<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Out Of My Access Control</title>
	<atom:link href="http://www.red-sweater.com/blog/427/out-of-my-access-control/feed" rel="self" type="application/rss+xml" />
	<link>http://www.red-sweater.com/blog/427/out-of-my-access-control</link>
	<description>Mac &#38; Technology Writings by Daniel Jalkut</description>
	<lastBuildDate>Wed, 17 Mar 2010 22:33:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: rvAmerongen</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134289</link>
		<dc:creator>rvAmerongen</dc:creator>
		<pubDate>Wed, 31 Oct 2007 21:28:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134289</guid>
		<description>Hi,

Is there a difference when people do upgrade, archive  their system and do a new install?

Someone did notice something?</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Is there a difference when people do upgrade, archive  their system and do a new install?</p>
<p>Someone did notice something?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134287</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Wed, 31 Oct 2007 11:47:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134287</guid>
		<description>@Robert - which would seem to confirm my suggestion - it&#039;s a well-buried piece of anti-idiot/malware protection.

I&#039;m still on Tiger, so have no ACL, though e is given as an option for ls. Does nothing, though.</description>
		<content:encoded><![CDATA[<p>@Robert &#8211; which would seem to confirm my suggestion &#8211; it&#8217;s a well-buried piece of anti-idiot/malware protection.</p>
<p>I&#8217;m still on Tiger, so have no ACL, though e is given as an option for ls. Does nothing, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Thompson</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134282</link>
		<dc:creator>Robert Thompson</dc:creator>
		<pubDate>Wed, 31 Oct 2007 02:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134282</guid>
		<description>Charles — I just now did a /bin/ls -led /Users/myusername… and the home folder does indeed have the no delete ACL.</description>
		<content:encoded><![CDATA[<p>Charles — I just now did a /bin/ls -led /Users/myusername… and the home folder does indeed have the no delete ACL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134280</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Tue, 30 Oct 2007 22:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134280</guid>
		<description>Daniel - I didn&#039;t mean to suggest that Apple was futzing things either. More that this is a protective measure; barely anyone would come across it. And those who did - like you - would eventually be able to figure it out. QED.</description>
		<content:encoded><![CDATA[<p>Daniel &#8211; I didn&#8217;t mean to suggest that Apple was futzing things either. More that this is a protective measure; barely anyone would come across it. And those who did &#8211; like you &#8211; would eventually be able to figure it out. QED.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134279</link>
		<dc:creator>Ben</dc:creator>
		<pubDate>Tue, 30 Oct 2007 22:03:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134279</guid>
		<description>Never mind. I figured it out.</description>
		<content:encoded><![CDATA[<p>Never mind. I figured it out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134275</link>
		<dc:creator>Ben</dc:creator>
		<pubDate>Tue, 30 Oct 2007 20:28:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134275</guid>
		<description>Does anyone have a link on how to set up Virtual Hosts on Leopard?

I haven&#039;t been able to figure it out now that Netinfo is gone.

Thanks.</description>
		<content:encoded><![CDATA[<p>Does anyone have a link on how to set up Virtual Hosts on Leopard?</p>
<p>I haven&#8217;t been able to figure it out now that Netinfo is gone.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Jalkut</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134274</link>
		<dc:creator>Daniel Jalkut</dc:creator>
		<pubDate>Tue, 30 Oct 2007 19:26:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134274</guid>
		<description>Charles - I don&#039;t think Apple&#039;s trying to futz anything up. It&#039;s just this is the kind of thing where unintended consequences are really hard to track down.  I wanted to mainly help publicize in case others run into the problem.</description>
		<content:encoded><![CDATA[<p>Charles &#8211; I don&#8217;t think Apple&#8217;s trying to futz anything up. It&#8217;s just this is the kind of thing where unintended consequences are really hard to track down.  I wanted to mainly help publicize in case others run into the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134273</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Tue, 30 Oct 2007 19:23:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134273</guid>
		<description>Possibly, if it is an inbuilt thing, it&#039;s so that people 
(a) can&#039;t delete their Documents folder by accident (people can do dumb things, after all) 

(b) malware can&#039;t do rm -rf ~/Documents (and, who knows, rm -rf ~/ - have you looked to see if this &quot;can&#039;t delete&quot; ACL applies to the whole of the home folder?)

So it might be Apple being a beneficient backstop, rather than trying to futz up your Apache. Though I&#039;m sure an upgrade install would tear up all sorts of symlinks etc if you had MySQL installed and PHP in Apache etc.</description>
		<content:encoded><![CDATA[<p>Possibly, if it is an inbuilt thing, it&#8217;s so that people<br />
(a) can&#8217;t delete their Documents folder by accident (people can do dumb things, after all) </p>
<p>(b) malware can&#8217;t do rm -rf ~/Documents (and, who knows, rm -rf ~/ &#8211; have you looked to see if this &#8220;can&#8217;t delete&#8221; ACL applies to the whole of the home folder?)</p>
<p>So it might be Apple being a beneficient backstop, rather than trying to futz up your Apache. Though I&#8217;m sure an upgrade install would tear up all sorts of symlinks etc if you had MySQL installed and PHP in Apache etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Sargent</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134269</link>
		<dc:creator>Paul Sargent</dc:creator>
		<pubDate>Tue, 30 Oct 2007 17:29:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134269</guid>
		<description>I&#039;ve seen this too, as I like to symlink certain parts of my home account between OS releases (Music, Movies, Pictures). All have ACL rules on them, and have done for a few seeds now.

This is doing an erase and install, and having a new blank user though. Slightly different to the process you guys are discussing/</description>
		<content:encoded><![CDATA[<p>I&#8217;ve seen this too, as I like to symlink certain parts of my home account between OS releases (Music, Movies, Pictures). All have ACL rules on them, and have done for a few seeds now.</p>
<p>This is doing an erase and install, and having a new blank user though. Slightly different to the process you guys are discussing/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Jalkut</title>
		<link>http://www.red-sweater.com/blog/427/out-of-my-access-control/comment-page-1#comment-134268</link>
		<dc:creator>Daniel Jalkut</dc:creator>
		<pubDate>Tue, 30 Oct 2007 15:12:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.red-sweater.com/blog/427/out-of-my-access-control#comment-134268</guid>
		<description>Matt - thanks for the feedback - I was worried I might be overstating the case, but I had gotten some corroboration from friends after I first discovered it. Just to clarify - you are checking for the ACL by &quot;ls -led&quot; on the affected directory?

Rich - thanks for your comments - I am glad to hear that at least if Matt is right that it&#039;s not happening across the board, it is still happening to quite a few people.</description>
		<content:encoded><![CDATA[<p>Matt &#8211; thanks for the feedback &#8211; I was worried I might be overstating the case, but I had gotten some corroboration from friends after I first discovered it. Just to clarify &#8211; you are checking for the ACL by &#8220;ls -led&#8221; on the affected directory?</p>
<p>Rich &#8211; thanks for your comments &#8211; I am glad to hear that at least if Matt is right that it&#8217;s not happening across the board, it is still happening to quite a few people.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
