Newbie greetings

John Logsdon <[email protected]> Wed, 2 Feb 2005 16:17:43 +0000 (GMT)
Newsgroups gmane.linux.file-systems.acl.devel
Message-ID <[email protected]>
Hello all

I have been looking at POSIX ACLs for a bit and thinking this will solve
some of my issues so that users can more easily share data since standard
Unix groups only allow single group/user access at any one time.  It
avoids creating excessive numbers of groups where there are a lot of
combinations.

I have a few questions.  My setup is currently running a Fedora Core 2 but
with a customised 2.4.29 kernel - that is including the grsecurity 2.1.1
patches.  It is using reiserfs but unless some really new patch is
available very soon, I can change the /home directory to xfs which seems
to be the most complete and (with 512 byte inodes) fastest. There are
other reasons for using XFS.  I don't want to move to 2.6 yet - I keep
reading about new issues that arise so I am not convinced it is ready for
a production system (I am sure some will disagree with this!).

The grsec ACLs - which are completely different - can be used to control
access to all the system files and very fine-grained control over what
program does what whereas POSIX ACLs and standard DAC are good for user
directories.  They also empower the user themselves to do some things.

Has anyone on the list co-patched grsec and POSIX?  I checked the patches
- there are only 3 possible conflicts, from the latest 2.4.29 patch today:

linux-2.4.29/fs/namei.c
linux-2.4.29/kernel/fork.c
linux-2.4.29/kernel/ksyms.c (in 2 places)

TIA

John

John Logsdon                               "Try to make things as simple
Quantex Research Ltd, Manchester UK         as possible but not simpler"
[email protected]              [email protected]
+44(0)161 445 4951/G:+44(0)7717758675       www.quantex-research.com


_______________________________________________
acl-devel mailing list
[email protected]
http://acl.bestbits.at/mailman/listinfo/acl-devel