From owner-svn-src-head@freebsd.org Sat Aug 19 01:09:16 2017 Return-Path: Delivered-To: svn-src-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id C416ADE58D1; Sat, 19 Aug 2017 01:09:16 +0000 (UTC) (envelope-from yaneurabeya@gmail.com) Received: from mail-pg0-x22f.google.com (mail-pg0-x22f.google.com [IPv6:2607:f8b0:400e:c05::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 9037E815B0; Sat, 19 Aug 2017 01:09:16 +0000 (UTC) (envelope-from yaneurabeya@gmail.com) Received: by mail-pg0-x22f.google.com with SMTP id n4so10097466pgn.1; Fri, 18 Aug 2017 18:09:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:mime-version:from:in-reply-to:date:cc:message-id:references :to; bh=+AibSXbEROeLc40iq9zylK3qz8IXX022mLR/UFSYpUk=; b=OL+M+RHJFm195VeUTtpJBVs0Ds6xnndJg7y/qYLBKfEVqZhNEH1ychaYXQq37MPPW2 RDAhfyu7EVHIIKwW+vY6M5MpMZuf2HA306uMA0Z0QCqMhHAuqov0vU0AnP1+FHeqZsgV g2kE3BntFEhlqN9ixCL6nwH4Ylg9hbTl761OwKid28JzDlH6OM9voN/sYM7o2pUzfS43 +6AzRNZjiR83l088+vQ5julPbJ/MgJDac+IEvkEtb0ZfEkRVWRZa3wJ7JaW1h5Y5jOhG /VeUNBmbm8mKMCI6Lhs5Ka/ffAI4vHAJCA0imKHFgSt8jkNmMFW5JW3x4+H8xx1UIXrG BDmA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:mime-version:from:in-reply-to:date:cc :message-id:references:to; bh=+AibSXbEROeLc40iq9zylK3qz8IXX022mLR/UFSYpUk=; b=mAhovg4dglX1ApZz/S2xKHNzbL9tbCrX9grm5ibtRU+6L3NiNd/YI1Pie69E16gWPB a2kDtnMHa23SFWXgzFnPYNXS4Hnxg7zjy9I7Awtpi/F9ylS1s6D74vm9x+LLn22waTMi ekBC8KguUtgejyUeBD8gwrsilh3sFAyhUqHGiG1c5R3Ig78029tqQTV0Js76+YO+0ErO crF+knq+9VCbFNqEhWxtMR5gQQQG7jjvBYd+7sMl3vfdImwAGTDjcghNUe3Z1PZL8Qxr 7DM1eXFlNVN9DHlRfkZ+Y6eVtSCNXpLN3GU0ngW6DLKAY+QlS7iQ1VcRBo8I6wNTzaYf 4xGA== X-Gm-Message-State: AHYfb5gZe6WWeJ/U8VgHzTeMWYmwn8xjxoQqPDD7pqqBXtH9ZsxCjeP7 zasgIk+YRCKYeELstvobrw== X-Received: by 10.99.176.4 with SMTP id h4mr9909406pgf.300.1503104955802; Fri, 18 Aug 2017 18:09:15 -0700 (PDT) Received: from [10.9.41.183] ([70.42.240.31]) by smtp.gmail.com with ESMTPSA id a63sm12288909pfc.165.2017.08.18.18.09.13 (version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Fri, 18 Aug 2017 18:09:15 -0700 (PDT) Subject: Re: svn commit: r322678 - in head/usr.sbin/pw: . tests Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\)) Content-Type: multipart/signed; boundary="Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4"; protocol="application/pgp-signature"; micalg=pgp-sha512 X-Pgp-Agent: GPGMail From: "Ngie Cooper (yaneurabeya)" In-Reply-To: <201708190032.v7J0WQAa017551@repo.freebsd.org> Date: Fri, 18 Aug 2017 18:08:54 -0700 Cc: src-committers , svn-src-all@freebsd.org, svn-src-head@freebsd.org Message-Id: References: <201708190032.v7J0WQAa017551@repo.freebsd.org> To: Ed Maste X-Mailer: Apple Mail (2.3124) X-BeenThere: svn-src-head@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the src tree for head/-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 19 Aug 2017 01:09:16 -0000 --Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4 Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=us-ascii > On Aug 18, 2017, at 17:32, Ed Maste wrote: > > Author: emaste > Date: Sat Aug 19 00:32:26 2017 > New Revision: 322678 > URL: https://svnweb.freebsd.org/changeset/base/322678 > > Log: > pw useradd: Validate the user name before creating the entry > > Previouly it was possible to create users with spaces in the name with: > pw useradd -u 1234 -g 1234 -n 'test user' > > The "-g 1234" is relevant, without it the name was already rejected > as expected: > > [fk@test ~]$ sudo pw useradd -u 1234 -n 'test user' > pw: invalid character ` ' at position 4 in userid/group name > > Bug unintentionally found with a salt config without explicit name entry: > > test user: > user.present: > - uid: 1234 > - gid: 1234 > - fullname: Test user > - shell: /usr/local/bin/bash > - home: /home/test > - groups: > - wheel > - salt > > "Luckily" salt modules rarely bother with input validation either ... > > PR: 221416 > Submitted by: Fabian Keil > Obtained from: ElectroBSD > MFC after: 1 week > > Modified: > head/usr.sbin/pw/pw_user.c > head/usr.sbin/pw/tests/pw_useradd_test.sh Usernames with passwords are permitted in some cases, e.g., AD. Thanks, -Ngie --Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJZl4+nAAoJEPWDqSZpMIYVGY0P/0M/T4jiP5+n1Cmqcw4qTJDD SzzAKN4yQxttQrhLYEuACOvWKOwexyBO307+zCluN2Xm0zkMdFY/iUbjr6Z3uQtD HZMcLvp40l1uyQtjXI4Xr3B86ElnYD5PFP0M3h/mjGZ6alG+dzcFUvzu5AItWN4E IaTa2JsGhQoE5u4b00818fO3RnoKRKic8AvJcEfkNTDdZ4hcdluOAWDlyw3sleXy JxoROMcCakkFkHSWcOmTGXw6ud1z4u5oDXWLzzLi+K57JwroATrRDHpzWcaJCxLG NKAvbLvCdBhDEWzfdAnEaEEgtQ9J7By2Au2jZNOqrKKgnwP8XwFd3wgYAgN5A2wF xetdTcE1+Qd0c75AE4++2RKWXYFHqTZLv4K4lv59GR9pX8IQgRWtGOHMWltr/bCj Jn9lmXUYqpBNmPjOyBdBTiMwZ0kfvR1axvFcnUnszwC0+qqGrp82eCw7g0RqT4EF vCwiRoREFNTSNS2pfEhXOWx6Mz+VHt3P1M9nbGaVOeXNyZRaK75uR8ltMGnn5KJq yItVQ2llg050ijpAqoPHdkvf+sPRz38Rrwf1y0jdmua9dtRELzZFCNocczgaZcUp SFG4167v15b9tcTUxtkm724Gh22/lIofdgJqdzstiUfICU4SEa6shPqi+G3t1XPa IVwQtbe68RYVEnZW8zvE =Q4jO -----END PGP SIGNATURE----- --Apple-Mail=_22802188-9797-4792-A343-4BD1D2E4FDF4--