From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 96682 invoked by alias); 5 Mar 2016 10:01:41 -0000 Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm Precedence: bulk List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner@cygwin.com Mail-Followup-To: cygwin@cygwin.com Received: (qmail 96661 invoked by uid 89); 5 Mar 2016 10:01:40 -0000 Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=-93.9 required=5.0 tests=BAYES_50,KAM_LAZY_DOMAIN_SECURITY,RCVD_IN_PBL,RDNS_DYNAMIC,USER_IN_WHITELIST autolearn=no version=3.3.2 spammy=H*R:U*cygwin, DOT, deny, Sometimes X-HELO: calimero.vinschen.de Received: from ipbcc0d020.dynamic.kabel-deutschland.de (HELO calimero.vinschen.de) (188.192.208.32) by sourceware.org (qpsmtpd/0.93/v0.84-503-g423c35a) with ESMTP; Sat, 05 Mar 2016 10:01:39 +0000 Received: by calimero.vinschen.de (Postfix, from userid 500) id 94443A8062F; Sat, 5 Mar 2016 11:01:37 +0100 (CET) Date: Sat, 05 Mar 2016 10:01:00 -0000 From: Corinna Vinschen To: cygwin@cygwin.com Subject: Re: Issues with ACL settings after updating to the latest cygwin.dll - correction Message-ID: <20160305100137.GB3860@calimero.vinschen.de> Reply-To: cygwin@cygwin.com Mail-Followup-To: cygwin@cygwin.com References: <2119166713.121814507.1457103633265.JavaMail.root@zimbra93-e16.priv.proxad.net> <550385091.121913198.1457106187258.JavaMail.root@zimbra93-e16.priv.proxad.net> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="cNdxnHkX5QqsyA0e" Content-Disposition: inline In-Reply-To: <550385091.121913198.1457106187258.JavaMail.root@zimbra93-e16.priv.proxad.net> User-Agent: Mutt/1.5.24 (2015-08-30) X-SW-Source: 2016-03/txt/msg00044.txt.bz2 --cNdxnHkX5QqsyA0e Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-length: 2255 Hi Akiki(?), On Mar 4 16:43, akikij@free.fr wrote: > Hi, > I have the different problems you have about this new security right NULL= SID DENY added to some files. I still doubt the NULL ACE is the actual culprit of whatever you observe. A NULL ACE doesn't affect your permissions, unless you have a NULL SID in your user token, which is extremly unlikely. > Sometimes also Windows can't access files concerned. > He considered security rigths unordered and I have to class them before c= ontinue. > It's too difficult for me to help you to correct the problem. No, I don't think so. First of all, the order in the ACL is deliberate to provide an emulation of POSIX permissions. Don't reorder the ACL using Windows means, this *will* break the ACL evaluation. Please also note that the Windows OS does *not* fail to evaluate an ACL just because it's not in the so-called "canonical order". The OS strictly evaluates the ACL top-down, from the first to the last ACE, without worrying about the order. Only the GUI and certain Windows tools written to manipulate an ACL (e.g. icacls) will choke on such ACLs. Don't use such tools on Cygwin-created ACLs. Use Cygwin's chmod, chown, and setfacl for this. My problem is this: You're the third person on this list reporting a problem along the lines of "ACL doesn't work with Windows", without giving me a clear reproducer. What I need is a clear description what *exactly* you do and what *exactly* fails. I assume you created a file using some Cygwin tool and then try to access it from non-Cygwin tools. Are you unable to read or write the file using that Windows tool? Are you expecting to double click on the file to execute something? I really need a=20 simple description which is easily reproduced using Windows system tools. What I then also need is that you do *NOT* try to *fix* the ACL, but rather send me - icacls output of the file and its parent dir - getfacl output of the file and its parent dir *If* there's a real problem, I need to be able to reproduce it, otherwise I won't be able to fix it in Cygwin. Thanks, Corinna --=20 Corinna Vinschen Please, send mails regarding Cygwin to Cygwin Maintainer cygwin AT cygwin DOT com Red Hat --cNdxnHkX5QqsyA0e Content-Type: application/pgp-signature; name="signature.asc" Content-length: 819 -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJW2q6BAAoJEPU2Bp2uRE+gQpIQAKV5Spu1GFrrWkupL4rtOaN1 yG5jdDKQ9NdvXKSHhEwlohB21X7nz6+Jlp8QKd/Y9L8r5ytFW+6JCXksicaEzZLK neUQN3J3VNj9BiZ8Vjp/dM4MMvit0T+0OpttCv4aPNHFUQZ+A7xU71xaUtXxMlc9 WzQAriK2sc+guO7HDUqow3+wPY7xk/FricFxIr2u7ebycaaop9R8lF+m9bFvHYzo F5W9mkyIKrNlmzmr9KS/ReTUdk0su8JI0sN9oF0ty2YLKCuu83Dsqiq5FpBXogy/ /l2wgOtSJUldvvp4SD9ZEgff6MGCZvqGGlBrS5b965xjUL3mX06JBxFvcQEgPsKy 38bXMpAAX5dvcnochDHlDHQtHQ8icy6De0/XyMnPU2b0zLV9s6vvid8/qN6b9Ogi m/i2730sFKHZX8Xo+uuj8dVnxO78z2o3JOpGvryK34dQAJFiyJARl58Ga7mXBGrG pCYd8PC7Waf+exzqtRLnP8b9poZdFLSbBnloBq9qwPumTJAccp1NbpjTSBRSqX6U renO+Sm0VFgHkFQlk39qOFL1+OOPrDQjUZD1m67Ko7eNOAgJ7qCTHev3fYrFOHqt Don+zWnwJPHCTL03+g+vB89FFyTtstn1Wx8Nm178hk/UB4tnfIuwpZ6H0hkT/iMN nqRLQWR3rj/UgK1vCADj =iAIa -----END PGP SIGNATURE----- --cNdxnHkX5QqsyA0e--