2012-09-19 18:33:30 +00:00
|
|
|
diff -up shadow-4.1.5.1/libmisc/chkname.c.goodname shadow-4.1.5.1/libmisc/chkname.c
|
|
|
|
--- shadow-4.1.5.1/libmisc/chkname.c.goodname 2009-07-13 00:24:45.000000000 +0200
|
2014-09-09 15:39:08 +00:00
|
|
|
+++ shadow-4.1.5.1/libmisc/chkname.c 2014-09-09 17:35:17.207303124 +0200
|
|
|
|
@@ -47,27 +47,42 @@
|
|
|
|
#include "chkname.h"
|
|
|
|
|
2012-09-19 18:33:30 +00:00
|
|
|
static bool is_valid_name (const char *name)
|
2014-09-09 15:39:08 +00:00
|
|
|
-{
|
|
|
|
+{
|
2012-09-19 18:33:30 +00:00
|
|
|
/*
|
|
|
|
- * User/group names must match [a-z_][a-z0-9_-]*[$]
|
|
|
|
- */
|
|
|
|
- if (('\0' == *name) ||
|
|
|
|
- !((('a' <= *name) && ('z' >= *name)) || ('_' == *name))) {
|
|
|
|
+ * User/group names must match gnu e-regex:
|
|
|
|
+ * [a-zA-Z0-9_.][a-zA-Z0-9_.-]{0,30}[a-zA-Z0-9_.$-]?
|
|
|
|
+ *
|
|
|
|
+ * as a non-POSIX, extension, allow "$" as the last char for
|
|
|
|
+ * sake of Samba 3.x "add machine script"
|
2014-09-09 15:39:08 +00:00
|
|
|
+ *
|
|
|
|
+ * Also do not allow fully numeric names.
|
2012-09-19 18:33:30 +00:00
|
|
|
+ */
|
2014-09-09 15:39:08 +00:00
|
|
|
+ int numeric;
|
|
|
|
+
|
2012-09-19 18:33:30 +00:00
|
|
|
+ if ( ('\0' == *name) ||
|
|
|
|
+ !((*name >= 'a' && *name <= 'z') ||
|
|
|
|
+ (*name >= 'A' && *name <= 'Z') ||
|
|
|
|
+ (*name >= '0' && *name <= '9') ||
|
|
|
|
+ (*name == '_') || (*name == '.')
|
|
|
|
+ )) {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2014-09-09 15:39:08 +00:00
|
|
|
+ numeric = isdigit(*name);
|
|
|
|
+
|
2012-09-19 18:33:30 +00:00
|
|
|
while ('\0' != *++name) {
|
|
|
|
- if (!(( ('a' <= *name) && ('z' >= *name) ) ||
|
|
|
|
- ( ('0' <= *name) && ('9' >= *name) ) ||
|
|
|
|
- ('_' == *name) ||
|
|
|
|
- ('-' == *name) ||
|
|
|
|
- ( ('$' == *name) && ('\0' == *(name + 1)) )
|
|
|
|
- )) {
|
|
|
|
+ if (!( (*name >= 'a' && *name <= 'z') ||
|
|
|
|
+ (*name >= 'A' && *name <= 'Z') ||
|
|
|
|
+ (*name >= '0' && *name <= '9') ||
|
|
|
|
+ (*name == '_') || (*name == '.') || (*name == '-') ||
|
|
|
|
+ (*name == '$' && *(name + 1) == '\0')
|
|
|
|
+ )) {
|
|
|
|
return false;
|
|
|
|
}
|
2014-09-09 15:39:08 +00:00
|
|
|
+ numeric &= isdigit(*name);
|
2012-09-19 18:33:30 +00:00
|
|
|
}
|
2014-09-09 15:39:08 +00:00
|
|
|
|
|
|
|
- return true;
|
|
|
|
+ return !numeric;
|
|
|
|
}
|
|
|
|
|
|
|
|
bool is_valid_user_name (const char *name)
|
2012-09-19 18:33:30 +00:00
|
|
|
diff -up shadow-4.1.5.1/man/groupadd.8.xml.goodname shadow-4.1.5.1/man/groupadd.8.xml
|
|
|
|
--- shadow-4.1.5.1/man/groupadd.8.xml.goodname 2012-05-25 13:45:27.000000000 +0200
|
2014-09-09 15:39:08 +00:00
|
|
|
+++ shadow-4.1.5.1/man/groupadd.8.xml 2014-09-09 17:28:46.330300342 +0200
|
2012-09-19 18:33:30 +00:00
|
|
|
@@ -259,12 +259,6 @@
|
|
|
|
<refsect1 id='caveats'>
|
|
|
|
<title>CAVEATS</title>
|
|
|
|
<para>
|
|
|
|
- Groupnames must start with a lower case letter or an underscore,
|
|
|
|
- followed by lower case letters, digits, underscores, or dashes.
|
|
|
|
- They can end with a dollar sign.
|
|
|
|
- In regular expression terms: [a-z_][a-z0-9_-]*[$]?
|
|
|
|
- </para>
|
|
|
|
- <para>
|
|
|
|
Groupnames may only be up to &GROUP_NAME_MAX_LENGTH; characters long.
|
|
|
|
</para>
|
|
|
|
<para>
|
|
|
|
diff -up shadow-4.1.5.1/man/useradd.8.xml.goodname shadow-4.1.5.1/man/useradd.8.xml
|
|
|
|
--- shadow-4.1.5.1/man/useradd.8.xml.goodname 2012-05-25 13:45:29.000000000 +0200
|
2014-09-09 15:39:08 +00:00
|
|
|
+++ shadow-4.1.5.1/man/useradd.8.xml 2014-09-09 17:28:46.330300342 +0200
|
2012-09-19 18:33:30 +00:00
|
|
|
@@ -366,7 +366,7 @@
|
|
|
|
</term>
|
|
|
|
<listitem>
|
|
|
|
<para>
|
|
|
|
- Do no create the user's home directory, even if the system
|
|
|
|
+ Do not create the user's home directory, even if the system
|
|
|
|
wide setting from <filename>/etc/login.defs</filename>
|
|
|
|
(<option>CREATE_HOME</option>) is set to
|
|
|
|
<replaceable>yes</replaceable>.
|
|
|
|
@@ -654,12 +654,6 @@
|
|
|
|
</para>
|
|
|
|
|
|
|
|
<para>
|
|
|
|
- Usernames must start with a lower case letter or an underscore,
|
|
|
|
- followed by lower case letters, digits, underscores, or dashes.
|
|
|
|
- They can end with a dollar sign.
|
|
|
|
- In regular expression terms: [a-z_][a-z0-9_-]*[$]?
|
|
|
|
- </para>
|
|
|
|
- <para>
|
|
|
|
Usernames may only be up to 32 characters long.
|
|
|
|
</para>
|
|
|
|
</refsect1>
|