File path sensors · GraphQL enum

AccessMask enum

A single permission bit in an ACL access mask, harmonized across Windows and Darwin to NTFS-style vocabulary.

Values

Enum Value Description

FILE_READ_DATA

Read the file's primary data stream (or, on directories, list contents).

FILE_WRITE_DATA

Write to (overwrite portions of) the file's primary data stream, or create files in a directory.

FILE_APPEND_DATA

Append data to the file, or create subdirectories within a directory.

FILE_READ_EA

Read extended attributes / named streams metadata.

FILE_WRITE_EA

Write extended attributes / named streams metadata.

FILE_EXECUTE

Execute the file (Darwin) or traverse the directory (Windows / Darwin).

FILE_DELETE_CHILD

On a directory, delete a file or subdirectory within it even if the child denies DELETE.

FILE_READ_ATTRIBUTES

Read the file's basic attributes (timestamps, size, mode bits).

FILE_WRITE_ATTRIBUTES

Modify the file's basic attributes.

DELETE

Delete the object itself.

READ_CONTROL

Read the object's security descriptor (owner, DACL).

WRITE_DAC

Modify the object's discretionary access-control list.

WRITE_OWNER

Change the object's owner.

SYNCHRONIZE

Use the object as a synchronization primitive (Windows). Has no equivalent semantics on Darwin and is preserved verbatim.

ACCESS_SYSTEM_SECURITY

Modify the object's system ACL / audit policy (privileged on Windows).

MAXIMUM_ALLOWED

Windows-only sentinel that resolves at access time to the maximum permissions the subject is allowed.

GENERIC_ALL

Generic bit that resolves to the full set of specific access rights for this object class.

GENERIC_EXECUTE

Generic execute / traverse bit (resolves to a subset of the specific bits).

GENERIC_WRITE

Generic write bit (resolves to a subset of the specific bits).

GENERIC_READ

Generic read bit (resolves to a subset of the specific bits).

Used by

  • AclEntryMacOS type: A single macOS Access Control Entry on a file or directory.
  • AclEntryWindows type: A single Windows Access Control Entry on a file or directory.

Example

Example

"FILE_READ_DATA"