diff options
author | Lennart Poettering <lennart@poettering.net> | 2016-12-27 17:59:21 +0100 |
---|---|---|
committer | Lennart Poettering <lennart@poettering.net> | 2016-12-27 18:09:58 +0100 |
commit | 1429dfe5f8d0e4d2dcc73d1702510697880a46de (patch) | |
tree | 3c0d87718c99cebce33bd52e035002e13e30ad48 /src/basic | |
parent | 27e2e3231fc1edbbaa9f73be363900701ab4598d (diff) |
util-lib: add a comment explaining the user name rules we enforce
Diffstat (limited to 'src/basic')
-rw-r--r-- | src/basic/user-util.c | 12 |
1 files changed, 11 insertions, 1 deletions
diff --git a/src/basic/user-util.c b/src/basic/user-util.c index 938533d2e7..c619dad527 100644 --- a/src/basic/user-util.c +++ b/src/basic/user-util.c @@ -46,6 +46,8 @@ bool uid_is_valid(uid_t uid) { + /* Also see POSIX IEEE Std 1003.1-2008, 2016 Edition, 3.436. */ + /* Some libc APIs use UID_INVALID as special placeholder */ if (uid == (uid_t) UINT32_C(0xFFFFFFFF)) return false; @@ -519,7 +521,15 @@ bool valid_user_group_name(const char *u) { const char *i; long sz; - /* Checks if the specified name is a valid user/group name. */ + /* Checks if the specified name is a valid user/group name. Also see POSIX IEEE Std 1003.1-2008, 2016 Edition, + * 3.437. We are a bit stricter here however. Specifically we deviate from POSIX rules: + * + * - We don't allow any dots (this would break chown syntax which permits dots as user/group name separator) + * - We require that names fit into the appropriate utmp field + * - We don't allow empty user names + * + * Note that other systems are even more restrictive, and don't permit underscores or uppercase characters. + */ if (isempty(u)) return false; |