filesystem.setacl¶
Set the ACL of a given path.
The dacl entry formatting depends on the underlying acltype: an NFS4 ACL requires NFSv4 entries, while a POSIX1E ACL requires POSIX1e entries. When stripacl is set, the ACL is converted to a trivial ACL; an ACL is trivial if it can be expressed as a file mode without losing any access rules.
Note
For each owner change, set one and only one of uid or user (and likewise one of
gid or group), and only if the caller wishes to change the owning user or group of
the file or directory.
Warning
If user, uid, group, or gid is specified in a recursive operation, then the
owning user, group, or both for all files will be changed.
The following notes about ACL entries are necessarily terse. If more detail is required, please consult relevant TrueNAS documentation.
NFSv4 ACL entry semantics
The tag identifies the principal to whom the entry applies. USER and GROUP have conventional meanings: owner@ refers to the owning user of the file, group@ to the owning group, and everyone@ to all users (including the owning user and group). The type may be ALLOW or DENY, and DENY entries take precedence over ALLOW when the ACL is evaluated. The flags inheritance flags determine how an entry is presented (if at all) on newly-created files or directories within the specified path and are only valid for directories.
POSIX1e ACL entry semantics
When default is true, the entry belongs to the POSIX default ACL and is copied to new files and directories created within the directory where it is set; default entries are not evaluated when determining access to the file on which they are set. When default is false, the entry applies to the POSIX access ACL which is used to determine access to the directory but is not inherited.
For the tag, USER_OBJ refers to the owning user (denoted “user” in conventional POSIX UGO permissions), GROUP_OBJ refers to the owning group (denoted “group”), and OTHER applies to all users and groups who are not USER_OBJ or GROUP_OBJ. MASK sets the maximum permissions granted to all USER and GROUP entries. A valid POSIX1e ACL contains precisely one USER_OBJ, GROUP_OBJ, OTHER, and MASK entry for each of the default and access lists.
This method is a job.
No Additional Items
Tuple Validation
Parameter 1: filesystem_acl
filesystem_acl
Type: objectFilesystemSetaclArgs parameters.
No Additional PropertiesPath
Type: stringMust be at least 1 characters long
Dacl
No Additional Items
Each item of this array must be:
NFS4ACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Must be one of:
- "owner@"
- "group@"
- "everyone@"
- "USER"
- "GROUP"
Type
Type: enum (of string)Must be one of:
- "ALLOW"
- "DENY"
Perms
NFS4ACE_AdvancedPerms
Type: objectNo Additional Properties
Read Data
Type: boolean Default: falseWrite Data
Type: boolean Default: falseAppend Data
Type: boolean Default: falseRead Named Attrs
Type: boolean Default: falseWrite Named Attrs
Type: boolean Default: falseExecute
Type: boolean Default: falseDelete
Type: boolean Default: falseDelete Child
Type: boolean Default: falseRead Attributes
Type: boolean Default: falseWrite Attributes
Type: boolean Default: falseRead Acl
Type: boolean Default: falseWrite Acl
Type: boolean Default: falseWrite Owner
Type: boolean Default: falseSynchronize
Type: boolean Default: falseNFS4ACE_BasicPerms
Type: objectNo Additional Properties
Basic
Type: enum (of string)Must be one of:
- "FULL_CONTROL"
- "MODIFY"
- "READ"
- "TRAVERSE"
Flags
NFS4ACE_AdvancedFlags
Type: objectNo Additional Properties
File Inherit
Type: boolean Default: falseDirectory Inherit
Type: boolean Default: falseNo Propagate Inherit
Type: boolean Default: falseInherit Only
Type: boolean Default: falseInherited
Type: boolean Default: falseNFS4ACE_BasicFlags
Type: objectNo Additional Properties
Basic
Type: enum (of string)Must be one of:
- "INHERIT"
- "NOINHERIT"
Id
Default: nullValue must be greater or equal to -1 and lesser or equal to 2147483647
Who
Default: nullMust be at least 1 characters long
No Additional Items
Each item of this array must be:
POSIXACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Must be one of:
- "USER_OBJ"
- "GROUP_OBJ"
- "OTHER"
- "MASK"
- "USER"
- "GROUP"
POSIXACE_Perms
Type: objectNo Additional Properties
Read
Type: booleanWrite
Type: booleanExecute
Type: booleanDefault
Type: booleanId
Default: nullValue must be greater or equal to -1 and lesser or equal to 2147483647
Who
Default: nullMust be at least 1 characters long
FilesystemSetAclOptions
Type: objectNo Additional Properties
Stripacl
Type: boolean Default: falseRecursive
Type: boolean Default: falseTraverse
Type: boolean Default: falseCanonicalize
Type: boolean Default: trueValidate Effective Acl
Type: boolean Default: trueNFS4ACL_Flags
Type: objectNo Additional Properties
Autoinherit
Type: boolean Default: falseProtected
Type: boolean Default: falseDefaulted
Type: boolean Default: falseUid
Default: -1Value must be greater or equal to -1 and lesser or equal to 2147483647
User
Default: nullGid
Default: -1Value must be greater or equal to -1 and lesser or equal to 2147483647
Group
Default: nullAcltype
Default: nullMust be one of:
- "NFS4"
- "POSIX1E"
Result
NFS4ACLResult
Type: objectNo Additional Properties
Path
Type: stringMust be at least 1 characters long
User
Must be at least 1 characters long
Group
Must be at least 1 characters long
Uid
Value must be greater or equal to -1 and lesser or equal to 2147483647
Gid
Value must be greater or equal to -1 and lesser or equal to 2147483647
Acltype
Type: constSpecific value:
"NFS4"
Acl
Type: array of objectNo Additional Items
Each item of this array must be:
NFS4ACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Must be one of:
- "owner@"
- "group@"
- "everyone@"
- "USER"
- "GROUP"
Type
Type: enum (of string)Must be one of:
- "ALLOW"
- "DENY"
Perms
NFS4ACE_AdvancedPerms
Type: objectNo Additional Properties
Read Data
Type: boolean Default: falseWrite Data
Type: boolean Default: falseAppend Data
Type: boolean Default: falseRead Named Attrs
Type: boolean Default: falseWrite Named Attrs
Type: boolean Default: falseExecute
Type: boolean Default: falseDelete
Type: boolean Default: falseDelete Child
Type: boolean Default: falseRead Attributes
Type: boolean Default: falseWrite Attributes
Type: boolean Default: falseRead Acl
Type: boolean Default: falseWrite Acl
Type: boolean Default: falseWrite Owner
Type: boolean Default: falseSynchronize
Type: boolean Default: falseNFS4ACE_BasicPerms
Type: objectNo Additional Properties
Basic
Type: enum (of string)Must be one of:
- "FULL_CONTROL"
- "MODIFY"
- "READ"
- "TRAVERSE"
Flags
NFS4ACE_AdvancedFlags
Type: objectNo Additional Properties
File Inherit
Type: boolean Default: falseDirectory Inherit
Type: boolean Default: falseNo Propagate Inherit
Type: boolean Default: falseInherit Only
Type: boolean Default: falseInherited
Type: boolean Default: falseNFS4ACE_BasicFlags
Type: objectNo Additional Properties
Basic
Type: enum (of string)Must be one of:
- "INHERIT"
- "NOINHERIT"
Id
Default: nullValue must be greater or equal to -1 and lesser or equal to 2147483647
Who
Default: nullMust be at least 1 characters long
NFS4ACL_Flags
Type: objectNo Additional Properties
Autoinherit
Type: boolean Default: falseProtected
Type: boolean Default: falseDefaulted
Type: boolean Default: falseTrivial
Type: booleanPOSIXACLResult
Type: objectNo Additional Properties
Path
Type: stringMust be at least 1 characters long
User
Must be at least 1 characters long
Group
Must be at least 1 characters long
Uid
Value must be greater or equal to -1 and lesser or equal to 2147483647
Gid
Value must be greater or equal to -1 and lesser or equal to 2147483647
Acltype
Type: constSpecific value:
"POSIX1E"
Acl
Type: array of objectNo Additional Items
Each item of this array must be:
POSIXACE
Type: objectNo Additional Properties
Tag
Type: enum (of string)Must be one of:
- "USER_OBJ"
- "GROUP_OBJ"
- "OTHER"
- "MASK"
- "USER"
- "GROUP"
POSIXACE_Perms
Type: objectNo Additional Properties
Read
Type: booleanWrite
Type: booleanExecute
Type: booleanDefault
Type: booleanId
Default: nullValue must be greater or equal to -1 and lesser or equal to 2147483647
Who
Default: nullMust be at least 1 characters long
Trivial
Type: booleanDISABLED_ACLResult
Type: objectNo Additional Properties
Path
Type: stringMust be at least 1 characters long
User
Must be at least 1 characters long
Group
Must be at least 1 characters long
Uid
Value must be greater or equal to -1 and lesser or equal to 2147483647
Gid
Value must be greater or equal to -1 and lesser or equal to 2147483647
Acltype
Type: constSpecific value:
"DISABLED"
Acl
Type: nullTrivial
Type: constSpecific value:
true
Required roles: FILESYSTEM_ATTRS_WRITE