Re: [nfsv4] Proposal for ACL changes

New Message Reply About this list Date view Thread view Subject view Author view Attachment view

From: Andreas Gruenbacher (agruen@suse.de)
Date: 06/05/03-02:47:07 AM Z


From: Andreas Gruenbacher <agruen@suse.de>
Subject: Re: [nfsv4] Proposal for ACL changes
Message-Id: <200306050947.07144.agruen@suse.de>
Date: Thu, 5 Jun 2003 09:47:07 +0200

On Thursday 05 June 2003 04:00, Sergey Klyushin wrote:
> I would like to propose the following changes for ACL in NFSv4 (at least
> for next minor version).
>
> 1. In paragraph 5.11.4.  ACE who
> Remove "OWNER@" and "GROUP@" from the list of special names.
>
> 2. In paragraph 5.11.6.  Mode and ACL Attribute
> Remove requirements for synchronization of access granted by ACL and mode.
>
> 3. In paragraph 5.11.6.  Mode and ACL Attribute
> Add the following rule for checking access:
> - Process ACL first.
> - If access is not denied or not fully granted, check mode
> - If access is not fully granted, then access is denied.
>
> I believe this proposal will match better into both POSIX and Windows ACL
> models.

Why do you believe that? From the point of view of POSIX (-like) ACLs this 
would indeed worsen the situation with NFSv4.


Regards,
Andreas Gruenbacher.

------------------------------------------------------------------
 Andreas Gruenbacher                                SuSE Linux AG
 mailto:agruen@suse.de                     Deutschherrnstr. 15-19
 http://www.suse.de/                   D-90429 Nuernberg, Germany

_______________________________________________
nfsv4 mailing list
nfsv4@ietf.org
https://www1.ietf.org/mailman/listinfo/nfsv4


New Message Reply About this list Date view Thread view Subject view Author view Attachment view

This archive was generated by hypermail 2.1.2 : 03/04/05-02:12:30 AM Z CST