[OpenAFS-devel] proposal: removing mac prefs pane

Jeffrey Altman jaltman@your-file-system.com
Fri, 30 Jan 2015 04:28:07 -0500


This is a cryptographically signed message in MIME format.

--------------ms070306020408050603030300
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 1/29/2015 10:44 AM, Dave Botsch wrote:
> Hi, Jeff.
>=20
> We can certainly move the pref pane portion over to openafs-info.
>=20
> See below...
>=20
>=20
>> The OSX client has a couple of huge holes in it at the moment:
>>
>> 1. The packaging is no longer current for Xcode that supports
>>    Mavericks or Yosemite.
>>
>=20
> Can you clarify what you mean? As far as I know, the only thing require=
d
> to build is an old packagebuilder script.

While it is possible to build an installer with the old packagebuilder
tool chain doing so comes with compromises.  Notably;

 1. it is not possible to sign the resulting package

 2. it is not possible to do so using the standard development
    toolchain as distributed by Apple which is a maintenance
    issue for development teams.

>> 2. Parts of the pref pane functionality no longer work because
>>    of changes in Mavericks and Yosemite.
>>
>=20
> The preference pane, to my knowledge, has never worked for cross realm
> authentication. So, that also needs to be fixed to call it "working".

Cross-realm acquisition of AFS tokens is not required for the majority
of end-users who are able to obtain AFS tokens from the realm in which
their client principal is issued.

The Windows AFSCreds tool and Network Identity Manager AFS token
provider both support cross-realm token acquisition because a
substantial amount of configuration logic was added to support that use
case.  Doing so was personally important to me at the time.

The lack of cross-realm token acquisition functionality in AFSCommander
is likely to be due to the fact that Claudio had no need to implement it
for his organization and no one raised the subject back in 2009.

It would be great if someone added this functionality to OpenAFS.  An
organization that requires it can either allocate developer staff time
or hire someone.

>> 3. There is no support for Bulk Status RPCs which cause the
>>    OSX client (especially when used through Finder) to be
>>    extremely slow when evaluating directories with large
>>    numbers of entries over high latency links.
>>
>>    This same lack of support for Bulk Status RPCs also triggers
>>    the file server throttling of clients when many of the objects
>>    in the directory are unreadable by the user.
>=20
> Interesting. What would you consider "large numbers" out of curiosity?
> Is there a plan to fix this?

How painful the issue is depends on the round trip time of the link, the
performance of the file server, and whether there are entries in the
directory that trigger throttling.   With no throttling and no delays
within the file server a 100ms RTT and 50 entries would require 5
seconds to fetch the status info.  If the RTT is increased to 250ms that
grows to 12.5 seconds.   100 entries becomes 25 seconds.  If throttling
is triggered, it could take minutes.  Of course the OpenAFS file servers
cannot process a call in 0ms and often experience significant contention
so these numbers are likely to be higher.

The reason that the OSX client does not implement BulkStat support is
because of limitations in OSX KPI.  Daria and I spoke in person with
Apple's file system team 8 or 9 years ago.  For Apple its a trade off of
file system stability from release to release or adding functionality
that most likely only OpenAFS would use.  I understand and appreciate
why they would prefer stability in the KPI

There are potential workarounds but they involve significant complexity
and a redesign of the UNIX cache manager locking model.  Substantial
development resources would be required.  Scope of effort two to four
developer months of an engineer intimately familiar with both the UNIX
cache manager and the Darwin KPI.

>>
>> 4. There is no support for PAGs.
>>
>=20
> Always been that way. PAGs have their plusses and minuses (on our SunRa=
y
> linux systems, I've actually disabled PAGs since certain processes get
> stuck in PAGs without authN).

The lack of PAGs prevents the use of OSX for certain use cases.

>> 5. Code signing for the installer, the userland binaries and
>>    the kernel extension are necessary for improved firewall
>>    access and installation behavior.
>=20
> Yeah, this sucks. It is workable aroundable pretty easily, but not
> something we want the end user to have to do.

Unless someone is extremely knowledgeable about what takes place behind
the scenes it is impossible for the user to do anything but throw their
hands up in the air in frustration.  Even knowledgeable users often bang
their heads against their desk in frustration.

>> Of these, the easiest to address is fixing the Preference Pane.
>>
>=20
> Is there a plan in place to fix this? It'd be nice to have this fully
> working :)

Changes in the behavior of software are the result of one or more
developers writing code, hopefully adding documentation and test suites,
and then having that code be reviewed and accepted by the community.
Developers write code for one of two reasons:

1. They have a personal interest in implementing the functionality.
   For example, an individual that uses OpenAFS on OSX and requires
   cross-realm authentication to work in order to obtain tokens for
   the cell they wish to access.

2. They are paid to do so.  Either as a side effect of their day
   job instructing them to perform the work or as a result of an
   organization hiring them to do so.

There is a significant lack of developers that work on OpenAFS for
personal interest.  The majority of the developers are employed by
commercial support and development organizations.  To obtain their
services their employers must be hired either via a support contract or
on a work for hire development contract.

Is there a plan to fix this?  No, there is a "wish".   You (and perhaps
others) wish that this change in behavior would be implemented.   A plan
requires resources to assign to the task of satisfying the wish. If you
have the necessary resources, you can make the wish come true.

Jeffrey Altman





--------------ms070306020408050603030300
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIINXTCC
BkIwggUqoAMCAQICEDirAC//rpa3Vv85Wvtd5xswDQYJKoZIhvcNAQEFBQAwgcoxCzAJBgNV
BAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVyaVNpZ24gVHJ1
c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5OTkgVmVyaVNpZ24sIEluYy4gLSBGb3IgYXV0
aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8VmVyaVNpZ24gQ2xhc3MgMSBQdWJsaWMgUHJp
bWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEczMB4XDTExMDkwMTAwMDAwMFoXDTIx
MDgzMTIzNTk1OVowgaYxCzAJBgNVBAYTAlVTMR0wGwYDVQQKExRTeW1hbnRlYyBDb3Jwb3Jh
dGlvbjEfMB0GA1UECxMWU3ltYW50ZWMgVHJ1c3QgTmV0d29yazEeMBwGA1UECxMVUGVyc29u
YSBOb3QgVmFsaWRhdGVkMTcwNQYDVQQDEy5TeW1hbnRlYyBDbGFzcyAxIEluZGl2aWR1YWwg
U3Vic2NyaWJlciBDQSAtIEc0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxuwn
/R1j9DsdisHTHMjIgoa2uEqGkqqBXHLKMA0vnkEiVzAhJZCao/SsKsaIF4ZhchN2LuwDyyeb
jyCAN+DkitpVplAP/LlcI2mJQqG6H6/vDvmkyQrx+DeyxtmSSq5937hEH5u6P4wG/tgjT0hR
I2pghKjuJy9g35byGiqMPI8AzE/L+iCOvDX24fCatgXz/B0/xhR7DtryBeTTgwKmxWlwtKnk
VunbHVz0pjbia7UeKi3cvrvuOgSwMAitX2hsxr0GloiE5+apZC28ODC7iCbDZ2ZmtLR3+cCh
xw5y72bi5bnK4POFdzWY3tQcsP5mceI4y258T0BV65fZqBge7QIDAQABo4ICRDCCAkAwOAYI
KwYBBQUHAQEELDAqMCgGCCsGAQUFBzABhhxodHRwOi8vcGtpLW9jc3AudmVyaXNpZ24uY29t
MBIGA1UdEwEB/wQIMAYBAf8CAQAwbAYDVR0gBGUwYzBhBgtghkgBhvhFAQcXATBSMCYGCCsG
AQUFBwIBFhpodHRwOi8vd3d3LnN5bWF1dGguY29tL2NwczAoBggrBgEFBQcCAjAcGhpodHRw
Oi8vd3d3LnN5bWF1dGguY29tL3JwYTA0BgNVHR8ELTArMCmgJ6AlhiNodHRwOi8vY3JsLnZl
cmlzaWduLmNvbS9wY2ExLWczLmNybDAOBgNVHQ8BAf8EBAMCAQYwKQYDVR0RBCIwIKQeMBwx
GjAYBgNVBAMTEVZlcmlTaWduTVBLSS0yLTk3MB0GA1UdDgQWBBSt+cOTci21uShh5KTXYNXE
Cl4aATCB8QYDVR0jBIHpMIHmoYHQpIHNMIHKMQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVy
aVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsT
MShjKSAxOTk5IFZlcmlTaWduLCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBD
BgNVBAMTPFZlcmlTaWduIENsYXNzIDEgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBB
dXRob3JpdHkgLSBHM4IRAItbdVaEVIULAM+vOEjOsaQwDQYJKoZIhvcNAQEFBQADggEBANaP
wdqbiPKzbE0fWC+6AVFddMFG6MO4e5/WQPHv/zK6iWvADjRDn6SZ5qTwXUgzYoWFYf4jiCKM
YJsrnGVJlMSiOCRIpVylUEto6WIip5PomSJuPVu7EEIOH0x1RzRWCY/4vYw881y70pZwVHBi
Te/REL6dSCxe7IZrB4LwPeElJygs4BZ2HrP95WKW0oo9Xyuu+1zCE7dlY8s0dkOf1oeZq26t
lcEAP0Yngf813iMOQ9wUXzL5yinvwlIw9ZnduYH4OiUgjYJo8rkhhXRmBOGGORYy8i3WKqjJ
3tkAAk/jGCDFpYFWtpXe04Kt+HslvmR8LqC6cCz4+XXidE0HbYQwggcTMIIF+6ADAgECAhAW
xDBJuKAcJVa7b+TJhwvEMA0GCSqGSIb3DQEBBQUAMIGmMQswCQYDVQQGEwJVUzEdMBsGA1UE
ChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAdBgNVBAsTFlN5bWFudGVjIFRydXN0IE5ldHdv
cmsxHjAcBgNVBAsTFVBlcnNvbmEgTm90IFZhbGlkYXRlZDE3MDUGA1UEAxMuU3ltYW50ZWMg
Q2xhc3MgMSBJbmRpdmlkdWFsIFN1YnNjcmliZXIgQ0EgLSBHNDAeFw0xNDEyMTgwMDAwMDBa
Fw0xNTEyMTkyMzU5NTlaMIHOMS4wLAYDVQQDDCVQZXJzb25hIE5vdCBWYWxpZGF0ZWQgLSAx
NDE4ODgyMzg2MTAyMSswKQYJKoZIhvcNAQkBFhxqYWx0bWFuQHlvdXItZmlsZS1zeXN0ZW0u
Y29tMQ8wDQYDVQQLDAZTL01JTUUxHjAcBgNVBAsMFVBlcnNvbmEgTm90IFZhbGlkYXRlZDEf
MB0GA1UECwwWU3ltYW50ZWMgVHJ1c3QgTmV0d29yazEdMBsGA1UECgwUU3ltYW50ZWMgQ29y
cG9yYXRpb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCteTFLbuPm2vx85lH2
Y6LHdMIqcKQPN9m4XYVTe0L8ZvMvnJ1YQ720ET52CF18RYdTc4to92+ffdmjWlBedK4YtLam
htsUkJ6WL3krwNVTYfeej0wgF9kVQ2FI8XTNngxnJ2CRkQX4Z9/1TI4wTkSNcAw5T0Y2HKM9
4p7wAJOefl+3oPwxXn338w8T7LsfwS9FOADZ8uRItv/J7S8BJEP0XtjZZlBoSyqQ4qxl5PtI
uybHVdwoo2PlK8LxU6r8Vcje1+OXmc5VoCBlXiYDWHl/wSDtZEWR6431/az1Z45n1AHHber2
G+Ijb0nF4RLiiFMkyJl3qx+46wqcqWrjrRxDAgMBAAGjggMRMIIDDTAMBgNVHRMBAf8EAjAA
MA4GA1UdDwEB/wQEAwIFoDAgBgNVHSUBAf8EFjAUBggrBgEFBQcDBAYIKwYBBQUHAwIwHQYD
VR0OBBYEFBUlv/9jizZz4uwaFtPzwdX6FsqwMCcGA1UdEQQgMB6BHGphbHRtYW5AeW91ci1m
aWxlLXN5c3RlbS5jb20wHwYDVR0jBBgwFoAUrfnDk3IttbkoYeSk12DVxApeGgEwggErBggr
BgEFBQcBAQSCAR0wggEZMIIBFQYIKwYBBQUHMAKGggEHbGRhcDovL2RpcmVjdG9yeS52ZXJp
c2lnbi5jb20vQ04lMjAlM0QlMjBTeW1hbnRlYyUyMENsYXNzJTIwMSUyMEluZGl2aWR1YWwl
MjBTdWJzY3JpYmVyJTIwQ0ElMjAtJTIwRzQlMkMlMjBPVSUyMCUzRCUyMFBlcnNvbmElMjBO
b3QlMjBWYWxpZGF0ZWQlMkMlMjBPVSUyMCUzRCUyMFN5bWFudGVjJTIwVHJ1c3QlMjBOZXR3
b3JrJTJDJTIwTyUyMCUzRCUyMFN5bWFudGVjJTIwQ29ycG9yYXRpb24lMkMlMjBDJTIwJTNE
JTIwVVM/Y0FDZXJ0aWZpY2F0ZTtiaW5hcnkwXQYDVR0fBFYwVDBSoFCgToZMaHR0cDovL3Br
aS1jcmwuc3ltYXV0aC5jb20vY2FfNTYxYzEwMzY5MGM5N2E2OTI0N2EwZWYwNzFhYzgxYWYv
TGF0ZXN0Q1JMLmNybDBsBgNVHSAEZTBjMGEGC2CGSAGG+EUBBxcBMFIwJgYIKwYBBQUHAgEW
Gmh0dHA6Ly93d3cuc3ltYXV0aC5jb20vY3BzMCgGCCsGAQUFBwICMBwaGmh0dHA6Ly93d3cu
c3ltYXV0aC5jb20vcnBhMCsGCmCGSAGG+EUBEAMEHTAbBhJghkgBhvhFARABAgIEAYbHzm8W
BTEwOTIyMDkGCmCGSAGG+EUBEAUEKzApAgEAFiRhSFIwY0hNNkx5OXdhMmt0Y21FdWMzbHRZ
WFYwYUM1amIyMD0wDQYJKoZIhvcNAQEFBQADggEBAJIvoMatM56/QjaVAlEUbeWZNOPkwuiC
gaaekWJi1h33fAVfdF+WZqh7dF4hBNalyPuxRcyZX7HxuPyBc3ajDCqew9MlmCJ3Cm4Co3fZ
Yh50OX4jnem2RmpHeKbJW6zUjZcAGqV6DPMl04kgrI2whJX7729HoRyUPwZS7CZSRFZO147X
2+/JogDYKffa/+q5AwgrHYvdECHxc3Iz9KnHSmit+DhWS9t+XxE0gHr3sW7zwcQ/GYyrJ3s3
VdWHTjM+3iGFeTOI06h1aBgFR/+8fTmuZXZz9+OdWVar0Crt9bn0cFN3u00Q6YAyjYhRnbXy
zYVIOS4oJmRoK79p/xodeDUxggRSMIIETgIBATCBuzCBpjELMAkGA1UEBhMCVVMxHTAbBgNV
BAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3
b3JrMR4wHAYDVQQLExVQZXJzb25hIE5vdCBWYWxpZGF0ZWQxNzA1BgNVBAMTLlN5bWFudGVj
IENsYXNzIDEgSW5kaXZpZHVhbCBTdWJzY3JpYmVyIENBIC0gRzQCEBbEMEm4oBwlVrtv5MmH
C8QwCQYFKw4DAhoFAKCCAmswGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0B
CQUxDxcNMTUwMTMwMDkyODA3WjAjBgkqhkiG9w0BCQQxFgQUXjJpwGy29r3HF+AOmbrmX4F+
IfowbAYJKoZIhvcNAQkPMV8wXTALBglghkgBZQMEASowCwYJYIZIAWUDBAECMAoGCCqGSIb3
DQMHMA4GCCqGSIb3DQMCAgIAgDANBggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG9w0D
AgIBKDCBzAYJKwYBBAGCNxAEMYG+MIG7MIGmMQswCQYDVQQGEwJVUzEdMBsGA1UEChMUU3lt
YW50ZWMgQ29ycG9yYXRpb24xHzAdBgNVBAsTFlN5bWFudGVjIFRydXN0IE5ldHdvcmsxHjAc
BgNVBAsTFVBlcnNvbmEgTm90IFZhbGlkYXRlZDE3MDUGA1UEAxMuU3ltYW50ZWMgQ2xhc3Mg
MSBJbmRpdmlkdWFsIFN1YnNjcmliZXIgQ0EgLSBHNAIQFsQwSbigHCVWu2/kyYcLxDCBzgYL
KoZIhvcNAQkQAgsxgb6ggbswgaYxCzAJBgNVBAYTAlVTMR0wGwYDVQQKExRTeW1hbnRlYyBD
b3Jwb3JhdGlvbjEfMB0GA1UECxMWU3ltYW50ZWMgVHJ1c3QgTmV0d29yazEeMBwGA1UECxMV
UGVyc29uYSBOb3QgVmFsaWRhdGVkMTcwNQYDVQQDEy5TeW1hbnRlYyBDbGFzcyAxIEluZGl2
aWR1YWwgU3Vic2NyaWJlciBDQSAtIEc0AhAWxDBJuKAcJVa7b+TJhwvEMA0GCSqGSIb3DQEB
AQUABIIBABDhARj1c9TGucW66V6/Fx4qyYqq2YLyu+pFTKsuj/HGrLXSWbLhW+iBHjoMucqK
AcQwyQUi+KR6z4rtCxBL+PEg35QnJjcRSYIRV93BpEvyasGYsU+bEjlfEbILr0ZW1TEwj8wq
7VDZ7kFqs6eQS0hxTgrxO+Vpk7cgDF3Oi5b2ikivoEuNwWLW3UyWATEjG1Ri37GbOdgsnfE9
Fbuix941oGP2Py3t8cbk9RUvFBsH3Bzkp5UIcfdfNgvycUdXqOLxRw+g8QGGQi1DggV687DF
JVpximgYA7hDrxK7XpMuT0O6S7oLmVCxQnsjeViO/sLjxY8FJEYPLdokxwcwJBkAAAAAAAA=
--------------ms070306020408050603030300--