mirror of
https://github.com/mainflux/mainflux.git
synced 2025-04-29 13:49:28 +08:00

* Use normalizer as stream source Renamed 'writer' service to 'normalizer' and dropped Cassandra facilities from it. Extracted the common dependencies to 'mainflux' package for easier sharing. Fixed the API docs and unified environment variables. Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Use docker build arguments to specify build Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Remove cassandra libraries Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Update go-kit version to 0.6.0 Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Fix manager configuration Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Refactor docker-compose Merged individual compose files and dropped external links. Remove CoAP container since it is not referenced from NginX config at the moment. Update port mapping in compose and nginx.conf. Dropped bin scripts. Updated service documentation. Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Drop content-type check Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Implement users data access layer in PostgreSQL Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Bump version to 0.1.0 Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Use go-kit logger everywhere (except CoAP) Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Improve factory methods naming Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Implement clients data access layer on PostgreSQL Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Make tests stateless All tests are refactored to use map-based table-driven tests. No cross-tests dependencies is present anymore. Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Remove gitignore Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Fix nginx proxying Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Mark client-user FK explicit Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Update API documentation Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Update channel model Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Add channel PostgreSQL repository tests Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Implement PostgreSQL channels DAO Replaced update queries with raw SQL. Explicitly defined M2M table due to difficulties of ensuring the referential integrity through GORM. Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Expose connection endpoints Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Fix swagger docs and remove DB logging Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Fix nested query remarks Signed-off-by: Dejan Mijic <dejan@mainflux.com> * Add unique indices Signed-off-by: Dejan Mijic <dejan@mainflux.com>
196 lines
5.1 KiB
Go
196 lines
5.1 KiB
Go
// Copyright 2017 The Go Authors. All rights reserved.
|
|
// Use of this source code is governed by a BSD-style
|
|
// license that can be found in the LICENSE file.
|
|
|
|
// +build freebsd
|
|
|
|
package unix
|
|
|
|
import (
|
|
errorspkg "errors"
|
|
"fmt"
|
|
)
|
|
|
|
// Go implementation of C mostly found in /usr/src/sys/kern/subr_capability.c
|
|
|
|
const (
|
|
// This is the version of CapRights this package understands. See C implementation for parallels.
|
|
capRightsGoVersion = CAP_RIGHTS_VERSION_00
|
|
capArSizeMin = CAP_RIGHTS_VERSION_00 + 2
|
|
capArSizeMax = capRightsGoVersion + 2
|
|
)
|
|
|
|
var (
|
|
bit2idx = []int{
|
|
-1, 0, 1, -1, 2, -1, -1, -1, 3, -1, -1, -1, -1, -1, -1, -1,
|
|
4, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
|
|
}
|
|
)
|
|
|
|
func capidxbit(right uint64) int {
|
|
return int((right >> 57) & 0x1f)
|
|
}
|
|
|
|
func rightToIndex(right uint64) (int, error) {
|
|
idx := capidxbit(right)
|
|
if idx < 0 || idx >= len(bit2idx) {
|
|
return -2, fmt.Errorf("index for right 0x%x out of range", right)
|
|
}
|
|
return bit2idx[idx], nil
|
|
}
|
|
|
|
func caprver(right uint64) int {
|
|
return int(right >> 62)
|
|
}
|
|
|
|
func capver(rights *CapRights) int {
|
|
return caprver(rights.Rights[0])
|
|
}
|
|
|
|
func caparsize(rights *CapRights) int {
|
|
return capver(rights) + 2
|
|
}
|
|
|
|
// CapRightsSet sets the permissions in setrights in rights.
|
|
func CapRightsSet(rights *CapRights, setrights []uint64) error {
|
|
// This is essentially a copy of cap_rights_vset()
|
|
if capver(rights) != CAP_RIGHTS_VERSION_00 {
|
|
return fmt.Errorf("bad rights version %d", capver(rights))
|
|
}
|
|
|
|
n := caparsize(rights)
|
|
if n < capArSizeMin || n > capArSizeMax {
|
|
return errorspkg.New("bad rights size")
|
|
}
|
|
|
|
for _, right := range setrights {
|
|
if caprver(right) != CAP_RIGHTS_VERSION_00 {
|
|
return errorspkg.New("bad right version")
|
|
}
|
|
i, err := rightToIndex(right)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
if i >= n {
|
|
return errorspkg.New("index overflow")
|
|
}
|
|
if capidxbit(rights.Rights[i]) != capidxbit(right) {
|
|
return errorspkg.New("index mismatch")
|
|
}
|
|
rights.Rights[i] |= right
|
|
if capidxbit(rights.Rights[i]) != capidxbit(right) {
|
|
return errorspkg.New("index mismatch (after assign)")
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// CapRightsClear clears the permissions in clearrights from rights.
|
|
func CapRightsClear(rights *CapRights, clearrights []uint64) error {
|
|
// This is essentially a copy of cap_rights_vclear()
|
|
if capver(rights) != CAP_RIGHTS_VERSION_00 {
|
|
return fmt.Errorf("bad rights version %d", capver(rights))
|
|
}
|
|
|
|
n := caparsize(rights)
|
|
if n < capArSizeMin || n > capArSizeMax {
|
|
return errorspkg.New("bad rights size")
|
|
}
|
|
|
|
for _, right := range clearrights {
|
|
if caprver(right) != CAP_RIGHTS_VERSION_00 {
|
|
return errorspkg.New("bad right version")
|
|
}
|
|
i, err := rightToIndex(right)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
if i >= n {
|
|
return errorspkg.New("index overflow")
|
|
}
|
|
if capidxbit(rights.Rights[i]) != capidxbit(right) {
|
|
return errorspkg.New("index mismatch")
|
|
}
|
|
rights.Rights[i] &= ^(right & 0x01FFFFFFFFFFFFFF)
|
|
if capidxbit(rights.Rights[i]) != capidxbit(right) {
|
|
return errorspkg.New("index mismatch (after assign)")
|
|
}
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// CapRightsIsSet checks whether all the permissions in setrights are present in rights.
|
|
func CapRightsIsSet(rights *CapRights, setrights []uint64) (bool, error) {
|
|
// This is essentially a copy of cap_rights_is_vset()
|
|
if capver(rights) != CAP_RIGHTS_VERSION_00 {
|
|
return false, fmt.Errorf("bad rights version %d", capver(rights))
|
|
}
|
|
|
|
n := caparsize(rights)
|
|
if n < capArSizeMin || n > capArSizeMax {
|
|
return false, errorspkg.New("bad rights size")
|
|
}
|
|
|
|
for _, right := range setrights {
|
|
if caprver(right) != CAP_RIGHTS_VERSION_00 {
|
|
return false, errorspkg.New("bad right version")
|
|
}
|
|
i, err := rightToIndex(right)
|
|
if err != nil {
|
|
return false, err
|
|
}
|
|
if i >= n {
|
|
return false, errorspkg.New("index overflow")
|
|
}
|
|
if capidxbit(rights.Rights[i]) != capidxbit(right) {
|
|
return false, errorspkg.New("index mismatch")
|
|
}
|
|
if (rights.Rights[i] & right) != right {
|
|
return false, nil
|
|
}
|
|
}
|
|
|
|
return true, nil
|
|
}
|
|
|
|
func capright(idx uint64, bit uint64) uint64 {
|
|
return ((1 << (57 + idx)) | bit)
|
|
}
|
|
|
|
// CapRightsInit returns a pointer to an initialised CapRights structure filled with rights.
|
|
// See man cap_rights_init(3) and rights(4).
|
|
func CapRightsInit(rights []uint64) (*CapRights, error) {
|
|
var r CapRights
|
|
r.Rights[0] = (capRightsGoVersion << 62) | capright(0, 0)
|
|
r.Rights[1] = capright(1, 0)
|
|
|
|
err := CapRightsSet(&r, rights)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return &r, nil
|
|
}
|
|
|
|
// CapRightsLimit reduces the operations permitted on fd to at most those contained in rights.
|
|
// The capability rights on fd can never be increased by CapRightsLimit.
|
|
// See man cap_rights_limit(2) and rights(4).
|
|
func CapRightsLimit(fd uintptr, rights *CapRights) error {
|
|
return capRightsLimit(int(fd), rights)
|
|
}
|
|
|
|
// CapRightsGet returns a CapRights structure containing the operations permitted on fd.
|
|
// See man cap_rights_get(3) and rights(4).
|
|
func CapRightsGet(fd uintptr) (*CapRights, error) {
|
|
r, err := CapRightsInit(nil)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
err = capRightsGet(capRightsGoVersion, int(fd), r)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return r, nil
|
|
}
|