Python 查看文件的讀寫權限方法


 
# -*- coding: utf-8 -*-
# @author flynetcn
import sys, os, pwd, stat, datetime;
LOG_FILE = '/var/log/checkDirPermission.log';
nginxWritableDirs = [
'/var/log/nginx',
'/usr/local/www/var',
];
otherReadableDirs = [
'/var/log/nginx',
'/usr/local/www/var/log',
];
dirs = [];
files = [];
def logger(level, str):
    logFd = open(LOG_FILE, 'a');
    logFd.write(datetime.datetime.now().strftime('%Y-%m-%d %H:%M:%S.%f')+": "+("WARNING " if level else "NOTICE ")+str);
    logFd.close();
def walktree(top, callback):
    for f in os.listdir(top):
        pathname = os.path.join(top, f);
        mode = os.stat(pathname).st_mode;
        if stat.S_ISDIR(mode):
            callback(pathname, True);
            walktree(pathname, callback);
        elif stat.S_ISREG(mode):
            callback(pathname, False);
        else:
            logger(1, "walktree skipping %s\n" % (pathname));
def collectPath(path, isDir=False):
    if isDir:
        dirs.append(path);
    else:
        files.append(path);
     
def checkNginxWritableDirs(paths):
    uid = pwd.getpwnam('nginx').pw_uid;
    gid = pwd.getpwnam('nginx').pw_gid;
    for d in paths:
        dstat = os.stat(d);
        if dstat.st_uid != uid:
            try:
                os.chown(d, uid, gid);
            except:
                logger(1, "chown(%s, nginx, nginx) failed\n" % (d));
def checkOtherReadableDirs(paths, isDir=False):
    for d in paths:
        dstat = os.stat(d);
        if isDir:
            checkMode = 5;
            willBeMode = dstat.st_mode | stat.S_IROTH | stat.S_IXOTH;
        else:
            checkMode = 4;
            willBeMode = dstat.st_mode | stat.S_IROTH;
        if int(oct(dstat.st_mode)[-1:]) & checkMode != checkMode:
            try:
                    os.chmod(d, willBeMode);
            except:
                logger(1, "chmod(%s, %d) failed\n" % (d, oct(willBeMode)));
if __name__ == "__main__":
    for d in nginxWritableDirs:
        walktree(d, collectPath)
    dirs = dirs + files;
    checkNginxWritableDirs(dirs);
    dirs = [];
    files = [];
    for d in otherReadableDirs:
        walktree(d, collectPath)
    checkOtherReadableDirs(dirs, True);
    checkOtherReadableDirs(files, False);
 
 

os.chmod(path,mode) 這個方法應該很簡單,只需要2個參數,一個是路徑,一個是說明路徑的模式,下面列出了這個用法中可以使用的一些常用的模式:

stat.S_ISUID: Set user ID on execution. 不常用

stat.S_ISGID: Set group ID on execution. 不常用

stat.S_ENFMT: Record locking enforced. 不常用

stat.S_ISVTX: Save text image after execution. 在執行之后保存文字和圖片

stat.S_IREAD: Read by owner. 對於擁有者讀的權限

stat.S_IWRITE: Write by owner. 對於擁有者寫的權限

stat.S_IEXEC: Execute by owner. 對於擁有者執行的權限

stat.S_IRWXU: Read, write, and execute by owner. 對於擁有者讀寫執行的權限

stat.S_IRUSR: Read by owner. 對於擁有者讀的權限

stat.S_IWUSR: Write by owner. 對於擁有者寫的權限

stat.S_IXUSR: Execute by owner. 對於擁有者執行的權限

stat.S_IRWXG: Read, write, and execute by group. 對於同組的人讀寫執行的權限

stat.S_IRGRP: Read by group. 對於同組讀的權限

stat.S_IWGRP: Write by group. 對於同組寫的權限

stat.S_IXGRP: Execute by group. 對於同組執行的權限

stat.S_IRWXO: Read, write, and execute by others. 對於其他組讀寫執行的權限

stat.S_IROTH: Read by others. 對於其他組讀的權限

stat.S_IWOTH: Write by others. 對於其他組寫的權限

stat.S_IXOTH: Execute by others. 對於其他組執行的權限

1
2
3
4
5
6
7
8
>>> os.stat('test')
posix.stat_result(st_mode=33204, st_ino=93328670, st_dev=18L, st_nlink=1, st_uid=30448, st_gid=1000, st_size=0, st_atime=1445932321, st_mtime=1445932321, st_ctime=1445932321)
>>> os.stat('test').st_mode
33204
>>> oct(os.stat('test').st_mode)
'0100664'
>>> oct(os.stat('test').st_mode)[-3:]
'664'

 

 

 

在Python我們要判斷一個文件對當前用戶有沒有讀、寫、執行權限,我們通常可以使用os.access函數來實現,比如:

# 判斷讀權限
os.access(<my file>, os.R_OK)
# 判斷寫權限
os.access(<my file>, os.W_OK)
# 判斷執行權限
os.access(<my file>, os.X_OK)
# 判斷讀、寫、執行權限
os.access(<my file>, os.R_OK | os.W_OK | os.X_OK)
1
2
3
4
5
6
7
8
但是如果要判斷任意一個指定的用戶對某個文件是否有讀、寫、執行權限,Python中是沒有默認實現的,此時我們可以通過下面的代碼斷來判斷

import os
import pwd
import stat

def is_readable(cls, path, user):
user_info = pwd.getpwnam(user)
uid = user_info.pw_uid
gid = user_info.pw_gid
s = os.stat(path)
mode = s[stat.ST_MODE]
return (
((s[stat.ST_UID] == uid) and (mode & stat.S_IRUSR > 0)) or
((s[stat.ST_GID] == gid) and (mode & stat.S_IRGRP > 0)) or
(mode & stat.S_IROTH > 0)
)

def is_writable(cls, path, user):
user_info = pwd.getpwnam(user)
uid = user_info.pw_uid
gid = user_info.pw_gid
s = os.stat(path)
mode = s[stat.ST_MODE]
return (
((s[stat.ST_UID] == uid) and (mode & stat.S_IWUSR > 0)) or
((s[stat.ST_GID] == gid) and (mode & stat.S_IWGRP > 0)) or
(mode & stat.S_IWOTH > 0)
)

def is_executable(cls, path, user):
user_info = pwd.getpwnam(user)
uid = user_info.pw_uid
gid = user_info.pw_gid
s = os.stat(path)
mode = s[stat.ST_MODE]
return (
((s[stat.ST_UID] == uid) and (mode & stat.S_IXUSR > 0)) or
((s[stat.ST_GID] == gid) and (mode & stat.S_IXGRP > 0)) or
(mode & stat.S_IXOTH > 0)
)


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM