SETPRIV(1) SETPRIV(1) (NAME) setpriv - (SYNOPSIS) setpriv [options] program [arguments] (DESCRIPTION) execve(2) . su(1) runuser(1) setpriv PAM . set-user-ID execve(2) setuidgid(8) daemontools chpst(8) runit . (OPTIONS) --clear-groups (supplementary groups). -d, --dump . . . --groups group... . GID . --inh-caps (+|-)cap..., --ambient-caps (+|-)cap..., --bounding-set (+|-)cap... (inheritable capabilities) (ambient capabilities) (capability bounding set). capabilities(7) . +cap -cap . cap capabilities(7) cap_ cap_N N . +all -all . --inh-caps --ambient-caps --bounding-set . ( capabilities(7)) : o (bounding set) . o (permitted) . o setpriv . . . --keep-groups . --rgid --egid --regid . --init-groups initgroups3. --ruid --reuid . --list-caps . . --nnp, --no-new-privs no_new_privs. execve(2) . set-user-ID set-group-ID . ( . LSM AppArmor .) . prctl(2) Documentation/prctl/no_new_privs.txt . no_new_privs . . --rgid gid, --egid gid, --regid gid GID (real) (effective) . gid . gid --clear-groups --groups --keep-groups --init-groups . --ruid uid, --euid uid, --reuid uid UID (real) (effective) . uid . uid gid exec . root : setpriv --reuid=1000 --regid=1000 --inh-caps=-all --securebits (+|-)securebit... securebits. . securebit noroot noroot_locked no_setuid_fixup no_setuid_fixup_locked keep_caps_locked. keep_caps execve(2) . --pdeathsig keep|clear| (parent death signal). LSM SELinux AppArmor . --pdeathsig keep . --ptracer pid|any|none ptrace Yama ( /proc/sys/kernel/yama/ptrace_scope 1 ) ptrace(2) PID . PR_SET_PTRACER(2const) . ( execve(2) .) Yama ptrace . --selinux-label label (transition) SELinux ( transition exec dyntrans). SELinux setpriv SELinux execve(2) . ( no_new_privs .) runcon(1) . --apparmor-profile profile (profile) AppArmor ( exec). AppArmor setpriv AppArmor execve(2) . --landlock-access access landlock . --landlock-rule . : setpriv --landlock-access fs : setpriv --landlock-access fs:remove-file,make-dir setpriv --help . "fs" . --landlock-rule rule --landlock-access. : --landlock-rule $ruletype:$access:$rulearg /boot: --landlock-rule path-beneath:read-file:/boot --seccomp-filter file BPF seccomp . enosys . --reset-env o TERM o HOME SHELL USER LOGNAME passwd o SHELL passwd /bin/sh . o PATH /etc/login.defs ( ENV_PATH ENV_SUPATH ENV_ROOTPATH) /usr/local/bin:/bin:/usr/bin root /usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin . PATH /bin /sbin /usr . -h, --help . -V, --version . (NOTES) program setpriv . -- . no_new_privs SELinux ( ) SELinux . (EXAMPLES) setpriv : su(1) runuser(1) sudo(8) . setpriv PAM (accounting) . . UID/GID runuser(1) ( --login) : setpriv --reuid=1000 --regid=1000 --inh-caps=-all --init-groups ( sudo(8) ) --reset-env : setpriv --reuid=1000 --regid=1000 --inh-caps=-all --init-groups --reset-env ( runuser sudo): setpriv --reuid=1000 --regid=1000 --init-groups --inh-caps=-all --bounding-set=-all --no-new-privs --reset-env setuid(8) daemontools : setpriv --reuid=1000 --regid=1000 --clear-groups (AUTHORS) Andy Lutomirski (SEE ALSO) runuser(1), su(1), prctl(2), capabilities(7), landlock(7) (REPORTING BUGS) . . (AVAILABILITY) setpriv util-linux . . util-linux 2.42.3 2026-09-02 SETPRIV(1)