Re: [RFC PATCH] CIFS posix acl permission checking

Jeremy Allison <[email protected]>
Newsgroups gmane.linux.file-systems.cifs,gmane.linux.file-systems,gmane.linux.kernel
Message-ID <20100304173345.GE18904@samba1>
On Thu, Mar 04, 2010 at 10:51:53AM -0500, simo wrote:
> 
> Letting a different user access the mount point *is* a security
> violation in itself. The CIFS security model lies in per user sessions.
> The right way to fix the problem is multi-session mounts. Allowing a
> different user to use a user session is a violation of the security
> model of CIFS.

Multi-session mounts are the only sane fix. This is what Windows
does in their redirectory (when a process with different credentials
traverses into a mount point a new sessionsetup is done to get remote
credentials).

Jeremy.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.