From nobody Thu Jul 9 01:23:56 2026 X-Original-To: sysinstall@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gwcgJ5xKtz6lD9R for ; Thu, 09 Jul 2026 01:23:56 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gwcgJ2dtqz3qxq for ; Thu, 09 Jul 2026 01:23:56 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1783560236; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=smuNv8dRWZI76Q9gj2Npy7a3AZrMMyf/Ezr5AwxzFcs=; b=gulDeJaDWwsSvU3/MSy44qXmluL0JW6oLzLNOLuAY+UX9Lc1NHnF5L046L61HTDDtSx1Wq kolpzUItViO4dc4GnqdnGTGffdUGiZnc8Dr3lBZV4uE/mEWF3vSNOA6V6ZtsPybbX+/Vrk io+Mrl2H3PJVJEYDpUN4lSnsw22BT0wsfvAk9uIvMs56tFHxGRtnQpCKTgcGJAvcH7jAwQ X6A9WfS/zQYXX69WXN0JZdFDom0zbXtaYWAcXyGZbnUGpFqaixfQi5qA5UzsouiBVVrcUV EomVXe0OdbtOtKu+QQzeHahADARKzHyh7vxwrD7EhCcENT/azfaGM1nxxEHK8A== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1783560236; a=rsa-sha256; cv=none; b=LJIIWilhPWyxE/C99zABlEFOlYGwwbXZDyiKRpm6sb5awhfo0bZGECQbE/PQqM2QBlwd16 n2Etp0GvpzYVdOqinRx78TyiIT8oi3vbjMgpqgn8b3ncvOVyEfjxdryBIzuChD+byLSIyt 5xaVl4Ft6IEqDs150AalhPjgo/soA7XvGMNbBKLs055GRuX6bvX1l72TaNOQMgNeHJvGNf 0KSgPxBiyB5ikSL+AOVncSitrXAhqlIG5fvbPoWkvW3/3kOiRZVmXMGWYD3jbaYF+VAfYy ZqsnyT6VZraEnJqCgJDGuga8O7RY9g39QwFU4dvn6jC2NToDApShEJe/49hCNQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1783560236; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=smuNv8dRWZI76Q9gj2Npy7a3AZrMMyf/Ezr5AwxzFcs=; b=YYZhaBfE9RT2O9HH6zdsT1WcREe4Vej8uN9vJhdH75aP2vfBrP6SUqRN2lRdwr6UYm8DC7 PQ3moSy1cgxBqaI4k3juhfMDD4XxMV+RFeep3Mpve8b5+qHQSoymFfT4mFkXqY7i8COUiK Q28xAfgicEEIcYxgIFkPaBNjHguq3XCaYtdRAp5K9yctikdtZ7gs9284KPw2Zvap0pEGVb +cyKPS67egyAs3jStcebZCVTnsAXWnwVFcZa7L8L53gzXz+BJKi1wMt+y7fBLTgf2W7Gvw UZ56/rnQvRXl7yNqdGP4GJFFFU0epJ2zY74K6T7qj44qC5z15r5PrOiA4Us/fw== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4gwcgJ1T76znRS for ; Thu, 09 Jul 2026 01:23:56 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 6691NukD008083 for ; Thu, 9 Jul 2026 01:23:56 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 6691NuK4008082 for sysinstall@FreeBSD.org; Thu, 9 Jul 2026 01:23:56 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: sysinstall@FreeBSD.org Subject: [Bug 295428] Installer: root password truncates to 32 characters Date: Thu, 09 Jul 2026 01:23:56 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: bin X-Bugzilla-Version: 16.0-CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: dteske@FreeBSD.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: sysinstall@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Sysinstall Work List-Archive: https://lists.freebsd.org/archives/freebsd-sysinstall List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-sysinstall@freebsd.org Sender: owner-freebsd-sysinstall@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D295428 --- Comment #1 from Devin Teske --- Investigated and problem appears to be here: https://cgit.freebsd.org/src/tree/usr.sbin/bsdinstall/scripts/rootpass#n99 https://cgit.freebsd.org/src/tree/usr.sbin/bsdinstall/scripts/rootpass#n100 ``` "Password" 0 0 '' 0 17 32 32 \ "Repeat password" 1 0 '' 1 17 32 32 \ ``` Wherein 32 is interpreted by the invocation of bsddialog (shown below) ``` bsddialog ... --passwordform ... ``` as `fieldlen` and `maxletters` as-documented in `man bsddialog`: ``` --passwordform text rows cols formrows [label ylabel xlabel init yfield xfield fieldlen maxletters] ... ``` And the POLA violation that is afoot here is that (you can see) nowhere in = the invocation is the user told that their password is going to be truncated to= 32 characters. Now, as you are typing, you see asterisks (*) [because --insecure is passed] and because fieldlen and maxletters is the same number, the user has no vis= ual indication that their keystrokes have reached a limit. ``` output=3D$(bsddialog --backtitle "$OSNAME Installer" \ --title "Set $username password" \ --cancel-label "Skip" \ --passwordform --insecure \ "Please select a password for the system management account ($username) $errormsg" \ 0 0 2 \ "Password" 0 0 '' 0 17 32 32 \ "Repeat password" 1 0 '' 1 17 32 32 \ 2>&1 1>&5) ``` Put quite simply, user starts typing, field starts filling with asterisks, field fills completely with asterisks, and user continues typing thinking t= hat their keystrokes are continuing to register. However, when the user hits enter, no error is generated and instead the in= put is (to the user's perception) truncated and when they boot to the login pro= mpt, they will be (as I was) astonished that their password does not work. On a hunch alone, I (as stated previously) started truncating my password u= ntil it let me in. Simply making fieldlen greater than maxletters would have generated a user interface that would have communicated to the user that their additional keystrokes beyond maxletters were being ignored and not registering. On top= of that user experience change, putting in the dialog text to the effect of "limited to N characters" would have further communicated why the behavior = was such that an unlimited number of characters will not register. This can be tested by changing the test-invocation below (that replicates t= he installer prompt): ``` bsddialog --backtitle "FreeBSD Installer" --title "Set root password" --cancel-label "Skip" --passwordform --insecure "Please select a password f= or the system management account (root) " 0 0 2 "Password" 0 0 '' 0 17 32 32 "Repeat Password" 1 0 '' 1 17 32 32 ``` to instead pass `33 32` such as below: ``` bsddialog --backtitle "FreeBSD Installer" --title "Set root password" --cancel-label "Skip" --passwordform --insecure "Please select a password f= or the system management account (root) " 0 0 2 "Password" 0 0 '' 0 17 33 32 "Repeat Password" 1 0 '' 1 17 33 32 ``` However, that doesn't quite do it. What it does is reveal yet another bug. When you get to the 32'nd character of input, the cursor stops moving forwa= rd (good; indicating you've reached the max) and the cursor is stopped before = the end of the field (also good). However, when you press backspace, you expect= the 32'nd character to be removed. That is not what happens. Because the cursor did not advance to the next position when the max is hit= and backspace causes the character immediately to the left of the cursor to be deleted, the 31'st character is removed. Put quite simply, if you use the above invocation which has 33 fieldlen and= 32 maxletters and enter: 12345678901234567890123456789012 Then press backspace followed by ENTER, you get: 1234567890123456789012345678902 So it is clear that bsddialog is not tracking when it has reached maxletter= s to artificially remove the last character but keep the cursor stationary so th= at the rather astonishing removal of the second-to-last character does not occ= ur. This is of course all entirely orthogonal to displaying to the user what the maximum is. I say this because naturally we will want to support more than fieldlen letters/characters, and there is no indication whatsoever that the maximum has been reached. This fact will remain whether we omit --secure or not. The good: There is a *very* subtle indication when fieldlen>maxletters that the max h= as been hit, and that is when an '*' appears under the cursor instead of immediately to the left (applies only when --insecure is given). The bad: Few will be paying that close of attention to notice it, and even if they d= o, if they choose to backspace, then you hit the second bug and start removing all-but the last character typed (which is tantamount to corrupting the inp= ut because without seeing the characters, there's no indication to the user th= at the input is nor malformed). There is of course only one workaround and tha= t is to use the arrow keys to advance the cursor to the right after first deleti= ng the maxletters'th character and then delete one additional character to take the input to maxletters-2. --=20 You are receiving this mail because: You are the assignee for the bug.=