Код: Выделить всё
[f0s@fileserver] //> uname -a
FreeBSD fileserver.artpaint 6.3-RELEASE-p6 FreeBSD 6.3-RELEASE-p6 #0: Mon Dec 1 16:37:14 MSK 2008 f0s@fileserver.artpaint:/usr/obj/usr/src/sys/fileserver-2008-01-12 amd64
Код: Выделить всё
[f0s@fileserver] //> pkg_info | grep samba
samba34-3.4.5_1 A free SMB and CIFS client and server for UNIX
шары лежат тута:
Код: Выделить всё
/dev/ar0s2e on /usr/home/public/homes (ufs, local, with quotas, soft-updates, acls)
/dev/ar0s2d on /usr/home/public/profiles (ufs, local, with quotas, soft-updates, acls)
/dev/ar0s2f on /usr/home/public/shared (ufs, local, soft-updates, acls)
во первых чтобы нормально работать пользователям проишлось делать setfacl -b * && setfacl -m u::rwx,g:rwx *
но, мало того, из виндоус теперь нельзя выставлять галки (рулить правами).. как только пытаюсь добавить разрешения к какому-лиюо файлу или папке, выдает сообщение:
Код: Выделить всё
Безопасность
Не удалось сохранить изменения разрешений на НОВАЯ ПАПКА
Отказано в доступе.
[Повтор] [Отмена]
Кто-нить сталкивался с таким? что вообще делать-то?
конфиг самбы выкладываю на всякий случай:
Код: Выделить всё
[f0s@fileserver] //> testparm
Load smb config files from /usr/local/etc/smb.conf
max_open_files: sysctl_max (11095) below minimum Windows limit (16384)
rlimit_max: rlimit_max (11095) below minimum Windows limit (16384)
Processing section "[HOME]"
Processing section "[profiles]"
Processing section "[shared]"
Processing section "[trash]"
Processing section "[magazin]"
Processing section "[backup]"
Processing section "[tmp]"
Processing section "[printers]"
Processing section "[print$]"
Processing section "[IPC$]"
Loaded services file OK.
Invalid combination of parameters for service profiles. Map hidden can only work if create mask includes octal 01 (S_IXOTH).
Invalid combination of parameters for service profiles. Map system can only work if create mask includes octal 010 (S_IXGRP).
Server role: ROLE_DOMAIN_MEMBER
Press enter to see a dump of your service definitions
[global]
dos charset = cp866
unix charset = koi8-r
display charset = koi8-r
workgroup = ARTPAINT
server string =
security = DOMAIN
passdb backend = ldapsam:ldaps://192.168.10.8/
log file = /var/log/samba34/log.%m
max log size = 500
acl compatibility = win2k
socket options = TCP_NODELAY IPTOS_LOWDELAY SO_RCVBUF=8192 SO_SNDBUF=8192
printcap name = cups
os level = 33
local master = No
domain master = No
wins server = 192.168.10.8
ldap admin dn = "cn=root,dc=artpaint,dc=spb,dc=ru"
ldap group suffix = ou=groups
ldap machine suffix = ou=computers
ldap suffix = dc=artpaint,dc=spb,dc=ru
ldap user suffix = ou=users
idmap uid = 8000-9000
idmap gid = 8000-9000
winbind separator = @
winbind enum users = Yes
winbind enum groups = Yes
winbind use default domain = Yes
inherit acls = Yes
hosts allow = 192.168.10., 192.168.20., 192.168.0., 127.
map acl inherit = Yes
[HOME]
comment = Home directories
path = /usr/home/public/homes/%u
read only = No
create mask = 0600
directory mask = 0700
browseable = No
browsable = No
vfs objects = recycle, full_audit
full_audit:priority = INFO
full_audit:failure = unlink rmdir mkdir write rename write aio_write pwrite
full_audit:success = unlink rmdir mkdir write rename write aio_write pwrite
full_audit:prefix = share=%S; id=%U; ip=%I -->
recycle:minsize = 1
recycle:versions = Yes
recycle:directory_mode = 0770
recycle:exclude = *.TMP *.tmp *.avi *.AVI *.MPG *.mpg
recycle:maxsize = 0
recycle:version = Yes
recycle:touch_mtime = Yes
recycle:touch = Yes
recycle:keeptree = Yes
recycle:repository = /var/spool/trash/%S
[profiles]
comment = Users profiles
path = /usr/home/public/profiles/%u
read only = No
create mask = 0600
directory mask = 0700
map hidden = Yes
map system = Yes
browseable = No
browsable = No
csc policy = disable
[shared]
comment = Shared files
path = /usr/home/public/shared
admin users = @ARTPAINT\admins
read list = @ARTPAINT\people
write list = @ARTPAINT\people
read only = No
create mask = 0660
directory mask = 0770
force unknown acl user = Yes
map archive = No
map readonly = no
browseable = No
browsable = No
delete readonly = Yes
vfs objects = recycle, full_audit
full_audit:priority = INFO
full_audit:failure = unlink rmdir mkdir write rename write aio_write pwrite
full_audit:success = unlink rmdir mkdir write rename write aio_write pwrite
full_audit:prefix = share=%S; id=%U; ip=%I -->
recycle:minsize = 1
recycle:versions = Yes
recycle:directory_mode = 0770
recycle:exclude = *.TMP *.tmp *.AVI *.avi *.mpg *.MPG
recycle:maxsize = 0
recycle:version = Yes
recycle:touch_mtime = Yes
recycle:touch = Yes
recycle:keeptree = Yes
recycle:repository = /var/spool/trash/%S
[trash]
path = /var/spool/trash
admin users = @ARTPAINT\admins
read list = @ARTPAINT\admins
write list = @ARTPAINT\admins
browseable = No
browsable = No
[magazin]
comment = Magazin files
path = /usr/home/public/magazin
read only = No
create mask = 0660
directory mask = 0770
browseable = No
browsable = No
[backup]
comment = Bases
path = /usr/home/public/backup
read only = No
create mask = 0660
directory mask = 0770
browseable = No
browsable = No
[tmp]
comment = Temporary files
path = /tmp
read only = No
create mask = 0644
directory mask = 0744
guest ok = Yes
[printers]
comment = All printers
path = /var/spool/samba34
guest ok = Yes
printable = Yes
browseable = No
browsable = No
[print$]
comment = Printer drivers
path = /usr/local/share/cups/drivers
write list = root
[IPC$]
path = /tmp
hosts allow = 192.168.10.0/24, 192.168.20.0/24, 192.168.0.0/24, 127.0.0.1
hosts deny = 0.0.0.0/0