ACL 与特殊权限
RHEL 9 用 ACL 对单个用户精准授权,以及 suid/sgid/sticky 特殊位:passwd 原理、共享目录与数字表示 4777/2777/1777。
本页目录
基础的 ugo 权限有时不够用:只想让 user1 写某个文件,又不想把 other 放开到 777;或者要在 /tmp 这种公共目录里防止互删。ACL 与三个特殊位就是补这两块的。
系列:从 RHCSA 到 RHCE · 第 7 / 17 篇 上一篇:用户与基础权限 下一篇:sudo 与找回 root 总目录:系列索引
环境说明
- 系统:RHEL 9(默认支持 ACL 的文件系统如 xfs/ext4)
- 身份:root(或对目标有相应权限的用户)
- 前置:用户与基础权限(rwx、chown)
问题:组不够细时怎么办
场景:test.txt 属主属组都是 root,user1 不在 root 组,却需要 只有 user1 能 rwx。
| 方案 | 结果 |
|---|---|
| 改 other 为 rwx | 所有人都能 rwx,过宽 |
| 把 user1 加进 root 组 | 组内其它权限一并继承,未必想要 |
| ACL | 只给 user1 单独设权限 |
ACL:访问控制列表
ACL(Access Control List)在 ugo 之外,为指定用户/组追加条目。
查看
touch /tmp/test.txt
ls -l /tmp/test.txt
getfacl /tmp/test.txt
# file: tmp/test.txt
# owner: root
# group: root
user::rw-
group::r--
other::r--
授予单个用户
setfacl -m u:user1:rwx /tmp/test.txt
getfacl /tmp/test.txt
ls -l /tmp/test.txt
ls -l 权限位末尾可能出现 +,表示存在 ACL:
-rw-rwxr--+ 1 root root ...
getfacl 里会多出用户条目与 mask:
user::rw-
user:user1:rwx
group::r--
mask::rwx
other::r--
| 选项 | 含义 |
|---|---|
| -m | 修改 modify,添加或更改 ACL 条目 |
| -x | 删除指定 ACL 条目 |
| u:用户:权限 | 用户条目 |
| g:组:权限 | 组条目 |
setfacl -m u:user1:rwx /tmp/test.txt
setfacl -x u:user1 /tmp/test.txt
getfacl /tmp/test.txt
也可以对目录递归:
setfacl -R -m u:user1:r-x /project
默认 ACL(目录,进阶)
给目录设 default ACL 后,在其中新建的子文件/子目录会继承:
mkdir /tmp/proj
setfacl -m d:u:user1:rwx /tmp/proj
touch /tmp/proj/newfile
getfacl /tmp/proj/newfile
考点:题面常只要求「给用户 X 对文件 Y 的 rwx」——一条
setfacl -m u:X:rwx Y即可。 易错:权限字母写错或用户名不存在时setfacl会失败;先id user1。
特殊权限三位
在 rwx 之前还有一位(或体现在 x 位置上)的特殊位:
| 特殊位 | 数字 | 文件(程序) | 目录 |
|---|---|---|---|
| suid | 4 | 执行时获得文件属主的身份 | (一般不用于目录授权场景) |
| sgid | 2 | 执行时获得文件属组的身份 | 目录内新建文件/子目录继承该目录的属组 |
| sticky | 1 | — | 目录内文件:谁创建谁删除(root 除外) |
数字写在原有三位权限之前,共 4 位:
| 表示 | 含义 |
|---|---|
| 777 | 普通 rwxrwxrwx |
| 4777 | suid + rwxrwxrwx |
| 2777 | sgid + rwxrwxrwx |
| 1777 | sticky + rwxrwxrwx |
| 7777 | 三位特殊全开(少见,慎用) |
ls -l 里,特殊位常把原来的 x 显示成 s/S:
-rwsr-xr-x # 属主 x 位为 s → suid
-rwxrwsr-x # 属组 x 位为 s → sgid
drwxrwxrwt # other x 位为 t → sticky
大写 S/T 表示有特殊位但没有对应的执行位。
suid:为什么普通用户能改自己的密码
系统里所有用户的密码在 /etc/shadow,权限类似:
ls -l /etc/shadow
ls -l /usr/bin/passwd
----------. 1 root root ... /etc/shadow
-rwsr-xr-x. 1 root root ... /usr/bin/passwd
passwd 程序带 suid:普通用户 user1 执行它时,进程短暂获得 root(文件属主) 身份,因此能把新密码写进 shadow。
chmod u+s /tmp/myscript # 给脚本/程序加 suid(实验用)
ls -l /tmp/myscript
# 也可用数字设为 4755(会覆盖为该完整权限组合)
chmod 4755 /tmp/myscript
ls -l /tmp/myscript
安全:给解释器脚本随意加 suid 风险极高;生产里 suid 程序要审计(
find / -perm -4000)。考试按题面操作即可。 考点:passwd能改密的原因 = suid + 文件属主是 root。
sgid:共享目录保持同一组
场景:adm 组要协作,目录里新建的文件都应属于组 adm,而不是创建者的私有组。
mkdir /tmp/shared
chown :adm /tmp/shared
ls -ld /tmp/shared
chmod g+s /tmp/shared
ls -ld /tmp/shared
# drwxr-sr-x ...
touch /tmp/shared/a.txt
ls -l /tmp/shared/a.txt
# 属组应为 adm,而不是创建者的同名组
也可用数字:
chmod 2775 /tmp/shared
考点:「目录设置后,新建文件自动继承目录属组」→ sgid。
sticky:公共目录防互删
/tmp 典型权限:
ls -ld /tmp
# drwxrwxrwt
有 sticky(末位 t)时:
- 用户 A 建的文件,用户 B 不能删除(即便目录是 777)
- root 仍可删除
mkdir /tmp/pub
chmod 1777 /tmp/pub
ls -ld /tmp/pub
# 用两个普通用户实验(需先建好用户)
# user1: touch /tmp/pub/u1.txt
# user2: rm /tmp/pub/u1.txt → 应失败
考点:「谁创建的文件只能自己删」→ 目录 sticky。 易错:sticky 必须打在目录上才符合该场景题意。
特殊位的设置与清除
chmod u+s file # suid
chmod g+s dir # sgid
chmod o+t dir # sticky
chmod u-s file # 去掉 suid
chmod g-s dir
chmod o-t dir
# 数字
chmod 4755 file
chmod 2775 dir
chmod 1777 dir
chmod 755 file # 去掉特殊位,只留普通权限
推荐实验(约 20 分钟)
# 准备用户
useradd u1
useradd u2
echo 'YourPass123' | passwd --stdin u1
echo 'YourPass123' | passwd --stdin u2
# ACL
touch /tmp/acl.txt
setfacl -m u:u1:rwx /tmp/acl.txt
getfacl /tmp/acl.txt
ls -l /tmp/acl.txt
setfacl -x u:u1 /tmp/acl.txt
getfacl /tmp/acl.txt
# suid 观察
ls -l /usr/bin/passwd
# sgid 共享目录
mkdir /tmp/sgidlab
chown :adm /tmp/sgidlab
chmod 2775 /tmp/sgidlab
ls -ld /tmp/sgidlab
touch /tmp/sgidlab/from-root
ls -l /tmp/sgidlab/from-root
# sticky
mkdir /tmp/stickylab
chmod 1777 /tmp/stickylab
ls -ld /tmp/stickylab
期望
getfacl出现user:u1:rwx,ls -l带+passwd显示-rwsr-xr-x- sgid 目录
drwxrwsr-x或drwxr-sr-x,新建文件属组为adm - sticky 目录
drwxrwxrwt
速查表
| 目标 | 命令 |
|---|---|
| 看 ACL | getfacl 文件 |
| 加用户 ACL | setfacl -m u:用户:rwx 文件 |
| 删用户 ACL | setfacl -x u:用户 文件 |
| suid | chmod u+s 文件 / chmod 4755 文件 |
| sgid | chmod g+s 目录 / chmod 2775 目录 |
| sticky | chmod o+t 目录 / chmod 1777 目录 |
| 查 suid 文件 | find /usr -perm -4000 2>/dev/null |
考点与易错
考点:ACL 用户条目读写;suid 解释
passwd;sgid 目录继承属组;sticky 公共目录。 易错:chmod 777当万能药——ACL 题应优先setfacl。 易错:sgid/sticky 打在文件上而不是目录(题面场景是共享目录时)。 易错:看到ls的+以为权限坏了,其实是 ACL 标记。 易错:S/T大写表示「有特殊位但无 x」,不是「权限最高」。 练习环境:课堂若在red上做/tmp实验,命令相同。
小结
- 单用户精准授权用 ACL:
setfacl -m u:用户:权限 文件。 - suid:执行程序时借文件属主身份(如
passwd)。 - sgid:目录上用,新建文件继承目录属组。
- sticky:目录上用,只能删自己的文件;数字记 4 / 2 / 1。
下一篇 sudo 提权与 rd.break 找回 root——把「谁能以谁的身份执行什么」写进 /etc/sudoers。
系列导航:总目录 · 上一篇:用户与基础权限 · 下一篇:sudo 与找回 root