From nobody Mon Sep 07 04:20:40 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hdYlY0X06z6rMDC for ; Mon, 07 Sep 2026 04:20:41 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hdYlX3rpNz3SGP for ; Mon, 07 Sep 2026 04:20:40 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788754840; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=3B4IArnBYGn57JTQYrZCEjgFF3r6hrVpO6qRSm1STPM=; b=aPkxMbgGPPmH63axJJTl43YL7ckrJXnKs/XipZUKzWNk6nWvfsaObB+EaZmuiHAKGkp1Dd 5LodTlkn6mh5k4tbA9jJrsETUcjVGaN4IglfWGJI9stqlrwlOE+qSKNhgyrsEQrvdw4Tom 2G5tjp81T9PO+Z9/q/JZvcijxbesu58beT1C/2mO+sHhq7h8voaIHLvDGPjLaxMBpKrIpG GSzQ5LmtG1Tni8bwEuZd6kUe0RLx/LRRJ9K43PNJHuzfS+ua5kri2FwS2m3IOD48sCLuR4 6Arh61+QdEoFt6tZ8B8+zWgT0GNrtsQL5lpDiqS2qf8l3quNPih5tHHfI7B+Iw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788754840; a=rsa-sha256; cv=none; b=x9yIRJpA3LDpdh5dSguAIShH5ttaJiMeNBBwkCTQKZzKhmh2fdCiH4xZfOkPf2uoB3x7d/ 9t8RyoDIVfG8reTtr0fb2PZAu6p62d41soiObS9jQ52vFxaNxtdvnbyhmDk42ppTSGOnVx uVD3KD+J0i2Cs8wp/2e8EHe50D/YuWWj15Luq41lyWDHSrkMBwn80lNh6ftkSgGDLq9P29 Oj0DgOVLALuUBlSY92s+9XLducmsXZumQH0vZLN3P5yHlG/vC6kDlYnCjmCTHPnKOF1vW0 +rU0NU7DHg1Ij+UUYP+kYVHf8mAKda580d97Cz1RV7BI4OCWNT2WFGpKk2Ylzw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788754840; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=3B4IArnBYGn57JTQYrZCEjgFF3r6hrVpO6qRSm1STPM=; b=bB5WwPkFX8dp65fEaf3qdbgbmVi7Jdty9IcuY5I6+34lKOdrPvUQfmFIIAAlRMwae/b0y4 sC0vVYx02aLfPXBbFuuP+fz4/CCZHlS2ZQTg4LXIw+XclWvOXyU8bmcbvRdUxBZOKiTtdr i2IXiyyA306Tds1lF2IODcQvmRjdAJFVaU3oB1h2KioGfYBA0J1/FVlej8tpFMiWAT10hd 3X0vlu244rJUn6LrUMElBprTYTdhbzwmQNV/E06Hzs/F9QztMo+NAlXqRvLz7oCEx/dMyM YQcXAINJ78q6AtyP8a/L5XT0pdY0yYRjx9sAhAQ3fq9cWQxKPPvo3ch2sziy0Q== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hdYlX2wYnz12gN for ; Mon, 07 Sep 2026 04:20:40 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 1be63 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 07 Sep 2026 04:20:40 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Baptiste Daroussin Subject: git: af0ca8cd7534 - stable/15 - nuageinit: accept lock_passwd for users List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: bapt X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: af0ca8cd7534d86e12186081a9b882fb9e7e71a9 Auto-Submitted: auto-generated Date: Mon, 07 Sep 2026 04:20:40 +0000 Message-Id: <6a9e3b98.1be63.48e7dc97@gitrepo.freebsd.org> The branch stable/15 has been updated by bapt: URL: https://cgit.FreeBSD.org/src/commit/?id=af0ca8cd7534d86e12186081a9b882fb9e7e71a9 commit af0ca8cd7534d86e12186081a9b882fb9e7e71a9 Author: Baptiste Daroussin AuthorDate: 2026-08-11 09:46:52 +0000 Commit: Baptiste Daroussin CommitDate: 2026-09-07 04:19:01 +0000 nuageinit: accept lock_passwd for users Alias cloud-init lock_passwd key alongside locked. (cherry picked from commit cd06bf52053d463f4a3f6c0b9cb5c9f1d578e439) --- libexec/nuageinit/nuage.lua | 2 +- libexec/nuageinit/nuageinit.7 | 5 ++++- libexec/nuageinit/tests/nuageinit.sh | 30 ++++++++++++++++++++++++++++++ 3 files changed, 35 insertions(+), 2 deletions(-) diff --git a/libexec/nuageinit/nuage.lua b/libexec/nuageinit/nuage.lua index 8f609feb0980..80ba54680039 100644 --- a/libexec/nuageinit/nuage.lua +++ b/libexec/nuageinit/nuage.lua @@ -388,7 +388,7 @@ local function adduser(pwd) warnmsg(cmd) return nil end - if pwd.locked then + if pwd.lock_passwd or pwd.locked then cmd = "pw " if root then cmd = cmd .. "-R " .. root .. " " diff --git a/libexec/nuageinit/nuageinit.7 b/libexec/nuageinit/nuageinit.7 index a9552cace85f..4f1a492473af 100644 --- a/libexec/nuageinit/nuageinit.7 +++ b/libexec/nuageinit/nuageinit.7 @@ -555,8 +555,11 @@ The encrypted password for the user. .It Ic plain_text_passwd The password in plain text for the user. Ignored if an encrypted password is already provided. -.It Ic locked +.It Ic lock_passwd Boolean to determine if the user account should be locked. +The legacy +.Ic locked +key is also accepted. .It Ic sudo A string or an array of strings which should be appended to .Pa ${LOCALBASE}/etc/sudoers.d/90-nuageinit-users diff --git a/libexec/nuageinit/tests/nuageinit.sh b/libexec/nuageinit/tests/nuageinit.sh index a4b0def48a86..4803ddf941ab 100644 --- a/libexec/nuageinit/tests/nuageinit.sh +++ b/libexec/nuageinit/tests/nuageinit.sh @@ -181,6 +181,35 @@ EOF atf_check -o inline:"permit persist foobar as root\ndeny bla as foobar\npermit persist bla as root cmd whoami\n" cat "${PWD}/${localbase}/etc/doas.conf" } +nocloud_userdata_cloudconfig_users_lock_passwd_head() +{ + atf_set "require.user" root +} +nocloud_userdata_cloudconfig_users_lock_passwd_body() +{ + mkdir -p media/nuageinit + printf "instance-id: iid-local01\n" > "${PWD}"/media/nuageinit/meta-data + mkdir -p etc + cat > etc/master.passwd << EOF +root:*:0:0::0:0:Charlie &:/root:/bin/sh +sys:*:1:0::0:0:Sys:/home/sys:/bin/sh +EOF + pwd_mkdb -d etc "${PWD}"/etc/master.passwd + cat > etc/group << EOF +wheel:*:0:root +users:*:1: +EOF + cat > media/nuageinit/user-data << 'EOF' +#cloud-config +users: + - name: lockeduser + lock_passwd: true +EOF + atf_check /usr/libexec/nuageinit "${PWD}"/media/nuageinit nocloud + atf_check /usr/libexec/nuageinit "${PWD}"/media/nuageinit postnet + atf_check -o match:'lockeduser:\*LOCKED\*:' cat "${PWD}"/etc/master.passwd +} + nocloud_network_head() { atf_set "require.user" root @@ -1474,6 +1503,7 @@ atf_init_test_cases() atf_add_test_case nocloud_userdata_script atf_add_test_case nocloud_user_data_script atf_add_test_case nocloud_userdata_cloudconfig_users + atf_add_test_case nocloud_userdata_cloudconfig_users_lock_passwd atf_add_test_case nocloud_network atf_add_test_case config2 atf_add_test_case config2_pubkeys