Bug 16157 - POSIX ACL backend doesn't apply DENY ACE for S-1-1-0 to all ALLOW ACE
Summary: POSIX ACL backend doesn't apply DENY ACE for S-1-1-0 to all ALLOW ACE
Status: NEW
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: File services (show other bugs)
Version: unspecified
Hardware: All All
: P5 normal (vote)
Target Milestone: ---
Assignee: Samba QA Contact
QA Contact: Samba QA Contact
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2026-07-03 09:49 UTC by Ralph Böhme
Modified: 2026-07-03 09:49 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ralph Böhme 2026-07-03 09:49:17 UTC
When setting an ACL that includes a DENY ACE for S-1-1-0, in merge_aces() we don't correctly apply that to all ALLOW ACEs when merging. There are two problems:

- we don't check for S-1-1-0 at all and

- we stop the loop after the first match