s4:objectclass LDB module - fix the "crossRef" delete protection
authorMatthias Dieter Wallnöfer <mdw@samba.org>
Sat, 25 Sep 2010 10:02:53 +0000 (12:02 +0200)
committerMatthias Dieter Wallnöfer <mdw@sn-devel-104.sn.samba.org>
Sun, 3 Oct 2010 15:23:18 +0000 (15:23 +0000)
This is what Windows does

Signed-off-by: Andrew Bartlett <abartlet@samba.org>
source4/dsdb/samdb/ldb_modules/objectclass.c

index 9ff20319b6e90f90036c8cae83fca556a980690b..11d61af44661dbdd311c9c0a98bb4e47e80e964f 100644 (file)
@@ -1423,11 +1423,17 @@ static int objectclass_do_delete(struct oc_context *ac)
                dn = ldb_msg_find_attr_as_dn(ldb, ac, ac->search_res->message,
                                             "nCName");
                if ((ldb_dn_compare(dn, ldb_get_default_basedn(ldb)) == 0) ||
-                   (ldb_dn_compare(dn, ldb_get_config_basedn(ldb)) == 0) ||
-                   (ldb_dn_compare(dn, ldb_get_schema_basedn(ldb)) == 0)) {
+                   (ldb_dn_compare(dn, ldb_get_config_basedn(ldb)) == 0)) {
                        talloc_free(dn);
 
-                       ldb_asprintf_errstring(ldb, "objectclass: Cannot delete %s, it's a crossRef object to the three main partitions!",
+                       ldb_asprintf_errstring(ldb, "objectclass: Cannot delete %s, it's a crossRef object to the main or configuration partition!",
+                                              ldb_dn_get_linearized(ac->req->op.del.dn));
+                       return LDB_ERR_NOT_ALLOWED_ON_NON_LEAF;
+               }
+               if (ldb_dn_compare(dn, ldb_get_schema_basedn(ldb)) == 0) {
+                       talloc_free(dn);
+
+                       ldb_asprintf_errstring(ldb, "objectclass: Cannot delete %s, it's a crossRef object to the schema partition!",
                                               ldb_dn_get_linearized(ac->req->op.del.dn));
                        return LDB_ERR_UNWILLING_TO_PERFORM;
                }