Detailed explanation of ACL usage
ACL: access control list, mainly used to set permissions for files or directories
How to use:
Getfacl [FILE]: view this file acl permissions
Setfacl [- bkndRLPvh] [{- m |-x} acl_spec] [{- M |-X} acl_file] file.
Special permissions:
Mask permission: this permission is the maximum valid permission. When the permission set for the user or group has the same permission as the mask permission, it is the final permission.
Common options:
-m: create a new acl permission
-x: removes the specified acl permission
-b: remove all acl permissions
-d: set default acl permissions
-k: delete the default acl permission
-R: set acl permissions recursively
View the acl permissions of the current file or directory:
# getfacl test
Set acl permissions on the user:
# setfacl-m u:liu:rwx test
Set acl permissions on the group:
# setfacl-m g:tgroup:rx test
Set the maximum valid permission mask:
# setfacl-m m:rx test previously set the permission for the user liu to rwx. After setting the mask permission, the final valid permission is rx.
Remove user permissions:
# setfacl-x u:liu test can see that the permissions previously set for user liu are gone
Delete group permissions:
# setfacl-x g:tgroup test can see that the permissions previously set for the group tgroup are gone
Set recursive permissions:
# setfacl-R-m u:liu:rx test all files or directories in this directory, user liu has only rx permission
Remove all permissions:
# setfacl-b test
Set the default permissions:
# setfacl-m d:u:liu:rx test
Delete default permissions:
# setfacl-k test