Trying to understand permissions in/out-side of jail

Discussion in 'Plugins' started by paleoN, Apr 23, 2012.

  1. paleoN Active Member

    Member Since:
    Apr 22, 2012
    Message Count:
    1,403
    Likes Received:
    15
    Trophy Points:
    38
    paleoN, Apr 23, 2012

    I'm running 8.2.0-BETA3-x64 with Beta-3 jail pbi & minidlna pbi installed. Thanks to William's post I have minidlna running. I then needed to give dlna user/group permissions on the media directory, mount point, which while obvious took way too long for me to realize.

    Which brings me to this post. I'm trying to understand how permissions should work from outside to inside of the jail. Is it simply going to be a requirement that the jail itself will have read and write access to the entire mount point? Will the mount point need to be world readable & writable? Will the final version of the plugin installs attempt to set some sort of sane permissions, whatever that is, on their media directories?

    The other thing I noticed was UID/GID collisions from inside of the jail to outside. All of a sudden my one user, outside, had access to the files in the media directory once it was fixed for the dlna user inside the jail. Whatever is decided about the mount points UID/GID collisions would be undesirable. I suppose a range of UIDs/GIDs could be reserved only for jail/plugin use, eg 40000 or whatever. Then of course you could have a deliberate UID/GID collision if you want/need such a thing.
  2. ProtoSD Active Member

    Member Since:
    Jul 1, 2011
    Message Count:
    3,359
    Likes Received:
    7
    Trophy Points:
    38
    Location:
    Leaving FreeNAS
  3. paleoN Active Member

    Member Since:
    Apr 22, 2012
    Message Count:
    1,403
    Likes Received:
    15
    Trophy Points:
    38
    paleoN, Apr 25, 2012

    Thanks for the links protosd. I have a much better understanding of the jail itself now. I think I might even read the other sections of chapter 16 later.

    You're right that it didn't answer all of my questions though.;)

    But then I imagine only the developers could do that assuming they have even decided yet.

Share This Page