priv_defs revision d2a70789f056fc6c9ce3ab047b52126d80b0e3da
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * CDDL HEADER START
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * The contents of this file are subject to the terms of the
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * Common Development and Distribution License (the "License").
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * You may not use this file except in compliance with the License.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * See the License for the specific language governing permissions
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * and limitations under the License.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * When distributing Covered Code, include this CDDL HEADER in each
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * If applicable, add the following below this CDDL HEADER, with the
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * fields enclosed by brackets "[]" replaced with your own identifying
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * information: Portions Copyright [yyyy] [name of copyright owner]
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * CDDL HEADER END
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * Copyright (c) 2003, 2010, Oracle and/or its affiliates. All rights reserved.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina * Copyright 2015, Joyent, Inc. All rights reserved.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel BřezinaINSERT COMMENT
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina# Privileges can be added to this file at any location, not
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina# necessarily at the end. For patches, it is probably best to
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina# add the new privilege at the end; for ordinary releases privileges
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to request critical events without limitation.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to request reliable delivery of all events on
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to set the service FMRI value of a process
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to observe contract events generated by
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina contracts created and owned by users other than the process's
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina effective user ID.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to open contract event endpoints belonging to
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina contracts created and owned by users other than the process's
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allow a process to access per-CPU hardware performance counters.
9b74009c1260e6f3b1031a6ae110bf1d957cba81Pavel Březina Allows process-level tracing probes to be placed and enabled in
9b74009c1260e6f3b1031a6ae110bf1d957cba81Pavel Březina Allows use of the syscall and profile DTrace providers to
f4f2edba5c555773d7c9adfa95562b96b0c0cdb2Pavel Březina examine processes to which the user has permissions.
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek Allows a process to change a file's owner user ID.
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek Allows a process to change a file's group ID to one other than
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek the process' effective group ID or one of the process'
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to give away its files; a process with this
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek privilege will run as if {_POSIX_CHOWN_RESTRICTED} is not
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek Allows a process to execute an executable file whose permission
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek bits or ACL do not allow the process execute permission.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to read a file or directory whose permission
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina bits or ACL do not allow the process read permission.
552390afcc81af96ca201fa6c25ddefbbecbeb4eJakub Hrozek Allows a process to search a directory whose permission bits or
f74408e37a3007aa41b19ab2afb693a91694da42Justin Stephenson ACL do not allow the process search permission.
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek Allows a process to write a file or directory whose permission
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina bits or ACL do not allow the process write permission.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina In order to write files owned by uid 0 in the absence of an
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina effective uid of 0 ALL privileges are required.
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to set the sensitivity label of a file or
d2c614143870e6efd4b3ab20c3a55cf714595256Justin Stephenson directory to a sensitivity label that does not dominate the
d2c614143870e6efd4b3ab20c3a55cf714595256Justin Stephenson This privilege is interpreted only if the system is configured
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to set immutable, nounlink or appendonly
488b455f6b7881ec108a127840b1c1f1523d937fMichal Židek Allows a process to create hardlinks to files owned by a uid
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březinaprivilege PRIV_FILE_OWNER
e088912418fd4db750f2097dfde8ef9b77303f05Michal Židek Allows a process which is not the owner of a file or directory
e088912418fd4db750f2097dfde8ef9b77303f05Michal Židek to perform the following operations that are normally permitted
4a9160e2b3b9c531e2b4a7884f49bfbb4a07a992Sumit Bose only for the file owner: modify that file's access and
4a9160e2b3b9c531e2b4a7884f49bfbb4a07a992Sumit Bose modification times; remove or rename a file or directory whose
4a9160e2b3b9c531e2b4a7884f49bfbb4a07a992Sumit Bose parent directory has the ``save text image after execution''
4a9160e2b3b9c531e2b4a7884f49bfbb4a07a992Sumit Bose (sticky) bit set; mount a ``namefs'' upon a file; modify
3ee8659bc6a77a78bc6c61b9650a36bd18ea95c8Jakub Hrozek permission bits or ACL except for the set-uid and set-gid
e157b9f6cb370e1b94bcac2044d26ad66d640fbaPavel Březina Allows a process to read objects in the filesystem.
"udp/tcp_extra_priv_ports" with the exception of the ports