Merge pull request #1482 from tklauser/x-sys-unix-keyctl

Use keyctl wrappers from x/sys/unix
This commit is contained in:
Michael Crosby 2017-06-23 11:07:55 -07:00 committed by GitHub
commit d337d807fc
1 changed files with 6 additions and 23 deletions

View File

@ -6,31 +6,16 @@ import (
"fmt" "fmt"
"strconv" "strconv"
"strings" "strings"
"unsafe"
"golang.org/x/sys/unix" "golang.org/x/sys/unix"
) )
const KEYCTL_JOIN_SESSION_KEYRING = 1
const KEYCTL_SETPERM = 5
const KEYCTL_DESCRIBE = 6
type KeySerial uint32 type KeySerial uint32
func JoinSessionKeyring(name string) (KeySerial, error) { func JoinSessionKeyring(name string) (KeySerial, error) {
var _name *byte sessKeyId, err := unix.KeyctlJoinSessionKeyring(name)
var err error
if len(name) > 0 {
_name, err = unix.BytePtrFromString(name)
if err != nil { if err != nil {
return KeySerial(0), err return 0, fmt.Errorf("could not create session key: %v", err)
}
}
sessKeyId, _, errn := unix.Syscall(unix.SYS_KEYCTL, KEYCTL_JOIN_SESSION_KEYRING, uintptr(unsafe.Pointer(_name)), 0)
if errn != 0 {
return 0, fmt.Errorf("could not create session key: %v", errn)
} }
return KeySerial(sessKeyId), nil return KeySerial(sessKeyId), nil
} }
@ -39,10 +24,8 @@ func JoinSessionKeyring(name string) (KeySerial, error) {
// anding the bits with the given mask (clearing permissions) and setting // anding the bits with the given mask (clearing permissions) and setting
// additional permission bits // additional permission bits
func ModKeyringPerm(ringId KeySerial, mask, setbits uint32) error { func ModKeyringPerm(ringId KeySerial, mask, setbits uint32) error {
dest := make([]byte, 1024) dest, err := unix.KeyctlString(unix.KEYCTL_DESCRIBE, int(ringId))
destBytes := unsafe.Pointer(&dest[0]) if err != nil {
if _, _, err := unix.Syscall6(unix.SYS_KEYCTL, uintptr(KEYCTL_DESCRIBE), uintptr(ringId), uintptr(destBytes), uintptr(len(dest)), 0, 0); err != 0 {
return err return err
} }
@ -59,7 +42,7 @@ func ModKeyringPerm(ringId KeySerial, mask, setbits uint32) error {
perm := (uint32(perm64) & mask) | setbits perm := (uint32(perm64) & mask) | setbits
if _, _, err := unix.Syscall(unix.SYS_KEYCTL, uintptr(KEYCTL_SETPERM), uintptr(ringId), uintptr(perm)); err != 0 { if err := unix.KeyctlSetperm(int(ringId), perm); err != nil {
return err return err
} }