Systemd’s “usernames that start with digit get root privileges” bug
ma.ttias.be
ma.ttias.be
"Should this be fixed? Yes, it's an obvious bug"
The author of systemd says:
"So, yeah, I don't think there's anything to fix in systemd here. I understand this is annoying, but still: the username is clearly not valid."
And that's basically the problem. Not that the bug exists. But the systemd author doesn't recognize it as such, and refuses to fix it. This seems to be a recurring theme with systemd.
> the username is clearly not valid.
It was, until systemd said it wasn't."Usernames must start with a lower case letter or an underscore, followed by lower case letters, digits, underscores, or dashes. They can end with a dollar sign. In regular expression terms: [a-z_][a-z0-9_-]*[$]?"
It is usually recommended to only use usernames that begin with a lower case letter or an underscore, followed by lower case letters, digits, underscores, or
dashes. They can end with a dollar sign. In regular expression terms: [a-z_][a-z0-9_-]*[$]?
On Debian, the only constraints are that usernames must neither start with a dash ('-') nor plus ('+') nor tilde ('~') nor contain a colon (':'), a comma (','),
or a whitespace (space: ' ', end of line: '\n', tabulation: '\t', etc.). Note that using a slash ('/') may break the default algorithm for the definition of the
user's home directory.(Not much point in continuing this, since the post has dropped from front page to 7th in half an hour, and will never be seen again.)
* http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_...
* http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_...
Valid portable user names can have digits and letters intermixed. They are simply restricted to not starting with a minus.
* https://github.com/systemd/systemd/issues/6237 (https://news.ycombinator.com/item?id=14681377)
In the actual bug report, as opposed to Mattias Geniar's article headlined here, this is already mentioned.
What happens when admin typos a username in this fashion? The system they think is conforming to least privilege suddenly is granting most privilege. Thanks systemd!
It's like the code is as self-righteous as its author.
They assume that the program is running as a user with limited privileges. Then, an exploit gets found in that program, and now instead of an attacker gaining user-level access, they now have root-level access.
By far the most worrying part of the issue for me was that the developers said "oh it's not a bug" and just closed the issue, without properly thinking through the implications of the behaviour (such as the other attack vectors mentioned here). That's gross negligence.
I experienced one first hand, a definition in fstab for a removable drive suddenly (after a systemd update and no warning) caused the computer to fail at boot time because the removable drive was not present. The fun part is that the emergency shell had a bug too that prevented itself from starting and looped to infinity instead.
It was nice to have to drive 6h each way to deal with this systemd new "feature".
> There's a new systemd bug that gets the haters aroused!
Oiy... I feel like I am walking into the middle of a Vim/Emacs flame war. Very unfortunate.
[0] https://www.freedesktop.org/software/systemd/man/systemd.uni...
[EDIT] As noted downstream, the parsing error causes the 'User=' directive to just be ignored, so a user unit file will be run by the user. Still too many vectors of attack, sadly.
Why should it? The bug is not that it runs as root but that it encounters a parsing error and uses the default. The default for root is root and the default for user A is user A.
Thank you for the correct, if condescending, answer. It was unclear from the original bug, or this article, if it was falling back on a hardcoded 0 or the user used when the directive is not present.
Since systemd's own behavior is inconsistent, I can't depend on that behavior to derive the reasonable answer. That inconsistency stems from the fact that a "valid" user name that doesn't exist triggers different behavior than an "invalid" user name; and the definition of "valid" is different between systemd and the rest of Linux.
There are no words. How can someone so obviously incompetent be in charge of such an important open source project? Unless he's hired by some 3-letter agency to leave as many security holes in systemd as possible.
For example, on some shared clusters I used there was a capability to request a service run as your user. This was before systemd at the time so it would end up generating an /etc/init.d entry, but I imagine a modern equivalent might generate a unit file.
So this article downplays the vulnerability a bit by claiming you have to trick a sysadmin when you could actually just use an automated service management system.
If you mangle the dependency chain in any way, you are likely to find yourself looking at the emergency console.
UNIX is all about small, composable tools. Do one job and do it well.
One of these tools didn't stand up to the test of time (SysV init) and needed to be replaced.
We could have chosen one of the mature candidates (upstart, runit, minit) or even built a great new one from scratch. Life would have been good.
But instead we ended up with this trainwreck of a monolith that not only replaced init, but at the same time tried to reinvent almost every critical userspace daemon from Syslog to NTP.
It predictably failed on every metric.
Now it is time for the major Linux distributions to conclude this experiment, roll back the Systemd mistake and return to the modularity that made UNIX successful.
We get to choose between Emacs/Vim, Perl/Python, Syslog-ng/RSyslog, ntpd/openntpd and so on.
This has resulted in multiple mature implementations for every core system task.
Yet instead of sticking with this code that has stood the test of time over decades, we threw it all out for a poorly written jack of all trades that gives root to usernames starting with a digit...
systemd as a package is more than just init.
It is init, inetd, session manager (logind), udev, dns client, dhcp client, cron, su, and the list keeps growing.
Basic thing is that first of all Poettering to it a toehold at Fedora (he works at Red Hat, so surprise surprise). Then he offered Gnome the code for supporting logind on a silver platter.
End result is that to offer Gnome as the desktop you either have to patch it, shim it (ask Canonical how well that worked out) or adopt systemd.
Effectively what is happening is that Fedora is becoming the de-facto standard for Linux. In part because it is effectively the testing distro for Red Hat Enterprise Linux, and thus a large portion of userland devs (and a number of kernel devs) use it as their "dogfood".
That said, refusing to run the unit would be a better default behavior.
Gobolinux as a joke used to ship with user 0 named gobo rather than root, but i think they stopped doing so because it broke certain scripts etc that assumed root and 0 was equivalent.
I don't even want to know how their code is written so that it allows such error to happen and remain undetected.
Are you saying everyone you disagree with is "gamer gate"?
And gamersgate lost media attention, my impression that a sizeable chunk of that mob has latched onto systemd as their target.
The problem is that the people being harassed can't separate the harassers from the people voicing actual complaints, lumping them all into the trolls/haters bin.
And frankly gamersgate was just the "peak" of a sorts, the root of it all lay further back. It is basically a mutated, nastier, form of the antics done under the "anonymous" moniker.
I am not a gamer, I have never trolled. I am a sysadmin in an 11,000+ person organisation and I have qualms with systemd.
And frankly speaking, proponents of systemd usually fobbed us off by saying that we're dinosaurs. Or intentionally misrepresenting our arguments.
Now we're being fobbed off as being some weird gaming industry crap? No.
I think there are legitimate complaints against systemd.
but at the same time i also think there is harassment going on.
From our side of the fence it is easy to tell the two apart.
But from the systemd developer side, and apparently also the systemd proponent side, the two intermix.
This akin to how hooligans join protest marches simply to start fights and riots, knowing it will be blamed on the legitimate protesters.
To be clear, I'm not objecting to potshots taken at either; /g/ is trash, and whining about vidya gaem journalism is childish and stupid - and lashing out viciously at people who work in the field is worse by far than that. I'm just saying it's worth checking your target first.