/usr/include/linux
NameSizeModeActions
byteorder/-0755rm
can/-0755rm
dvb/-0755rm
hdlc/-0755rm
isdn/-0755rm
netfilter/-0755rm
netfilter_arp/-0755rm
netfilter_bridge/-0755rm
netfilter_ipv4/-0755rm
netfilter_ipv6/-0755rm
nfsd/-0755rm
raid/-0755rm
spi/-0755rm
sunrpc/-0755rm
tc_act/-0755rm
tc_ematch/-0755rm
usb/-0755rm
wimax/-0755rm
a.out.h73190644editdlrm
acct.h34900644editdlrm
adb.h10770644editdlrm
adfs_fs.h8560644editdlrm
affs_hardblocks.h14810644editdlrm
agpgart.h39250644editdlrm
aio_abi.h31120644editdlrm
apm_bios.h35440644editdlrm
arcfb.h1500644editdlrm
atalk.h9270644editdlrm
atm.h78060644editdlrm
atmapi.h8890644editdlrm
atmarp.h12330644editdlrm
atmbr2684.h32080644editdlrm
atmclip.h5130644editdlrm
atmdev.h75930644editdlrm
atmioc.h15830644editdlrm
atmlec.h25610644editdlrm
atmmpc.h41630644editdlrm
atmppp.h5760644editdlrm
atmsap.h49070644editdlrm
atmsvc.h17900644editdlrm
atm_eni.h5850644editdlrm
atm_he.h3430644editdlrm
atm_idt77105.h8920644editdlrm
atm_nicstar.h12150644editdlrm
atm_tcp.h15370644editdlrm
atm_zatm.h16060644editdlrm
audit.h158800644editdlrm
auto_fs.h23460644editdlrm
auto_fs4.h41310644editdlrm
auxvec.h13840644editdlrm
ax25.h27520644editdlrm
b1lli.h16540644editdlrm
baycom.h8200644editdlrm
bfs_fs.h18300644editdlrm
binfmts.h5650644editdlrm
blkpg.h15980644editdlrm
blktrace_api.h44730644editdlrm
blk_types.h71060644editdlrm
bpqether.h9520644editdlrm
bsg.h23850644editdlrm
can.h33260644editdlrm
capability.h105890644editdlrm
capi.h30570644editdlrm
cciss_ioctl.h58240644editdlrm
cdk.h127700644editdlrm
cdrom.h281290644editdlrm
cgroupstats.h21550644editdlrm
chio.h52800644editdlrm
cm4000_cs.h17180644editdlrm
cn_proc.h27150644editdlrm
coda.h174870644editdlrm
coda_psdev.h6790644editdlrm
coff.h124130644editdlrm
comstats.h31200644editdlrm
connector.h21290644editdlrm
const.h6820644editdlrm
cramfs_fs.h29300644editdlrm
cuda.h7690644editdlrm
cyclades.h170450644editdlrm
cycx_cfm.h29260644editdlrm
dcbnl.h221200644editdlrm
dccp.h58000644editdlrm
dlm.h25290644editdlrm
dlmconstants.h50130644editdlrm
dlm_device.h24800644editdlrm
dlm_netlink.h10640644editdlrm
dlm_plock.h8060644editdlrm
dm-ioctl.h106680644editdlrm
dm-log-userspace.h151730644editdlrm
dn.h45270644editdlrm
dqblk_xfs.h69520644editdlrm
edd.h55440644editdlrm
efs_fs_sb.h21640644editdlrm
elf-em.h18340644editdlrm
elf-fdpic.h25570644editdlrm
elf.h112360644editdlrm
elfcore.h29320644editdlrm
errno.h790644editdlrm
errqueue.h4430644editdlrm
ethtool.h341660644editdlrm
eventpoll.h13530644editdlrm
ext2_fs.h188020644editdlrm
fadvise.h8550644editdlrm
falloc.h2930644editdlrm
fb.h160160644editdlrm
fcntl.h16070644editdlrm
fd.h115630644editdlrm
fdreg.h53550644editdlrm
fib_rules.h14590644editdlrm
fiemap.h25480644editdlrm
filter.h35340644editdlrm
firewire-cdev.h250530644editdlrm
firewire-constants.h19750644editdlrm
flat.h20850644editdlrm
fs.h189100644editdlrm
fuse.h114410644editdlrm
futex.h49090644editdlrm
gameport.h8160644editdlrm
generic_serial.h8950644editdlrm
genetlink.h16830644editdlrm
gen_stats.h13040644editdlrm
gfs2_ondisk.h118140644editdlrm
gigaset_dev.h9810644editdlrm
hayesesp.h2300644editdlrm
hdlc.h5740644editdlrm
hdlcdrv.h28450644editdlrm
hdreg.h226400644editdlrm
hid.h18240644editdlrm
hiddev.h62650644editdlrm
hidraw.h12170644editdlrm
hpet.h6860644editdlrm
hysdn_if.h13190644editdlrm
i2c-dev.h24030644editdlrm
i2c.h66310644editdlrm
i2o-dev.h114880644editdlrm
i8k.h14380644editdlrm
icmp.h28920644editdlrm
icmpv6.h38310644editdlrm
if.h86730644editdlrm
if_addr.h14560644editdlrm
if_addrlabel.h6580644editdlrm
if_arcnet.h37180644editdlrm
if_arp.h61090644editdlrm
if_bonding.h40760644editdlrm
if_bridge.h38100644editdlrm
if_cablemodem.h9100644editdlrm
if_ec.h9010644editdlrm
if_eql.h12840644editdlrm
if_ether.h65390644editdlrm
if_fc.h16740644editdlrm
if_fddi.h37000644editdlrm
if_frad.h29400644editdlrm
if_hippi.h41750644editdlrm
if_infiniband.h11450644editdlrm
if_link.h120780644editdlrm
if_ltalk.h1250644editdlrm
if_packet.h35300644editdlrm
if_phonet.h3370644editdlrm
if_plip.h5960644editdlrm
if_ppp.h69380644editdlrm
if_pppol2tp.h19830644editdlrm
if_pppox.h37720644editdlrm
if_slip.h8090644editdlrm
if_strip.h7000644editdlrm
if_tr.h31990644editdlrm
if_tun.h30140644editdlrm
if_tunnel.h14590644editdlrm
if_vlan.h17080644editdlrm
igmp.h29280644editdlrm
in.h92030644editdlrm
in6.h74950644editdlrm
inet_diag.h24530644editdlrm
inotify.h28380644editdlrm
input.h275940644editdlrm
in_route.h8730644editdlrm
ioctl.h1000644editdlrm
ip.h35550644editdlrm
ip6_tunnel.h10730644editdlrm
ipc.h20380644editdlrm
ipmi.h165430644editdlrm
ipmi_msgdefs.h44770644editdlrm
ipsec.h8840644editdlrm
ipv6.h28920644editdlrm
ipv6_route.h16140644editdlrm
ipx.h18240644editdlrm
ip_vs.h125830644editdlrm
irda.h76510644editdlrm
irqnr.h930644editdlrm
isdn.h56870644editdlrm
isdnif.h23060644editdlrm
isdn_divertif.h10380644editdlrm
isdn_ppp.h18590644editdlrm
iso_fs.h64390644editdlrm
ivtv.h27260644editdlrm
ivtvfb.h11430644editdlrm
ixjuser.h251160644editdlrm
jffs2.h69490644editdlrm
joystick.h35870644editdlrm
kd.h61690644editdlrm
kdev_t.h2980644editdlrm
kernel.h24570644editdlrm
kernelcapi.h9590644editdlrm
keyboard.h126950644editdlrm
keyctl.h29840644editdlrm
kvm.h206810644editdlrm
kvm_para.h5640644editdlrm
libc-compat.h35400644editdlrm
limits.h8740644editdlrm
llc.h28350644editdlrm
loop.h21890644editdlrm
lp.h37940644editdlrm
magic.h22920644editdlrm
major.h46550644editdlrm
map_to_7segment.h71870644editdlrm
matroxfb.h14290644editdlrm
mempolicy.h20520644editdlrm
meye.h25440644editdlrm
mii.h79500644editdlrm
minix_fs.h20590644editdlrm
mman.h2300644editdlrm
mmtimer.h20540644editdlrm
mqueue.h20550644editdlrm
mroute.h38130644editdlrm
mroute6.h39910644editdlrm
msdos_fs.h58390644editdlrm
msg.h25390644editdlrm
mtio.h80800644editdlrm
nbd.h19580644editdlrm
ncp.h50550644editdlrm
ncp_fs.h33540644editdlrm
ncp_mount.h21120644editdlrm
ncp_no.h6510644editdlrm
neighbour.h40600644editdlrm
net.h20210644editdlrm
netdevice.h17710644editdlrm
netfilter.h15460644editdlrm
netfilter_arp.h3800644editdlrm
netfilter_bridge.h7350644editdlrm
netfilter_decnet.h18720644editdlrm
netfilter_ipv4.h20320644editdlrm
netfilter_ipv6.h20500644editdlrm
netlink.h49690644editdlrm
netrom.h7190644editdlrm
net_dropmon.h10910644editdlrm
net_tstamp.h34680644editdlrm
nfs.h43510644editdlrm
nfs2.h14050644editdlrm
nfs3.h22070644editdlrm
nfs4.h57630644editdlrm
nfs4_mount.h18690644editdlrm
nfsacl.h5770644editdlrm
nfs_fs.h15520644editdlrm
nfs_idmap.h22380644editdlrm
nfs_mount.h32000644editdlrm
nl80211.h1923540644editdlrm
nubus.h83660644editdlrm
nvram.h4700644editdlrm
n_r3964.h23490644editdlrm
oom.h4560644editdlrm
param.h780644editdlrm
parport.h36440644editdlrm
patchkey.h8310644editdlrm
pci.h14850644editdlrm
pci_regs.h379750644editdlrm
perf_event.h218490644editdlrm
personality.h19980644editdlrm
pfkeyv2.h101470644editdlrm
pg.h22820644editdlrm
phantom.h15900644editdlrm
phonet.h43490644editdlrm
pktcdvd.h26230644editdlrm
pkt_cls.h92930644editdlrm
pkt_sched.h108870644editdlrm
pmu.h51870644editdlrm
poll.h960644editdlrm
posix_types.h12700644editdlrm
ppdev.h31470644editdlrm
ppp-comp.h65160644editdlrm
ppp_defs.h64610644editdlrm
pps.h39390644editdlrm
prctl.h49720644editdlrm
ptp_clock.h34960644editdlrm
ptrace.h22900644editdlrm
qnx4_fs.h22650644editdlrm
qnxtypes.h5610644editdlrm
quota.h57230644editdlrm
radeonfb.h2970644editdlrm
random.h10850644editdlrm
raw.h3020644editdlrm
reboot.h12800644editdlrm
reiserfs_fs.h9070644editdlrm
reiserfs_xattr.h4650644editdlrm
resource.h20870644editdlrm
rfkill.h33840644editdlrm
romfs_fs.h11270644editdlrm
rose.h21000644editdlrm
route.h22690644editdlrm
rtc.h36960644editdlrm
rtnetlink.h153350644editdlrm
scc.h45430644editdlrm
sched.h20960644editdlrm
screen_info.h22020644editdlrm
sdla.h28370644editdlrm
selinux_netlink.h11320644editdlrm
sem.h36660644editdlrm
serial.h67800644editdlrm
serial_core.h40240644editdlrm
serial_reg.h132450644editdlrm
serio.h16880644editdlrm
shm.h21870644editdlrm
signal.h1290644editdlrm
signalfd.h10960644editdlrm
smb.h12090644editdlrm
smbno.h145200644editdlrm
smb_fs.h5350644editdlrm
smb_mount.h4680644editdlrm
snmp.h111570644editdlrm
socket.h7380644editdlrm
sockios.h59670644editdlrm
som.h54800644editdlrm
sonet.h22070644editdlrm
sonypi.h51360644editdlrm
sound.h10990644editdlrm
soundcard.h460190644editdlrm
stat.h10050644editdlrm
stddef.h6330644editdlrm
string.h1750644editdlrm
suspend_ioctls.h13680644editdlrm
swab.h62920644editdlrm
synclink.h86950644editdlrm
sysctl.h264950644editdlrm
taskstats.h69470644editdlrm
tcp.h52050644editdlrm
telephony.h90510644editdlrm
termios.h5440644editdlrm
time.h17360644editdlrm
times.h2150644editdlrm
timex.h62210644editdlrm
tiocl.h16660644editdlrm
tipc.h59100644editdlrm
tipc_config.h153700644editdlrm
toshiba.h12840644editdlrm
tty.h1280644editdlrm
types.h9910644editdlrm
udf_fs_i.h6340644editdlrm
udp.h11660644editdlrm
uinput.h51250644editdlrm
uio.h6480644editdlrm
ultrasound.h44990644editdlrm
un.h2030644editdlrm
unistd.h1570644editdlrm
usbdevice_fs.h53400644editdlrm
utime.h1520644editdlrm
utsname.h6060644editdlrm
uuid.h17690644editdlrm
version.h2810644editdlrm
veth.h4740644editdlrm
vhost.h45660644editdlrm
videodev.h105130644editdlrm
videodev2.h660710644editdlrm
videotext.h42420644editdlrm
virtio_9p.h3510644editdlrm
virtio_balloon.h12550644editdlrm
virtio_blk.h29810644editdlrm
virtio_config.h12840644editdlrm
virtio_console.h14060644editdlrm
virtio_ids.h5450644editdlrm
virtio_net.h70260644editdlrm
virtio_pci.h22630644editdlrm
virtio_ring.h44890644editdlrm
virtio_rng.h2650644editdlrm
vt.h30700644editdlrm
wait.h5800644editdlrm
wanrouter.h178360644editdlrm
watchdog.h24000644editdlrm
wimax.h83700644editdlrm
wireless.h426530644editdlrm
x25.h34180644editdlrm
xattr.h6460644editdlrm
xfrm.h105580644editdlrm
Edit: /usr/include/linux/capability.h (10589B)
/* * This is * * Andrew G. Morgan * Alexander Kjeldaas * with help from Aleph1, Roland Buresund and Andrew Main. * * See here for the libcap library ("POSIX draft" compliance): * * ftp://www.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.6/ */ #ifndef _LINUX_CAPABILITY_H #define _LINUX_CAPABILITY_H #include struct task_struct; /* User-level do most of the mapping between kernel and user capabilities based on the version tag given by the kernel. The kernel might be somewhat backwards compatible, but don't bet on it. */ /* Note, cap_t, is defined by POSIX (draft) to be an "opaque" pointer to a set of three capability sets. The transposition of 3*the following structure to such a composite is better handled in a user library since the draft standard requires the use of malloc/free etc.. */ #define _LINUX_CAPABILITY_VERSION_1 0x19980330 #define _LINUX_CAPABILITY_U32S_1 1 #define _LINUX_CAPABILITY_VERSION_2 0x20071026 /* deprecated - use v3 */ #define _LINUX_CAPABILITY_U32S_2 2 #define _LINUX_CAPABILITY_VERSION_3 0x20080522 #define _LINUX_CAPABILITY_U32S_3 2 typedef struct __user_cap_header_struct { __u32 version; int pid; } *cap_user_header_t; typedef struct __user_cap_data_struct { __u32 effective; __u32 permitted; __u32 inheritable; } *cap_user_data_t; #define XATTR_CAPS_SUFFIX "capability" #define XATTR_NAME_CAPS XATTR_SECURITY_PREFIX XATTR_CAPS_SUFFIX #define VFS_CAP_REVISION_MASK 0xFF000000 #define VFS_CAP_REVISION_SHIFT 24 #define VFS_CAP_FLAGS_MASK ~VFS_CAP_REVISION_MASK #define VFS_CAP_FLAGS_EFFECTIVE 0x000001 #define VFS_CAP_REVISION_1 0x01000000 #define VFS_CAP_U32_1 1 #define XATTR_CAPS_SZ_1 (sizeof(__le32)*(1 + 2*VFS_CAP_U32_1)) #define VFS_CAP_REVISION_2 0x02000000 #define VFS_CAP_U32_2 2 #define XATTR_CAPS_SZ_2 (sizeof(__le32)*(1 + 2*VFS_CAP_U32_2)) #define XATTR_CAPS_SZ XATTR_CAPS_SZ_2 #define VFS_CAP_U32 VFS_CAP_U32_2 #define VFS_CAP_REVISION VFS_CAP_REVISION_2 struct vfs_cap_data { __le32 magic_etc; /* Little endian */ struct { __le32 permitted; /* Little endian */ __le32 inheritable; /* Little endian */ } data[VFS_CAP_U32]; }; /* * Backwardly compatible definition for source code - trapped in a * 32-bit world. If you find you need this, please consider using * libcap to untrap yourself... */ #define _LINUX_CAPABILITY_VERSION _LINUX_CAPABILITY_VERSION_1 #define _LINUX_CAPABILITY_U32S _LINUX_CAPABILITY_U32S_1 /** ** POSIX-draft defined capabilities. **/ /* In a system with the [_POSIX_CHOWN_RESTRICTED] option defined, this overrides the restriction of changing file ownership and group ownership. */ #define CAP_CHOWN 0 /* Override all DAC access, including ACL execute access if [_POSIX_ACL] is defined. Excluding DAC access covered by CAP_LINUX_IMMUTABLE. */ #define CAP_DAC_OVERRIDE 1 /* Overrides all DAC restrictions regarding read and search on files and directories, including ACL restrictions if [_POSIX_ACL] is defined. Excluding DAC access covered by CAP_LINUX_IMMUTABLE. */ #define CAP_DAC_READ_SEARCH 2 /* Overrides all restrictions about allowed operations on files, where file owner ID must be equal to the user ID, except where CAP_FSETID is applicable. It doesn't override MAC and DAC restrictions. */ #define CAP_FOWNER 3 /* Overrides the following restrictions that the effective user ID shall match the file owner ID when setting the S_ISUID and S_ISGID bits on that file; that the effective group ID (or one of the supplementary group IDs) shall match the file owner ID when setting the S_ISGID bit on that file; that the S_ISUID and S_ISGID bits are cleared on successful return from chown(2) (not implemented). */ #define CAP_FSETID 4 /* Overrides the restriction that the real or effective user ID of a process sending a signal must match the real or effective user ID of the process receiving the signal. */ #define CAP_KILL 5 /* Allows setgid(2) manipulation */ /* Allows setgroups(2) */ /* Allows forged gids on socket credentials passing. */ #define CAP_SETGID 6 /* Allows set*uid(2) manipulation (including fsuid). */ /* Allows forged pids on socket credentials passing. */ #define CAP_SETUID 7 /** ** Linux-specific capabilities **/ /* Without VFS support for capabilities: * Transfer any capability in your permitted set to any pid, * remove any capability in your permitted set from any pid * With VFS support for capabilities (neither of above, but) * Add any capability from current's capability bounding set * to the current process' inheritable set * Allow taking bits out of capability bounding set * Allow modification of the securebits for a process */ #define CAP_SETPCAP 8 /* Allow modification of S_IMMUTABLE and S_APPEND file attributes */ #define CAP_LINUX_IMMUTABLE 9 /* Allows binding to TCP/UDP sockets below 1024 */ /* Allows binding to ATM VCIs below 32 */ #define CAP_NET_BIND_SERVICE 10 /* Allow broadcasting, listen to multicast */ #define CAP_NET_BROADCAST 11 /* Allow administration of IP firewall, masquerading and accounting */ /* Allow setting debug option on sockets */ /* Allow modification of routing tables */ /* Allow binding to any address for transparent proxying */ /* Allow setting TOS (type of service) */ /* Allow setting promiscuous mode */ /* Allow clearing driver statistics */ /* Allow multicasting */ /* Allow read/write of device-specific registers */ /* Allow activation of ATM control sockets */ #define CAP_NET_ADMIN 12 /* Allow use of RAW sockets */ /* Allow use of PACKET sockets */ #define CAP_NET_RAW 13 /* Allow locking of shared memory segments */ /* Allow mlock and mlockall (which doesn't really have anything to do with IPC) */ #define CAP_IPC_LOCK 14 /* Override IPC ownership checks */ #define CAP_IPC_OWNER 15 /* Insert and remove kernel modules - modify kernel without limit */ #define CAP_SYS_MODULE 16 /* Allow ioperm/iopl access */ /* Allow O_DIRECT access */ /* Allow sending USB messages to any device via /proc/bus/usb */ #define CAP_SYS_RAWIO 17 /* Allow use of chroot() */ #define CAP_SYS_CHROOT 18 /* Allow ptrace() of any process */ #define CAP_SYS_PTRACE 19 /* Allow configuration of process accounting */ #define CAP_SYS_PACCT 20 /* Allow configuration of the secure attention key */ /* Allow administration of the random device */ /* Allow configuring the kernel's syslog (printk behaviour) */ /* Allow setting the domainname */ /* Allow setting the hostname */ /* Allow calling bdflush() */ /* Allow setting up new smb connection */ /* Allow some autofs root ioctls */ /* Allow nfsservctl */ /* Allow VM86_REQUEST_IRQ */ /* Allow to read/write pci config on alpha */ /* Allow irix_prctl on mips (setstacksize) */ /* Allow flushing all cache on m68k (sys_cacheflush) */ /* Allow locking/unlocking of shared memory segment */ /* Allow turning swap on/off */ /* Allow setting readahead and flushing buffers on block devices */ /* Allow setting geometry in floppy driver */ /* Allow turning DMA on/off in xd driver */ /* Allow administration of md devices (mostly the above, but some extra ioctls) */ /* Allow tuning the ide driver */ /* Allow access to the nvram device */ /* Allow administration of apm_bios, serial and bttv (TV) device */ /* Allow manufacturer commands in isdn CAPI support driver */ /* Allow reading non-standardized portions of pci configuration space */ /* Allow DDI debug ioctl on sbpcd driver */ /* Allow setting up serial ports */ /* Allow sending raw qic-117 commands */ /* Allow enabling/disabling tagged queuing on SCSI controllers and sending arbitrary SCSI commands */ /* Allow setting encryption key on loopback filesystem */ /* Allow setting zone reclaim policy */ #define CAP_SYS_ADMIN 21 /* Allow use of reboot() */ #define CAP_SYS_BOOT 22 /* Allow raising priority and setting priority on other (different UID) processes */ /* Allow use of FIFO and round-robin (realtime) scheduling on own processes and setting the scheduling algorithm used by another process. */ /* Allow setting cpu affinity on other processes */ #define CAP_SYS_NICE 23 /* Override resource limits. Set resource limits. */ /* Override quota limits. */ /* Override reserved space on ext2 filesystem */ /* Modify data journaling mode on ext3 filesystem (uses journaling resources) */ /* NOTE: ext2 honors fsuid when checking for resource overrides, so you can override using fsuid too */ /* Override size restrictions on IPC message queues */ /* Allow more than 64hz interrupts from the real-time clock */ /* Override max number of consoles on console allocation */ /* Override max number of keymaps */ #define CAP_SYS_RESOURCE 24 /* Allow manipulation of system clock */ /* Allow irix_stime on mips */ /* Allow setting the real-time clock */ #define CAP_SYS_TIME 25 /* Allow configuration of tty devices */ /* Allow vhangup() of tty */ #define CAP_SYS_TTY_CONFIG 26 /* Allow the privileged aspects of mknod() */ #define CAP_MKNOD 27 /* Allow taking of leases on files */ #define CAP_LEASE 28 #define CAP_AUDIT_WRITE 29 #define CAP_AUDIT_CONTROL 30 #define CAP_SETFCAP 31 /* Override MAC access. The base kernel enforces no MAC policy. An LSM may enforce a MAC policy, and if it does and it chooses to implement capability based overrides of that policy, this is the capability it should use to do so. */ #define CAP_MAC_OVERRIDE 32 /* Allow MAC configuration or state changes. The base kernel requires no MAC configuration. An LSM may enforce a MAC policy, and if it does and it chooses to implement capability based checks on modifications to that policy or the data required to maintain it, this is the capability it should use to do so. */ #define CAP_MAC_ADMIN 33 #define CAP_LAST_CAP CAP_MAC_ADMIN #define cap_valid(x) ((x) >= 0 && (x) <= CAP_LAST_CAP) /* * Bit location of each capability (used by user-space library and kernel) */ #define CAP_TO_INDEX(x) ((x) >> 5) /* 1 << 5 == bits in __u32 */ #define CAP_TO_MASK(x) (1 << ((x) & 31)) /* mask for indexed __u32 */ #endif /* !_LINUX_CAPABILITY_H */