IDMAP_BOTH support in smbd

Andrew Bartlett abartlet at
Mon Mar 26 05:25:56 MDT 2012

On Wed, 2012-03-21 at 22:23 +0100, Stefan (metze) Metzmacher wrote:

> No, the acl mapping code also needs it and that is actually the problem.
> As the acl code generates posix aces for users instead of groups,
> if a mapping uses IDMAP_BOTH.

I've been trying to get this working, in terms of sorting out the cache
layers to know about IDMAP_BOTH.  But I'm really quite stuck, the
caching semantics of the two caching layers is quite complex, and my
'simple' changes seem to have broken something. 

In particular, samba3.winbind.wbclient fails, but only when part of a
longer 'make test', which indicates a problem with the caching layer.
Even in my testing on origin/master, it doesn't seem to be perfectly
deterministic if builtin\users is given an allocated GID, or a failed

I'm really at my wits end, and I wonder if someone else could take on
getting s3fs to handle these id maps, so I can tackle some of the many
other challenges?

My branch (on top of my krb5 work) so far is at:;a=shortlog;h=refs/heads/idmap


Andrew Bartlett

Andrew Bartlett                      
Authentication Developer, Samba Team 

More information about the samba-technical mailing list