Commit a4aec769 authored by dellis@goetia.(none)'s avatar dellis@goetia.(none)

sql_acl.cc:

  BUG #5831 Revoke privileges in a loop until no more privileges are revoked, because acl_dbs and column_priv_hash can re-organize during privilege removal.
parent 47f63805
...@@ -3623,67 +3623,91 @@ int mysql_revoke_all(THD *thd, List <LEX_USER> &list) ...@@ -3623,67 +3623,91 @@ int mysql_revoke_all(THD *thd, List <LEX_USER> &list)
} }
/* Remove db access privileges */ /* Remove db access privileges */
for (counter= 0 ; counter < acl_dbs.elements ; ) /*
{ Because acl_dbs and column_priv_hash shrink and may re-order
const char *user,*host; as privileges are removed, removal occurs in a repeated loop
until no more privileges are revoked.
acl_db=dynamic_element(&acl_dbs,counter,ACL_DB*); */
if (!(user=acl_db->user)) while (1)
user= ""; {
if (!(host=acl_db->host.hostname)) int revoke= 0;
host= ""; for (counter= 0 ; counter < acl_dbs.elements ; )
if (!strcmp(lex_user->user.str,user) &&
!my_strcasecmp(system_charset_info, lex_user->host.str, host))
{ {
if (replace_db_table(tables[1].table, acl_db->db, *lex_user, ~0, 1)) const char *user,*host;
result= -1;
else acl_db=dynamic_element(&acl_dbs,counter,ACL_DB*);
continue; if (!(user=acl_db->user))
user= "";
if (!(host=acl_db->host.hostname))
host= "";
if (!strcmp(lex_user->user.str,user) &&
!my_strcasecmp(system_charset_info, lex_user->host.str, host))
{
if (replace_db_table(tables[1].table, acl_db->db, *lex_user, ~0, 1))
result= -1;
else
{
revoke= 1;
continue;
}
}
++counter;
} }
++counter; if (!revoke)
break;
} }
/* Remove column access */ /* Remove column access */
for (counter= 0 ; counter < column_priv_hash.records ; ) while (1)
{ {
const char *user,*host; int revoke= 0;
GRANT_TABLE *grant_table= (GRANT_TABLE*) hash_element(&column_priv_hash, for (counter= 0 ; counter < column_priv_hash.records ; )
counter);
if (!(user=grant_table->user))
user= "";
if (!(host=grant_table->host))
host= "";
if (!strcmp(lex_user->user.str,user) &&
!my_strcasecmp(system_charset_info, lex_user->host.str, host))
{ {
if (replace_table_table(thd,grant_table,tables[2].table,*lex_user, const char *user,*host;
grant_table->db, GRANT_TABLE *grant_table= (GRANT_TABLE*)hash_element(&column_priv_hash,
grant_table->tname, counter);
~0, 0, 1)) if (!(user=grant_table->user))
user= "";
if (!(host=grant_table->host))
host= "";
if (!strcmp(lex_user->user.str,user) &&
!my_strcasecmp(system_charset_info, lex_user->host.str, host))
{ {
result= -1; if (replace_table_table(thd,grant_table,tables[2].table,*lex_user,
} grant_table->db,
else grant_table->tname,
{ ~0, 0, 1))
if (grant_table->cols) result= -1;
else
{ {
List<LEX_COLUMN> columns; if (grant_table->cols)
if (replace_column_table(grant_table,tables[3].table, *lex_user, {
columns, List<LEX_COLUMN> columns;
grant_table->db, if (replace_column_table(grant_table,tables[3].table, *lex_user,
grant_table->tname, columns,
~0, 1)) grant_table->db,
result= -1; grant_table->tname,
~0, 1))
result= -1;
else
{
revoke= 1;
continue;
}
}
else else
{
revoke= 1;
continue; continue;
}
} }
else
continue;
} }
++counter;
} }
++counter; if (!revoke)
break;
} }
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment