Lab 6.3 - ACLs - Wrong solution, misunderstanding or typo?
Hi, it's Pablo, evolving throw the LFS203 course learning.
Hope you all are well.
I got confused with the lab 6.3 while following the solution procedure I obtain different results.
As you can see later in the outputs, they do not correspond to what is shown in the LAB.
Here is the output of the terminals I used (usernames are my dogs' names ^^):
Steps 1 to 4:
Terminal 1 (user "mago"):
[mago@centos9 test]$ echo "This is a file" > afile
[mago@centos9 test]$ getfacl afile
file: afile
owner: mago
group: mago
user::rw-
group::r--
other::r--
[mago@centos9 test]$ setfacl -m u:kio:rw afile
[mago@centos9 test]$ getfacl afile
file: afile
owner: mago
group: mago
user::rw-
user:kio:rw-
group::r--
mask::rw-
other::r--
Terminal 2 (user kio):
[kio@centos9 test]$ ls -alrt
total 8
drwxrwxrwt. 19 root root 4096 mar 18 08:39 ..
-rw-r--r--. 1 mago mago 15 mar 18 08:40 afile
drwxr-xr-x. 2 mago mago 19 mar 18 08:40 .
[kio@centos9 test]$ echo "another line" >> afile
(It is all ok until here)
Step 5:
Terminal 1 (user "mago"):
[mago@centos9 test]$ setfacl -m u:kio:w afile
[mago@centos9 test]$ getfacl afile
file: afile
owner: mago
group: mago
user::rw-
user:kio:-w-
group::r--
mask::rw-
other::r--
[mago@centos9 test]$
Terminal 2 (user kio):
[kio@centos9 test]$ echo "another line" >> afile
[kio@centos9 test]$
Step 6 (added by myself):
Terminal 1 (user "mago"):
[mago@centos9 test]$ cat afile
This is a file
another line
another line
[mago@centos9 test]$ getfacl afile
file: afile
owner: mago
group: mago
user::rw-
user:kio:-w-
group::r--
mask::rw-
other::r--
Terminal 2 (user kio):
[kio@centos9 test]$ cat afile
cat: afile: Permiso denegado
[kio@centos9 test]$ echo "another line" >> afile
[kio@centos9 test]$
This makes me getting confused about ACLs, but I really think there is something wrong with the outputs shown in the LAB solution because of the solution shown here by me is very logical when following the Linux convention about file permissions:
owner can write and read the file.
"kio" can write to "afile", but can't read from it.
Let me know what you think about, please.
Thanks in advance for your replies.
Kind regards,
Pablo.
Comments
-
Hi Pablo,
I went through Lab 6.3 on CentOS Stream 10 and it worked for me. I also see in your outputs it worked for you as well.
On item 5 we removed the read permission over the file 'afile', so you can write on it but you can't read it -you can't 'cat' it, right? This is for examples only, for showing what you can do with the tool; perhaps you got confused on the application of this?
Regards,
Luis.0 -
Hi Luis, thanks for your reply.
I tested the lab on Centos 9, inside /tmp/test directory, but I don't think is a matter of the machine, I really think there is a mistake in the outputs shown by the solution.
What I am trying to explain is that the command "setfacl -m u:fool:w /tmp/afile" is still giving +w permission to fool user (as noted in the line "user:kio:-w-" of my first post), so the last message about "Permission denied" (bold line) is not truly occuring, for me at least.
The solution's text shows the following:
In window 1:
\$ setfacl -m u:fool:rw /tmp/afile
\$ getfacl /tmp/afile
getfacl: Removing leading '/' from absolute path names
# file: tmp/afile
# owner: coop
# group: coop
user::rw-
user:fool:rw-
group::rw-
mask::rwx
other::r--In window 2:
$ echo another line > /tmp/afile
5. In window 1:
$ setfacl -m u:fool:w /tmp/afileIn window 2:
$ echo another line > /tmp/afile
-bash: /tmp/afile: Permission denied
\$ rm /tmp/afile
\$ sudo userdel -r foolSorry if I am wrong, and thanks a lot for your time.
Kind regards,
Pablo.0 -
Hi Pablo,
I get it now. In my case I'm using these two users:
1) luis.
2) eduardo.3) So, I ran 'setfacl -m u:eduardo:w /tmp/afile' and it got like this:
luis@centoserver:/tmp$ getfacl afile
file: afile
owner: luis
group: luis
user::rw-
user:eduardo:-w-
group::r--
mask::rw-
other::r--So the 'eduardo' user can write but not read, right? That's what make sense here.
In the 'eduardo' 's terminal it should file reading the file and should work to write on it:
eduardo@centoserver:/tmp$ cat afile
cat: afile: Permission deniededuardo@centoserver:/tmp$ echo another line > /tmp/afile
So try that in your system, please. I hope it make sense now!
Regards,
Luis.0 -
Hi Luis,
I totally agree with you, sorry if I could not explain it well.
Anyway, just to clarify things, what we are in agreement to is different to what lab solution shows.
In the document I read the following at the end ot the solution:In window 1:
$ setfacl -m u:fool:w /tmp/afileIn window 2:
$ echo another line > /tmp/afile
-bash: /tmp/afile: Permission denied
$ rm /tmp/afile
$ sudo userdel -r foolSo, the "echo anocher line > /tmp/afile" should work, as you explained before, being it different to "cat /tmp/afile" (which should not work and through "permission denied")
Best regards,
Pablo.0 -
Hi Pablo,
Yes, that's correct. I'll inform the team about this so we can correct it.
Say 'hi' from me to Mago and Kio

Luis.
1
Categories
- All Categories
- 164 LFX Mentorship
- 164 LFX Mentorship: Linux Kernel
- 724 Linux Foundation IT Professional Programs
- 368 Cloud Engineer IT Professional Program
- 161 Advanced Cloud Engineer IT Professional Program
- 69 DevOps IT Professional Program - Discontinued
- 1 DevOps & GitOps IT Professional Program
- 94 Cloud Native Developer IT Professional Program
- 33 Express Training Courses & Microlearning
- 31 Express Courses - Discussion Forum
- 2 Microlearning - Discussion Forum
- 7.4K Training Courses
- 25 LFC110 Class Forum - Discontinued
- 15 LFC131 Class Forum - DISCONTINUED
- 54 LFD102 Class Forum
- 254 LFD103 Class Forum
- 1 LFD103-JP クラス フォーラム
- 17 LFD110 Class Forum
- LFD114 Class Forum
- 54 LFD121 Class Forum
- 3 LFD123 Class Forum
- 2 LFD125 Class Forum
- 3 LFD133 Class Forum
- 4 LFD134 Class Forum
- 4 LFD137 Class Forum
- 1 LFD140 Class Forum
- 66 LFD201 Class Forum
- 7 LFD210 Class Forum
- 3 LFD210-CN Class Forum
- 1 LFD213 Class Forum - Discontinued
- 1 LFD221 Class Forum
- 127 LFD232 Class Forum - Discontinued
- 2 LFD233 Class Forum - Discontinued
- 4 LFD237 Class Forum
- 24 LFD254 Class Forum
- 758 LFD259 Class Forum
- 110 LFD272 Class Forum - Discontinued
- 2 LFD272-JP クラス フォーラム - Discontinued
- 22 LFD273 Class Forum
- 652 LFS101 Class Forum
- 4 LFS111 Class Forum - Discontinued
- 2 LFS112 Class Forum
- LFS114 Class Forum
- 4 LFS116 Class Forum
- 6 LFS118 Class Forum
- 2 LFS120 Class Forum
- LFS140 Class Forum
- 11 LFS142 Class Forum
- 9 LFS144 Class Forum
- 5 LFS145 Class Forum
- 6 LFS146 Class Forum
- 7 LFS147 Class Forum
- 26 LFS148 Class Forum
- 22 LFS151 Class Forum - Discontinued
- 4 LFS157 Class Forum
- 162 LFS158 Class Forum
- 1 LFS158-JP クラス フォーラム
- 17 LFS162 Class Forum
- 1 LFS166 Class Forum - Discontinued
- 8 LFS167 Class Forum
- 4 LFS170 Class Forum
- 1 LFS171 Class Forum - Discontinued
- 3 LFS178 Class Forum - Discontinued
- 3 LFS180 Class Forum
- 2 LFS182 Class Forum
- 6 LFS183 Class Forum
- 2 LFS184 Class Forum
- 42 LFS200 Class Forum
- 736 LFS201 Class Forum - Discontinued
- 2 LFS201-JP クラス フォーラム - Discontinued
- 23 LFS203 Class Forum
- 150 LFS207 Class Forum
- 2 LFS207-DE-Klassenforum
- 3 LFS207-JP クラス フォーラム
- 301 LFS211 Class Forum - Discontinued
- 55 LFS216 Class Forum - Discontinued
- 60 LFS241 Class Forum
- 51 LFS242 Class Forum
- 41 LFS243 Class Forum
- 18 LFS244 Class Forum
- 8 LFS245 Class Forum
- 1 LFS246 Class Forum
- 1 LFS248 Class Forum
- 160 LFS250 Class Forum
- 3 LFS250-JP クラス フォーラム
- 2 LFS251 Class Forum - Discontinued
- 164 LFS253 Class Forum
- 1 LFS254 Class Forum - Discontinued
- 3 LFS255 Class Forum
- 18 LFS256 Class Forum
- 2 LFS257 Class Forum
- 1.4K LFS258 Class Forum
- 12 LFS258-JP クラス フォーラム
- 149 LFS260 Class Forum
- 164 LFS261 Class Forum
- 45 LFS262 Class Forum
- 82 LFS263 Class Forum - Discontinued
- 15 LFS264 Class Forum - Discontinued
- 11 LFS266 Class Forum - Discontinued
- 25 LFS267 Class Forum
- 27 LFS268 Class Forum
- 38 LFS269 Class Forum
- 10 LFS270 Class Forum
- 202 LFS272 Class Forum - Discontinued
- 2 LFS272-JP クラス フォーラム - Discontinued
- 1 LFS274 Class Forum - Discontinued
- 4 LFS281 Class Forum - Discontinued
- 32 LFW111 Class Forum
- 265 LFW211 Class Forum - Discontinued
- 190 LFW212 Class Forum - Discontinued
- 18 SKF100 Class Forum
- 2 SKF200 Class Forum
- 3 SKF201 Class Forum
- 789 Hardware
- 202 Drivers
- 68 I/O Devices
- 37 Monitors
- 95 Multimedia
- 173 Networking
- 89 Printers & Scanners
- 86 Storage
- 764 Linux Distributions
- 81 Debian
- 67 Fedora
- 20 Linux Mint
- 13 Mageia
- 23 openSUSE
- 150 Red Hat Enterprise
- 31 Slackware
- 13 SUSE Enterprise
- 355 Ubuntu
- 459 Linux System Administration
- 31 Cloud Computing
- 72 Command Line/Scripting
- Github systems admin projects
- 94 Linux Security
- 78 Network Management
- 100 System Management
- 46 Web Management
- 66 Mobile Computing
- 18 Android
- 37 Development
- 1.2K New to Linux
- 1K Getting Started with Linux
- 381 Off Topic
- 117 Introductions
- 174 Small Talk
- 29 Study Material
- 725 Programming and Development
- 309 Kernel Development
- 398 Software Development
- 888 Software
- 281 Applications
- 182 Command Line
- 5 Compiling/Installing
- 68 Games
- 316 Installation
- 62 All In Program
- 62 All In Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)