]> git.ipfire.org Git - thirdparty/samba.git/commitdiff
s3: smbd: vfs_fruit: Replace code in fruit_fget_nt_acl() with remove_virtual_nfs_aces().
authorJeremy Allison <jra@samba.org>
Thu, 15 Mar 2018 16:57:09 +0000 (09:57 -0700)
committerJeremy Allison <jra@samba.org>
Fri, 16 Mar 2018 22:07:09 +0000 (23:07 +0100)
BUG: https://bugzilla.samba.org/show_bug.cgi?id=13319

Signed-off-by: Jeremy Allison <jra@samba.org>
Reviewed-by: Ralph Boehme <slow@samba.org>
source3/modules/vfs_fruit.c

index 38f421c337d5356793eaee56f0242f15bf260441..19b78edb949655de5b2eef8ebea6f584d6d8a154 100644 (file)
@@ -5735,7 +5735,6 @@ static NTSTATUS fruit_fget_nt_acl(vfs_handle_struct *handle,
        struct security_ace ace;
        struct dom_sid sid;
        struct fruit_config_data *config;
-       bool remove_ok = false;
 
        SMB_VFS_HANDLE_GET_DATA(handle, config,
                                struct fruit_config_data,
@@ -5757,18 +5756,16 @@ static NTSTATUS fruit_fget_nt_acl(vfs_handle_struct *handle,
                return NT_STATUS_OK;
        }
 
+       /* First remove any existing ACE's with NFS style mode/uid/gid SIDs. */
+       status = remove_virtual_nfs_aces(*ppdesc);
+       if (!NT_STATUS_IS_OK(status)) {
+               DBG_WARNING("failed to remove MS NFS style ACEs\n");
+               return status;
+       }
+
        /* MS NFS style mode */
        sid_compose(&sid, &global_sid_Unix_NFS_Mode, fsp->fsp_name->st.st_ex_mode);
        init_sec_ace(&ace, &sid, SEC_ACE_TYPE_ACCESS_DENIED, 0, 0);
-
-       /* First remove any existing ACE's with this SID. */
-       status = security_descriptor_dacl_del(*ppdesc, &sid);
-       remove_ok = (NT_STATUS_IS_OK(status) ||
-                    NT_STATUS_EQUAL(status, NT_STATUS_OBJECT_NAME_NOT_FOUND));
-       if (!remove_ok) {
-               DBG_WARNING("failed to remove MS NFS_mode style ACE\n");
-               return status;
-       }
        status = security_descriptor_dacl_add(*ppdesc, &ace);
        if (!NT_STATUS_IS_OK(status)) {
                DEBUG(1,("failed to add MS NFS style ACE\n"));
@@ -5778,15 +5775,6 @@ static NTSTATUS fruit_fget_nt_acl(vfs_handle_struct *handle,
        /* MS NFS style uid */
        sid_compose(&sid, &global_sid_Unix_NFS_Users, fsp->fsp_name->st.st_ex_uid);
        init_sec_ace(&ace, &sid, SEC_ACE_TYPE_ACCESS_DENIED, 0, 0);
-
-       /* First remove any existing ACE's with this SID. */
-       status = security_descriptor_dacl_del(*ppdesc, &sid);
-       remove_ok = (NT_STATUS_IS_OK(status) ||
-                    NT_STATUS_EQUAL(status, NT_STATUS_OBJECT_NAME_NOT_FOUND));
-       if (!remove_ok) {
-               DBG_WARNING("failed to remove MS NFS_users style ACE\n");
-               return status;
-       }
        status = security_descriptor_dacl_add(*ppdesc, &ace);
        if (!NT_STATUS_IS_OK(status)) {
                DEBUG(1,("failed to add MS NFS style ACE\n"));
@@ -5796,15 +5784,6 @@ static NTSTATUS fruit_fget_nt_acl(vfs_handle_struct *handle,
        /* MS NFS style gid */
        sid_compose(&sid, &global_sid_Unix_NFS_Groups, fsp->fsp_name->st.st_ex_gid);
        init_sec_ace(&ace, &sid, SEC_ACE_TYPE_ACCESS_DENIED, 0, 0);
-
-       /* First remove any existing ACE's with this SID. */
-       status = security_descriptor_dacl_del(*ppdesc, &sid);
-       remove_ok = (NT_STATUS_IS_OK(status) ||
-                    NT_STATUS_EQUAL(status, NT_STATUS_OBJECT_NAME_NOT_FOUND));
-       if (!remove_ok) {
-               DBG_WARNING("failed to remove MS NFS_groups style ACE\n");
-               return status;
-       }
        status = security_descriptor_dacl_add(*ppdesc, &ace);
        if (!NT_STATUS_IS_OK(status)) {
                DEBUG(1,("failed to add MS NFS style ACE\n"));