Re: Choice of default of --alter=atime or ctime

Denis Corbin <[email protected]> Mon, 06 Mar 2006 16:35:36 +0100
Newsgroups gmane.comp.sysutils.backup.dar.general
Message-ID <[email protected]>
Wiebe Cazemier wrote:
> I'd like to bring up an issue about what file property to preserve by
> default (when doing a backup for example), ctime or atime. It's somewhat
> of a long mail, so please bear with me :)
> 
> Currently, dar's default is to preserve the atime of file that is read,
> thereby changing it's ctime. Is this a logical default? Isn't it more
> logical for the default action that the access time of a file changes,
> because after all, it _is_ accessed. By changing the ctime, you imply
> that something has changed, when in fact nothing has.

yes,

> 
> I think it's very good dar has the option, but in my opinion, the
> default should be to preserve ctime (in essence, preserve nothing). This
> opinion has three bases:
> 
> 1) It is in accordance with what atime, mtime and ctime were designed to
> represent.

agreeded,

> 
> 2) Any package which is sensative to atime changing is flakey, because
> atimes may very well be altered by other programs, such as beagle (which
> indexes your files, in smart way). Ctimes however, are important, for
> security software for example (as you stated in the manpage), because a
> ctime is the only way to detect possible replacement of system commands
> with rootkits, for example.

agreeded,

> 
> 3) Atimes of system files can be changed by normal users.
> 
> Also, the "--alter" command seems inverted, if you know what I mean. For
> example, alter=atime, it implies action, while in fact, it does nothing.
> I think something "--preserve-..." would be better. Or better yet, if
> you agree with me and change the default behaviour, only one option like
> --preserve-ctimes would be needed, and no for atimes.

well, the --alter=* is more general, it means an alteration of dar's 
default behavior. This is only a technical way to overcome the 
limitation of letters in the alphabet and thus the number of available 
options on command-line.

> 
> As a final note, the manpage is kind of unlear about the
> --alter=ctime/atime feature. I had to read it a few times, and test for
> myself before I understood what really happens. This is the secton:
> 
> -aa, --alter=atime  when reading a filesystem, while doing a backup (-c
> option)
> or  comparing  (-d  option)  by default  dar tries to be as much
> transparent as
> possible, and set back the last access time (atime) of read files and
> directories, as if they have not been read. But, preserving atime of  read
> files, make their ctime to be changed (last inode change). There is no
> possibility to preserve both atime and ctime. If you want to overcome the
> default original behavior  of dar  and want to keep ctime unchanged, the
> --alter=atime is for you. Some security software rely on the ctime to be
> preserved, some other software rely on the atime  to  be  preserved like
> leafnode NNTP caching software.
> 
> -ac, --alter=ctime  set back the date alteration to ctime (see --alter=atime
> above), this is the default behav- ior. The use of this switch is to
> override
> the -aa option in  dar  configuration  files  or command-line  (see  -B
> option). From -aa and -ac the one which is last parsed from command- line or
> included files takes the win.
> 
> For -ac, something like "preserve the atime of a file, resulting in a
> changed ctime. See -aa above for more info on the matter." It is only an
> example to illustrate. What is says now at -ac is really confusing, and
> I believe even incorrect. But, should you agree with my suggestions

we will try to improve that (my English is far from being perfect ;-) I 
know). If we have a lot of freedom in the writing of a man page, it is 
not the case about the choice of what command will be used for what 
feature on command line...

> (change of default behaviour and a --preserve-ctimes option) and accept
> them, these sections will need to rewritten anyway :)

In fact, the current behavior of dar is due to its history. In its early 
versions (still using it by the way). I found that the cache could not 
expire files due to dar's backup, thus I decided to make dar even more 
transparent, in the way you know today, that it does not change atime, 
but set it back to its original values. At that time, I already found 
that ctime was not possible to set, thus it was not necessary to backup 
it, as I was not using any security tool re back atime would around, 
somebody complained about the fact that dar changed ctime of any file. 
Where comes the -aa option. I had already thought about changing the 
default behavior of dar, but after 4 years, nobody complained about that 
so it was still in the stack but always behind a higher priority task.

So yes, we will change that feature's default behavior.

> 
> Regards,
> 
> Wiebe Cazemier

Regards,
Denis.
signature.asc (application/pgp-signature, 252 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFEDFbYpC5CI8gYGlIRAroXAKDDjEQJOaftASZ8PJp9UysCkkjw1QCggylS
AUyQxIRz4CwJdDUTTlcBUkw=
=zb/R
-----END PGP SIGNATURE-----