question about acl permission.
Files that could be deleted with freeBSD12 cannot be deleted with FreeBS13.
I updated os from freebsd12.0 to freensd13.2, and updated samba from Version 4.8.12 to Version 4.19.7.
via samba, user can delete/rename and file in freebsd12.0, but can't delete/rename file in freebsd13.2.
settings about permission are listed below.
if below settings, user can delete/file.
or
or
Files that could be deleted with freeBSD12 cannot be deleted with FreeBS13.
I updated os from freebsd12.0 to freensd13.2, and updated samba from Version 4.8.12 to Version 4.19.7.
via samba, user can delete/rename and file in freebsd12.0, but can't delete/rename file in freebsd13.2.
settings about permission are listed below.
Code:
# getfacl /nas/home/user
# file: /nas/home/user
# owner: root
# group: cifsusers
group@:rw-p--aARWc---:f-i----:allow
group@:rwxp--aARWc---:-di----:allow
user:apiadmin:rwxp--a-R-c---:-------:allow
user:user_name:rwxp--a-R-c---:-------:allow
owner@:rwxp--aARWcCos:-------:allow
group@:------a-R-c--s:-------:allow
everyone@:------a-R-c--s:-------:allow
Code:
# pw show user user
user:*:1120:1001::0:0:User &:/nas/home/user:/usr/sbin/nologin
# pw show group cifsusers
cifsusers:*:1001:
Code:
# ls -la /nas/home/user
total 5211
drwx------+ 7 root cifsusers 30 Sep 30 00:39 .
if below settings, user can delete/file.
Code:
# getfacl /nas/home/user
# file: /nas/home/user
# owner: root
# group: cifsusers
group@:rw----a-R-c--s:-------:allow
group@:rw-p--aARWc---:f-i----:allow
group@:rwxp--aARWc---:-di----:allow
user:apiadmin:rwxp--a-R-c---:-------:allow
user:user:rwxp--a-R-c---:-------:allow
owner@:rwxp--aARWcCos:-------:allow
group@:------a-R-c--s:-------:allow
everyone@:------a-R-c--s:-------:allow
Code:
# getfacl /nas/home/user
# file: /nas/home/user
# owner: root
# group: cifsusers
user:user:rwxpDda-R-c---:-------:allow
group@:rw-p--aARWc---:f-i----:allow
group@:rwxp--aARWc---:-di----:allow
user:apiadmin:rwxp--a-R-c---:-------:allow
user:user:rwxp--a-R-c---:-------:allow
owner@:rwxp--aARWcCos:-------:allow
group@:------a-R-c--s:-------:allow
everyone@:------a-R-c--s:-------:allow
or
chmod 770 /nas/home/user