From abef3f91ce5fa9eeffceead885d2d2cabd9f1c96 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Wed, 11 Jun 2014 10:14:07 +0200 Subject: tmpfiles: add ability to mask access mode by pre-existing access mode on files/directories This way it makes a lot more sense to specify an access mode for "Z" lines. --- man/tmpfiles.d.xml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) (limited to 'man/tmpfiles.d.xml') diff --git a/man/tmpfiles.d.xml b/man/tmpfiles.d.xml index 5d8c2b5b32..0081a6762a 100644 --- a/man/tmpfiles.d.xml +++ b/man/tmpfiles.d.xml @@ -368,6 +368,22 @@ r! /tmp/.X[0-9]*-lock ignored for x, r, R, L lines. + + Optionally, if prefixed with + ~ the access mode is masked + based on the already set access bits for + existing file or directories: if the existing + file has all executable bits unset then all + executable bits are removed from the new + access mode, too. Similar, if all read bits + are removed from the old access mode they will + be removed from the new access mode too, and + if all write bits are removed, they will be + removed from the new access mode too. In + addition the sticky/suid/gid bit is removed unless + applied to a directory. This + functionality is particularly useful in + conjunction with Z. -- cgit v1.2.3-54-g00ecf