[Lustre-discuss] ACL question

Robert LeBlanc robert at leblancnet.us
Tue Oct 27 07:24:42 PDT 2009


On Mon, Oct 26, 2009 at 6:44 PM, Daniel Kobras <kobras at linux.de> wrote:

> Hi!
>
> On Mon, Oct 26, 2009 at 05:35:36PM -0600, Robert LeBlanc wrote:
> > Well, my little trick isn't working right now. I'm not sure how to debug
> > this.
>
> With Lustre, the MDS authorizes access when a client first touches a
> certain
> file. Once it's cached, the client handles authorization itself. If you
> experience erratic behaviour, this point to a difference in either
> nameservice
> or ACL configuration between MDS and client. Are ACLs turned on on the MDT?
> Does user2 show up as a member of group1 on the MDS? Is the Lustre group
> upcall
> configured?
>
>
ACL is configured on the MDS, I tried on a Lustre FS where it wasn't turned
on and got an operation not supported error. We are using Samba for our
nameservice and we switched from RID to Hash for UID and GID. I noticed a
couple of things that may be part of the problem. The MDS was not switched
over to the Hash method and the mdt.group_upcall was set to none. I'll
change both of thoes and see if things improve. Makes me wonder why it
worked at all (and the directories that it did work with still do) in the
first place.

My testing was done all on the same client, not on different clients. I'll
report back my findings.

Robert LeBlanc
Life Sciences & Undergraduate Education Computer Support
Brigham Young University
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.lustre.org/pipermail/lustre-discuss-lustre.org/attachments/20091027/b9c858bc/attachment.htm>


More information about the lustre-discuss mailing list