From cfe87fe3e2aeb5f23a29535af929d67c5d90f585 Mon Sep 17 00:00:00 2001 From: Tobias Klauser Date: Fri, 9 Jun 2017 15:55:18 +0200 Subject: [PATCH] Use keyctl wrappers from x/sys/unix Use KeyctlJoinSessionKeyring, KeyctlString and KeyctlSetperm from golang.org/x/sys/unix instead of manually reimplementing them. Signed-off-by: Tobias Klauser --- libcontainer/keys/keyctl.go | 29 ++++++----------------------- 1 file changed, 6 insertions(+), 23 deletions(-) diff --git a/libcontainer/keys/keyctl.go b/libcontainer/keys/keyctl.go index 7cf8055f..82ffa7a8 100644 --- a/libcontainer/keys/keyctl.go +++ b/libcontainer/keys/keyctl.go @@ -6,31 +6,16 @@ import ( "fmt" "strconv" "strings" - "unsafe" "golang.org/x/sys/unix" ) -const KEYCTL_JOIN_SESSION_KEYRING = 1 -const KEYCTL_SETPERM = 5 -const KEYCTL_DESCRIBE = 6 - type KeySerial uint32 func JoinSessionKeyring(name string) (KeySerial, error) { - var _name *byte - var err error - - if len(name) > 0 { - _name, err = unix.BytePtrFromString(name) - if err != nil { - return KeySerial(0), err - } - } - - sessKeyId, _, errn := unix.Syscall(unix.SYS_KEYCTL, KEYCTL_JOIN_SESSION_KEYRING, uintptr(unsafe.Pointer(_name)), 0) - if errn != 0 { - return 0, fmt.Errorf("could not create session key: %v", errn) + sessKeyId, err := unix.KeyctlJoinSessionKeyring(name) + if err != nil { + return 0, fmt.Errorf("could not create session key: %v", err) } return KeySerial(sessKeyId), nil } @@ -39,10 +24,8 @@ func JoinSessionKeyring(name string) (KeySerial, error) { // anding the bits with the given mask (clearing permissions) and setting // additional permission bits func ModKeyringPerm(ringId KeySerial, mask, setbits uint32) error { - dest := make([]byte, 1024) - destBytes := unsafe.Pointer(&dest[0]) - - if _, _, err := unix.Syscall6(unix.SYS_KEYCTL, uintptr(KEYCTL_DESCRIBE), uintptr(ringId), uintptr(destBytes), uintptr(len(dest)), 0, 0); err != 0 { + dest, err := unix.KeyctlString(unix.KEYCTL_DESCRIBE, int(ringId)) + if err != nil { return err } @@ -59,7 +42,7 @@ func ModKeyringPerm(ringId KeySerial, mask, setbits uint32) error { perm := (uint32(perm64) & mask) | setbits - if _, _, err := unix.Syscall(unix.SYS_KEYCTL, uintptr(KEYCTL_SETPERM), uintptr(ringId), uintptr(perm)); err != 0 { + if err := unix.KeyctlSetperm(int(ringId), perm); err != nil { return err }