Understanding underscore "_" in group permissions & external drives

Some time ago I followed these instructions to get my Mac working properly after a migration from an older version of Mac OS... I'm moving along on "same" Mac...and things have been basically OK...except now I am seeing some weird behavior.
I have an external hard disk that I would like permissions to enforced on. Getting Info on the drive itself in the Finder shows me basically:
Name
Privilege
bob (Me)
Read & Write
_bob
Read & Write
everyone
Read only
Ignore ownership is NOT checked
But, when I log into the GUEST account on this machine the guest can read and write to the external drive!?! Getting Info on the external drive from the Guest's account shows:
Name
Privilege
Guest (Me)
Read & Write
_guest
Read & Write
everyone
Read only
Ignore ownership is NOT checked   <- and this is now grayed out and un-selectable
So, I guess my question is...how do I prevent anyone else from making changes to this external drive? And what is this underscore group name (_bob & _guest) all about? Is it normal?

OK, I tried what you recommended on a subfolder on this external drive. I removed the "group" permission that was "_bob"...and propagated it through enclosed subfolders. Leaving me with ONLY:
Name
Privilege
bob (Me)
Read & Write
everyone
Read only
Before:
$ ls -l
drwxr-xr-x  13 bob  _bob   442 Oct 15  2004 TestFolder
After:
$ ls -l
drwx---r-x  13 bob  wheel  442 Oct 15  2004 TestFolder
     bold added by me for emphasis
So it would seem that by removing the group...I've effectively assigned the folder the default group of "wheel" which I as I recall is all users who can 'su' to root!?! So, what happens when another admin user (member of 'wheel') tries to access this folder...will they be denied or will they fall back to "everyone's" privileges?!?  Something tells me I should chmod 755 this folder now to make it drwxr-xr-x so members of wheel also have r+x privileges!?! hmm…

Similar Messages

  • Cure for crash after creating a RAID group on external drives?

    I tried creating a RAID 1 mirror group on a pair of Western Digital Studio LX Firewire-attached 2 TB external drives (new), and Lion crashed with the RAID code on the stack (according to the crash report).   The system always crashes the same way if I connect even one of the drives, at boot time or later.  The RAID group was of the whole drives, not a pair of partitions.   I was using a Mac Mini, but I expect my MacBook, also running Lion, will crash the same way, if I try to attach the drives to repartion them.   I suppose I can attach the drives via USB to a Linux box to clobber the partition tables.
    Is there a way to set up RAID 1 on Lion which does not lead to an immediate crash?
    I have been a happy Mac user, but shipping with RAID 1 being so badly broken is really careless.   I expect a lot better.

    I set up a mirror raid on two external USB drives, and set to 256k under osx 10.7.5 then got the full melt down
    and the same every time i tried to reformat the drives.
    I did notice a slight moment of time when opening disk utility before the crash!
    The following worked for me.
    Start the computer, insert just one of the USB or Firewire drives then open disk utility.
    Here is the key point as fast as you can select the drive icon as soon as it appears on the left  and hit the erase option
    don't worry about the type of format select the t hit the erase button as quickly as you can and again as the prompt comes up are you sure you want to erase the disk.
    Then repeat again on the second drive and then start the raid set up over again with blocks set at 128k.
    Probably advised to unmount all other drives so you do not accidentally format the wrong drive given this is all about haste.
    Really hope this helps and think it through as to how it relates to your set up.

  • Trying to understand File Sharing (need to share an external drive)

    Hello,
    I feel a bit dumb, but after years of getting along without really understanding, I feel I need to get to the basics of file sharing and permissions now.
    We have a small office, and use a MacMini (10.6.4 Client) to serve files. Those files are in a folder called 'data' on an external drive.
    The Mini has two users set up, 'admin' and 'user'. I want everyone to log in via AFP as 'user' to access the 'data' folder.
    Until now our setup was a 10.4 machine, with the third-party application Sharepoints by Hornware managing the sharing. Now with 10.6 I know I should be able to do without that.
    I've removed all user's Public folders from the System Preferences/Sharing pane, and added the 'data' folder. I've added the 'user' user to it, and have given it read/write access. Also, I've done the same for the 'admin' user.
    Now I'm unsure if I need to change permissions to the 300GB worth of files on that external drive. (that's question #1.)
    If I look at those files from a client machine, logged in as 'user', Finder tells me they belong to 'unknown'.
    Question #2: If I understand correctly, the settings on the server's Sharing preferences pane only apply for ACCESS to the shared folder (i.e. they make it possible to log in via AFP). These settings don't do anything to ownership and permissions on the shared files, right? (not sure here!)
    Grateful if anybody can shed light on this!

    Jens Grotzscherst wrote:
    Now I'm unsure if I need to change permissions to the 300GB worth of files on that external drive. (that's question #1.)
    If you want to allow anyone accessing as "user" to be able to read or write all files on that volume, you could do that. You should also be able to set the volume attribute to ignore ownership:
    http://www.peachpit.com/guides/content.aspx?g=mac&seqNum=256
    If I look at those files from a client machine, logged in as 'user', Finder tells me they belong to 'unknown'.
    I imagine that they're owned by a user with a user ID that's not present on that machine.
    Question #2: If I understand correctly, the settings on the server's Sharing preferences pane only apply for ACCESS to the shared folder (i.e. they make it possible to log in via AFP).
    If that were the case, there would be no need for the "Read & Write" / "Read Only" setting in the Sharing panel.

  • Permissions on external drive

    I have been using a Linux based NAS drive for storing media files and this has worked fine under Leopard and Snow Leopard. I have now upgrade to Lion and I can no longer access the folders on the NAS drive. Lion will connect to the drive but the Finder window shows folders with a red & white stop sign. Selecting one of the folders elicits a 'The folder “xxxxx” can’t be opened because you don’t have permission to see its contents.' I can see the folders and files using the terminal. I have tried connecting the external NAS using SMB and bonjour but get the same result with Finder.
    Can anyone provide an explanation as to what has happened during the upgrade from Snow Leopard to Lion? Is there a way to reset the permissions so that I can access the files from Finder?
    Oddly, iTunes can see the and play the files without a problem.

    After MANY frustrating hours of trying everything to regain permission to my external hard drives I found an easy and fast solution. FYI- I'm on Snow Leopard 10.6.8, though I believe this solution will work for anyone on Mac OS X 10.5 or later.
    1. Download BatChmod.app (http://www.lagentesoft.com/batchmod/index.html).
    2. Click on the "File" button and choose the external drive in question.
    3. Under Owner, choose "root" and check all 3 boxes (R, W and X). Under Group, choose "admin" and again check all 3 boxes. Under Everyone, again check all 3 boxes. **make sure you've checked the boxes and not just put a line in them...
    4. In Options box, check "Change ownership and privileges," check "Clear ACLs (10.5+)" and check "Unlock." Do not check "Clear xattrs."
    5. Finally, DO NOT check the box at the bottom that says "Apply to enclosed folders and files," because this is probably similar to what got you locked out of your own external hard drive in the first place!
    6. Click on the "Apply" button.
    7. Now open finder and open your external hard drive!

  • Shared external drive - user permissions setup

    I've set a home LAN made of 3 iMac/eMac connected via Airport. I've recently added a 500 Gb firewire external drive connected to my iMac to manage backups. I divided it into 3 partitions (1 per user/xMac) and mounted them using sharepoints. It's all great; users can see, mount and use all partitions.
    Here is the issue: I would like each user to only see and use his dedicated partition. I believe I must play with users and groups, but could not make it to work. I'm not very familiar with this and I'm afraid to make big mistake. Coud somebody help on this ?
    iMac   Mac OS X (10.4.9)  

    I should write one, but it's fairly simple once you get into it...
    Click on the Groups tab, make a group name... say "PartitionA", click add group, repeat for 2 more groups... "PartitionB", "PartitionC".
    Click on the Users & Public Tab, fill in for "Tom, "Dick", & "Harry".
    Back to the Goups tab, higlight "PartitionA", then highlight "Tom", click the plus sign... repeat for the other two groups and users.
    Now under "Normal Shares" tab, you can highlight a Share, then click on the Show File Properties button and assign a Group, and it's Permissions.

  • OS X extern drive ownership/permissions and NFS exporting

    - I have an external (250GB) firewire drive on OS X 10.4.9.
    - I want to have it available to local users of this Mac but with ownership/permissions of created files/directories protected in the usual UNIX sense of unique UID/GID -- files/directories created by one user cannot be read/written by other users of this Mac except as allowed by standard UNIX permissions groups settings; eg., those set with 'chmod' command.
    - I want to NFS-server this drive volume to a linux NFS client (eg., RHEL 4), again with files/directories protected in this same UID/GID UNIX sense. In our case, the users' UID/GIDs will be made to match, but regardless, I wish likewise for file/directory use on the linux client to be restricted as per UNIX permissions and the files/directories created by the Mac users have protections remain in place against linux user access, and visa versa, as above.
    Is this feasable in Mac OS X (without OS X Server)?
    How does one go about acheiving it?
    I have basic Netinfo Manager skills for creating NFS exports and starting NFS daemon services, but am not expert on all available export options. I have average linux IT NFS server/client and user management skills.
    Thanks,
    -Neil

    I don't know about networking with Linux, but I don know that for OS X users, enforcing permissions on an external drive without OS X Server is tricky.
    First, log in to your admin account. Right-click the drive, Get Info, expand Ownership & Permissions, and uncheck "Ignore ownership on this volume". Then set permissions accordingly.
    The problem is that any unprivileged user can log in to his own account, Get Info, recheck the box, and get ownership of the entire contents of the drive. This is possible even without the admin password.
    There is a workaround that will remove the Ignore Ownership box from the Get Info panel so that there will be no box for them to check. First make sure that the box is unchecked and that the permissions are set how you want. Then enable ACLs on the volume by entering this command in a Terminal window:
    sudo fsaclctl -p /Volumes/volumename -e
    Then restart Finder. Now there's no box for the unprivileged user to check. But I don't know where this setting is stored; perhaps the unprivileged user can find some command-line way of getting the box re-checked and thus getting ownership of everything.
    If there is some way you can get the data off of the external drive and onto the main boot drive you will have the best chance of keeping the data safe.

  • Need help repairing bootable external drive permissions

    I, like some of the other posters I have read, have messed up the permissions on a bootable external drive.
    I don't have direct access to my home computer right now so I set up an external bootable copy of my personal account, so I can basically run a copy of my own personal computer from anyone elses mac. And when I get back home I will be able to copy back across any new files.
    The set up was working great till I realized that my external drive was completely readable, and writeable by anyone who turned it on as a peripheral disk while logged in on the main computer if the computer was booted up on it's own startup disk.
    If my external was set as the startup disk, then my password and account kept everything secure.
    So anyway, not really knowing what I was doing I, using the show info command, changed the group permission for the whole disk/volume from admin to my username. Now unfortunately I cannot startup using my external disk; the whole system goes straight to Kernal. And all my files are still totally assesible to any one logged in on the computer using its own start up disk.
    Can you help me with the commands, to first repair the group permission so my disk is bootable again, then second so that I can prevent anyone with out my password access to any files on the disk?
    Thanks alot!

    Can you help me with the commands, to first repair the group permission so my disk is bootable again, then second so that I can prevent anyone with out my password access to any files on the disk?
    On another machine, open the Disk Utility in the /Applications/Utilities/ folder, select your drive in the list of disks, and then click on the Repair Permissions button; other solutions are available if this doesn't work.
    Your two goals are mutually exclusive; there is no way to restrict access to an entire disk to yourself while maintaining the ability of that disk to boot Mac OS X. Your home folder can be protected in this way by changing the permissions on the item inside /Users/ with the house icon, or by turning on FileVault in the Security pane of System Preferences.
    (11310)

  • How do I give myself read/write access/permissions for my external drive?

    Im a brand new Mac user, so please stay with me.
    I have an external drive and I can't delete, modify, ANYTHING on it. When I go to "Get Info" it says "You can only read" under sharing & permissions. How do I change this?

    When you get info on the external drive, at the very bottom is a box you can check
    "Ignore ownership on this volume"...
    If you check that, then see if you can delete and move things around.
    If that doesn't work then try clicking on the + sign and adding you as an admin so you can Read & Write.

  • My macbook 13 inch late 2007 model got soaked in wine I bought a pro to replace it , I want to use my hard drive on it as an external , I already purchased the case , now the motherboard I understand gets bad but not the hard drive , right?

    my macbook 13 inch late 2007 model got soaked in wine I bought a pro to replace it , I want to use my hard drive froom the old one on the macbook pro and use it as an external , I already purchased the case , now the motherboard I understand gets bad but not the hard drive , right? but everything else still is in there right. ? 
    I got my case from owc computing
    thye used a cloner last time I got the hard drive from them , but the apple had to be working. and now it's just not going to turn on wine is sticky forget about
    no worries I enjoyed it for 6 years could have gone longer I have all this extra gig ram memory, and a new digital drive for ith had broke
    all I want it my hard drive available at owc and make it a usb drive and acc3sss my stutt ? thansk any ideas and also on how I could sell or use the parts I can salvage,    and yay my new pro ix 17 inches silver sleek full ms office i life and i work. included 389 awesome price , no need for new this does awesome . rather than buying an optical drive for 200.00 I got a new computer to me and better for a lot less.          
    I am gratefful , just please help on the hard drive question as external ,
    thanks
    just didnt want to make this sound like a sob sitiuation and also inspire others what can be done.
    and I then will be able to upgrade to Snow Leopard and i life 2011.

    Well as I suspected I love OWC company I pulled out the mac hard drive , they offered me a Macdrive  free trial program to check your drive on PC Windows and yesSSSSSSSSSSSSSSSSSSSSSSSS it all there nothing lost
    woohooooo , thank you but nothing is dead, when you have faith , this was a prayer answered big time I wanted a pro so much and I get to use my 500  plust 250 plus 120 GB drives all of them
    ladies and gentlemen and I get to keep the 2 GB in from my macbook 13 inch and sell all the parts
    yipeee
    thanks for the support, now the case is Solved. !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

  • Unable to repair External Drive disk permissions

    I have an external harddrive which holds my itunes library. Today I have been getting permission errors and now my itunes won't access the files on the drive.
    I have tried to fix the errors with disk utility but now when I try to repair it I get the error: Could not unmount the disk.
    Now I can't even see the iTunes folder on the external drive (I can see others) but I know it is there as 150GB of data is unaccounted for.

    I had the same problem with my Time Machine backup disk and was able to solve it without the serious computer calisthenics recommended by others on the web. I'm running Snow Leopard on an intel iMac and using an external Seagate drive. Here's how I got it fixed.
    1. Unmounted the drive and unplugged it.
    2. Plugged it back in after a decent interval to let the disk spin down.
    3. Shut down the iMac and restarted it a few minutes later (hard reset).
    4. THE DISK DID NOT SHOW UP IN FINDER. Because I had a lot of work to do, I postponed further systems programming.
    5. After about 20 minutes, my Norton utilities found it and began to search it. It was back in finder with r/w permissions for me and everybody else.
    Hope this helps.

  • External drives won't mount after running repair permissions

    None of my external drives will mount after running disk permissions. Drives work fine on my mbpro.
    None of the external drives show up in disk utilities...
    I've try shutting down and unplugging computer. even mini zip drives won't mount.
    I'm running 10.4.11
    PPC G5 2.3Ghz
    Thanks for any help..

    Repairing Permission only deals with installer receipts and system components. Not with mounting or accessing hard drives.
    Have your run Apple DU First Aid? Disk Warrior? Only use latest version for your OS.
    Are you trying to clone your system to external and then repairing permissions? trying to boot from them?
    If cloning, make sure the "Ignore Ownership" flag is unchecked before cloning (but do repair permissions on external drives you intend to boot from, such as a Firewire drive).
    What type of cases and interface are these?

  • Permissions problem - unable to write to external drive

    I have 2 x 2TB external drives connected to which I have been manually copying media from other drives with mixed content.
    The same content has been copied to both from other drives of mixed content - drives 1 and 2 are manual copies of each other.
    I have set both to ignore ownership on Lion but cannot write to drive 1 but I can to drive 2.
    Under Snow Leopard both are writable.  Ignore ownership is not appearing checked though.
    Looks as though I created my user accounts out of order for the new Mountain Lion boot drive - under SL the user UID is 503, for ML 502. Same group.
    Any suggestions about how to rectify?
    Not a huge issue as they're nearly full and I can complete this via Snow Leopard as they will be effectively read only archives when full.
    Any advise on how you would approach this?
    The problem may partly stem from using several non admin accounts for different purposes but I can't see why ML is making one disk read only.
    AC

    Thanks Linc
    That's what's slightly odd.
    As far as I can remember I used disk utility to create these external volumes via Snow Leopard and it's on ML they are showing with Ignore ownership - I can't remember if I ever set that manually as I upgraded a Lion boot disk I'd rarely used on a Mac Pro.
    Found this earlier and not sure if it is relevant as it's the same Mac Pro:
    http://hints.macworld.com/article.php?story=20020418091450891
    (This is kind of a cross-post from Neverland if you see what I mean.)
    AC

  • Group Permissions using External Table

    I have a problem with using an external table for user group permissions.
    I am using OBI authentication but need to use an external table to manage the user’s group permissions. I created two RPD groups, GROUP1 and GROUP2. GROUP1 has access to TABLE1. GROUP2 has access to TABLE2. I created the initialization block with the following SQL:
    Select ‘GROUP’, groupname from groups_tab where username = ‘:USER’
    I also turned on row-wise initialization.
    I created a user, USER1, with access to both RPD groups. I also created corresponding Catalog Group (Settings  Administration  Manage Presentation Catalog Groups and Users  Create a new Catalog Group). I have two dashboard pages PAGE1 and PAGE2. GROUP1 has access to PAGE1 and GROUP2 has access to PAGE2. When I log in as USER1, I have a quick test on the My Dashboard page that displays the GROUP session variable (@{biServer.variables[‘NQ_SESSION.GROUP’]}). The variable displays that USER1 belongs to GROUP1; GROUP2. I still cannot see the dashboard pages PAGE1 and PAGE2. When I go to Answers I cannot see TABLE1 or TABLE2.
    Obviously, I must be missing a step somewhere. Any ideas?
    I have tried the Rittman Mead post (http://www.rittmanmead.com/2007/05/21/using-initialization-blocks-with-ldap-and-database-queries-to-control-authentication-and-authorization/) and I am still not getting the right results.
    Edited by: Canz on Feb 25, 2009 4:39 PM

    It's likely to be a permissioning setup issue rather than your Init Block setup which seems to be working. Start by granting your test user full permissions on the object you want and then start removing them gradually to see where you don't see the dashboard any more. I think you might be missing a Traverse privilege in your dashboard shared folders but I can't check all the possible conditions with seeing your web catalog. Also check the case of your Web Catalog groups and the ones you populate on the Init block.

  • Permissions external hard drives

    I recently switched to a mac and attached external drives used on another computer (pc).  Now I don't have permissions to change the drive name or save documents to the drives.  What do I need to do?

    That drive is probably formatted in the Windows format, NTFS. Mac can not write to that format. It can read from it but can't write to it. So since it can't write to it you can't make any changes to it.
    For it to work seemlessly with the Mac it needs to be formatted in the Mac format, Mac Extended (Journaled). You do that with Disk Utility.
    If you plan on using it on both OS X and Windows then you need to format it either FAT32 or exFAT. Do that on a Windows PC.
    Formatting it in any format will erase all the data on that drive. So if there are files you want to keep copy them to a computer before you do any formatting.

  • I am running Lion 10.7.2 and I have an external drive hooked to my time machine. I can't rename folders and when trying, I get an error code 8076. The checkbox "ignore permissions for this device" does not show on volume info. Help please???

    I am running Lion 10.7.2 and I have an external drive hooked to my time machine. I can't rename folders and when trying, I get an error code 8076. The checkbox "ignore permissions for this device" does not show on volume info. Help please???

    The TIme Machine volume does not have that checkbox.
    I think the issue is with your Finder...
    Go to Finder "Go" menu hold the option key and choose Library. Then go to Preferences trash these files:
    com.apple.finder.plist
    com.apple.sidebarlists.plist
    Then, restart, or log out and in again.
    (You will have to reset a few finder prefs the way you like them.)

Maybe you are looking for