git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: No fchmod() under msygit - Was: Re: [PATCH 00/14] Add submodule test harness

From
NWNico Williams <nico@cryptonector.com>
Date
Jul 14, 2014, 13:55 UTC
Message-ID
<CAK3OfOjoqOsL5GnJAC251gqRoQo_4qwKMicLSod=7ZA69SL68w@mail.gmail.com>
In-Reply-To
<CABPQNSY5x_JOsxyKn7xZ9nc5TJ0yHdNvam0htyX01U58bvV7vg@mail.gmail.com>
On Mon, Jul 14, 2014 at 6:31 AM, Erik Faye-Lund <kusmabite@gmail.com> wrote:
Show 8 quoted lines
> On Wed, Jul 9, 2014 at 10:00 PM, Eric Wong <normalperson@yhbt.net> wrote:
>> Torsten Bögershausen <tboegi@web.de> wrote:
>>
>
> You're saying this as if Windows is a single-user system. It's not,
> but it uses ACLs rather than POSIX permissions to manage file-system
> permissions. So far we've opted to ignore ACLs in Git for Windows,
> though.

The clever thing to do (that some versions of ZFS do nowadays) is to use the new mask to "edit" the ACL as follows:

 - leave any DENY ACEs as-is; for all others continue
 - remove (reset) from any ACEs for Everyone (and/or Authenticated
Users) any bits corresponding to zero'ed bits in the new mask's other
bits
 - remove from any other ACEs that are not for the owner (@OWNER in
NFSv4 speak) any bits corresponding to zero'ed bits in the new mask's
group bits
 - remove from the owner's ACEs any bits corresponding to zero'ed bits
in the new mask's owner bits, but with some exceptions, in particular
the owner must retain the right to edit the ACL
 - add (set) to the Everyone (and/or Authenticated Users) ACEs a set
of bits corresponding to the set bits in the new mask's other bits
 - add (set) either only to the ACE for the file's group
(alternatively, to all non-owner, non-Everyone/Authenticated Users
ACEs) a set of bits corresponding to the set bits in the new mask's
group bits
...

I.e., use the chmod mask to decrease/increase access without changing the "shape" of the ACL.

Determining a file's mode_t from an ACL is similar, though it must take DENY entries into account: make a set of users/groups referred to by any ACEs in the ACL, divide them into owner, other (Everyone and/or Authenticated Users), and group (all others), find the maximal access granted.

Still, git might like to know what ACLs to apply to files at checkout time. That would be a vast new feature, I think, and probably not worth it, particularly since that would require dealing with the different types of ACLs: NTFS/NFSv4/ZFS on the one hand, POSIX Draft on the other, plus AFS and who knows what else -- ETOOMUCH IMO.

Nico --

Previous: Erik Faye-LundNext: Nico Williams
Message 45 of 65 in “Add submodule test harness”
  1. 00/14 Add submodule test harnessJens Lehmann, Jun 15, 2014
  2. 01/14 test-lib: add test_dir_is_empty()Jens Lehmann, Jun 15, 2014
  3. Junio C HamanoJun 16, 2014
  4. Jens LehmannJun 17, 2014
  5. 01/14 test-lib: add test_dir_is_empty()Jens Lehmann, Jun 19, 2014
  6. 02/14 submodules: Add the lib-submodule-update.sh test libraryJens Lehmann, Jun 15, 2014
  7. Junio C HamanoJun 16, 2014
  8. Jens LehmannJun 17, 2014
  9. Junio C HamanoJun 17, 2014
  10. Jens LehmannJun 17, 2014
  11. Junio C HamanoJun 17, 2014
  12. 02/14 submodules: Add the lib-submodule-update.sh test libraryJens Lehmann, Jun 19, 2014
  13. Junio C HamanoJun 20, 2014
  14. 02/14 submodules: Add the lib-submodule-update.sh test libraryJens Lehmann, Jul 1, 2014
  15. 03/14 checkout: call the new submodule update test frameworkJens Lehmann, Jun 15, 2014
  16. 04/14 apply: add t4137 for submodule updatesJens Lehmann, Jun 15, 2014
  17. 05/14 read-tree: add t1013 for submodule updatesJens Lehmann, Jun 15, 2014
  18. 06/14 reset: add t7112 for submodule updatesJens Lehmann, Jun 15, 2014
  19. 07/14 bisect: add t6041 for submodule updatesJens Lehmann, Jun 15, 2014
  20. 07/14 bisect: add t6041 for submodule updatesJens Lehmann, Jun 19, 2014
  21. 08/14 merge: add t7613 for submodule updatesJens Lehmann, Jun 15, 2014
  22. 09/14 rebase: add t3426 for submodule updatesJens Lehmann, Jun 15, 2014
  23. Eric SunshineJun 16, 2014
  24. Jens LehmannJun 17, 2014
  25. 09/14 rebase: add t3426 for submodule updatesJens Lehmann, Jun 19, 2014
  26. 10/14 pull: add t5572 for submodule updatesJens Lehmann, Jun 15, 2014
  27. 11/14 cherry-pick: add t3512 for submodule updatesJens Lehmann, Jun 15, 2014
  28. 12/14 am: add t4255 for submodule updatesJens Lehmann, Jun 15, 2014
  29. 13/14 stash: add t3906 for submodule updatesJens Lehmann, Jun 15, 2014
  30. 13/14 stash: add t3906 for submodule updatesJens Lehmann, Jun 19, 2014
  31. 14/14 revert: add t3513 for submodule updatesJens Lehmann, Jun 15, 2014
  32. 14/14 revert: add t3513 for submodule updatesJens Lehmann, Jun 19, 2014
  33. Torsten BögershausenJul 2, 2014
  34. Jens LehmannJul 2, 2014
  35. Torsten BögershausenJul 3, 2014
  36. Jens LehmannJul 3, 2014
  37. Junio C HamanoJul 7, 2014
  38. Torsten BögershausenJul 7, 2014
  39. Jens LehmannJul 8, 2014
  40. Ramsay JonesJul 8, 2014
  41. Ramsay JonesJul 8, 2014
  42. No fchmod() under msygit - Was: Re: [PATCH 00/14] Add submodule test harnessTorsten Bögershausen, Jul 9, 2014
  43. Eric WongJul 9, 2014
  44. Erik Faye-LundJul 14, 2014
  45. Nico WilliamsJul 14, 2014
  46. Nico WilliamsJul 14, 2014
  47. Karsten BleesJul 14, 2014
  48. Junio C HamanoJul 14, 2014
  49. Torsten BögershausenJul 9, 2014
  50. Junio C HamanoJul 9, 2014
  51. Jens LehmannJul 9, 2014
  52. Junio C HamanoJul 9, 2014
  53. Junio C HamanoJul 10, 2014
  54. Jens LehmannJul 12, 2014
  55. Junio C HamanoJul 14, 2014
  56. Jens LehmannJul 14, 2014
  57. Junio C HamanoJul 14, 2014
  58. Johannes SixtJul 9, 2014
  59. Junio C HamanoJul 9, 2014
  60. Eric WongJul 9, 2014
  61. Junio C HamanoJul 9, 2014
  62. No fchmd. was: Re: [PATCH 00/14] Add submodule test harnessTorsten Bögershausen, Jul 10, 2014
  63. Junio C HamanoJul 10, 2014
  64. Torsten BögershausenJul 10, 2014
  65. Junio C HamanoJul 10, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.