summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoey Hess2015-04-19 21:00:21 -0400
committerJoey Hess2015-04-19 21:00:21 -0400
commit3d735c52f4186133da7113ca671a16d68fe76b33 (patch)
tree02179702ed89e5769ec13e50fd10aa49fee9412c
parentfe6ff079e6770ce452ea0ba1b49b68bebeaed2d3 (diff)
Added hasLoginShell and shellEnabled.
My code with some improvements from weinzwang.
-rw-r--r--debian/changelog1
-rw-r--r--src/Propellor/Property/User.hs19
2 files changed, 20 insertions, 0 deletions
diff --git a/debian/changelog b/debian/changelog
index db9ffbd9..89c63c12 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -6,6 +6,7 @@ propellor (2.2.2) UNRELEASED; urgency=medium
and by Cron.runPropellor. If the binary doesn't work, it will be rebuilt.
* Note that since a new switch had to be added to allow testing the binary,
upgrading to this version will cause a rebuild from scratch of propellor.
+ * Added hasLoginShell and shellEnabled.
-- Joey Hess <id@joeyh.name> Thu, 02 Apr 2015 10:09:46 -0400
diff --git a/src/Propellor/Property/User.hs b/src/Propellor/Property/User.hs
index 9e115290..557875fb 100644
--- a/src/Propellor/Property/User.hs
+++ b/src/Propellor/Property/User.hs
@@ -3,6 +3,7 @@ module Propellor.Property.User where
import System.Posix
import Propellor
+import qualified Propellor.Property.File as File
data Eep = YesReallyDeleteHome
@@ -110,3 +111,21 @@ shadowConfig False = check shadowExists $
shadowExists :: IO Bool
shadowExists = doesFileExist "/etc/shadow"
+
+-- | Ensures that a user has a specified login shell, and that the shell
+-- is enabled in /etc/shells.
+hasLoginShell :: UserName -> FilePath -> Property NoInfo
+hasLoginShell user loginshell = shellSetTo user loginshell `requires` shellEnabled loginshell
+
+shellSetTo :: UserName -> FilePath -> Property NoInfo
+shellSetTo user loginshell = check needchangeshell $
+ cmdProperty "chsh" ["--shell", loginshell, user]
+ `describe` (user ++ " has login shell " ++ loginshell)
+ where
+ needchangeshell = do
+ currshell <- userShell <$> getUserEntryForName user
+ return (currshell /= loginshell)
+
+-- | Ensures that /etc/shells contains a shell.
+shellEnabled :: FilePath -> Property NoInfo
+shellEnabled loginshell = "/etc/shells" `File.containsLine` loginshell