Home
last modified time | relevance | path

Searched refs:ambient (Results 1 – 7 of 7) sorted by relevance

/systemd-251/src/basic/
Dcapability-util.c408 ambient_supported = q->ambient != UINT64_MAX; in capability_quintet_mangle()
410 combined |= q->ambient; in capability_quintet_mangle()
431 q->ambient &= ~drop; in capability_quintet_mangle()
440 if (q->ambient != UINT64_MAX) { in capability_quintet_enforce()
454 if ((q->ambient & m) == 0) in capability_quintet_enforce()
477 r = capability_ambient_set_apply(q->ambient, false); in capability_quintet_enforce()
Dcapability-util.h58 uint64_t ambient; member
70 q->ambient != UINT64_MAX; in capability_quintet_is_set()
/systemd-251/src/nspawn/
Dnspawn.c2719 if (q.ambient == UINT64_MAX && ambient_capabilities_supported()) in drop_capabilities()
2720 q.ambient = arg_caps_ambient; in drop_capabilities()
2731 .ambient = ambient_capabilities_supported() ? arg_caps_ambient : UINT64_MAX, in drop_capabilities()
4351 uint64_t ambient; in merge_settings() local
4385 ambient = settings->ambient_capability; in merge_settings()
4386 if (!arg_settings_trusted && ambient != 0) in merge_settings()
4389 arg_caps_ambient |= ambient; in merge_settings()
Dnspawn-oci.c326 …ambient", JSON_VARIANT_ARRAY, oci_capability_array, offsetof(CapabilityQuintet, ambient) }, in oci_capabilities()
/systemd-251/
DREADME34 ≥ 4.3 for ambient capabilities
DTODO185 * drop support for kernels that lack ambient capabilities support (i.e. make
664 * userdb: add field for ambient caps, so that a user can have CAP_WAKE_ALARM
665 for example. And add code that resets ambient caps for all services by
DNEWS2310 * systemd-nspawn gained a new --ambient-capability= setting
2311 (AmbientCapability= in .nspawn files) to configure ambient
6863 systems that support ambient capabilities. This is useful to write
6864 unit files that work with ambient capabilities where possible but