<!-- 
RSS generated by JIRA (8.3.4#803005-sha1:1f96e09b3c60279a408a2ae47be3c745f571388b) at Sat Feb 10 16:25:41 JST 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>PFS-JIRA</title>
    <link>https://pfspipe.ipmu.jp/jira</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.3.4</version>
        <build-number>803005</build-number>
        <build-date>13-09-2019</build-date>
    </build-info>


<item>
            <title>[INSTRM-503] Add per-user groups</title>
                <link>https://pfspipe.ipmu.jp/jira/browse/INSTRM-503</link>
                <project id="10300" key="INSTRM">Instrument control development</project>
                    <description>&lt;p&gt;The security model for PFS is a common one:&lt;/p&gt;
&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;All development and installation work is done by individual user accounts&lt;/li&gt;
	&lt;li&gt;All user accounts are also in a common group (&lt;tt&gt;pfs&lt;/tt&gt;)&lt;/li&gt;
	&lt;li&gt;All work is saved in a shared directory (&lt;tt&gt;/software&lt;/tt&gt;)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;A time-tested way to make that work smoothly is:&lt;/p&gt;
&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;Each user has a primary per-user group id.&lt;/li&gt;
	&lt;li&gt;All users are additionally in group &lt;tt&gt;pfs&lt;/tt&gt;&lt;/li&gt;
	&lt;li&gt;Each user&apos;s $HOME has that group id, and is 0755, so that ssh works safely.&lt;/li&gt;
	&lt;li&gt;All shared directories (&lt;tt&gt;/software&lt;/tt&gt; and under) are group &lt;tt&gt;pfs&lt;/tt&gt; and &lt;tt&gt;g+srwx&lt;/tt&gt;.&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;I notice that the LDAP accounts do not have per-user primary groups. Can they be added?&lt;/p&gt;</description>
                <environment></environment>
        <key id="12903">INSTRM-503</key>
            <summary>Add per-user groups</summary>
                <type id="3" iconUrl="https://pfspipe.ipmu.jp/jira/secure/viewavatar?size=xsmall&amp;avatarId=10518&amp;avatarType=issuetype">Task</type>
                                            <priority id="10000" iconUrl="https://pfspipe.ipmu.jp/jira/images/icons/priorities/medium.svg">Normal</priority>
                        <status id="1" iconUrl="https://pfspipe.ipmu.jp/jira/images/icons/statuses/open.png" description="The issue is open and ready for the assignee to start work on it.">Open</status>
                    <statusCategory id="2" key="new" colorName="blue-gray"/>
                                    <resolution id="-1">Unresolved</resolution>
                                        <assignee username="kiaina">Kiaina Schubert</assignee>
                                    <reporter username="cloomis">cloomis</reporter>
                        <labels>
                            <label>subaru-personnel</label>
                    </labels>
                <created>Tue, 2 Oct 2018 16:56:43 +0000</created>
                <updated>Thu, 7 Nov 2019 01:20:36 +0000</updated>
                                                                                <due></due>
                            <votes>0</votes>
                                    <watches>1</watches>
                                                                <comments>
                            <comment id="14700" author="cloomis" created="Mon, 3 Dec 2018 13:19:49 +0000"  >&lt;p&gt;Bump. Is this possible?&lt;/p&gt;

&lt;p&gt;I&apos;ll add the main appeal:&lt;/p&gt;
&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;content written to the pfs group directories (&lt;tt&gt;/software/products&lt;/tt&gt;, etc) are &lt;em&gt;writable&lt;/em&gt; by all in the project, but&lt;/li&gt;
	&lt;li&gt;content written to non-fps group directories (&lt;tt&gt;/home/&lt;/tt&gt;, etc) are by default &lt;em&gt;readable&lt;/em&gt; but not &lt;em&gt;writable&lt;/em&gt; by all in the project.&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;If you do not have per-user primary groups it is difficult and error-prone to avoid making non-shared files group/world writable.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                <customfield id="customfield_10500" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                            <customfield id="customfield_10010" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|s00168:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>