Really? That's the fix?
A proper fix is to use "--" to separate arguments.
Really? That's the fix?
A proper fix is to use "--" to separate arguments.
Still, requesting the information from systemd-userdb would be a better way of doing this if it's really necessary.
EDIT: Yeah, some older comments confirm that was their reasoning. https://github.com/tailscale/tailscale/commit/1fc1077052dfa7...
A better fix is to call “getent passwd” with no user controlled arguments and then parse the resulting list. This gets rid of the input sanitization problem entirely.
Reference: https://gitlab.alpinelinux.org/alpine/aports/-/blob/master/m...
Your answer is mostly correct, except that when you tug on that thread the shelf comes off the wall, the plaster comes with it, and then it cracks the water pipes on the way to the floor.
Refactoring external invocations to use safe argument handling is a better way to fix it. Along with tests that exercise weird names.
If so, this is kind of an understandably ugly problem, though there is still a better option than shelling out -- systemd-userdb.
The username policy fixes this issue for good, regardless of whatever you write in the future, or whatever new mechanism is introduced.
It’s a restriction for sure, but it’s not a nonsense restriction? Who would have a username starting with a hyphen? I didn’t even know it was possible until today.
The better fix would be to not have the username pass through a parser looking for cli flags in the first place.