Descriptions of capabilities defined in <linux/capability.h>
(Updated to 2.2.16)


chown
=====
In a system with the [_POSIX_CHOWN_RESTRICTED] option defined, this
overrides the restriction of changing file ownership and group
ownership.


dac_override  dac
============  ===
Override all DAC access, including ACL execute access if
[_POSIX_ACL] is defined. Excluding DAC access covered by
CAP_LINUX_IMMUTABLE.


dac_read_search  dacrs
===============  =====
Overrides all DAC restrictions regarding read and search on files
and directories, including ACL restrictions if [_POSIX_ACL] is
defined. Excluding DAC access covered by CAP_LINUX_IMMUTABLE.
Since kernel is buggy it doesn't even check this capability if
user is not an owner of file/directory. Should be fixed in 2.2.17
and 2.4.0 kernel version. Use 'dac_override' instead.


fowner
======
Overrides all restrictions about allowed operations on files, where
file owner ID must be equal to the user ID, except where CAP_FSETID
is applicable. It doesn't override MAC and DAC restrictions. 


fsetid
======
Overrides the following restrictions that the effective user ID
shall match the file owner ID when setting the S_ISUID and S_ISGID
bits on that file; that the effective group ID (or one of the
supplementary group IDs) shall match the file owner ID when setting
the S_ISGID bit on that file; that the S_ISUID and S_ISGID bits are
cleared on successful return from chown(2) (not implemented). 


fs_mask fs
======= ==
Used to decide between falling back on the old suser() or fsuser(). 


kill
====
Overrides the restriction that the real or effective user ID of a
process sending a signal must match the real or effective user ID
of the process receiving the signal. 



setgid
======
Allows setgid(2) manipulation 
Allows setgroups(2) 
Allows forged gids on socket credentials passing. 


setuid
======
Allows set*uid(2) manipulation (including fsuid). 
Allows forged pids on socket credentials passing. 


(Linux-specific capabilities)


setpcap
=======
Transfer any capability in your permitted set to any pid,
remove any capability in your permitted set from any pid 


linux_immutable immutable
=============== =========
Allow modification of S_IMMUTABLE and S_APPEND file attributes 


net_bind_service bind
================ ====
Allows binding to TCP/UDP sockets below 1024 


net_broadcast broadcast
============= =========
Allow broadcasting, listen to multicast 


net_admin netadmin net
========= ============
Allow interface configuration 
Allow administration of IP firewall, masquerading and accounting 
Allow setting debug option on sockets 
Allow modification of routing tables 
Allow setting arbitrary process / process group ownership on
 sockets 
Allow binding to any address for transparent proxying 
Allow setting TOS (type of service) 
Allow setting promiscuous mode 
Allow clearing driver statistics 
Allow multicasting 
Allow read/write of device-specific registers 


net_raw raw
======= ===
Allow use of RAW sockets 
Allow use of PACKET sockets 


ipc_lock
========
Allow locking of shared memory segments 
Allow mlock and mlockall (which doesn't really have anything to do
 with IPC) 


ipc_owner ipc
========= ===
Override IPC ownership checks 


sys_module module
========== ======
Insert and remove kernel modules 
Modify cap_bset


sys_rawio rawio
========= =====
Allow ioperm/iopl access 


sys_chroot chroot
========== ======
Allow use of chroot() 


sys_ptrace ptrace
========== ======
Allow ptrace() of any process 


sys_pacct pacct
========= =====
Allow configuration of process accounting 


sys_admin admin
========= =====
Allow configuration of the secure attention key 
Allow administration of the random device 
Allow device administration (mknod)
Allow examination and configuration of disk quotas 
Allow configuring the kernel's syslog (printk behaviour) 
Allow setting the domainname 
Allow setting the hostname 
Allow calling bdflush() 
Allow mount() and umount(), setting up new smb connection 
Allow some autofs root ioctls 
Allow nfsservctl 
Allow VM86_REQUEST_IRQ 
Allow to read/write pci config on alpha 
Allow irix_prctl on mips (setstacksize) 
Allow flushing all cache on m68k (sys_cacheflush) 
Allow removing semaphores 
Used instead of CAP_CHOWN to "chown" IPC message queues, semaphores
 and shared memory 
Allow locking/unlocking of shared memory segment 
Allow turning swap on/off 
Allow forged pids on socket credentials passing 
Allow setting readahead and flushing buffers on block devices 
Allow setting geometry in floppy driver 
Allow turning DMA on/off in xd driver 
Allow administration of md devices (mostly the above, but some
 extra ioctls) 
Allow tuning the ide driver 
Allow access to the nvram device 
Allow administration of apm_bios, serial and bttv (TV) device 
Allow manufacturer commands in isdn CAPI support driver 
Allow reading non-standardized portions of pci configuration space 
Allow DDI debug ioctl on sbpcd driver 
Allow setting up serial ports 
Allow sending raw qic-117 commands 
Allow enabling/disabling tagged queuing on SCSI controllers and sending
 arbitrary SCSI commands 
Allow setting encryption key on loopback filesystem 


sys_boot boot
======== ====
Allow use of reboot() 


sys_nice nice
======== ====
Allow raising priority and setting priority on other (different
UID) processes 
Allow use of FIFO and round-robin (realtime) scheduling on own
processes and setting the scheduling algorithm used by another
process. 


sys_resource resource
============ ========
Override resource limits. Set resource limits. 
Override quota limits. 
Override reserved space on ext2 filesystem 
NOTE: ext2 honors fsuid when checking for resource overrides, so 
      you can override using fsuid too 
Override size restrictions on IPC message queues 
Allow more than 64hz interrupts from the real-time clock 
Override max number of consoles on console allocation 
Override max number of keymaps 


sys_time time
======== ====
Allow manipulation of system clock 
Allow irix_stime on mips
Allow setting the real-time clock


sys_tty_config ttyconfig
============== =========
Allow configuration of tty devices
Allow vhangup() of tty
