Cite hq issue 228: 225 was taken on main while this branch was open
This commit is contained in:
@@ -27,7 +27,7 @@ import (
|
||||
// setting a shell and adding groups are each done only when the machine does not already agree.
|
||||
//
|
||||
// previous is this resource's record, which carries the shell the account had before the mesh
|
||||
// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 225).
|
||||
// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 228).
|
||||
func applyUser(ctx context.Context, sys system.System, r *declaration.User, run Runner,
|
||||
previous store.Applied) (Outcome, error) {
|
||||
out := begin(r)
|
||||
@@ -44,7 +44,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run
|
||||
return out, err
|
||||
}
|
||||
|
||||
// **A shell is refused before anything is touched** (novox/hq issue 225). Refused after the
|
||||
// **A shell is refused before anything is touched** (novox/hq issue 228). Refused after the
|
||||
// account was created or its groups changed, the account would be half the declaration's; a
|
||||
// refusal fails this resource and leaves the account exactly as it was.
|
||||
if r.Shell != "" && (!exists || login.Shell != r.Shell) {
|
||||
@@ -127,7 +127,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run
|
||||
}
|
||||
|
||||
// removeUser is what undeclaring a login does: never deleting the account, and giving back the
|
||||
// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 225).
|
||||
// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 228).
|
||||
//
|
||||
// **The account is never deleted, whether or not the mesh created it.** An account owns a home,
|
||||
// files, a crontab, a mailbox — what a person did with it is not the mesh's to know, and deleting
|
||||
|
||||
Reference in New Issue
Block a user