IDMAP_BOTH support in smbd

Michael Adam obnox at
Mon Mar 26 16:30:18 MDT 2012

Hi Andrew,

Andrew Bartlett wrote:
> On Wed, 2012-03-21 at 22:23 +0100, Stefan (metze) Metzmacher wrote:
> > No, the acl mapping code also needs it and that is actually the problem.
> > As the acl code generates posix aces for users instead of groups,
> > if a mapping uses IDMAP_BOTH.
> > 
> I've been trying to get this working, in terms of sorting out the cache
> layers to know about IDMAP_BOTH.  But I'm really quite stuck, the
> caching semantics of the two caching layers is quite complex, and my
> 'simple' changes seem to have broken something. 
> In particular, samba3.winbind.wbclient fails, but only when part of a
> longer 'make test', which indicates a problem with the caching layer.
> Even in my testing on origin/master, it doesn't seem to be perfectly
> deterministic if builtin\users is given an allocated GID, or a failed
> mapping. 
> I'm really at my wits end, and I wonder if someone else could take on
> getting s3fs to handle these id maps, so I can tackle some of the many
> other challenges?

I can try and find some time to brood over the problem hopefully
together with Metze. If you can be more productive in other areas
for now, then you should probably switch. :)

Cheers - Michael

> My branch (on top of my krb5 work) so far is at:  
> Thanks,
> Andrew Bartlett
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 206 bytes
Desc: not available
URL: <>

More information about the samba-technical mailing list