Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Disk-File Security Commands
Safeguard Reference Manual 520618-030
8 - 4
Disk-File Security Command Summary
An open request that passes the Safeguard authorization check can nevertheless fail.
For example, if a process attempts to open a file that is already open with exclusive
access, the open attempt fails with file error 12 (file in use). (For more information, see
the Guardian Procedure Calls Reference Manual.)
Disk-File Security Command Summary
Table 8-2 gives a brief description of the disk-file security commands. The remainder of
this section describes these commands in detail.
Yes Yes - Yes Yes Yes
Yes Yes - Yes No No
Yes No - - - No
Note.
If a persistent protection record exists for the new file name, the renamed file assumes
that persistent ACL. If the current file has a Safeguard ACL and the new file name does not
have a persistent protection record, the renamed file assumes the ACL of the current file.
However, if the PERSISTENT flag is ON in the current file’s protection record, that ACL is not
transferred to the renamed file.
Table 8-2. Disk-File Security Command Summary (page 1 of 2)
Command Description
ADD DISKFILE* Adds a disk-file authorization record with the specified attributes.
Current de
fault disk-file attribute values are used for any attributes
not specified in the ADD DISKFILE command.
ADD DISKFILE-
P
ATTERN*
Adds a diskfile pattern for files in specified location. Current default
diskfile-pattern attribute values are used for any attributes not
specified in the ADD DISKFILE command.
ALTER DISKFILE* Changes one or more attribute values in an authorization record. For
all disk-file attributes except ACCESS, AL
TER DISKFILE replaces
the current attribute value with the specified value. For the ACCESS
attribute, ALTER DISKFILE changes the existing ACL to incorporate
access-spec.
ALTER DISKFILE-
P
ATTERN*
Changes one or more of the security attributes in the diskfile-pattern
authorization record.
DELETE DISKFILE* Deletes a disk-file authorization record. After deletion, all accesses to
the file a
re subject to standard Guardian security checking. The
original security is restored for the deleted file.
DELETE DISKFILE-
P
ATTERN*
Removes a diskfile pattern from the Safeguard database by deleting
the disk-file authorization record.
Table 8-1. Access Authority Required to Rename a File
Current File Name New File Name Result