3 ms·
One thing that has always astounded me is the fact that the following script can be executed without any special permission (apart from execution, read and writ
by skdotdan 7y ago
One thing that has always astounded me is the fact that the following script can be executed without any special permission (apart from execution, read and write):
rm -rf ~
A key to a more modern file system would be a much more granular permission systems apart from "rwx" for a certain group of users.
- nybble41 7y agoWhat permissions do you think that command should require? You could add a separate "delete" capability, but the fact that you have permission to write to the file already means that you can delete or overwrite its contents, which is effectively the same from the user's point of view. (Granted, the fact that you can delete a read-only file if you have write permission on the directory is a bit odd, but that situation doesn't come up often.) I don't think more granular permission can solve this problem. What does solve it, however, is read-only copy-on-write snapshots. No matter how files are renamed, deleted, or modified, you can always recover the original version from the snapshot.