Hallo Andreas,
> On Wed, 2008-06-11 at 14:40 +0400, Andrey Kiryanov wrote:
> > > does anybody know why a pool account determined by lcmaps looks
> > > differently than locally configured on a CE (gLite 3.1-24)?
> > >
> > > [oreade38] ~ % globus-job-run brutus-vm1.ifh.de /usr/bin/id
> > > uid=34328(datlas28) gid=44100(datlas) groups=44100(datlas)
> > >
> > > [root@brutus-vm1 ~]# id datlas28
> > > uid=34328(datlas28) gid=44100(datlas) groups=44100(datlas),45000(atlas)
> > >
> > > Why is the atlas group membership missing when I run a script via the
> > > gatekeeper? Any hints?
> >
> > Do you have globus-*-marshal packages installed on your CE?
>
> yes.
>
> > If yes, it's just a side effect for the fork jobs - they run with only primary group
> > applied.
>
> OK. Just wanted to ask as it affects how I have to configure queue
> access to torque. So lcgpbs jobmanager will run with the correct group
> ids (well, I could just try...)?
With the marshal packages only the primary group ID is set on the CE;
we think this should not cause problems, since normally it is only
the primary GID that is decisive for submission to the batch system.
On the WN the job will have all the group IDs it may need, taken from
/etc/group. If this does not work for you, please consider adapting
your configuration before opening a bug.
|