NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

chopin70's avatar
chopin70
Virtuoso
Jun 29, 2016

User and group broken permissions

Hi,

I am using latest OS 6.5.1

 

I setup a share called "torrents"

I have two groups: users and famille

famille group has one user: enfants

In SMB Network access: users: r/w - famille: no access - enfants: no access

In file access: same setup

 

However, the user "enfants" still has r/w access on the torrents share

 

Even if I set them to read only, still they have r/w access

This use to work before on early 6.4.x versions, last time I checked

 

I tried to reset permissions, but no fix

As soon as the group users has ro permission, "enfants" gets r/o access, despite it is not a membrer of that group

63 Replies

Replies have been turned off for this discussion
  • Ok. So a user without specific permission should inherit permission from group. And a user with a specific permission should overrule inherited permission from group. This is what I expected when I did the testing.
    So I don't understand which of my "effective vs expected permissions" you disagree with...
    • chopin70's avatar
      chopin70
      Virtuoso

      Where I disagree is what I wrote in the first line of my answer above

      And yes, if nothing is checked, as it is by default, it should mean no access at all. So we cannot for now, make it inherit by default from group.

       

  • The first line of your previous reply says: "read/only user member of a read/write group gets read/write access: should never occur as user privileges should be considered before group. This is something like escalating permissions"
    Which is exactly what I have in "expected permission", so I still don't understand which one of my expected permission you disahree with...
    • chopin70's avatar
      chopin70
      Virtuoso

      Can we have an official statement if these broken permissions will be fixed ?

      • StephenB's avatar
        StephenB
        Guru - Experienced User

        chopin70 wrote:

        Can we have an official statement if these broken permissions will be fixed ?


        Seems rather unlikely, since no one from Netgear has even posted to this thread.  

  • Can you bullet point which ones of my expectations you disagree with?
    I'm interested to know this.

    You should contact NETGEAR support.
    • chopin70's avatar
      chopin70
      Virtuoso

      then should we assume every one is happy with broken permissions, or maybe no one really using 6.5.x ?

       

      How should I contact support so that they look at the issue ?

  • For me, as long as you haven't clarified exactly which expected vs effective permission listed before you disagree with, I can't move forward. (If you do so, please the exact lines)

    To contact NETGEAR Support, use your my.netgear.com account, under My Support or something like that. If you mention that you believe this is a security issue, I doubt they'll talk about support entitlement...
    • StephenB's avatar
      StephenB
      Guru - Experienced User

      FWIW, I did forward a link to this thread to a Netgear developer for comment.  I'll send a reminder if I don't hear back.

       

      It would be a useful thing if someone tried various settings, and posted the ACL and permissions that result in the file system.  That can be done by any commmunity member who has SSH access enabled on their OS6 NAS.

       

      That might also help focus this discussion into what specifically might need to be changed.

      • chopin70's avatar
        chopin70
        Virtuoso
        StephenB wrote:

        FWIW, I did forward a link to this thread to a Netgear developer for comment.  I'll send a reminder if I don't hear back.

         

        It would be a useful thing if someone tried various settings, and posted the ACL and permissions that result in the file system.  That can be done by any commmunity member who has SSH access enabled on their OS6 NAS.

         

        That might also help focus this discussion into what specifically might need to be changed.


         

        Thank you StephenB

        Can you detail the needed commands that I should run in SSH for a debugging ?

        I already posted the output of specific "id -a" commands in SSH

         

        Since we are at leat 3 people in the forum to reproduce the issue, it could be a generalized issue. Again, it clearly appeared somewhere between 6.4 and 6.5.1, maybe the 6.5.x as I recall 6.4.x builds were fine when I first migrated to OS 6 and setup my groups and permissions

  • I have seen similar behavior where group permissions do NOT work the way they are supposed to...I only use AFP if that helps.

  • Why doesn't Netgear provide a 6.5.1 ReadyNas 516 VMWare image.  It would be easy enough to configure these and "document" that failure and even give them back the VMWare images to see for themselves. Doing this "testing" on my actual 516 isn't convienent and is somewhat dangerous.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More