Refresh patches, drop upstream-applied chkhask patches

This commit is contained in:
Chris Hofstaedtler
2026-01-25 14:18:28 +01:00
parent 0f9a3e27ea
commit 63645e1b11
5 changed files with 2 additions and 82 deletions
@@ -80,7 +80,7 @@ index bbc9859..5446f35 100644
case 'c':
if (!VALID (optarg)) {
diff --git a/src/usermod.c b/src/usermod.c
index e8c9da6..dc88776 100644
index e26f011..f0f6234 100644
--- a/src/usermod.c
+++ b/src/usermod.c
@@ -396,7 +396,7 @@ usage (int status)
@@ -9,7 +9,7 @@ Reported as https://github.com/shadow-maint/shadow/issues/1229
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
index b3dd34d..bbda154 100644
index 7727d1c..b5114e8 100644
--- a/configure.ac
+++ b/configure.ac
@@ -23,7 +23,7 @@ AC_SUBST([LIBSUBID_ABI], [libsubid_abi])
@@ -1,39 +0,0 @@
From: Alejandro Colomar <alx@kernel.org>
Date: Wed, 7 Jan 2026 23:44:26 +0100
Subject: lib/chkhash.c: is_valid_hash(): Accept '*' as the hash
This is widely accepted as an invalid hash, to remove password access
for an account (that is, no passwords will match the "hash").
Fixes: c44f1e096a19 (2025-07-20; "chpasswd: Check hash before write when using -e")
Closes: <https://github.com/shadow-maint/shadow/issues/1483>
Closes: <https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1124835>
Reported-by: Chris Hofstaedtler <zeha@debian.org>
Cc: vinz <mmpx09@protonmail.com>
Signed-off-by: Alejandro Colomar <alx@kernel.org>
---
lib/chkhash.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/lib/chkhash.c b/lib/chkhash.c
index 4bf98f8..46b3863 100644
--- a/lib/chkhash.c
+++ b/lib/chkhash.c
@@ -8,6 +8,7 @@
#include <string.h>
#include "string/strcmp/strprefix.h"
+#include "string/strcmp/streq.h"
/*
* match_regex - return true if match, false if not
@@ -42,6 +43,9 @@ is_valid_hash(const char *hash)
hash = strprefix(hash, "!") ?: hash;
+ if (streq(hash, "*"))
+ return true;
+
// Minimum hash length
if (strlen(hash) < 13)
return false;
-2
View File
@@ -8,5 +8,3 @@ debian/Adapt-login.defs-for-Debian.patch
debian/Stop-building-programs-we-do-not-install.patch
debian/Warn-when-badname-and-variants-are-given.patch
debian/configure.ac-align-exec_prefix-with-prefix.patch
upstream/lib-chkhash.c-is_valid_hash-Accept-a-leading.patch
debian/lib-chkhash.c-is_valid_hash-Accept-as-the-hash.patch
@@ -1,39 +0,0 @@
From: Alejandro Colomar <alx@kernel.org>
Date: Wed, 7 Jan 2026 23:39:53 +0100
Subject: lib/chkhash.c: is_valid_hash(): Accept a leading '!'
A leading '!' means that the account is locked.
Fixes: c44f1e096a19 (2025-07-20; "chpasswd: Check hash before write when using -e")
Link: <https://github.com/shadow-maint/shadow/issues/1483>
Link: <https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1124835>
Reported-by: Chris Hofstaedtler <zeha@debian.org>
Cc: vinz <mmpx09@protonmail.com>
Signed-off-by: Alejandro Colomar <alx@kernel.org>
---
lib/chkhash.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/lib/chkhash.c b/lib/chkhash.c
index 6687050..4bf98f8 100644
--- a/lib/chkhash.c
+++ b/lib/chkhash.c
@@ -7,6 +7,7 @@
#include <stddef.h>
#include <string.h>
+#include "string/strcmp/strprefix.h"
/*
* match_regex - return true if match, false if not
@@ -37,6 +38,10 @@ match_regex(const char *pattern, const char *string)
bool
is_valid_hash(const char *hash)
{
+ const char *p;
+
+ hash = strprefix(hash, "!") ?: hash;
+
// Minimum hash length
if (strlen(hash) < 13)
return false;