Bug 765433 (GLUSTER-3701) - flip user to trusted namespace in xattr key for certain client mounts
Summary: flip user to trusted namespace in xattr key for certain client mounts
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: GLUSTER-3701
Product: GlusterFS
Classification: Community
Component: fuse
Version: mainline
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Venky Shankar
QA Contact:
URL:
Whiteboard:
: 785101 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-10-05 11:25 UTC by Venky Shankar
Modified: 2013-03-04 04:36 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed:
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:


Attachments (Terms of Use)

Description Venky Shankar 2011-10-05 11:25:13 UTC
as gsyncd and hadoop plugin plan to run as non-super user, we need a way to fetch extended attributes under trusted namespace.

Since trusted n/s need CAP_SYS_ADMIN privileges, plan is to request the key under user n/s (so as to bypass VFS blocking) and flip it (under certain conditions) to trusted when it reaches fuse xlator.

Comment 1 Anand Avati 2011-10-28 12:08:43 UTC
CHANGE: http://review.gluster.com/563 (This is needed for gsyncd/hadoop-plugin running as non-super) merged in master by Vijay Bellur (vijay)

Comment 2 Anand Avati 2012-03-05 15:53:00 UTC
CHANGE: http://review.gluster.com/2838 (geo-rep / syncdaemon: determine suitable xattr namespace based on privilege) merged in master by Vijay Bellur (vijay)

Comment 3 Venky Shankar 2012-03-26 10:06:22 UTC
*** Bug 785101 has been marked as a duplicate of this bug. ***

Comment 4 Anand Avati 2012-04-23 21:51:07 UTC
CHANGE: http://review.gluster.com/3170 (clean up handling of special client pids) merged in master by Anand Avati (avati)

Comment 5 Vijay Bellur 2013-03-04 04:36:03 UTC
CHANGE: http://review.gluster.org/4601 (cluster xlators: s/-1/GF_CLIENT_PID_GSYNCD/) merged in master by Anand Avati (avati)


Note You need to log in before you can comment on or make changes to this bug.