https://wiki.vmssoftware.com/index.php?title=CMKRNL&feed=atom&action=historyCMKRNL - Revision history2024-03-28T22:41:27ZRevision history for this page on the wikiMediaWiki 1.31.0https://wiki.vmssoftware.com/index.php?title=CMKRNL&diff=343&oldid=prevDarya.zelenina: Created page with "The '''CMKRNL''' privilege allows the user's process to execute the Change Mode to Kernel ($CMKRNL) system service. This system service lets a process change its a..."2019-02-28T07:30:54Z<p>Created page with "The '''CMKRNL''' privilege allows the user's process to execute the <a href="/index.php?title=$CMKRNL&action=edit&redlink=1" class="new" title="$CMKRNL (page does not exist)">Change Mode to Kernel ($CMKRNL)</a> system service. This system service lets a process change its a..."</p>
<p><b>New page</b></p><div>The '''CMKRNL''' privilege allows the user's process to execute the [[$CMKRNL|Change Mode to Kernel ($CMKRNL)]] system service.<br />
This system service lets a process change its access mode to kernel mode, execute a specified routine, and then return to the access mode that was in effect before the system service was called. While in kernel mode, a process can enable any system privilege.<br />
A process holding both CMKRNL and [[SYSNAM]] can set the system time.<br />
<br />
Grant this privilege only to users who need to execute privileged instructions or who need to gain access to the most protected and sensitive data structures and functions of the operating system. If unqualified users have unrestricted use of privileged instructions and unrestricted access to sensitive data structures and functions, the operating system and service to other users can be easily disrupted. Such disruptions can include failure of the system, destruction of all system and user data, and exposure of confidential information.<br />
<br />
The CMKRNL privilege lets a process perform the following tasks:<br />
<br />
{| class="wikitable"<br />
! colspan="col" | Task<br />
! colspan="col" | Interface<br />
|-<br />
| Modify a multiprocessor operation<br />
| START/CPU, STOP/CPU<br />
|-<br />
| Modify systemwide RMS defaults<br />
| SET RMS/SYSTEM<br />
|-<br />
| Suspend a process in kernel mode<br />
| SET PROCESS/SUSPEND=KERNEL<br />
|-<br />
| Modify another process’ rights list or its nondynamic identifier attributes<br />
| SET RIGHTS_LIST<br />
|-<br />
| Grant an identifier with modified attributes<br />
| SET RIGHTS/ATTRIBUTE<br />
|-<br />
| Modify the system rights list<br />
| SET RIGHTS_LIST/SYSTEM<br />
|-<br />
| Change a process [[UIC]]<br />
| SET UIC<br />
|-<br />
| Modify the number of interlocked queue retries<br />
| $QIO request to an Ethernet 802 driver (DEBNA/NI)<br />
|-<br />
| Connect to a device interrupt vector<br />
| $QIO request to an interrupt vector (CONTINTERR)<br />
|- <br />
| Start or modify a line in Genbyte mode<br />
| $QIO request to a synchronous communications line (XGDRIVER)<br />
|-<br />
| Set the spin-wait time on the port command register<br />
| $QIO request to an Ethernet 802 driver (DEBNA)<br />
|-<br />
| Modify a known image list<br />
| [[INSTALL]]<br />
|-<br />
| Process the following item codes: [[SJC$_ACCOUNT_NAME]] item<br />
[[SJC$_UIC]]<br />
[[SJC$_USERNAME]]<br />
| [[$SNDJBC|Send to the Job Controller system service ($SNDJBC)]]<br />
|-<br />
| Create a [[Detached Process|detached process]] with unrestricted quotas<br />
| RUN/DETACHED, [[$CREPRC]]<br />
|-<br />
| Examine the internals of a running system<br />
| ANALYZE/SYSTEM<br />
|}<br />
<br />
[[Category:All Privileges]]</div>Darya.zelenina