Privilege catalog

The per-privilege catalogue — every name, its LUID bit position, and what it does — is in the Peios Kernel TRM §3.4.2, "Catalogue". It is not duplicated here.

The conceptual treatment is Privileges, and the four-category model is Categories.

Five privileges influence an access check #

Only five can contribute bits to a granted mask, and therefore only five can appear in a privilege-use event:

  • SeSecurityPrivilege
  • SeTakeOwnershipPrivilege
  • SeBackupPrivilege
  • SeRestorePrivilege
  • SeRelabelPrivilege

Any other bit fails the audit encoder closed rather than emitting an unnamed privilege. See the Events Index §3.3.

Two are enforced but not nameable #

SeTakeOwnershipPrivilege and SeRelabelPrivilege are enforced by KACS but absent from the published privilege table, so they cannot be named in a service's RequiredPrivileges. A service needing either declares nothing and takes its source token's defaults, or fails to start if it tries to name one.

That asymmetry is peinit's, not the kernel's — see the peinit TRM §4.5.

Edit this page