Linux

ACL 与特殊权限

RHEL 9 用 ACL 对单个用户精准授权,以及 suid/sgid/sticky 特殊位:passwd 原理、共享目录与数字表示 4777/2777/1777。

基础的 ugo 权限有时不够用:只想让 user1 写某个文件,又不想把 other 放开到 777;或者要在 /tmp 这种公共目录里防止互删。ACL 与三个特殊位就是补这两块的。

系列:从 RHCSA 到 RHCE · 第 7 / 17 篇 上一篇:用户与基础权限 下一篇:sudo 与找回 root 总目录:系列索引

环境说明

  • 系统:RHEL 9(默认支持 ACL 的文件系统如 xfs/ext4)
  • 身份:root(或对目标有相应权限的用户)
  • 前置:用户与基础权限(rwx、chown)

问题:组不够细时怎么办

场景:test.txt 属主属组都是 root,user1 不在 root 组,却需要 只有 user1 能 rwx。

方案结果
改 other 为 rwx所有人都能 rwx,过宽
把 user1 加进 root 组组内其它权限一并继承,未必想要
ACL只给 user1 单独设权限

ACL:访问控制列表

ACL(Access Control List)在 ugo 之外,为指定用户/组追加条目。

查看

touch /tmp/test.txt
ls -l /tmp/test.txt
getfacl /tmp/test.txt
# file: tmp/test.txt
# owner: root
# group: root
user::rw-
group::r--
other::r--

授予单个用户

setfacl -m u:user1:rwx /tmp/test.txt
getfacl /tmp/test.txt
ls -l /tmp/test.txt

ls -l 权限位末尾可能出现 +,表示存在 ACL:

-rw-rwxr--+ 1 root root ...

getfacl 里会多出用户条目与 mask:

user::rw-
user:user1:rwx
group::r--
mask::rwx
other::r--
选项含义
-m修改 modify,添加或更改 ACL 条目
-x删除指定 ACL 条目
u:用户:权限用户条目
g:组:权限组条目
setfacl -m u:user1:rwx /tmp/test.txt
setfacl -x u:user1 /tmp/test.txt
getfacl /tmp/test.txt

也可以对目录递归:

setfacl -R -m u:user1:r-x /project

默认 ACL(目录,进阶)

给目录设 default ACL 后,在其中新建的子文件/子目录会继承:

mkdir /tmp/proj
setfacl -m d:u:user1:rwx /tmp/proj
touch /tmp/proj/newfile
getfacl /tmp/proj/newfile

考点:题面常只要求「给用户 X 对文件 Y 的 rwx」——一条 setfacl -m u:X:rwx Y 即可。 易错:权限字母写错或用户名不存在时 setfacl 会失败;先 id user1。

特殊权限三位

在 rwx 之前还有一位(或体现在 x 位置上)的特殊位:

特殊位数字文件(程序)目录
suid4执行时获得文件属主的身份(一般不用于目录授权场景)
sgid2执行时获得文件属组的身份目录内新建文件/子目录继承该目录的属组
sticky1—目录内文件:谁创建谁删除(root 除外)

数字写在原有三位权限之前,共 4 位:

表示含义
777普通 rwxrwxrwx
4777suid + rwxrwxrwx
2777sgid + rwxrwxrwx
1777sticky + rwxrwxrwx
7777三位特殊全开(少见,慎用)

ls -l 里,特殊位常把原来的 x 显示成 s/S:

-rwsr-xr-x     # 属主 x 位为 s → suid
-rwxrwsr-x     # 属组 x 位为 s → sgid
drwxrwxrwt     # other x 位为 t → sticky

大写 S/T 表示有特殊位但没有对应的执行位。

suid:为什么普通用户能改自己的密码

系统里所有用户的密码在 /etc/shadow,权限类似:

ls -l /etc/shadow
ls -l /usr/bin/passwd
----------. 1 root root ... /etc/shadow
-rwsr-xr-x. 1 root root ... /usr/bin/passwd

passwd 程序带 suid:普通用户 user1 执行它时,进程短暂获得 root(文件属主) 身份,因此能把新密码写进 shadow。

chmod u+s /tmp/myscript   # 给脚本/程序加 suid(实验用)
ls -l /tmp/myscript
# 也可用数字设为 4755(会覆盖为该完整权限组合)
chmod 4755 /tmp/myscript
ls -l /tmp/myscript

安全:给解释器脚本随意加 suid 风险极高;生产里 suid 程序要审计(find / -perm -4000)。考试按题面操作即可。 考点:passwd 能改密的原因 = suid + 文件属主是 root。

sgid:共享目录保持同一组

场景:adm 组要协作,目录里新建的文件都应属于组 adm,而不是创建者的私有组。

mkdir /tmp/shared
chown :adm /tmp/shared
ls -ld /tmp/shared

chmod g+s /tmp/shared
ls -ld /tmp/shared
# drwxr-sr-x ...

touch /tmp/shared/a.txt
ls -l /tmp/shared/a.txt
# 属组应为 adm,而不是创建者的同名组

也可用数字:

chmod 2775 /tmp/shared

考点:「目录设置后,新建文件自动继承目录属组」→ sgid。

sticky:公共目录防互删

/tmp 典型权限:

ls -ld /tmp
# drwxrwxrwt

有 sticky(末位 t)时:

  • 用户 A 建的文件,用户 B 不能删除(即便目录是 777)
  • root 仍可删除
mkdir /tmp/pub
chmod 1777 /tmp/pub
ls -ld /tmp/pub

# 用两个普通用户实验(需先建好用户)
# user1: touch /tmp/pub/u1.txt
# user2: rm /tmp/pub/u1.txt  → 应失败

考点:「谁创建的文件只能自己删」→ 目录 sticky。 易错:sticky 必须打在目录上才符合该场景题意。

特殊位的设置与清除

chmod u+s file      # suid
chmod g+s dir       # sgid
chmod o+t dir       # sticky
chmod u-s file      # 去掉 suid
chmod g-s dir
chmod o-t dir

# 数字
chmod 4755 file
chmod 2775 dir
chmod 1777 dir
chmod 755 file      # 去掉特殊位,只留普通权限

推荐实验(约 20 分钟)

# 准备用户
useradd u1
useradd u2
echo 'YourPass123' | passwd --stdin u1
echo 'YourPass123' | passwd --stdin u2

# ACL
touch /tmp/acl.txt
setfacl -m u:u1:rwx /tmp/acl.txt
getfacl /tmp/acl.txt
ls -l /tmp/acl.txt
setfacl -x u:u1 /tmp/acl.txt
getfacl /tmp/acl.txt

# suid 观察
ls -l /usr/bin/passwd

# sgid 共享目录
mkdir /tmp/sgidlab
chown :adm /tmp/sgidlab
chmod 2775 /tmp/sgidlab
ls -ld /tmp/sgidlab
touch /tmp/sgidlab/from-root
ls -l /tmp/sgidlab/from-root

# sticky
mkdir /tmp/stickylab
chmod 1777 /tmp/stickylab
ls -ld /tmp/stickylab

期望

  • getfacl 出现 user:u1:rwx,ls -l 带 +
  • passwd 显示 -rwsr-xr-x
  • sgid 目录 drwxrwsr-x 或 drwxr-sr-x,新建文件属组为 adm
  • sticky 目录 drwxrwxrwt

速查表

目标命令
看 ACLgetfacl 文件
加用户 ACLsetfacl -m u:用户:rwx 文件
删用户 ACLsetfacl -x u:用户 文件
suidchmod u+s 文件 / chmod 4755 文件
sgidchmod g+s 目录 / chmod 2775 目录
stickychmod o+t 目录 / chmod 1777 目录
查 suid 文件find /usr -perm -4000 2>/dev/null

考点与易错

考点:ACL 用户条目读写;suid 解释 passwd;sgid 目录继承属组;sticky 公共目录。 易错:chmod 777 当万能药——ACL 题应优先 setfacl。 易错:sgid/sticky 打在文件上而不是目录(题面场景是共享目录时)。 易错:看到 ls 的 + 以为权限坏了,其实是 ACL 标记。 易错:S/T 大写表示「有特殊位但无 x」,不是「权限最高」。 练习环境:课堂若在 red 上做 /tmp 实验,命令相同。

小结

  1. 单用户精准授权用 ACL:setfacl -m u:用户:权限 文件。
  2. suid:执行程序时借文件属主身份(如 passwd)。
  3. sgid:目录上用,新建文件继承目录属组。
  4. sticky:目录上用,只能删自己的文件;数字记 4 / 2 / 1。

下一篇 sudo 提权与 rd.break 找回 root——把「谁能以谁的身份执行什么」写进 /etc/sudoers。


系列导航:总目录 · 上一篇:用户与基础权限 · 下一篇:sudo 与找回 root

相关阅读

全部文章 →
← 返回列表更多「Linux」