A login the mesh set is given back, and directories made inside a home are its account's (hq issue 228, to-be 41 WP1) #89

Merged
mesh-admin merged 3 commits from feat/the-shell-and-its-environment into main 2026-10-04 08:49:30 +00:00
Contributor

hq to-be 41 WP1, issue 228.

  • Undeclaring a user no longer stops the node applying. remove() gains a user case. It never deletes an account. If the shell is still the one the mesh set, the shell the account had before is given back. Otherwise it is left as it is, and the outcome says why. A failed give-back is reported, never fatal.
  • The shell the account had is recorded the first time the mesh changes it (Applied.Shell: Found/Set/Created), and is never overwritten by a later change.
  • A shell is refused before anything is touched unless it is executable and listed in /etc/shells. The exception is nologin/false, which need only be executable: the distribution does not list them, and the controller's own account uses one.
  • Directories the host creates inside an owner's home are the owner's, the home included. Existing directories are never chowned or chmodded. This applies to files, directories, archives, blocks and write-into.

Tests: internal/apply/user_test.go and home_parents_test.go. go build, go vet, go test ./... and gofmt are clean.

hq to-be 41 WP1, issue 228. - **Undeclaring a `user` no longer stops the node applying.** `remove()` gains a user case. It never deletes an account. If the shell is still the one the mesh set, the shell the account had before is given back. Otherwise it is left as it is, and the outcome says why. A failed give-back is reported, never fatal. - **The shell the account had is recorded** the first time the mesh changes it (`Applied.Shell`: Found/Set/Created), and is never overwritten by a later change. - **A shell is refused before anything is touched** unless it is executable and listed in /etc/shells. The exception is `nologin`/`false`, which need only be executable: the distribution does not list them, and the controller's own account uses one. - **Directories the host creates inside an owner's home are the owner's**, the home included. Existing directories are never chowned or chmodded. This applies to files, directories, archives, blocks and write-into. Tests: `internal/apply/user_test.go` and `home_parents_test.go`. `go build`, `go vet`, `go test ./...` and `gofmt` are clean.
mesh-admin added 3 commits 2026-10-04 08:33:07 +00:00
A user had no removal, so an undeclared one failed as an orphan and
aborted every apply after. Removal now keeps the account, gives back
the shell recorded when the mesh first changed it if it is still the
mesh's and still usable, and says why otherwise (hq ADR 0176 §2).
A shell is refused before it is set unless it is executable and listed
in /etc/shells, since usermod succeeds on a missing one.
A file or archive placed under a fresh account's home with an owner left
the parents it created, such as ~/.config or ~/.local/share, owned by
root, so the person's own programs could not write there. Parents that
already existed, and any outside the owner's home, are left as before.
mesh-admin merged commit 64b421b6e1 into main 2026-10-04 08:49:30 +00:00
mesh-admin deleted branch feat/the-shell-and-its-environment 2026-10-04 08:49:30 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#89