@dalias Granted, it would be possible to re-implement all of this to properly handle USER being a string like '-f root' and pass it on to login(1) as one parameter and let login(1) deal with invalid usernames. But is there a real use-case for anything like that? We'll see if the patch breaks someones deployment, it has potential for doing so