linux-nfs.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Mike Grant <mggr@pml.ac.uk>
To: Christoph Bartoschek <bartoschek@gmx.de>
Cc: <linux-nfs@vger.kernel.org>
Subject: Re: Spurious permission denied
Date: Wed, 20 Jun 2012 03:16:00 +0100	[thread overview]
Message-ID: <4FE13260.1050002@pml.ac.uk> (raw)
In-Reply-To: <43v5b9-ifa.ln1@barney.bruehl.pontohonk.de>

On 06/19/2012 10:58 AM, Christoph Bartoschek wrote:
> we still have the problem that some users get permission denied for
> directories they normally can access. The problem only affects a single user
> at a time and automatically goes away after about 30 minutes.

We've seen this error quite a bit too, though never managed to pin it 
down well enough to report it as it's intermittent and unpredictable.  I 
agree that it seems to be server side and we tried a few things to get 
rid of it.  I'm not sure if they worked or if it's just in remission, 
but the two things that seemed to help most were:
  a) increase the amount of memory in the server (we went from 6 to 24GB)
  b) reduce dependence on NIS by (ick) hard coding key users into the 
server's /etc/passwd file.

We tried the latter because our NIS server was struggling a lot at the 
time and I'm not sure what happens if the NFS server fails to get a NIS 
response in a timely manner or gets a failed response (i,e. it can't 
identify the user).

It may be worth you seeing if the user id resolves correctly on the 
server at the time of the failure.  It might also be interesting to know 
what happens if you restart the NFS server when you have this problem. 
I'm wondering if the 30min thing indicates a cached bad credential or 
something that expires after a bit or perhaps the NFS server thread just 
gets recycled..

It may also be worth doing a capture on the server side at the same 
time, as that might show issues with NIS or whatever you use.  There's a 
good chance it may not be visible after the problem has occurred though, 
if it's cached somewhere.

Anyway, sorry that's not directly helpful, but maybe a few things to try!

Cheers,

Mike.

<br />
<hr />
<p><font face="Arial" size="1">
Plymouth Marine Laboratory<br />
Registered Office: <br />
Prospect Place<br />
The Hoe<br />
Plymouth  PL1 3DH
</font></p>

<p><font face="Arial" size="1">Website: <a href="http://www.pml.ac.uk">www.pml.ac.uk</a>
<br />
<a href="http://www.pml.ac.uk/pdf/PML%20Annual%20Review%202011_2.pdf">Click here for the latest PML Annual Review</a>
<br />
Registered Charity No. 1091222<br />
PML is a company limited by guarantee<br />
registered in England & Wales<br />
company number 4178503</font></p>

<p><font face="Arial" size="1" color="green">Please think before you print.</font></p>

<hr />

<p><font face="Arial" size="1">This e-mail, its content and any file attachments are confidential.</font></p>

<p><font face="Arial" size="1">If you have received this e-mail in error please do not copy, disclose it to any third party or use the contents or attachments in any way. Please notify the sender by replying to this e-mail or e-mail forinfo@pml.ac.uk and then delete the email without making any copies or using it in any other way.</font></p>

<p><font face="Arial" size="1">The content of this message may contain personal views which are not the views of Plymouth Marine Laboratory unless specifically stated.</font></p>

<p><font face="Arial" size="1">You are reminded that e-mail communications are not secure and may contain viruses. Plymouth Marine Laboratory accepts no liability for any loss or damage which may be caused by viruses.</font></p>

<hr />
<br />
<br />


      parent reply	other threads:[~2012-06-20  2:21 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-06-19  9:58 Spurious permission denied Christoph Bartoschek
2012-06-19 13:39 ` Myklebust, Trond
2012-06-19 18:23   ` Christoph Bartoschek
2012-06-20  2:16 ` Mike Grant [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4FE13260.1050002@pml.ac.uk \
    --to=mggr@pml.ac.uk \
    --cc=bartoschek@gmx.de \
    --cc=linux-nfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).