Date: Fri, 18 Aug 2017 18:08:54 -0700 From: "Ngie Cooper (yaneurabeya)" <yaneurabeya@gmail.com> To: Ed Maste <emaste@freebsd.org> Cc: src-committers <src-committers@freebsd.org>, svn-src-all@freebsd.org, svn-src-head@freebsd.org Subject: Re: svn commit: r322678 - in head/usr.sbin/pw: . tests Message-ID: <CEE799EF-356D-46F8-BD04-640A4A33EC79@gmail.com> In-Reply-To: <201708190032.v7J0WQAa017551@repo.freebsd.org> References: <201708190032.v7J0WQAa017551@repo.freebsd.org>
next in thread | previous in thread | raw e-mail | index | archive | help
--Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4 Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=us-ascii > On Aug 18, 2017, at 17:32, Ed Maste <emaste@freebsd.org> wrote: > > Author: emaste > Date: Sat Aug 19 00:32:26 2017 > New Revision: 322678 > URL: https://svnweb.freebsd.org/changeset/base/322678 > > Log: > pw useradd: Validate the user name before creating the entry > > Previouly it was possible to create users with spaces in the name with: > pw useradd -u 1234 -g 1234 -n 'test user' > > The "-g 1234" is relevant, without it the name was already rejected > as expected: > > [fk@test ~]$ sudo pw useradd -u 1234 -n 'test user' > pw: invalid character ` ' at position 4 in userid/group name > > Bug unintentionally found with a salt config without explicit name entry: > > test user: > user.present: > - uid: 1234 > - gid: 1234 > - fullname: Test user > - shell: /usr/local/bin/bash > - home: /home/test > - groups: > - wheel > - salt > > "Luckily" salt modules rarely bother with input validation either ... > > PR: 221416 > Submitted by: Fabian Keil > Obtained from: ElectroBSD > MFC after: 1 week > > Modified: > head/usr.sbin/pw/pw_user.c > head/usr.sbin/pw/tests/pw_useradd_test.sh Usernames with passwords are permitted in some cases, e.g., AD. Thanks, -Ngie --Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJZl4+nAAoJEPWDqSZpMIYVGY0P/0M/T4jiP5+n1Cmqcw4qTJDD SzzAKN4yQxttQrhLYEuACOvWKOwexyBO307+zCluN2Xm0zkMdFY/iUbjr6Z3uQtD HZMcLvp40l1uyQtjXI4Xr3B86ElnYD5PFP0M3h/mjGZ6alG+dzcFUvzu5AItWN4E IaTa2JsGhQoE5u4b00818fO3RnoKRKic8AvJcEfkNTDdZ4hcdluOAWDlyw3sleXy JxoROMcCakkFkHSWcOmTGXw6ud1z4u5oDXWLzzLi+K57JwroATrRDHpzWcaJCxLG NKAvbLvCdBhDEWzfdAnEaEEgtQ9J7By2Au2jZNOqrKKgnwP8XwFd3wgYAgN5A2wF xetdTcE1+Qd0c75AE4++2RKWXYFHqTZLv4K4lv59GR9pX8IQgRWtGOHMWltr/bCj Jn9lmXUYqpBNmPjOyBdBTiMwZ0kfvR1axvFcnUnszwC0+qqGrp82eCw7g0RqT4EF vCwiRoREFNTSNS2pfEhXOWx6Mz+VHt3P1M9nbGaVOeXNyZRaK75uR8ltMGnn5KJq yItVQ2llg050ijpAqoPHdkvf+sPRz38Rrwf1y0jdmua9dtRELzZFCNocczgaZcUp SFG4167v15b9tcTUxtkm724Gh22/lIofdgJqdzstiUfICU4SEa6shPqi+G3t1XPa IVwQtbe68RYVEnZW8zvE =Q4jO -----END PGP SIGNATURE----- --Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CEE799EF-356D-46F8-BD04-640A4A33EC79>