From: Ralph Boehme Date: Thu, 27 Dec 2018 10:37:16 +0000 (+0100) Subject: Revert "smbd: avoid explicit change_to_user() in defer_rename_done() already done... X-Git-Tag: talloc-2.1.15~174 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=ac17919ae306514aeb668cf422ce46daa3897ae3;p=thirdparty%2Fsamba.git Revert "smbd: avoid explicit change_to_user() in defer_rename_done() already done by impersonation" This reverts commit e37e41b3cac52e3623f0c79f83733a51edb35c10. See the discussion in https://lists.samba.org/archive/samba-technical/2018-December/131731.html for the reasoning behind this revert. Signed-off-by: Ralph Boehme Reviewed-by: Volker Lendecke Reviewed-by: Stefan Metzmacher --- diff --git a/source3/smbd/smb2_setinfo.c b/source3/smbd/smb2_setinfo.c index 11b126aa794..7c1f84bd79d 100644 --- a/source3/smbd/smb2_setinfo.c +++ b/source3/smbd/smb2_setinfo.c @@ -284,6 +284,7 @@ static void defer_rename_done(struct tevent_req *subreq) NTSTATUS status; struct share_mode_lock *lck; int ret_size = 0; + bool ok; status = dbwrap_watched_watch_recv(subreq, NULL, NULL); TALLOC_FREE(subreq); @@ -294,6 +295,16 @@ static void defer_rename_done(struct tevent_req *subreq) return; } + /* + * Make sure we run as the user again + */ + ok = change_to_user(state->smb2req->tcon->compat, + state->smb2req->session->compat->vuid); + if (!ok) { + tevent_req_nterror(state->req, NT_STATUS_ACCESS_DENIED); + return; + } + /* Do we still need to wait ? */ lck = get_existing_share_mode_lock(state->req, state->fsp->file_id); if (lck == NULL) {