2008-03-19 23:15:55 +00:00
|
|
|
/* vi: set sw=4 ts=4: */
|
|
|
|
/*
|
2009-03-31 13:14:18 +00:00
|
|
|
* Check user and group names for illegal characters
|
2008-03-19 23:15:55 +00:00
|
|
|
*
|
|
|
|
* Copyright (C) 2008 Tito Ragusa <farmatito@tiscali.it>
|
|
|
|
*
|
|
|
|
* Licensed under GPLv2 or later, see file LICENSE in this tarball for details.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "libbb.h"
|
|
|
|
|
|
|
|
/* To avoid problems, the username should consist only of
|
|
|
|
* letters, digits, underscores, periods, at signs and dashes,
|
|
|
|
* and not start with a dash (as defined by IEEE Std 1003.1-2001).
|
|
|
|
* For compatibility with Samba machine accounts $ is also supported
|
|
|
|
* at the end of the username.
|
|
|
|
*/
|
|
|
|
|
2008-06-27 02:52:20 +00:00
|
|
|
void FAST_FUNC die_if_bad_username(const char *name)
|
2008-03-19 23:15:55 +00:00
|
|
|
{
|
2010-02-06 20:50:59 +00:00
|
|
|
/* 1st char being dash or dot isn't valid: */
|
|
|
|
goto skip;
|
|
|
|
/* For example, name like ".." can make adduser
|
|
|
|
* chown "/home/.." recursively - NOT GOOD
|
|
|
|
*/
|
|
|
|
|
2008-03-19 23:15:55 +00:00
|
|
|
do {
|
2010-02-06 20:50:59 +00:00
|
|
|
if (*name == '-' || *name == '.')
|
2008-03-19 23:25:00 +00:00
|
|
|
continue;
|
|
|
|
skip:
|
|
|
|
if (isalnum(*name)
|
|
|
|
|| *name == '_'
|
|
|
|
|| *name == '@'
|
2010-02-06 20:50:59 +00:00
|
|
|
|| (*name == '$' && !name[1])
|
2008-03-19 23:25:00 +00:00
|
|
|
) {
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
bb_error_msg_and_die("illegal character '%c'", *name);
|
2008-03-19 23:15:55 +00:00
|
|
|
} while (*++name);
|
|
|
|
}
|