[opensuse] opensuse 11.4 a User in group video has unexpected access to NFS share
Hi I have just had a rather confusing experience. I have an NFS mount with permissions as follows. /mount/point server1:/var/log # ls -l /mount/ total 64 drwxrwx--- 2 user1 group1 32768 May 18 12:54 point server1:/var/log # And I noticed that a username "user2" who is not in group1 could enter and write to the area. Lots of experimenting eventually gave the following user2 could only have this unexpected access to the share if it was in the group "video" (group 33) - when the user was removed from this group access to the share was denied as expected. I ran in updates and rebooted (the last update prior to this one was 22/04/2012) and the behaviour disappeared. There were no kernel updates and the current kernel version is 2.6.37.6-0.11.1 x86_64. Has anyone seen anything like this? As far as I know the video group just gives access to various device drivers. Thanks Bob -- Bob Cregan Senior Storage Systems Administrator ACRC Bristol University -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 2012-05-18 15:10, Bob Cregan wrote:
user2 could only have this unexpected access to the share if it was in the group "video" (group 33) - when the user was removed from this group access to the share was denied as expected.
Curious. - -- Cheers / Saludos, Carlos E. R. (from 11.4 x86_64 "Celadon" at Telcontar) -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.16 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk+2St4ACgkQIvFNjefEBxolNgCfeR8GfTlciWIHAZqtNWgAVkPX hBgAoLAALobI75vyHrE/lu2vmorpBLH2 =1MOV -----END PGP SIGNATURE----- -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org
Bob Cregan wrote:
Hi I have just had a rather confusing experience. I have an NFS mount with permissions as follows.
/mount/point
server1:/var/log # ls -l /mount/ total 64 drwxrwx--- 2 user1 group1 32768 May 18 12:54 point server1:/var/log #
I'm a bit confused too. Which machine are we talking about here? Are these users on the NFS server or NFS client? Which machine is the ls done on? If the client is involved, what are the mount options? What version of NFS? What version of opensuse? -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org
participants (3)
-
Bob Cregan
-
Carlos E. R.
-
Dave Howorth