RE: [nfsv4] Re: [NFS] NFSv4 ACL and POSIX interaction / mask, draft-ietf-nfsv4-acls-00 not ready

"Yoder, Alan" <agy@netapp.com> Fri, 14 July 2006 19:23 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1G1TGU-0003no-6S; Fri, 14 Jul 2006 15:23:54 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1G1TGS-0003nj-E4 for nfsv4@ietf.org; Fri, 14 Jul 2006 15:23:52 -0400
Received: from mx2.netapp.com ([216.240.18.37]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1G1TGR-0006SR-5y for nfsv4@ietf.org; Fri, 14 Jul 2006 15:23:52 -0400
Received: from smtp2.corp.netapp.com ([10.57.159.114]) by mx2.netapp.com with ESMTP; 14 Jul 2006 12:23:50 -0700
X-IronPort-AV: i="4.06,244,1149490800"; d="scan'208"; a="393034026:sNHT32490616"
Received: from svlexc02.hq.netapp.com (svlexc02.corp.netapp.com [10.57.157.136]) by smtp2.corp.netapp.com (8.13.1/8.13.1/NTAP-1.6) with ESMTP id k6EJNocw003925; Fri, 14 Jul 2006 12:23:50 -0700 (PDT)
Received: from exsvlrb02.hq.netapp.com ([10.56.8.63]) by svlexc02.hq.netapp.com with Microsoft SMTPSVC(5.0.2195.6713); Fri, 14 Jul 2006 12:23:50 -0700
Received: from exsvl02.hq.netapp.com ([10.56.8.60]) by exsvlrb02.hq.netapp.com with Microsoft SMTPSVC(6.0.3790.1830); Fri, 14 Jul 2006 12:23:49 -0700
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Subject: RE: [nfsv4] Re: [NFS] NFSv4 ACL and POSIX interaction / mask, draft-ietf-nfsv4-acls-00 not ready
Date: Fri, 14 Jul 2006 12:26:29 -0700
Message-ID: <992BA60650F1584BA63E339312CE420305958904@exsvl02.hq.netapp.com>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: [nfsv4] Re: [NFS] NFSv4 ACL and POSIX interaction / mask, draft-ietf-nfsv4-acls-00 not ready
Thread-Index: AcandYnv1kBCCab5STS4tqZDjuhkVgABLVBA
From: "Yoder, Alan" <agy@netapp.com>
To: "J. Bruce Fields" <bfields@fieldses.org>, wurzl_mario@emc.com
X-OriginalArrivalTime: 14 Jul 2006 19:23:49.0702 (UTC) FILETIME=[08CBAE60:01C6A77B]
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 21c69d3cfc2dd19218717dbe1d974352
Cc: Sam.Falkner@sun.com, nfsv4@ietf.org
X-BeenThere: nfsv4@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: NFSv4 Working Group <nfsv4.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/nfsv4>
List-Post: <mailto:nfsv4@ietf.org>
List-Help: <mailto:nfsv4-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=subscribe>
Errors-To: nfsv4-bounces@ietf.org

 > > >> For a client that doesn't support the new attributes, a 
> > >> server can apply
> > >> the mask attributes to the ACL before returning it.  I suppose a
> > >> multi-protocol server would do the same for CIFS clients.
> > >> 
> > Since CIFS does not understand the semantics of permission 
> mask, does
> > the server enforce the mask when the access for the data comes from
> > a CIFS client ?
> 
> Yes, it does.  But it also only ever shows CIFS clients a 
> version of the
> ACL with the mask already applied, so CIFS clients see no 
> inconcistency.
> (In other words, if there's an "ALLOW bfields READ+WRITE" ACE, but the
> relevant mask only allows READ, then the CIFS client will see 
> a version
> of the ACL where that ACE only allows READ.)
> 
> See any reason why that won't work?

Let me see if I understand.

A POSIX ACL client sees ALLOW bfields READ+WRITE
A *nix client that only does perms sees r
A client that only does CIFS sees ALLOW bfields READ

If I have that right, this is like going straight to hell 
for a multi-protocol server company.  Does that qualify
as a reason for why this won't work?

Alan

===============================================================
Alan G. Yoder                                    agy@netapp.com
Technical Staff                           
Network Appliance, Inc.                            408-822-6919
===============================================================



_______________________________________________
nfsv4 mailing list
nfsv4@ietf.org
https://www1.ietf.org/mailman/listinfo/nfsv4