From f2b03c9258bb9b7dbcb92d573e2b877d4c6f07dd Mon Sep 17 00:00:00 2001 From: Corinna Vinschen Date: Sun, 31 Aug 2014 19:33:19 +0000 Subject: [PATCH] * uinfo.cc (pwdgrp::fetch_account_from_windows): Disallow user accounts as groups. Add comment. --- winsup/cygwin/ChangeLog | 5 +++++ winsup/cygwin/uinfo.cc | 7 +++++++ 2 files changed, 12 insertions(+) diff --git a/winsup/cygwin/ChangeLog b/winsup/cygwin/ChangeLog index 3abdc0c82..8650c1a8b 100644 --- a/winsup/cygwin/ChangeLog +++ b/winsup/cygwin/ChangeLog @@ -1,3 +1,8 @@ +2014-08-31 Corinna Vinschen + + * uinfo.cc (pwdgrp::fetch_account_from_windows): Disallow user accounts + as groups. Add comment. + 2014-08-31 Corinna Vinschen * uinfo.cc (cygheap_pwdgrp::init): Fix comment. Rearrange code for diff --git a/winsup/cygwin/uinfo.cc b/winsup/cygwin/uinfo.cc index 4dff53ade..6d1b5b7a8 100644 --- a/winsup/cygwin/uinfo.cc +++ b/winsup/cygwin/uinfo.cc @@ -1504,6 +1504,13 @@ pwdgrp::fetch_account_from_windows (fetch_user_arg_t &arg, cyg_ldap *pldap) switch (acc_type) { case SidTypeUser: + /* Don't allow users as group. While this is technically possible, + it doesn't make sense in a POSIX scenario. It *is* used for + Microsoft Accounts, but those are converted to well-known groups + above. */ + if (is_group ()) + return NULL; + /*FALLTHRU*/ case SidTypeGroup: case SidTypeAlias: /* Predefined alias? */ -- 2.43.5