vfs_fruit bug in ACL get/set - [PATCH] attached.

Ralph Böhme slow at samba.org
Wed Mar 7 20:53:13 UTC 2018


Hi!

On Fri, Mar 02, 2018 at 02:35:13PM -0800, Jeremy Allison wrote:
> On Fri, Mar 02, 2018 at 11:17:00PM +0100, Ralph Böhme wrote:
> > 
> > I was thinking about moving setting *and* getting to a lower layer. Whichever
> > layer ends up doing it, should be fixed to correctly filter of course. I'm just
> > questioning whether keeping this in fruit is the right thing to do when we're
> > starting to use this more broadly.
> 
> Well it's still pretty fruit-specific. For example,
> I don't want the SMB2 unix extensions to return the
> global_sid_Unix_NFS_Users or global_sid_Unix_NFS_Groups,
> as that's info that the client shouldn't have (IMHO),
> as it's already covered by the owner and group SIDs
> in the ACL returned. My current prototype code for
> SMB2 unix only returns global_sid_Unix_NFS_Mode.
> 
> I understand why they did it for NFS or fruit, but
> I really want the SMB2 unix design to be cleaner
> than that - and one of the mandates I set myself
> was "No UID's/GID's" - only SIDs.

what is the rationale? Why return the mode but not the uid/gid. Are we *sure*
that no SMB2 POSIX extensions client will ever need this in the future?

-slow

-- 
Ralph Boehme, Samba Team       https://samba.org/
Samba Developer, SerNet GmbH   https://sernet.de/en/samba/
GPG Key Fingerprint:           FAE2 C608 8A24 2520 51C5
                               59E4 AA1E 9B71 2639 9E46



More information about the samba-technical mailing list