Home
last modified time | relevance | path

Searched refs:bounding (Results 1 – 4 of 4) sorted by relevance

/systemd-251/src/basic/
Dcapability-util.c406 combined = q->effective | q->bounding | q->inheritable | q->permitted; in capability_quintet_mangle()
426 q->bounding &= ~drop; in capability_quintet_mangle()
562 if (q->bounding != UINT64_MAX) { in capability_quintet_enforce()
590 if (q->bounding != UINT64_MAX) { in capability_quintet_enforce()
591 r = capability_bounding_set_drop(q->bounding, false); in capability_quintet_enforce()
Dcapability-util.h55 uint64_t bounding; member
67 q->bounding != UINT64_MAX || in capability_quintet_is_set()
/systemd-251/src/nspawn/
Dnspawn-oci.c323 …bounding", JSON_VARIANT_ARRAY, oci_capability_array, offsetof(CapabilityQuintet, bounding) }, in oci_capabilities()
339 if (s->full_capabilities.bounding != UINT64_MAX) { in oci_capabilities()
340 s->capability = s->full_capabilities.bounding; in oci_capabilities()
341 s->drop_capability = ~s->full_capabilities.bounding; in oci_capabilities()
Dnspawn.c2707 if (q.bounding == UINT64_MAX) in drop_capabilities()
2708 q.bounding = uid == 0 ? arg_caps_retain : 0; in drop_capabilities()
2711 q.effective = uid == 0 ? q.bounding : 0; in drop_capabilities()
2714 q.inheritable = uid == 0 ? q.bounding : arg_caps_ambient; in drop_capabilities()
2717 q.permitted = uid == 0 ? q.bounding : arg_caps_ambient; in drop_capabilities()
2727 .bounding = arg_caps_retain, in drop_capabilities()