Next: The CAP_SYS_BOOT capability
Up: Capabilities
Previous: The CAP_SYS_PACCT capability
  Contents
- Allow configuration of the secure attention key
- Allow administration of the random device
- Allow device administration (mknod)
- Allow examination and configuration of disk quotas
- Allow configuring the kernel's syslog (printk behaviour)
- Allow setting the domainname
- Allow setting the hostname
- Allow calling bdflush()
- Allow mount() and umount(), setting up new smb connection
- Allow some autofs root ioctls
- Allow nfsservctl
- Allow VM86_REQUEST_IRQ
- Allow to read/write pci config on alpha
- Allow irix_prctl on mips (setstacksize)
- Allow flushing all cache on m68k (sys_cacheflush)
- Allow removing semaphores
- Used instead of CAP_CHOWN to "chown" IPC message queues, semaphores
and shared memory
- Allow locking/unlocking of shared memory segment
- Allow turning swap on/off
- Allow forged pids on socket credentials passing
- Allow setting readahead and flushing buffers on block devices
- Allow setting geometry in floppy driver
- Allow turning DMA on/off in xd driver
- Allow administration of md devices (mostly the above, but some
extra ioctls)
- Allow tuning the ide driver
- Allow access to the nvram device
- Allow administration of apm_bios, serial and bttv (TV) device
- Allow manufacturer commands in isdn CAPI support driver
- Allow reading non-standardized portions of pci configuration space
- Allow DDI debug ioctl on sbpcd driver
- Allow setting up serial ports
- Allow sending raw qic-117 commands
- Allow enabling/disabling tagged queuing on SCSI controllers and sending
arbitrary SCSI commands
- Allow setting encryption key on loopback filesystem
Next: The CAP_SYS_BOOT capability
Up: Capabilities
Previous: The CAP_SYS_PACCT capability
  Contents
Biondi Philippe
2000-02-24