4 ms·
The article says: "Should this be fixed? Yes, it's an obvious bug" The author of systemd says: "So, yeah, I don't think there's anything to fix in systemd he
by comstock 9y ago
The article says:
"Should this be fixed? Yes, it's an obvious bug"
The author of systemd says:
"So, yeah, I don't think there's anything to fix in systemd here. I understand this is annoying, but still: the username is clearly not valid."
And that's basically the problem. Not that the bug exists. But the systemd author doesn't recognize it as such, and refuses to fix it. This seems to be a recurring theme with systemd.
- kps 9y ago> the username is clearly not valid. It was, until systemd said it wasn't.
- rnhmjoj 9y agoI understand the criticism towards systemd but let's not start making things up. From useradd (8) manual: "Usernames must start with a lower case letter or an underscore, followed by lower case letters, digits, underscores, or dashes. They can end with a dollar sign. In regular expression terms: [a-z_][a-z0-9_-]*[$]?"
- dlgtho 9y agoMine(Ubuntu) differs: It is usually recommended to only use usernames that begin with a lower case letter or an underscore, followed by lower case letters, digits, underscores, or dashes. They can end with a dollar sign. In regular expression terms: [a-z_][a-z0-9_-]*[$]? On Debian, the only constraints are that usernames must neither start with a dash ('-') nor plus ('+') nor tilde ('~') nor contain a colon (':'), a comma (','), or a whitespace (space: ' ', end of line: '\n', tabulation: '\t', etc.). Note that using a slash ('/') may break the default algorithm for the definition of the user's home directory.
- kps 9y agoAs dlgtho notes, your system's useradd(8) man page is not a description of all existing systems. Historically, the prohibitions were against ‘:’ (breaks passwd(5)), initial ‘-’ (mistaken for an option by login(1)), and upper case without lower case (makes getty(8) think you have an upper-case-only terminal). (Not much point in continuing this, since the post has dropped from front page to 7th in half an hour, and will never be seen again.)
- rnhmjoj 9y agoMy bad, I though this was somewhat standard.
- JdeBP 9y agoWhat the standards say supports that assertion even less than what the other manual pages say. There is a standard for this. It is IEEE 1003.1 a.k.a. The Single Unix Specification. * http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap03.html#tag_03_437 http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_... * http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap03.html#tag_03_282 http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_... Valid portable user names can have digits and letters intermixed. They are simply restricted to not starting with a minus. * https://github.com/systemd/systemd/issues/6237 https://github.com/systemd/systemd/issues/6237 (https://news.ycombinator.com/item?id=14681377 https://news.ycombinator.com/item?id=14681377) In the actual bug report, as opposed to Mattias Geniar's article headlined here, this is already mentioned.
- CodeWriter23 9y agoSo in that case, when systemd encounters a username it is rejecting, it should throw an error instead of launching the process as root. What happens when admin typos a username in this fashion? The system they think is conforming to least privilege suddenly is granting most privilege. Thanks systemd! It's like the code is as self-righteous as its author.
- lordlimecat 9y agoThis very article demonstrates that the largest enterprise Linux distros -- Red Hat and CentOS 7.3-- both recognize and support usernames beginning with a digit.