From owner-freebsd-security Fri Jun 26 05:32:58 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id FAA28842 for freebsd-security-outgoing; Fri, 26 Jun 1998 05:32:58 -0700 (PDT) (envelope-from owner-freebsd-security@FreeBSD.ORG) Received: from baerenklau.de.freebsd.org (baerenklau.de.freebsd.org [195.185.195.14]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id FAA28820 for ; Fri, 26 Jun 1998 05:32:44 -0700 (PDT) (envelope-from wosch@panke.de.freebsd.org) Received: (from uucp@localhost) by baerenklau.de.freebsd.org (8.8.8/8.8.8) with UUCP id OAA06569; Fri, 26 Jun 1998 14:30:58 +0200 (CEST) (envelope-from wosch@panke.de.freebsd.org) Received: (from wosch@localhost) by campa.panke.de (8.8.8/8.8.8) id OAA01431; Fri, 26 Jun 1998 14:23:08 +0200 (MET DST) (envelope-from wosch) Message-ID: <19980626142307.02422@panke.de> Date: Fri, 26 Jun 1998 14:23:07 +0200 From: Wolfram Schneider To: Peter Jeremy Cc: freebsd-security@FreeBSD.ORG Subject: Re: adduser chmod permissions References: <199806250059.KAA02884@gsms01.alcatel.com.au> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Mailer: Mutt 0.79 In-Reply-To: <199806250059.KAA02884@gsms01.alcatel.com.au>; from Peter Jeremy on Thu, Jun 25, 1998 at 10:59:08AM +1000 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On 1998-06-25 10:59:08 +1000, Peter Jeremy wrote: > >> - /etc/group is limited to 1024 char lines and no more than 200 users > >> per group. > >This was fixed 18 months ago in > >src/lib/libc/gen/getgrent.c rev 1.14 > > Looking through CVSROOT/src/lib/libc/gen/getgrent.c,v the CVS log does > say that. It also says `Not a 2.2 candidate' and the relevant code > does not appear to be in the 2.2.6-RELEASE version of > src/lib/libc/gen/getgrent.c :-(. > > FWIW, the other places I found that appear to impose these limits (at > least in 2.2.6-RELEASE) are src/libexec/mknetid/parse_group.c, > src/usr.sbin/pw/pw.h and src/usr.sbin/pw/pwupd.h. > > Why 18-month old code hasn't been moved from -current into -stable, I > can't say... Because it is a new feature and -stable is only for bugfixes. IMHO. A merge from current requires a lot of testing - the group database is a critical part of the OS. I don't have the time and the resources to do that. -- Wolfram Schneider http://www.freebsd.org/~w/ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe security" in the body of the message