delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2021/02/22/18:47:10

X-Recipient: archive-cygwin AT delorie DOT com
X-Original-To: cygwin AT cygwin DOT com
Delivered-To: cygwin AT cygwin DOT com
DMARC-Filter: OpenDMARC Filter v1.3.2 sourceware.org 33ABF385800A
Authentication-Results: sourceware.org; dmarc=none (p=none dis=none)
header.from=SystematicSw.ab.ca
Authentication-Results: sourceware.org;
spf=none smtp.mailfrom=brian DOT inglis AT systematicsw DOT ab DOT ca
X-Authority-Analysis: v=2.4 cv=fdJod2cF c=1 sm=1 tr=0 ts=60344277
a=T+ovY1NZ+FAi/xYICV7Bgg==:117 a=T+ovY1NZ+FAi/xYICV7Bgg==:17
a=IkcTkHD0fZMA:10 a=vzuxeAwJZnfo9eXj1_0A:9 a=QEXdDO2ut3YA:10 a=H9mzJr2JvMoA:10
To: cygwin AT cygwin DOT com
References: <003401d70864$cd3b3400$67b19c00$@gmail.com>
<CAJ1FpuMbx1pyOqoRSwgieQbGPgcXOOiUusFtsmqKWoyJdzF0pg AT mail DOT gmail DOT com>
<306dd40d-666d-4a27-0a2c-dc03053d2f8c AT SystematicSw DOT ab DOT ca>
<e4540cda-2874-71e4-fc56-9a53a7d8e5ee AT t-online DOT de>
From: Brian Inglis <Brian DOT Inglis AT SystematicSw DOT ab DOT ca>
Organization: Systematic Software
Subject: Re: CRITICAL ls MEMORY LEAK
Message-ID: <1ca42c00-db0a-4999-11e1-a82828a5e074@SystematicSw.ab.ca>
Date: Mon, 22 Feb 2021 16:47:02 -0700
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101
Thunderbird/78.7.1
MIME-Version: 1.0
In-Reply-To: <e4540cda-2874-71e4-fc56-9a53a7d8e5ee@t-online.de>
X-CMAE-Envelope: MS4xfBwCMGr/Flzt0FafgKxNLGb7Tgj+Xe79nH3M+bwedlx7QywlnNaXnzV0VhrqyFXj5LnVbFVjQMcS8PdjZt6NIm/XDfBPBOFmPZ5FXoVL21uLlFSNUSJP
jAkqdgWocN34PfmSlq9EolHPIyvQ0gFi7QndvXeBk0rd31pvFs6Pg/AAkVHyeIqemsopDpVxJp/16kvWm5MVv0MQVcc58geTMTM=
X-Spam-Status: No, score=0.8 required=5.0 tests=BAYES_00, KAM_DMARC_STATUS,
KAM_LAZY_DOMAIN_SECURITY, NICE_REPLY_A, RCVD_IN_BARRACUDACENTRAL,
RCVD_IN_DNSWL_LOW, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, SPF_HELO_NONE,
SPF_NONE, TXREP autolearn=no autolearn_force=no version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on
server2.sourceware.org
X-BeenThere: cygwin AT cygwin DOT com
X-Mailman-Version: 2.1.29
List-Id: General Cygwin discussions and problem reports <cygwin.cygwin.com>
List-Unsubscribe: <https://cygwin.com/mailman/options/cygwin>,
<mailto:cygwin-request AT cygwin DOT com?subject=unsubscribe>
List-Archive: <https://cygwin.com/pipermail/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-request AT cygwin DOT com?subject=help>
List-Subscribe: <https://cygwin.com/mailman/listinfo/cygwin>,
<mailto:cygwin-request AT cygwin DOT com?subject=subscribe>
Reply-To: cygwin AT cygwin DOT com
Errors-To: cygwin-bounces AT cygwin DOT com
Sender: "Cygwin" <cygwin-bounces AT cygwin DOT com>
X-MIME-Autoconverted: from base64 to 8bit by delorie.com id 11MNlAVn028305

On 2021-02-22 14:50, Hans-Bernhard Bröker wrote:
> Am 22.02.2021 um 21:30 schrieb Brian Inglis:
> 
>> I've often wondered if the heavy activity is due to Windows' defaults to 
>> writing files with F+RX perms which triggers executable virus scans?
> 
> That could only be the case if Windows actually had an 'x' permission bit.

Strictly speaking, I am not sure if *Unix* has an 'x' permission bit, but most 
filesystems do provide such a facility (V/FAT e.g. some /boot/ do not), as do 
POSIX/Solaris ACLs, and Windows NTFS, whose ACLs have execute permissions:

$ icacls /? | egrep exec\|X
                 RX - read and execute access
                 GE - generic execute
                 X - execute/traverse

GE grants FILE_EXECUTE and STANDARD_RIGHTS_EXECUTE access rights.

Access Mask Format:
|31|30|29|28|27|26|25|24|23|22|21|20|19|18|17|16|15|14|13|12|11|10|9|8|7|6|5|4|3|2|1|0|
|GR|GW|GE|GA|27|26|25|AS|23|22|21|20|19|18|17|16|15|14|13|12|11|10|9|8|7|6|5|4|3|2|1|0|
|..generic..|reserved|..|.......standard........|...........object.specific...........|

GR GENERIC_READ
GW GENERIC_WRITE
GE GENERIC_EXECUTE
GA GENERIC_ALL
AS ACCESS_SYSTEM_SECURITY access Security ACL in object security descriptor

Windows also supports ACLs on system objects, and there may be similar features 
on SELinux.

-- 
Take care. Thanks, Brian Inglis, Calgary, Alberta, Canada

This email may be disturbing to some readers as it contains
too much technical detail. Reader discretion is advised.
[Data in binary units and prefixes, physical quantities in SI.]
--
Problem reports:      https://cygwin.com/problems.html
FAQ:                  https://cygwin.com/faq/
Documentation:        https://cygwin.com/docs.html
Unsubscribe info:     https://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019