Re: [RFC PATCH] CIFS posix acl permission checking

Jeremy Allison <[email protected]>
Newsgroups gmane.linux.file-systems.cifs
Message-ID <20100312163225.GB6620@jeremy-laptop>
On Fri, Mar 12, 2010 at 01:23:01PM +0100, Volker Lendecke wrote:
> On Fri, Mar 12, 2010 at 07:18:32AM -0500, Jeff Layton wrote:
> > > But what's the alternative? Let NFS go and do that piece
> > > better forever? :-)
> > > 
> > > Volker
> > 
> > Establish sessions as needed, based on a user's own credentials and
> > have the kernel use that session/tcon combinaton instead of those
> > established at mount time. My goal is to have a prototype of this to
> > present at SambaXP, but I may have an initial set of patches in the
> > next few weeks.
> 
> Ok, then we rule out batch machines where there are no user
> credentials. NFS does this fine. I know this is REALLY ugly,
> but I have customers who need this. If you have a good
> solution for that problem, I would really be happy to hear
> this. Something like constrained delegation in Kerberos to
> me sounds pretty much like the exact same hack in a
> different place.

If you want to code this up in the server, I have
no objections. Sort of a passwordless "sessionsetup"
that returns a new vuid.

I think it should be a Samba-only extension though.
Too ugly to propose to the wider unix-extension
community :-).

Jeremy.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.