98 lines
7.7 KiB
Plaintext
98 lines
7.7 KiB
Plaintext
-cap='all= CAP_MAC_READ,CAP_DAC_READ_SEARCH+ip CAP_PRIV_PORT,CAP_MAC_MLD,CAP_MAC_RELABEL_SUBJ,CAP_DAC_WRITE+p CAP_MAC_RELABEL_OPEN,CAP_FOWNER,CAP_MAC_DOWNGRADE,CAP_MAC_UPGRADE,CAP_MAC_WRITE,CAP_DEVICE_MGT,CAP_DAC_EXECUTE+i' sbin/chlabel
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p' usr/bin/lp
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p CAP_MAC_READ,CAP_MAC_WRITE,CAP_DAC_WRITE+i' usr/bin/cancel
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p' usr/bin/disable
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p' usr/bin/enable
|
|
-cap='all= CAP_SETUID,CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p CAP_MAC_READ,CAP_DAC_READ_SEARCH+i' usr/bin/lpstat
|
|
-cap='all= CAP_SETUID+p CAP_AUDIT_CONTROL+i' usr/bin/satd
|
|
-cap='all= CAP_AUDIT_CONTROL+i' usr/bin/sat_select
|
|
-cap='all= CAP_AUDIT_WRITE,CAP_DAC_WRITE,CAP_MAC_RELABEL_SUBJ+ep' usr/bin/passwd
|
|
-cap='all=ei CAP_CHOWN,CAP_AUDIT_CONTROL+p' usr/bin/at
|
|
-cap='all= CAP_SETGID,CAP_SETUID,CAP_AUDIT_CONTROL,CAP_AUDIT_WRITE,CAP_MAC_RELABEL_OPEN,CAP_MAC_RELABEL_SUBJ,CAP_MAC_MLD,CAP_MAC_READ+ie' usr/etc/cron
|
|
-cap='all=ei CAP_PRIV_PORT+p' usr/bsd/rlogin
|
|
-cap='all=ei CAP_PRIV_PORT+p' usr/bsd/rsh
|
|
-cap='all=ei CAP_PRIV_PORT+p' usr/bsd/rcp
|
|
-cap='all= CAP_PRIV_PORT+p' usr/bsd/ordist
|
|
-cap='all= CAP_SETGID,CAP_SETUID,CAP_AUDIT_WRITE,CAP_PRIV_PORT,CAP_SETPCAP+i' usr/etc/rshd
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD+p CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/etc/portmap
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD+p CAP_SETUID,CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/etc/ypbind
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD+p CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/etc/ypserv
|
|
-cap='all= CAP_DAC_WRITE,CAP_FOWNER,CAP_SETPCAP,CAP_SETGID,CAP_SETUID,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_SUBJ,CAP_MAC_WRITE,CAP_MAC_UPGRADE,CAP_AUDIT_CONTROL,CAP_AUDIT_WRITE,CAP_PRIV_PORT,CAP_CHROOT+p' usr/lib/iaf/scheme
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p' usr/lib/accept
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p CAP_SETUID,CAP_SETGID+i' usr/lib/lpadmin
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p' usr/lib/lpmove
|
|
-cap='all= CAP_SETGID,CAP_SETUID,CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE,CAP_PRIV_PORT+p' usr/lib/lpsched
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p' usr/lib/lpshut
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p' usr/lib/reject
|
|
-cap='all= CAP_SCHED_MGT,CAP_DAC_READ_SEARCH,CAP_CHROOT,CAP_CHOWN,CAP_SETGID,CAP_SETUID,CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD,CAP_MAC_READ,CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE,CAP_FOWNER,CAP_DEVICE_MGT,CAP_NETWORK_MGT+p CAP_PRIV_PORT+i' usr/lib/sendmail
|
|
-cap='all= CAP_MOUNT_MGT+p' usr/sbin/havenfs
|
|
-cap='all= CAP_DAC_WRITE,CAP_FOWNER,CAP_MAC_RELABEL_OPEN,CAP_MAC_WRITE,CAP_DEVICE_MGT+ep' usr/sbin/mkpts
|
|
-cap='all= CAP_DAC_WRITE,CAP_FOWNER,CAP_DEVICE_MGT+p' sbin/getty
|
|
-cap='all= CAP_STREAMS_MGT+p' sbin/lfmt
|
|
-cap='all= CAP_SCHED_MGT,CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE+p CAP_PRIV_PORT,CAP_MOUNT_MGT+i' usr/etc/automount
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE,CAP_MAC_WRITE+p CAP_PRIV_PORT,CAP_MOUNT_MGT,CAP_MAC_READ,CAP_DAC_READ_SEARCH+i' sbin/mount
|
|
-cap='all= CAP_MAC_RELABEL_SUBJ,CAP_AUDIT_WRITE,CAP_MAC_WRITE+p CAP_PRIV_PORT,CAP_MOUNT_MGT,CAP_MAC_READ,CAP_DAC_READ_SEARCH+i' sbin/umount
|
|
-cap='all= CAP_FOWNER+p CAP_MAC_READ+i' sbin/ps
|
|
-cap='all= CAP_DAC_READ_SEARCH,CAP_DAC_WRITE,CAP_SETPCAP,CAP_SETGID,CAP_SETUID,CAP_MAC_READ,CAP_MAC_WRITE,CAP_MAC_RELABEL_SUBJ,CAP_MAC_MLD,CAP_AUDIT_WRITE,CAP_PRIV_PORT+p CAP_AUDIT_CONTROL+i' sbin/su
|
|
-cap='all= CAP_SETPCAP,CAP_MAC_READ,CAP_MAC_RELABEL_SUBJ,CAP_MAC_MLD,CAP_AUDIT_WRITE+p' sbin/suattr
|
|
-cap='all=epi' sbin/sulogin
|
|
-cap='all= CAP_KILL,CAP_MAC_READ,CAP_MAC_WRITE,CAP_SHUTDOWN+i' sbin/killall
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/rhost
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/iflabel
|
|
-cap='all= CAP_NETWORK_MGT,CAP_DEVICE_MGT+i' usr/etc/ifconfig
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/ifuid
|
|
-cap='all= CAP_MOUNT_MGT,CAP_MAC_READ+i' usr/etc/exportfs
|
|
-cap='all=ie CAP_DAC_READ_SEARCH,CAP_DAC_WRITE,CAP_FOWNER,CAP_STREAMS_MGT,CAP_SCHED_MGT,CAP_MAC_RELABEL_OPEN,CAP_DEVICE_MGT,CAP_MAC_WRITE+p' usr/sbin/xwsh
|
|
-cap='all= CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/etc/smtd
|
|
-cap='all= CAP_PRIV_PORT,CAP_NETWORK_MGT+i' usr/etc/routed
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/route
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD,CAP_CHROOT,CAP_DAC_WRITE,CAP_MAC_READ,CAP_MAC_WRITE+p CAP_NETWORK_MGT+i' usr/etc/rpc.lockd
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD+p CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/etc/rpc.passwd
|
|
-cap='all= CAP_AUDIT_WRITE,CAP_SETUID,CAP_SETGID,CAP_MAC_RELABEL_SUBJ,CAP_SETPCAP+p CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/etc/inetd
|
|
-cap='all= CAP_SYSINFO_MGT+i' usr/bsd/hostname
|
|
-cap='all= CAP_SYSINFO_MGT+i' usr/bin/domainname
|
|
-cap='all= CAP_SYSINFO_MGT+i' usr/bsd/hostid
|
|
-cap='all= CAP_SHUTDOWN+i' sbin/uadmin
|
|
-cap='all= CAP_SWAP_MGT+i' sbin/swap
|
|
-cap='all= CAP_CHROOT,CAP_DAC_READ_SEARCH,CAP_DAC_WRITE,CAP_MAC_WRITE,CAP_MAC_READ,CAP_FOWNER+p CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/etc/nfsd
|
|
-cap='all= CAP_PRIV_PORT+i' usr/etc/rarpd
|
|
-cap='all= CAP_PRIV_PORT+i' usr/sbin/showmount
|
|
-cap='all= CAP_PRIV_PORT+i' usr/etc/rpcinfo
|
|
-cap='all= CAP_MOUNT_MGT+i' usr/etc/biod
|
|
-cap='all= CAP_PRIV_PORT+i' usr/etc/spray
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/arp
|
|
-cap='all= CAP_NETWORK_MGT,CAP_SCHED_MGT+p' usr/etc/ping
|
|
-cap='all= CAP_SYSINFO_MGT+i' usr/sbin/idbg
|
|
-cap='all= CAP_TIME_MGT,CAP_SCHED_MGT+i' usr/sbin/mpadmin
|
|
-cap='all= CAP_SYSINFO_MGT+i' sbin/nvram
|
|
-cap='all= CAP_SYSINFO_MGT+i' usr/sbin/systune
|
|
-cap='all=ie CAP_SETUID+p' usr/bin/newproj
|
|
-cap='all= CAP_DAC_WRITE,CAP_MAC_WRITE,CAP_PRIV_PORT,CAP_NETWORK_MGT+i' usr/etc/syslogd
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD,CAP_MAC_READ+p CAP_NETWORK_MGT,CAP_MOUNT_MGT+i' usr/etc/rpc.mountd
|
|
-cap='all= CAP_DAC_READ_SEARCH,CAP_DAC_WRITE,CAP_AUDIT_WRITE,CAP_DEVICE_MGT,CAP_FOWNER,CAP_MAC_RELABEL_OPEN+i' usr/etc/telnetd
|
|
-cap='all= CAP_DAC_READ_SEARCH,CAP_DAC_WRITE,CAP_AUDIT_WRITE,CAP_DEVICE_MGT,CAP_FOWNER,CAP_MAC_RELABEL_OPEN+i' usr/etc/rlogind
|
|
-cap='all= CAP_SETUID,CAP_SETGID,CAP_SETPCAP+i' usr/etc/rexecd
|
|
-cap='all= CAP_DAC_WRITE,CAP_AUDIT_WRITE,CAP_SETUID,CAP_SETGID,CAP_CHROOT,CAP_PRIV_PORT+i' usr/etc/ftpd
|
|
-cap='all= CAP_QUOTA_MGT+i' usr/etc/rpc.rquotad
|
|
-cap='all= CAP_DAC_WRITE,CAP_MAC_WRITE+i' sbin/wall
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/bootp
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD+p CAP_NETWORK_MGT+i' usr/etc/rpc.statd
|
|
-cap='all= CAP_PRIV_PORT,CAP_NETWORK_MGT+i' usr/etc/satmpd
|
|
-cap='all= CAP_TIME_MGT,CAP_SCHED_MGT,CAP_PRIV_PORT,CAP_NETWORK_MGT+i' usr/etc/timed
|
|
-cap='all= CAP_MAC_WRITE+i' usr/etc/savecore
|
|
-cap='all= CAP_XTCB,CAP_DAC_WRITE+ep' usr/bin/X11/4Dwm
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD,CAP_NETWORK_MGT,CAP_PRIV_PORT+i' usr/sbin/named
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD,CAP_NETWORK_MGT+i' usr/sbin/named-xfer
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/mrouted
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/mtrace
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/rsvpd
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/rsvpeep
|
|
-cap='all= CAP_PRIV_PORT,CAP_NETWORK_MGT+i' usr/etc/rwhod
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/epdump
|
|
-cap='all= CAP_NETWORK_MGT+i' usr/etc/epfirm
|
|
-cap='all= CAP_MOUNT_MGT,CAP_PRIV_PORT,CAP_AUDIT_WRITE,CAP_SCHED_MGT,CAP_MAC_READ+i' usr/etc/autofs
|
|
-cap='all= CAP_MAC_UPGRADE,CAP_MAC_DOWNGRADE,CAP_MAC_RELABEL_OPEN,CAP_MAC_MLD,CAP_MOUNT_MGT,CAP_NETWORK_MGT,CAP_PRIV_PORT,CAP_MAC_WRITE+i' usr/etc/nsd
|
|
-cap='all= CAP_PRIV_PORT,CAP_MOUNT_MGT,CAP_MAC_WRITE+i' sbin/nsmount
|
|
-cap='all= CAP_SETUID,CAP_CHOWN+p' usr/bin/mail
|
|
-cap='all=ie CAP_FOWNER,CAP_MAC_RELABEL_OPEN,CAP_DAC_READ_SEARCH,CAP_DAC_WRITE,CAP_STREAMS_MGT,CAP_SETGID+p' usr/bin/X11/xterm
|