Manpages
Table
Table 4-2 Fine-Grained Privileges Manpages
Manpage | Description |
privileges(5) | Overview of |
privileges(3) | Describes |
setfilexsec(1M) | Describes setfilexsec functionality and syntax. |
getfilexsec(1M) | Describes getfilexsec functionality and syntax. |
getprocxsec(1M) | Describes getprocxsec funtionality and syntax. |
Available Privileges
Table
Table 4-3 Available Privileges
Privilege | Description |
PRIV_ACCOUNTING | Allows a process to control the process accounting system. |
PRIV_AUDCONTROL | Allows a process to start, modify, and stop the auditing system. |
PRIV_CHANGECMPT | Grants a process the ability to change its compartment. |
PRIV_CHANGEFILEXSEC | Allows a process to grant privileges to binaries. |
PRIV_CHOWN | Allows a process to access chown system calls. |
PRIV_CHROOT | Allows a process to change its root directory. |
PRIV_CHSUBJIDENT | Allows a process to change its UIDs, GIDs, and group lists. Also allows a |
| process to leave the suid or sgid bits set on the file when the chown |
| system call is used. |
PRIV_CMPTREAD | Allows a process to open a file or directory for reading, executing, or |
| searching, bypassing compartment rules that otherwise would not allow |
| these operations. |
PRIV_CMPTWRITE | Allows a process to write to a file or directory, bypassing compartment |
| rules that otherwise would not allow this operation. |
PRIV_COMMALLOWED | Allows a process to override compartment rules in the IPC and networking |
| subsystems. |
PRIV_DACREAD | Allows a process to override all discretionary read, execute, and search |
| access restrictions. |
PRIV_DACWRITE | Allows a process to override all discretionary write access restrictions. |
PRIV_DEVOPS | Allows a process to do |
| tape or disk formatting. |
PRIV_DLKM | Allows a process to load a kernel module, get information about a loaded |
| kernel module, and change global search paths for a dynamically loadable |
| kernel module. |
PRIV_FSINTEGRITY | Allows a process to perform disk operations such as removing or |
| modifying the size or boundaries of disk partitions, or to import and export |
| an LVM volume group across the system. |
52