valeriyvdovin / rpms / systemd

Forked from rpms/systemd 4 years ago
Clone

Blame SOURCES/0250-basic-user-util-allow-dots-in-user-names.patch

Brian Stinson 2593d8
From 76176de0889c3e8b9b3a176da24e4f8dbbd380a3 Mon Sep 17 00:00:00 2001
Brian Stinson 2593d8
From: Jan Synacek <jsynacek@redhat.com>
Brian Stinson 2593d8
Date: Wed, 2 Oct 2019 11:59:41 +0200
Brian Stinson 2593d8
Subject: [PATCH] basic/user-util: allow dots in user names
Brian Stinson 2593d8
Brian Stinson 2593d8
(based on commit 1a29610f5fa1bcb2eeb37d2c6b79d8d1a6dbb865)
Brian Stinson 2593d8
Brian Stinson 2593d8
Resolves: #1717603
Brian Stinson 2593d8
---
Brian Stinson 2593d8
 src/basic/user-util.c     | 9 ++++++---
Brian Stinson 2593d8
 src/test/test-user-util.c | 8 ++++----
Brian Stinson 2593d8
 2 files changed, 10 insertions(+), 7 deletions(-)
Brian Stinson 2593d8
Brian Stinson 2593d8
diff --git a/src/basic/user-util.c b/src/basic/user-util.c
Brian Stinson 2593d8
index c533f67025..d92969c966 100644
Brian Stinson 2593d8
--- a/src/basic/user-util.c
Brian Stinson 2593d8
+++ b/src/basic/user-util.c
Brian Stinson 2593d8
@@ -575,11 +575,14 @@ bool valid_user_group_name(const char *u) {
Brian Stinson 2593d8
         /* Checks if the specified name is a valid user/group name. Also see POSIX IEEE Std 1003.1-2008, 2016 Edition,
Brian Stinson 2593d8
          * 3.437. We are a bit stricter here however. Specifically we deviate from POSIX rules:
Brian Stinson 2593d8
          *
Brian Stinson 2593d8
-         * - We don't allow any dots (this would break chown syntax which permits dots as user/group name separator)
Brian Stinson 2593d8
          * - We require that names fit into the appropriate utmp field
Brian Stinson 2593d8
          * - We don't allow empty user names
Brian Stinson 2593d8
          *
Brian Stinson 2593d8
          * Note that other systems are even more restrictive, and don't permit underscores or uppercase characters.
Brian Stinson 2593d8
+         *
Brian Stinson 2593d8
+         * jsynacek: We now allow dots in user names. The checks are not exhaustive as user names like "..." are allowed
Brian Stinson 2593d8
+         * and valid according to POSIX, but can't be created using useradd. However, ".user" can be created. Let's not
Brian Stinson 2593d8
+         * complicate the code by adding additional checks for weird corner cases like these,  as they don't really matter here.
Brian Stinson 2593d8
          */
Brian Stinson 2593d8
 
Brian Stinson 2593d8
         if (isempty(u))
Brian Stinson 2593d8
@@ -587,14 +590,14 @@ bool valid_user_group_name(const char *u) {
Brian Stinson 2593d8
 
Brian Stinson 2593d8
         if (!(u[0] >= 'a' && u[0] <= 'z') &&
Brian Stinson 2593d8
             !(u[0] >= 'A' && u[0] <= 'Z') &&
Brian Stinson 2593d8
-            u[0] != '_')
Brian Stinson 2593d8
+            u[0] != '_' && u[0] != '.')
Brian Stinson 2593d8
                 return false;
Brian Stinson 2593d8
 
Brian Stinson 2593d8
         for (i = u+1; *i; i++) {
Brian Stinson 2593d8
                 if (!(*i >= 'a' && *i <= 'z') &&
Brian Stinson 2593d8
                     !(*i >= 'A' && *i <= 'Z') &&
Brian Stinson 2593d8
                     !(*i >= '0' && *i <= '9') &&
Brian Stinson 2593d8
-                    !IN_SET(*i, '_', '-'))
Brian Stinson 2593d8
+                    !IN_SET(*i, '_', '-', '.'))
Brian Stinson 2593d8
                         return false;
Brian Stinson 2593d8
         }
Brian Stinson 2593d8
 
Brian Stinson 2593d8
diff --git a/src/test/test-user-util.c b/src/test/test-user-util.c
Brian Stinson 2593d8
index c1428fab02..9114d30b8c 100644
Brian Stinson 2593d8
--- a/src/test/test-user-util.c
Brian Stinson 2593d8
+++ b/src/test/test-user-util.c
Brian Stinson 2593d8
@@ -71,8 +71,6 @@ static void test_valid_user_group_name(void) {
Brian Stinson 2593d8
         assert_se(!valid_user_group_name("-1"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name("-kkk"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name("rööt"));
Brian Stinson 2593d8
-        assert_se(!valid_user_group_name("."));
Brian Stinson 2593d8
-        assert_se(!valid_user_group_name("eff.eff"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name("foo\nbar"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name("0123456789012345678901234567890123456789"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("aaa:bbb"));
Brian Stinson 2593d8
@@ -83,6 +81,8 @@ static void test_valid_user_group_name(void) {
Brian Stinson 2593d8
         assert_se(valid_user_group_name("_kkk"));
Brian Stinson 2593d8
         assert_se(valid_user_group_name("kkk-"));
Brian Stinson 2593d8
         assert_se(valid_user_group_name("kk-k"));
Brian Stinson 2593d8
+        assert_se(valid_user_group_name(".moo"));
Brian Stinson 2593d8
+        assert_se(valid_user_group_name("eff.eff"));
Brian Stinson 2593d8
 
Brian Stinson 2593d8
         assert_se(valid_user_group_name("some5"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name("5some"));
Brian Stinson 2593d8
@@ -102,8 +102,6 @@ static void test_valid_user_group_name_or_id(void) {
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("-1"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("-kkk"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("rööt"));
Brian Stinson 2593d8
-        assert_se(!valid_user_group_name_or_id("."));
Brian Stinson 2593d8
-        assert_se(!valid_user_group_name_or_id("eff.eff"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("foo\nbar"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("0123456789012345678901234567890123456789"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("aaa:bbb"));
Brian Stinson 2593d8
@@ -114,6 +112,8 @@ static void test_valid_user_group_name_or_id(void) {
Brian Stinson 2593d8
         assert_se(valid_user_group_name_or_id("_kkk"));
Brian Stinson 2593d8
         assert_se(valid_user_group_name_or_id("kkk-"));
Brian Stinson 2593d8
         assert_se(valid_user_group_name_or_id("kk-k"));
Brian Stinson 2593d8
+        assert_se(valid_user_group_name_or_id(".moo"));
Brian Stinson 2593d8
+        assert_se(valid_user_group_name_or_id("eff.eff"));
Brian Stinson 2593d8
 
Brian Stinson 2593d8
         assert_se(valid_user_group_name_or_id("some5"));
Brian Stinson 2593d8
         assert_se(!valid_user_group_name_or_id("5some"));