Bug 1994269

Summary: Stop allocating ID 65535 (reserved) for new users/groups
Product: Red Hat Enterprise Linux 8 Reporter: Denis Volkov <dvolkov>
Component: shadow-utilsAssignee: Iker Pedrosa <ipedrosa>
Status: CLOSED ERRATA QA Contact: Anuj Borah <aborah>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 8.4CC: aboscatt, dbodnarc, ipedrosa, pbrezina, ravpatil
Target Milestone: betaKeywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: shadow-utils-4.6-18.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 2179988 (view as bug list) Environment:
Last Closed: 2023-11-14 15:49:14 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2179988    

Description Denis Volkov 2021-08-17 07:53:08 UTC
Description of problem:
On a fresh system change UID_MAX to be higher than current max UID. After this new users are created with UIDs higher than current max UID, while there is a large gap between UID_MIN and old UID_MAX where new UIDs could be allocated. 

Version-Release number of selected component (if applicable):
shadow-utils-4.6-12.el8.x86_64

Steps to Reproduce:
Information from the Customer on how the issue is getting reproduced on a fresh installation:

-----------------------------------------------------------------
Fresh install, so only standard users, UID < 1000
[root@jumpy ~]# cat /etc/redhat-release 
Red Hat Enterprise Linux release 8.4 (Ootpa)
[root@jumpy ~]# grep nobody /etc/passwd
nobody:x:65534:65534:Kernel Overflow User:/:/sbin/nologin
[root@jumpy ~]# grep UID_ /etc/login.defs
UID_MIN                  1000
UID_MAX                 60000
[root@jumpy ~]# useradd okuser
[root@jumpy ~]# id okuser
uid=1004(okuser) gid=1004(okuser) groups=1004(okuser)
[root@jumpy ~]# vi /etc/login.defs
[root@jumpy ~]# grep UID_ /etc/login.defs
UID_MIN                  1000
UID_MAX                 90000
[root@jumpy ~]# useradd nokuser
[root@jumpy ~]# id nokuser
uid=65535(nokuser) gid=1005(nokuser) groups=1005(nokuser)
-----------------------------------------------------------------

Actual results:
Users are created starting with UID 65535 (current max UID + 1 )

Expected results:
Users are created with UIDs starting with UID_MIN - inside the pool between UID_MIN and old UID_MAX first

Comment 8 Iker Pedrosa 2023-03-01 11:49:37 UTC
master:
    * find_new_[gu]id(): Skip over IDs that are reserved for legacy reasons - baae5b4a06c905d9f52ed1f922a0d7d0625d11cf

Comment 17 errata-xmlrpc 2023-11-14 15:49:14 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Low: shadow-utils security and bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2023:7112