Bug 10647 - inherit acls = yes can ignore the set group id bit
inherit acls = yes can ignore the set group id bit
Status: NEW
Product: Samba 4.1 and newer
Classification: Unclassified
Component: File services
4.1.7
All All
: P5 normal
: ---
Assigned To: Samba QA Contact
Samba QA Contact
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-06-02 18:00 UTC by Tom Schulz
Modified: 2016-08-25 16:12 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tom Schulz 2014-06-02 18:00:16 UTC
This problem shows up on both Linux and Solaris.
We have a setup where we want a group of users to be able to work in a common share. To do that I set up a group and made the users members of that group. I made the parent directory have that group as it's group and added an ACL to make sure that everyone in the group could create files there and modify any files there. I set the set group id bit so that any new files would get this group as it's group. I set the share to have inherit acls = yes so that the acl would be inherited and used. But with inherit acls = yes, the set group id bit is not honored.

For instance, for a directory with an ACL of:
# file: ../acltest
# owner: hwdesign
# group: hwdesign
user::rwx
group::rwx
mask::rwx
other::r-x
default:user::rwx
default:group::rwx
default:mask::rwx
default:other::r-x

And permissions set as:
drwxrwsr-x+ 6 hwdesign hwdesign 4096 2014-06-02 10:36 ../acltest/

A new folder (directory) is created with the following ACL
# file: test
# owner: schulz
# group: users
user::rwx
user:schulz:rwx
group::rwx
group:users:rwx
mask::rwx
other::r-x
default:user::rwx
default:user:schulz:rwx
default:group::rwx
default:group:users:rwx
default:mask::rwx
default:other::r-x

And the following permissions:
drwxrwsr-x+ 2 schulz users 4096 2014-06-02 10:35 test

Note that the expected and desired group should be hwdesign.
Also, if the directory is accessed as a NFS mount by the Samba server then the set group id bit is lost (not shown above).
Comment 1 Jochem 2014-08-15 22:59:14 UTC
We have the same problem here on Samba 4.1.11.
Comment 2 Tom Schulz 2015-06-11 15:37:24 UTC
Ping.
Comment 3 Tom Schulz 2015-08-07 17:10:26 UTC
Problem also on Samba 4.2.3.
Comment 4 Tom Schulz 2016-02-24 18:57:09 UTC
The problem still exists on Samba 4.4.0rc3.