public inbox for linux-nfs@vger.kernel.org
 help / color / mirror / Atom feed
From: Steve French <smfrench@gmail.com>
To: "J. Bruce Fields" <bfields@fieldses.org>
Cc: linux-nfs@vger.kernel.org, nfsv4@linux-nfs.org,
	Trond Myklebust <Trond.Myklebust@netapp.com>,
	ffilzlnx@linux.vnet.ibm.com, jra@samba.org, agruen@suse.de
Subject: Re: POSIX ACL support for NFSV4 (using sideband protocol)
Date: Wed, 2 Sep 2009 15:53:17 -0500	[thread overview]
Message-ID: <524f69650909021353o1e055cbema16495c57cb9909b@mail.gmail.com> (raw)
In-Reply-To: <20090902202206.GJ17884@fieldses.org>

On Wed, Sep 2, 2009 at 3:22 PM, J. Bruce Fields<bfields@fieldses.org> wrote=
:
> On Wed, Sep 02, 2009 at 01:56:23PM -0500, Steve French wrote:
>> "J. Bruce Fields" <bfields@fieldses.org> wrote on 09/02/2009 11:42:43 AM=
:
>> > On Wed, Sep 02, 2009 at 05:54:20PM +0530, Aneesh Kumar K.V wrote:
>> > > This patch series implement POSIX ACL support for NFSV4 clients
>> > > using sideband protocol.
>> >
>> > What motivates this? =A0Who exactly wants this and why? =A0 What would=
 be
>> > the advantages compared to other options, such as:
>>
>> The most obvious reason to me is that security information
>> can be lost as the ACL which was generated by Linux utilities and
>> client acl tools (which get/set posix acls) are converted by the Linux n=
fs
>> v4 client
>
> The kernel v4 client doesn't do that--it passes untouched v4 acls to and
> from userspace.

1) Passing untouched ACLs doesn't help as these ACLs would be NFS specific,
and unrecognized by the default Linux tools and GUIs.  Access Control on
file and directory objects is a "system feature" - part of the OS (it has b=
een
that way since at least OS/2, not just Windows, MacOS, Solaris etc..)
 You wouldn't require the user to use different tools for modifying ACLs in
Windows, MacOS and require that the user try to figure out the ACL model of
the underlying file system before deciding what tool to use and what permis=
sions
to apply to his home directory
2) If POSIX->NFSv4 client mapping is done (as had been suggested IIRC
by others in the past) at least you lose less data (NFSv4 ACLs are "richer"
in function than POSIX ACLs - so at least with the POSIX->NFSv4->POSIX
case you are limiting the user to the subset of choices which are actually
going to be able to be stored, no inheritence etc.)




--=20
Thanks,

Steve
_______________________________________________
NFSv4 mailing list
NFSv4@linux-nfs.org
http://linux-nfs.org/cgi-bin/mailman/listinfo/nfsv4

  reply	other threads:[~2009-09-02 20:53 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-09-02 18:56 POSIX ACL support for NFSV4 (using sideband protocol) Steve French
2009-09-02 20:22 ` J. Bruce Fields
2009-09-02 20:53   ` Steve French [this message]
2009-09-03  6:20     ` Ondrej Valousek
2009-09-03  7:46       ` Muntz, Daniel
2009-09-03 10:41         ` Aneesh Kumar K.V
2009-09-03 13:36         ` Steve French
2009-09-03 13:54           ` J. Bruce Fields
2009-09-03 13:57             ` Steve French
2009-09-03 15:01         ` David P. Quigley
2009-09-03 13:54       ` Steve French
2009-09-03 13:55         ` J. Bruce Fields
2009-09-03 15:35           ` Steve French
     [not found]             ` <524f69650909030835s41e78436p4b67594cf91de639-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2009-09-03 16:08               ` J. Bruce Fields
2009-09-03 14:09         ` Trond Myklebust
2009-09-03 18:55           ` Andreas Gruenbacher
2009-09-03 14:16     ` J. Bruce Fields
2009-09-03 15:14       ` Steve French
2009-10-05 16:31   ` Andreas Gruenbacher
2009-10-05 16:44     ` Steve French
2009-10-05 17:09       ` Andreas Gruenbacher
2009-10-05 17:19         ` Steve French
  -- strict thread matches above, loose matches on Subject: below --
2009-09-02 19:06 Steve French
2009-09-02 12:24 Aneesh Kumar K.V
2009-09-02 16:42 ` J. Bruce Fields
2009-09-02 17:49   ` Aneesh Kumar K.V
2009-09-02 18:27     ` J. Bruce Fields
2009-09-03 19:09   ` Andreas Gruenbacher

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=524f69650909021353o1e055cbema16495c57cb9909b@mail.gmail.com \
    --to=smfrench@gmail.com \
    --cc=Trond.Myklebust@netapp.com \
    --cc=agruen@suse.de \
    --cc=bfields@fieldses.org \
    --cc=ffilzlnx@linux.vnet.ibm.com \
    --cc=jra@samba.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=nfsv4@linux-nfs.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox