Nested groups is broken in the latest updates.

Bug #1852955 reported by Brian Ryder
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
samba (Ubuntu)
Invalid
High
Unassigned

Bug Description

Nested groups aren't allowed access to files when given permissions to files in an Active Directory joined samba member server.

I had to switch to Windows Server because of this and move all my users to it.

getent group also doesn't return ad groups that are members of the group.

Revision history for this message
Brian Ryder (bryanryder) wrote :

This happened after the latest samba/winbind updates with Ubuntu 18.04.

Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for your bug report.

When you write latest updates, you mean https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.13 ?

Could you give some specifics on your configuration and the error you are getting?

Also you are free to switch OS and migrate your users, that's not reality relevant information for a bug report, if it's true it also seems high cost to do rather than blocking the buggy update and reporting the issue/getting it resolved.

Changed in samba (Ubuntu):
importance: Undecided → High
status: New → Incomplete
Revision history for this message
Brian Ryder (bryanryder) wrote :

It is relevant to a bug report as those creating the patches need to understand the full impact of what they do and what happens when they don't properly unit test whether I'm a jerk or not.

I've given you enough details. Unit testing on nested groups should easily reveal the problem. Put users in a group. Put a group in a group. Give the outside group permissions to a share and ntfs permissions--bam failure. Simple. Just as I described. https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.13

Yes, this one.

Revision history for this message
Brian Ryder (bryanryder) wrote :

Also, since I've moved on, I'm only telling you guys this as a kindness to the community and future potential users. I don't give a shit any more as samba and/or the package maintainers for debian/ubuntu isn't stable enough to be relied upon in production.

Also, this bug reporting tool is shit and not up to modern standards.

Revision history for this message
Brian Ryder (bryanryder) wrote :

My fault. I'm a complete ass. It's working. Someone had removed all the users from the inside group.

Once again, egg on my face. I'm a complete ass. Laugh at the ass and disregard.

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Thanks for getting back to us about this.

Changed in samba (Ubuntu):
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.