[19524] in Kerberos_V5_Development
Re: Question about aname_do_match behavior on invalid patten
daemon@ATHENA.MIT.EDU (Greg Hudson)
Tue Jan 24 11:43:32 2017
To: Eric Diven <ebd2.github@gmail.com>, krbdev@mit.edu
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <82aefe99-e823-2848-f5ad-863605dc4a19@mit.edu>
Date: Tue, 24 Jan 2017 11:43:24 -0500
MIME-Version: 1.0
In-Reply-To: <CAAWz=6CFr6CpDAQ563KZkKRRBeBKpun3q+Lrj53r3M+u7N2arA@mail.gmail.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On 01/23/2017 06:15 PM, Eric Diven wrote:
> When regcomp returns a non-zero result, aname_do_match returns
> KRB5_LNAME_NOTRANS. This seems like odd behavior for what appears to be an
> error in the krb5.conf file. Can somebody please explain the rationale
> behind this?
I don't think anyone can speak to the rationale behind this behavior as
it's very old. Although I reorganized the code significantly in 1.12
when I added the localauth pluggable interface, that behavior dates back
to 1.0. If you look at the an_to_ln.c code from back then, the behavior
could be explained by a kind of laziness; the code looks like "if
(!regcomp(...) && !regexec(...))" and similar for other regexp types.
I agree that it would be more helpful to KRB5_CONFIG_BADFORMAT, with an
extended error message explaining that the regexp is bad. There is some
risk of breaking people's kind-of-working config files if we make that
change, but the risk might be acceptable.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev