diff options
author | Jeremy Allison <jra@samba.org> | 2009-01-22 16:09:26 -0800 |
---|---|---|
committer | Karolin Seeger <kseeger@samba.org> | 2009-01-23 09:07:39 +0100 |
commit | 3d0da7fae928197a993f7411a95d36f4cb2f0f51 (patch) | |
tree | d5637029d62ca7f728fdf827cf9955bc2110c501 /source/smbd | |
parent | 6c9843446df64fd7f517bfeeca0afab654a6f0f5 (diff) | |
download | samba-3d0da7fae928197a993f7411a95d36f4cb2f0f51.tar.gz samba-3d0da7fae928197a993f7411a95d36f4cb2f0f51.tar.xz samba-3d0da7fae928197a993f7411a95d36f4cb2f0f51.zip |
Fix logic error in try_chown - we shouldn't arbitrarily chown
to ourselves unless that was passed in.
Jeremy.
(cherry picked from commit db2d56484e21daeb91df4b5e2286d242910336e8)
Diffstat (limited to 'source/smbd')
-rw-r--r-- | source/smbd/posix_acls.c | 15 |
1 files changed, 9 insertions, 6 deletions
diff --git a/source/smbd/posix_acls.c b/source/smbd/posix_acls.c index 0882cb504e9..b862699f42f 100644 --- a/source/smbd/posix_acls.c +++ b/source/smbd/posix_acls.c @@ -3187,6 +3187,15 @@ int try_chown(connection_struct *conn, const char *fname, uid_t uid, gid_t gid) return -1; } + /* only allow chown to the current user. This is more secure, + and also copes with the case where the SID in a take ownership ACL is + a local SID on the users workstation + */ + if (uid != current_user.ut.uid) { + errno = EPERM; + return -1; + } + if (SMB_VFS_STAT(conn,fname,&st)) { return -1; } @@ -3195,12 +3204,6 @@ int try_chown(connection_struct *conn, const char *fname, uid_t uid, gid_t gid) return -1; } - /* only allow chown to the current user. This is more secure, - and also copes with the case where the SID in a take ownership ACL is - a local SID on the users workstation - */ - uid = current_user.ut.uid; - become_root(); /* Keep the current file gid the same. */ ret = SMB_VFS_FCHOWN(fsp, uid, (gid_t)-1); |