• C 55.7%
  • Go 31.8%
  • Shell 6.4%
  • Makefile 5.5%
  • C++ 0.2%
  • Other 0.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Nexory 8cab242e8b capsh: validate the --decode value
--decode is the one numeric conversion in capsh that discards the end
pointer: strtoull() stops at the first character it cannot use and the rest
is dropped. capsh then prints a capability set and exits 0.

The case that does not look like an error is a line pasted from
/proc/<pid>/status with its field name still attached. "Ca" is valid hex, so

  capsh --decode=CapEff:0000003fffffffff

prints 0x00000000000000ca, four capabilities that have nothing to do with
the input, rather than the 38 the value names. --decode=3junk, --decode=xyz
and --decode=-1 are the same shape, and an over-long value is accepted
because errno is not checked.

Add hex_ull(), the 64-bit hexadecimal counterpart of nonneg_uint(), and
route --decode through it. Valid values including a 0x prefix are
unaffected. Add quicktests for the pasted-field and trailing-character
forms.

Signed-off-by: Nexory <St4yl3r30@hotmail.de>
Signed-off-by: Andrew G. Morgan <morgan@kernel.org>
2026-09-29 19:11:26 -07:00
cap cap: avoid recursive read lock in file capability writes 2026-09-11 06:30:05 -07:00
contrib Up the release version to 2.78 2026-04-05 08:31:36 -07:00
doc Stop inlining bugzilla.kernel.org as its future is uncertain. 2026-04-08 06:36:33 -07:00
go Minor style adjustment for human readability. 2026-06-19 06:18:13 -07:00
goapps Up the release version to 2.78 2026-04-05 08:31:36 -07:00
kdebug Make the kdebug test use the terminal output. 2025-05-06 23:17:09 -07:00
libcap cap_flag: reject negative bit in the cap_iab_t vector accessors 2026-07-12 15:05:17 -07:00
pam_cap Drop linux/ headers for standard ones. 2025-03-02 10:25:00 -08:00
progs capsh: validate the --decode value 2026-09-29 19:11:26 -07:00
psx Cast getdents64() return as ssize_t and not the unsigned size_t. 2026-06-16 05:54:28 -07:00
tests Fix a test's link order to be -lpsx (with flags) before -lcap. 2026-04-24 20:57:45 -07:00
.gitignore Rewrite libpsx to work with native linux threads. 2024-10-25 22:58:46 -07:00
CHANGELOG Update the CHANGELOG file to point to current locations. 2020-06-02 19:45:10 -07:00
distcheck.sh Linux 5.7 supports CAP_PERFMON 2020-06-02 20:56:01 -07:00
gomods.sh Add a handy update script for the various go.mod files. 2021-05-24 11:50:15 -07:00
License Reviewed license information and adde SPDX ids. 2022-10-19 19:05:11 -07:00
Make.Rules Up the release version to 2.78 2026-04-05 08:31:36 -07:00
Makefile Tighten up the comments for the various signed tags moving forward. 2024-10-26 20:53:42 -07:00
pgp.keys.asc Add a more modern signing key. 2024-10-25 21:50:53 -07:00
README Fix typos. 2021-08-14 11:03:27 -07:00
template.c Prepare for 1.95 release. 2007-07-10 22:38:22 -07:00

This is a library for getting and setting POSIX.1e (formerly POSIX 6)
draft 15 capabilities.

Natively supported languages are C/C++ and Go.

This library would not have been possible without the help of 

    Aleph1, Roland Buresund and Andrew Main, Alexander Kjeldaas.

More information on capabilities in the Linux kernel, links to the
official git repository for libcap, release notes and how to report
bugs can be found at:

    http://sites.google.com/site/fullycapable/

The primary upstream git repository is this one:

    https://git.kernel.org/pub/scm/libs/libcap/libcap.git/

# BUILDING AND INSTALLATION

    $ make

       builds the library and the programs that are expected to work
       on your system. For example, if you have Linux-PAM installed,
       pam_cap is built. A golang installation is required to build
       the Go packages.

    $ make test

       runs all of the tests not requiring privilege

    $ make sudotest

       runs all of the tests including those that require privilege.

    $ sudo make install

       default installs the library libcap.XX.Y in /lib[64]/
       the binaries in /sbin/
       the header files in /usr/include
       the {libcap,libpsx}.pc files in /usr/lib[64]/pkgconfig
       the Go packages (if built) under /usr/share/gocode/src

For some example C programs look in the progs/ directory.
Specifically, capsh, getpcaps, setcap and getcap. There are some C
tests in the tests/ directory.

Go example programs are to be found in the goapps/ directory. There
are also some more complicated integration tests in the go/ directory.

There are also some oddball experimental things in the contrib/
directory, but they are mostly curiosities.

Cheers

Andrew G. Morgan <morgan@kernel.org>