]> git.ipfire.org Git - thirdparty/shadow.git/commitdiff
lib/getdef.c: def_load(): Don't handle '"' specially master
authorAlejandro Colomar <alx@kernel.org>
Tue, 14 Jul 2026 12:40:43 +0000 (14:40 +0200)
committerAlejandro Colomar <foss+github@alejandro-colomar.es>
Thu, 30 Jul 2026 11:51:22 +0000 (13:51 +0200)
That handling of '"' in login.defs(5) is undocumented, and doesn't seem
very robust:

name  "this value"string

The line above will be taken as if the value was 'this value', with the
remainder completely ignored.  Another weird case is:

name value"string

where the value is 'value'.

Since this is undocumented, brittle, and most likely not used, let's
remove it entirely.  After all, it's entirely useless.

The following entry

name value string

is interpreted as having a value of 'value string', as one would expect.
The quotations don't provide absolutely any value (they don't serve to
escape any characters) at all, and seem dangerous instead.

Fixes: 45c6603cc86c (2007-10-07; "[svn-upgrade] Integrating new upstream version, shadow (19990709)")
Closes: <https://github.com/shadow-maint/shadow/issues/1674>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Signed-off-by: Alejandro Colomar <alx@kernel.org>
lib/getdef.c

index 4616b65efe5e02107d80de22e1130c66f195a595..113397f851a85993ecf16415af5fbc804217714f 100644 (file)
@@ -574,8 +574,7 @@ static void def_load (void)
                if (s == NULL)
                        continue;       /* only 1 field?? */
 
-               value = stpspn(s, " \"\t");     /* next nonwhite */
-               stpsep(value, "\"");
+               value = stpspn(s, " \t");
 
                /*
                 * Store the value in def_table.