Cite hq issue 228: 225 was taken on main while this branch was open

This commit is contained in:
jochen
2026-10-04 10:30:57 +02:00
parent 2a5f4c8270
commit f2eda240ec
5 changed files with 9 additions and 9 deletions
+3 -3
View File
@@ -27,7 +27,7 @@ import (
// setting a shell and adding groups are each done only when the machine does not already agree.
//
// previous is this resource's record, which carries the shell the account had before the mesh
// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 225).
// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 228).
func applyUser(ctx context.Context, sys system.System, r *declaration.User, run Runner,
previous store.Applied) (Outcome, error) {
out := begin(r)
@@ -44,7 +44,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run
return out, err
}
// **A shell is refused before anything is touched** (novox/hq issue 225). Refused after the
// **A shell is refused before anything is touched** (novox/hq issue 228). Refused after the
// account was created or its groups changed, the account would be half the declaration's; a
// refusal fails this resource and leaves the account exactly as it was.
if r.Shell != "" && (!exists || login.Shell != r.Shell) {
@@ -127,7 +127,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run
}
// removeUser is what undeclaring a login does: never deleting the account, and giving back the
// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 225).
// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 228).
//
// **The account is never deleted, whether or not the mesh created it.** An account owns a home,
// files, a crontab, a mailbox — what a person did with it is not the mesh's to know, and deleting