[nfsv4] yet more on delayed writes

rick@snowhite.cis.uoguelph.ca Thu, 02 October 2003 18:16 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA17999 for <nfsv4-archive@odin.ietf.org>; Thu, 2 Oct 2003 14:16:24 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1A57zf-00016M-RV for nfsv4-archive@odin.ietf.org; Thu, 02 Oct 2003 14:16:03 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id h92IG3Wb004228 for nfsv4-archive@odin.ietf.org; Thu, 2 Oct 2003 14:16:03 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1A57zf-000167-M6 for nfsv4-web-archive@optimus.ietf.org; Thu, 02 Oct 2003 14:16:03 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA17975 for <nfsv4-web-archive@ietf.org>; Thu, 2 Oct 2003 14:15:54 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 1A57zc-0004ik-00 for nfsv4-web-archive@ietf.org; Thu, 02 Oct 2003 14:16:00 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 1A57zc-0004ih-00 for nfsv4-web-archive@ietf.org; Thu, 02 Oct 2003 14:16:00 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1A57zd-00015W-Dd; Thu, 02 Oct 2003 14:16:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1A57ys-00014n-SW for nfsv4@optimus.ietf.org; Thu, 02 Oct 2003 14:15:14 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA17943 for <nfsv4@ietf.org>; Thu, 2 Oct 2003 14:15:05 -0400 (EDT)
From: rick@snowhite.cis.uoguelph.ca
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 1A57yq-0004iS-00 for nfsv4@ietf.org; Thu, 02 Oct 2003 14:15:12 -0400
Received: from snowhite.cis.uoguelph.ca ([131.104.48.1]) by ietf-mx with esmtp (Exim 4.12) id 1A57yp-0004iP-00 for nfsv4@ietf.org; Thu, 02 Oct 2003 14:15:11 -0400
Received: (from rick@localhost) by snowhite.cis.uoguelph.ca (8.9.3/8.9.3) id OAA10686 for nfsv4@ietf.org; Thu, 2 Oct 2003 14:11:11 -0400 (EDT)
Message-Id: <200310021811.OAA10686@snowhite.cis.uoguelph.ca>
To: nfsv4@ietf.org
Subject: [nfsv4] yet more on delayed writes
Sender: nfsv4-admin@ietf.org
Errors-To: nfsv4-admin@ietf.org
X-BeenThere: nfsv4@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=unsubscribe>
List-Id: NFSv4 Working Group <nfsv4.ietf.org>
List-Post: <mailto:nfsv4@ietf.org>
List-Help: <mailto:nfsv4-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/mail-archive/working-groups/nfsv4/>
X-Original-Date: Thu, 2 Oct 2003 14:11:11 -0400 (EDT)
Date: Thu, 02 Oct 2003 14:11:11 -0400

[William A.(Andy) Adamson wrote]
> wait a minute: for #3 to happen, the file permissions have to allow the user 
> nfs/host1@KERBEROS.REALM to write. are you proposing that machine creds have 
> acl's in exported filesystems?

I'm wasn't proposing machine creds in acl's (although that's an interesting
idea). I took a quick look at the section on the WriteOp (14.2.36)
and didn't spot any statement that the server was required to check for
file permissions when a WriteOp is performed. (Most will, because they
don't trust the cred. enough to accept the related Open or Write Delegation
as sufficient. Local POSIX file access doesn't check file protection
on every write, so it seems to me a V4 server doesn't have to, if it can
trust the cred enough to believe the Write is associated with the
Open or Write Delegation related to it by the stateid.)

However, it sounds like the consensus is that that is too much trust,
at least for most cases.

Anyhow, just a thought, rick

_______________________________________________
nfsv4 mailing list
nfsv4@ietf.org
https://www1.ietf.org/mailman/listinfo/nfsv4