mirror of
https://github.com/rwinkhart/sys.git
synced 2026-09-01 22:57:29 -04:00
OpenBSD 7.3 and 7.4 are the only supported OpenBSD releases. This change simplifies the version detection and error handling to require at least OpenBSD 6.4 to call the Pledge and Unveil functions. Updates golang/go#63569. Change-Id: I6bd0d58807a73a532ddd2d3239687ca19a93db9d GitHub-Last-Rev: d03d157e76d1d861fa8bd9be179f9dc4fb91f8d2 GitHub-Pull-Request: golang/sys#177 Reviewed-on: https://go-review.googlesource.com/c/sys/+/537355 TryBot-Result: Gopher Robot <gobot@golang.org> Run-TryBot: Joel Sing <joel@sing.id.au> Reviewed-by: David Chase <drchase@google.com> Reviewed-by: Cherry Mui <cherryyz@google.com> Reviewed-by: Joel Sing <joel@sing.id.au>
66 lines
1.5 KiB
Go
66 lines
1.5 KiB
Go
// Copyright 2018 The Go Authors. All rights reserved.
|
|
// Use of this source code is governed by a BSD-style
|
|
// license that can be found in the LICENSE file.
|
|
|
|
package unix
|
|
|
|
import (
|
|
"fmt"
|
|
"syscall"
|
|
"unsafe"
|
|
)
|
|
|
|
// Unveil implements the unveil syscall.
|
|
// For more information see unveil(2).
|
|
// Note that the special case of blocking further
|
|
// unveil calls is handled by UnveilBlock.
|
|
func Unveil(path string, flags string) error {
|
|
if err := supportsUnveil(); err != nil {
|
|
return err
|
|
}
|
|
pathPtr, err := syscall.BytePtrFromString(path)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
flagsPtr, err := syscall.BytePtrFromString(flags)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
_, _, e := syscall.Syscall(SYS_UNVEIL, uintptr(unsafe.Pointer(pathPtr)), uintptr(unsafe.Pointer(flagsPtr)), 0)
|
|
if e != 0 {
|
|
return e
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// UnveilBlock blocks future unveil calls.
|
|
// For more information see unveil(2).
|
|
func UnveilBlock() error {
|
|
if err := supportsUnveil(); err != nil {
|
|
return err
|
|
}
|
|
// Both pointers must be nil.
|
|
var pathUnsafe, flagsUnsafe unsafe.Pointer
|
|
_, _, e := syscall.Syscall(SYS_UNVEIL, uintptr(pathUnsafe), uintptr(flagsUnsafe), 0)
|
|
if e != 0 {
|
|
return e
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// supportsUnveil checks for availability of the unveil(2) system call based
|
|
// on the running OpenBSD version.
|
|
func supportsUnveil() error {
|
|
maj, min, err := majmin()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// unveil is not available before 6.4
|
|
if maj < 6 || (maj == 6 && min <= 3) {
|
|
return fmt.Errorf("cannot call Unveil on OpenBSD %d.%d", maj, min)
|
|
}
|
|
|
|
return nil
|
|
}
|