Cite hq issue 228: 225 was taken on main while this branch was open
This commit is contained in:
@@ -61,7 +61,7 @@ type Outcome struct {
|
|||||||
// found is, for a service, its unit as the host first found it (novox/hq ADR 0118).
|
// found is, for a service, its unit as the host first found it (novox/hq ADR 0118).
|
||||||
found *store.FoundUnit
|
found *store.FoundUnit
|
||||||
// shell is, for a user, the login shell it was found with and the one the mesh set (novox/hq
|
// shell is, for a user, the login shell it was found with and the one the mesh set (novox/hq
|
||||||
// ADR 0176 §2, issue 225).
|
// ADR 0176 §2, issue 228).
|
||||||
shell *store.LoginShell
|
shell *store.LoginShell
|
||||||
// reads is, for a container, the digest of each file it was created reading, by path — so
|
// reads is, for a container, the digest of each file it was created reading, by path — so
|
||||||
// the next apply can say which one changed (novox/hq 04-ISSUES/103).
|
// the next apply can say which one changed (novox/hq 04-ISSUES/103).
|
||||||
@@ -1435,7 +1435,7 @@ func remove(ctx context.Context, sys system.System, a store.Applied, run Runner,
|
|||||||
return "forgotten", "an operator-owned path is never the host's to remove", nil
|
return "forgotten", "an operator-owned path is never the host's to remove", nil
|
||||||
|
|
||||||
case declaration.TypeUser:
|
case declaration.TypeUser:
|
||||||
// Kept, with its shell given back when that is safe (novox/hq ADR 0176 §2, issue 225).
|
// Kept, with its shell given back when that is safe (novox/hq ADR 0176 §2, issue 228).
|
||||||
return removeUser(ctx, sys, a, run)
|
return removeUser(ctx, sys, a, run)
|
||||||
|
|
||||||
case declaration.TypeNetwork:
|
case declaration.TypeNetwork:
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ import (
|
|||||||
// setting a shell and adding groups are each done only when the machine does not already agree.
|
// setting a shell and adding groups are each done only when the machine does not already agree.
|
||||||
//
|
//
|
||||||
// previous is this resource's record, which carries the shell the account had before the mesh
|
// previous is this resource's record, which carries the shell the account had before the mesh
|
||||||
// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 225).
|
// first changed it, so removal can give it back (novox/hq ADR 0176 §2, issue 228).
|
||||||
func applyUser(ctx context.Context, sys system.System, r *declaration.User, run Runner,
|
func applyUser(ctx context.Context, sys system.System, r *declaration.User, run Runner,
|
||||||
previous store.Applied) (Outcome, error) {
|
previous store.Applied) (Outcome, error) {
|
||||||
out := begin(r)
|
out := begin(r)
|
||||||
@@ -44,7 +44,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run
|
|||||||
return out, err
|
return out, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// **A shell is refused before anything is touched** (novox/hq issue 225). Refused after the
|
// **A shell is refused before anything is touched** (novox/hq issue 228). Refused after the
|
||||||
// account was created or its groups changed, the account would be half the declaration's; a
|
// account was created or its groups changed, the account would be half the declaration's; a
|
||||||
// refusal fails this resource and leaves the account exactly as it was.
|
// refusal fails this resource and leaves the account exactly as it was.
|
||||||
if r.Shell != "" && (!exists || login.Shell != r.Shell) {
|
if r.Shell != "" && (!exists || login.Shell != r.Shell) {
|
||||||
@@ -127,7 +127,7 @@ func applyUser(ctx context.Context, sys system.System, r *declaration.User, run
|
|||||||
}
|
}
|
||||||
|
|
||||||
// removeUser is what undeclaring a login does: never deleting the account, and giving back the
|
// removeUser is what undeclaring a login does: never deleting the account, and giving back the
|
||||||
// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 225).
|
// shell the mesh replaced when that is still safe (novox/hq ADR 0176 §2, issue 228).
|
||||||
//
|
//
|
||||||
// **The account is never deleted, whether or not the mesh created it.** An account owns a home,
|
// **The account is never deleted, whether or not the mesh created it.** An account owns a home,
|
||||||
// files, a crontab, a mailbox — what a person did with it is not the mesh's to know, and deleting
|
// files, a crontab, a mailbox — what a person did with it is not the mesh's to know, and deleting
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ import (
|
|||||||
"github.com/novox/mesh-host/internal/system"
|
"github.com/novox/mesh-host/internal/system"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Defends novox/hq ADR 0176 §2 and issue 225: a login the mesh set is given back when its holding
|
// Defends novox/hq ADR 0176 §2 and issue 228: a login the mesh set is given back when its holding
|
||||||
// moves, undeclaring one never stops the node applying, and a shell is checked before it is set.
|
// moves, undeclaring one never stops the node applying, and a shell is checked before it is set.
|
||||||
|
|
||||||
// logins is a fake user database: each account's shell by name, and every command it was asked.
|
// logins is a fake user database: each account's shell by name, and every command it was asked.
|
||||||
@@ -96,7 +96,7 @@ func userWith(shell string) string {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func TestAnUndeclaredUserNoLongerStopsTheApply(t *testing.T) {
|
func TestAnUndeclaredUserNoLongerStopsTheApply(t *testing.T) {
|
||||||
// Before issue 225 the host had no removal for a user, the orphan failed with "no way to
|
// Before issue 228 the host had no removal for a user, the orphan failed with "no way to
|
||||||
// remove", and an orphan's failure aborts the apply before its first resource — on every
|
// remove", and an orphan's failure aborts the apply before its first resource — on every
|
||||||
// apply after, since the record stayed.
|
// apply after, since the record stayed.
|
||||||
dir := shellsOn(t, []string{"bash", "zsh"})
|
dir := shellsOn(t, []string{"bash", "zsh"})
|
||||||
|
|||||||
@@ -96,7 +96,7 @@ type Applied struct {
|
|||||||
Into *Into `json:"into,omitempty"`
|
Into *Into `json:"into,omitempty"`
|
||||||
|
|
||||||
// Shell is, for a user, the login shell the account had before the mesh first set one, and
|
// Shell is, for a user, the login shell the account had before the mesh first set one, and
|
||||||
// the shell the mesh set last (novox/hq ADR 0176 §2, issue 225). Removal gives the found shell
|
// the shell the mesh set last (novox/hq ADR 0176 §2, issue 228). Removal gives the found shell
|
||||||
// back, and only while the account still has the one the mesh set: a shell a person chose since
|
// back, and only while the account still has the one the mesh set: a shell a person chose since
|
||||||
// is theirs. Absent when the mesh never changed the shell, and on a record written before the
|
// is theirs. Absent when the mesh never changed the shell, and on a record written before the
|
||||||
// host kept it — then the shell is left exactly as it is.
|
// host kept it — then the shell is left exactly as it is.
|
||||||
|
|||||||
@@ -145,7 +145,7 @@ func ShellsIn(list string) (restore func()) {
|
|||||||
// warns about a shell that is missing or not executable, and succeeds; the host's read-back
|
// warns about a shell that is missing or not executable, and succeeds; the host's read-back
|
||||||
// compares the user database's string, which then matches. So an account could be pointed at a
|
// compares the user database's string, which then matches. So an account could be pointed at a
|
||||||
// shell that is not there, and console, ssh and display-manager logins all fail — after a
|
// shell that is not there, and console, ssh and display-manager logins all fail — after a
|
||||||
// failed package install, say, which does not stop the resources after it (novox/hq issue 225).
|
// failed package install, say, which does not stop the resources after it (novox/hq issue 228).
|
||||||
//
|
//
|
||||||
// Listed among the machine's shells as well as executable, because that list is what login
|
// Listed among the machine's shells as well as executable, because that list is what login
|
||||||
// services check: an unlisted shell is one ssh and the display manager may refuse.
|
// services check: an unlisted shell is one ssh and the display manager may refuse.
|
||||||
|
|||||||
Reference in New Issue
Block a user