From 80ed1bf997117a36b9d0e10744de736e84d96e7f Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Tue, 29 Sep 2026 03:04:42 -0300 Subject: Shell refuses a name that is no executable, and bare restores the default Shell took any word and the host quietly ran another shell at the next spawn. It now refuses a path or name that is not executable ("Shell: x: no executable by that name", failing a ctl write, logged err), a bare Shell goes back to the default, and a default $SHELL that is not executable falls back to /bin/sh. shellset's golden takes the refusal on the message row (re-recorded by name). Co-Authored-By: Claude Opus 5.5 --- docs/config.md | 7 ++++++- src/builtins.zig | 7 ++++--- src/config.zig | 8 +++++--- src/exec.zig | 18 ++++++++++++++++++ src/ninep/ctl.zig | 17 +++++++++++++++++ test/snapshots/shellset.golden | 2 +- test/snapshots/shellset.snap | 12 ++++++------ 7 files changed, 57 insertions(+), 14 deletions(-) diff --git a/docs/config.md b/docs/config.md index 93190556..95f034d7 100644 --- a/docs/config.md +++ b/docs/config.md @@ -47,7 +47,12 @@ The startup path is printed whether or not a file exists — that is usually whe it is most useful — and is ordinary selectable text, so a right click on it opens the file. Shell follows the same requested/effective/pending model as Font. `Default shell` is the one used while no `Shell` is set: `$SHELL`, the -user's login shell, else `/bin/sh`; an explicit `Shell` overrides it. `Shell +user's login shell, else `/bin/sh` (also when `$SHELL` names nothing +executable); an explicit `Shell` overrides it. `Shell ` is +refused, `Shell: : no executable by that name`, unless it names an +executable (a bare name is looked for in the usual bin directories), and a +bare `Shell` goes back to the default. The root ctl reads `Shell `. `Shell effective (last spawn)` is the executable the native host really chose after installation lookup and fallback. A changed request remains pending until a terminal is spawned, because the core does not resolve native executables. diff --git a/src/builtins.zig b/src/builtins.zig index f7104a8c..f7dd543a 100644 --- a/src/builtins.zig +++ b/src/builtins.zig @@ -170,9 +170,10 @@ pub const registry = struct { if (@intFromEnum(b) == i) return @hasDecl(T, "requires_arg") and T.requires_arg; inline for (comptime settingList(), manualBuiltinCount()..) |setting, i| if (@intFromEnum(b) == i) return switch (setting.action) { - // a switch flips bare, a choice steps, and DumpDir bare is the default - .toggle, .transition, .scene, .dump_dir, .choice, .lift, .shader_animation, .motion => false, - .shell, .theme, .font, .tagline_size, .window_opacity, .window_blur, .message_ms, .shader, .inactive_dim, .grip_width => true, + // a switch flips bare, a choice steps, and DumpDir and Shell bare + // are the default + .toggle, .transition, .scene, .dump_dir, .choice, .lift, .shader_animation, .motion, .shell => false, + .theme, .font, .tagline_size, .window_opacity, .window_blur, .message_ms, .shader, .inactive_dim, .grip_width => true, }; unreachable; } diff --git a/src/config.zig b/src/config.zig index a59fe18d..e0fcab48 100644 --- a/src/config.zig +++ b/src/config.zig @@ -350,7 +350,8 @@ test "wheel drift guard" { pub fn defaultShell() []const u8 { if (comptime pardes.hosted) if (std.c.getenv("SHELL")) |s| { const shell = std.mem.span(s); - if (shell.len > 0) return shell; + // One that is not there, or not executable, is no shell: /bin/sh. + if (shell.len > 0 and std.c.access(s, std.c.X_OK) == 0) return shell; }; return "/bin/sh"; } @@ -1045,8 +1046,9 @@ pub const Runtime = struct { } }, .shell => { - const value = std.mem.trim(u8, argument orelse return false, " \t\r\n"); - if (value.len == 0 or !state.shell.requested.set(value)) return false; + // Bare, the default again ($SHELL, else /bin/sh). + const value = std.mem.trim(u8, argument orelse "", " \t\r\n"); + if (!state.shell.requested.set(value)) return false; state.shell.pending = true; }, .tagline_size => { diff --git a/src/exec.zig b/src/exec.zig index 6de7991c..0a7e71f9 100644 --- a/src/exec.zig +++ b/src/exec.zig @@ -761,6 +761,24 @@ pub fn applySettingBuiltin(p: *Pardes, setting: config.Runtime.Setting, arg: ?[] if (!p.settings.requestFont(matches[0].path, matches[0].name, spec.size_hundredths)) return; p.font_request_taken = false; }, + // A shell that is no executable is refused, not taken and quietly + // replaced at the next spawn; bare, it goes back to the default. + .shell => { + const want = std.mem.trim(u8, arg orelse "", " \t\r\n"); + if (want.len == 0) { + p.settings.shell.requested.clear(); + p.settings.shell.pending = true; + return; + } + if (comptime pardes.hosted) { + var buf: [std.fs.max_path_bytes]u8 = undefined; + if (@import("host_io.zig").Shell.find(want, &buf) == null) { + var text: [320]u8 = undefined; + return p.reportFailure(p.active, std.fmt.bufPrint(&text, "Shell: {s}: no executable by that name", .{want[0..@min(want.len, 255)]}) catch "Shell: no such executable"); + } + } + if (!p.settings.apply(setting, want) and p.announce) p.reportFailure(p.active, "Shell: does not take that value"); + }, else => if (!p.settings.apply(setting, arg) and p.announce) { var text: [96]u8 = undefined; const takes = if (setting.action == .toggle) "takes on or off" else "does not take that value"; diff --git a/src/ninep/ctl.zig b/src/ninep/ctl.zig index 0ab63fbb..76f09084 100644 --- a/src/ninep/ctl.zig +++ b/src/ninep/ctl.zig @@ -1389,3 +1389,20 @@ test "a setting this frontend cannot show says GUI-only, and DumpDir reads back try testing.expect(std.mem.indexOf(u8, rd(p, root_ctl, 0, 1 << 16).bytes, line) != null); } } + +test "Shell refuses a path that is no executable, and bare it goes back to the default" { + const p = try withFile(testing.allocator, "x\n"); + defer p.deinit(); + const root_ctl = @intFromEnum(tree.TopFile.ctl); + const refused = wr(p, root_ctl, "Shell /nonexistent/zzsh\n"); + try testing.expectEqual(Status.err, refused.reply.status); + try testing.expect(std.mem.indexOf(u8, refused.reply.ename, "Shell: /nonexistent/zzsh: no executable by that name") != null); + try testing.expect(th.logHas(p, "/nonexistent/zzsh: no executable")); + try testing.expectEqualStrings("", p.settings.shell.requested.get()); + try testing.expectEqual(Status.ok, wr(p, root_ctl, "Shell /bin/sh\n").reply.status); + try testing.expectEqualStrings("/bin/sh", p.settings.shell.requested.get()); + try testing.expectEqual(Status.ok, wr(p, root_ctl, "Shell\n").reply.status); + try testing.expectEqualStrings("", p.settings.shell.requested.get()); + var want: [300]u8 = undefined; + try testing.expect(std.mem.indexOf(u8, rd(p, root_ctl, 0, 8192).bytes, try std.fmt.bufPrint(&want, "Shell {s}\n", .{config.defaultShell()})) != null); +} diff --git a/test/snapshots/shellset.golden b/test/snapshots/shellset.golden index 0af8f2e1..ae3b9fd0 100644 --- a/test/snapshots/shellset.golden +++ b/test/snapshots/shellset.golden @@ -4,7 +4,7 @@ | /tmp/pardes-snap/shellset/cwd/cmd.txt Save Tty Collapse Del | 1 Shell zznosuchshell == snap builtin-ran grid=90x21 cursor=25,3 -|3: 1 Shell zznosuchshell Shell +|3: 1 Shell zznosuchshell Shell: zznosuchshell: no executable by that name == snap fallback-shell grid=90x21 cursor=49,6 |1: New Tty Find Grep Joincol Delcol New Tty Find Grep Joincol Delcol |2: /tmp/pardes-snap/shellset/cwd/cmd.txt Save /tmp/pardes-snap/shellset/cwd Tty+bash Sav diff --git a/test/snapshots/shellset.snap b/test/snapshots/shellset.snap index ef8b02b9..7d213a84 100644 --- a/test/snapshots/shellset.snap +++ b/test/snapshots/shellset.snap @@ -1,12 +1,12 @@ # The Shell builtin names the binary the NEXT terminal execs. What is pinned # here is the case that has to hold on a machine you did not set up: the name -# resolves to nothing, and the pane opens anyway. +# resolves to nothing, so Shell refuses it and says why on the message row, +# and the next pane opens anyway with the shell that was set before. # -# That is not a corner — it is the DEFAULT's failure mode. pardes defaults -# to $SHELL, which may name a shell the box lacks, and it must still get a working -# shell rather than a pane whose child dies at exec and shows one EOF. So the -# lookup falls back, and this is the proof: a name nothing resolves to, and the -# new pane still greets and lists like any other. +# A default $SHELL that names nothing executable falls back to /bin/sh +# (config.defaultShell), and the host's lookup still falls back at spawn for +# a shell that went away after it was set: a pane never gets a child that +# dies at exec and shows one EOF. # # The rest of the feature is unit-tested rather than pinned here, on purpose. # Which family a binary belongs to, what argv each one gets and where the -- cgit v1.3