[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Seeking consensus for some changes in adduser



On Thu, 10 Mar 2022 00:01:36 +0000, Seth Arnold
<seth.arnold@canonical.com> wrote:
>On Tue, Mar 08, 2022 at 05:49:04PM +0100, Marc Haber wrote:
>> (2)
>> #774046 #520037
>> Which special characters should we allow for account names?
>
>Please consider the leading character separately from the rest of the
>characters:
>
>- leading digits sometimes causes programs to parse a 'username' as an
>  'user id' instead; you can see some of this here:
>  https://github.com/systemd/systemd/issues/6237
>  I know I've seen more instances of this over the years.
>
>- leading dash may cause the username to be treated as command line
>  options in some programs. I've lost references to this happening.

Should those two restrictions apply for both system and user accounts?
Should they be overrideable?

>While you can argue these are bugs in the programs involved, they do
>happen in the wild. Thus, I'd like to suggest that the regex be more
>restrictive for the first character.

Noted.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | 
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834


Reply to: