Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1355930 > unrolled thread

Re: [PATCH v18 00/22] Richacls (Core and Ext4)

Started by"J. Bruce Fields" <bfields@fieldses.org>
First post2016-03-11 15:10 +0100
Last post2016-03-15 08:20 +0100
Articles 3 — 3 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [PATCH v18 00/22] Richacls (Core and Ext4) "J. Bruce Fields" <bfields@fieldses.org> - 2016-03-11 15:10 +0100
    Re: [PATCH v18 00/22] Richacls (Core and Ext4) Simo <simo@samba.org> - 2016-03-12 22:20 +0100
    Re: [PATCH v18 00/22] Richacls (Core and Ext4) Christoph Hellwig <hch@infradead.org> - 2016-03-15 08:20 +0100

#1355930 — Re: [PATCH v18 00/22] Richacls (Core and Ext4)

From"J. Bruce Fields" <bfields@fieldses.org>
Date2016-03-11 15:10 +0100
SubjectRe: [PATCH v18 00/22] Richacls (Core and Ext4)
Message-ID<rbvVn-7ms-7@gated-at.bofh.it>
On Fri, Mar 11, 2016 at 06:01:34AM -0800, Christoph Hellwig wrote:
> On Mon, Feb 29, 2016 at 09:17:05AM +0100, Andreas Gruenbacher wrote:
> > Al,
> > 
> > could you please make sure you are happy with the current version of the
> > richacl patch queue for the next merge window?
> 
> I'm still not happy.
> 
> For one I still see no reason to merge this broken ACL model at all.
> It provides our actualy Linux users no benefit at all, while breaking
> a lot of assumptions, especially by adding allow and deny ACE at the
> same sime.

Could you explain what you mean by "adding allow and deny ACE at the
same time"?

> It also doesn't help with the issue that the main thing it's trying
> to be compatible with (Windows) actually uses a fundamentally different
> identifier to apply the ACLs to - as long as you're still limited
> to users and groups and not guids we'll still have that mapping problem
> anyway.

Agreed, but, one step at a time?  My impression is that the Samba people
still consider this a step forward for Linux compatibility.

--b.

> 
> But besides that fundamental question on the purpose of it I also
> don't think the code is suitable, more in the individual patches.

[toc] | [next] | [standalone]


#1356538

FromSimo <simo@samba.org>
Date2016-03-12 22:20 +0100
Message-ID<rbZ73-3NR-1@gated-at.bofh.it>
In reply to#1355930
On Fri, 2016-03-11 at 09:07 -0500, J. Bruce Fields wrote:
> On Fri, Mar 11, 2016 at 06:01:34AM -0800, Christoph Hellwig wrote:
> > 
> > On Mon, Feb 29, 2016 at 09:17:05AM +0100, Andreas Gruenbacher
> > wrote:
> > > 
> > > Al,
> > > 
> > > could you please make sure you are happy with the current version
> > > of the
> > > richacl patch queue for the next merge window?
> > I'm still not happy.
> > 
> > For one I still see no reason to merge this broken ACL model at
> > all.
> > It provides our actualy Linux users no benefit at all, while
> > breaking
> > a lot of assumptions, especially by adding allow and deny ACE at
> > the
> > same sime.
> Could you explain what you mean by "adding allow and deny ACE at the
> same time"?
> 
> > 
> > It also doesn't help with the issue that the main thing it's trying
> > to be compatible with (Windows) actually uses a fundamentally
> > different
> > identifier to apply the ACLs to - as long as you're still limited
> > to users and groups and not guids we'll still have that mapping
> > problem
> > anyway.
> Agreed, but, one step at a time?  My impression is that the Samba
> people
> still consider this a step forward for Linux compatibility.

It is a step forward, but being able to store SIDs in the ACL, would be
a much better one.

Simo.

> --b.
> 
> > 
> > 
> > But besides that fundamental question on the purpose of it I also
> > don't think the code is suitable, more in the individual patches.
> --
> To unsubscribe from this list: send the line "unsubscribe linux-cifs" 
> in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html

[toc] | [prev] | [next] | [standalone]


#1357848

FromChristoph Hellwig <hch@infradead.org>
Date2016-03-15 08:20 +0100
Message-ID<rcRqO-7hA-21@gated-at.bofh.it>
In reply to#1355930
On Fri, Mar 11, 2016 at 09:07:57AM -0500, J. Bruce Fields wrote:
> Could you explain what you mean by "adding allow and deny ACE at the
> same time"?

NFSv4/rich ACLs have both ALLOW and DENY ACE, which is contrary to
the model how we've operated since the dawn of time.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web