run input user/group names through input validation
to harden against abuse we'll match them against a regex that should only match what could possibly be a valid user or group name.
thanks to Wolfgang Frisch and SUSE for the suggestion
BUG: 432757 FIXED-IN: 20.12.3