From sacadmin Fri Mar 20 15:40:12 2009
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2KMeC0h009656;
	Fri, 20 Mar 2009 15:40:12 -0700 (PDT)
Received: (from jb25718@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n2KMeCbE009652;
	Fri, 20 Mar 2009 15:40:12 -0700 (PDT)
Date: Fri, 20 Mar 2009 15:40:12 -0700 (PDT)
From: Jordan Brown <jb25718@sac.sfbay.sun.com>
Message-Id: <200903202240.n2KMeCbE009652@sac.sfbay.sun.com>
To: PSARC-record@sac.sfbay.sun.com
Cc: cifs-eng@sun.com
Subject: SMB/CIFS Share Exec Properties [PSARC/2009/184 FastTrack timeout 03/27/2009]
Status: RO
Content-Length: 562


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 SMB/CIFS Share Exec Properties
    1.2. Name of Document Author/Supplier:
	 Author:  Hoa Nguyen
    1.3  Date of This Document:
	20 March, 2009
4. Technical Description
    See the case directory for more detail

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Jordan.Brown@sun.com Fri Mar 20 15:43:43 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2KMhhRp009930
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 20 Mar 2009 15:43:43 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2KMhgV4034397
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Fri, 20 Mar 2009 16:43:42 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGT0020PTSUP400@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Fri, 20 Mar 2009 16:43:42 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGT00063TSTYS10@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Fri,
 20 Mar 2009 16:43:42 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2KMhf9p024999	for
 <psarc-ext@sun.com>; Fri, 20 Mar 2009 15:43:41 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KGT00900TK26G00@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Fri, 20 Mar 2009 15:43:41 -0700 (PDT)
Received: from [129.145.155.183] ([unknown] [129.145.155.183])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KGT000NHTSP8PA0@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Fri, 20 Mar 2009 15:43:37 -0700 (PDT)
Date: Fri, 20 Mar 2009 15:43:37 -0700
From: Jordan Brown <Jordan.Brown@sun.com>
Subject: 2009/184 SMB/CIFS Share Exec Properties
Sender: Jordan.Brown@sun.com
To: psarc-ext@sun.com
Message-id: <49C41C19.40308@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)
Status: RO
Content-Length: 4105

I am sponsoring the following for fast track approval.
The timer expires 27 March 2009.

1. Introduction
      1.1. Project/Component Working Name:
           SMB/CIFS share exec properties
      1.2. Name of Document Author/Supplier:
           Author:  Hoa Nguyen
      1.3  Date of This Document:
           20 March, 2009

      A patch binding is requested for this change.
      This is a Committed interface.

4. Technical Description

	This fast-track proposes new service properties to support the
	execution of a command or script when connecting or disconnecting
	CIFS shares.  These properties are configurable with sharectl(1M)
	and will be applied to all shares.  The command may be used to
	perform automated administrative tasks each time a share is mapped
	or disconnected, for example, to create home directories or monitor
	resources.  The command will be executed using the credentials of
	the smbd daemon, which, by default, is root/sys.  The command
	will be executed using one of the exec() functions.  The content
	of the environment is not specified.

	See also 6766364 Add scripting support to Autohome.

	In order to configure properties using sharectl(1M), a user must
	be the superuser or assume an equivalent role to obtain the
	solaris.smf.value.smb and solaris.smf.manage.smb RBAC
	authorizations, or use the SMB Management RBAC profile, which
	is part of the File System Management profile.

	Additional privileges are required to allow the smbd process to
	fork a child process and execute the commands.  The privileges
	will be enabled in the effective set and inheritable set when
	needed for command execution.  Otherwise, they will be disabled.

	The following privileges are enabled for the exec'd process:
	PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
	PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
	PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
	PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
	PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
	PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.

	The service property names and values are as follows:

	map		The value is a command to be executed when connecting
			to the share.  The command can take the following
			arguments, which will be substituted when the command
			is exec'd as described below.

			%U - Windows username.

			%D - Name of the domain or workgroup of %U.

			%h - The server hostname.

			%M - The client hostname, or "" if not available.

			%L - The server NetBIOS name.

			%m - The client NetBIOS name, or "" if not available.
			This option is only valid for NetBIOS connections
			(port 139).

			%I - The IP address of the client machine.

			%i - The local IP address to which the client is
			connected.

			%S - The name of the share.

			%P - The root directory of the share.

			%u - The UID of the Unix user.

	unmap		The value is a command to be executed when
			disconnecting the share.  The command can take the
			same substitutions listed on the map property.

	disposition	A value that controls whether to disconnect the share
			or proceed if the map command fails.  The disposition
			property only has meaning when the map property has
			been set.  Otherwise it will have no effect.

			disposition = [ continue | terminate ]

			continue	Proceed with share connection if the
					map command fails.  This is the default
					in the event that disposition is not
					specified.

			terminate	Disconnect the share if the map
					command fails.

	Examples of setting these properties with sharectl(1M):

		sharectl  set -p map="/tmp/map_script %U" smb
		sharectl  set -p unmap=/tmp/unmap_script smb
		sharectl  set -p disposition=terminate smb

	For example,

		sharectl  set -p map="/tmp/map_script %U" smb

	would be invoked with arguments of the form:

		arg0 = /tmp/map_script
		arg1 = <Windows username>
		arg2 = NULL

6. Resources and Schedule
      6.4. Steering Committee requested information
     	6.4.1. Consolidation C-team Name:
		ON
      6.5. ARC review type: FastTrack
      6.6. ARC Exposure: open

From Darren.Moffat@sun.com Mon Mar 23 02:38:25 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2N9cPQ9006410
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 02:38:25 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2N9cOXL022647
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 23 Mar 2009 02:38:25 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGY0050DDG06G00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 02:38:24 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGY00LETDFZ2090@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 02:38:23 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2N9cM7S019974	for
 <psarc-ext@sun.com>; Mon, 23 Mar 2009 09:38:22 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KGY00B00D2GHZ00@fe-emea-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 09:38:22 +0000 (GMT)
Received: from [129.156.173.21] ([unknown] [129.156.173.21])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KGY00EBSDFRIXC0@fe-emea-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 09:38:16 +0000 (GMT)
Date: Mon, 23 Mar 2009 09:38:15 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C41C19.40308@sun.com>
Sender: Darren.Moffat@sun.com
To: Jordan Brown <Jordan.Brown@sun.com>
Cc: psarc-ext@sun.com
Message-id: <49C75887.6030303@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 1749

Jordan Brown wrote:
>     In order to configure properties using sharectl(1M), a user must
>     be the superuser or assume an equivalent role to obtain the
>     solaris.smf.value.smb and solaris.smf.manage.smb RBAC
>     authorizations, or use the SMB Management RBAC profile, which
>     is part of the File System Management profile.

This case makes that authorisation equivalent to handing out the list of 
privileges below.  I'm not sure that is a safe thing to do.

I need some more time to thing about this and see if there is a safer 
way to achieve this.  I have some ideas (that won't be difficult to 
implement) I just need to think through them a bit more first.

>     Additional privileges are required to allow the smbd process to
>     fork a child process and execute the commands.  The privileges
>     will be enabled in the effective set and inheritable set when
>     needed for command execution.  Otherwise, they will be disabled.
> 
>     The following privileges are enabled for the exec'd process:
>     PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
>     PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
>     PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
>     PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
>     PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
>     PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.

Where did this list of privileges come from (other than those in the 
basic set)?  Why this list and in particular why the very powerful 
sys_config ?

Is it just because that is what smbd is running with ?  I want the case 
to give the reason why this set of privileges rather than some other set 
is the correct and useful set.

-- 
Darren J Moffat

From edward.pilatowicz@Sun.COM Mon Mar 23 10:47:24 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NHlNjn026073
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 10:47:24 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n2NHl0YW005456;
	Tue, 24 Mar 2009 01:47:19 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ00H0302TPM00@brm-avmta-1.central.sun.com>; Mon,
 23 Mar 2009 11:47:17 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00DQ402R9SA0@brm-avmta-1.central.sun.com>; Mon,
 23 Mar 2009 11:47:15 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com (localhost [127.0.0.1])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n2NHlF1h344507
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon,
 23 Mar 2009 10:47:15 -0700 (PDT)
Received: (from edp@localhost)	by jurassic-x4600.sfbay.sun.com
 (8.14.3+Sun/8.14.3/Submit) id n2NHlEFH344506; Mon,
 23 Mar 2009 10:47:14 -0700 (PDT)
Date: Mon, 23 Mar 2009 10:47:14 -0700
From: Edward Pilatowicz <edward.pilatowicz@Sun.COM>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C41C19.40308@sun.com>
To: Jordan Brown <Jordan.Brown@Sun.COM>
Cc: psarc-ext@Sun.COM
Message-id: <20090323174714.GA332868@eng.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com>
X-Authentication-warning: jurassic-x4600.sfbay.sun.com: edp set sender to
 edward.pilatowicz@sun.com using -f
User-Agent: Mutt/1.5.19 (2009-01-05)
Status: RO
Content-Length: 4785

having worked on frameworks with lots of callbacks, i just have one nit
comment.

the names of the callbacks (map, and unmap) are ambigious wrt when they
are invoked wrt their associated event.  i think it's implied that map
will be invoked after a mapping is established, and unmap will before,
but it would be nice if the name of these callbacks was changed so that
this was explicit.  say post-map and pre-unmap.

ed

On Fri, Mar 20, 2009 at 03:43:37PM -0700, Jordan Brown wrote:
> I am sponsoring the following for fast track approval.
> The timer expires 27 March 2009.
>
> 1. Introduction
>      1.1. Project/Component Working Name:
>           SMB/CIFS share exec properties
>      1.2. Name of Document Author/Supplier:
>           Author:  Hoa Nguyen
>      1.3  Date of This Document:
>           20 March, 2009
>
>      A patch binding is requested for this change.
>      This is a Committed interface.
>
> 4. Technical Description
>
> 	This fast-track proposes new service properties to support the
> 	execution of a command or script when connecting or disconnecting
> 	CIFS shares.  These properties are configurable with sharectl(1M)
> 	and will be applied to all shares.  The command may be used to
> 	perform automated administrative tasks each time a share is mapped
> 	or disconnected, for example, to create home directories or monitor
> 	resources.  The command will be executed using the credentials of
> 	the smbd daemon, which, by default, is root/sys.  The command
> 	will be executed using one of the exec() functions.  The content
> 	of the environment is not specified.
>
> 	See also 6766364 Add scripting support to Autohome.
>
> 	In order to configure properties using sharectl(1M), a user must
> 	be the superuser or assume an equivalent role to obtain the
> 	solaris.smf.value.smb and solaris.smf.manage.smb RBAC
> 	authorizations, or use the SMB Management RBAC profile, which
> 	is part of the File System Management profile.
>
> 	Additional privileges are required to allow the smbd process to
> 	fork a child process and execute the commands.  The privileges
> 	will be enabled in the effective set and inheritable set when
> 	needed for command execution.  Otherwise, they will be disabled.
>
> 	The following privileges are enabled for the exec'd process:
> 	PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
> 	PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
> 	PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
> 	PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
> 	PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
> 	PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.
>
> 	The service property names and values are as follows:
>
> 	map		The value is a command to be executed when connecting
> 			to the share.  The command can take the following
> 			arguments, which will be substituted when the command
> 			is exec'd as described below.
>
> 			%U - Windows username.
>
> 			%D - Name of the domain or workgroup of %U.
>
> 			%h - The server hostname.
>
> 			%M - The client hostname, or "" if not available.
>
> 			%L - The server NetBIOS name.
>
> 			%m - The client NetBIOS name, or "" if not available.
> 			This option is only valid for NetBIOS connections
> 			(port 139).
>
> 			%I - The IP address of the client machine.
>
> 			%i - The local IP address to which the client is
> 			connected.
>
> 			%S - The name of the share.
>
> 			%P - The root directory of the share.
>
> 			%u - The UID of the Unix user.
>
> 	unmap		The value is a command to be executed when
> 			disconnecting the share.  The command can take the
> 			same substitutions listed on the map property.
>
> 	disposition	A value that controls whether to disconnect the share
> 			or proceed if the map command fails.  The disposition
> 			property only has meaning when the map property has
> 			been set.  Otherwise it will have no effect.
>
> 			disposition = [ continue | terminate ]
>
> 			continue	Proceed with share connection if the
> 					map command fails.  This is the default
> 					in the event that disposition is not
> 					specified.
>
> 			terminate	Disconnect the share if the map
> 					command fails.
>
> 	Examples of setting these properties with sharectl(1M):
>
> 		sharectl  set -p map="/tmp/map_script %U" smb
> 		sharectl  set -p unmap=/tmp/unmap_script smb
> 		sharectl  set -p disposition=terminate smb
>
> 	For example,
>
> 		sharectl  set -p map="/tmp/map_script %U" smb
>
> 	would be invoked with arguments of the form:
>
> 		arg0 = /tmp/map_script
> 		arg1 = <Windows username>
> 		arg2 = NULL
>
> 6. Resources and Schedule
>      6.4. Steering Committee requested information
>     	6.4.1. Consolidation C-team Name:
> 		ON
>      6.5. ARC review type: FastTrack
>      6.6. ARC Exposure: open

From amw@Sun.COM Mon Mar 23 11:49:56 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NInt36001726
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 11:49:56 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n2NInm3w013909
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 24 Mar 2009 02:49:54 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ00K0B2Z54E00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 11:49:53 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00DGH2Z4KXC0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 11:49:53 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n2NInqXw004746	for
 <psarc-ext@sun.com>; Mon, 23 Mar 2009 18:49:52 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KGZ00M002ILMW00@mail-amer.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 12:49:52 -0600 (MDT)
Received: from [10.1.106.211] ([unknown] [10.1.106.211])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KGZ007UJ2YN19D0@mail-amer.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 12:49:36 -0600 (MDT)
Date: Mon, 23 Mar 2009 11:49:35 -0700
From: Alan M Wright <amw@Sun.COM>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C75887.6030303@Sun.COM>
Sender: Alan.M.Wright@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: Jordan Brown <Jordan.Brown@Sun.COM>, psarc-ext@Sun.COM
Message-id: <49C7D9BF.40202@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 2050

On 03/23/09 02:38, Darren J Moffat wrote:
> Jordan Brown wrote:
>>     In order to configure properties using sharectl(1M), a user must
>>     be the superuser or assume an equivalent role to obtain the
>>     solaris.smf.value.smb and solaris.smf.manage.smb RBAC
>>     authorizations, or use the SMB Management RBAC profile, which
>>     is part of the File System Management profile.
> 
> This case makes that authorisation equivalent to handing out the list of 
> privileges below.  I'm not sure that is a safe thing to do.

The purpose is to allow the root user to do anything that
would be possible if root was to login and run the command.

> I need some more time to thing about this and see if there is a safer 
> way to achieve this.  I have some ideas (that won't be difficult to 
> implement) I just need to think through them a bit more first.

Okay.

>>     Additional privileges are required to allow the smbd process to
>>     fork a child process and execute the commands.  The privileges
>>     will be enabled in the effective set and inheritable set when
>>     needed for command execution.  Otherwise, they will be disabled.
>>
>>     The following privileges are enabled for the exec'd process:
>>     PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
>>     PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
>>     PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
>>     PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
>>     PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
>>     PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.
> 
> Where did this list of privileges come from (other than those in the 
> basic set)?  Why this list and in particular why the very powerful 
> sys_config ?
 >
> Is it just because that is what smbd is running with ?  I want the case 
> to give the reason why this set of privileges rather than some other set 
> is the correct and useful set.

smbd doesn't need these privileges, this is only to support
the automated execution of the command.

Alan


From amw@sun.com Mon Mar 23 11:56:18 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NIuIXA002527
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 11:56:18 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2NIuHtw007477
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 23 Mar 2009 11:56:17 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ00K1B39TX000@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 11:56:17 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00DU839TKRE0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 11:56:17 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n2NIuHat010766	for
 <psarc-ext@sun.com>; Mon, 23 Mar 2009 18:56:17 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KGZ00A002RXIC00@mail-amer.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 12:56:17 -0600 (MDT)
Received: from [10.1.106.211] ([unknown] [10.1.106.211])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KGZ00J3E39KTJE0@mail-amer.sun.com>; Mon,
 23 Mar 2009 12:56:09 -0600 (MDT)
Date: Mon, 23 Mar 2009 11:56:08 -0700
From: Alan M Wright <amw@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <20090323174714.GA332868@eng.sun.com>
Sender: Alan.M.Wright@sun.com
To: Edward Pilatowicz <Edward.Pilatowicz@sun.com>
Cc: Jordan Brown <Jordan.Brown@sun.com>, psarc-ext@sun.com
Message-id: <49C7DB48.8000507@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <20090323174714.GA332868@eng.sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 5243

On 03/23/09 10:47, Edward Pilatowicz wrote:
> having worked on frameworks with lots of callbacks, i just have one nit
> comment.
> 
> the names of the callbacks (map, and unmap) are ambigious wrt when they
> are invoked wrt their associated event.  i think it's implied that map
> will be invoked after a mapping is established,

The command is invoked during the mapping of a share, we don't specify
when it will be executed during the mapping process.  The only constraint
is that the command will have been executed before a response is returned
to the client.

> and unmap will before,

Similarly, for unmap.

Alan

> but it would be nice if the name of these callbacks was changed so that
> this was explicit.  say post-map and pre-unmap.
> ed
> 
> On Fri, Mar 20, 2009 at 03:43:37PM -0700, Jordan Brown wrote:
>> I am sponsoring the following for fast track approval.
>> The timer expires 27 March 2009.
>>
>> 1. Introduction
>>      1.1. Project/Component Working Name:
>>           SMB/CIFS share exec properties
>>      1.2. Name of Document Author/Supplier:
>>           Author:  Hoa Nguyen
>>      1.3  Date of This Document:
>>           20 March, 2009
>>
>>      A patch binding is requested for this change.
>>      This is a Committed interface.
>>
>> 4. Technical Description
>>
>> 	This fast-track proposes new service properties to support the
>> 	execution of a command or script when connecting or disconnecting
>> 	CIFS shares.  These properties are configurable with sharectl(1M)
>> 	and will be applied to all shares.  The command may be used to
>> 	perform automated administrative tasks each time a share is mapped
>> 	or disconnected, for example, to create home directories or monitor
>> 	resources.  The command will be executed using the credentials of
>> 	the smbd daemon, which, by default, is root/sys.  The command
>> 	will be executed using one of the exec() functions.  The content
>> 	of the environment is not specified.
>>
>> 	See also 6766364 Add scripting support to Autohome.
>>
>> 	In order to configure properties using sharectl(1M), a user must
>> 	be the superuser or assume an equivalent role to obtain the
>> 	solaris.smf.value.smb and solaris.smf.manage.smb RBAC
>> 	authorizations, or use the SMB Management RBAC profile, which
>> 	is part of the File System Management profile.
>>
>> 	Additional privileges are required to allow the smbd process to
>> 	fork a child process and execute the commands.  The privileges
>> 	will be enabled in the effective set and inheritable set when
>> 	needed for command execution.  Otherwise, they will be disabled.
>>
>> 	The following privileges are enabled for the exec'd process:
>> 	PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
>> 	PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
>> 	PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
>> 	PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
>> 	PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
>> 	PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.
>>
>> 	The service property names and values are as follows:
>>
>> 	map		The value is a command to be executed when connecting
>> 			to the share.  The command can take the following
>> 			arguments, which will be substituted when the command
>> 			is exec'd as described below.
>>
>> 			%U - Windows username.
>>
>> 			%D - Name of the domain or workgroup of %U.
>>
>> 			%h - The server hostname.
>>
>> 			%M - The client hostname, or "" if not available.
>>
>> 			%L - The server NetBIOS name.
>>
>> 			%m - The client NetBIOS name, or "" if not available.
>> 			This option is only valid for NetBIOS connections
>> 			(port 139).
>>
>> 			%I - The IP address of the client machine.
>>
>> 			%i - The local IP address to which the client is
>> 			connected.
>>
>> 			%S - The name of the share.
>>
>> 			%P - The root directory of the share.
>>
>> 			%u - The UID of the Unix user.
>>
>> 	unmap		The value is a command to be executed when
>> 			disconnecting the share.  The command can take the
>> 			same substitutions listed on the map property.
>>
>> 	disposition	A value that controls whether to disconnect the share
>> 			or proceed if the map command fails.  The disposition
>> 			property only has meaning when the map property has
>> 			been set.  Otherwise it will have no effect.
>>
>> 			disposition = [ continue | terminate ]
>>
>> 			continue	Proceed with share connection if the
>> 					map command fails.  This is the default
>> 					in the event that disposition is not
>> 					specified.
>>
>> 			terminate	Disconnect the share if the map
>> 					command fails.
>>
>> 	Examples of setting these properties with sharectl(1M):
>>
>> 		sharectl  set -p map="/tmp/map_script %U" smb
>> 		sharectl  set -p unmap=/tmp/unmap_script smb
>> 		sharectl  set -p disposition=terminate smb
>>
>> 	For example,
>>
>> 		sharectl  set -p map="/tmp/map_script %U" smb
>>
>> 	would be invoked with arguments of the form:
>>
>> 		arg0 = /tmp/map_script
>> 		arg1 = <Windows username>
>> 		arg2 = NULL
>>
>> 6. Resources and Schedule
>>      6.4. Steering Committee requested information
>>     	6.4.1. Consolidation C-team Name:
>> 		ON
>>      6.5. ARC review type: FastTrack
>>      6.6. ARC Exposure: open
> 


From Darren.Moffat@sun.com Mon Mar 23 13:01:21 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NK1KD2002355
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 13:01:21 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n2NK1Avv023644
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 24 Mar 2009 04:01:19 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ0051T6A6N600@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 13:01:18 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00LRX6A58090@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 13:01:17 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2NK1GJX019554	for
 <psarc-ext@sun.com>; Mon, 23 Mar 2009 20:01:16 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KGZ00C0068FN000@fe-emea-10.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 20:01:16 +0000 (GMT)
Received: from [129.156.173.21] ([unknown] [129.156.173.21])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KGZ008P36A0J110@fe-emea-10.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 20:01:16 +0000 (GMT)
Date: Mon, 23 Mar 2009 20:01:12 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C7D9BF.40202@sun.com>
Sender: Darren.Moffat@sun.com
To: Alan M Wright <amw@sun.com>
Cc: Jordan Brown <Jordan.Brown@sun.com>, psarc-ext@sun.com
Message-id: <49C7EA88.40208@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
 <49C7D9BF.40202@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 3469

Alan M Wright wrote:
> On 03/23/09 02:38, Darren J Moffat wrote:
>> Jordan Brown wrote:
>>>     In order to configure properties using sharectl(1M), a user must
>>>     be the superuser or assume an equivalent role to obtain the
>>>     solaris.smf.value.smb and solaris.smf.manage.smb RBAC
>>>     authorizations, or use the SMB Management RBAC profile, which
>>>     is part of the File System Management profile.
>>
>> This case makes that authorisation equivalent to handing out the list 
>> of privileges below.  I'm not sure that is a safe thing to do.
> 
> The purpose is to allow the root user to do anything that
> would be possible if root was to login and run the command.

We try very hard in Solaris not to think and code this way anymore. 
That is why we have privileges and authoriations and all the other tools 
from RBAC.

If the intent is actually that only root should be able to do this then 
the ability to set it up shouldn't be controlled via a solaris.smf 
hierarchy RBAC authorisation.

The 'SMB Management RBAC profile' is probably suitable but the specific 
solaris.smb.*.smb auths probably aren't.

>> I need some more time to thing about this and see if there is a safer 
>> way to achieve this.  I have some ideas (that won't be difficult to 
>> implement) I just need to think through them a bit more first.
> 
> Okay.
> 
>>>     Additional privileges are required to allow the smbd process to
>>>     fork a child process and execute the commands.  The privileges
>>>     will be enabled in the effective set and inheritable set when
>>>     needed for command execution.  Otherwise, they will be disabled.
>>>
>>>     The following privileges are enabled for the exec'd process:
>>>     PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
>>>     PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
>>>     PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
>>>     PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
>>>     PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
>>>     PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.
>>
>> Where did this list of privileges come from (other than those in the 
>> basic set)?  Why this list and in particular why the very powerful 
>> sys_config ?
>  >
>> Is it just because that is what smbd is running with ?  I want the 
>> case to give the reason why this set of privileges rather than some 
>> other set is the correct and useful set.
> 
> smbd doesn't need these privileges, this is only to support
> the automated execution of the command.

Then sys_config is highly inappropriate in my opinion, I can also 
imagine cases where that list of privileges isn't actually sufficient - 
since it won't be possible to change any root owned files with just that 
list.

This should either run as root with all privs - and thus required root 
with all privs to configure it (not an RBAC authorisation likely to be 
given out for lower impact things).   This is basically how dhcpagent 
does it.

Or - and this is my preferred option - there should be a requirement 
that the commands be listed in a specific RBAC exec_attr(4) profile and 
that smbd 'pfexec' them and by default they only run with basic privs 
(unless the exec_attr(4) profile gives them more.   We can work the 
details of how to do this offline with the security team.

The name of the RBAC profile would be a Committed interface and it would 
likely be empty by default.

-- 
Darren J Moffat

From Jordan.Brown@sun.com Mon Mar 23 13:22:45 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NKMi8E003866
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 13:22:45 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n2NKMW16006529
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 24 Mar 2009 04:22:43 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ00F0V79TVW00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 13:22:41 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00D8579S6E30@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 13:22:40 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2NKMedT002738	for
 <psarc-ext@sun.com>; Mon, 23 Mar 2009 13:22:40 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KGZ00J006YUDO00@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 13:22:40 -0700 (PDT)
Received: from [129.145.155.183] ([unknown] [129.145.155.183])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KGZ005U679MOYC0@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 13:22:35 -0700 (PDT)
Date: Mon, 23 Mar 2009 13:22:34 -0700
From: Jordan Brown <Jordan.Brown@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C7EA88.40208@Sun.COM>
Sender: Jordan.Brown@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Alan M Wright <amw@sun.com>, psarc-ext@sun.com
Message-id: <49C7EF8A.1070101@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
 <49C7D9BF.40202@sun.com> <49C7EA88.40208@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)
Status: RO
Content-Length: 592

Darren J Moffat wrote:
> Or - and this is my preferred option - there should be a requirement 
> that the commands be listed in a specific RBAC exec_attr(4) profile and 
> that smbd 'pfexec' them and by default they only run with basic privs 
> (unless the exec_attr(4) profile gives them more.

That sounds like it might be theoretically correct, but it seems like a 
pretty heavyweight thing to ask users to set up.  Remember that this is 
a mechanism intended to allow users to plug their own components - 
typically but not necessarily scripts - into the SMB connect/disconnect 
process.

From amw@sun.com Mon Mar 23 13:36:00 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NKa0Km004927
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 13:36:00 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2NKZxIc009126
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Mon, 23 Mar 2009 14:36:00 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ00A0J7VZ0I00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 13:35:59 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00L047VY7XF0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 13:35:58 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n2NKZw7A028177	for
 <psarc-ext@sun.com>; Mon, 23 Mar 2009 20:35:58 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KGZ007007DPCY00@mail-amer.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Mon, 23 Mar 2009 14:35:58 -0600 (MDT)
Received: from [10.1.106.211] ([unknown] [10.1.106.211])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KGZ008PB7VUIP60@mail-amer.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Mon,
 23 Mar 2009 14:35:54 -0600 (MDT)
Date: Mon, 23 Mar 2009 13:35:54 -0700
From: Alan M Wright <amw@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C7EF8A.1070101@sun.com>
Sender: Alan.M.Wright@sun.com
To: Jordan Brown <Jordan.Brown@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>, psarc-ext@sun.com
Message-id: <49C7F2AA.1070102@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
 <49C7D9BF.40202@sun.com> <49C7EA88.40208@Sun.COM> <49C7EF8A.1070101@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 764

On 03/23/09 13:22, Jordan Brown wrote:
> Darren J Moffat wrote:
>> Or - and this is my preferred option - there should be a requirement 
>> that the commands be listed in a specific RBAC exec_attr(4) profile 
>> and that smbd 'pfexec' them and by default they only run with basic 
>> privs (unless the exec_attr(4) profile gives them more.
> 
> That sounds like it might be theoretically correct, but it seems like a 
> pretty heavyweight thing to ask users to set up.  Remember that this is 
> a mechanism intended to allow users to plug their own components - 
> typically but not necessarily scripts - into the SMB connect/disconnect 
> process.

I thought about that a while ago but was concerned about end
user flexibility.  We can take a look at it.

Alan



From Nicolas.Williams@sun.com Mon Mar 23 13:41:29 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NKfT8a005246
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 13:41:29 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2NKfQB9012615;
	Mon, 23 Mar 2009 13:41:27 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ00G09851ZG00@nwk-avmta-2.sfbay.sun.com>; Mon,
 23 Mar 2009 13:41:25 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00D4R8506850@nwk-avmta-2.sfbay.sun.com>; Mon,
 23 Mar 2009 13:41:24 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n2NKdemh002982;
 Mon, 23 Mar 2009 15:39:40 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n2NKdevT002981; Mon,
 23 Mar 2009 15:39:40 -0500 (CDT)
Date: Mon, 23 Mar 2009 15:39:40 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C75887.6030303@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Jordan Brown <Jordan.Brown@sun.com>, psarc-ext@sun.com
Message-id: <20090323203939.GU9992@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1455

On Mon, Mar 23, 2009 at 09:38:15AM +0000, Darren J Moffat wrote:
> >    The following privileges are enabled for the exec'd process:

"enabled" is not very specific.  Between the above and this:

> >                 The command will be executed using the credentials
> >     of the smbd daemon, which, by default, is root/sys. 

I assume that these processes will run with all of the listed privs in E
(and with euid==0).

> >    PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
> >    PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
> >    PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
> >    PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
> >    PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
> >    PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.
> 
> Where did this list of privileges come from (other than those in the 
> basic set)?  Why this list and in particular why the very powerful 
> sys_config ?

euid == 0 + PRIV_FILE_DAC_WRITE, PRIV_PROC_SETID, PRIV_PROC_FORK,
PRIV_PROC_EXEC -> might as well be all privileges :)

> Is it just because that is what smbd is running with ?  I want the case 
> to give the reason why this set of privileges rather than some other set 
> is the correct and useful set.

What do these hooks need to do?  I imagine they need to be able to
create ZFS datasets, setup home directories, etcetera.  For some tasks
they'll need effectively all privileges.

Nico
-- 

From Nicolas.Williams@sun.com Mon Mar 23 13:44:04 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2NKi4Dw005407
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 23 Mar 2009 13:44:04 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2NKi1j7011399;
	Mon, 23 Mar 2009 13:44:02 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGZ00H1189D4300@nwk-avmta-2.sfbay.sun.com>; Mon,
 23 Mar 2009 13:44:01 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGZ00DM889C5X40@nwk-avmta-2.sfbay.sun.com>; Mon,
 23 Mar 2009 13:44:00 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n2NKgJOt002991;
 Mon, 23 Mar 2009 15:42:19 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n2NKgJSY002990; Mon,
 23 Mar 2009 15:42:19 -0500 (CDT)
Date: Mon, 23 Mar 2009 15:42:19 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C7F2AA.1070102@sun.com>
To: Alan M Wright <amw@sun.com>
Cc: Jordan Brown <Jordan.Brown@sun.com>,
        Darren J Moffat <Darren.Moffat@sun.com>, psarc-ext@sun.com
Message-id: <20090323204218.GV9992@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
 <49C7D9BF.40202@sun.com> <49C7EA88.40208@Sun.COM> <49C7EF8A.1070101@sun.com>
 <49C7F2AA.1070102@sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1222

On Mon, Mar 23, 2009 at 01:35:54PM -0700, Alan M Wright wrote:
> On 03/23/09 13:22, Jordan Brown wrote:
> >Darren J Moffat wrote:
> >>Or - and this is my preferred option - there should be a requirement 
> >>that the commands be listed in a specific RBAC exec_attr(4) profile 
> >>and that smbd 'pfexec' them and by default they only run with basic 
> >>privs (unless the exec_attr(4) profile gives them more.
> >
> >That sounds like it might be theoretically correct, but it seems like a 
> >pretty heavyweight thing to ask users to set up.  Remember that this is 
> >a mechanism intended to allow users to plug their own components - 
> >typically but not necessarily scripts - into the SMB connect/disconnect 
> >process.
> 
> I thought about that a while ago but was concerned about end
> user flexibility.  We can take a look at it.

On OpenSolaris systems the user will have Primary Administrator assigned
to them, so user-friendliness in small environments is probably not an
issue.  For enterprise customers managing RBAC not likely a significant
issue (beyond the usual SUDO vs RBAC threads, which should be put to
rest by merging them as much as possible).  Nor should it be for the
storage appliance.

Nico
-- 

From Darren.Moffat@sun.com Tue Mar 24 02:16:01 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2O9G0eP021771
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 24 Mar 2009 02:16:01 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2O9Fwrv003359
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 24 Mar 2009 02:16:00 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KH000I0R72K2V00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 02:15:56 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KH000C3W72IPN50@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 24 Mar 2009 02:15:55 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2O9FsFS001048	for
 <psarc-ext@sun.com>; Tue, 24 Mar 2009 09:15:54 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KH000I005DJIG00@fe-emea-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 09:15:54 +0000 (GMT)
Received: from [129.156.173.21] ([unknown] [129.156.173.21])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KH000DAU72BQND0@fe-emea-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 09:15:48 +0000 (GMT)
Date: Tue, 24 Mar 2009 09:15:47 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C7F2AA.1070102@sun.com>
Sender: Darren.Moffat@sun.com
To: Alan M Wright <amw@sun.com>
Cc: Jordan Brown <Jordan.Brown@sun.com>, psarc-ext@sun.com
Message-id: <49C8A4C3.7000904@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
 <49C7D9BF.40202@sun.com> <49C7EA88.40208@Sun.COM> <49C7EF8A.1070101@sun.com>
 <49C7F2AA.1070102@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 1035

Alan M Wright wrote:
> On 03/23/09 13:22, Jordan Brown wrote:
>> Darren J Moffat wrote:
>>> Or - and this is my preferred option - there should be a requirement 
>>> that the commands be listed in a specific RBAC exec_attr(4) profile 
>>> and that smbd 'pfexec' them and by default they only run with basic 
>>> privs (unless the exec_attr(4) profile gives them more.
>>
>> That sounds like it might be theoretically correct, but it seems like 
>> a pretty heavyweight thing to ask users to set up.  Remember that this 
>> is a mechanism intended to allow users to plug their own components - 
>> typically but not necessarily scripts - into the SMB 
>> connect/disconnect process.
> 
> I thought about that a while ago but was concerned about end
> user flexibility.  We can take a look at it.

Great, in the mean time can we have the case put in "waiting need spec" 
please since this is crucial to the architecture.

It does provide more flexibility but it also provides more 
accountability and more security.

-- 
Darren J Moffat

From Darren.Moffat@sun.com Tue Mar 24 02:16:25 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2O9GPvs021806
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 24 Mar 2009 02:16:25 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2O9G2gL012201
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 24 Mar 2009 02:16:25 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KH000H0V7367R00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 02:16:18 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KH000H0Q7357H00@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 24 Mar 2009 02:16:18 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2O9GH7W002238	for
 <psarc-ext@sun.com>; Tue, 24 Mar 2009 09:16:17 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KH000C005LWJC00@fe-emea-10.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 09:16:17 +0000 (GMT)
Received: from [129.156.173.21] ([unknown] [129.156.173.21])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KH0008UZ72RJ1B0@fe-emea-10.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 09:16:06 +0000 (GMT)
Date: Tue, 24 Mar 2009 09:16:03 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C7EF8A.1070101@sun.com>
Sender: Darren.Moffat@sun.com
To: Jordan Brown <Jordan.Brown@sun.com>
Cc: Alan M Wright <amw@sun.com>, psarc-ext@sun.com
Message-id: <49C8A4D3.7070707@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
 <49C7D9BF.40202@sun.com> <49C7EA88.40208@Sun.COM> <49C7EF8A.1070101@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 928

Jordan Brown wrote:
> Darren J Moffat wrote:
>> Or - and this is my preferred option - there should be a requirement 
>> that the commands be listed in a specific RBAC exec_attr(4) profile 
>> and that smbd 'pfexec' them and by default they only run with basic 
>> privs (unless the exec_attr(4) profile gives them more.
> 
> That sounds like it might be theoretically correct, but it seems like a 
> pretty heavyweight thing to ask users to set up.  Remember that this is 
> a mechanism intended to allow users to plug their own components - 
> typically but not necessarily scripts - into the SMB connect/disconnect 
> process.

I don't thing it is heavyweight at all.  In fact all that would be 
required is a single entry in the specific RBAC exec_attr(4) table that 
listed what uid/gid and privs the "script" ran with.  That can even be 
done once for the whole network and stored in NIS, NIS+, LDAP.

-- 
Darren J Moffat

From Jordan.Brown@sun.com Tue Mar 24 08:24:02 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2OFO1fP005811
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 24 Mar 2009 08:24:02 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2OFNo1X029709
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 24 Mar 2009 09:24:01 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KH000F11O41QB00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 08:24:01 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KH000AQBO409D70@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 24 Mar 2009 08:24:01 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2OFO0A9004069	for
 <psarc-ext@sun.com>; Tue, 24 Mar 2009 08:24:00 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KH000C00MH2YR00@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 08:24:00 -0700 (PDT)
Received: from [129.145.155.183] ([unknown] [129.145.155.183])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KH0007A1O3BNXB0@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 24 Mar 2009 08:23:36 -0700 (PDT)
Date: Tue, 24 Mar 2009 08:23:35 -0700
From: Jordan Brown <Jordan.Brown@sun.com>
Subject: Re: 2009/184 SMB/CIFS Share Exec Properties
In-reply-to: <49C8A4C3.7000904@Sun.COM>
Sender: Jordan.Brown@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Alan M Wright <amw@sun.com>, psarc-ext@sun.com
Message-id: <49C8FAF7.7070502@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49C41C19.40308@sun.com> <49C75887.6030303@Sun.COM>
 <49C7D9BF.40202@sun.com> <49C7EA88.40208@Sun.COM> <49C7EF8A.1070101@sun.com>
 <49C7F2AA.1070102@sun.com> <49C8A4C3.7000904@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)
Status: RO
Content-Length: 158

Darren J Moffat wrote:
> Great, in the mean time can we have the case put in "waiting need spec" 
> please since this is crucial to the architecture.

Done.


From Jordan.Brown@sun.com Wed Apr 22 18:13:08 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3N1D7mD024610
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 22 Apr 2009 18:13:07 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n3N1D0l9007699
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 23 Apr 2009 02:13:06 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIJ00J1B4PS8K00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 22 Apr 2009 18:13:04 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIJ007NI4PSHEC0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 22 Apr 2009 18:13:04 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n3N1D3Gk008744	for
 <psarc-ext@sun.com>; Wed, 22 Apr 2009 18:13:03 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KIJ00F004G50K00@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 22 Apr 2009 18:13:03 -0700 (PDT)
Received: from [129.145.155.183] ([unknown] [129.145.155.183])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KIJ000WF4PRBH50@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 22 Apr 2009 18:13:03 -0700 (PDT)
Date: Wed, 22 Apr 2009 18:13:03 -0700
From: Jordan Brown <Jordan.Brown@sun.com>
Subject: 2009/184 CIFS share exec - new spec
Sender: Jordan.Brown@sun.com
To: PSARC-ext@sun.com
Message-id: <49EFC09F.3020008@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)
Status: RO
Content-Length: 7900

We'd like to restart the timer on this case.  The restarted
timer expires 29 April 2009.

Darren raised some concerns about privilege escalation and
suggested a possible avenue to addressing those concerns
(using /etc/security/exec_attr and pfexec to control the
execution environment of the program executed), but that
avenue did not work out.

We have simplified the specification - we now explicitly give the
program all privileges, rather than a large (and for practical
purposes omnipotent) set.  We have clarified it, specifying the
exact FMRI and property group that will store the properties, and
the authorization that will most directly allow a user to edit
those properties.

Our discussions with Darren mentioned requiring that the user
be root and have all privileges in order to set these values, but
that is not a practical restriction for data that is stored in
SMF - SMF defines authorizations that allow near-total control
over its activities, including the ability to change any property
on any service in the system (solaris.smf.modify), which is
clearly omnipotent.  (Consider, for instance, the ability
to change the properties that represent the command to be run
to start a service.)

Inspection of the existing properties that can be modified
using solaris.smf.modify.application suggests that although it
is not clear that one can directly escalate privilege to
omnipotence, one can certainly muck up the system with it.

Given the limitations of the problem ...

     - That it is desirable to offer the user unrestricted
       control over the system in the program to be executed,
       and
     - That it is desirable to store the configuration data in
       SMF properties,
       and
     - The available SMF and RBAC expertise

... we believe that this is the best solution available.

Minor variations are possible.  We could rearrange things
so as to change exactly which SMF-related authorizations
could be used to configure this feature.  (But note that
some of the high-level SMF authorizations have global effect,
and will be usable to control our properties no matter what
we do.)

The essence would remain, though:  there would be some set
of authorizations which could be used to achieve total
control over the system.  Those could be existing authorizations
that *already* allow substantial or total control, or could be
fine-grained new authorizations that allowed total control
only through this mechanism.

All that said, below are some diffs, and then the full
specification.

27,31c27,29
<     In order to configure properties using sharectl(1M), a user must
<     be the superuser or assume an equivalent role to obtain the
<     solaris.smf.value.smb and solaris.smf.manage.smb RBAC
<     authorizations, or use the SMB Management RBAC profile, which
<     is part of the File System Management profile.
---
 >     In order to configure these properties using sharectl(1M), a user
 >     must be the superuser or assume an equivalent role to obtain the
 >     solaris.smf.modify.application RBAC authorization.
38,44c36
<     The following privileges are enabled for the exec'd process:
<     PRIV_FILE_CHOWN, PRIV_FILE_CHOWN_SELF, PRIV_FILE_DAC_EXECUTE,
<     PRIV_FILE_DAC_READ, PRIV_FILE_DAC_SEARCH, PRIV_FILE_DAC_WRITE,
<     PRIV_FILE_LINK_ANY, PRIV_FILE_OWNER, PRIV_FILE_SETID,
<     PRIV_PROC_EXEC, PRIV_PROC_FORK, PRIV_PROC_INFO, PRIV_PROC_OWNER,
<     PRIV_PROC_SESSION, PRIV_PROC_SETID, PRIV_SYS_CONFIG,
<     PRIV_SYS_LINKDIR, and PRIV_SYS_MOUNT.
---
 >     All privileges are enabled for the exec'd process.
45a38,40
 >     These properties are stored in SMF(5) in the
 >     svc:/network/smb/server:default service under the exec property group.
 >

1. Introduction
      1.1. Project/Component Working Name:
           SMB/CIFS share exec properties
      1.2. Name of Document Author/Supplier:
           Author:  Hoa Nguyen
      1.3  Date of This Document:
           20 March, 2009

      A patch binding is requested for this change.
      This is a Committed interface.

4. Technical Description

     This fast-track proposes new service properties to support the
     execution of a command or script when connecting or disconnecting
     CIFS shares.  These properties are configurable with sharectl(1M)
     and will be applied to all shares.  The command may be used to
     perform automated administrative tasks each time a share is mapped
     or disconnected, for example, to create home directories or monitor
     resources.  The command will be executed using the credentials of
     the smbd daemon, which, by default, is root/sys.  The command
     will be executed using one of the exec() functions.  The content
     of the environment is not specified.

     See also 6766364 Add scripting support to Autohome.

     In order to configure these properties using sharectl(1M), a user
     must be the superuser or assume an equivalent role to obtain the
     solaris.smf.modify.application RBAC authorization.

     Additional privileges are required to allow the smbd process to
     fork a child process and execute the commands.  The privileges
     will be enabled in the effective set and inheritable set when
     needed for command execution.  Otherwise, they will be disabled.

     All privileges are enabled for the exec'd process.

     These properties are stored in SMF(5) in the
     svc:/network/smb/server:default service under the exec property group.

     The service property names and values are as follows:

     map        The value is a command to be executed when connecting
             to the share.  The command can take the following
             arguments, which will be substituted when the command
             is exec'd as described below.

             %U - Windows username.

             %D - Name of the domain or workgroup of %U.

             %h - The server hostname.

             %M - The client hostname, or "" if not available.

             %L - The server NetBIOS name.

             %m - The client NetBIOS name, or "" if not available.
             This option is only valid for NetBIOS connections
             (port 139).

             %I - The IP address of the client machine.

             %i - The local IP address to which the client is
             connected.

             %S - The name of the share.

             %P - The root directory of the share.

             %u - The UID of the Unix user.

     unmap        The value is a command to be executed when
             disconnecting the share.  The command can take the
             same substitutions listed on the map property.

     disposition    A value that controls whether to disconnect the share
             or proceed if the map command fails.  The disposition
             property only has meaning when the map property has
             been set.  Otherwise it will have no effect.

             disposition = [ continue | terminate ]

             continue    Proceed with share connection if the
                     map command fails.  This is the default
                     in the event that disposition is not
                     specified.

             terminate    Disconnect the share if the map
                     command fails.

     Examples of setting these properties with sharectl(1M):

         sharectl  set -p map="/tmp/map_script %U" smb
         sharectl  set -p unmap=/tmp/unmap_script smb
         sharectl  set -p disposition=terminate smb

     For example,

         sharectl  set -p map="/tmp/map_script %U" smb

     would be invoked with arguments of the form:

         arg0 = /tmp/map_script
         arg1 = <Windows username>
         arg2 = NULL

6. Resources and Schedule
      6.4. Steering Committee requested information
         6.4.1. Consolidation C-team Name:
         ON
      6.5. ARC review type: FastTrack
      6.6. ARC Exposure: open



From Darren.Moffat@sun.com Thu Apr 23 01:23:31 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3N8NUPq024253
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 23 Apr 2009 01:23:31 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n3N8NJMC014785
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 23 Apr 2009 09:23:29 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIJ00B11ON3VU00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 23 Apr 2009 01:23:27 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIJ00A5FON2QM10@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 23 Apr 2009 01:23:26 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n3N8NPvN014662	for
 <PSARC-ext@sun.com>; Thu, 23 Apr 2009 08:23:25 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KIJ00I00NP5CJ00@fe-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 23 Apr 2009 09:23:25 +0100 (BST)
Received: from [192.168.1.103]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KIJ00DN4OMY0A60@fe-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 23 Apr 2009 09:23:23 +0100 (BST)
Date: Thu, 23 Apr 2009 09:23:20 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: 2009/184 CIFS share exec - new spec
In-reply-to: <49EFC09F.3020008@sun.com>
Sender: Darren.Moffat@sun.com
To: Jordan Brown <Jordan.Brown@sun.com>
Cc: PSARC-ext@sun.com
Message-id: <49F02578.1090508@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <49EFC09F.3020008@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20090211)
Status: RO
Content-Length: 95

I'm happy with the case as specified given the constraints imposed by SMF.

--
Darren J Moffat

From Jordan.Brown@sun.com Thu Apr 30 14:25:34 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3ULPXkR021921
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 30 Apr 2009 14:25:33 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n3ULPURw016525
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Fri, 1 May 2009 05:25:32 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIX00B05NIK2A00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 30 Apr 2009 14:25:32 -0700 (PDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIX00A1SNIIZZ00@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 30 Apr 2009 14:25:30 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n3ULPUW9022716	for
 <psarc-ext@sun.com>; Thu, 30 Apr 2009 14:25:30 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KIX00C00NI2WL00@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 30 Apr 2009 14:25:30 -0700 (PDT)
Received: from [129.145.155.183] ([unknown] [129.145.155.183])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KIX00KQMNHQNT50@fe-sfbay-09.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 30 Apr 2009 14:25:03 -0700 (PDT)
Date: Thu, 30 Apr 2009 14:25:02 -0700
From: Jordan Brown <Jordan.Brown@sun.com>
Subject: 2009/184 SMB/CIFS Share Exec Properties
Sender: Jordan.Brown@sun.com
To: psarc-ext@sun.com
Message-id: <49FA172E.4070509@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)
Status: RO
Content-Length: 107

[ Didn't make it into the case mail log.  Trying again. ]

This case was approved at Wednesday's meeting.


