Re: [Proftpd-user] error: unable to set groups: Invalid argument
Palvelin Postmaster via Proftp-user <[email protected]>
| Newsgroups | gmane.network.proftpd.user |
|---|---|
| Message-ID | <[email protected]> |
> On 12 Nov 2018, at 16:58, Palvelin Postmaster via Proftp-user <[email protected]> wrote: > > I’m struggling to understand why I’m getting the FAQ’d error on macOS High Sierra > > http://www.proftpd.org/docs/faq/linked/faq-ch4.html#AEN439 > > I have used ’id -G <user>’ to investigate affected users. None of them belong to supplemental groups with an ID < 0. They belong to 9-16 supplemental groups. ’sysctl kern.ngroups’ returns 16. > > It may be significant that the affected users don’t have home directories (in macOS the local network directory NFSHomeDirectory property value is set to ’99’ or ’/dev/null’). I also have ftp-specific users which have a home directory to which they are chrooted to. They don’t seem to cause the error message. However, they also belong to less user groups (typically 2-4), so it’s hard to say. I subsequently discovered that while the above is true for my Open Directory master, my proftpd runs on another host which is also a SMB/AFP file server. Apparently macOS file sharing creates local user groups named ’com.apple.sharepoint.group.X' for each share and attaches privileged directory users to them. This creates a situation where the 16 groups limit is easily surpassed especially in a scenario where one utilizes nested groups. It looks like the kern.ngroups limitation can’t be raised. Is there any workaround to this? -- Palvelin.fi Hostmaster [email protected] _______________________________________________ ProFTPD Users List <[email protected]> Unsubscribe problems? http://www.proftpd.org/list-unsub.html