All of lore.kernel.org
 help / color / mirror / Atom feed
From: Florian Manschwetus <florianmanschwetus@gmx.de>
To: "Myklebust, Trond" <Trond.Myklebust@netapp.com>
Cc: "linux-nfs@vger.kernel.org" <linux-nfs@vger.kernel.org>
Subject: Re: nfs4 acl problems using Nexenta-Communityedition Server and debian testing clients
Date: Wed, 05 Dec 2012 17:23:56 +0100	[thread overview]
Message-ID: <50BF751C.90808@gmx.de> (raw)
In-Reply-To: <4FA345DA4F4AE44899BD2B03EEEC2FA90B337973@SACEXCMBX04-PRD.hq.netapp.com>

Am 05.12.2012 16:41, schrieb Myklebust, Trond:
> On Wed, 2012-12-05 at 10:48 +0100, Florian Manschwetus wrote:
>> I setup a little network using a central storage server based on
>> nexenta-Communityedition clients use homes and several shares via nfs4.
>> As we have some shares used for webdevelopment purposes it is desired to
>> have acls inherited for specific groups access and user access
>
> Inherited acls are inherently incompatible with basic POSIX
> open(O_CREAT). The latter takes a mode bit argument that will clobber
> your inherited acl.
>
>> (webserver user). I also have trouble with sticky-bit inheritance, which
>> is needed as the linux gui tools unaware of nfs-acls. Are there plans to
>> improve support for nfs acls?
>>
>> Maybe someone here have successfully a solaris nfs server running with
>> linux clients using extended acls, with inheritance working as expected?
>>
>> It is really annoying having users not allowed to view/edit files/dirs
>> they copied just the moment.
>
> This is not the right list for requesting gui tool changes. The right
> address would be the GNOME, KDE and XFCE project mail lists.
>
Sounds reasonable, but at least a cp -r /share/orig /share/copy should 
produce a copy with expected acls (as defined on /share).

My normal outcoming is that the user coping the directory is unallowed 
to access it, by @owner-deny ace. Which is really ugly. Unfortunately I 
can't find a mode making the server to enforce correct inheritance 
(disallowing the users to alter acls, mode, etc via nfs, maybe with 
nfs-acls tools but this isn't really needed).

Regards,
Florian

  reply	other threads:[~2012-12-05 16:24 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-12-05  9:48 nfs4 acl problems using Nexenta-Communityedition Server and debian testing clients Florian Manschwetus
2012-12-05 15:41 ` Myklebust, Trond
2012-12-05 16:23   ` Florian Manschwetus [this message]
2012-12-05 18:21     ` Myklebust, Trond

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=50BF751C.90808@gmx.de \
    --to=florianmanschwetus@gmx.de \
    --cc=Trond.Myklebust@netapp.com \
    --cc=linux-nfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.