[Samba] Full control access rights mapped as execute

Petr Kopecky kejpi at centrum.cz
Wed Apr 23 19:15:13 GMT 2008

Hi there,

I have some problem with Windows access rights mapping on Samba 3.0.28. I am
using XFS filesystem and ACL is working.

This is a part of my smb.conf:

  domain logons = Yes
  preferred master = Yes
  map acl inherit = Yes
  map archive = Yes
  map hidden = Yes
  map system = Yes
  veto files = /*.eml/*.nws/*.{*}/
  veto oplock files = /*.doc/*.xls/*.mdb/
  create mask = 0755
  directory mask = 0755

  comment = Profile Share
  path = /data/samba/profiles
  read only = No
  profile acls = Yes
  browseable = No  

  comment = Shared Data
  path = /data/samba/share
  public = No
  writable = No
  write list = @smbusers
  browseable = Yes

This configuration works fine for profiles where I need to map hidden and
system flags as windows uses them. But those flags are mapped in execute
flags not acl rights, but it works.

getfacl /data/samba/profiles/some.user
# file: data/samba/profiles/some.user
# owner: someuser
# group: smbusers

The problem is on other share. If anyone changes the premissions on the file
then access rights are mapped to execute flag not ACL and it is very
If domain user rights are set to write and modify, it is stored as group 
execute, if others are granted for write and modify, then execute flag for
others is set. But these flags are interpreted as system and hidden.
Additionally all created files have owner's executable bit set which means

Could you please help me what should I set to have DOS access rights working
together with windows ACL? I cannot find this simple information on net :-(

Thank you!


Ing. Petr Kopecky
E-mail: kejpi at centrum.cz

OpenDocument is now international standard ISO/IEC 26300. Use OpenOffice!
It's free for everyone :-)


More information about the samba mailing list