Trusted Solaris Developer's Guide
    
A
 
 abbreviations in names ( Index Term Link )
 
 access
  checks
   executing a file ( Index Term Link )
   IPC files ( Index Term Link )
   mapped memory ( Index Term Link )
   MLDs ( Index Term Link )
   network ( Index Term Link ) ( Index Term Link )
   opening a file ( Index Term Link )
   pipes ( Index Term Link ) ( Index Term Link )
   process tracing ( Index Term Link )
   processes ( Index Term Link )
   PTYs ( Index Term Link )
   signals ( Index Term Link )
   SLDs ( Index Term Link )
   sockets ( Index Term Link )
   System V IPC ( Index Term Link ) ( Index Term Link )
   TLI ( Index Term Link )
   writing to a file ( Index Term Link )
   X Window System ( Index Term Link )
  discretionary operations ( Index Term Link )
  file labels ( Index Term Link )
  file privileges ( Index Term Link )
  file systems
   code examples ( Index Term Link )
   privileges ( Index Term Link )
   security policy ( Index Term Link )
  guidelines for labels ( Index Term Link )
  mandatory operations ( Index Term Link )
  multilevel port connections ( Index Term Link )
  protection ( Index Term Link )
 
 accreditation ranges
  checking ( Index Term Link ) ( Index Term Link )
  networks ( Index Term Link )
  structures ( Index Term Link )
 
 ACLs, information on ( Index Term Link )
 
 actions
  assigning inheritable privileges ( Index Term Link )
  creating ( Index Term Link )
 
 ADMIN_HIGH label
  defined ( Index Term Link )
  initialize to ( Index Term Link )
  running applications ( Index Term Link )
 
 ADMIN_LOW label
  defined ( Index Term Link )
  initialize to ( Index Term Link )
  running applications ( Index Term Link )
 
 adorned pathnames
  described ( Index Term Link )
  translating ( Index Term Link )
 
 adornfc routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 algorithms, process privileges ( Index Term Link )
 
 allowed privileges
  defined ( Index Term Link )
  on file systems ( Index Term Link )
  set to none during write ( Index Term Link )
  turning off ( Index Term Link )
 
 APIs
  declarations ( Index Term Link )
  list of types ( Index Term Link ) ( Index Term Link )
  security policy on man pages ( Index Term Link )
 
 application auditing
  API declarations ( Index Term Link )
  argument information ( Index Term Link )
  audit trail ( Index Term Link )
  command line arguments ( Index Term Link )
  control commands ( Index Term Link )
  creating audit records ( Index Term Link )
  creating parallel audit records ( Index Term Link )
  described ( Index Term Link )
  event definition numbers ( Index Term Link )
  invalid call ( Index Term Link )
  IPC identifier ( Index Term Link )
  preselection mask ( Index Term Link )
  privilege sets ( Index Term Link )
  privileged tasks ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
  queueing record information ( Index Term Link )
  return token ( Index Term Link )
  return values ( Index Term Link )
  save area ( Index Term Link )
  sensitivity label ( Index Term Link )
  server area ( Index Term Link )
  subject token ( Index Term Link )
  terminator command ( Index Term Link )
  token commands ( Index Term Link )
  valid call ( Index Term Link )
 
 applications
  administrative ( Index Term Link )
  integration ( Index Term Link )
  MLDs ( Index Term Link )
  testing and debugging ( Index Term Link )
  user ( Index Term Link )
 
 atoms, predefined ( Index Term Link )
 
 audit_class file
  application auditing ( Index Term Link )
  creating class ( Index Term Link )
 
 audit classes
  process preselection mask ( Index Term Link )
  third-party ( Index Term Link )
 
 audit_control file
  application auditing ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 audit_event file
  application auditing ( Index Term Link )
  creating event ( Index Term Link )
 
 audit events
  third-party ( Index Term Link )
  viewing ( Index Term Link )
 
 audit records
  creating in an application ( Index Term Link )
  minimum ( Index Term Link )
 
 audit tokens
  return token ( Index Term Link )
  subject token structure ( Index Term Link )
 
 auditid field ( Index Term Link )
 
 auditing
  preselection mask
   classes on file systems ( Index Term Link )
  public files and directories ( Index Term Link )
 
 auditwrite routine
  code examples ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
  invalid call ( Index Term Link )
  valid call ( Index Term Link )
 
 authorizations
  and privileges ( Index Term Link ) ( Index Term Link )
  Label builder ( Index Term Link )
  when to check ( Index Term Link )
 
 AW_ARG token command ( Index Term Link )
 
 AW_DEFAULTRD token command ( Index Term Link )
 
 AW_DISCARDRD token command ( Index Term Link )
 
 AW_END terminator command ( Index Term Link )
 
 AW_EVENT token command ( Index Term Link )
 
 AW_EXEC_ARGS token command ( Index Term Link )
 
 AW_FLUSH token command ( Index Term Link )
 
 AW_GETRD token command ( Index Term Link )
 
 AW_IPC token command ( Index Term Link )
 
 AW_NOPRESELECT token command ( Index Term Link )
 
 AW_NOQUEUE token command ( Index Term Link )
 
 AW_NOSAVE token command ( Index Term Link )
 
 AW_NOSERVER token command ( Index Term Link )
 
 AW_PATH token command ( Index Term Link )
 
 AW_PRESELECT token command ( Index Term Link )
 
 AW_PRIVILEGE token command ( Index Term Link )
 
 AW_QUEUE token command ( Index Term Link )
 
 AW_RETURN token command ( Index Term Link ) ( Index Term Link )
 
 AW_SAVERD token command ( Index Term Link )
 
 AW_SERVER token command ( Index Term Link )
 
 AW_SLABEL token command ( Index Term Link ) ( Index Term Link )
 
 AW_SUBJECT token command ( Index Term Link )
 
 AW_TEXT token command ( Index Term Link )
 
 AW_USERD token command ( Index Term Link )
    
B
 
 banner_fields structure ( Index Term Link )
 
 bclabel_t type ( Index Term Link )
 
 bclear_t type ( Index Term Link )
 
 bclearhigh routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bclearlow routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bcleartoh_r routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 bcleartoh routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bcleartos routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bclearundef routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bclearvalid routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bclhigh routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bcllow routine, declaration ( Index Term Link )
 
 bcltobanner routine
  code example ( Index Term Link )
  declarationBinary ( Index Term Link )
 
 bcltoh_r routine, declaration ( Index Term Link )
 
 bcltoh routine, declaration ( Index Term Link )
 
 bcltos routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 bcltosl routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bclundef routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bilvalid routine, declaration ( Index Term Link )
 
 binary
  to hexadecimal ( Index Term Link ) ( Index Term Link )
 
 bldominates routine
  code example ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 blequal routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 blevel_t type ( Index Term Link )
 
 blinrange routine
  code example ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 blinset routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 blmaximum routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 blminimum routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 blstrictdom routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 bltocolor routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bltocolor_t routine, declaration ( Index Term Link )
 
 bltype routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 brange_t type ( Index Term Link )
 
 bslabel_t type ( Index Term Link ) ( Index Term Link )
 
 bslevel_t type ( Index Term Link )
 
 bslhigh routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 bsllow routine, declaration ( Index Term Link )
 
 bsltoh_r routine, declaration ( Index Term Link )
 
 bsltoh routine, declaration ( Index Term Link )
 
 bsltos routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 bslundef routine, declaration ( Index Term Link )
 
 bslvalid routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 builders, GUI
  API declarations ( Index Term Link )
  interfaces described ( Index Term Link )
    
C
 
 caveats field ( Index Term Link )
 
 caveats_len field ( Index Term Link ) ( Index Term Link )
 
 channels field ( Index Term Link )
 
 channels_len field ( Index Term Link ) ( Index Term Link )
 
 chkauth routine, code example ( Index Term Link )
 
 cl_tsol_incoming_attrsp field ( Index Term Link )
 
 cl_tsol_outgoing_attrsp field ( Index Term Link )
 
 clabel_len field ( Index Term Link )
 
 classifications
  clearance component ( Index Term Link )
  dominate ( Index Term Link ) ( Index Term Link )
  equal ( Index Term Link ) ( Index Term Link )
  SL component ( Index Term Link )
  strictly dominate ( Index Term Link ) ( Index Term Link )
 
 clear_len field ( Index Term Link )
 
 clearances
  checking clearances ( Index Term Link )
  session ( Index Term Link )
  user ( Index Term Link )
 
 CLIENT structure ( Index Term Link )
 
 CMW labels
  API declarations ( Index Term Link )
  components ( Index Term Link )
  defined ( Index Term Link )
  file systems ( Index Term Link )
  objects ( Index Term Link )
  processes ( Index Term Link )
 
 code examples
  accreditation range, checking ( Index Term Link )
  auditing
   adding a sensitivity label ( Index Term Link )
   creating audit records ( Index Term Link )
   creating mimimum record ( Index Term Link )
   creating parallel records ( Index Term Link )
   handling return values ( Index Term Link )
   invalid call ( Index Term Link )
   preliminary setup ( Index Term Link ) ( Index Term Link )
   queueing information ( Index Term Link )
   using preselection mask ( Index Term Link )
   using save area ( Index Term Link )
   using server area ( Index Term Link )
   valid call ( Index Term Link )
   writing arguments ( Index Term Link )
   writing command line arguments ( Index Term Link )
   writing IPC identifier ( Index Term Link )
   writing privilege sets ( Index Term Link )
  authorizations
   and privileges ( Index Term Link )
   checking ( Index Term Link )
  checking labels ( Index Term Link )
  clearances
   checking before file access ( Index Term Link )
   checking if valid ( Index Term Link )
   checking prior to access ( Index Term Link )
   checking type ( Index Term Link )
   finding lower bound ( Index Term Link )
   finding upper bound ( Index Term Link )
   getting ( Index Term Link )
   initializing to ADMIN_LOW ( Index Term Link )
   initializing to undefined ( Index Term Link )
   setting ( Index Term Link )
   testing relationships ( Index Term Link )
   translating ( Index Term Link ) ( Index Term Link )
   translating and clipping ( Index Term Link )
   translating to hex ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  CMW labels
   getting on file system ( Index Term Link )
   getting on window ( Index Term Link )
   getting pointers to portions ( Index Term Link )
   getting process label ( Index Term Link ) ( Index Term Link )
   getting SL ( Index Term Link )
   setting on file system ( Index Term Link )
   setting on window ( Index Term Link )
   setting process label ( Index Term Link )
   translating to binary ( Index Term Link )
   translating to hex ( Index Term Link )
   translating to text ( Index Term Link )
  databases
   getting user entries ( Index Term Link )
  file systems
   accessing ( Index Term Link )
   executing ( Index Term Link )
   getting attribute flags ( Index Term Link )
   getting attributes ( Index Term Link )
   getting attributes (inode) ( Index Term Link )
   getting CMW label ( Index Term Link )
   getting label range ( Index Term Link )
   opening a file ( Index Term Link )
   setting CMW label ( Index Term Link )
   writing to a file ( Index Term Link )
  Label builder ( Index Term Link )
  label_encodings file
   getting character-coded color names ( Index Term Link )
   getting information on ( Index Term Link )
   retrieving version string ( Index Term Link )
   translating printer banner ( Index Term Link )
  labels
   checking accreditation ranges ( Index Term Link )
   checking before file access ( Index Term Link )
   checking if valid ( Index Term Link )
   creating ( Index Term Link )
   finding lower bound ( Index Term Link )
   finding upper bound ( Index Term Link )
   getting file system range ( Index Term Link )
   initializing ( Index Term Link )
   testing relationships ( Index Term Link )
   translating to binary ( Index Term Link )
   translating to text ( Index Term Link )
   translating with font list ( Index Term Link )
  MLDs
   creating a file ( Index Term Link )
   getting adorned name ( Index Term Link )
   getting MLD name ( Index Term Link )
   getting real path ( Index Term Link )
   getting security attribute flags ( Index Term Link )
   getting security attributes ( Index Term Link )
   getting SLD name ( Index Term Link )
   getting working directory ( Index Term Link )
   opening a file ( Index Term Link )
  printer banner, translating ( Index Term Link )
  privilege sets
   bracketing effective set ( Index Term Link )
   checking allowed set ( Index Term Link )
   checking permitted set ( Index Term Link )
   checking saved set ( Index Term Link )
   clearing allowed set ( Index Term Link )
   clearing effective set ( Index Term Link )
   clearing inheritable set ( Index Term Link )
   exec'ing a process ( Index Term Link )
   forking a process ( Index Term Link )
   removing permitted privs ( Index Term Link )
   setting forced set on file ( Index Term Link )
   setting inheritable set ( Index Term Link )
   translating set to string ( Index Term Link )
  privileges
   after checking authorizations ( Index Term Link )
   and authorizations ( Index Term Link )
   asserting privileges in sets ( Index Term Link )
   getting description text ( Index Term Link )
   setting user ID ( Index Term Link )
   translating ID to string ( Index Term Link )
   translating string to ID ( Index Term Link )
   when to use ( Index Term Link )
  processes, getting attribute flags ( Index Term Link )
  RPC
   example application ( Index Term Link ) ( Index Term Link )
   header file ( Index Term Link )
   running the application ( Index Term Link )
  security configuration variables ( Index Term Link )
  SLDs
   creating a file ( Index Term Link )
   getting name ( Index Term Link )
   getting security attributes ( Index Term Link )
   getting SLD name ( Index Term Link )
   getting working directory ( Index Term Link )
   opening a file ( Index Term Link )
  System V IPC
   using shared memory labels ( Index Term Link )
  TSIX
   allocating space ( Index Term Link )
   clearing attributes ( Index Term Link )
   client application ( Index Term Link ) ( Index Term Link )
   comparing attributes ( Index Term Link )
   copying attribute structures ( Index Term Link )
   creating attribute masks ( Index Term Link )
   duplicating structures ( Index Term Link )
   examining the last attribute ( Index Term Link )
   example application ( Index Term Link ) ( Index Term Link )
   freeing allocated space ( Index Term Link )
   getting attribute size ( Index Term Link )
   getting attributes ( Index Term Link )
   getting endpoint defaults ( Index Term Link )
   getting endpoint mask ( Index Term Link )
   peeking at attributes ( Index Term Link )
   receiving attributes ( Index Term Link )
   receiving new attributess ( Index Term Link )
   replying to request ( Index Term Link )
   sending attributes ( Index Term Link )
   server application ( Index Term Link )
   setting attributes ( Index Term Link )
   setting endpoint defaults ( Index Term Link )
   setting enpoint mask ( Index Term Link )
   using multilevel ports ( Index Term Link )
  vfstab_adjunct file ( Index Term Link )
  X Window System
   getting window attributes ( Index Term Link )
   getting window CMW label ( Index Term Link )
   getting window userID ( Index Term Link )
   getting workstation owner ( Index Term Link )
   Motif application ( Index Term Link )
   setting window CMW label ( Index Term Link )
   translating with font list ( Index Term Link )
 
 command arguments
  control ( Index Term Link )
  terminator ( Index Term Link )
  token ( Index Term Link )
 
 communication endpoints
  access checks ( Index Term Link ) ( Index Term Link )
  connections described ( Index Term Link )
  objects ( Index Term Link )
  security attributes (TSIX) ( Index Term Link )
 
 compartments
  clearance component ( Index Term Link )
  dominate ( Index Term Link ) ( Index Term Link )
  equal ( Index Term Link ) ( Index Term Link )
  SL component ( Index Term Link )
  strictly dominate ( Index Term Link ) ( Index Term Link )
 
 compile
  auditing libraries ( Index Term Link )
  clearance libraries ( Index Term Link )
  Label builder libraries ( Index Term Link )
  label libraries ( Index Term Link )
  MLD libraries ( Index Term Link )
  privilege libraries ( Index Term Link )
  profile database access libraries ( Index Term Link )
  RPC libraries ( Index Term Link )
  SLD libraries ( Index Term Link )
  System V IPC libraries ( Index Term Link )
  TSIX libraries ( Index Term Link )
  user database access libraries ( Index Term Link )
  X Window System libraries ( Index Term Link )
 
 config.privs file ( Index Term Link )
 
 connection requests
  security attributes ( Index Term Link )
  security policy ( Index Term Link )
 
 control commands ( Index Term Link )
 
 core files ( Index Term Link )
 
 covert channels ( Index Term Link )
    
D
 
 DAC
  accessing System V IPC objects ( Index Term Link )
  privilege bracketing ( Index Term Link )
  security policy ( Index Term Link )
 
 data types
  auditing ( Index Term Link )
  clearance APIs ( Index Term Link )
  label APIs ( Index Term Link )
  Label buider APIs ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  MLD APIs ( Index Term Link )
  privilege APIs ( Index Term Link )
  profile database access APIs ( Index Term Link )
  RPC APIs ( Index Term Link )
  SLD APIs ( Index Term Link )
  System V IPC APIs ( Index Term Link )
  TSIX APIs ( Index Term Link )
  user database access APIs ( Index Term Link )
  X Window System APIs ( Index Term Link )
 
 databases
  API declarations ( Index Term Link )
  authorizations ( Index Term Link )
  profile ( Index Term Link )
  user ( Index Term Link )
 
 debugging, applications ( Index Term Link )
 
 development environment privs ( Index Term Link )
 
 devices
  input device privileges ( Index Term Link )
  label ranges ( Index Term Link )
 
 DGA, privileges ( Index Term Link )
 
 diskless boot flag ( Index Term Link )
 
 dominate
  levels ( Index Term Link ) ( Index Term Link )
 
 downgrading labels
  guidelines ( Index Term Link )
  privileges needed ( Index Term Link )
  X Window System ( Index Term Link )
    
E
 
 effective privileges
  bracketing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  change UID, GUID, or SGUID ( Index Term Link )
  code example ( Index Term Link )
  defined ( Index Term Link )
  privilege to change IDs ( Index Term Link )
 
 equal
  levels ( Index Term Link ) ( Index Term Link )
 
 errors ( Index Term Link )
 
 exec system call
  inheritable privileges ( Index Term Link )
  privileges in new program ( Index Term Link )
 
 execution profiles, checking ( Index Term Link )
 
 extended operations ( Index Term Link )
    
F
 
 FAF_ALL flag ( Index Term Link )
 
 FAF_MLD flag ( Index Term Link )
 
 FAF_PUBLIC flag ( Index Term Link )
 
 FAF_SLD flag ( Index Term Link )
 
 features, operating system ( Index Term Link )
 
 fgetcmwfsrange system call, declaration ( Index Term Link )
 
 fgetcmwlabel system call, declaration ( Index Term Link )
 
 fgetfattrflag function, declaration ( Index Term Link )
 
 fgetfpriv system call, declaration ( Index Term Link )
 
 fgetfsattr system call, declaration ( Index Term Link ) ( Index Term Link )
 
 fgetmldadorn system call, declaration ( Index Term Link )
 
 fgetsldname system call
  creating SLDs ( Index Term Link )
  declaration ( Index Term Link )
 
 file_audit privilege ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 file_dac_execute privilege ( Index Term Link )
 
 file_dac_read privilege ( Index Term Link )
 
 file_dac_search privilege ( Index Term Link ) ( Index Term Link )
 
 file_dac_write privilege ( Index Term Link ) ( Index Term Link )
 
 file_downgrade_sl privilege ( Index Term Link ) ( Index Term Link )
 
 file_mac_read privilege ( Index Term Link ) ( Index Term Link )
 
 file_mac_search privilege ( Index Term Link )
 
 file_mac_write privilege ( Index Term Link )
 
 file_owner privilege ( Index Term Link ) ( Index Term Link )
 
 file_setfpriv privilege ( Index Term Link )
 
 file_setpriv privilege ( Index Term Link )
 
 file systems
  access privileges ( Index Term Link )
  accessing MLDs ( Index Term Link )
  accessing SLDs ( Index Term Link )
  ACL information ( Index Term Link )
  hide upgraded names ( Index Term Link )
  IPC bind to file ( Index Term Link )
  objects ( Index Term Link )
  polyinstantiated ( Index Term Link )
  privileges, defined ( Index Term Link )
  security policy ( Index Term Link ) ( Index Term Link )
 
 files
  allowed privileges ( Index Term Link )
  forced privileges ( Index Term Link )
  interpreted ( Index Term Link )
  label privileges ( Index Term Link )
  privilege sets ( Index Term Link )
  privileges for creating core files ( Index Term Link )
  when writing to executables ( Index Term Link )
 
 fonts
  font list translation ( Index Term Link )
  font path privileges ( Index Term Link )
 
 forced privileges
  clearing ( Index Term Link )
  defined ( Index Term Link )
  on file systems ( Index Term Link )
  set to none during write ( Index Term Link )
  when turning off allowed ( Index Term Link )
 
 fork system call
  CMW label values ( Index Term Link )
  guidelines for changing labels ( Index Term Link )
  inheritable privileges ( Index Term Link )
  privileges in child ( Index Term Link )
 
 FSA_ACL value ( Index Term Link )
 
 FSA_ACLCNT value ( Index Term Link )
 
 FSA_AFLAGS value ( Index Term Link )
 
 FSA_APRIV value ( Index Term Link )
 
 FSA_APSA value ( Index Term Link )
 
 FSA_APSACNT value ( Index Term Link )
 
 FSA_FPRIV value ( Index Term Link )
 
 FSA_LABEL value ( Index Term Link )
 
 FSA_LBLRNG value ( Index Term Link )
 
 FSA_MLDPFX value ( Index Term Link )
 
 fsetcmwlabel system call, declaration ( Index Term Link )
 
 fsetfattrflag system call, declaration ( Index Term Link )
 
 fsetfpriv system call, declaration ( Index Term Link )
    
G
 
 get_priv_text routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 getclearance system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 getcmwfsrange function, code example ( Index Term Link )
 
 getcmwfsrange system call, declaration ( Index Term Link )
 
 getcmwlabel system call
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 getcmwplabel system call
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 getcsl routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 getfattrflag system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 getfpriv command ( Index Term Link ) ( Index Term Link )
 
 getfpriv system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
  privileges needed ( Index Term Link )
 
 getfsattr system call
  code example ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 getlabel command ( Index Term Link )
 
 getmldadorn system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 getmsgqcmwlabel system call, declaration ( Index Term Link )
 
 getpattr system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 getppriv system call
  code example ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 getsemcmwlabel system call, declaration ( Index Term Link )
 
 getshmcmwlabel system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 getsldname system call
  code example ( Index Term Link ) ( Index Term Link )
  creating SLDs ( Index Term Link )
  declaration ( Index Term Link )
 
 getuserentbyname routine, code example ( Index Term Link )
 
 getvfsaent routine, code example ( Index Term Link )
 
 getvfsafile routine, code example ( Index Term Link )
 
 gid field ( Index Term Link )
 
 GIDs, privilege to change ( Index Term Link )
 
 GUIs
  CDE ( Index Term Link )
  Motif ( Index Term Link )
  Xlib ( Index Term Link )
  Xlib objects ( Index Term Link )
    
H
 
 h_alloc routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 h_free routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 header field ( Index Term Link )
 
 header files
  auditing APIs ( Index Term Link )
  clearance APIs ( Index Term Link )
  label APIs ( Index Term Link )
  Label builder APIs ( Index Term Link )
  locations, list of ( Index Term Link )
  MLD APIs ( Index Term Link )
  privilege APIs ( Index Term Link )
  profile database access APIs ( Index Term Link )
  RPC APIs ( Index Term Link )
  SLD APIs ( Index Term Link )
  System V IPC APIs ( Index Term Link )
  TSIX APIs ( Index Term Link )
  user database access APIs ( Index Term Link )
  X Window System APIs ( Index Term Link )
 
 header_len field ( Index Term Link ) ( Index Term Link )
 
 hexadecimal
  to binary ( Index Term Link ) ( Index Term Link )
 
 hide upgraded names ( Index Term Link )
 
 htobcl routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 htobclear routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 htobsl routine, declaration ( Index Term Link )
    
I
 
 iaddr field ( Index Term Link )
 
 ilabel field ( Index Term Link )
 
 ilabel_len field ( Index Term Link )
 
 inheritable privileges
  code example ( Index Term Link )
  defined ( Index Term Link )
 
 integrating an application ( Index Term Link )
 
 IPC
  communication endpoint objects ( Index Term Link )
  file binding ( Index Term Link )
  mechanisms described ( Index Term Link )
  multilevel port connections ( Index Term Link )
  network accreditation range ( Index Term Link )
  objects ( Index Term Link )
  polyinstantiated ports ( Index Term Link )
  port binding ( Index Term Link )
  privileges, defined ( Index Term Link )
  security attributes
   changing ( Index Term Link )
   contrast with Solaris ( Index Term Link )
   described ( Index Term Link )
  security policy ( Index Term Link ) ( Index Term Link )
  single-level port connections ( Index Term Link )
 
 ipc_dac_read privilege ( Index Term Link )
 
 ipc_dac_write privilege ( Index Term Link )
 
 ipc_mac_rad privilege ( Index Term Link )
 
 ipc_mac_read privilege ( Index Term Link ) ( Index Term Link )
 
 ipc_mac_write privilege ( Index Term Link )
 
 ipc_owner privilege ( Index Term Link ) ( Index Term Link )
    
L
 
 Label builder
  Cancel pushbutton ( Index Term Link )
  declarations ( Index Term Link )
  described ( Index Term Link )
  extended operations ( Index Term Link )
  functionality ( Index Term Link )
  Reset pushbutton ( Index Term Link )
  SL radio button ( Index Term Link )
 
 label clipping
  API declarations ( Index Term Link ) ( Index Term Link )
  translating with font list ( Index Term Link )
 
 label data types
  accreditation ranges ( Index Term Link )
  banner fields ( Index Term Link )
  CMW label structure ( Index Term Link )
  label information ( Index Term Link )
  levels ( Index Term Link )
  sensitivity labels ( Index Term Link )
  setting flags ( Index Term Link )
  SL ranges ( Index Term Link )
 
 label_encodings file
  API declarations ( Index Term Link )
  color names ( Index Term Link )
  information on ( Index Term Link )
  Label builder ( Index Term Link )
  label translation flag ( Index Term Link )
  Non-English ( Index Term Link )
  retrieving version string ( Index Term Link )
  valid clearances ( Index Term Link )
  valid labels ( Index Term Link )
  view flag ( Index Term Link )
 
 label_info structure ( Index Term Link )
 
 label ranges
  accreditation ( Index Term Link ) ( Index Term Link )
  assigning ( Index Term Link )
  checking ( Index Term Link )
  described ( Index Term Link )
  file systems
   API declarations ( Index Term Link )
   data structure ( Index Term Link )
 
 labelinfo routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 labels
  accreditation ranges ( Index Term Link )
  acquiring ( Index Term Link )
  administrative ( Index Term Link )
  adorned pathnames ( Index Term Link )
  API declarations ( Index Term Link )
   CMW labels ( Index Term Link )
   entire ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   file systems ( Index Term Link )
   label clipping with font list ( Index Term Link )
   label_encodings file ( Index Term Link )
   label types ( Index Term Link )
   labels ( Index Term Link )
   levels ( Index Term Link )
   reentrant routines ( Index Term Link )
  changing on client ( Index Term Link )
  checking before file access ( Index Term Link )
  components ( Index Term Link )
  defined ( Index Term Link )
  dominate levels ( Index Term Link )
  equal levels ( Index Term Link )
  guidelines ( Index Term Link ) ( Index Term Link )
   downgrading labels ( Index Term Link )
   upgrading labels ( Index Term Link )
  in CMW label ( Index Term Link )
  Label builder ( Index Term Link )
  MAC checks ( Index Term Link )
  mandatory access ( Index Term Link )
  on file systems ( Index Term Link )
  privileged tasks ( Index Term Link )
  privileges
   changing process SL ( Index Term Link )
   downgrading labels ( Index Term Link )
   upgrading labels ( Index Term Link )
  purpose ( Index Term Link )
  reentrant routines ( Index Term Link ) ( Index Term Link )
  relationships ( Index Term Link )
  replying at equal SL ( Index Term Link )
  strictly dominate levels ( Index Term Link )
  System V IPC ( Index Term Link )
  translation flag ( Index Term Link )
  TSIX ( Index Term Link )
  undefined ( Index Term Link )
  user processes ( Index Term Link )
  valid ( Index Term Link )
  view ( Index Term Link )
  view flag ( Index Term Link )
 
 labelvers routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 LBUILD_CHECK_AR operation ( Index Term Link )
 
 LBUILD_LOWER_BOUND operation ( Index Term Link )
 
 LBUILD_MODE_CLR value ( Index Term Link )
 
 LBUILD_MODE_CMW value ( Index Term Link )
 
 LBUILD_MODE operation ( Index Term Link )
 
 LBUILD_MODE_SL value ( Index Term Link )
 
 LBUILD_SHOW operation ( Index Term Link )
 
 LBUILD_TITLE operation ( Index Term Link )
 
 LBUILD_UPPER_BOUND operation ( Index Term Link )
 
 LBUILD_USERFIELD operation ( Index Term Link )
 
 LBUILD_VALUE_CLR operation ( Index Term Link )
 
 LBUILD_VALUE_CMW operation ( Index Term Link )
 
 LBUILD_VALUE_SL operation ( Index Term Link )
 
 LBUILD_VIEW_EXTERNAL value ( Index Term Link )
 
 LBUILD_VIEW_INTERNAL value ( Index Term Link )
 
 LBUILD_VIEW operation ( Index Term Link )
 
 LBUILD_WORK_CMW operation ( Index Term Link )
 
 LBUILD_WORK_SL operation ( Index Term Link )
 
 LBUILD_WORKJ_CLR operation ( Index Term Link )
 
 LBUILD_X operation ( Index Term Link )
 
 LBUILD_Y operation ( Index Term Link )
 
 LD_LIBRARY_PATH ( Index Term Link )
 
 levels
  defined ( Index Term Link ) ( Index Term Link )
  relationship ( Index Term Link )
  relationships ( Index Term Link )
  upper and lower bounds ( Index Term Link ) ( Index Term Link )
 
 lgetcmwlabel system call, declaration ( Index Term Link )
 
 libraries, compile
  auditing APIs ( Index Term Link )
  clearance APIs ( Index Term Link )
  label APIs ( Index Term Link )
  Label builder APIs ( Index Term Link )
  MLD APIs ( Index Term Link )
  privilege APIs ( Index Term Link )
  profile database access APIs ( Index Term Link )
  RPC APIs ( Index Term Link )
  SLD APIs ( Index Term Link )
  System V IPC APIs ( Index Term Link )
  trusted shared libraries ( Index Term Link )
  TSIX APIs ( Index Term Link )
  user database access APIs ( Index Term Link )
  X Window System APIs ( Index Term Link )
 
 library routines
  API declarations ( Index Term Link )
  security policy on man pages ( Index Term Link )
 
 LONG_CLASSIFICATION flag ( Index Term Link )
 
 LONG_WORDS flag ( Index Term Link )
 
 lsetcmwlabel system call, declaration ( Index Term Link )
    
M
 
 MAC
  accessing System V IPC objects ( Index Term Link )
  clearance limits ( Index Term Link )
  guidelines for bypassing ( Index Term Link )
  privilege bracketing ( Index Term Link )
  security policy ( Index Term Link )
  SL limits ( Index Term Link ) ( Index Term Link )
 
 manual pages
  modified ( Index Term Link )
  security policy on ( Index Term Link )
 
 mapped memory, access checks ( Index Term Link )
 
 mappings
  multilevel ( Index Term Link )
  single-level ( Index Term Link )
 
 message queues
  API declarations ( Index Term Link ) ( Index Term Link )
 
 mldgetcwd routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 mldgetfattrflag system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 mldrealpath routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 mldrealpathl routine, declaration ( Index Term Link )
 
 MLDs
  accessing ( Index Term Link )
  adorned names ( Index Term Link )
  API declarations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  creating ( Index Term Link )
  described ( Index Term Link )
  information structure ( Index Term Link )
  prefix on file systems ( Index Term Link )
  privileged tasks ( Index Term Link )
  querying MLD flag ( Index Term Link )
  security attribute flags ( Index Term Link )
  security policy ( Index Term Link )
  structure ( Index Term Link )
  symbolic links ( Index Term Link )
  used by applications ( Index Term Link )
 
 mldsetfattrflag system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 mldstat system call
  code example ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 ModLabelData structure ( Index Term Link )
 
 Motif, described ( Index Term Link )
 
 Motif application
  described ( Index Term Link )
  Label builder widgets ( Index Term Link )
  online help ( Index Term Link )
  source code ( Index Term Link )
 
 msggetl system call, declaration ( Index Term Link )
 
 MT_SAFE ( Index Term Link ) ( Index Term Link )
 
 multilabel file systems ( Index Term Link )
 
 multilevel mappings ( Index Term Link )
 
 multilevel ports
  contrast to polyinstantiated ( Index Term Link )
  described ( Index Term Link ) ( Index Term Link )
  example application ( Index Term Link )
  replying at equal SL ( Index Term Link )
  RPC ( Index Term Link )
    
N
 
 names, abbreviations ( Index Term Link )
 
 net_downgrade_sl privilege ( Index Term Link )
 
 net_mac_read privilege ( Index Term Link )
 
 net_reply_equal privilege ( Index Term Link ) ( Index Term Link )
 
 net_setclr privilege ( Index Term Link )
 
 net_setid privilege ( Index Term Link )
 
 net_setpriv privilege ( Index Term Link )
 
 networks, security attributes ( Index Term Link )
 
 NEW_LABEL flag ( Index Term Link )
 
 NO_CLASSIFICATION flag ( Index Term Link )
 
 NO_CORRECTION flag ( Index Term Link )
    
O
 
 objects ( Index Term Link ) ( Index Term Link )
 
 Open Look Interface Toolkit (OLIT) ( Index Term Link )
 
 OpenWindows ( Index Term Link )
 
 operating system features ( Index Term Link )
 
 ouid field ( Index Term Link )
    
P
 
 packets
  location of security attributes ( Index Term Link )
  security attributes ( Index Term Link )
 
 PAF_DISKLESS_BOOT value ( Index Term Link )
 
 PAF_LABEL_VIEW value ( Index Term Link )
 
 PAF_LABEL_XLATE value ( Index Term Link )
 
 PAF_NO_TOKMAP value ( Index Term Link )
 
 PAF_PRINT_SYSTEM value ( Index Term Link )
 
 PAF_PRIV_DEBUG value ( Index Term Link )
 
 PAF_SELAGENT value ( Index Term Link )
 
 PAF_SELAGNT flag ( Index Term Link )
 
 PAF_TRUSTED_PATH value ( Index Term Link )
 
 pathnames
  adorned names ( Index Term Link )
  translation ( Index Term Link )
 
 permitted privileges
  checking ( Index Term Link )
  code example ( Index Term Link )
  defined ( Index Term Link )
 
 pfsh command
  determining privilege origination ( Index Term Link )
  inheriting privileges ( Index Term Link )
 
 pid field ( Index Term Link )
 
 pipes, access checks ( Index Term Link )
 
 polyinstantiation
  described ( Index Term Link )
  files and directories ( Index Term Link )
  network connections ( Index Term Link )
 
 ports, single-level ( Index Term Link )
 
 praudit command, audit trail ( Index Term Link )
 
 print server applications ( Index Term Link )
 
 printer banner page, label translation ( Index Term Link )
 
 printing flag ( Index Term Link )
 
 PRIV_ALLOWED value ( Index Term Link )
 
 PRIV_ASSERT macro
  and str_to_priv routine ( Index Term Link )
  described ( Index Term Link )
 
 PRIV_CLEAR macro ( Index Term Link )
 
 PRIV_EFFECTIVE value ( Index Term Link )
 
 PRIV_EMPTY macro ( Index Term Link )
 
 PRIV_EQUAL macro ( Index Term Link )
 
 PRIV_FILL macro ( Index Term Link )
 
 PRIV_FORCED value ( Index Term Link )
 
 priv_ftype_t type ( Index Term Link )
 
 PRIV_INHERITABLE value ( Index Term Link )
 
 PRIV_INTERSECT macro ( Index Term Link )
 
 PRIV_ISASSERT macro
  code example ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link )
 
 PRIV_ISEMPTY macro ( Index Term Link )
 
 PRIV_ISFULL macro ( Index Term Link )
 
 PRIV_ISSUBSET macro
  described ( Index Term Link )
  purpose ( Index Term Link )
 
 PRIV_OFF value ( Index Term Link )
 
 PRIV_ON value ( Index Term Link )
 
 priv_op_t type ( Index Term Link )
 
 PRIV_PERMITTED value ( Index Term Link )
 
 priv_ptype_t type ( Index Term Link )
 
 PRIV_SAVED value ( Index Term Link )
 
 priv_set_t structure ( Index Term Link )
 
 priv_set_to_str routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 PRIV_SET value ( Index Term Link )
 
 priv_t type ( Index Term Link )
 
 PRIV_TEST macro ( Index Term Link )
 
 priv_to_str routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 PRIV_UNION macro ( Index Term Link )
 
 PRIV_XOR macro ( Index Term Link )
 
 privilege APIs
  declarations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  macros ( Index Term Link )
 
 privilege bracketing
  benefits ( Index Term Link )
  code example ( Index Term Link )
  procedure ( Index Term Link )
 
 privilege data types
  file sets ( Index Term Link )
  operations on sets ( Index Term Link )
  privilege ID ( Index Term Link )
  process sets ( Index Term Link )
  structure ( Index Term Link )
 
 privilege debugging
  enabling ( Index Term Link ) ( Index Term Link )
  flag ( Index Term Link )
 
 privilege macros
  API declarations ( Index Term Link )
  asserting privilege example ( Index Term Link )
  described ( Index Term Link )
  initializing set example ( Index Term Link )
 
 privilege sets
  after exec function ( Index Term Link )
  after fork function ( Index Term Link )
  algorithms ( Index Term Link )
  API declarations ( Index Term Link )
  file ( Index Term Link )
  on network messages ( Index Term Link )
  privileged tasks ( Index Term Link )
  privileges needed ( Index Term Link )
  process ( Index Term Link ) ( Index Term Link )
  turning off allowed sey ( Index Term Link )
 
 privileged process defined ( Index Term Link )
 
 privileged tasks
  auditing ( Index Term Link )
  clearance ( Index Term Link )
  IPC ( Index Term Link )
  Label builder ( Index Term Link )
  labels ( Index Term Link )
  MLDs ( Index Term Link )
  multilevel port connections ( Index Term Link )
  privilege sets ( Index Term Link )
  RPC ( Index Term Link )
  SLDs ( Index Term Link )
  System V IPC ( Index Term Link )
  TSIX ( Index Term Link )
  X Window System ( Index Term Link )
 
 privileges
  administrative applications ( Index Term Link )
  and authorizations ( Index Term Link )
  API declarations ( Index Term Link )
  applications, privileged ( Index Term Link )
  categories
   file system ( Index Term Link )
   IPC ( Index Term Link )
   process ( Index Term Link )
   system ( Index Term Link )
   System V IPC ( Index Term Link )
   X Window System ( Index Term Link )
  contrast to superuser ( Index Term Link )
  defined ( Index Term Link )
  delimiters ( Index Term Link )
  description text API ( Index Term Link )
  development environment ( Index Term Link )
  errors ( Index Term Link )
  guidelines ( Index Term Link )
  on interpreted files ( Index Term Link )
  scripts ( Index Term Link )
  separators ( Index Term Link )
  TCB ( Index Term Link ) ( Index Term Link )
  UIDs, changed ( Index Term Link )
  upgraded names
   hide ( Index Term Link )
  user applications ( Index Term Link )
  when to use ( Index Term Link ) ( Index Term Link )
  when writing to executable ( Index Term Link )
 
 proc_audit_appl privilege ( Index Term Link )
 
 proc_audit_tcb privilege ( Index Term Link )
 
 proc_mac_owner privilege ( Index Term Link )
 
 proc_mac_read privilege ( Index Term Link )
 
 proc_set_sl privilege ( Index Term Link )
 
 proc_setclr privilege ( Index Term Link ) ( Index Term Link )
 
 proc_setid privilege ( Index Term Link )
 
 proc_setsl privilege ( Index Term Link )
 
 process clearances
  acquiring ( Index Term Link )
  API declarations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  checking before file access ( Index Term Link )
  components ( Index Term Link )
  data types
   clearance structure ( Index Term Link )
   levels ( Index Term Link )
  described ( Index Term Link )
  dominate levels ( Index Term Link )
  equal levels ( Index Term Link )
  levels defined ( Index Term Link )
  MAC checks ( Index Term Link )
  mandatory access operations ( Index Term Link )
  privileged tasks ( Index Term Link )
  reentrant routines ( Index Term Link )
  strictly dominate levels ( Index Term Link )
  TSIX ( Index Term Link )
  valid ( Index Term Link )
 
 process preselection mask
  application auditing ( Index Term Link )
  changing ( Index Term Link )
  return token ( Index Term Link )
 
 process tracing, access checks ( Index Term Link )
 
 processes
  changing labels, guidelines ( Index Term Link )
  CMW label, inheriting values ( Index Term Link )
  effective privilege set ( Index Term Link )
  inheritable privilege set ( Index Term Link )
  label privileges ( Index Term Link )
  objects ( Index Term Link )
  permitted privilege set ( Index Term Link )
  privilege sets ( Index Term Link )
  privileged, defined ( Index Term Link )
  privileged tasks ( Index Term Link )
  privileges, defined ( Index Term Link )
  saved privilege set ( Index Term Link )
 
 properties
  described ( Index Term Link ) ( Index Term Link )
  privileges ( Index Term Link )
 
 property.atoms file ( Index Term Link )
 
 protect_as field ( Index Term Link )
 
 protect_as_len field ( Index Term Link ) ( Index Term Link )
 
 PTYs, access checks ( Index Term Link )
 
 public.atoms file ( Index Term Link )
    
R
 
 read access, security policy ( Index Term Link )
 
 read down ( Index Term Link )
 
 read equal ( Index Term Link )
 
 reentrant routines
  binary to hex declarations ( Index Term Link )
  binary to hex translation ( Index Term Link ) ( Index Term Link )
 
 relationships
  between levels ( Index Term Link ) ( Index Term Link )
 
 releasing an application ( Index Term Link )
 
 resource file ( Index Term Link )
 
 ResourceType structure ( Index Term Link )
 
 RPC
  API man pages ( Index Term Link )
  client program ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link )
  example application ( Index Term Link ) ( Index Term Link )
  mappings ( Index Term Link )
  multilevel ports ( Index Term Link )
  privileged tasks ( Index Term Link )
  remote procedure ( Index Term Link )
  running the application ( Index Term Link )
  security attributes ( Index Term Link )
  server program ( Index Term Link )
 
 runpd command, using ( Index Term Link )
    
S
 
 saved privileges
  change UID, GUID, or SGUID ( Index Term Link )
  checking ( Index Term Link )
  defined ( Index Term Link )
  purpose ( Index Term Link )
 
 sbcleartos routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 sbcltos routine, declaration ( Index Term Link )
 
 sbsltos routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 scripts, privileged ( Index Term Link )
 
 secconf system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 security attribute flags
  API declarations ( Index Term Link ) ( Index Term Link )
  file systems
   API declarations ( Index Term Link )
   contrast with Solaris ( Index Term Link )
   manifest constants ( Index Term Link ) ( Index Term Link )
  processes
   API declarations ( Index Term Link )
   contrast with Solaris ( Index Term Link )
   getting and setting ( Index Term Link )
   manifest constants ( Index Term Link )
   when to use ( Index Term Link )
 
 security attributes
  access checks ( Index Term Link )
  access to privileges ( Index Term Link )
  accessing labels ( Index Term Link )
  API declarations ( Index Term Link )
  file systems
   API declarations ( Index Term Link )
   contrast with Solaris ( Index Term Link )
   described ( Index Term Link )
   manifest constants ( Index Term Link )
   vfstab_adjunct file ( Index Term Link )
   when to use ( Index Term Link )
  MLDs ( Index Term Link )
  on software packages ( Index Term Link )
  privileges ( Index Term Link )
  processes ( Index Term Link )
  RPC ( Index Term Link )
  TSIX
   changing ( Index Term Link )
   changing procedure ( Index Term Link )
   contrast with Solaris ( Index Term Link )
   location on packet ( Index Term Link )
   sending and receiving ( Index Term Link )
  X Window System
   contrast with Solaris ( Index Term Link )
   described ( Index Term Link )
 
 security policy
  accessing MLDs ( Index Term Link )
  accessing SLDs ( Index Term Link )
  administrative applications ( Index Term Link )
  auditing ( Index Term Link )
  CDE actions ( Index Term Link )
  clearances ( Index Term Link )
  command line execution ( Index Term Link ) ( Index Term Link )
  communication endpoints ( Index Term Link )
  covert channels ( Index Term Link )
  discretionary access operations ( Index Term Link )
  file system examples ( Index Term Link )
  file systems ( Index Term Link )
  file systems access ( Index Term Link )
  file systems privileges ( Index Term Link )
  IPC ( Index Term Link ) ( Index Term Link )
  label guidelines ( Index Term Link )
  labels ( Index Term Link )
  mandatory access operations ( Index Term Link )
  mapped memory ( Index Term Link )
  MLD access ( Index Term Link )
  multilevel ports ( Index Term Link )
  on man pages ( Index Term Link )
  pipes ( Index Term Link ) ( Index Term Link )
  privilege bracketing ( Index Term Link )
  privilege guidelines ( Index Term Link )
  privilege sets ( Index Term Link )
  privileges
   when to use ( Index Term Link )
  privileges, when to use ( Index Term Link )
  process tracing ( Index Term Link )
  PTYs ( Index Term Link )
  read access ( Index Term Link )
  reading man pages ( Index Term Link )
  signals ( Index Term Link )
  SLD access ( Index Term Link )
  sockets ( Index Term Link )
  System V IPC ( Index Term Link ) ( Index Term Link )
  TLI ( Index Term Link )
  translating labels ( Index Term Link ) ( Index Term Link )
  user applications ( Index Term Link )
  write access ( Index Term Link )
  X Window System ( Index Term Link )
 
 selection agent flag ( Index Term Link )
 
 selection.atoms file ( Index Term Link )
 
 Selection Manager
  bypassing with flag ( Index Term Link )
  security policy ( Index Term Link )
 
 semaphore sets
  API declarations ( Index Term Link ) ( Index Term Link )
 
 semgetl system call, declaration ( Index Term Link )
 
 sessionid field ( Index Term Link )
 
 set_effective_priv routine
  code example ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 set_id structure ( Index Term Link )
 
 set_inheritable_priv routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 set_permitted_priv routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 setbltype routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link ) ( Index Term Link )
 
 SETCL_ALL flag ( Index Term Link )
 
 SETCL_SL flag ( Index Term Link )
 
 setclearance system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 setcmwlabel system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 setcmwplabel system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
  when to use ( Index Term Link )
 
 setcsl routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 seteuid system call, and privileges ( Index Term Link )
 
 setfattrflag system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 setfpriv command, scripts ( Index Term Link )
 
 setfpriv system call
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 setpattr system call declaration ( Index Term Link )
 
 setppriv system call
  declaration ( Index Term Link )
  privilege bracketing ( Index Term Link )
 
 setreuid system call, and privileges ( Index Term Link )
 
 setting_flag field ( Index Term Link )
 
 setuid system call, and privileges ( Index Term Link )
 
 SGIDs, privilege to change ( Index Term Link )
 
 shared libraries, trusted ( Index Term Link )
 
 shared memory regions
  API declarations ( Index Term Link ) ( Index Term Link )
 
 shell escapes and privileges ( Index Term Link )
 
 shmgetl system call
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 SHORT_CLASSIFICATION flag ( Index Term Link )
 
 SHORT_WORDS flag ( Index Term Link )
 
 signals, access checks ( Index Term Link )
 
 single-label file systems ( Index Term Link )
 
 single-level mappings ( Index Term Link )
 
 single-level ports
  changing client SL ( Index Term Link )
  described ( Index Term Link )
 
 sl field ( Index Term Link ) ( Index Term Link )
 
 slabel_len field ( Index Term Link )
 
 SLDs
  accessing ( Index Term Link )
  adorned names ( Index Term Link )
  API declarations ( Index Term Link ) ( Index Term Link )
  creating ( Index Term Link )
  described ( Index Term Link )
  information structure ( Index Term Link )
  privileged tasks ( Index Term Link )
  sensitivity labels ( Index Term Link )
  structure ( Index Term Link )
 
 SLs
  See labels
 
 sockets
  access checks ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 software packages
  adding new ( Index Term Link )
  creating ( Index Term Link )
  editing existing ( Index Term Link )
  MAC attributes on ( Index Term Link )
  prototype file ( Index Term Link )
 
 st_atime field ( Index Term Link )
 
 st_ctime field ( Index Term Link )
 
 st_gid field ( Index Term Link )
 
 st_mode field ( Index Term Link )
 
 st_mtime field ( Index Term Link )
 
 st_nlink field ( Index Term Link )
 
 st_uid field ( Index Term Link )
 
 stat structure ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 stobc routine, code example ( Index Term Link )
 
 stobcl routine, declaration ( Index Term Link )
 
 stobclear routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 stobsl routine
  code example ( Index Term Link ) ( Index Term Link )
  declaration ( Index Term Link )
 
 str_to_priv routine
  and PRIV_ASSERT macro ( Index Term Link )
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 str_to_priv_set routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 strictly dominate levels ( Index Term Link ) ( Index Term Link )
 
 SUN_CLR_ID value ( Index Term Link )
 
 SUN_CLR_UN value ( Index Term Link )
 
 SUN_CMW_ID value ( Index Term Link )
 
 SUN_SL_ID value ( Index Term Link )
 
 SUN_SL_UN value ( Index Term Link )
 
 SVCXPRT structure ( Index Term Link )
 
 symbolic links
  information structure ( Index Term Link )
  MLDs ( Index Term Link )
 
 sys_trans_label privilege ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 system, privileges defined ( Index Term Link )
 
 SYSTEM_ACCREDITATION_RANGE value ( Index Term Link )
 
 system calls
  API declarations ( Index Term Link )
  security policy in man pages ( Index Term Link )
 
 system security configuration
  API declarations ( Index Term Link )
  variables described ( Index Term Link )
  when to check ( Index Term Link )
 
 System V IPC
  access checks ( Index Term Link ) ( Index Term Link )
  API declarations ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link )
  discretionary access ( Index Term Link )
  mandatory access ( Index Term Link )
  privileged tasks ( Index Term Link )
  privileges, defined ( Index Term Link )
  sensitivity label structure ( Index Term Link )
    
T
 
 T6_AUDIT_ID value ( Index Term Link )
 
 T6_AUDIT_INFO value ( Index Term Link )
 
 T6_CLEARANCE value ( Index Term Link )
 
 T6_GID value ( Index Term Link )
 
 T6_GROUPS value ( Index Term Link )
 
 T6_PID value ( Index Term Link )
 
 T6_PRIVILEGES value ( Index Term Link )
 
 T6_PROC_ATTR value ( Index Term Link )
 
 T6_SESSION_IC value ( Index Term Link )
 
 T6_SL value ( Index Term Link )
 
 T6_UID value ( Index Term Link )
 
 t6alloc_blk(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6allocated_attrs(3NSL), code example ( Index Term Link )
 
 t6allocated_attrs routine, declaration ( Index Term Link )
 
 t6attr_id_t structure ( Index Term Link )
 
 t6attr_t structure ( Index Term Link )
 
 t6clear_blk(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6cmp_blk(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6copy_blk(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6dup_blk(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6ext_attr(3NSL), declaration ( Index Term Link )
 
 t6free_blk(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6get_attr(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6get_endpt_default(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6get_endpt_mask(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6last_attr(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 T6M_ALL_ATTRS value ( Index Term Link )
 
 T6M_AUDIT_ID value ( Index Term Link )
 
 T6M_AUDIT_INFO value ( Index Term Link )
 
 T6M_CLEARANCE value ( Index Term Link )
 
 T6M_GID value ( Index Term Link )
 
 T6M_GROUPS value ( Index Term Link )
 
 T6M_NO_ATTRS value ( Index Term Link )
 
 T6M_PID value ( Index Term Link )
 
 T6M_PRIVILEGES value ( Index Term Link )
 
 T6M_SESSION_ID value ( Index Term Link )
 
 T6M_SL value ( Index Term Link )
 
 T6M_UID value ( Index Term Link )
 
 t6mask_t structure ( Index Term Link )
 
 t6new_attr(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6peek_attr(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6present_attrs(3NSL), code example ( Index Term Link )
 
 t6present_attrs routine, declaration ( Index Term Link )
 
 t6recvfrom(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6sendto(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6set_attr(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6set_endpt_default(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6set_endpt_mask(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6size_attr(3NSL)
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 t6supported_attrs(3NSL), code example ( Index Term Link )
 
 t6supported_attrs routine, declaration ( Index Term Link )
 
 TCB
  network flag ( Index Term Link )
  privileged applications ( Index Term Link )
 
 terminator commands ( Index Term Link )
 
 testing and debugging applications ( Index Term Link )
 
 text, color names ( Index Term Link )
 
 TLI
  access checks ( Index Term Link )
  objects ( Index Term Link )
 
 token commands ( Index Term Link )
 
 translation
  adorned pathnames ( Index Term Link )
  clearances
   binary and hexadecimal ( Index Term Link )
   binary to hex ( Index Term Link )
   binary to text ( Index Term Link )
   binary to text, clipped ( Index Term Link )
   forms ( Index Term Link )
   reentrant routines ( Index Term Link )
   text to binary ( Index Term Link )
  CMW labels
   binary to hex ( Index Term Link )
   binary to text ( Index Term Link )
   input form ( Index Term Link )
   output form ( Index Term Link )
   text to binary ( Index Term Link )
  font list ( Index Term Link )
  labels
   binary and hexadecimal ( Index Term Link ) ( Index Term Link )
   binary and text rules ( Index Term Link )
   binary to text ( Index Term Link ) ( Index Term Link )
   binary to text guidelines ( Index Term Link )
   flag values ( Index Term Link )
   font list ( Index Term Link )
   forms ( Index Term Link )
   input form ( Index Term Link )
   output form ( Index Term Link )
   reentrant routines ( Index Term Link )
   text to binary correction ( Index Term Link )
   view ( Index Term Link )
  privileges
   ID to string ( Index Term Link )
   string to ID ( Index Term Link )
  privileges, binary and text ( Index Term Link )
  privileges needed ( Index Term Link ) ( Index Term Link )
  reentrant binary to hex ( Index Term Link )
 
 Trojan horse protection ( Index Term Link )
 
 trusted path, attribute flag ( Index Term Link )
 
 trusted shared libraries ( Index Term Link )
 
 trusted streams
  API declarations ( Index Term Link ) ( Index Term Link )
  objects ( Index Term Link )
 
 TSIX library
  API declarations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  attribute enumerations ( Index Term Link )
  attribute masks ( Index Term Link )
  attribute structure ( Index Term Link )
  changing client SL ( Index Term Link )
  changing security attributes ( Index Term Link ) ( Index Term Link )
  client application ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link )
  example application ( Index Term Link ) ( Index Term Link )
  network accreditation range ( Index Term Link )
  privileged tasks ( Index Term Link )
  replying at equal SL ( Index Term Link )
  security attributes ( Index Term Link )
  server application ( Index Term Link )
 
 TSOL_AUTH_FILE_DOWNGRADE authorization ( Index Term Link )
 
 TSOL_HIDE_UPGRADED_NAMES variable ( Index Term Link )
 
 tsol_lbuild_create routine
  declaration ( Index Term Link )
  description ( Index Term Link )
 
 tsol_lbuild_destroy routine, declaration ( Index Term Link )
 
 tsol_lbuild_get routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 tsol_lbuild_set routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
    
U
 
 uid field ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 UIDs
  changed ( Index Term Link )
  getting on window ( Index Term Link )
  getting on workstation ( Index Term Link )
  privilege to change ( Index Term Link )
 
 undefined labels, described ( Index Term Link )
 
 upgraded names, hide ( Index Term Link )
 
 upgrading labels
  guidelines ( Index Term Link )
  privileges needed ( Index Term Link )
  X Window System ( Index Term Link )
 
 USER_ACCREDITATION_RANGE value ( Index Term Link )
    
V
 
 valid clearances
  checking ( Index Term Link )
  ensuring ( Index Term Link )
 
 valid labels
  accreditation ranges ( Index Term Link )
  checking ( Index Term Link )
  ensuring ( Index Term Link )
 
 vers_len field ( Index Term Link )
 
 version string retrieval ( Index Term Link )
 
 vfstab_adjunct file
  code example ( Index Term Link )
  retrieving entries ( Index Term Link )
 
 VIEW_EXTERNAL flag ( Index Term Link )
 
 VIEW_INTERNAL flag ( Index Term Link )
    
W
 
 win_config privilege ( Index Term Link )
 
 win_dac_read privilege ( Index Term Link )
 
 win_dac_write privilege ( Index Term Link )
 
 win_devices privilege ( Index Term Link )
 
 win_dga privilege ( Index Term Link )
 
 win_downgrade_sl privilege ( Index Term Link )
 
 win_fontpath privilege ( Index Term Link )
 
 win_mac_read privilege ( Index Term Link )
 
 win_mac_write privilege ( Index Term Link )
 
 win_upgrade_sl privilege ( Index Term Link )
 
 windows
  client, security policy ( Index Term Link )
  defaults ( Index Term Link )
  described ( Index Term Link )
  override-redirect, security policy ( Index Term Link )
  privileges ( Index Term Link )
  root, security policy ( Index Term Link )
  security policy ( Index Term Link )
 
 write access, security policy ( Index Term Link )
 
 write equal ( Index Term Link )
 
 write up ( Index Term Link )
    
X
 
 X Window System
  API declarations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  client attributes structure ( Index Term Link )
  defaults ( Index Term Link )
  input devices ( Index Term Link )
  label clipping API declarations ( Index Term Link )
  Motif source code ( Index Term Link )
  object attribute structure ( Index Term Link )
  object type definition ( Index Term Link )
  objects ( Index Term Link ) ( Index Term Link )
  override-redirect ( Index Term Link )
  predefined atoms ( Index Term Link )
  privileged tasks ( Index Term Link )
  privileges, defined ( Index Term Link )
  properties ( Index Term Link )
  property attribute structure ( Index Term Link )
  protocol extensions ( Index Term Link )
  resource file ( Index Term Link )
  root window ( Index Term Link )
  security attributes
   contrast with Solaris ( Index Term Link )
   described ( Index Term Link )
  security policy ( Index Term Link )
  Selection Manager ( Index Term Link )
  server control ( Index Term Link )
 
 xbcleartos routine, declaration ( Index Term Link )
 
 xbcltos routine, declaration ( Index Term Link )
 
 xbsltos routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 Xlib
  API declarations ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link )
  objects ( Index Term Link )
 
 xp_tsol_incoming_attrsp field ( Index Term Link )
 
 xp_tsol_incoming_new_attrs field ( Index Term Link )
 
 xp_tsol_outgoing_attrsp field ( Index Term Link )
 
 Xsession file ( Index Term Link )
 
 XTsolClientAttributes structure ( Index Term Link )
 
 XTSOLgetClientAttributes routine, declaration ( Index Term Link )
 
 XTSOLgetPropAttributes routine, declaration ( Index Term Link )
 
 XTSOLgetPropLabel routine, declaration ( Index Term Link )
 
 XTSOLgetPropUID routine, declaration ( Index Term Link )
 
 XTSOLgetResAttributes routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 XTSOLgetResLabel routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 XTSOLgetResUID routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 XTSOLgetSSHeight routine, declaration ( Index Term Link )
 
 XTSOLgetWorkstationOwner routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 XTSOLIsWindowTrusted routine, declaration ( Index Term Link )
 
 XTSOLmakeTPWindow routine, declaration ( Index Term Link )
 
 XTsolPropAttributes structure ( Index Term Link )
 
 XTsolResAttributes structure ( Index Term Link )
 
 XTSOLsetPropLabel routine, declaration ( Index Term Link )
 
 XTSOLsetPropUID routine, declaration ( Index Term Link )
 
 XTSOLsetResLabel routine
  code example ( Index Term Link )
  declaration ( Index Term Link )
 
 XTSOLsetSessionHI routine, declaration ( Index Term Link )
 
 XTSOLsetSessionLO routine, declaration ( Index Term Link )
 
 XTSOLsetSSHeight routine, declaration ( Index Term Link )
 
 XTSOLsetWorkstationOwner routine, declaration ( Index Term Link )
 
 Xtsolusersession file ( Index Term Link )