The problem isn't the format of the usernames, it's that they detected an error, then ignored that the error happened while doing the opposite of what the user wanted. Failing the unit with an error would have been fine. Alternatively, proceeding with the indicated setuid(2) while warning about an invalid username would is also a sane response.
As the owner for a critical service like systemd (I don't use it, I prefer openRC on gentoo), he should know better.
I don't like your name. Therefore you get root.
How on earth did this init system become so prevalent?
* http://jdebp.eu./FGA/debian-systemd-packaging-hoo-hah.html
The Arch process was rather different:
* https://news.ycombinator.com/item?id=11834348
The Debian people did look at who develops the various systems, but they mainly just measured the developer count and what else was on each bandwagon. (See section 3.3 in Russ Allbery's evaluation, for example.) They didn't make any deeper evaluation extending to things such as the way that bugs got responded to in practice or what design steps people were taking to limit bugs.
Neither process was extensive enough to have spotted a User=0pointer gives superuser rights bug.
I didn't see Russ' evaluation, but I get the point.
systemd is a task manager (which happens to manage init along with everything else it can and often cannot). Referring to systemd as an init system is just muddying well-tread waters by people who are lazily misunderstanding the technical issues. The problem with usernames is that there is no standard so schemes are OS specific. It's not really a systemd problem at the core. The systemd problem (because it almost always is badly implemented) is that it uses it's own username validation scheme that defaults to permissive root when the systemd scheme is not matched for configured services. Running on top of heterogeneous environments, you get inconsistent behavior (even when you comply with the OS). This would be like apache spawning handler threads as root if it doesn't like the username it's configured to run as, regardless if the username is valid under OSX and invalid under Fedora. Too bad, username schemes are now dictated by systemd, is Poettering's position.
Yes there is: https://github.com/systemd/systemd/issues/6237#issuecomment-...
In regard to usernames, I can definitely forgive Poettering's initial failure in design to confusion. His assertion that he is following "the standard" fails on both a practical and logical level.
> systemd is not the one coming up with the restrictions on user names, and while some distributions are less restrictive, many do enforce the same restrictions as we do. In order to make systemd unit files portable between systems we'll hence enforce something that resembles more the universally accepted set, rather than accept the most liberal set possible.
These are pretty clear "refuse to fix". Though I do agree that this is a poor example to illustrate the point.