From f2eda240ecd51ca81a677463d025ab185dff8c16 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 4 Oct 2026 10:30:57 +0200 Subject: [PATCH] Cite hq issue 228: 225 was taken on main while this branch was open --- internal/apply/apply.go | 4 ++-- internal/apply/user.go | 6 +++--- internal/apply/user_test.go | 4 ++-- internal/store/store.go | 2 +- internal/system/system.go | 2 +- 5 files changed, 9 insertions(+), 9 deletions(-) diff --git a/internal/apply/apply.go b/internal/apply/apply.go index 1d489d0..79ef74f 100644 --- a/internal/apply/apply.go +++ b/internal/apply/apply.go @@ -61,7 +61,7 @@ type Outcome struct { // found is, for a service, its unit as the host first found it (novox/hq ADR 0118). found *store.FoundUnit // shell is, for a user, the login shell it was found with and the one the mesh set (novox/hq - // ADR 0176 §2, issue 225). + // ADR 0176 §2, issue 228). shell *store.LoginShell // reads is, for a container, the digest of each file it was created reading, by path — so // the next apply can say which one changed (novox/hq 04-ISSUES/103). @@ -1435,7 +1435,7 @@ func remove(ctx context.Context, sys system.System, a store.Applied, run Runner, return "forgotten", "an operator-owned path is never the host's to remove", nil case declaration.TypeUser: - // Kept, with its shell given back when that is safe (novox/hq ADR 0176 §2, issue 225). + // Kept, with its shell given back when that is safe (novox/hq ADR 0176 §2, issue 228). return removeUser(ctx, sys, a, run) case declaration.TypeNetwork: diff --git a/internal/apply/user.go b/internal/apply/user.go index 81e80ff..740eea2 100644 --- a/internal/apply/user.go +++ b/internal/apply/user.go @@ -27,7 +27,7 @@ import ( // setting a shell and adding groups are each done only when the machine does not already agree. // // previous is this resource's record, which carries the shell the account had before the mesh -// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 225). +// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 228). func applyUser(ctx context.Context, sys system.System, r *declaration.User, run Runner, previous store.Applied) (Outcome, error) { out := begin(r) @@ -44,7 +44,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run return out, err } - // **A shell is refused before anything is touched** (novox/hq issue 225). Refused after the + // **A shell is refused before anything is touched** (novox/hq issue 228). Refused after the // account was created or its groups changed, the account would be half the declaration's; a // refusal fails this resource and leaves the account exactly as it was. if r.Shell != "" && (!exists || login.Shell != r.Shell) { @@ -127,7 +127,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run } // removeUser is what undeclaring a login does: never deleting the account, and giving back the -// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 225). +// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 228). // // **The account is never deleted, whether or not the mesh created it.** An account owns a home, // files, a crontab, a mailbox — what a person did with it is not the mesh's to know, and deleting diff --git a/internal/apply/user_test.go b/internal/apply/user_test.go index 401461f..e6e81a9 100644 --- a/internal/apply/user_test.go +++ b/internal/apply/user_test.go @@ -12,7 +12,7 @@ import ( "github.com/novox/mesh-host/internal/system" ) -// Defends novox/hq ADR 0176 §2 and issue 225: a login the mesh set is given back when its holding +// Defends novox/hq ADR 0176 §2 and issue 228: a login the mesh set is given back when its holding // moves, undeclaring one never stops the node applying, and a shell is checked before it is set. // logins is a fake user database: each account's shell by name, and every command it was asked. @@ -96,7 +96,7 @@ func userWith(shell string) string { } func TestAnUndeclaredUserNoLongerStopsTheApply(t *testing.T) { - // Before issue 225 the host had no removal for a user, the orphan failed with "no way to + // Before issue 228 the host had no removal for a user, the orphan failed with "no way to // remove", and an orphan's failure aborts the apply before its first resource — on every // apply after, since the record stayed. dir := shellsOn(t, []string{"bash", "zsh"}) diff --git a/internal/store/store.go b/internal/store/store.go index 8b01bf7..05d9c92 100644 --- a/internal/store/store.go +++ b/internal/store/store.go @@ -96,7 +96,7 @@ type Applied struct { Into *Into `json:"into,omitempty"` // Shell is, for a user, the login shell the account had before the mesh first set one, and - // the shell the mesh set last (novox/hq ADR 0176 §2, issue 225). Removal gives the found shell + // the shell the mesh set last (novox/hq ADR 0176 §2, issue 228). Removal gives the found shell // back, and only while the account still has the one the mesh set: a shell a person chose since // is theirs. Absent when the mesh never changed the shell, and on a record written before the // host kept it — then the shell is left exactly as it is. diff --git a/internal/system/system.go b/internal/system/system.go index aac4b14..7669917 100644 --- a/internal/system/system.go +++ b/internal/system/system.go @@ -145,7 +145,7 @@ func ShellsIn(list string) (restore func()) { // warns about a shell that is missing or not executable, and succeeds; the host's read-back // compares the user database's string, which then matches. So an account could be pointed at a // shell that is not there, and console, ssh and display-manager logins all fail — after a -// failed package install, say, which does not stop the resources after it (novox/hq issue 225). +// failed package install, say, which does not stop the resources after it (novox/hq issue 228). // // Listed among the machine's shells as well as executable, because that list is what login // services check: an unlisted shell is one ssh and the display manager may refuse.