From c4fedcdbe350864aabc499868ccd0dfb5c290ba1 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 4 Oct 2026 03:58:06 +0200 Subject: [PATCH] To-be 41 WP1: a shell that refuses logins need not be listed; giving back is never fatal --- .../01-to-be/41-the-shell-and-the-accounts-environment.md | 6 +++++- .../00-report.md | 4 +++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/03-DESIGN/01-to-be/41-the-shell-and-the-accounts-environment.md b/03-DESIGN/01-to-be/41-the-shell-and-the-accounts-environment.md index 4f16bf4..89f9063 100644 --- a/03-DESIGN/01-to-be/41-the-shell-and-the-accounts-environment.md +++ b/03-DESIGN/01-to-be/41-the-shell-and-the-accounts-environment.md @@ -100,7 +100,11 @@ against WP2's controller before anything is published. shell is still the one the mesh set, and the recorded shell is still executable, the recorded shell is set back. Otherwise the shell is left as it is, and the outcome says why. - Before a shell is set, it is refused unless it is executable and listed among the machine's shells. - The refusal fails that resource and leaves the account untouched. + The exception is a shell that refuses logins (`nologin`, `false`): the distribution does not list + those, and the controller's own account uses one, so it need only be executable. The refusal fails + that resource and leaves the account untouched. +- Giving the shell back is reported, never fatal. A failed `usermod` on removal is named in the + outcome and the record is dropped, because a fatal removal is exactly the wedge issue 225 is about. **Proof.** The host's tests: diff --git a/04-ISSUES/225-a-login-the-mesh-set-is-never-given-back/00-report.md b/04-ISSUES/225-a-login-the-mesh-set-is-never-given-back/00-report.md index 66a5ea9..33ab02f 100644 --- a/04-ISSUES/225-a-login-the-mesh-set-is-never-given-back/00-report.md +++ b/04-ISSUES/225-a-login-the-mesh-set-is-never-given-back/00-report.md @@ -47,4 +47,6 @@ it replaced nor checks the shell it sets. The fix is set out in - a removal that never deletes an account; - the login shell given back, if it is still the one the mesh set and the recorded one still exists; -- a shell refused before it is set unless it is executable and listed among the machine's shells. +- a shell refused before it is set unless it is executable and listed among the machine's shells + (a shell that refuses logins need only be executable, since the distribution does not list it and + the controller's own account uses one).