Hey guys, pardon me if I seem new at this. I'm just learning about the concept of extended attributes. I'm trying to get support on a critical issue we're having on one of our Teamsite installations here.
The situation is that the teamsite user cannot write to a directory where it has umask permissions (see fig. 1 and fig. 2). Besides a user's umask, there are 2 other mechanisms that ZFS (Solaris' file system) uses to control access to files - Extended Attributes and Access Control Lists. I think ACLs are not the issue because the ACE on the directory in question allows full access to everyong (see fig. 3). Now, I can't find tools for getting/setting extended attributes on our Solaris boxes. I tried 'fsattr', but that's not in my path. Is that the tool one should use? Is it in root's path?
Also, is there a kind of umask or default set for extended attributes each time a file gets created. Where do extended attributes reside on the file system?
Through the teamsite UI, I was able to i) set my WORKAREA Sharing to 'Group' and ii) set permission overrides for a given role. But for these changes to take effect, you may have to restart Teamsite (I'm not sure). We should be able to control default extended attributes through the UI. Thanks a lot for any help.
2008/04/07 10:27:17 DEBUG> generate_page_portfolio.cgi:66 main:: - Generate command: [/app/iw-home/bin/iwgen -t "/iwmnt/
default/main/portfolio/WORKAREA/twashing/templatedata/common/article/presentation/XML.tpl" -r "/iwmnt/default/main/portf
olio/WORKAREA/twashing/templatedata/common/article/data/business-travel/features/2008/02/02/testarticletim" "/default/ma
in/portfolio/WORKAREA/twashing/contentxml/business-travel/features/2008/02/02/testarticletim.xml"], result [/default/mai
n/portfolio/WORKAREA/twashing/contentxml/business-travel/features/2008/02/02/testarticletim.xml: could not create]
fig. 1 (executed by teamsite with error)
twashing@sptfdelj07:02> pwd
/default/main/portfolio/WORKAREA/twashing/contentxml/business-travel/features/2008/02/02
twashing@sptfdelj07:02> /app/iw-home/bin/iwgen -t "/iwmnt/default/main/portfolio/WORKAREA/twashing/templatedata/common/article/presentation/XML.tpl" -r "/iwmnt/default/main/portfolio/WORKAREA/twashing/templatedata/common/article/data/business-travel/features/2008/02/02/testarticletim" "/default/main/portfolio/WORKAREA/twashing/contentxml/business-travel/features/2008/02/02/testarticletim.xml"
twashing@sptfdelj07:02> ls -la
drwxrwxrwx 2 twashing amgdev 512 Apr 7 11:21 ./
drwxrwxr-x 8 twashing amgdev 512 Mar 31 14:02 ../
-rw-rw-r-- 1 twashing amgdev 2691 Mar 27 16:23 testarticledcr.xml
-rw-rw-r-- 1 twashing amgdev 2699 Mar 27 16:27 testarticledcrzzz.xml
-rw-rw-r-- 1 twashing amgdev 2608 Apr 7 11:21 testarticletim.xml
twashing@sptfdelj07:02>
fig. 2 (exact same command as in fig. 1, executed by twashing with no error)
twashing@sptfdelj07:~> getfacl /default/main/portfolio/WORKAREA/twashing/contentxml/business-travel/features/2008/02/02/
# file: /default/main/portfolio/WORKAREA/twashing/contentxml/business-travel/features/2008/02/02/
# owner: twashing
# group: amgdev
user::rwx
group::rwx #effective:rwx
mask:rwx
other:rwx
fig. 3 (ace provides full access to all people)
Tim Washington
Java Analyst; Portfolio.com; Conde Nast
twashing@condenast.com212.286.2989