I mentioned this at the workshop and spent a little bit getting it closer to being done... anyway, here it is for everyone's reading (dis)pleasure. It's something of a "come walk with me through the viced source" document, but perhaps informative nevertheless (I know it was to me!). It's certainly more than a little rough around the edges, but I'd enjoy feedback: http://hydra.ietfng.org/nwf/misc/afs-permissions.html
Looking forward, I would like to push a patch to gerrit that enables setting GIDs by ordinary clients (who could otherwise mutate the file); I hope this document helps make the case that there is no harm in so doing. Cheers, --nwf;
pgpPrKRwgsCFg.pgp
Description: PGP signature
