Print this page
7029 want per-process exploit mitigation features (secflags)
7030 want basic address space layout randomization (aslr)
7031 noexec_user_stack should be a secflag
7032 want a means to forbid mappings around NULL.


 555 .sp .6
 556 .RS 4n
 557 Allow a process to elevate its priority above its current level.
 558 .RE
 559 
 560 .sp
 561 .ne 2
 562 .na
 563 \fB\fBPRIV_PROC_PRIOCNTL\fR\fR
 564 .ad
 565 .sp .6
 566 .RS 4n
 567 Allows all that PRIV_PROC_PRIOUP allows.
 568 Allow a process to change its scheduling class to any scheduling class,
 569 including the RT class.
 570 .RE
 571 
 572 .sp
 573 .ne 2
 574 .na











 575 \fB\fBPRIV_PROC_SESSION\fR\fR
 576 .ad
 577 .sp .6
 578 .RS 4n
 579 Allow a process to send signals or trace processes outside its session.
 580 .RE
 581 
 582 .sp
 583 .ne 2
 584 .na
 585 \fB\fBPRIV_PROC_SETID\fR\fR
 586 .ad
 587 .sp .6
 588 .RS 4n
 589 Allow a process to set its UIDs at will, assuming UID 0 requires all privileges
 590 to be asserted.
 591 .RE
 592 
 593 .sp
 594 .ne 2




 555 .sp .6
 556 .RS 4n
 557 Allow a process to elevate its priority above its current level.
 558 .RE
 559 
 560 .sp
 561 .ne 2
 562 .na
 563 \fB\fBPRIV_PROC_PRIOCNTL\fR\fR
 564 .ad
 565 .sp .6
 566 .RS 4n
 567 Allows all that PRIV_PROC_PRIOUP allows.
 568 Allow a process to change its scheduling class to any scheduling class,
 569 including the RT class.
 570 .RE
 571 
 572 .sp
 573 .ne 2
 574 .na
 575 \fB\PRIV_PROC_SECFLAGS\fR
 576 .ad
 577 .sp .6
 578 .RS 4n
 579 Allow a process to manipulate the secflags of processes (subject to,
 580 additionally, the ability to signal that process).
 581 .RE
 582 
 583 .sp
 584 .ne 2
 585 .na
 586 \fB\fBPRIV_PROC_SESSION\fR\fR
 587 .ad
 588 .sp .6
 589 .RS 4n
 590 Allow a process to send signals or trace processes outside its session.
 591 .RE
 592 
 593 .sp
 594 .ne 2
 595 .na
 596 \fB\fBPRIV_PROC_SETID\fR\fR
 597 .ad
 598 .sp .6
 599 .RS 4n
 600 Allow a process to set its UIDs at will, assuming UID 0 requires all privileges
 601 to be asserted.
 602 .RE
 603 
 604 .sp
 605 .ne 2