HP-UX System Administrator's Guide: Security Management HP-UX 11i v3 (B3921-90020, September 2010)

Table Of Contents
Table 7-3 Available Privileges (continued)
DescriptionPrivilege
Allows a process to change its root directory.
PRIV_CHROOT
Allows a process to change its UIDs, GIDs, and group lists. Also
allows a process to leave the suid or sgid bits set on the file when
the chown() system call is used.
PRIV_CHSUBJIDENT
Allows a process to open a file or directory for reading, executing,
or searching, bypassing compartment rules that otherwise would
not permit these operations.
PRIV_CMPTREAD
Allows a process to write to a file or directory, bypassing
compartment rules that otherwise would not permit this operation.
PRIV_CMPTWRITE
Allows a process to override compartment rules in the IPC and
networking subsystems.
PRIV_COMMALLOWED
Allows a process to override all discretionary read, execute, and
search access restrictions.
PRIV_DACREAD
Allows a process to override all discretionary write access
restrictions.
PRIV_DACWRITE
Allows a process to do device-specific administrative operations,
such as tape or disk formatting.
PRIV_DEVOPS
Allows a process to load a kernel module, get information about
a loaded kernel module, and change global search paths for a
dynamically loadable kernel module.
PRIV_DLKM
Allows a process to perform disk operations such as removing or
modifying the size or boundaries of disk partitions, or to import
and export an LVM volume group across the system.
PRIV_FSINTEGRITY
Allows a process to set resource and priority limits beyond the
maximum limit values.
PRIV_LIMIT
Allows a process to use the lockf() system call to lock files opened
with read-only permission.
PRIV_LOCKRDONLY
Allows a process to create character or block special files using the
mknod() system call.
PRIV_MKNOD
Allows a process to access the plock system call.PRIV_MLOCK
Allows a process to mount and unmount a file system using the
mount() and umount() system calls.
PRIV_MOUNT
Allows a process to change processor binding, locality domain
binding, or launch policy.
PRIV_MPCTL
Allows a process to perform network administrative operations
including configuring the network routing tables and querying
interface information.
PRIV_NETADMIN
7.3 Available Privileges 129