From 3d735c52f4186133da7113ca671a16d68fe76b33 Mon Sep 17 00:00:00 2001 From: Joey Hess Date: Sun, 19 Apr 2015 21:00:21 -0400 Subject: Added hasLoginShell and shellEnabled. My code with some improvements from weinzwang. --- src/Propellor/Property/User.hs | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) (limited to 'src/Propellor/Property') diff --git a/src/Propellor/Property/User.hs b/src/Propellor/Property/User.hs index 9e115290..557875fb 100644 --- a/src/Propellor/Property/User.hs +++ b/src/Propellor/Property/User.hs @@ -3,6 +3,7 @@ module Propellor.Property.User where import System.Posix import Propellor +import qualified Propellor.Property.File as File data Eep = YesReallyDeleteHome @@ -110,3 +111,21 @@ shadowConfig False = check shadowExists $ shadowExists :: IO Bool shadowExists = doesFileExist "/etc/shadow" + +-- | Ensures that a user has a specified login shell, and that the shell +-- is enabled in /etc/shells. +hasLoginShell :: UserName -> FilePath -> Property NoInfo +hasLoginShell user loginshell = shellSetTo user loginshell `requires` shellEnabled loginshell + +shellSetTo :: UserName -> FilePath -> Property NoInfo +shellSetTo user loginshell = check needchangeshell $ + cmdProperty "chsh" ["--shell", loginshell, user] + `describe` (user ++ " has login shell " ++ loginshell) + where + needchangeshell = do + currshell <- userShell <$> getUserEntryForName user + return (currshell /= loginshell) + +-- | Ensures that /etc/shells contains a shell. +shellEnabled :: FilePath -> Property NoInfo +shellEnabled loginshell = "/etc/shells" `File.containsLine` loginshell -- cgit v1.2.3