINUX_CAPABILITY_H
|
||||||
|
+
|
||||||
|
+#include <linux/types.h>
|
||||||
|
+/*#include <linux/fs.h>*/
|
||||||
|
+
|
||||||
|
+/* User-level do most of the mapping between kernel and user
|
||||||
|
+ capabilities based on the version tag given by the kernel. The
|
||||||
|
+ kernel might be somewhat backwards compatible, but don't bet on
|
||||||
|
+ it. */
|
||||||
|
+
|
||||||
|
+/* XXX - Note, cap_t, is defined by POSIX to be an "opaque" pointer to
|
||||||
|
+ a set of three capability sets. The transposition of 3*the
|
||||||
|
+ following structure to such a composite is better handled in a user
|
||||||
|
+ library since the draft standard requires the use of malloc/free
|
||||||
|
+ etc.. */
|
||||||
|
+
|
||||||
|
+#define _LINUX_CAPABILITY_VERSION 0x19980330
|
||||||
|
+
|
||||||
|
+typedef struct __user_cap_header_struct {
|
||||||
|
+ __u32 version;
|
||||||
|
+ int pid;
|
||||||
|
+} *cap_user_header_t;
|
||||||
|
+
|
||||||
|
+typedef struct __user_cap_data_struct {
|
||||||
|
+ __u32 effective;
|
||||||
|
+ __u32 permitted;
|
||||||
|
+ __u32 inheritable;
|
||||||
|
+} *cap_user_data_t;
|
||||||
|
+
|
||||||
|
+#ifdef __KERNEL__
|
||||||
|
+
|
||||||
|
+/* #define STRICT_CAP_T_TYPECHECKS */
|
||||||
|
+
|
||||||
|
+#ifdef STRICT_CAP_T_TYPECHECKS
|
||||||
|
+
|
||||||
|
+typedef struct kernel_cap_struct {
|
||||||
|
+ __u32 cap;
|
||||||
|
+} kernel_cap_t;
|
||||||
|
+
|
||||||
|
+#else
|
||||||
|
+
|
||||||
|
+typedef __u32 kernel_cap_t;
|
||||||
|
+
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+#define _USER_CAP_HEADER_SIZE (2*sizeof(__u32))
|
||||||
|
+#define _KERNEL_CAP_T_SIZE (sizeof(kernel_cap_t))
|
||||||
|
+
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+
|
||||||
|
+/**
|
||||||
|
+ ** POSIX-draft defined capabilities.
|
||||||
|
+ **/
|
||||||
|
+
|
||||||
|
+/* In a system with the [_POSIX_CHOWN_RESTRICTED] option defined, this
|
||||||
|
+ overrides the restriction of changing file ownership and group
|
||||||
|
+ ownership. */
|
||||||
|
+
|
||||||
|
+#define CAP_CHOWN 0
|
||||||
|
+
|
||||||
|
+/* Override all DAC access, including ACL execute access if
|
||||||
|
+ [_POSIX_ACL] is defined. Excluding DAC access covered by
|
||||||
|
+ CAP_LINUX_IMMUTABLE. */
|
||||||
|
+
|
||||||
|
+#define CAP_DAC_OVERRIDE 1
|
||||||
|
+
|
||||||
|
+/* Overrides all DAC restrictions regarding read and search on files
|
||||||
|
+ and directories, including ACL restrictions if [_POSIX_ACL] is
|
||||||
|
+ defined. Excluding DAC access covered by CAP_LINUX_IMMUTABLE. */
|
||||||
|
+
|
||||||
|
+#define CAP_DAC_READ_SEARCH 2
|
||||||
|
+
|
||||||
|
+/* Overrides all restrictions about allowed operations on files, where
|
||||||
|
+ file owner ID must be equal to the user ID, except where CAP_FSETID
|
||||||
|
+ is applicable. It doesn't override MAC and DAC restrictions. */
|
||||||
|
+
|
||||||
|
+#define CAP_FOWNER 3
|
||||||
|
+
|
||||||
|
+/* Overrides the following restrictions that the effective user ID
|
||||||
|
+ shall match the file owner ID when setting the S_ISUID and S_ISGID
|
||||||
|
+ bits on that file; that the effective group ID (or one of the
|
||||||
|
+ supplementary group IDs) shall match the file owner ID when setting
|
||||||
|
+ the S_ISGID bit on that file; that the S_ISUID and S_ISGID bits are
|
||||||
|
+ cleared on successful return from chown(2) (not implemented). */
|
||||||
|
+
|
||||||
|
+#define CAP_FSETID 4
|
||||||
|
+
|
||||||
|
+/* Used to decide between falling back on the old suser() or fsuser(). */
|
||||||
|
+
|
||||||
|
+#define CAP_FS_MASK 0x1f
|
||||||
|
+
|
||||||
|
+/* Overrides the restriction that the real or effective user ID of a
|
||||||
|
+ process sending a signal must match the real or effective user ID
|
||||||
|
+ of the process receiving the signal. */
|
||||||
|
+
|
||||||
|
+#define CAP_KILL 5
|
||||||
|
+
|
||||||
|
+/* Allows setgid(2) manipulation */
|
||||||
|
+/* Allows setgroups(2) */
|
||||||
|
+/* Allows forged gids on socket credentials passing. */
|
||||||
|
+
|
||||||
|
+#define CAP_SETGID 6
|
||||||
|
+
|
||||||
|
+/* Allows set*uid(2) manipulation (including fsuid). */
|
||||||
|
+/* Allows forged pids on socket credentials passing. */
|
||||||
|
+
|
||||||
|
+#define CAP_SETUID 7
|
||||||
|
+
|
||||||
|
+
|
||||||
|
+/**
|
||||||
|
+ ** Linux-specific capabilities
|
||||||
|
+ **/
|
||||||
|
+
|
||||||
|
+/* Transfer any capability in your permitted set to any pid,
|
||||||
|
+ remove any capability in your permitted set from any pid */
|
||||||
|
+
|
||||||
|
+#define CAP_SETPCAP 8
|
||||||
|
+
|
||||||
|
+/* Allow modification of S_IMMUTABLE and S_APPEND file attributes */
|
||||||
|
+
|
||||||
|
+#define CAP_LINUX_IMMUTABLE 9
|
||||||
|
+
|
||||||
|
+/* Allows binding to TCP/UDP sockets below 1024 */
|
||||||
|
+/* Allows binding to ATM VCIs below 32 */
|
||||||
|
+
|
||||||
|
+#define CAP_NET_BIND_SERVICE 10
|
||||||
|
+
|
||||||
|
+/* Allow broadcasting, listen to multicast */
|
||||||
|
+
|
||||||
|
+#define CAP_NET_BROADCAST 11
|
||||||
|
+
|
||||||
|
+/* Allow interface configuration */
|
||||||
|
+/* Allow administration of IP firewall, masquerading and accounting */
|
||||||
|
+/* Allow setting debug option on sockets */
|
||||||
|
+/* Allow modification of routing tables */
|
||||||
|
+/* Allow setting arbitrary process / process group ownership on
|
||||||
|
+ sockets */
|
||||||
|
+/* Allow binding to any address for transparent proxying */
|
||||||
|
+/* Allow setting TOS (type of service) */
|
||||||
|
+/* Allow setting promiscuous mode */
|
||||||
|
+/* Allow clearing driver statistics */
|
||||||
|
+/* Allow multicasting */
|
||||||
|
+/* Allow read/write of device-specific registers */
|
||||||
|
+/* Allow activation of ATM control sockets */
|
||||||
|
+
|
||||||
|
+#define CAP_NET_ADMIN 12
|
||||||
|
+
|
||||||
|
+/* Allow use of RAW sockets */
|
||||||
|
+/* Allow use of PACKET sockets */
|
||||||
|
+
|
||||||
|
+#define CAP_NET_RAW 13
|
||||||
|
+
|
||||||
|
+/* Allow locking of shared memory segments */
|
||||||
|
+/* Allow mlock and mlockall (which doesn't really have anything to do
|
||||||
|
+ with IPC) */
|
||||||
|
+
|
||||||
|
+#define CAP_IPC_LOCK 14
|
||||||
|
+
|
||||||
|
+/* Override IPC ownership checks */
|
||||||
|
+
|
||||||
|
+#define CAP_IPC_OWNER 15
|
||||||
|
+
|
||||||
|
+/* Insert and remove kernel modules - modify kernel without limit */
|
||||||
|
+/* Modify cap_bset */
|
||||||
|
+#define CAP_SYS_MODULE 16
|
||||||
|
+
|
||||||
|
+/* Allow ioperm/iopl access */
|
||||||
|
+/* Allow sending USB messages to any device via /proc/bus/usb */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_RAWIO 17
|
||||||
|
+
|
||||||
|
+/* Allow use of chroot() */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_CHROOT 18
|
||||||
|
+
|
||||||
|
+/* Allow ptrace() of any process */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_PTRACE 19
|
||||||
|
+
|
||||||
|
+/* Allow configuration of process accounting */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_PACCT 20
|
||||||
|
+
|
||||||
|
+/* Allow configuration of the secure attention key */
|
||||||
|
+/* Allow administration of the random device */
|
||||||
|
+/* Allow examination and configuration of disk quotas */
|
||||||
|
+/* Allow configuring the kernel's syslog (printk behaviour) */
|
||||||
|
+/* Allow setting the domainname */
|
||||||
|
+/* Allow setting the hostname */
|
||||||
|
+/* Allow calling bdflush() */
|
||||||
|
+/* Allow mount() and umount(), setting up new smb connection */
|
||||||
|
+/* Allow some autofs root ioctls */
|
||||||
|
+/* Allow nfsservctl */
|
||||||
|
+/* Allow VM86_REQUEST_IRQ */
|
||||||
|
+/* Allow to read/write pci config on alpha */
|
||||||
|
+/* Allow irix_prctl on mips (setstacksize) */
|
||||||
|
+/* Allow flushing all cache on m68k (sys_cacheflush) */
|
||||||
|
+/* Allow removing semaphores */
|
||||||
|
+/* Used instead of CAP_CHOWN to "chown" IPC message queues, semaphores
|
||||||
|
+ and shared memory */
|
||||||
|
+/* Allow locking/unlocking of shared memory segment */
|
||||||
|
+/* Allow turning swap on/off */
|
||||||
|
+/* Allow forged pids on socket credentials passing */
|
||||||
|
+/* Allow setting readahead and flushing buffers on block devices */
|
||||||
|
+/* Allow setting geometry in floppy driver */
|
||||||
|
+/* Allow turning DMA on/off in xd driver */
|
||||||
|
+/* Allow administration of md devices (mostly the above, but some
|
||||||
|
+ extra ioctls) */
|
||||||
|
+/* Allow tuning the ide driver */
|
||||||
|
+/* Allow access to the nvram device */
|
||||||
|
+/* Allow administration of apm_bios, serial and bttv (TV) device */
|
||||||
|
+/* Allow manufacturer commands in isdn CAPI support driver */
|
||||||
|
+/* Allow reading non-standardized portions of pci configuration space */
|
||||||
|
+/* Allow DDI debug ioctl on sbpcd driver */
|
||||||
|
+/* Allow setting up serial ports */
|
||||||
|
+/* Allow sending raw qic-117 commands */
|
||||||
|
+/* Allow enabling/disabling tagged queuing on SCSI controllers and sending
|
||||||
|
+ arbitrary SCSI commands */
|
||||||
|
+/* Allow setting encryption key on loopback filesystem */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_ADMIN 21
|
||||||
|
+
|
||||||
|
+/* Allow use of reboot() */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_BOOT 22
|
||||||
|
+
|
||||||
|
+/* Allow raising priority and setting priority on other (different
|
||||||
|
+ UID) processes */
|
||||||
|
+/* Allow use of FIFO and round-robin (realtime) scheduling on own
|
||||||
|
+ processes and setting the scheduling algorithm used by another
|
||||||
|
+ process. */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_NICE 23
|
||||||
|
+
|
||||||
|
+/* Override resource limits. Set resource limits. */
|
||||||
|
+/* Override quota limits. */
|
||||||
|
+/* Override reserved space on ext2 filesystem */
|
||||||
|
+/* NOTE: ext2 honors fsuid when checking for resource overrides, so
|
||||||
|
+ you can override using fsuid too */
|
||||||
|
+/* Override size restrictions on IPC message queues */
|
||||||
|
+/* Allow more than 64hz interrupts from the real-time clock */
|
||||||
|
+/* Override max number of consoles on console allocation */
|
||||||
|
+/* Override max number of keymaps */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_RESOURCE 24
|
||||||
|
+
|
||||||
|
+/* Allow manipulation of system clock */
|
||||||
|
+/* Allow irix_stime on mips */
|
||||||
|
+/* Allow setting the real-time clock */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_TIME 25
|
||||||
|
+
|
||||||
|
+/* Allow configuration of tty devices */
|
||||||
|
+/* Allow vhangup() of tty */
|
||||||
|
+
|
||||||
|
+#define CAP_SYS_TTY_CONFIG 26
|
||||||
|
+
|
||||||
|
+/* Allow the privileged aspects of mknod() */
|
||||||
|
+
|
||||||
|
+#define CAP_MKNOD 27
|
||||||
|
+
|
||||||
|
+/* Allow taking of leases on files */
|
||||||
|
+
|
||||||
|
+#define CAP_LEASE 28
|
||||||
|
+
|
||||||
|
+#endif /* !_LINUX_CAPABILITY_H */
|
||||||
|
|
||||||
|
-#include <linux/capability.h>
|
||||||
|
|
||||||
|
/*
|
||||||
|
* POSIX capability types
|
||||||
15
libcap-1.10-fPIC.patch
Normal file
15
libcap-1.10-fPIC.patch
Normal file
|
|
@ -0,0 +1,15 @@
|
||||||
|
--- libcap-1.10/libcap/Makefile.rh2 2007-02-21 15:21:12.000000000 +0100
|
||||||
|
+++ libcap-1.10/libcap/Makefile 2007-02-21 15:22:00.000000000 +0100
|
||||||
|
@@ -65,10 +65,10 @@
|
||||||
|
ln -sf $(MAJLIBNAME) $(LIBNAME).so
|
||||||
|
|
||||||
|
%.o: %.c $(INCLS)
|
||||||
|
- $(CC) $(CFLAGS) -fpic -c $< -o $@
|
||||||
|
+ $(CC) $(CFLAGS) -fPIC -c $< -o $@
|
||||||
|
|
||||||
|
%.lo: %.c $(INCLS)
|
||||||
|
- $(CC) $(CFLAGS) -c $< -o $@
|
||||||
|
+ $(CC) $(CFLAGS) -fPIC -c $< -o $@
|
||||||
|
|
||||||
|
install: all
|
||||||
|
mkdir -p -m 0755 $(INCDIR)/sys
|
||||||
47
libcap-1.10-ia64.patch
Normal file
47
libcap-1.10-ia64.patch
Normal file
|
|
@ -0,0 +1,47 @@
|
||||||
|
--- libcap-1.10/libcap/cap_sys.c.ia64 Mon May 21 16:23:27 2001
|
||||||
|
+++ libcap-1.10/libcap/cap_sys.c Mon May 21 16:24:09 2001
|
||||||
|
@@ -11,14 +11,6 @@
|
||||||
|
#define __LIBRARY__
|
||||||
|
#include <linux/unistd.h>
|
||||||
|
|
||||||
|
-_syscall2(int, capget,
|
||||||
|
- cap_user_header_t, header,
|
||||||
|
- cap_user_data_t, data)
|
||||||
|
-
|
||||||
|
-_syscall2(int, capset,
|
||||||
|
- cap_user_header_t, header,
|
||||||
|
- const cap_user_data_t, data)
|
||||||
|
-
|
||||||
|
/*
|
||||||
|
* $Log: libcap-1.10-ia64.patch,v $
|
||||||
|
* Revision 1.1 2004/09/09 07:21:23 cvsdist
|
||||||
|
* auto-import changelog data from libcap-1.10-4.src.rpm
|
||||||
|
* * Tue Jul 10 2001 Jakub Jelinek <jakub@redhat.com>
|
||||||
|
* - don't build libcap.so.1 with ld -shared, but gcc -shared
|
||||||
|
*
|
||||||
|
* * Wed Jun 20 2001 Trond Eivind Glomsrød <teg@redhat.com>
|
||||||
|
* - Rebuild - it was missing for alpha
|
||||||
|
*
|
||||||
|
* * Wed Jun 06 2001 Florian La Roche <Florian.LaRoche@redhat.de>
|
||||||
|
* - add s390/s390x support
|
||||||
|
*
|
||||||
|
* * Thu May 17 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-1
|
||||||
|
* - initial RPM
|
||||||
|
* - fix build on ia64
|
||||||
|
*
|
||||||
|
* Revision 1.1.1.1 1999/04/17 22:16:31 morgan
|
||||||
|
--- libcap-1.10/Make.Rules.ia64 Mon May 21 16:22:08 2001
|
||||||
|
+++ libcap-1.10/Make.Rules Mon May 21 16:22:32 2001
|
||||||
|
@@ -44,10 +44,10 @@
|
||||||
|
CC=gcc
|
||||||
|
COPTFLAGS=-O2
|
||||||
|
DEBUG=-g #-DDEBUG
|
||||||
|
-WARNINGS=-ansi -D_POSIX_SOURCE -Wall -Wwrite-strings \
|
||||||
|
+WARNINGS=-D_POSIX_SOURCE -Wall -Wwrite-strings \
|
||||||
|
-Wpointer-arith -Wcast-qual -Wcast-align \
|
||||||
|
-Wtraditional -Wstrict-prototypes -Wmissing-prototypes \
|
||||||
|
- -Wnested-externs -Winline -Wshadow -pedantic
|
||||||
|
+ -Wnested-externs -Winline -Wshadow
|
||||||
|
LD=ld
|
||||||
|
LDFLAGS=-s #-g
|
||||||
|
|
||||||
38
libcap-1.10-nostaticlib.patch
Normal file
38
libcap-1.10-nostaticlib.patch
Normal file
|
|
@ -0,0 +1,38 @@
|
||||||
|
--- libcap-1.10/libcap/Makefile.rh1 2007-02-21 15:00:01.000000000 +0100
|
||||||
|
+++ libcap-1.10/libcap/Makefile 2007-02-21 15:00:53.000000000 +0100
|
||||||
|
@@ -45,7 +45,7 @@
|
||||||
|
MAJLIBNAME=$(LIBNAME).so.$(VERSION)
|
||||||
|
MINLIBNAME=$(MAJLIBNAME).$(MINOR)
|
||||||
|
|
||||||
|
-all: $(MINLIBNAME) $(LIBNAME).a
|
||||||
|
+all: $(MINLIBNAME)
|
||||||
|
|
||||||
|
_makenames: _makenames.c cap_names.sed
|
||||||
|
$(CC) $(CFLAGS) $(LDFLAGS) $< -o $@
|
||||||
|
@@ -59,9 +59,6 @@
|
||||||
|
@sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define \([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < include/sys/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
|
||||||
|
-$(LIBNAME).a: $(OBJS)
|
||||||
|
- ar cruv $(LIBNAME).a $(OBJS)
|
||||||
|
-
|
||||||
|
$(MINLIBNAME): $(LOBJS)
|
||||||
|
$(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -fPIC -o $@ $(LOBJS)
|
||||||
|
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||||
|
@@ -77,7 +74,6 @@
|
||||||
|
mkdir -p -m 0755 $(INCDIR)/sys
|
||||||
|
install -m 0644 include/sys/capability.h $(INCDIR)/sys
|
||||||
|
mkdir -p -m 0755 $(LIBDIR)
|
||||||
|
- install -m 0644 $(LIBNAME).a $(LIBDIR)
|
||||||
|
install -m 0644 $(MINLIBNAME) $(LIBDIR)/$(MINLIBNAME)
|
||||||
|
ln -sf $(MINLIBNAME) $(LIBDIR)/$(MAJLIBNAME)
|
||||||
|
ln -sf $(MAJLIBNAME) $(LIBDIR)/$(LIBNAME).so
|
||||||
|
@@ -85,7 +81,7 @@
|
||||||
|
|
||||||
|
clean:
|
||||||
|
$(LOCALCLEAN)
|
||||||
|
- rm -f $(OBJS) $(LOBJS) $(LIBNAME).a $(LIBNAME).so*
|
||||||
|
+ rm -f $(OBJS) $(LOBJS) $(LIBNAME).so*
|
||||||
|
rm -f cap_names.h cap_names.sed _makenames
|
||||||
|
cd include/sys && $(LOCALCLEAN)
|
||||||
|
|
||||||
17
libcap-1.10-shared.patch
Normal file
17
libcap-1.10-shared.patch
Normal file
|
|
@ -0,0 +1,17 @@
|
||||||
|
--- libcap-1.11/libcap/Makefile.shared 1999-04-17 18:16:31.000000000 -0400
|
||||||
|
+++ libcap-1.11/libcap/Makefile 2002-07-19 06:24:23.000000000 -0400
|
||||||
|
@@ -56,12 +56,12 @@ cap_names.sed: Makefile /usr/include/lin
|
||||||
|
# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
|
||||||
|
$(MINLIBNAME): $(OBJS)
|
||||||
|
- $(LD) -soname $(MAJLIBNAME) -x -shared -o $@ $(OBJS)
|
||||||
|
+ $(CC) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||||
|
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||||
|
ln -sf $(MAJLIBNAME) $(LIBNAME)
|
||||||
|
|
||||||
|
%.o: %.c $(INCLS)
|
||||||
|
- $(CC) $(CFLAGS) -c $< -o $@
|
||||||
|
+ $(CC) $(CFLAGS) -fpic -c $< -o $@
|
||||||
|
|
||||||
|
install: all
|
||||||
|
mkdir -p -m 0755 $(INCDIR)/sys
|
||||||
22
libcap-1.10-useCFLAGSwithCC.patch
Normal file
22
libcap-1.10-useCFLAGSwithCC.patch
Normal file
|
|
@ -0,0 +1,22 @@
|
||||||
|
--- libcap-1.10/libcap/Makefile.BAD 2006-07-13 20:42:35.000000000 -0400
|
||||||
|
+++ libcap-1.10/libcap/Makefile 2006-07-13 20:42:53.000000000 -0400
|
||||||
|
@@ -56,7 +56,7 @@
|
||||||
|
# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||||
|
|
||||||
|
$(MINLIBNAME): $(OBJS)
|
||||||
|
- $(CC) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||||
|
+ $(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||||
|
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||||
|
ln -sf $(MAJLIBNAME) $(LIBNAME)
|
||||||
|
|
||||||
|
--- libcap-1.10/progs/Makefile.BAD 2006-07-13 20:48:44.000000000 -0400
|
||||||
|
+++ libcap-1.10/progs/Makefile 2006-07-13 20:48:54.000000000 -0400
|
||||||
|
@@ -36,7 +36,7 @@
|
||||||
|
all: $(PROGS)
|
||||||
|
|
||||||
|
$(PROGS): %: %.o
|
||||||
|
- $(CC) $(LDFLAGS) -o $@ $< $(LIBS)
|
||||||
|
+ $(CC) $(COPTFLAG) $(LDFLAGS) -o $@ $< $(LIBS)
|
||||||
|
|
||||||
|
%.o: %.c $(INCS)
|
||||||
|
$(CC) $(CFLAGS) -c $< -o $@
|
||||||
19
libcap-1.10-userland.patch
Normal file
19
libcap-1.10-userland.patch
Normal file
|
|
@ -0,0 +1,19 @@
|
||||||
|
--- libcap-1.10/libcap/include/sys/capability.h.foo Fri Nov 9 16:26:25 2001
|
||||||
|
+++ libcap-1.10/libcap/include/sys/capability.h Fri Nov 9 16:28:47 2001
|
||||||
|
@@ -21,6 +21,16 @@
|
||||||
|
*/
|
||||||
|
|
||||||
|
#include <sys/types.h>
|
||||||
|
+#include <stdint.h>
|
||||||
|
+
|
||||||
|
+/*
|
||||||
|
+ * Make sure we can be included from userland by preventing
|
||||||
|
+ * capability.h from including other kernel headers
|
||||||
|
+ */
|
||||||
|
+#define _LINUX_TYPES_H
|
||||||
|
+#define _LINUX_FS_H
|
||||||
|
+typedef unsigned int __u32;
|
||||||
|
+
|
||||||
|
#include <linux/capability.h>
|
||||||
|
|
||||||
|
/*
|
||||||
194
libcap.spec
Normal file
194
libcap.spec
Normal file
|
|
@ -0,0 +1,194 @@
|
||||||
|
Name: libcap
|
||||||
|
Version: 1.10
|
||||||
|
Release: 29
|
||||||
|
Summary: Library for getting and setting POSIX.1e capabilities
|
||||||
|
Source: ftp://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.4/%{name}-%{version}.tar.bz2
|
||||||
|
Source1: http://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.4/capfaq-0.2.txt
|
||||||
|
URL: http://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.4/
|
||||||
|
License: BSD-like and LGPL
|
||||||
|
Patch1: libcap-1.10-userland.patch
|
||||||
|
Patch2: libcap-1.10-shared.patch
|
||||||
|
Patch3: libcap-1.10-useCFLAGSwithCC.patch
|
||||||
|
Patch4: libcap-1.10-debian.patch
|
||||||
|
Patch5: libcap-1.10-nostaticlib.patch
|
||||||
|
Patch6: libcap-1.10-fPIC.patch
|
||||||
|
Patch7: libcap-1.10-audit.patch
|
||||||
|
Group: System Environment/Libraries
|
||||||
|
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
||||||
|
Requires(post): /sbin/ldconfig
|
||||||
|
Requires(postun): /sbin/ldconfig
|
||||||
|
|
||||||
|
%description
|
||||||
|
libcap is a library for getting and setting POSIX.1e (formerly POSIX 6)
|
||||||
|
draft 15 capabilities.
|
||||||
|
|
||||||
|
%package devel
|
||||||
|
Summary: Development files for libcap
|
||||||
|
Group: Development/Libraries
|
||||||
|
Requires: %{name} = %{version}-%{release}
|
||||||
|
|
||||||
|
%description devel
|
||||||
|
Development files (Headers, libraries for static linking, etc) for libcap.
|
||||||
|
|
||||||
|
libcap is a library for getting and setting POSIX.1e (formerly POSIX 6)
|
||||||
|
draft 15 capabilities.
|
||||||
|
|
||||||
|
Install libcap-devel if you want to develop or compile applications using
|
||||||
|
libcap.
|
||||||
|
|
||||||
|
%prep
|
||||||
|
%setup -q
|
||||||
|
%patch1 -p1
|
||||||
|
%patch2 -p1
|
||||||
|
%patch3 -p1
|
||||||
|
%patch4 -p1
|
||||||
|
%patch5 -p1
|
||||||
|
%patch6 -p1
|
||||||
|
%patch7 -p1
|
||||||
|
|
||||||
|
%build
|
||||||
|
make PREFIX=%{_prefix} LIBDIR=%{_libdir} SBINDIR=%{_sbindir} \
|
||||||
|
INCDIR=%{_includedir} MANDIR=%{_mandir} COPTFLAG="$RPM_OPT_FLAGS" \
|
||||||
|
%{?_smp_mflags}
|
||||||
|
|
||||||
|
%install
|
||||||
|
rm -rf ${RPM_BUILD_ROOT}
|
||||||
|
make install DESTDIR=${RPM_BUILD_ROOT} \
|
||||||
|
LIBDIR=${RPM_BUILD_ROOT}/%{_lib} \
|
||||||
|
SBINDIR=${RPM_BUILD_ROOT}/%{_sbindir} \
|
||||||
|
INCDIR=${RPM_BUILD_ROOT}/%{_includedir} \
|
||||||
|
MANDIR=${RPM_BUILD_ROOT}/%{_mandir}/ \
|
||||||
|
COPTFLAG="$RPM_OPT_FLAGS"
|
||||||
|
mkdir -p ${RPM_BUILD_ROOT}/%{_mandir}/man{2,3,8}
|
||||||
|
mv -f doc/*.2 ${RPM_BUILD_ROOT}/%{_mandir}/man2/
|
||||||
|
mv -f doc/*.3 ${RPM_BUILD_ROOT}/%{_mandir}/man3/
|
||||||
|
cp %{SOURCE1} doc/
|
||||||
|
|
||||||
|
chmod +x ${RPM_BUILD_ROOT}/%{_lib}/*.so.*
|
||||||
|
|
||||||
|
%post -p /sbin/ldconfig
|
||||||
|
%postun -p /sbin/ldconfig
|
||||||
|
|
||||||
|
%files
|
||||||
|
%defattr(-,root,root)
|
||||||
|
/%{_lib}/*.so.*
|
||||||
|
%{_sbindir}/*
|
||||||
|
%doc doc/capability.notes doc/capfaq-0.2.txt
|
||||||
|
|
||||||
|
%files devel
|
||||||
|
%defattr(-,root,root)
|
||||||
|
%{_includedir}/*
|
||||||
|
/%{_lib}/*.so
|
||||||
|
%{_mandir}/man2/*
|
||||||
|
%{_mandir}/man3/*
|
||||||
|
|
||||||
|
%clean
|
||||||
|
rm -rf ${RPM_BUILD_ROOT}
|
||||||
|
|
||||||
|
%changelog
|
||||||
|
* Fri Feb 23 2007 Karsten Hopp <karsten@redhat.com> 1.10-29
|
||||||
|
- add CAP_AUDIT_WRITE and CAP_AUDIT_CONTROL (#229833)
|
||||||
|
|
||||||
|
* Wed Feb 21 2007 Karsten Hopp <karsten@redhat.com> 1.10-28
|
||||||
|
- drop obsolete ia64 patch
|
||||||
|
- rpmlint fixes
|
||||||
|
|
||||||
|
* Wed Feb 21 2007 Karsten Hopp <karsten@redhat.com> 1.10-27
|
||||||
|
- misc. review fixes
|
||||||
|
- add debian patch to make it build with a recent glibc
|
||||||
|
- remove static lib
|
||||||
|
|
||||||
|
* Wed Jul 19 2006 Karsten Hopp <karsten@redhat.de> 1.10-25
|
||||||
|
- add patch to support COPTFLAG (#199365)
|
||||||
|
|
||||||
|
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 1.10-24.2.1
|
||||||
|
- rebuild
|
||||||
|
|
||||||
|
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 1.10-24.2
|
||||||
|
- bump again for double-long bug on ppc(64)
|
||||||
|
|
||||||
|
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 1.10-24.1
|
||||||
|
- rebuilt for new gcc4.1 snapshot and glibc changes
|
||||||
|
|
||||||
|
* Mon Dec 19 2005 Karsten Hopp <karsten@redhat.de> 1.10-24
|
||||||
|
- added development manpages
|
||||||
|
- as there are no manpages for the executables available, added at least
|
||||||
|
a FAQ (#172324)
|
||||||
|
|
||||||
|
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
|
||||||
|
- rebuilt
|
||||||
|
|
||||||
|
* Mon Oct 31 2005 Steve Grubb <sgrubb@redhat.com> 1.10-23
|
||||||
|
- rebuild to pick up audit capabilities
|
||||||
|
|
||||||
|
* Wed Mar 02 2005 Karsten Hopp <karsten@redhat.de> 1.10-22
|
||||||
|
- build with gcc-4
|
||||||
|
|
||||||
|
* Wed Feb 09 2005 Karsten Hopp <karsten@redhat.de> 1.10-21
|
||||||
|
- rebuilt
|
||||||
|
|
||||||
|
* Tue Aug 31 2004 Phil Knirsch <pknirsch@redhat.com> 1.10-20
|
||||||
|
- Fix wrong typedef in userland patch (#98801)
|
||||||
|
|
||||||
|
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
|
||||||
|
- rebuilt
|
||||||
|
|
||||||
|
* Tue Mar 02 2004 Elliot Lee <sopwith@redhat.com>
|
||||||
|
- rebuilt
|
||||||
|
|
||||||
|
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
|
||||||
|
- rebuilt
|
||||||
|
|
||||||
|
* Tue Jan 27 2004 Karsten Hopp <karsten@redhat.de> 1.10-17
|
||||||
|
- use _manpath
|
||||||
|
|
||||||
|
* Wed Jun 04 2003 Elliot Lee <sopwith@redhat.com>
|
||||||
|
- rebuilt
|
||||||
|
|
||||||
|
* Wed Jan 22 2003 Tim Powers <timp@redhat.com>
|
||||||
|
- rebuilt
|
||||||
|
|
||||||
|
* Sat Jan 4 2003 Jeff Johnson <jbj@redhat.com> 1.10-14
|
||||||
|
- set execute bits on library so that requires are generated.
|
||||||
|
|
||||||
|
* Thu Nov 21 2002 Mike A. Harris <mharris@redhat.com> 1.10-13
|
||||||
|
- Removed %%name macro sillyness from package Summary, description text, etc.
|
||||||
|
- Removed archaic Prefix: tag
|
||||||
|
- lib64 fixes everywhere to use _lib, _libdir, etc
|
||||||
|
- Removed deletion of RPM_BUILD_DIR from %%clean section
|
||||||
|
- Added -q flag to setup macro
|
||||||
|
- Severely cleaned up spec file, and removed usage of perl
|
||||||
|
|
||||||
|
* Fri Jul 19 2002 Jakub Jelinek <jakub@redhat.com> 1.10-12
|
||||||
|
- CFLAGS was using COPTFLAG variable, not COPTFLAGS
|
||||||
|
- build with -fpic
|
||||||
|
- apply the IA-64 patch everywhere, use capget/capset from glibc,
|
||||||
|
not directly as _syscall (as it is broken on IA-32 with -fpic)
|
||||||
|
- reenable alpha
|
||||||
|
|
||||||
|
* Fri Jun 21 2002 Tim Powers <timp@redhat.com>
|
||||||
|
- automated rebuild
|
||||||
|
|
||||||
|
* Wed May 29 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-10
|
||||||
|
- Exclude alpha for now, apparent gcc bug.
|
||||||
|
|
||||||
|
* Fri Nov 9 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-6
|
||||||
|
- Fix sys/capabilities.h header (#55727)
|
||||||
|
- Move to /lib, some applications seem to be using this rather early
|
||||||
|
(#55733)
|
||||||
|
|
||||||
|
* Mon Jul 16 2001 Trond Eivind Glomsrød <teg@redhat.com>
|
||||||
|
- Add post,postun scripts
|
||||||
|
|
||||||
|
* Tue Jul 10 2001 Jakub Jelinek <jakub@redhat.com>
|
||||||
|
- don't build libcap.so.1 with ld -shared, but gcc -shared
|
||||||
|
|
||||||
|
* Wed Jun 20 2001 Trond Eivind Glomsrød <teg@redhat.com>
|
||||||
|
- Rebuild - it was missing for alpha
|
||||||
|
|
||||||
|
* Wed Jun 06 2001 Florian La Roche <Florian.LaRoche@redhat.de>
|
||||||
|
- add s390/s390x support
|
||||||
|
|
||||||
|
* Thu May 17 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-1
|
||||||
|
- initial RPM
|
||||||
|
- fix build on ia64
|
||||||
1
sources
1
sources
|
|
@ -0,0 +1 @@
|
||||||
|
4426a413128142cab89eb2e6f13d8571 libcap-1.10.tar.bz2
|
||||||
Loading…
Add table
Add a link
Reference in a new issue