This discussion is locked
Lenny8Ball

Q: Permissions on a shared XSAN

Hi there,

I'm actually not sure if this is a real XSAN problem or a general MacOSX issue (resp. in any case it's a user problem).
I have four editing suites running Snow Leopard and a XSAN system set up. The users for the workstations are network users, defined by an additional server. When I create a new folder from one of these workstations on the XSAN (or anywhere else on the computer) it has 755 (write/read/read) permissions by default. But I also want other users to have write access within this folder.
Is there a way to define the default permissions or to give specific permissions to a folder and all (later created!) sub-folders?

Thanks a lot for your help!

Best regards,
Lenny

Posted on Mar 22, 2010 11:25 AM

Close

Q: Permissions on a shared XSAN

  • All replies
  • Helpful answers

  • by Strontium90,

    Strontium90 Strontium90 Mar 22, 2010 5:22 PM in response to Lenny8Ball
    Level 5 (4,087 points)
    Servers Enterprise
    Mar 22, 2010 5:22 PM in response to Lenny8Ball
    Yes. There are two methods to accomplish. The preferred method is to use ACLs. However, be aware that not all of your applications may be able to respect ACLs. The number of apps that can't figure out ACLs is dropping but there are still a few that screw it up. The second option is to change the default umask. This is a bit more of a brutal surgery and Apple has a Kbase article on doing it. Be careful though, as the change impacts the entire operating system, not just the volume or a folder. Look at Server Admin and use the Sharing tab to set ACLs.

    Hope this helps
  • by Lenny8Ball,

    Lenny8Ball Lenny8Ball Mar 23, 2010 8:04 AM in response to Strontium90
    Level 1 (0 points)
    Mar 23, 2010 8:04 AM in response to Strontium90
    Thanks a lot for your help!
    You're right, ACL's seem to be the more elaborated methode here.
    But do you know if Final Cut Pro is respecting the ACL's? Cause afaik they are set correctly for the XSAN (I will have a look at his again).
    But when I create a project on one editing workstation and capture material, FCP creates a new folder on the XSAN and this folder has no write permissions for the other workstations (same is true for rendering folders).

    Best regards,
    Lenny
  • by Strontium90,

    Strontium90 Strontium90 Mar 23, 2010 5:30 PM in response to Lenny8Ball
    Level 5 (4,087 points)
    Servers Enterprise
    Mar 23, 2010 5:30 PM in response to Lenny8Ball
    Yes. I've had some issues with certain versions of FCP. The best strategy is to save the project locally and then use the Finder to get it on the SAN. This seems to work well because the ACL is written when the Finder writes the file. Once this is done, FCP seems to respect and maintain the ACL on subsequent saves. But the initial save does not allow creation of ACLs.

    Hope this helps
  • by Lenny8Ball,

    Lenny8Ball Lenny8Ball Apr 8, 2010 1:47 AM in response to Strontium90
    Level 1 (0 points)
    Apr 8, 2010 1:47 AM in response to Strontium90
    Hi again,
    sorry for the long time, I didn't find the time to answer.
    My problem is not getting the FCP project on the XSAN. This is done fine FCSrv and works just fine.
    But my cpature scratch and my render files are set to a folder on the XSAN. And these are really problematic, because it seems that FCP sets the permissions (POSIX?) to 755 (or rwxr-xr-x) for every new folder it creates, e.g. for the render files, while group is 'wheel'.
    So it's not possible to render or capture into the same project from another machine. There is a group called 'post' and I thought that it would be set as write permitted group on the XSAN via ACL. But when I create a new folder on the XSAN from within the Finder, I also do not have write permissions on other workstations (also 755 with group "wheel").
    So I think here's the problem and the ACL in the XSAN admin is not set correctly, no matter what FCP does anyway. Or what do you think? Any other suggestions before I bother the system administrator?

    Thanks a lot for your help!
  • by Strontium90,

    Strontium90 Strontium90 Apr 15, 2010 5:19 PM in response to Lenny8Ball
    Level 5 (4,087 points)
    Servers Enterprise
    Apr 15, 2010 5:19 PM in response to Lenny8Ball
    Can not be done. Been asking Apple for this for years...

    http://support.apple.com/kb/TA23014