>samba : NTFS full control cab be applied on file why not on directories?

By | August 20, 2009

>With Samba 3.3.x, we moved to using the returned Windows permissions (as mapped from POSIX ACLs) to control all file access. This gets us closer to Windows behavior,but there’s one catch. “Full Control” includes the ability to delete a file, but in POSIX the ability to delete a file belongs to the containing directory, not the file itself.

So when we return the Windows permissions for a file ACL with “rwx” set, by default we’d like to map to “Full Control” (see the default setting of the parameter acl map full control) but we must remove the DELETE_ACCESS flag from the mapping, as that is not a permission that is granted. Thus the ACL editor doesn’t see “DELETE_ACCESS”in the returned ACE entry, and so doesn’t believe it’s “Full Control”.

If we don’t remove the DELETE_ACCESS bit, the client will open a file for delete, and successfully get a file handle back, but the delete will fail when the set file info (delete this file) call is made. Windows clients only check the error return on the open for
delete call, not the actual set file info that allows the delete – if you fail that call Windows explorer silently ignores the error, tells you you have deleted the file, but the file is still there and will reappear on the next directory refresh, thus confusing users.

Share itShare on FacebookEmail this to someoneTweet about this on TwitterShare on Google+Share on LinkedInPrint this page

One thought on “>samba : NTFS full control cab be applied on file why not on directories?

  1. Stead

    >Hi Vishesh,

    We've also been struggling with this. How did you go about removing the delete access bit? I believe our situation is fairly similar. We have a samba server, and grant permissions using setfacl to the appropriate group. Group members with rwx are complaining that deleted files disappear but then come back after the next refresh.

    Thanks for any pointers you can give! I'm just getting my feet wet in the world of samba. We're on version 3.6.5.

    Thanks!

    -Stead Halstead
    stead.halstead@gmail.com

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

Current month ye@r day *