The following are the set of capability types that can be assigned to
a given policy:
Value | Description |
---|
TCB
|
Grants write access to executables, and shared read-only
resources.
|
CommDD
|
Grants direct access to all communication equipment device
drivers.
|
PowerMgmt
|
Grants the right to end any process in the system, to
switch-off unused peripherals, to switch the machine into standby state, wake
it up again, or power it down completely.
|
MultimediaDD
|
Grants access to critical multimedia functions, such as direct
access to associated device drivers, high priority access to multimedia APIs,
and for pre-empting lower priority users.
|
ReadDeviceData
|
Grants read access to network operator, phone manufacturer and
device confidential settings or data.
|
WriteDeviceData
|
Grants write access to settings that control the behaviour of
the device.
|
DRM
|
Grants access to the protected content.
|
TrustedUI
|
Grants the right to create a trusted UI session, and to display
dialogs in a secure UI environment.
|
ProtServ
|
Grants the right to a server to register with a protected name.
|
DiskAdmin
|
Grants access to disk administration operations that affect
more than one file or one directory (or overall file-system integrity or
behaviour, and so on).
|
NetworkControl
|
Grants the right to modify or access network protocol controls.
|
AllFiles
|
Grants read access to the entire file system. Grants write
access to the private directories of other processes.
|
SwEvent
|
Grants the right to generate software key and pen events, and
to capture any of them regardless of the status of the application.
|
NetworkServices
|
Grants access to the remote services irrespective of their
physical location. In most cases, location of the remote services is unknown to
the phone user, and such services may cost the phone user.
|
LocalServices
|
Grants access to remote services in the close vicinity of the
phone. The location of the remote service is well known to the phone user.
|
ReadUserData
|
Grants the phone user read access to confidential data.
|
WriteUserData
|
Grants write access to user data. This capability supports the
management of the integrity of user data.
|
Location
|
Grants access to the location of the device.
|
SurroundingsDD
|
Grants access to logical device drivers that provide input
information about the surroundings of the device.
|
UserEnvironment
|
Grants access to live confidential information about the user
and the immediate environment. This capability protects privacy.
|
None
|
No capability specified.
|