From: Jan Kara <jack@suse.cz>
To: "J. Bruce Fields" <bfields@fieldses.org>
Cc: Andreas Gruenbacher <agruenba@redhat.com>,
linux-fsdevel@vger.kernel.org, lsf-pc@lists.linux-foundation.org
Subject: Re: [Lsf-pc] [LSF/MM ATTEND] Richacls
Date: Tue, 13 Jan 2015 11:14:35 +0100 [thread overview]
Message-ID: <20150113101435.GA28924@quack.suse.cz> (raw)
In-Reply-To: <20150112223016.GB1940@fieldses.org>
On Mon 12-01-15 17:30:16, J. Bruce Fields wrote:
> On Mon, Jan 12, 2015 at 04:06:44PM -0500, Andreas Gruenbacher wrote:
> > I would like to discuss the status and next steps for completing
> > richacl support (http://en.wikipedia.org/wiki/Richacls) in
> > the vfs, local file systems, nfs, cifs.
> >
> > Right now, we don't have kernel support for a file permission
> > model powerful enough to support both POSIX permissions and
> > NFSv4 / CIFS access control lists at the same time. As a result,
> > support for the NFSv4 and CIFS permission models is very limited,
> > and permission wise, Linux is neither a very good client nor
> > server to other systems. For example, the permission to only
> > append to a file or to take ownership of a file cannot be
> > represented. When files are copied across systems, file
> > permissions change or are lost. This should be improved.
> >
> > I've started working on this a long time ago but didn't have
> > enough time to complete it. More recently, Aneesh Kumar has
> > spent time on this topic (http://lwn.net/Articles/596517/) but
> > eventually also stopped working on it. Things have improved on
> > my side and I'll be able to work on this again now, though.
>
> This has been stalled a while and it will be good to see it unstuck.
>
> Don't know if if it needs time on the official schedule but I'd look
> forward to discussing it in the hallway....
As far as I remember (and I'm sorry if I'm too explicit here) the main
issue is to find a way of implementing the features necessary for RichACLs
in a way acceptable for Al and Christoph Hellwig. I specifically remember
Christoph having strong opinions on the rich ACL features as such. I don't
remember the details but the first step is IMO that someone who understands
the needs of NFS and Samba talks to them about what would be an acceptable
extension of the permission model we have.
Honza
--
Jan Kara <jack@suse.cz>
SUSE Labs, CR
next prev parent reply other threads:[~2015-01-13 10:14 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <1626890778.1513173.1421087867777.JavaMail.zimbra@redhat.com>
2015-01-12 21:06 ` [LSF/MM ATTEND] Richacls Andreas Gruenbacher
2015-01-12 21:54 ` Jeremy Allison
2015-01-12 22:30 ` J. Bruce Fields
2015-01-13 10:14 ` Jan Kara [this message]
2015-01-13 15:07 ` [Lsf-pc] " Andreas Gruenbacher
2015-01-13 16:48 ` Jeremy Allison
2015-01-13 17:23 ` Andreas Gruenbacher
2015-01-13 17:29 ` Jeremy Allison
2015-01-13 17:40 ` J. Bruce Fields
2015-01-13 18:04 ` Jeremy Allison
2015-01-13 19:53 ` Frank Filz
2015-01-13 20:24 ` 'J. Bruce Fields'
2015-01-13 20:26 ` Jeremy Allison
2015-01-13 20:30 ` Jeremy Allison
2015-01-13 20:35 ` Frank Filz
2015-01-14 7:57 ` Andreas Gruenbacher
2015-01-13 21:04 ` Jan Kara
2015-01-13 21:16 ` J. Bruce Fields
2015-01-13 21:20 ` Jeremy Allison
2015-01-13 21:27 ` Frank Filz
2015-01-13 21:31 ` Jan Kara
2015-01-14 8:53 ` Andreas Gruenbacher
2015-01-14 12:01 ` Jeff Layton
2015-01-14 16:11 ` J. Bruce Fields
2015-01-14 17:21 ` Frank Filz
2015-01-23 5:31 ` Steve French
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150113101435.GA28924@quack.suse.cz \
--to=jack@suse.cz \
--cc=agruenba@redhat.com \
--cc=bfields@fieldses.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=lsf-pc@lists.linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).