ubusd: allow all object access if uid=0 (ignore gid)
[project/ubus.git] / ubusd_acl.c
index 9f0f0fc..eb5cec5 100644 (file)
@@ -101,7 +101,7 @@ ubusd_acl_check(struct ubus_client *cl, const char *obj,
        struct blob_attr *cur;
        int rem;
 
-       if (!cl->gid && !cl->uid)
+       if (!cl->uid)
                return 0;
 
        acl = avl_find_ge_element(&ubusd_acls, obj, acl, avl);
@@ -413,26 +413,28 @@ ubusd_reply_add(struct ubus_object *obj)
 
        if (!obj->path.key)
                return;
+
        acl = avl_find_ge_element(&ubusd_acls, obj->path.key, acl, avl);
-       while (acl && !avl_is_last(&ubusd_acls, &acl->avl) &&
-                     !ubusd_acl_match_path(obj->path.key, acl->avl.key, NULL)) {
+       avl_for_element_to_last(&ubusd_acls, acl, acl, avl) {
+               void *c;
+
+               if (!acl->priv)
+                       continue;
 
-               if (acl->priv) {
-                       void *c = blobmsg_open_table(&b, NULL);
+               if (!ubusd_acl_match_path(obj->path.key, acl->avl.key, NULL))
+                       continue;
 
-                       blobmsg_add_string(&b, "obj", obj->path.key);
-                       if (acl->user)
-                               blobmsg_add_string(&b, "user", acl->user);
-                       if (acl->group)
-                               blobmsg_add_string(&b, "group", acl->group);
+               c = blobmsg_open_table(&b, NULL);
+               blobmsg_add_string(&b, "obj", obj->path.key);
+               if (acl->user)
+                       blobmsg_add_string(&b, "user", acl->user);
+               if (acl->group)
+                       blobmsg_add_string(&b, "group", acl->group);
 
-                       if (acl->priv)
-                               blobmsg_add_field(&b, blobmsg_type(acl->priv), "acl",
-                                       blobmsg_data(acl->priv), blobmsg_data_len(acl->priv));
+               blobmsg_add_field(&b, blobmsg_type(acl->priv), "acl",
+                       blobmsg_data(acl->priv), blobmsg_data_len(acl->priv));
 
-                       blobmsg_close_table(&b, c);
-               }
-               acl = avl_next_element(acl, avl);
+               blobmsg_close_table(&b, c);
        }
 }
 static int ubusd_reply_query(struct ubus_client *cl, struct ubus_msg_buf *ub, struct blob_attr **attr, struct blob_attr *msg)