[OpenAFS] "group prefix doesn't match owner"

Russ Allbery rra@stanford.edu
Mon, 03 May 2010 19:55:03 -0700

Derrick Brashear <shadow@gmail.com> writes:

> If it tracked by name.

> A similar "attack" has been discussed before.

> pts cg shadow:something
> pts chown shadow:something jaltman

> jaltman now owns jaltman:something.

This behavior is also really annoying if you have an external group system
whose names you're trying to synchronize with AFS PTS groups.

