[Samba] Folder ACLs

Jeremy Allison jra at samba.org
Mon Oct 25 13:33:43 MDT 2010

On Mon, Oct 25, 2010 at 02:04:30AM -0700, Derek Lewis wrote:
> I am running Samba 3.6 and I have implemented extended attributes and acls
> for my shares.  I want to make directory behavior as similar as possible to
> client Windows XP.

3.5.x or 3.6 ? 3.6 is not released yet.

> When I open the properties tab on a directory in a share, under user names I
> see two additional users: CREATOR GROUP and CREATOR OWNER.  This seems to be
> a consequence of the ACL translation, as copying or moving this directory
> back to the PC results in the user list to the same users as the directories
> on the PC.  The inherit permissions flag is not set on the share folder
> although it is set on the PC.
> I have tried to edit the folder permissions from the Windows property menu
> for both the file owner as well as the CREATOR OWNER user above, and the
> making a change as deselecting full control flag, reverts back to the
> original state. 
> I can post my configuration if required, I intended to map permissions as
> directly as possible, though leave them flexible so that I can edit them
> later if required.
> I saw the posting earlier regarding an experimental patch for Samba 3.6 ACL
> handling.  Are these changes already included in the next version of 3.x
> Samba?

The fixes for the acl_xattr module are in the git v3-6-test and master
trees. Here is the jumbo patch that will apply to 3.5.6 and bring the
ACL handling to functional parity with the later code.

Please test and let me know if it works for you.


More information about the samba mailing list