← NAS: shares, permissions, and operations
10 / 12 · 70 MIN

Samba: modes, operations and delivery

Interpret observed creation modes and separately validate modification, rename and reading by the consumer.

Predict the mode and compare with stat

In the controlled exercise, creation produces a file in mode 0660 with recorded UID and GID. The configuration uses create mask 0640 and force create mode 0020. For the initial 0666 value stated in the question, first calculate the bitwise intersection with 0640 and then add 0020: the result is 0660. That calculation predicts an outcome under those assumptions; execution evidence confirms the mode this request actually produced. In a fictional change, retain both and investigate discrepancies. Do not claim every client requests the same bits or that changing a mask retroactively modified existing objects. The previous inventory remains necessary to decide how to handle files already present.

Distinguish directories from files

The same exercise creates a directory with mode 02770. Record directory mask 0750 and force directory mode 0020 separately, together with the parent directory setgid context. Comparing only the last three digits would lose relevant information. The workshop asks the learner to explain why the file outcome is insufficient to predict the directory outcome, separating access bits, ownership and inheritance. In a fictional collection service, each batch folder may have different requirements from the delivered files. Define those requirements with producer and consumer owners. Acceptance should observe newly created objects of both kinds without assuming equivalence with Windows ACLs or another NAS server implementation.

Test modification and rename separately

The script explicitly changes the file to 0440 and attempts to overwrite it through the SMB client. That attempt is denied. Next, rename succeeds in the writable directory: the old name disappears and the new name retains the content hash. This observed contrast supports a discussion of operations on content and names under this environment’s concrete controls. It does not mean any read-only file can always be renamed on any NAS. It also does not measure crashes, concurrent writers or enterprise ACLs. In the troubleshooting exercise, ask the learner for one hypothesis per operation and the supporting evidence. A generic statement such as no permissions would not adequately explain both outcomes.

Deliver to the consumer and close the scope

The second identity reads the renamed file and obtains the same nineteen bytes and content hash. This adds evidence that producer success alone did not supply. There is still no business application interpreting those bytes. In a fictional RUN handover, complete the matrix with authorized real identities, expected functional outcome, denial criteria, owner and reconciliation procedure. Keep secrets out of the report. The client was invoked with SMB3 as its permitted maximum; the exercise did not record the negotiated dialect or establish encryption. The correct conclusion identifies observed operations, resource cleanup and required additional tests, including enterprise identity, ACLs, recovery and acceptance by a representative consumer.

# Read the recorded observations without rerunning any service.
python3 - <<'PY'
import json
from pathlib import Path
r=json.loads(Path("content/labs/nas-samba/evidence.json").read_text)
for name in ["fileMaskThenForce", "directoryMasksSeparate",
 "readableNotOverwritable", "renameUsesDirectoryRights",
 "secondIdentityReadsResult"]:
 print(name, r["checks"][name])
PY
IN PRACTICE

The producer creates a file in 0660. After a controlled change to 0440, its content cannot be overwritten, but the observed rename remains possible.

Common pitfalls

Treating create mask as the final result, applying file rules to directories or declaring delivery complete before testing the consumer identity.

Related topics: Application acceptance and migration · Unix modes and file coordination

Take this idea with you

Observe each operation with the correct identity and do not turn a lab result into a guarantee of durability or enterprise migration.

Create account

Reference: Samba share access and creation permissions · BigSavant NAS 2026-09; selected Linux NFS, Samba, Windows SMB and ONTAP behavior