3 fs_copyacl - Copies an ACL from a directory to one or more other directories
10 B<fs copyacl> S<<< B<-fromdir> <I<source directory (or DFS file)>> >>>
11 S<<< B<-todir> <I<destination directory (or DFS file)>>+ >>>
12 [B<-clear>] [B<-id>] [B<-if>] [-help]
14 B<fs co> S<<< B<-f> <I<source directory (or DFS file)>> >>>
15 S<<< B<-t> <I<destination directory (or DFS file)>>+ >>>
16 [B<-c>] [B<-id>] [B<-if>] [-h]
23 The fs copyacl command copies the access control list (ACL) from a source
24 directory to each specified destination directory. The source directory's
25 ACL is unchanged, and changes to the destination directory's ACL obey the
32 If an entry on the source ACL does not already exist on the destination
37 If an entry exists on both the source and destination ACLs, the
38 permissions from the source ACL entry replace the current permissions on
39 the destination ACL entry.
43 If an entry on the destination ACL has no corresponding entry on the
44 source ACL, it is removed if the B<-clear> flag is included and is
45 unchanged otherwise. In other words, if the B<-clear> flag is provided,
46 the source ACL completely replaces the destination ACL.
50 When using this command to copy ACLs between objects in DFS filespace
51 accessed via the AFS/DFS Migration Toolkit Protocol Translator, it is
52 possible to specify files, as well as directories, with the B<-fromdir>
53 and B<-todir> arguments. For more information on copying ACLs between DFS
54 directories and files, refer to the I<IBM AFS/DFS Migration Toolkit
55 Administration Guide and Reference>.
59 Do not copy ACLs between AFS and DFS files or directories. The ACL formats
66 =item B<-fromdir> <I<source directory>>
68 Specifies the source directory from which to copy the ACL. (Specifying an
69 AFS file copies its directory's ACL, but specifying a DFS file copies its
70 own ACL.) A partial pathname is interpreted relative to the current
73 =item B<-todir> <I<destination directory>>
75 Specifies each directory for which to alter the ACL to match the source
76 ACL. (Specifying an AFS file halts the command with an error, but
77 specifying a DFS file alters the file's ACL). A partial pathname is
78 interpreted relative to the current working directory.
80 Specify the read/write path to each directory (or DFS file), to avoid the
81 failure that results from attempting to change a read-only volume. By
82 convention, the read/write path is indicated by placing a period before
83 the cell name at the pathname's second level (for example,
84 C</afs/.abc.com>). For further discussion of the concept of read/write and
85 read-only paths through the filespace, see the B<fs mkmount> reference
90 Replaces the ACL of each destination directory with the source ACL.
94 Modifies the Initial Container ACL of each DFS directory named by the
95 B<-todir> argument, rather than the regular Object ACL. This argument is
96 supported only when both the source and each destination directory reside
97 in DFS and are accessed via the AFS/DFS Migration Toolkit Protocol
102 Modifies the Initial Object ACL of each DFS directory named by the
103 B<-todir> argument, rather than the regular Object ACL. This argument is
104 supported only when both the source and each destination directory reside
105 in DFS and are accessed via the AFS/DFS Migration Toolkit Protocol
110 Prints the online help for this command. All other valid options are
117 The following example command copies the current working directory's ACL
118 to its subdirectory called F<reports>. Note that the source directory's
119 ACL is unaffected. Entries on the F<reports> directory's that are not on
120 the source ACL of the current directory remain unaffected as well, because
121 the B<-clear> flag is not used.
123 % fs listacl . reports
128 Access list for reports is
135 % fs copyacl -fromdir . -todir reports
137 % fs listacl . reports
142 Access list for reports is
150 =head1 PRIVILEGE REQUIRED
152 To copy an ACL between AFS objects, the issuer must have the C<l> (lookup)
153 permission on the source directory's ACL and the C<a> (administer)
154 permission on each destination directory's ACL. If the B<-fromdir>
155 argument names a file rather than a directory, the issuer must have both
156 the C<l> and C<r> (read) permissions on the ACL of the file's directory.
158 To copy an ACL between DFS objects, the issuer must have the r permission
159 on the source directory or file's ACL and the C<c> (control) permission on
160 each destination directory or file's ACL.
168 I<IBM AFS/DFS Migration Toolkit Administration Guide and Reference>
172 IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
174 This documentation is covered by the IBM Public License Version 1.0. It was
175 converted from HTML to POD by software written by Chas Williams and Russ
176 Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.