
Manpages
Table 
Table 4-2  Fine-Grained  Privileges Manpages
| Manpage | Description | 
| privileges(5) | Overview of  | 
| privileges(3) | Describes  | 
| setfilexsec(1M) | Describes setfilexsec functionality and syntax. | 
| getfilexsec(1M) | Describes getfilexsec functionality and syntax. | 
| getprocxsec(1M) | Describes getprocxsec funtionality and syntax. | 
Available Privileges
Table 
Table 4-3  Available Privileges
| Privilege | Description | 
| PRIV_ACCOUNTING | Allows a process to control the process accounting system. | 
| PRIV_AUDCONTROL | Allows a process to start, modify, and stop the auditing system. | 
| PRIV_CHANGECMPT | Grants a process the ability to change its compartment. | 
| PRIV_CHANGEFILEXSEC | Allows a process to grant privileges to binaries. | 
| PRIV_CHOWN | Allows a process to access chown system calls. | 
| PRIV_CHROOT | Allows a process to change its root directory. | 
| PRIV_CHSUBJIDENT | Allows a process to change its UIDs, GIDs, and group lists. Also allows a | 
| 
 | process to leave the suid or sgid bits set on the file when the chown | 
| 
 | system call is used. | 
| PRIV_CMPTREAD | Allows a process to open a file or directory for reading, executing, or | 
| 
 | searching, bypassing compartment rules that otherwise would not allow | 
| 
 | these operations. | 
| PRIV_CMPTWRITE | Allows a process to write to a file or directory, bypassing compartment | 
| 
 | rules that otherwise would not allow this operation. | 
| PRIV_COMMALLOWED | Allows a process to override compartment rules in the IPC and networking | 
| 
 | subsystems. | 
| PRIV_DACREAD | Allows a process to override all discretionary read, execute, and search | 
| 
 | access restrictions. | 
| PRIV_DACWRITE | Allows a process to override all discretionary write access restrictions. | 
| PRIV_DEVOPS | Allows a process to do  | 
| 
 | tape or disk formatting. | 
| PRIV_DLKM | Allows a process to load a kernel module, get information about a loaded | 
| 
 | kernel module, and change global search paths for a dynamically loadable | 
| 
 | kernel module. | 
| PRIV_FSINTEGRITY | Allows a process to perform disk operations such as removing or | 
| 
 | modifying the size or boundaries of disk partitions, or to import and export | 
| 
 | an LVM volume group across the system. | 
52 
