Hi, I can now reproduce my winbind problem in an easy case.
1) create a directory /z-var/lib/xxx on read-only branch (cdrom) 2) chown root.root /z-var/lib/xxx chmod 750 /z-var/lib/xxx 3) mount writable filesystem and aufs: mount -n -t aufs -o br:/DISK/var:/z-var none /var /dev/sda2 on /DISK/var type ext3 (rw,data=ordered) none on /var type aufs (rw,xino=/DISK/var/.aufs.xino,br:/DISK/var=rw:/z-var=ro) 4) change permissions on /var/lib/xxx (aufs): chgrp 750 /var/lib/xxx now is: % ls -ld /z-var/lib/xxx /DISK/var/lib/xxx /var/lib/xxx drwxr-x--- 2 root root 2048 May 21 11:16 /z-var/lib/xxx/ drwxr-x--- 2 root proxy 4096 May 21 13:37 /DISK/var/lib/xxx/ drwxr-x--- 2 root proxy 4096 May 21 13:37 /var/lib/xxx/ 5) create a file /var/lib/xxx/test.txt with permissions 777: -rwxrwxrwx 1 root root 18 May 21 13:37 /var/lib/xxx/xxx.txt* 6) su - proxy [EMAIL PROTECTED]:~$ id uid=13(proxy) gid=13(proxy) groups=13(proxy) [EMAIL PROTECTED]:~$ cd /var/lib/xxx -su: cd: /var/lib/xxx: Permission denied 7) strings /lib/modules/2.6.21.1/kernel/fs/aufs/aufs.ko | grep version version=20070521 srcversion=CE41BE984A8B453369C86FF Wolfgang -- <wob (at) swobspace de> * http://www.swobspace.de ------------------------------------------------------------------------- This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/