4 merge requests!368Update prace.md to document the change from qprace to qprod as the default...,!367Update prace.md to document the change from qprace to qprod as the default...,!366Update prace.md to document the change from qprace to qprod as the default...,!323extended-acls-storage-section
@@ -227,34 +227,24 @@ Extended ACLs provide another security mechanism beside the standard POSIX ACLs
ACLs on a Lustre file system work exactly like ACLs on any Linux file system. They are manipulated with the standard tools in the standard manner. Below, we create a directory and allow a specific user access.
*[nfs4_setfacl][e]
*[nfs4_getfacl][l]
```console
[vop999@login1.barbora ~]$umask 027
[vop999@login1.barbora ~]$mkdir test
[vop999@login1.barbora ~]$ls-ldtest
drwxr-x--- 2 vop999 vop999 4096 Nov 5 14:17 test
[vop999@login1.barbora ~]$getfacl test
vop999@login1:~$nfs4_getfacl test
#file: test
#owner: vop999
#group: vop999
user::rwx
group::r-x
other::---
[vop999@login1.barbora ~]$setfacl -m user:johnsm:rwx test
[vop999@login1.barbora ~]$ls-ldtest
drwxrwx---+ 2 vop999 vop999 4096 Nov 5 14:17 test
[vop999@login1.barbora ~]$getfacl test
A::OWNER@:rwaxtTcCy
A::GROUP@:rwatcy
A::EVERYONE@:rtcy
vop999@login1:~$nfs4_setfacl -a A::GROUP@:RWX test
vop999@login1:~$nfs4_getfacl test
#file: test
#owner: vop999
#group: vop999
user::rwx
user:johnsm:rwx
group::r-x
mask::rwx
other::---
A::OWNER@:rwaxtTcCy
A::GROUP@:rwaxtcy
A::EVERYONE@:rtcy
```
Default ACL mechanism can be used to replace setuid/setgid permissions on directories. Setting a default ACL on a directory (-d flag to setfacl) will cause the ACL permissions to be inherited by any newly created file or subdirectory within the directory. Refer to this page for more information on Linux ACL at [RedHat guide][e].
Default ACL mechanism can be used to replace setuid/setgid permissions on directories. Setting a default ACL on a directory will cause the ACL permissions to be inherited by any newly created file or subdirectory within the directory.
## Local Filesystems
...
...
@@ -378,10 +368,11 @@ Transfer rates of about 28 MB/s can be expected.