Lines Matching full:allows

24 	// CHOWN allows a process to arbitrarily change the user and
28 // DAC_OVERRIDE allows a process to override of all Discretionary
35 // DAC_READ_SEARCH allows a process to override all DAC restrictions
41 // FOWNER allows a process to perform operations on files, even
51 // FSETID allows a process to set the S_ISUID and S_ISUID bits of
57 // KILL allows a process to send a kill(2) signal to any other
62 // SETGID allows a process to freely manipulate its own GIDs:
65 // - allows the forging of GID credentials passed over a
69 // SETUID allows a process to freely manipulate its own UIDs:
72 // - allows the forging of UID credentials passed over a
76 // SETPCAP allows a process to freely manipulate its inheritable
102 // LINUX_IMMUTABLE allows a process to modify the S_IMMUTABLE and
106 // NET_BIND_SERVICE allows a process to bind to privileged ports:
111 // NET_BROADCAST allows a process to broadcast to the network and to
115 // NET_ADMIN allows a process to perform network configuration
134 // NET_RAW allows a process to use raw networking:
141 // IPC_LOCK allows a process to lock shared memory segments for IPC
146 // IPC_OWNER allows a process to override IPC ownership checks.
149 // SYS_MODULE allows a process to initiate the loading and unloading
154 // SYS_RAWIO allows a process to perform raw IO:
160 // SYS_CHROOT allows a process to perform a chroot syscall to change
165 // SYS_PTRACE allows a process to perform a ptrace() of any other
169 // SYS_PACCT allows a process to configure process accounting.
172 // SYS_ADMIN allows a process to perform a somewhat arbitrary
217 // SYS_BOOT allows a process to initiate a reboot of the system.
220 // SYS_NICE allows a process to maipulate the execution priorities
228 // SYS_RESOURCE allows a process to adjust resource related parameters
244 // SYS_TIME allows a process to perform time manipulation of clocks:
250 // SYS_TTY_CONFIG allows a process to manipulate tty devices:
255 // MKNOD allows a process to perform privileged operations with
259 // LEASE allows a process to take leases on files.
262 // AUDIT_WRITE allows a process to write to the audit log via a
266 // AUDIT_CONTROL allows a process to configure audit logging via a
270 // SETFCAP allows a process to set capabilities on files.
278 // MAC_OVERRIDE allows a process to override Manditory Access Control
284 // MAC_ADMIN allows a process to configure the Mandatory Access
290 // SYSLOG allows a process to configure the kernel's syslog
294 // WAKE_ALARM allows a process to trigger something that can wake the
298 // BLOCK_SUSPEND allows a process to block system suspends - prevent the
302 // AUDIT_READ allows a process to read the audit log via a multicast
306 // PERFMON allows a process to enable observability of privileged
312 // BPF allows a process to manipulate aspects of the kernel
347 // CHECKPOINT_RESTORE allows a process to perform checkpoint