privileges.5 (2010 09)

p
privileges(5) privileges(5)
PRIV_DACWRITE (DACWRITE)
Allows the process to override all discretionary write access restrictions. See Discretionary
Restrictions for more information.
PRIV_DEVOPS (DEVOPS)
Allows the process to do device specific administrative operations, such as tape or disk format-
ting.
PRIV_DLKM (DLKM)
Allows a process to load a kernel module (see modload (2)), get information about a loaded ker-
nel module (see modstat (2)), and change the global search path for dynamically loadable ker-
nel modules (see modpath (2)).
PRIV_EXEC (EXEC)
Allows a process to call exec() (see exec (2)) family calls.
PRIV_FORK (FORK)
Allows a process to create additional processes (using
fork() and vfork()).
PRIV_FSINTEGRITY (FSINTEGRITY)
Allows a process to perform disk operations such as removing or modifying the size or boun-
daries of disk partitions, or to import and export an LVM volume group across the system.
PRIV_FSSTHREAD (FSSTHREAD)
Reserved.
PRIV_FSS (FSS)
Reserved.
PRIV_LIMIT (LIMIT)
Allows a process to set resource and priority limits beyond the maximum limit values (see
setrlimit (2) or nice (2)).
PRIV_LINKANY (LINKANY)
Reserved.
PRIV_LOCKRDONLY (LOCKRDONLY)
Permits the use of the lockf() system call for setting locks on files open for reading only (see
lockf (2)).
PRIV_MKNOD (MKNOD)
Allows a process to create character or block special files using the mknod() system call (see
mknod(2)).
PRIV_MLOCK (MLOCK)
Allows access to the plock() system call (see plock (2)).
PRIV_MOUNT (MOUNT)
Allows a process to mount and unmount a file system using the mount() and umount() sys-
tem calls. See mount(2) and umount(2).
PRIV_MPCTL (MPCTL)
Permits the use of the mpctl() system call for changing processor binding, locality domain
binding or launch policy of a process (see mpctl (2)).
PRIV_NETADMIN (NETADMIN)
Allows a process to perform network administrative operations including configuring the net-
work routing tables and querying interface information.
PRIV_NETPRIVPORT (NETPRIVPORT)
Allows a process to bind to a privileged port. By default, port numbers 0-1023 are privileged
ports.
PRIV_NETPROMISCUOUS (NETPROMISCUOUS)
Enables a process to configure an interface to listen in promiscuous mode.
PRIV_NETRAWACCESS (NETRAWACCESS)
Allows a process to access the raw internet network protocols.
PRIV_OBJSUID (OBJSUID)
Allows a process to set the suid or sgid bits on any file if they also have the OWNER privilege.
Additionally, allows a process to change the ownership of a file without clearing the suid or
HP-UX 11i Version 3: September 2010 3 Hewlett-Packard Company 3