16 Groups limitation work around?

172 views
Skip to first unread message

lost in the woods

unread,
Aug 27, 2008, 7:24:27 AM8/27/08
to ClearCase
Hello,

I am new to clearcase and I have encountered this 16 group limitation.
We have Clearcase installed in UINX-AIX environment and access vobs
ethier via telnet of Local Clearcase via windows.

I am aware of the discussions about the limitations and that really
there is no work around for this issue..

However, I was thinking if this is a possible solution:

1. Add all Vobs to 1 group (All users have write access to the group)
2. Control user access to vobs via the dynamic user_view

Is it possible to pass a list of vobs to be viewed by a dynamic
user_view.. I.e, could I force the user_view to read a file that
contains lists all the vobs based on userID? Thus, A user would be
assigned to a group giving them access to 200 vobs but the access
control list read by the user_view would limit them to read only 20 of
the vobs that they have access too.

Is this possible?
I would like to to this outside of the confiq spec:
so that the user couldn't remove the rule..
and that we don't have to lock the config spec..as users would still
need to edit the config spec so that label and version rules could be
applied to vobs that they are allowed access from the list..

Also would I be able to apply the list of vobs to other view that I
accessed without effecting the user_view of a second user as they may
have different vob requirements to me..

Is this possible or just pie in the sky?

Anand Mehta

unread,
Aug 27, 2008, 1:06:30 PM8/27/08
to Clea...@googlegroups.com
hey,
I do remember this coming up sometime back...

there is a clearcase variable ... for this....for sure.
i'll dig up some last posts and let you know.

-Anand.

Marc Girod

unread,
Aug 27, 2008, 4:41:53 PM8/27/08
to ClearCase
On Aug 27, 6:06 pm, "Anand Mehta" <anmev.me...@gmail.com> wrote:

> there is a clearcase variable ... for this....for sure.
> i'll dig up some last posts and let you know.

You probably mean CLEARCASE_GROUPS,
but this was for 32 groups, and otherwise,
I am not sure it is the same problem.

What exact limitation is this about?

The above variable is for one user belonging to more
than 32 groups, and to picks the ones that may be
useful for ClearCase.

I don't know whether there is a limitation to the
number of groups declared to a vob.
Of course, it is unlikely that the Avogadro number
would be possible...

Marc

Kinni

unread,
Sep 6, 2008, 3:31:57 AM9/6/08
to ClearCase
Windows
This variable is used to counteract a limitation to the MVFS whereby
any user who is a member of more than 32 Microsoft Windows groups
(domain or local) can run into access problems.
Users should set CLEARCASE_GROUPS as a Windows User variable in order
to specify which subset of those groups Rational ClearCase should
consider when checking the user's access rights.

UNIX and Linux
The CLEARCASE_GROUPS variable was introduced to UNIX and Linux as of
ClearCase 7.0 and is used ONLY as part of a larger work around to help
alleviate the problem related to the 16 group limitation issue. the
work around which involves a new utility called setgroup-swap.

Also check this...

http://www-01.ibm.com/support/docview.wss?rs=984&uid=swg21207807

Cheers!
K

vr san

unread,
Sep 6, 2008, 5:10:11 AM9/6/08
to Clea...@googlegroups.com

Hi

I am not very sure of your requirement, by this single email, could you explain in detail,


 but when it comes to views and isolating users using views ,one more way to control is

you can isolate views based on storage location and having different storage locations for different Unix groups, for ex: Unix group1 - stgloc: viewgroup1

also within a view, you can change the permission of configspec alone. if you have to just the change the permissions or rights on a configspec of a view and not other aspects, you can change the config_spec files permissions within the .vws directory

Regards
Raghu
Reply all
Reply to author
Forward
0 new messages