diff --git a/uwsgi.c b/uwsgi.c index 333ecac8..a7395494 100644 --- a/uwsgi.c +++ b/uwsgi.c @@ -151,14 +151,12 @@ static struct uwsgi_option uwsgi_base_options[] = { {"chroot", required_argument, 0, "chroot() to the specified directory", uwsgi_opt_set_str, &uwsgi.chroot,0}, {"uid", required_argument, 0, "setuid to the specified user/uid", uwsgi_opt_set_uid, NULL, 0}, {"gid", required_argument, 0, "setgid to the specified group/gid", uwsgi_opt_set_gid, NULL, 0}, -/* #ifdef UWSGI_CAP - {"cap", required_argument,0, LONG_ARGS_CAP,0}, + {"cap", required_argument,0, "set process capability", uwsgi_opt_set_cap, NULL, 0}, #endif #ifdef __linux__ - {"unshare", required_argument,0, LONG_ARGS_UNSHARE,0}, + {"unshare", required_argument,0, "unshare() part of the processes and put it in a new namespace", uwsgi_opt_set_unshare, 0}, #endif -*/ {"exec-pre-jail", required_argument,0, "run the specified command before jailing", uwsgi_opt_add_string_list, &uwsgi.exec_pre_jail ,0}, {"exec-post-jail", required_argument,0, "run the specified command after jailing", uwsgi_opt_add_string_list, &uwsgi.exec_post_jail,0}, {"exec-in-jail", required_argument,0, "run the specified command in jail after initialization", uwsgi_opt_add_string_list, &uwsgi.exec_in_jail,0}, @@ -3309,6 +3307,18 @@ void uwsgi_opt_set_gid(char *opt, char *value, void *none) { uwsgi.gidname = value; } +#ifdef UWSGI_CAP +void uwsgi_opt_set_cap(char *opt, char *value, void *none) { + uwsgi_build_cap(value); +} +#endif +#ifdef __linux__ +void uwsgi_opt_set_unshare(char *opt, char *value, void *none) { + uwsgi_build_unshare(value); +} +#endif + + void uwsgi_opt_load_plugin(char *opt, char *value, void *none) { char *p = strtok(uwsgi_concat2(value, ""), ","); while (p != NULL) { diff --git a/uwsgi.h b/uwsgi.h index 6cf1df64..6a04b850 100644 --- a/uwsgi.h +++ b/uwsgi.h @@ -2510,6 +2510,13 @@ void uwsgi_opt_set_umask(char *, char *, void *); void uwsgi_opt_add_spooler(char *, char *, void *); void uwsgi_opt_set_uid(char *, char *, void *); void uwsgi_opt_set_gid(char *, char *, void *); +#ifdef UWSGI_CAP +void uwsgi_opt_set_cap(char *, char *, void *); +#endif +#ifdef __linux__ +void uwsgi_opt_set_unshare(char *, char *, void *); +#endif + #ifdef UWSGI_AS_SHARED_LIBRARY int uwsgi_init(int, char **, char **);