Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Sticky Group permissions
Johnny
Hi Guys,
Im trying to find a way to utilise the set-group-ID bit of a directory (sticky bit some choose to call it).
The is no absolute numerical value for this according to the chmod manual under solaris.
Instead you have to use the symbolic values. eg chmod g+s dirname.
With that in mind,
are we able to set this with the submit.cfg file, which requires absolute numerical values?
John Cuiuli
Consultant
Sydney, Australia
Find more posts tagged with
Comments
tvaughan
Hey John,
Check out
this thread
from a while back.
Tom
Johnny
Thanks again Tom
I saw the post when searching for an answer, but it doesn't actually talk about submit.cfg being able to set this bit.
I have my doubts this is supported, actually I doubt whether it can ever be supported under the current backing store architecture.
Hopefully one our friendly Interwoven folk can shed some light.
John Cuiuli
Consultant
Sydney, Australia
james1
My Solaris 8 "man chmod" says:
20#0 Set group ID on execution if # is 7, 5, 3,
or 1.
-- James
--
James H Koh
Interwoven Engineering
Johnny
Yes I know but.........
On that same Solaris 8 "man chmod"
If you look at the NOTES section at the bottom it says...
Absolute changes don't work for the set-group-ID bit of a
directory. You must use g+s or g-s.
It could be refering to regular files not directories.
Though, I havent found any other answers so I may aswell try it, despite what the NOTES section says. Dont like my chances though
Thanks for your help guys.... No cookie yet though!!!
John Cuiuli
Consultant
Sydney, Australia
james1
On my Solaris 8 machine, "chmod 2777 (directory)" seems to set an unpreviously-set sticky bit.
Just try it in your submit.cfg and see what happens. I think I have seen it work a long time ago...
-- James
--
James H Koh
Interwoven Engineering
Johnny
Thanks for your help on this James.
Ill fiddle around with it a little more, but it doesnt seem to work
I cant repeat it on my machine.
chmod 2777 (directory) does not set the set-groud-id bit. Neither a file within the teamsite mount or outside of it.
Couldnt get it to work on submit.cfg either.
We are running SunOS 5.8 Generic_108528-11
Let you know if I get anywhere
John Cuiuli
Consultant
Sydney, Australia
kailash1
Hi John Cuiuli,
First some clarification here. Set-gid and sticky bit are different. Stickybit "Only the owner of a file or directory (or the super user) may change that file's or directory's mode. Only the super-user may set the sticky bit on a non- directory file. If you are not super-user, chmod will mask the sticky-bit but will not return an error. In order to turn on a file's set-group-ID bit, your own group ID must correspond to the file's and group exe- cution must be set.". Where as group ID is used to in herit permissions of that group during execution. Also If the filesystem is mounted with the nosuid option, setuid execution is not allowed.
Hope this clarifies the question. Now we can set sticky bit on submit.cfg and also set gid on submit.cfg.
Regards
Kailash
gzevin
Well - I've been telling John that this is the case, so the set-gid bit is NOT a sticky bit, but somehow he is still persisting...
Greg Zevin
Independent Interwoven Consultant/Architect
Sydney, AU
Johnny
Thanks for your value input there Greg
There has been no persistance if you actually read the post.
John Cuiuli
Consultant
Sydney, Australia
Adam Stoller
I think it may depend on who the submit.cfg process is run by (and I don't know the answer to that).
I don't have complete empirical evidence because I don't have root access on a Solaris box to verify - but on a Solaris 8 machine I created two directories (foo, bar) and did a chmod g+s foo, and chmod 2755 bar - and bar did not have the group 's' bit set.
I then performed the same test on my MacOS-X machine (different flavor of Unix - I know) where I do have root access - and the chmod 2755 bar *did* set the group 's' bit.
So it's either a root-thing or a Solaris-thing ... someone with root access on their Solaris box (you?) could probably verify.
If you cannot do it from the shell - it won't work from submit.cfg....
--fish
(Interwoven Senior Technical Consultant)
james1
> I think it may depend on who the submit.cfg process is run by
> (and I don't know the answer to that).
submit.cfg processing is performed by iwserver (at submit time), which on Solaris runs as the superuser.
-- James
--
James H Koh
Interwoven Engineering
Johnny
I also tried a similar test fish.
chmod 2777 on red hat linux works fine for a
regular
user.
I think that version of solaris is causing me grief.
John Cuiuli
Consultant
Sydney, Australia