Commit decffcf2 by Edward Thomson

fs: allow ownership match if user is in admin group

Allow the user ownership to match if the file is owned by the admin
group and the user is in the admin group, even if the current process is
not running as administrator directly.
parent be29b861
......@@ -2124,6 +2124,7 @@ int git_path_owner_is(
git_path_owner_t owner_type)
{
PSID owner_sid = NULL, user_sid = NULL;
BOOL is_admin, admin_owned;
int error;
if (mock_owner) {
......@@ -2144,12 +2145,22 @@ int git_path_owner_is(
}
}
if ((owner_type & GIT_PATH_OWNER_ADMINISTRATOR) != 0) {
if (IsWellKnownSid(owner_sid, WinBuiltinAdministratorsSid) ||
IsWellKnownSid(owner_sid, WinLocalSystemSid)) {
*out = true;
goto done;
}
admin_owned =
IsWellKnownSid(owner_sid, WinBuiltinAdministratorsSid) ||
IsWellKnownSid(owner_sid, WinLocalSystemSid);
if (admin_owned &&
(owner_type & GIT_PATH_OWNER_ADMINISTRATOR) != 0) {
*out = true;
goto done;
}
if (admin_owned &&
(owner_type & GIT_PATH_USER_IS_ADMINISTRATOR) != 0 &&
CheckTokenMembership(NULL, owner_sid, &is_admin) &&
is_admin) {
*out = true;
goto done;
}
*out = false;
......@@ -2201,6 +2212,7 @@ int git_path_owner_is(
return 0;
}
#endif
int git_path_owner_is_current_user(bool *out, const char *path)
......
......@@ -731,8 +731,15 @@ typedef enum {
/** The file must be owned by the system account. */
GIT_PATH_OWNER_ADMINISTRATOR = (1 << 1),
/**
* The file may be owned by a system account if the current
* user is in an administrator group. Windows only; this is
* a noop on non-Windows systems.
*/
GIT_PATH_USER_IS_ADMINISTRATOR = (1 << 2),
/** The file may be owned by another user. */
GIT_PATH_OWNER_OTHER = (1 << 2)
GIT_PATH_OWNER_OTHER = (1 << 3)
} git_path_owner_t;
/**
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment