Print this page
NEX-9808 SMB3 persistent handles
Reviewed by: Matt Barden <matt.barden@nexenta.com>
Reviewed by: Evan Layton <evan.layton@nexenta.com>
NEX-9808 SMB3 persistent handles
Reviewed by: Matt Barden <matt.barden@nexenta.com>
Reviewed by: Evan Layton <evan.layton@nexenta.com>
NEX-15425 rework share man pages
Reviewed by: Roman Strashkin <roman.strashkin@nexenta.com>
Reviewed by: Matt Barden <matt.barden@nexenta.com>
Reviewed by: Evan Layton <evan.layton@nexenta.com>
NEX-15425 rework share man pages
Reviewed by: Roman Strashkin <roman.strashkin@nexenta.com>
Reviewed by: Matt Barden <matt.barden@nexenta.com>
Reviewed by: Evan Layton <evan.layton@nexenta.com>
NEX-5273 SMB 3 Encryption
Reviewed by: Gordon Ross <gordon.ross@nexenta.com>
Reviewed by: Evan Layton <evan.layton@nexenta.com>
Reviewed by: Roman Strashkin <roman.strashkin@nexenta.com>

Split Close
Expand all
Collapse all
          --- old/usr/src/man/man1m/sharemgr.1m
          +++ new/usr/src/man/man1m/sharemgr.1m
   1    1  '\" te
   2    2  .\" Copyright (c) 2008, Sun Microsystems, Inc. All Rights Reserved
        3 +.\" Copyright 2017 Nexenta Systems, Inc.  All rights reserved.
   3    4  .\" The contents of this file are subject to the terms of the Common Development and Distribution License (the "License").  You may not use this file except in compliance with the License. You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE or http://www.opensolaris.org/os/licensing.
   4    5  .\"  See the License for the specific language governing permissions and limitations under the License. When distributing Covered Code, include this CDDL HEADER in each file and include the License file at usr/src/OPENSOLARIS.LICENSE.  If applicable, add the following below this CDDL HEADER, with
   5    6  .\" the fields enclosed by brackets "[]" replaced with your own identifying information: Portions Copyright [yyyy] [name of copyright owner]
   6      -.TH SHAREMGR 1M "Feb 25, 2017"
        7 +.TH SHAREMGR 1M "Sep 5, 2017"
   7    8  .SH NAME
   8    9  sharemgr \- configure and manage file sharing
   9   10  .SH SYNOPSIS
  10   11  .LP
  11   12  .nf
  12   13  \fBsharemgr\fR \fIsubcommand\fR [\fIoptions\fR]
  13   14  .fi
  14   15  
  15   16  .LP
  16   17  .nf
↓ open down ↓ 603 lines elided ↑ open up ↑
 620  621  \fIsharepath\fR\fR\fR
 621  622  .ad
 622  623  .sp .6
 623  624  .RS 4n
 624  625  Unshares the specified share. This subcommand implements the \fBunshare\fR(1M)
 625  626  functionality. By default, the \fBunshare\fR is temporary. The \fB-p\fR option
 626  627  is provided to remove the share from the configuration in a way that persists
 627  628  across reboots.
 628  629  .RE
 629  630  
 630      -.SS "Supported Properties"
 631      -.LP
 632      -Properties are protocol-specific. Currently, only the NFS and SMB protocols are
 633      -supported. Properties have the following characteristics:
 634      -.RS +4
 635      -.TP
 636      -.ie t \(bu
 637      -.el o
 638      -Values of type \fIboolean\fR take either \fBtrue\fR or \fBfalse\fR.
 639      -.RE
 640      -.RS +4
 641      -.TP
 642      -.ie t \(bu
 643      -.el o
 644      -Values of type \fIvalue\fR take a numeric value.
 645      -.RE
 646      -.RS +4
 647      -.TP
 648      -.ie t \(bu
 649      -.el o
 650      -Values of type \fIfile\fR take a file name and not a file path.
 651      -.RE
 652      -.RS +4
 653      -.TP
 654      -.ie t \(bu
 655      -.el o
 656      -Values of type \fIaccess-list\fR are described in detail following the
 657      -descriptions of the NFS properties.
 658      -.RE
 659      -.sp
 660      -.LP
 661      -The general properties supported for NFS are:
 662      -.sp
 663      -.ne 2
 664      -.na
 665      -\fB\fBabe=\fR\fIboolean\fR\fR
 666      -.ad
 667      -.sp .6
 668      -.RS 4n
 669      -Set the access-based enumeration (ABE) policy for a share.  When set to
 670      -\fBtrue\fR, ABE filtering is enabled on this share and directory entries to
 671      -which the requesting user has no access will be omitted from directory listings
 672      -returned to the client. When set to \fBfalse\fR or not defined, ABE filtering
 673      -will not be performed on  this share. This property is not defined by default.
 674      -.sp
 675      -.ne 2
 676      -.na
 677      -\fB\fBdisabled\fR\fR
 678      -.ad
 679      -.sp .6
 680      -.RS 4n
 681      -Disable ABE for this share.
 682      -.RE
 683      -
 684      -.sp
 685      -.ne 2
 686      -.na
 687      -\fB\fBenabled\fR\fR
 688      -.ad
 689      -.sp .6
 690      -.RS 4n
 691      -Enable ABE for this share.
 692      -.RE
 693      -
 694      -.RE
 695      -
 696      -.sp
 697      -.ne 2
 698      -.na
 699      -\fB\fBaclok=\fIboolean\fR\fR\fR
 700      -.ad
 701      -.sp .6
 702      -.RS 4n
 703      -Allows the NFS server to do access control for NFS Version 2 clients (running
 704      -SunOS 2.4 or earlier). When \fBaclok\fR is set on the server, maximum access is
 705      -given to all clients. For example, with \fBaclok\fR set, if anyone has read
 706      -permissions, then everyone does. If \fBaclok\fR is not set, minimum access is
 707      -given to all clients.
 708      -.RE
 709      -
 710      -.sp
 711      -.ne 2
 712      -.na
 713      -\fB\fBad-container\fR\fR
 714      -.ad
 715      -.sp .6
 716      -.RS 4n
 717      -Specifies the AD container in which to publish shares.
 718      -.sp
 719      -The AD container is specified as a comma-separated list of attribute name-value
 720      -pairs using the LDAP distinguished name (DN) or relative distinguished name
 721      -(RDN) format. The DN or RDN must be specified in LDAP format using the
 722      -\fBcn=\fR, \fBou=\fR, and \fBdc=\fR prefixes:
 723      -.RS +4
 724      -.TP
 725      -.ie t \(bu
 726      -.el o
 727      -\fBcn\fR represents the common name
 728      -.RE
 729      -.RS +4
 730      -.TP
 731      -.ie t \(bu
 732      -.el o
 733      -\fBou\fR represents the organizational unit
 734      -.RE
 735      -.RS +4
 736      -.TP
 737      -.ie t \(bu
 738      -.el o
 739      -\fBdc\fR represents the domain component
 740      -.RE
 741      -\fBcn=\fR, \fBou=\fR and \fBdc=\fR are attribute types. The attribute type used
 742      -to describe an object's RDN is called the naming attribute, which, for ADS,
 743      -includes the following object classes:
 744      -.RS +4
 745      -.TP
 746      -.ie t \(bu
 747      -.el o
 748      -\fBcn\fR for the \fBuser\fR object class
 749      -.RE
 750      -.RS +4
 751      -.TP
 752      -.ie t \(bu
 753      -.el o
 754      -\fBou\fR for the organizational unit (\fBOU\fR) object class
 755      -.RE
 756      -.RS +4
 757      -.TP
 758      -.ie t \(bu
 759      -.el o
 760      -\fBdc\fR for the \fBdomainDns\fR object class
 761      -.RE
 762      -.RE
 763      -
 764      -.sp
 765      -.ne 2
 766      -.na
 767      -\fB\fBanon=\fIuid\fR\fR\fR
 768      -.ad
 769      -.sp .6
 770      -.RS 4n
 771      -Set \fIuid\fR to be the effective user ID of unknown users. By default, unknown
 772      -users are given the effective user ID \fBUID_NOBODY\fR. If uid is set to
 773      -\fB-1\fR, access is denied.
 774      -.RE
 775      -
 776      -.sp
 777      -.ne 2
 778      -.na
 779      -\fB\fBcatia=\fIboolean\fR\fR\fR
 780      -.ad
 781      -.sp .6
 782      -.RS 4n
 783      -CATIA V4 uses characters in file names that are considered to be invalid by
 784      -Windows. CATIA V5 is available on Windows. A CATIA V4 file could be
 785      -inaccessible to Windows clients if the file name contains any of the characters
 786      -that are considered illegal in Windows. By default, CATIA character
 787      -substitution is not performed.
 788      -.sp
 789      -If the \fBcatia\fR property is set to true, the following character
 790      -substitution is applied to file names.
 791      -.sp
 792      -.in +2
 793      -.nf
 794      -CATIA    CATIA
 795      -V4 UNIX  V5 Windows
 796      -  "      \e250   0x00a8  Dieresis
 797      -  *      \e244   0x00a4  Currency Sign
 798      -  /      \e370   0x00f8  Latin Small Letter O with Stroke
 799      -  :      \e367   0x00f7  Division Sign
 800      -  <      \e253   0x00ab  Left-Pointing Double Angle Quotation Mark
 801      -  >      \e273   0x00bb  Right-Pointing Double Angle Quotation Mark
 802      -  ?      \e277   0x00bf  Inverted Question Mark
 803      -  \e      \e377   0x00ff  Latin Small Letter Y with Dieresis
 804      -  |      \e246   0x00a6  Broken Bar
 805      -.fi
 806      -.in -2
 807      -.sp
 808      -
 809      -.RE
 810      -
 811      -.sp
 812      -.ne 2
 813      -.na
 814      -\fB\fBcksum=\fIcksumlist\fR\fR\fR
 815      -.ad
 816      -.sp .6
 817      -.RS 4n
 818      -Set the share to attempt to use end-to-end checksums. The value \fIcksumlist\fR
 819      -specifies the checksum algorithms that should be used.
 820      -.RE
 821      -
 822      -.sp
 823      -.ne 2
 824      -.na
 825      -\fB\fBcsc=\fR\fIvalue\fR\fR
 826      -.ad
 827      -.sp .6
 828      -.RS 4n
 829      -Set the client-side caching policy for a share. Client-side caching is a client
 830      -feature and offline files are managed entirely by the clients.
 831      -.sp
 832      -.LP
 833      -The following are valid values for the \fBcsc\fR property:
 834      -.RS +4
 835      -.TP
 836      -.ie t \(bu
 837      -.el o
 838      -\fBmanual\fR \fB-\fR Clients are permitted to cache files from the specified
 839      -share for offline use as requested by users. However, automatic file-by-file
 840      -reintegration is not permitted. \fBmanual\fR is the default value.
 841      -.RE
 842      -.RS +4
 843      -.TP
 844      -.ie t \(bu
 845      -.el o
 846      -\fBauto\fR \fB-\fR Clients are permitted to automatically cache files from the
 847      -specified share for offline use and file-by-file reintegration is permitted.
 848      -.RE
 849      -.RS +4
 850      -.TP
 851      -.ie t \(bu
 852      -.el o
 853      -\fBvdo\fR \fB-\fR Clients are permitted to automatically cache files from the
 854      -specified share for offline use, file-by-file reintegration is permitted, and
 855      -clients are permitted to work from their local cache even while offline.
 856      -.RE
 857      -.RS +4
 858      -.TP
 859      -.ie t \(bu
 860      -.el o
 861      -\fBdisabled\fR \fB-\fR Client-side caching is not permitted for this share.
 862      -.RE
 863      -.RE
 864      -
 865      -.sp
 866      -.ne 2
 867      -.na
 868      -\fB\fBguestok=\fR\fIboolean\fR\fR
 869      -.ad
 870      -.sp .6
 871      -.RS 4n
 872      -Set the guest access policy for the share. When set to \fBtrue\fR guest access
 873      -is allowed on this share. When set to \fBfalse\fR or not defined guest access
 874      -is not allowed on this share. This property is not defined by default.
 875      -.sp
 876      -An \fBidmap\fR(1M) name-based rule can be used to map \fBguest\fR to any local
 877      -username, such as \fBguest\fR or \fBnobody\fR. If the local account has a
 878      -password in \fB/var/smb/smbpasswd\fR the guest connection will be authenticated
 879      -against that password. Any connection made using an account that maps to the
 880      -local guest account will be treated as a guest connection.
 881      -.sp
 882      -Example name-based rule:
 883      -.sp
 884      -.in +2
 885      -.nf
 886      -# \fBidmap add winname:Guest unixuser:guest\fR
 887      -.fi
 888      -.in -2
 889      -.sp
 890      -
 891      -.RE
 892      -
 893      -.sp
 894      -.ne 2
 895      -.na
 896      -\fB\fBindex=\fIfile\fR\fR\fR
 897      -.ad
 898      -.sp .6
 899      -.RS 4n
 900      -Load \fIfile\fR rather than a listing of the directory containing this file
 901      -when the directory is referenced by an NFS URL.
 902      -.RE
 903      -
 904      -.sp
 905      -.ne 2
 906      -.na
 907      -\fB\fBlog=\fItag\fR\fR\fR
 908      -.ad
 909      -.sp .6
 910      -.RS 4n
 911      -Enables NFS server logging for the specified system. The optional tag
 912      -determines the location of the related log files. The tag is defined in
 913      -\fBetc/nfs/nfslog.conf\fR. If no tag is specified, the default values
 914      -associated with the global tag in \fBetc/nfs/nfslog.conf\fR is used. Support of
 915      -NFS server logging is available only for NFS Version 2 and Version 3 requests.
 916      -.RE
 917      -
 918      -.sp
 919      -.ne 2
 920      -.na
 921      -\fB\fBnosub=\fIboolean\fR\fR\fR
 922      -.ad
 923      -.sp .6
 924      -.RS 4n
 925      -Prevents clients from mounting subdirectories of shared directories. For
 926      -example, if \fB/export\fR is shared with the \fBnosub\fR option on server
 927      -\fBwool\fR then an NFS client cannot do:
 928      -.sp
 929      -.in +2
 930      -.nf
 931      -# \fBmount -F nfs wool:/export/home/mnt\fR
 932      -.fi
 933      -.in -2
 934      -.sp
 935      -
 936      -NFS Version 4 does not use the MOUNT protocol. The \fBnosub\fR option applies
 937      -only to NFS Version 2 and Version 3 requests.
 938      -.RE
 939      -
 940      -.sp
 941      -.ne 2
 942      -.na
 943      -\fB\fBnosuid=\fIboolean\fR\fR\fR
 944      -.ad
 945      -.sp .6
 946      -.RS 4n
 947      -By default, clients are allowed to create files on a shared file system with
 948      -the \fBsetuid\fR or \fBsetgid\fR mode enabled. Specifying \fBnosuid\fR causes
 949      -the server file system to silently ignore any attempt to enable the
 950      -\fBsetuid\fR or \fBsetgid\fR mode bits.
 951      -.RE
 952      -
 953      -.sp
 954      -.ne 2
 955      -.na
 956      -\fB\fBpublic=\fIboolean\fR\fR\fR
 957      -.ad
 958      -.sp .6
 959      -.RS 4n
 960      -Moves the location of the public file handle from root (\fB/\fR) to the
 961      -exported directory for WebNFS-enabled browsers and clients. This option does
 962      -not enable WebNFS service; WebNFS is always on. Only one file system per server
 963      -can have the \fBpublic\fR property. You can apply the \fBpublic\fR property
 964      -only to a share and not to a group.
 965      -.RE
 966      -
 967      -.sp
 968      -.LP
 969      -NFS also supports negotiated optionsets for supported security modes. The
 970      -security modes are documented in \fBnfssec\fR(5). The properties supported for
 971      -these optionsets are:
 972      -.sp
 973      -.ne 2
 974      -.na
 975      -\fB\fIcharset\fR=\fIaccess-list\fR\fR
 976      -.ad
 977      -.sp .6
 978      -.RS 4n
 979      -Where \fIcharset\fR is one of: \fBeuc-cn\fR, \fBeuc-jp\fR, \fBeuc-jpms\fR,
 980      -\fBeuc-kr\fR, \fBeuc-tw\fR, \fBiso8859-1\fR, \fBiso8859-2\fR, \fBiso8859-5\fR,
 981      -\fBiso8859-6\fR, \fBiso8859-7\fR, \fBiso8859-8\fR, \fBiso8859-9\fR,
 982      -\fBiso8859-13\fR, \fBiso8859-15\fR, \fBkoi8-r\fR.
 983      -.sp
 984      -Clients that match the \fIaccess-list\fR for one of these properties will be
 985      -assumed to be using that character set and file and path names will be
 986      -converted to UTF-8 for the server.
 987      -.RE
 988      -
 989      -.sp
 990      -.ne 2
 991      -.na
 992      -\fB\fBro=\fIaccess-list\fR\fR\fR
 993      -.ad
 994      -.sp .6
 995      -.RS 4n
 996      -Sharing is read-only to the clients listed in \fIaccess-list\fR; overrides the
 997      -\fBrw\fR suboption for the clients specified. See the description of
 998      -\fIaccess-list\fR below.
 999      -.RE
1000      -
1001      -.sp
1002      -.ne 2
1003      -.na
1004      -\fB\fBrw=\fIaccess-list\fR\fR\fR
1005      -.ad
1006      -.sp .6
1007      -.RS 4n
1008      -Sharing is read-write to the clients listed in \fIaccess-list\fR; overrides the
1009      -\fBro\fR suboption for the clients specified. See the description of
1010      -\fIaccess-list\fR below.
1011      -.RE
1012      -
1013      -.sp
1014      -.ne 2
1015      -.na
1016      -\fB\fBnone=\fIaccess-list\fR\fR\fR
1017      -.ad
1018      -.sp .6
1019      -.RS 4n
1020      -Access is not allowed to any client that matches the access list. The exception
1021      -is when the access list is an asterisk (\fB*\fR), in which case \fBro\fR or
1022      -\fBrw\fR can override \fBnone\fR.
1023      -.RE
1024      -
1025      -.sp
1026      -.ne 2
1027      -.na
1028      -\fB\fBroot=\fIaccess-list\fR\fR\fR
1029      -.ad
1030      -.sp .6
1031      -.RS 4n
1032      -Only root users from the hosts specified in \fIaccess-list\fR have root access.
1033      -See details on \fIaccess-list\fR below. By default, no host has root access, so
1034      -root users are mapped to an anonymous user ID (see the \fBanon=uid\fR option
1035      -described above). Netgroups can be used if the file system shared is using UNIX
1036      -authentication (\fBAUTH_SYS\fR).
1037      -.RE
1038      -
1039      -.sp
1040      -.ne 2
1041      -.na
1042      -\fB\fBroot_mapping=\fIuid\fR\fR\fR
1043      -.ad
1044      -.sp .6
1045      -.RS 4n
1046      -For a client that is allowed root access, map the root UID to the specified
1047      -user id.
1048      -.RE
1049      -
1050      -.sp
1051      -.ne 2
1052      -.na
1053      -\fB\fBwindow=\fIvalue\fR\fR\fR
1054      -.ad
1055      -.sp .6
1056      -.RS 4n
1057      -When sharing with \fBsec=dh\fR (see \fBnfssec\fR(5)), set the maximum lifetime
1058      -(in seconds) of the RPC request's credential (in the authentication header)
1059      -that the NFS server allows. If a credential arrives with a lifetime larger than
1060      -what is allowed, the NFS server rejects the request. The default value is 30000
1061      -seconds (8.3 hours). This property is ignored for security modes other than
1062      -\fBdh\fR.
1063      -.RE
1064      -
1065      -.sp
1066      -.LP
1067      -The general properties supported for SMB are:
1068      -.sp
1069      -.ne 2
1070      -.na
1071      -\fB\fBro=\fIaccess-list\fR\fR\fR
1072      -.ad
1073      -.sp .6
1074      -.RS 4n
1075      -Sharing is read-only to the clients listed in \fIaccess-list\fR; overrides the
1076      -\fBrw\fR suboption for the clients specified. See the description of
1077      -\fIaccess-list\fR below.
1078      -.RE
1079      -
1080      -.sp
1081      -.ne 2
1082      -.na
1083      -\fB\fBrw=\fIaccess-list\fR\fR\fR
1084      -.ad
1085      -.sp .6
1086      -.RS 4n
1087      -Sharing is read-write to the clients listed in \fIaccess-list\fR; overrides the
1088      -\fBro\fR suboption for the clients specified. See the description of
1089      -\fIaccess-list\fR below.
1090      -.RE
1091      -
1092      -.sp
1093      -.ne 2
1094      -.na
1095      -\fB\fBnone=\fIaccess-list\fR\fR\fR
1096      -.ad
1097      -.sp .6
1098      -.RS 4n
1099      -Access is not allowed to any client that matches the access list. The exception
1100      -is when the access list is an asterisk (\fB*\fR), in which case \fBro\fR or
1101      -\fBrw\fR can override \fBnone\fR.
1102      -.RE
1103      -
1104      -.SS "Access List Argument"
1105      -.LP
1106      -The \fIaccess-list\fR argument is either the string \fB"*"\fR to represent all
1107      -hosts or a colon-separated list whose components can be any number of the
1108      -following:
1109      -.sp
1110      -.ne 2
1111      -.na
1112      -\fB\fIhostname\fR\fR
1113      -.ad
1114      -.sp .6
1115      -.RS 4n
1116      -The name of a host. With a server configured for DNS or LDAP naming in the
1117      -\fBnsswitch.conf\fR(4) \fBhosts\fR entry, a hostname must be represented as a
1118      -fully qualified DNS or LDAP name.
1119      -.RE
1120      -
1121      -.sp
1122      -.ne 2
1123      -.na
1124      -\fB\fInetgroup\fR\fR
1125      -.ad
1126      -.sp .6
1127      -.RS 4n
1128      -A \fInetgroup\fR contains a number of hostnames. With a server configured for
1129      -DNS or LDAP naming in the \fBnsswitch.conf\fR(4) \fBhosts\fR entry, any
1130      -hostname in a netgroup must be represented as a fully qualified DNS or LDAP
1131      -name.
1132      -.RE
1133      -
1134      -.sp
1135      -.ne 2
1136      -.na
1137      -\fB\fIdomainname\fR.\fIsuffix\fR\fR
1138      -.ad
1139      -.sp .6
1140      -.RS 4n
1141      -To use domain membership the server must use DNS or LDAP, rather than, for
1142      -example, NIS, to resolve hostnames to IP addresses. That is, the
1143      -\fBhosts\fR entry in the \fBnsswitch.conf\fR(4) must specify \fBdns\fR or
1144      -\fBldap\fR ahead of \fBnis\fR, because only DNS and LDAP
1145      -return the full domain name of the host. Other name services, such as NIS,
1146      -cannot be used to resolve hostnames on the server because, when mapping
1147      -an IP address to a hostname, they do not return domain information. For
1148      -example, for the IP address 172.16.45.9:
1149      -.sp
1150      -.ne 2
1151      -.na
1152      -\fBNIS\fR
1153      -.ad
1154      -.sp .6
1155      -.RS 4n
1156      -Returns: \fBmyhost\fR
1157      -.RE
1158      -
1159      -.sp
1160      -.ne 2
1161      -.na
1162      -\fBDNS or LDAP\fR
1163      -.ad
1164      -.sp .6
1165      -.RS 4n
1166      -Returns: \fBmyhost.mydomain.mycompany.com\fR
1167      -.RE
1168      -
1169      -The domain name suffix is distinguished from hostnames and netgroups by a
1170      -prefixed dot. For example:
1171      -.sp
1172      -.in +2
1173      -.nf
1174      -rw=.mydomain.mycompany.com
1175      -.fi
1176      -.in -2
1177      -
1178      -A single dot can be used to match a hostname with no suffix. For example, the
1179      -specification:
1180      -.sp
1181      -.in +2
1182      -.nf
1183      -rw=.
1184      -.fi
1185      -.in -2
1186      -
1187      -\&...matches \fBmydomain\fR but not \fBmydomain.mycompany.com\fR. This feature
1188      -can be used to match hosts resolved through NIS rather than DNS and
1189      -LDAP.
1190      -.RE
1191      -
1192      -.sp
1193      -.ne 2
1194      -.na
1195      -\fB\fInetwork\fR\fR
1196      -.ad
1197      -.sp .6
1198      -.RS 4n
1199      -The network or subnet component is preceded by an at-sign (\fB@\fR). It can be
1200      -either a name or a dotted address. If a name, it is converted to a dotted
1201      -address by \fBgetnetbyname\fR(3SOCKET). For example:
1202      -.sp
1203      -.in +2
1204      -.nf
1205      -=@mynet
1206      -.fi
1207      -.in -2
1208      -
1209      -\&...is equivalent to:
1210      -.sp
1211      -.in +2
1212      -.nf
1213      -=@172.16 or =@172.16.0.0
1214      -.fi
1215      -.in -2
1216      -
1217      -The network prefix assumes an octet-aligned netmask determined from the zeroth
1218      -octet in the low-order part of the address up to and including the high-order
1219      -octet, if you want to specify a single IP address. In the case where network
1220      -prefixes are not byte-aligned, the syntax allows a mask length to be specified
1221      -explicitly following a slash (\fB/\fR) delimiter. For example:
1222      -.sp
1223      -.in +2
1224      -.nf
1225      -=@theothernet/17 or =@172.16.132/22
1226      -.fi
1227      -.in -2
1228      -
1229      -\&...where the mask is the number of leftmost contiguous significant bits in
1230      -the corresponding IP address.
1231      -.RE
1232      -
1233      -.sp
1234      -.LP
1235      -A prefixed minus sign (\fB-\fR) denies access to a component of
1236      -\fIaccess-list\fR. The list is searched sequentially until a match is found
1237      -that either grants or denies access, or until the end of the list is reached.
1238      -For example, if host \fBterra\fR is in the netgroup \fBengineering\fR, then:
1239      -.sp
1240      -.in +2
1241      -.nf
1242      -rw=-terra:engineering
1243      -.fi
1244      -.in -2
1245      -
1246      -.sp
1247      -.LP
1248      -\&...denies access to \fBterra\fR, but:
1249      -.sp
1250      -.in +2
1251      -.nf
1252      -rw=engineering:-terra
1253      -.fi
1254      -.in -2
1255      -
1256      -.sp
1257      -.LP
1258      -\&...grants access to \fBterra\fR.
1259  631  .SH EXIT STATUS
1260  632  .ne 2
1261  633  .na
1262  634  \fB\fB0\fR\fR
1263  635  .ad
1264  636  .RS 18n
1265  637  Successful completion.
1266  638  .RE
1267  639  
1268  640  .sp
↓ open down ↓ 34 lines elided ↑ open up ↑
1303  675  c | c
1304  676  l | l .
1305  677  ATTRIBUTE TYPE  ATTRIBUTE VALUE
1306  678  _
1307  679  Interface Stability     Committed
1308  680  .TE
1309  681  
1310  682  .SH SEE ALSO
1311  683  .LP
1312  684  \fBidmap\fR(1M), \fBsharectl\fR(1M), \fBzfs\fR(1M), \fBattributes\fR(5),
1313      -\fBnfssec\fR(5), \fBsmf\fR(5), \fBstandards\fR(5)
      685 +\fBnfssec\fR(5), \fBshareacl\fR(5), \fBsharenfs\fR(5), \fBsharesmb\fR(5),
      686 +\fBsmf\fR(5), \fBstandards\fR(5)
    
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX