That handling of '"' in login.defs(5) is undocumented, and doesn't seem
very robust:
name "this value"string
The line above will be taken as if the value was 'this value', with the
remainder completely ignored. Another weird case is:
name value"string
where the value is 'value'.
Since this is undocumented, brittle, and most likely not used, let's
remove it entirely. After all, it's entirely useless.
The following entry
name value string
is interpreted as having a value of 'value string', as one would expect.
The quotations don't provide absolutely any value (they don't serve to
escape any characters) at all, and seem dangerous instead.
Fixes: 45c6603cc86c (2007-10-07; "[svn-upgrade] Integrating new upstream version, shadow (19990709)")
Closes: <https://github.com/shadow-maint/shadow/issues/1674>
Reviewed-by: Iker Pedrosa <ipedrosa@redhat.com>
Signed-off-by: Alejandro Colomar <alx@kernel.org>
if (s == NULL)
continue; /* only 1 field?? */
- value = stpspn(s, " \"\t"); /* next nonwhite */
- stpsep(value, "\"");
+ value = stpspn(s, " \t");
/*
* Store the value in def_table.