Cloud Engineering/Linux ๐Ÿง

[Linux] Default POSIX ACL ENTRY (๊ธฐ๋ณธ ACL)

minjiwoo 2023. 1. 4. 13:31
728x90

์ผ๋ฐ˜ ACL๊ณผ ๋‹ค๋ฅด๊ฒŒ ์•ž์— d:๊ฐ€ ๋ถ™๋Š”๋‹ค. Default ACL์€ ์ผ๋ฐ˜ ACL๊ณผ ๋‹ฌ๋ฆฌ, ๋””๋ ‰ํ† ๋ฆฌ์—๋งŒ ๋ถ€์—ฌํ•  ์ˆ˜ ์žˆ๋‹ค. 

Default ACL์—์„œ ํผ๋ฏธ์…œ

d:u::PERMS                     ํŒŒ์ผ์˜ ์†Œ์œ ์ž
d:u:USER:PERMS           ํŠน์ • ์‚ฌ์šฉ์ž
d:g::PERMS                     ํŒŒ์ผ์˜ ์†Œ์œ  ๊ทธ๋ฃน
d:g:GROUP:PERMS       ํŠน์ • ๊ทธ๋ฃน
d:o::PERMS                     ๊ธฐํƒ€ ์‚ฌ์šฉ์ž

Default ACL ์„ค์ •

์•„๋ž˜ ๋‘๊ฐ€์ง€ ๋ช…๋ น์–ด๋Š” ๊ฐ™์€ ์˜๋ฏธ๋กœ, default acl ๋ฅผ ์„ค์ •ํ•˜๋Š” ๋ช…๋ น์–ด์ด๋‹ค.

$ setfacl -m d:ACL_ENTRY DIRECTORY

๋””๋ ‰ํ† ๋ฆฌ์—๋งŒ ์ ์šฉํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ผ๋ฐ˜ acl๋ฅผ ํ•˜์œ„ ํŒŒ์ผ์—๊ฒŒ ์ ์šฉ์‹œ์ผœ์ค€๋‹ค.

$ setfacl -d -m ACL_ENTRY DIRECTORY

-d ์˜ต์…˜์€ default acl ์„ค์ •ํ•˜๋Š” ์˜ต์…˜์ด๋‹ค. ๋’ค์—๋Š” ์ผ๋ฐ˜ acl๋ฌธ๋ฒ•์œผ๋กœ ์ ์–ด์ฃผ๋ฉด ๋œ๋‹ค.

 

Default ACL : ACL ์ œ๊ฑฐ

$ setfacl -x DEFAULT_ACL_ENTRY DIRECTORY

 

Default ACL ๋ชจ๋‘ ์‚ญ์ œํ•˜๊ธฐ

$ setfacl -k DIRECTORY



Default ACL ์„ค์ • ์˜ˆ์‹œ 

[user@localhost work]$ setfacl -m d:u:staff01:rwX dir3

staff01์ด dir3์— ๋Œ€ํ•ด default acl ๋ถ€์—ฌํ•˜๊ณ  ์žˆ๋‹ค. ๊ถŒํ•œ์€ rwX ํผ๋ฏธ์…˜์„ ๋ถ€์—ฌํ•œ๋‹ค. 
์ž˜ ์ ์šฉ์ด ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด์„œ getfacl ๋ช…๋ น์–ด๋ฅผ ์จ์„œ dir3์˜ acl ๋ฅผ ํ™•์ธํ•œ๋‹ค. 

[user@localhost work]$ getfacl dir3
# file: dir3
# owner: user
# group: user
user::rwx
group::rwx
other::r-x
default:user::rwx
default:user:staff01:rwx
default:group::rwx
default:mask::rwx
default:other::r-x

dir3์— default ACL ์ ์šฉํ•œ ๊ฒฐ๊ณผ๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. default: ~์ดํ›„์˜ ๋‚ด์šฉ๋“ค์ด default ACL ๊ถŒํ•œ ๋‚ด์šฉ์ด๋‹ค. 

[user@localhost work]$ ls -lR dir3
dir3:
ํ•ฉ๊ณ„ 0
drwxrwxr-x+ 2 user user 23 1์›” 4 11:24 subdir1
drwxrwxr-x+ 2 user user 6 1์›” 4 11:24 subdir2
drwxrwxr-x+ 2 user user 6 1์›” 4 11:24 subdir3
-rw-rw-r--+ 1 user user 0 1์›” 4 11:23 userfile1
-rw-rw-r--+ 1 user user 0 1์›” 4 11:23 userfile2

dir3/subdir1: ํ•ฉ๊ณ„ 0
-rw-rw-r--+ 1 user user 0 1์›” 4 11:24 userfilea
dir3/subdir2: ํ•ฉ๊ณ„ 0
dir3/subdir3: ํ•ฉ๊ณ„ 0

default acl ๋ฅผ ์ ์šฉํ•œ ํ›„ dir3์˜ ํ•˜์œ„ ๋””๋ ‰ํ† ๋ฆฌ์—๋„ ACL์ด ์ƒ์†๋˜์–ด์„œ ์ ์šฉ๋œ๋‹ค. 

[user@localhost work]$ getfacl dir3/subdir3
# file: dir3/subdir3
# owner: user
# group: user
user::rwx
user:staff01:rwx
group::rwx
mask::rwx
other::r-x
default:user::rwx
default:user:staff01:rwx
default:group::rwx
default:mask::rwx
default:other::r-x


๋˜ํ•œ dir3์˜ ํ•˜์œ„ ํŒŒ์ผ์—๋„ ACL์ด ์ ์šฉ๋˜์—ˆ๋‹ค. dir3 ํ•˜์œ„์— ๋ฏธ๋ฆฌ ์ƒ์„ฑํ•ด๋‘์—ˆ๋˜ userfile1์˜ ๋‚ด์šฉ์„ ํ™•์ธํ•˜๋ฉด, ์ผ๋ฐ˜ ACL์ด ์ ์šฉ๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. 

[user@localhost work]$ getfacl dir3/userfile1
# file: dir3/userfile1
# owner: user
# group: user
user::rw-
user:staff01:rwx #effective:rw-
group::rwx #effective:rw-
mask::rw-
other::r--

 

728x90