<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://kibale.unm.edu/w/index.php?action=history&amp;feed=atom&amp;title=Media_Repository_Administration</id>
	<title>Media Repository Administration - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://kibale.unm.edu/w/index.php?action=history&amp;feed=atom&amp;title=Media_Repository_Administration"/>
	<link rel="alternate" type="text/html" href="https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;action=history"/>
	<updated>2026-08-05T10:10:35Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.0</generator>
	<entry>
		<id>https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=16&amp;oldid=prev</id>
		<title>KarlPinc: /* User and group management tools */</title>
		<link rel="alternate" type="text/html" href="https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=16&amp;oldid=prev"/>
		<updated>2025-08-29T22:46:41Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;User and group management tools&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 22:46, 29 August 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l100&quot;&gt;Line 100:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 100:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;kcpm-adduser&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;kcpm-adduser&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;: Creates a media user, or adds &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;a media &lt;/del&gt;user to a media group.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;: Creates a media user &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;(a member of the sftp-only group)&lt;/ins&gt;, or adds &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;any &lt;/ins&gt;user to a media group.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;    &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;kcpm-deluser&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;kcpm-deluser&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l116&quot;&gt;Line 116:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 116:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;kcpm-delgroup&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;kcpm-delgroup&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;: Deletes a media group, only if there are no members, and no files in the group.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;: Deletes a media group, only if there are no members, and no files in the group.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Directory and file management tools ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Directory and file management tools ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key kcp_wiki:diff:1.41:old-14:rev-16:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>KarlPinc</name></author>
	</entry>
	<entry>
		<id>https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=14&amp;oldid=prev</id>
		<title>KarlPinc: /* Working from the Unix command line */ Note group membership is not changed until login</title>
		<link rel="alternate" type="text/html" href="https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=14&amp;oldid=prev"/>
		<updated>2025-02-08T17:57:04Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Working from the Unix command line: &lt;/span&gt; Note group membership is not changed until login&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:57, 8 February 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l79&quot;&gt;Line 79:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 79:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;herein.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;herein.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Permission &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;errors &lt;/del&gt;===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Permission &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Errors &lt;/ins&gt;===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Some of the standard Unix commands, like &amp;lt;code&amp;gt;chown&amp;lt;/code&amp;gt;, which&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Some of the standard Unix commands, like &amp;lt;code&amp;gt;chown&amp;lt;/code&amp;gt;, which&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l90&quot;&gt;Line 90:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 90:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;code&amp;gt;/srv/media/&amp;lt;/code&amp;gt; and lists all intermediate directories.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;code&amp;gt;/srv/media/&amp;lt;/code&amp;gt; and lists all intermediate directories.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=== Difficulties Involving Adding Groups ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;When a user is added to or removed from a group, the change does not take effect&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;until after the user logs in.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;This matters, among other times, when adding your login to a group.  Your login normally does not have permission to work with a group when your login is not a group member.  After adding yourself to a group it is usually best to login again to gain immediate access to the group.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== User and group management tools ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== User and group management tools ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key kcp_wiki:diff:1.41:old-13:rev-14:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>KarlPinc</name></author>
	</entry>
	<entry>
		<id>https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=13&amp;oldid=prev</id>
		<title>KarlPinc: /* Directory and file management tools */ Clean up formatting</title>
		<link rel="alternate" type="text/html" href="https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=13&amp;oldid=prev"/>
		<updated>2025-02-08T17:37:10Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Directory and file management tools: &lt;/span&gt; Clean up formatting&lt;/p&gt;
&lt;a href=&quot;https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;amp;diff=13&amp;amp;oldid=12&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>KarlPinc</name></author>
	</entry>
	<entry>
		<id>https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=12&amp;oldid=prev</id>
		<title>KarlPinc: Initial page; wiki markup is incomplete</title>
		<link rel="alternate" type="text/html" href="https://kibale.unm.edu/w/index.php?title=Media_Repository_Administration&amp;diff=12&amp;oldid=prev"/>
		<updated>2025-02-06T23:57:27Z</updated>

		<summary type="html">&lt;p&gt;Initial page; wiki markup is incomplete&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Introduction ==&lt;br /&gt;
&lt;br /&gt;
The KCP media repository controls access using the standard Unix&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/Changing-file-attributes.html  ownership] and&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/File-permissions.html permission] system.&lt;br /&gt;
Specifically, it uses the [https://flylib.com/books/en/4.150.1.60/1/ User-Private-Group] (UPG) idiom.&lt;br /&gt;
This scheme works by associating a group with a directory and giving users, users that are allowed to make changes, membership in the group.&lt;br /&gt;
In this document such groups are called &amp;quot;media groups&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
If you are in a media group you have read/write access to the group&amp;#039;s media files.&lt;br /&gt;
Otherwise, you have read access -- or no access.&lt;br /&gt;
&lt;br /&gt;
This is a simple approach, and has some limitations.&lt;br /&gt;
&lt;br /&gt;
* Any given file can be in only one directory and is associated with only a single group.  Categorizing a file as modifiable by multiple groups is not possible.&lt;br /&gt;
&lt;br /&gt;
* Files and directories have an owner as well as a group.  Typically the owner has read/write permissions.  When a file or directory&amp;#039;s owner is not a member of the file or directory&amp;#039;s group, looking solely at group membership does not reflect the owner&amp;#039;s permissions.&lt;br /&gt;
&lt;br /&gt;
* The UPG idiom assumes that files remain in the directories in which they were initially put, or a sub-directory.  It works because new files are given the group of the directory in which they are placed.  Moving files between directories that belong to different groups requires that the file&amp;#039;s groups be manually changed to reflect the group of the new containing directory.  At least this is required if directories are assumed to control permission, so that who has access to what can be readily determined by where a file is placed in the directory hierarchy.  This problem is mitigated with the use of a bespoke auditing tool, kcpm-audit.&lt;br /&gt;
&lt;br /&gt;
* Membership in a group gives read/write permissions but says nothing about who can read but not change a file.  To grant or deny read-only permission a different mechanism is used, granting or denying access to &amp;quot;other&amp;quot;, anybody who&amp;#039;s not either the file&amp;#039;s owner or a group member.  So determining who has read-only access is different from, and more complicated than determining who has read-write access.  To obtain any kind of access to a file a user must have at least read permissions on the directory containing the file, and all of the parent directories.&lt;br /&gt;
&lt;br /&gt;
Although standard Unix command line tools are available for use and&lt;br /&gt;
can do the job, to simplify and standardize a number of bespoke command&lt;br /&gt;
line tools are made available to do things like create media user&lt;br /&gt;
accounts, create permission controlled media directories, and other&lt;br /&gt;
management tasks.&lt;br /&gt;
&lt;br /&gt;
The system has some naming conventions which aim to simplify&lt;br /&gt;
management and system use.  These are enforced when using the bespoke&lt;br /&gt;
management command line tools.  The conventions are:&lt;br /&gt;
&lt;br /&gt;
* Directories that introduce permission restrictions have names that end in either &amp;quot;_public&amp;quot; or &amp;quot;_private&amp;quot;.  The ones ending in &amp;quot;_public&amp;quot; contain files that are readable by anyone with a media login.  The ones ending in &amp;quot;_private&amp;quot; are readable only by media logins who are members of the directory&amp;#039;s group.&lt;br /&gt;
&lt;br /&gt;
* The groups that categorize access to media files, in which media users are made members, begin with &amp;quot;m-&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== About alternative permission control mechanisms ===&lt;br /&gt;
&lt;br /&gt;
[https://manpages.debian.org/bookworm/acl/acl.5.en.html ACL]s are a&lt;br /&gt;
permission system that can be used in conjunction with the traditional&lt;br /&gt;
Unix permission system.  ACLs provide fine-grained control over who&lt;br /&gt;
has permission to do exactly what to each file.  But ACL use is&lt;br /&gt;
non-obvious, and ACL permissions are unlikely to be visible in&lt;br /&gt;
off-the-shelf graphical remote access mechanisms which use SFTP.&lt;br /&gt;
So while ACLs are available their use is not recommended.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The Groups Built-In to the System ==&lt;br /&gt;
&lt;br /&gt;
The media repository&amp;lt; system is constructed of 2 core groups.&lt;br /&gt;
These are the groups which the operating system is aware of and which provide it control.&lt;br /&gt;
&lt;br /&gt;
;sftp-only&lt;br /&gt;
: Members of this group are &amp;quot;media logins&amp;quot;. A media login is a regular Unix login that is in the &amp;lt;code&amp;gt;sftp-only&amp;lt;/code&amp;gt; group. These logins cannot reach the Unix shell, which processes Unix commands.&lt;br /&gt;
&lt;br /&gt;
;media-admin&lt;br /&gt;
: Members of this group have permission to use the bespoke programs which require elevated system-level privileges, like create new logins or groups.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Working from the Unix command line ==&lt;br /&gt;
&lt;br /&gt;
=== File Locations and Disk Space Management ===&lt;br /&gt;
&lt;br /&gt;
All media files are located in the &amp;lt;code&amp;gt;/srv/media/&amp;lt;/code&amp;gt; directory.&lt;br /&gt;
&lt;br /&gt;
The amount of available space, and space already used, can be seen&lt;br /&gt;
with:&lt;br /&gt;
&lt;br /&gt;
  [https://www.gnu.org/software/coreutils/manual/html_node/df-invocation.html df] -h /srv/media&lt;br /&gt;
&lt;br /&gt;
=== Using the Unix Command Line ===&lt;br /&gt;
&lt;br /&gt;
All the command line tools take a &amp;lt;code&amp;gt;--help&amp;lt;/code&amp;gt; argument, which&lt;br /&gt;
causes the command to display a brief summary of its functionality and&lt;br /&gt;
arguments.  The bespoke command line tools generally have no other&lt;br /&gt;
documentation.  You will need to execute them with the&lt;br /&gt;
&amp;lt;code&amp;gt;--help&amp;lt;/code&amp;gt; argument to determine their usage and arguments.&lt;br /&gt;
Documentation to the standard Unix command line tools are linked&lt;br /&gt;
herein.&lt;br /&gt;
&lt;br /&gt;
=== Permission errors ===&lt;br /&gt;
&lt;br /&gt;
Some of the standard Unix commands, like &amp;lt;code&amp;gt;chown&amp;lt;/code&amp;gt;, which&lt;br /&gt;
changes file or directory ownership, requires special permission to&lt;br /&gt;
run.  If a &amp;quot;permission denied&amp;quot; error is received, try running the&lt;br /&gt;
command with the word &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt; placed in front.&lt;br /&gt;
&lt;br /&gt;
When specifying a file or directory, &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt; will require&lt;br /&gt;
the fully qualified path -- a pathname that starts with&lt;br /&gt;
&amp;lt;code&amp;gt;/srv/media/&amp;lt;/code&amp;gt; and lists all intermediate directories.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== User and group management tools ==&lt;br /&gt;
&lt;br /&gt;
;kcpm-adduser&lt;br /&gt;
: Creates a media user, or adds a media user to a media group.&lt;br /&gt;
  &lt;br /&gt;
;kcpm-deluser&lt;br /&gt;
: Deletes a media user, if the user owns no files. Or removes a media user from a media group.&lt;br /&gt;
&lt;br /&gt;
;kcpm-user-list&lt;br /&gt;
: Lists all members of the sftp-only group, and the groups they are in.&lt;br /&gt;
&lt;br /&gt;
;kcpm-group-list&lt;br /&gt;
: Lists all media groups, and the users they contain.  Media groups are identified by a &amp;quot;m-&amp;quot; prefix.&lt;br /&gt;
&lt;br /&gt;
;kcpm-addgroup&lt;br /&gt;
:Creates a media group.&lt;br /&gt;
&lt;br /&gt;
;kcpm-delgroup&lt;br /&gt;
: Deletes a media group, only if there are no members, and no files in the group.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Directory and file management tools ==&lt;br /&gt;
&lt;br /&gt;
CAUTION:&lt;br /&gt;
  Do not move files between directories which are in different groups.&lt;br /&gt;
  If you do, by a method other than kcpm-mv, the file&amp;#039;s group will not&lt;br /&gt;
  reflect the group of its containing directory.  That means that when&lt;br /&gt;
  a file is moved to a publicly readable directory it can still be&lt;br /&gt;
  modified by the group members of the origin directory, and is not&lt;br /&gt;
  modifiable by the group members of the containing directory.&lt;br /&gt;
&lt;br /&gt;
  If you do move a file, the group of the file must be changed to&lt;br /&gt;
  match the group of its containing directory.  As an alternative to&lt;br /&gt;
  moving (renaming), copy the file and delete the original.  (This&lt;br /&gt;
  will involve downloading and re-uploading, unless you&amp;#039;re working&lt;br /&gt;
  from the Unix prompt.)&lt;br /&gt;
&lt;br /&gt;
  kcpm-audit can be run to report on such discrepancies, and to change&lt;br /&gt;
  group membership of files to reflect that of their containing&lt;br /&gt;
  directory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Directories are rooted at a setgid directory, group sftp-only, so all&lt;br /&gt;
sub-directories are setgid.&lt;br /&gt;
&lt;br /&gt;
kcpm-mkmdir&lt;br /&gt;
  Given a group and a directory name, makes a directory in the group.&lt;br /&gt;
  --private makes a *_private directory&lt;br /&gt;
  --public makes a *_public directory.&lt;br /&gt;
  The named directory is readable by anyone with a login.  The *_private&lt;br /&gt;
  directory is readable only by members of the group.&lt;br /&gt;
&lt;br /&gt;
  This is a convenience utility.  The `chgrp` command can be used to&lt;br /&gt;
  change the group of a directory, and `chmod o-x` will make a&lt;br /&gt;
  directory private.  The *_public and *_private naming conventions&lt;br /&gt;
  are recommended.  They provide clear guidance as to which&lt;br /&gt;
  directories control access.&lt;br /&gt;
&lt;br /&gt;
kcpm-mv&lt;br /&gt;
  Move or rename files or directories&lt;br /&gt;
  Takes care of re-assigning groups when moving files.&lt;br /&gt;
&lt;br /&gt;
  This is a convenience utility.  The `chgrp -R` command can be used&lt;br /&gt;
  to (recursively) change group permissions.  Files should be in the&lt;br /&gt;
  group of their containing directory, so take care using&lt;br /&gt;
  &amp;lt;code&amp;gt;-R&amp;lt;/code&amp;gt; when nested directories are in different groups.&lt;br /&gt;
&lt;br /&gt;
kcpm-audit&lt;br /&gt;
  Given a directory, recursively:&lt;br /&gt;
  Reports on unexpected permissions structures&lt;br /&gt;
    Directories named *_public that are in the group of the parent&lt;br /&gt;
    Directories named *_public that are private (o-x)&lt;br /&gt;
    Directories named *_private that are not private (o+x)&lt;br /&gt;
    Files that are not in the group of their parent directory&lt;br /&gt;
    Files or directories that are owned by a user who is not a member&lt;br /&gt;
      of the file or directory&amp;#039;s group.&lt;br /&gt;
  Or, changes permissions to fix all of the above.&lt;br /&gt;
    &lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/chgrp-invocation.html chgrp] (-R) ...&lt;br /&gt;
  Change the group&lt;br /&gt;
&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/chmod-invocation.html chmod] o-x ...&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/chmod-invocation.html chmod] o+x ...&lt;br /&gt;
  Change public access to a directory.&lt;br /&gt;
&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/rm-invocation.html rm]&lt;br /&gt;
  Delete a file or a directory structure.&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/rmdir-invocation.html rmdir]&lt;br /&gt;
  Delete an empty directory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/mkdir-invocation.html mkdir]&lt;br /&gt;
  Make non-media-controlled directories&lt;br /&gt;
&lt;br /&gt;
[https://www.gnu.org/software/findutils/manual/html_mono/find.html find] . -group name&lt;br /&gt;
  Find everything belonging to a group.  Find has many options, and&lt;br /&gt;
  can even be used to execute commands on the files found.  It is&lt;br /&gt;
  useful for things like bulk changing of file ownership.&lt;br /&gt;
&lt;br /&gt;
[https://www.gnu.org/software/coreutils/manual/html_node/ls-invocation.html ls] -lhR&lt;br /&gt;
  Show everything in the file system&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Techniques:&lt;br /&gt;
&lt;br /&gt;
Anything put in the top-level directory are read/writable to anyone&lt;br /&gt;
with a login.&lt;br /&gt;
&lt;br /&gt;
Make a test login to test access:&lt;br /&gt;
&lt;br /&gt;
A test login can be created, and put into any set of groups.&lt;br /&gt;
This allows for testing of access, and emulating what a user who&amp;#039;s in&lt;br /&gt;
the same set of groups is allowed to do.&lt;br /&gt;
&lt;br /&gt;
Layer directories to control access:&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Regular&amp;quot; directories can be used at any level to structure content.&lt;br /&gt;
&lt;br /&gt;
If you have topdir_private/subdir, in respective groups topdir and&lt;br /&gt;
subdir, consider the content of subdir.  Only topdir members have&lt;br /&gt;
access.  Members of subdir have read/write access, and topdir members&lt;br /&gt;
have read-only access.&lt;/div&gt;</summary>
		<author><name>KarlPinc</name></author>
	</entry>
</feed>