From Tim.Haley@sun.com Tue Jun 30 18:24:10 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n611OA9l021707
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 30 Jun 2009 18:24:10 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n611O6oI055938;
	Tue, 30 Jun 2009 19:24:09 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KM20092HX86HS00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 30 Jun 2009 18:24:06 -0700 (PDT)
Received: from dm-central-01.central.sun.com ([129.147.62.4])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KM200KP6X86R870@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 30 Jun 2009 18:24:06 -0700 (PDT)
Received: from spidey.local (spidey.Central.Sun.COM [172.20.25.27])
	by dm-central-01.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n611O5tl007278; Tue, 30 Jun 2009 19:24:05 -0600 (MDT)
Received: from spidey.local (localhost [127.0.0.1])
	by spidey.local (8.14.3+Sun/8.14.3) with ESMTP id n611GHHk001154; Tue,
 30 Jun 2009 19:16:17 -0600 (MDT)
Received: (from timh@localhost)	by spidey.local (8.14.3+Sun/8.14.3/Submit)
 id n611GHZp001153; Tue, 30 Jun 2009 19:16:17 -0600 (MDT)
Date: Tue, 30 Jun 2009 19:16:17 -0600 (MDT)
From: Tim Haley <Tim.Haley@sun.com>
Subject: ABE share property for NFS and SMB [PSARC/2009/375 Self Review]
To: PSARC-ext@sun.com
Cc: cifs-team@sun.com
Message-id: <200907010116.n611GHZp001153@spidey.local>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2269

I am sponsoring this case on behalf of Alan Wright.  Requested binding
is minor/patch.  The case provides a new NFS and SMB share property
enabling ABE filtering.  Since the proposal is so straight-forward I
believe it qualifies for self-review.  If anyone disagrees, please let
me know and I'll promote this to a fast-track.

Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 ABE share property for NFS and SMB
    1.2. Name of Document Author/Supplier:
	 Author:  Alan Wright
    1.3  Date of This Document:
	30 June, 2009

4. Technical Description
    4.1. Details:

	This case proposes a new share property to support Access Based
	Enumeration (ABE) on NFS and SMB shares.

	The NFS and SMB services will consume the interface defined by
	PSARC/2009/246, which added ABE support to ZFS.  The ABE share
	property will provide administrators with the ability to enable
	ACL based directory content filtering on NFS and SMB shares.
	As described in PSARC/2009/246, with ABE enabled, entries to
	which the requesting user has no access will be omitted from
	the dirent data returned by the file system.

	Additional information is available in the following RFEs:
	6802734 Support for Access Based Enumeration
	6802736 SMB share support for Access Based Enumeration 

	The proposed property name and values are:

		abe=boolean

	Values of type boolean take either true or false.

    4.2. Bug/RFE Number(s):
	6802736 SMB share support for Access Based Enumeration

    4.6. Doc Impact:

	Modifications to the sharemgr(1M) man page:

+        abe=boolean
+
+	    Set the access based enumeration (ABE) policy for the share.
+	    When set to true ABE filtering is enabled on this share and
+	    directory entries to which the requesting user has no access
+	    will be omitted from directory listings returned to the client.
+	    When set to false or not defined ABE filtering will not be
+	    performed on this share.  This property is not defined by
+	    default.

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: Automatic
    6.6. ARC Exposure: open


From Darren.Moffat@sun.com Wed Jul  1 04:24:10 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n61BOAGS004979
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 1 Jul 2009 04:24:10 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n61BO8Se003372;
	Wed, 1 Jul 2009 04:24:10 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KM30000VP09PS00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 01 Jul 2009 04:24:09 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KM300CUCP07ABB0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 01 Jul 2009 04:24:08 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n61BO71h001285; Wed,
 01 Jul 2009 11:24:07 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KM300J00NUSTR00@fe-emea-09.sun.com>; Wed, 01 Jul 2009 12:24:07 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KM300AYWOZPNE90@fe-emea-09.sun.com>; Wed,
 01 Jul 2009 12:23:50 +0100 (BST)
Date: Wed, 01 Jul 2009 12:23:49 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: ABE share property for NFS and SMB [PSARC/2009/375 Self Review]
In-reply-to: <200907010116.n611GHZp001153@spidey.local>
Sender: Darren.Moffat@sun.com
To: Tim Haley <Tim.Haley@sun.com>
Cc: PSARC-ext@sun.com, cifs-team@sun.com
Message-id: <4A4B4745.6040704@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200907010116.n611GHZp001153@spidey.local>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 2135

Tim Haley wrote:
> I am sponsoring this case on behalf of Alan Wright.  Requested binding
> is minor/patch.  The case provides a new NFS and SMB share property
> enabling ABE filtering.  Since the proposal is so straight-forward I
> believe it qualifies for self-review.  If anyone disagrees, please let
> me know and I'll promote this to a fast-track.
> 
> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 ABE share property for NFS and SMB
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Alan Wright
>     1.3  Date of This Document:
> 	30 June, 2009
> 
> 4. Technical Description
>     4.1. Details:
> 
> 	This case proposes a new share property to support Access Based
> 	Enumeration (ABE) on NFS and SMB shares.
> 
> 	The NFS and SMB services will consume the interface defined by
> 	PSARC/2009/246, which added ABE support to ZFS.  The ABE share
> 	property will provide administrators with the ability to enable
> 	ACL based directory content filtering on NFS and SMB shares.
> 	As described in PSARC/2009/246, with ABE enabled, entries to
> 	which the requesting user has no access will be omitted from
> 	the dirent data returned by the file system.
> 
> 	Additional information is available in the following RFEs:
> 	6802734 Support for Access Based Enumeration
> 	6802736 SMB share support for Access Based Enumeration 
> 
> 	The proposed property name and values are:
> 
> 		abe=boolean

IMO that isn't a very descriptive name for end admins isn't there 
anything better ?  If there isn't then fair-enough.

Is this a ZPL property or a normal one ?

Why is this a separate per dataset property rather than an option for 
sharenfs or sharesmb ?  I'm assuming the answer is because like the 
oplocks discussion in PSARC/2009/140 ie it has to be the same for all 
shares of the dataset (which for CIFS can overlap but can't for NFS). 
Actually given that what is the reason this isn't an option for the smb 
property (obviously that doesn't allow it to be used for NFS) ?

-- 
Darren J Moffat

From amw@sun.com Wed Jul  1 04:32:36 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n61BWaKv005014
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 1 Jul 2009 04:32:36 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n61BWYcw017863;
	Wed, 1 Jul 2009 12:32:35 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KM300805PEA7300@brm-avmta-1.central.sun.com>; Wed,
 01 Jul 2009 05:32:34 -0600 (MDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KM300IAFPE90R70@brm-avmta-1.central.sun.com>; Wed,
 01 Jul 2009 05:32:33 -0600 (MDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n61BWXt7027539; Wed,
 01 Jul 2009 11:32:33 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KM300F00P6S1P00@mail-amer.sun.com>; Wed, 01 Jul 2009 05:32:33 -0600 (MDT)
Received: from TOSHIBA ([unknown] [68.228.88.55])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KM300FFCPE807A0@mail-amer.sun.com>; Wed,
 01 Jul 2009 05:32:33 -0600 (MDT)
Date: Wed, 01 Jul 2009 04:32:30 -0700
From: "Alan.M.Wright" <amw@sun.com>
Subject: Re: ABE share property for NFS and SMB [PSARC/2009/375 Self Review]
Sender: Alan.M.Wright@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>, Tim Haley <Tim.Haley@sun.com>
Cc: PSARC-ext@sun.com, cifs-team@sun.com
Message-id: <FB8C89919B4B4E9BA703878FC3038A08@TOSHIBA>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.5579
X-Mailer: Microsoft Outlook Express 6.00.2900.5512
Content-type: text/plain; CHARSET=US-ASCII; reply-type=response; format=flowed
Content-transfer-encoding: 7BIT
X-Priority: 3
X-MSMail-priority: Normal
X-PMX-Version: 5.4.1.325704
References: <200907010116.n611GHZp001153@spidey.local>
 <4A4B4745.6040704@Sun.COM>
Status: RO
Content-Length: 2541

Darren J Moffat <Darren.Moffat@Sun.COM> wrote:
> Tim Haley wrote:
>> I am sponsoring this case on behalf of Alan Wright.  Requested binding
>> is minor/patch.  The case provides a new NFS and SMB share property
>> enabling ABE filtering.  Since the proposal is so straight-forward I
>> believe it qualifies for self-review.  If anyone disagrees, please let
>> me know and I'll promote this to a fast-track.
>> 
>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>> This information is Copyright 2009 Sun Microsystems
>> 1. Introduction
>>     1.1. Project/Component Working Name:
>> ABE share property for NFS and SMB
>>     1.2. Name of Document Author/Supplier:
>> Author:  Alan Wright
>>     1.3  Date of This Document:
>> 30 June, 2009
>> 
>> 4. Technical Description
>>     4.1. Details:
>> 
>> This case proposes a new share property to support Access Based
>> Enumeration (ABE) on NFS and SMB shares.
>> 
>> The NFS and SMB services will consume the interface defined by
>> PSARC/2009/246, which added ABE support to ZFS.  The ABE share
>> property will provide administrators with the ability to enable
>> ACL based directory content filtering on NFS and SMB shares.
>> As described in PSARC/2009/246, with ABE enabled, entries to
>> which the requesting user has no access will be omitted from
>> the dirent data returned by the file system.
>> 
>> Additional information is available in the following RFEs:
>> 6802734 Support for Access Based Enumeration
>> 6802736 SMB share support for Access Based Enumeration 
>> 
>> The proposed property name and values are:
>> 
>> abe=boolean
> 
> IMO that isn't a very descriptive name for end admins isn't there 
> anything better ?  If there isn't then fair-enough.

It's generally known as ABE.

> Is this a ZPL property or a normal one ?

Neither.

> Why is this a separate per dataset property rather than an option for 
> sharenfs or sharesmb ?

It's a regular per-share property that can be set via sharemgr or
via sharenfs/sharesmb.

>  I'm assuming the answer is because like the 
> oplocks discussion in PSARC/2009/140 ie it has to be the same for all 
> shares of the dataset (which for CIFS can overlap but can't for NFS). 
> Actually given that what is the reason this isn't an option for the smb 
> property (obviously that doesn't allow it to be used for NFS) ?

There are no restrictions related to overlapping shares for this property.
You can share the same directory twice with different ABE settings.
One share will filter readdir requests, the other won't.

Alan


From Darren.Moffat@sun.com Wed Jul  1 04:55:14 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n61BtDOR005406
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 1 Jul 2009 04:55:13 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n61BtAZC041582;
	Wed, 1 Jul 2009 05:55:13 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KM300405QFZXW00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 01 Jul 2009 04:55:11 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KM300CW9QFYAID0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 01 Jul 2009 04:55:11 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n61BtAEl006095; Wed,
 01 Jul 2009 11:55:10 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KM300200O0ZYM00@fe-emea-09.sun.com>; Wed, 01 Jul 2009 12:55:10 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KM300AFYQF4NEB0@fe-emea-09.sun.com>; Wed,
 01 Jul 2009 12:54:40 +0100 (BST)
Date: Wed, 01 Jul 2009 12:54:40 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: ABE share property for NFS and SMB [PSARC/2009/375 Self Review]
In-reply-to: <FB8C89919B4B4E9BA703878FC3038A08@TOSHIBA>
Sender: Darren.Moffat@sun.com
To: "Alan.M.Wright" <amw@sun.com>
Cc: Tim Haley <Tim.Haley@sun.com>, PSARC-ext@sun.com, cifs-team@sun.com
Message-id: <4A4B4E80.2090204@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200907010116.n611GHZp001153@spidey.local>
 <4A4B4745.6040704@Sun.COM> <FB8C89919B4B4E9BA703878FC3038A08@TOSHIBA>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 1444

Alan.M.Wright wrote:
>>> This case proposes a new share property to support Access Based
>>> Enumeration (ABE) on NFS and SMB shares.
>>>
>>> The NFS and SMB services will consume the interface defined by
>>> PSARC/2009/246, which added ABE support to ZFS.  The ABE share
>>> property will provide administrators with the ability to enable
>>> ACL based directory content filtering on NFS and SMB shares.
>>> As described in PSARC/2009/246, with ABE enabled, entries to
>>> which the requesting user has no access will be omitted from
>>> the dirent data returned by the file system.
>>>
>>> Additional information is available in the following RFEs:
>>> 6802734 Support for Access Based Enumeration
>>> 6802736 SMB share support for Access Based Enumeration
>>> The proposed property name and values are:
>>>
>>> abe=boolean
>>
>> IMO that isn't a very descriptive name for end admins isn't there 
>> anything better ?  If there isn't then fair-enough.
> 
> It's generally known as ABE.

Okay.

>> Is this a ZPL property or a normal one ?
> 
> Neither.
> 
>> Why is this a separate per dataset property rather than an option for 
>> sharenfs or sharesmb ?
> 
> It's a regular per-share property that can be set via sharemgr or
> via sharenfs/sharesmb.

Okay, great I got confused in my reading of the case and assumed where 
it said property it mean't ZFS property.

I agree this is suitable for Self Review as specified.

-- 
Darren J Moffat

From Darren.Moffat@Sun.COM Fri Aug 28 02:19:54 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n7S9Jsmq000780
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 28 Aug 2009 02:19:54 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n7S9Jse1059965;
	Fri, 28 Aug 2009 03:19:54 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KP200L05XX4Z200@nwk-avmta-2.sfbay.sun.com>; Fri,
 28 Aug 2009 02:19:52 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KP200FLTXX32HA0@nwk-avmta-2.sfbay.sun.com>; Fri,
 28 Aug 2009 02:19:52 -0700 (PDT)
Received: from fe-emea-09.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n7S9JoHJ015855; Fri,
 28 Aug 2009 09:19:51 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KP200H00X31LG00@fe-emea-09.sun.com>; Fri, 28 Aug 2009 10:19:42 +0100 (BST)
Received: from [192.168.1.105]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KP200DHQXWKPY40@fe-emea-09.sun.com>; Fri,
 28 Aug 2009 10:19:32 +0100 (BST)
Date: Fri, 28 Aug 2009 10:19:32 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Minor update ABE share property for NFS and SMB [PSARC/2009/375 Self
 Review]
Sender: Darren.Moffat@Sun.COM
To: PSARC-ext@Sun.COM, cifs-team@Sun.COM
Message-id: <4A97A124.7060603@Sun.COM>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_c3VZX072b1V3L6wxELsV7w)"
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.21 (X11/20090623)
Status: RO
Content-Length: 4756

This is a multi-part message in MIME format.

--Boundary_(ID_c3VZX072b1V3L6wxELsV7w)
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT

Attached is a minor update to this already closed case.  I'm submitting 
this on behalf of the project team since their original sponsor isn't 
available to do so at the moment.

The update is to not use ABE for NFS only CIFS.

I don't believe that this change causes the case to need to be re-opened 
to run with a timer.

-- 
Darren J Moffat

--Boundary_(ID_c3VZX072b1V3L6wxELsV7w)
Content-type: text/plain; name=abe_diff.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=abe_diff.txt

5c5
< 	ABE share property for NFS and SMB
---
> 	ABE share property for SMB
9c9
< 	29 June, 2009
---
> 	28 August, 2009
15c15
< 	Enumeration (ABE) on NFS and SMB shares.
---
> 	Enumeration (ABE) on SMB shares.
17c17
< 	The NFS and SMB services will consume the interface defined by
---
> 	The SMB services will consume the interface defined by
20c20
< 	ACL based directory content filtering on NFS and SMB shares.
---
> 	ACL based directory content filtering on SMB shares.
28a29,42
> 	Note:
> 	The ABE property was considered for the NFS service but this has
> 	been rejected because readdir caching on NFS clients can defeat ABE.
> 	NFS client readdir caching is not user specific.  After a user has
> 	read a directory from an NFS client, other users on the same client
> 	will get the same results as the original user, which can cause
> 	spurious behavior with ABE enabled.  Although this issue can be
> 	resolved by disabling the NFS client readdir cache, this was deemed
> 	to be an unsuitable solution due to:
> 		- it would create a dependecy between a server share property
> 		  and the configuration on all NFS clients.
> 		- complexity of administration
> 		- potential differences in behavior of various NFS clients
> 


--Boundary_(ID_c3VZX072b1V3L6wxELsV7w)
Content-type: text/plain; name=abe_smb.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=abe_smb.txt

Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
   1.1. Project/Component Working Name:
	ABE share property for SMB
   1.2. Name of Document Author/Supplier:
	Author:  Alan Wright
   1.3  Date of This Document:
	28 August, 2009

4. Technical Description
    4.1. Details:

	This case proposes a new share property to support Access Based
	Enumeration (ABE) on SMB shares.

	The SMB services will consume the interface defined by
	PSARC/2009/246, which added ABE support to ZFS.  The ABE share
	property will provide administrators with the ability to enable
	ACL based directory content filtering on SMB shares.
	As described in PSARC/2009/246, with ABE enabled, entries to
	which the requesting user has no access will be omitted from
	the dirent data returned by the file system.

	Additional information is available in the following RFEs:
	6802734 Support for Access Based Enumeration
	6802736 SMB share support for Access Based Enumeration 

	Note:
	The ABE property was considered for the NFS service but this has
	been rejected because readdir caching on NFS clients can defeat ABE.
	NFS client readdir caching is not user specific.  After a user has
	read a directory from an NFS client, other users on the same client
	will get the same results as the original user, which can cause
	spurious behavior with ABE enabled.  Although this issue can be
	resolved by disabling the NFS client readdir cache, this was deemed
	to be an unsuitable solution due to:
		- it would create a dependecy between a server share property
		  and the configuration on all NFS clients.
		- complexity of administration
		- potential differences in behavior of various NFS clients

	The proposed property name and values are:

		abe=boolean

	Values of type boolean take either true or false.

    4.2. Bug/RFE Number(s):
	6802736 SMB share support for Access Based Enumeration

    4.6. Doc Impact:

	Modifications to the sharemgr(1M) man page:

+        abe=boolean
+
+	    Set the access based enumeration (ABE) policy for the share.
+	    When set to true ABE filtering is enabled on this share and
+	    directory entries to which the requesting user has no access
+	    will be omitted from directory listings returned to the client.
+	    When set to false or not defined ABE filtering will not be
+	    performed on this share.  This property is not defined by
+	    default.

6. Resources and Schedule
    6.4. Steering Committee requested information
	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


--Boundary_(ID_c3VZX072b1V3L6wxELsV7w)--

