acl(9) 맨 페이지 - 윈디하나의 솔라나라

개요

섹션
맨 페이지 이름
검색(S)

acl(9)

In  the kernel configuration file: Access control lists, or ACLs,
allow fine-grained specification of rights for vnodes  represent‐
ing  files  and directories.  However, as there are a plethora of
file systems with differing ACL semantics, the vnode interface is
aware only of the syntax of ACLs, relying on the underlying  file
system  to  implement  the  details.  Depending on the underlying
file system, each file or directory may have zero  or  more  ACLs
associated  with it, named using the field of the appropriate vn‐
ode ACL calls: and Currently, each ACL is  represented  in-kernel
by a fixed-size structure, defined as follows: struct acl {
        unsigned int            acl_maxcnt;
        unsigned int            acl_cnt;
        int                     acl_spare[4];
        struct acl_entry        acl_entry[ACL_MAX_ENTRIES]; }; An
ACL  is  constructed from a fixed size array of ACL entries, each
of which consists of a set of permissions,  principal  namespace,
and  principal  identifier.  In this implementation, the field is
always set to Each individual ACL entry is of the type which is a
structure with the following members: The following is a list  of
definitions  of  ACL types to be set in Undefined ACL type.  Dis‐
cretionary access rights for processes whose  effective  user  ID
matches  the  user  ID of the file's owner.  Discretionary access
rights for processes whose effective user ID matches the ACL  en‐
try  qualifier.   Discretionary access rights for processes whose
effective group ID or any supplemental groups match the group  ID
of  the  file's owner.  Discretionary access rights for processes
whose effective group ID or any supplemental groups match the ACL
entry qualifier.  The maximum discretionary  access  rights  that
can  be  granted  to  a process in the file group class.  This is
only valid for POSIX.1e ACLs.  Discretionary  access  rights  for
processes not covered by any other ACL entry.  This is only valid
for  POSIX.1e  ACLs.  Same as Discretionary access rights for all
users.  This is only valid for NFSv4  ACLs.   Each  POSIX.1e  ACL
must  contain  exactly  one one and one If any of or are present,
then exactly one entry should be present.  The  ID  of  user  for
whom  this  ACL  describes access permissions.  For entries other
than and this field should be set to This field defines what kind
of access the process matching this ACL has for accessing the as‐
sociated file.  For POSIX.1e ACLs, the following are  valid:  The
process  may  execute the associated file.  The process may write
to the associated file.  The process may read from the associated
file.  The process has no read, write or execute  permissions  to
the  associated  file.   For NFSv4 ACLs, the following are valid:
The process may read from  the  associated  file.   Same  as  The
process  may  write  to the associated file.  Same as Same as Ig‐
nored.  Ignored.  The process may execute  the  associated  file.
Ignored.   This field defines the type of NFSv4 ACL entry.  It is
not used with POSIX.1e ACLs.  The  following  values  are  valid:
This  field defines the inheritance flags of NFSv4 ACL entry.  It
is not used with POSIX.1e ACLs.  The following values are  valid:
The  flag  is set on an ACE that has been inherited from its par‐
ent.  It may also be set programmatically, and is valid  on  both
files and directories.  This manual page was written by













맨 페이지 내용의 저작권은 맨 페이지 작성자에게 있습니다.
RSS ATOM XHTML 5 CSS3