Commit Graph
1 Commits
Author SHA1 Message Date
Andrew Tridgell d7f929a30e lib/acl.c: POSIX ACL get/set via fd/at xattr syscalls + unit test
POSIX ACLs are stored by the kernel as the system.posix_acl_{access,default}
xattrs.  lib/acl.c serializes that wire format and operates on it via
fgetxattr/fsetxattr on a held O_NOFOLLOW fd -- or getxattrat/setxattrat
(AT_SYMLINK_NOFOLLOW) on a dirfd+leaf -- giving a symlink-race-safe ACL
primitive that, unlike libacl's access-only acl_get_fd/acl_set_fd, also covers
the default ACL.

It is self-contained (no libacl, no rsync globals): it speaks a neutral
(tag, perm, id) entry array, so t_acl can compare it directly against the system
libacl as an oracle.  configure gains SUPPORT_ACL_FD (POSIX ACLs + the xattr
header, independent of the -X feature) and an optional HAVE_XATTRAT_SYSCALLS
probe (the *xattrat syscalls, Linux 6.13+); the fd path needs neither.

t_acl exercises every op rsync needs in both directions (set via lib -> read via
libacl and vice versa), round-trips, the default-ACL delete, errno
discrimination, and the NOFOLLOW leaf refusal.  It self-skips (77) without
SUPPORT_ACL_FD or on a filesystem lacking ACL support.
2026-06-15 15:24:42 +10:00