/* User-level do most of the mapping between kernel and user capabilitiesbasedontheversiontaggivenbythekernel.The kernelmightbesomewhatbackwardscompatible,butdon'tbeton
it. */
/* Note, cap_t, is defined by POSIX (draft) to be an "opaque" pointer to asetofthreecapabilitysets.Thetranspositionof3*the followingstructuretosuchacompositeisbetterhandledinauser librarysincethedraftstandardrequirestheuseofmalloc/free
etc.. */
/* In a system with the [_POSIX_CHOWN_RESTRICTED] option defined, this overridestherestrictionofchangingfileownershipandgroup
ownership. */
#define CAP_CHOWN 0
/* Override all DAC access, including ACL execute access if [_POSIX_ACL]isdefined.ExcludingDACaccesscoveredby
CAP_LINUX_IMMUTABLE. */
#define CAP_DAC_OVERRIDE 1
/* Overrides all DAC restrictions regarding read and search on files anddirectories,includingACLrestrictionsif[_POSIX_ACL]is
defined. Excluding DAC access covered by CAP_LINUX_IMMUTABLE. */
#define CAP_DAC_READ_SEARCH 2
/* Overrides all restrictions about allowed operations on files, where fileownerIDmustbeequaltotheuserID,exceptwhereCAP_FSETID
is applicable. It doesn't override MAC and DAC restrictions. */
#define CAP_FOWNER 3
/* Overrides the following restrictions that the effective user ID shallmatchthefileownerIDwhensettingtheS_ISUIDandS_ISGID bitsonthatfile;thattheeffectivegroupID(oroneofthe supplementarygroupIDs)shallmatchthefileownerIDwhensetting theS_ISGIDbitonthatfile;thattheS_ISUIDandS_ISGIDbitsare
cleared on successful return from chown(2) (not implemented). */
#define CAP_FSETID 4
/* Overrides the restriction that the real or effective user ID of a processsendingasignalmustmatchtherealoreffectiveuserID
of the process receiving the signal. */
/* Without VFS support for capabilities: *Transferanycapabilityinyourpermittedsettoanypid, *removeanycapabilityinyourpermittedsetfromanypid *WithVFSsupportforcapabilities(neitherofabove,but) *Addanycapabilityfromcurrent'scapabilityboundingset *tothecurrentprocess'inheritableset *Allowtakingbitsoutofcapabilityboundingset *Allowmodificationofthesecurebitsforaprocess
*/
#define CAP_SETPCAP 8
/* Allow modification of S_IMMUTABLE and S_APPEND file attributes */
#define CAP_LINUX_IMMUTABLE 9
/* Allows binding to TCP/UDP sockets below 1024 */ /* Allows binding to ATM VCIs below 32 */
#define CAP_NET_BIND_SERVICE 10
/* Allow broadcasting, listen to multicast */
#define CAP_NET_BROADCAST 11
/* Allow interface configuration */ /* Allow administration of IP firewall, masquerading and accounting */ /* Allow setting debug option on sockets */ /* Allow modification of routing tables */ /* Allow setting arbitrary process / process group ownership on
sockets */ /* Allow binding to any address for transparent proxying (also via NET_RAW) */ /* Allow setting TOS (type of service) */ /* Allow setting promiscuous mode */ /* Allow clearing driver statistics */ /* Allow multicasting */ /* Allow read/write of device-specific registers */ /* Allow activation of ATM control sockets */
#define CAP_NET_ADMIN 12
/* Allow use of RAW sockets */ /* Allow use of PACKET sockets */ /* Allow binding to any address for transparent proxying (also via NET_ADMIN) */
#define CAP_NET_RAW 13
/* Allow locking of shared memory segments */ /* Allow mlock and mlockall (which doesn't really have anything to do
with IPC) */
#define CAP_IPC_LOCK 14
/* Override IPC ownership checks */
#define CAP_IPC_OWNER 15
/* Insert and remove kernel modules - modify kernel without limit */ #define CAP_SYS_MODULE 16
/* Allow ioperm/iopl access */ /* Allow sending USB messages to any device via /dev/bus/usb */
#define CAP_SYS_RAWIO 17
/* Allow use of chroot() */
#define CAP_SYS_CHROOT 18
/* Allow ptrace() of any process */
#define CAP_SYS_PTRACE 19
/* Allow configuration of process accounting */
#define CAP_SYS_PACCT 20
/* Allow configuration of the secure attention key */ /* Allow administration of the random device */ /* Allow examination and configuration of disk quotas */ /* Allow setting the domainname */ /* Allow setting the hostname */ /* Allow mount() and umount(), setting up new smb connection */ /* Allow some autofs root ioctls */ /* Allow nfsservctl */ /* Allow VM86_REQUEST_IRQ */ /* Allow to read/write pci config on alpha */ /* Allow irix_prctl on mips (setstacksize) */ /* Allow flushing all cache on m68k (sys_cacheflush) */ /* Allow removing semaphores */ /* Used instead of CAP_CHOWN to "chown" IPC message queues, semaphores
and shared memory */ /* Allow locking/unlocking of shared memory segment */ /* Allow turning swap on/off */ /* Allow forged pids on socket credentials passing */ /* Allow setting readahead and flushing buffers on block devices */ /* Allow setting geometry in floppy driver */ /* Allow turning DMA on/off in xd driver */ /* Allow administration of md devices (mostly the above, but some
extra ioctls) */ /* Allow tuning the ide driver */ /* Allow access to the nvram device */ /* Allow administration of apm_bios, serial and bttv (TV) device */ /* Allow manufacturer commands in isdn CAPI support driver */ /* Allow reading non-standardized portions of pci configuration space */ /* Allow DDI debug ioctl on sbpcd driver */ /* Allow setting up serial ports */ /* Allow sending raw qic-117 commands */ /* Allow enabling/disabling tagged queuing on SCSI controllers and sending
arbitrary SCSI commands */ /* Allow setting encryption key on loopback filesystem */ /* Allow setting zone reclaim policy */ /* Allow everything under CAP_BPF and CAP_PERFMON for backward compatibility */ /* Allow setting hardware protection emergency action */
#define CAP_SYS_ADMIN 21
/* Allow use of reboot() */
#define CAP_SYS_BOOT 22
/* Allow raising priority and setting priority on other (different
UID) processes */ /* Allow use of FIFO and round-robin (realtime) scheduling on own processesandsettingtheschedulingalgorithmusedbyanother
process. */ /* Allow setting cpu affinity on other processes */ /* Allow setting realtime ioprio class */ /* Allow setting ioprio class on other processes */
#define CAP_SYS_NICE 23
/* Override resource limits. Set resource limits. */ /* Override quota limits. */ /* Override reserved space on ext2 filesystem */ /* Modify data journaling mode on ext3 filesystem (uses journaling
resources) */ /* NOTE: ext2 honors fsuid when checking for resource overrides, so
you can override using fsuid too */ /* Override size restrictions on IPC message queues */ /* Allow more than 64hz interrupts from the real-time clock */ /* Override max number of consoles on console allocation */ /* Override max number of keymaps */ /* Control memory reclaim behavior */
#define CAP_SYS_RESOURCE 24
/* Allow manipulation of system clock */ /* Allow irix_stime on mips */ /* Allow setting the real-time clock */
#define CAP_SYS_TIME 25
/* Allow configuration of tty devices */ /* Allow vhangup() of tty */
#define CAP_SYS_TTY_CONFIG 26
/* Allow the privileged aspects of mknod() */
#define CAP_MKNOD 27
/* Allow taking of leases on files */
#define CAP_LEASE 28
/* Allow writing the audit log via unicast netlink socket */
#define CAP_AUDIT_WRITE 29
/* Allow configuration of audit via unicast netlink socket */
#define CAP_AUDIT_CONTROL 30
/* Set or remove capabilities on files.
Map uid=0 into a child user namespace. */
#define CAP_SETFCAP 31
/* Override MAC access. ThebasekernelenforcesnoMACpolicy. AnLSMmayenforceaMACpolicy,andifitdoesanditchooses toimplementcapabilitybasedoverridesofthatpolicy,thisis
the capability it should use to do so. */
#define CAP_MAC_OVERRIDE 32
/* Allow MAC configuration or state changes. ThebasekernelrequiresnoMACconfiguration. AnLSMmayenforceaMACpolicy,andifitdoesanditchooses toimplementcapabilitybasedchecksonmodificationstothat policyorthedatarequiredtomaintainit,thisisthe
capability it should use to do so. */
#define CAP_MAC_ADMIN 33
/* Allow configuring the kernel's syslog (printk behaviour) */
#define CAP_SYSLOG 34
/* Allow triggering something that will wake the system */
#define CAP_WAKE_ALARM 35
/* Allow preventing system suspends */
#define CAP_BLOCK_SUSPEND 36
/* Allow reading the audit log via multicast netlink socket */
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.