From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Achim Gratz Newsgroups: gmane.emacs.devel Subject: Re: [PATCH] POSIX ACL support Date: Wed, 21 Nov 2012 20:52:08 +0100 Organization: Linux Private Site Message-ID: <87zk2abuon.fsf@Rainer.invalid> References: <878v9yr1h1.fsf@silenus.orebokech.com> <87ehjpp9b7.fsf@silenus.orebokech.com> <87mwybm84m.fsf@silenus.orebokech.com> <50ACF4E9.60604@cs.ucla.edu> <83k3tevn0l.fsf@gnu.org> <50AD1C91.5030708@cs.ucla.edu> <874nkidb8n.fsf@Rainer.invalid> <83d2z6vj6o.fsf@gnu.org> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: ger.gmane.org 1353527552 28813 80.91.229.3 (21 Nov 2012 19:52:32 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Wed, 21 Nov 2012 19:52:32 +0000 (UTC) To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Wed Nov 21 20:52:44 2012 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1TbGLj-0004Z0-Oj for ged-emacs-devel@m.gmane.org; Wed, 21 Nov 2012 20:52:43 +0100 Original-Received: from localhost ([::1]:56726 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TbGLZ-0007SR-Dq for ged-emacs-devel@m.gmane.org; Wed, 21 Nov 2012 14:52:33 -0500 Original-Received: from eggs.gnu.org ([208.118.235.92]:59743) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TbGLW-0007SC-75 for emacs-devel@gnu.org; Wed, 21 Nov 2012 14:52:31 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TbGLU-0004uA-S1 for emacs-devel@gnu.org; Wed, 21 Nov 2012 14:52:30 -0500 Original-Received: from plane.gmane.org ([80.91.229.3]:37934) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TbGLU-0004tz-L2 for emacs-devel@gnu.org; Wed, 21 Nov 2012 14:52:28 -0500 Original-Received: from list by plane.gmane.org with local (Exim 4.69) (envelope-from ) id 1TbGLc-0004Td-7r for emacs-devel@gnu.org; Wed, 21 Nov 2012 20:52:36 +0100 Original-Received: from pd9eb3124.dip.t-dialin.net ([217.235.49.36]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Wed, 21 Nov 2012 20:52:36 +0100 Original-Received: from Stromeko by pd9eb3124.dip.t-dialin.net with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Wed, 21 Nov 2012 20:52:36 +0100 X-Injected-Via-Gmane: http://gmane.org/ Original-Lines: 25 Original-X-Complaints-To: usenet@ger.gmane.org X-Gmane-NNTP-Posting-Host: pd9eb3124.dip.t-dialin.net User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.2.50 (gnu/linux) Cancel-Lock: sha1:5eOjYqJ7x0hz6t/k6xaZywfVm4E= X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 80.91.229.3 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:155033 Archived-At: Eli Zaretskii writes: > True. But I think this is unlikely to be a problem when _copying_ a > file, because the copy is created by you, so you get full access by > default, and that includes the "write DAC" (a.k.a. "change ACL") > privilege. However, it _can_ happen that after copying the ACL from > the original, you no longer can change the access rights, if that > privilege was denied in the original. Which is okay, I think. Well, talk to our corporate IT department then which happens to think that it is a sensible thing to not let you do this and in addition don't let you even look at the existing ACL (which means I can't be sure how they accomplished that, but I believe it's some inheritable property that makes all files, including new ones, owned by a service account). As I said, I'm almost certain you could achieve something similar with SElinux policies, but then I haven't tried it yet. Regards, Achim. -- +<[Q+ Matrix-12 WAVE#46+305 Neuron microQkb Andromeda XTk Blofeld]>+ Wavetables for the Terratec KOMPLEXER: http://Synth.Stromeko.net/Downloads.html#KomplexerWaves