2014-03-28 02:01:51 +00:00
|
|
|
<?xml version="1.0" encoding="ISO-8859-1"?>
|
|
|
|
<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
|
|
|
|
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
|
|
|
|
<!ENTITY % general-entities SYSTEM "../general.ent">
|
|
|
|
%general-entities;
|
|
|
|
]>
|
|
|
|
|
|
|
|
<sect1 id="ch-system-libcap" role="wrap">
|
|
|
|
<?dbhtml filename="libcap.html"?>
|
|
|
|
|
|
|
|
<sect1info condition="script">
|
|
|
|
<productname>libcap</productname>
|
|
|
|
<productnumber>&libcap-version;</productnumber>
|
|
|
|
<address>&libcap-url;</address>
|
|
|
|
</sect1info>
|
|
|
|
|
|
|
|
<title>Libcap-&libcap-version;</title>
|
|
|
|
|
|
|
|
<indexterm zone="ch-system-libcap">
|
|
|
|
<primary sortas="a-Libcap">Libcap</primary>
|
|
|
|
</indexterm>
|
|
|
|
|
|
|
|
<sect2 role="package">
|
|
|
|
<title/>
|
|
|
|
|
|
|
|
<para>The Libcap package implements the user-space interfaces to the POSIX
|
|
|
|
1003.1e capabilities available in Linux kernels. These capabilities are a
|
|
|
|
partitioning of the all powerful root privilege into a set of distinct
|
|
|
|
privileges.</para>
|
|
|
|
|
|
|
|
<segmentedlist>
|
|
|
|
<segtitle>&buildtime;</segtitle>
|
|
|
|
<segtitle>&diskspace;</segtitle>
|
|
|
|
|
|
|
|
<seglistitem>
|
|
|
|
<seg>&libcap-ch6-sbu;</seg>
|
|
|
|
<seg>&libcap-ch6-du;</seg>
|
|
|
|
</seglistitem>
|
|
|
|
</segmentedlist>
|
|
|
|
|
|
|
|
</sect2>
|
|
|
|
|
|
|
|
<sect2 role="installation">
|
|
|
|
<title>Installation of Libcap</title>
|
|
|
|
|
2015-03-15 23:29:31 +00:00
|
|
|
<para>Prevent a static library from being installed:</para>
|
|
|
|
|
|
|
|
<screen><userinput remap="pre">sed -i '/install.*STALIBNAME/d' libcap/Makefile</userinput></screen>
|
|
|
|
|
2014-03-28 02:01:51 +00:00
|
|
|
<para>Compile the package:</para>
|
|
|
|
|
|
|
|
<screen><userinput remap="make">make</userinput></screen>
|
|
|
|
|
|
|
|
<para>This package does not come with a test suite.</para>
|
|
|
|
|
|
|
|
<para>Install the package:</para>
|
|
|
|
|
2016-12-17 06:46:18 +00:00
|
|
|
<screen><userinput remap="install">make RAISE_SETFCAP=no lib=lib prefix=/usr install
|
2018-11-19 20:51:45 +00:00
|
|
|
chmod -v 755 /usr/lib/libcap.so.&libcap-version;</userinput></screen>
|
2014-03-28 02:01:51 +00:00
|
|
|
|
2014-06-28 06:52:16 +01:00
|
|
|
<variablelist>
|
|
|
|
<title>The meaning of the make option:</title>
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
<term><parameter>RAISE_SETFCAP=no</parameter></term>
|
|
|
|
<listitem>
|
|
|
|
<para>This parameter skips trying to use <command>setcap</command>
|
|
|
|
on itself. This avoids an installation error if the kernel or file
|
|
|
|
system does not support extended capabilities.</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
2016-12-17 06:46:18 +00:00
|
|
|
<varlistentry>
|
|
|
|
<term><parameter>lib=lib</parameter></term>
|
|
|
|
<listitem>
|
|
|
|
<para>This parameter installs the library in
|
|
|
|
<filename>$prefix/lib</filename> rather than
|
|
|
|
<filename>$prefix/lib64</filename> on x86_64. It has no effect on
|
|
|
|
x86.</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
2014-06-28 06:52:16 +01:00
|
|
|
</variablelist>
|
|
|
|
|
2014-03-28 02:01:51 +00:00
|
|
|
<para>The shared library needs to be moved to
|
|
|
|
<filename class="directory">/lib</filename>, and as a result the
|
|
|
|
<filename class="extension">.so</filename> file in
|
|
|
|
<filename class="directory">/usr/lib</filename> will need to be recreated:</para>
|
|
|
|
|
|
|
|
<screen><userinput remap="install">mv -v /usr/lib/libcap.so.* /lib
|
|
|
|
ln -sfv ../../lib/$(readlink /usr/lib/libcap.so) /usr/lib/libcap.so</userinput></screen>
|
|
|
|
|
|
|
|
</sect2>
|
|
|
|
|
|
|
|
<sect2 id="contents-libcap" role="content">
|
|
|
|
<title>Contents of Libcap</title>
|
|
|
|
|
|
|
|
<segmentedlist>
|
|
|
|
<segtitle>Installed programs</segtitle>
|
|
|
|
<segtitle>Installed library</segtitle>
|
|
|
|
|
|
|
|
<seglistitem>
|
|
|
|
<seg>capsh, getcap, getpcaps, and setcap</seg>
|
2015-10-12 22:20:03 +01:00
|
|
|
<seg>libcap.so</seg>
|
2014-03-28 02:01:51 +00:00
|
|
|
</seglistitem>
|
|
|
|
</segmentedlist>
|
|
|
|
|
|
|
|
<variablelist>
|
|
|
|
<bridgehead renderas="sect3">Short Descriptions</bridgehead>
|
|
|
|
<?dbfo list-presentation="list"?>
|
|
|
|
<?dbhtml list-presentation="table"?>
|
|
|
|
|
|
|
|
<varlistentry id="capsh">
|
|
|
|
<term><command>capsh</command></term>
|
|
|
|
<listitem>
|
|
|
|
<para>A shell wrapper to explore and constrain capability support</para>
|
|
|
|
<indexterm zone="ch-system-libcap capsh">
|
|
|
|
<primary sortas="b-capsh">capsh</primary>
|
|
|
|
</indexterm>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
<varlistentry id="getcap">
|
|
|
|
<term><command>getcap</command></term>
|
|
|
|
<listitem>
|
|
|
|
<para>Examines file capabilities</para>
|
|
|
|
<indexterm zone="ch-system-libcap getcap">
|
|
|
|
<primary sortas="b-getcap">getcap</primary>
|
|
|
|
</indexterm>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
<varlistentry id="getpcaps">
|
|
|
|
<term><command>getpcaps</command></term>
|
|
|
|
<listitem>
|
|
|
|
<para>Displays the capabilities on the queried process(es)</para>
|
|
|
|
<indexterm zone="ch-system-libcap getpcaps">
|
|
|
|
<primary sortas="b-getpcaps">getpcaps</primary>
|
|
|
|
</indexterm>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
2016-09-18 19:22:29 +01:00
|
|
|
<varlistentry id="setcap">
|
|
|
|
<term><command>setcap</command></term>
|
|
|
|
<listitem>
|
|
|
|
<para>Sets file capabilities</para>
|
|
|
|
<indexterm zone="ch-system-libcap setcap">
|
|
|
|
<primary sortas="b-setcap">setcap</primary>
|
|
|
|
</indexterm>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
2017-12-28 03:52:38 +00:00
|
|
|
<varlistentry id="libcap">
|
|
|
|
<term><filename class="libraryfile">libcap</filename></term>
|
|
|
|
<listitem>
|
|
|
|
<para>Contains the library functions for manipulating POSIX 1003.1e
|
|
|
|
capabilities</para>
|
|
|
|
<indexterm zone="ch-system-libcap libcap">
|
|
|
|
<primary sortas="c-libcap">libcap</primary>
|
|
|
|
</indexterm>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
2016-09-18 19:22:29 +01:00
|
|
|
|
2014-03-28 02:01:51 +00:00
|
|
|
</variablelist>
|
|
|
|
|
|
|
|
</sect2>
|
|
|
|
|
|
|
|
</sect1>
|