[PATCH] pyldb: Don't segfault when invalid type is specified to as_sddl and from_sddl.

Matthieu Patou mat at matws.net
Thu Sep 17 09:56:02 MDT 2009


  Fix bug #6723
---
 source4/libcli/security/tests/bindings.py |   17 +++++++++++++++++
 source4/librpc/ndr/py_security.c          |    4 ++--
 2 files changed, 19 insertions(+), 2 deletions(-)

diff --git a/source4/libcli/security/tests/bindings.py b/source4/libcli/security/tests/bindings.py
index f0d55f1..00fa05d 100644
--- a/source4/libcli/security/tests/bindings.py
+++ b/source4/libcli/security/tests/bindings.py
@@ -57,6 +57,16 @@ class SecurityDescriptorTests(unittest.TestCase):
         self.assertEquals(desc.sacl, None)
         self.assertEquals(desc.type, 0x8004)
 
+    def test_from_sddl_invalidsddl(self):
+        self.assertRaises(TypeError,security.descriptor.from_sddl, "foo",security.dom_sid("S-2-0-0"))
+
+    def test_from_sddl_invalidtype1(self):
+        self.assertRaises(TypeError,security.descriptor.from_sddl, security.dom_sid('S-2-0-0-512'),security.dom_sid("S-2-0-0"))
+
+    def test_from_sddl_invalidtype1(self):
+        sddl = "O:AOG:DAD:(A;;RPWPCCDCLCSWRCWDWOGA;;;S-1-0-0)"
+        self.assertRaises(TypeError,security.descriptor.from_sddl, sddl,"S-2-0-0")
+
     def test_as_sddl(self):
         text = "O:AOG:DAD:(A;;RPWPCCDCLCSWRCWDWOGA;;;S-1-0-0)"
         dom = security.dom_sid("S-2-0-0")
@@ -67,6 +77,13 @@ class SecurityDescriptorTests(unittest.TestCase):
         self.assertEquals(desc1.sacl, desc2.sacl)
         self.assertEquals(desc1.type, desc2.type)
 
+    def test_as_sddl_invalid(self):
+        text = "O:AOG:DAD:(A;;RPWPCCDCLCSWRCWDWOGA;;;S-1-0-0)"
+        dom = security.dom_sid("S-2-0-0")
+        desc1 = security.descriptor.from_sddl(text, dom)
+        self.assertRaises(TypeError, desc1.as_sddl,text)
+
+
     def test_as_sddl_no_domainsid(self):
         dom = security.dom_sid("S-2-0-0")
         text = "O:AOG:DAD:(A;;RPWPCCDCLCSWRCWDWOGA;;;S-1-0-0)"
diff --git a/source4/librpc/ndr/py_security.c b/source4/librpc/ndr/py_security.c
index 8ab790d..02dc059 100644
--- a/source4/librpc/ndr/py_security.c
+++ b/source4/librpc/ndr/py_security.c
@@ -173,7 +173,7 @@ static PyObject *py_descriptor_from_sddl(PyObject *self, PyObject *args)
 	PyObject *py_sid;
 	struct dom_sid *sid;
 
-	if (!PyArg_ParseTuple(args, "sO", &sddl, &py_sid))
+	if (!PyArg_ParseTuple(args, "sO!", &sddl, &dom_sid_Type, &py_sid))
 		return NULL;
 
 	sid = py_talloc_get_ptr(py_sid);
@@ -195,7 +195,7 @@ static PyObject *py_descriptor_as_sddl(PyObject *self, PyObject *args)
 	char *text;
 	PyObject *ret;
 
-	if (!PyArg_ParseTuple(args, "|O", &py_sid))
+	if (!PyArg_ParseTuple(args, "|O!", &dom_sid_Type, &py_sid))
 		return NULL;
 
 	if (py_sid != Py_None)
-- 
1.6.0.4


--------------010500030008090808040600--


More information about the samba-technical mailing list