From 80ed1bf997117a36b9d0e10744de736e84d96e7f Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Tue, 29 Sep 2026 03:04:42 -0300 Subject: Shell refuses a name that is no executable, and bare restores the default Shell took any word and the host quietly ran another shell at the next spawn. It now refuses a path or name that is not executable ("Shell: x: no executable by that name", failing a ctl write, logged err), a bare Shell goes back to the default, and a default $SHELL that is not executable falls back to /bin/sh. shellset's golden takes the refusal on the message row (re-recorded by name). Co-Authored-By: Claude Opus 5.5 --- src/builtins.zig | 7 ++++--- src/config.zig | 8 +++++--- src/exec.zig | 18 ++++++++++++++++++ src/ninep/ctl.zig | 17 +++++++++++++++++ 4 files changed, 44 insertions(+), 6 deletions(-) (limited to 'src') diff --git a/src/builtins.zig b/src/builtins.zig index f7104a8c..f7dd543a 100644 --- a/src/builtins.zig +++ b/src/builtins.zig @@ -170,9 +170,10 @@ pub const registry = struct { if (@intFromEnum(b) == i) return @hasDecl(T, "requires_arg") and T.requires_arg; inline for (comptime settingList(), manualBuiltinCount()..) |setting, i| if (@intFromEnum(b) == i) return switch (setting.action) { - // a switch flips bare, a choice steps, and DumpDir bare is the default - .toggle, .transition, .scene, .dump_dir, .choice, .lift, .shader_animation, .motion => false, - .shell, .theme, .font, .tagline_size, .window_opacity, .window_blur, .message_ms, .shader, .inactive_dim, .grip_width => true, + // a switch flips bare, a choice steps, and DumpDir and Shell bare + // are the default + .toggle, .transition, .scene, .dump_dir, .choice, .lift, .shader_animation, .motion, .shell => false, + .theme, .font, .tagline_size, .window_opacity, .window_blur, .message_ms, .shader, .inactive_dim, .grip_width => true, }; unreachable; } diff --git a/src/config.zig b/src/config.zig index a59fe18d..e0fcab48 100644 --- a/src/config.zig +++ b/src/config.zig @@ -350,7 +350,8 @@ test "wheel drift guard" { pub fn defaultShell() []const u8 { if (comptime pardes.hosted) if (std.c.getenv("SHELL")) |s| { const shell = std.mem.span(s); - if (shell.len > 0) return shell; + // One that is not there, or not executable, is no shell: /bin/sh. + if (shell.len > 0 and std.c.access(s, std.c.X_OK) == 0) return shell; }; return "/bin/sh"; } @@ -1045,8 +1046,9 @@ pub const Runtime = struct { } }, .shell => { - const value = std.mem.trim(u8, argument orelse return false, " \t\r\n"); - if (value.len == 0 or !state.shell.requested.set(value)) return false; + // Bare, the default again ($SHELL, else /bin/sh). + const value = std.mem.trim(u8, argument orelse "", " \t\r\n"); + if (!state.shell.requested.set(value)) return false; state.shell.pending = true; }, .tagline_size => { diff --git a/src/exec.zig b/src/exec.zig index 6de7991c..0a7e71f9 100644 --- a/src/exec.zig +++ b/src/exec.zig @@ -761,6 +761,24 @@ pub fn applySettingBuiltin(p: *Pardes, setting: config.Runtime.Setting, arg: ?[] if (!p.settings.requestFont(matches[0].path, matches[0].name, spec.size_hundredths)) return; p.font_request_taken = false; }, + // A shell that is no executable is refused, not taken and quietly + // replaced at the next spawn; bare, it goes back to the default. + .shell => { + const want = std.mem.trim(u8, arg orelse "", " \t\r\n"); + if (want.len == 0) { + p.settings.shell.requested.clear(); + p.settings.shell.pending = true; + return; + } + if (comptime pardes.hosted) { + var buf: [std.fs.max_path_bytes]u8 = undefined; + if (@import("host_io.zig").Shell.find(want, &buf) == null) { + var text: [320]u8 = undefined; + return p.reportFailure(p.active, std.fmt.bufPrint(&text, "Shell: {s}: no executable by that name", .{want[0..@min(want.len, 255)]}) catch "Shell: no such executable"); + } + } + if (!p.settings.apply(setting, want) and p.announce) p.reportFailure(p.active, "Shell: does not take that value"); + }, else => if (!p.settings.apply(setting, arg) and p.announce) { var text: [96]u8 = undefined; const takes = if (setting.action == .toggle) "takes on or off" else "does not take that value"; diff --git a/src/ninep/ctl.zig b/src/ninep/ctl.zig index 0ab63fbb..76f09084 100644 --- a/src/ninep/ctl.zig +++ b/src/ninep/ctl.zig @@ -1389,3 +1389,20 @@ test "a setting this frontend cannot show says GUI-only, and DumpDir reads back try testing.expect(std.mem.indexOf(u8, rd(p, root_ctl, 0, 1 << 16).bytes, line) != null); } } + +test "Shell refuses a path that is no executable, and bare it goes back to the default" { + const p = try withFile(testing.allocator, "x\n"); + defer p.deinit(); + const root_ctl = @intFromEnum(tree.TopFile.ctl); + const refused = wr(p, root_ctl, "Shell /nonexistent/zzsh\n"); + try testing.expectEqual(Status.err, refused.reply.status); + try testing.expect(std.mem.indexOf(u8, refused.reply.ename, "Shell: /nonexistent/zzsh: no executable by that name") != null); + try testing.expect(th.logHas(p, "/nonexistent/zzsh: no executable")); + try testing.expectEqualStrings("", p.settings.shell.requested.get()); + try testing.expectEqual(Status.ok, wr(p, root_ctl, "Shell /bin/sh\n").reply.status); + try testing.expectEqualStrings("/bin/sh", p.settings.shell.requested.get()); + try testing.expectEqual(Status.ok, wr(p, root_ctl, "Shell\n").reply.status); + try testing.expectEqualStrings("", p.settings.shell.requested.get()); + var want: [300]u8 = undefined; + try testing.expect(std.mem.indexOf(u8, rd(p, root_ctl, 0, 8192).bytes, try std.fmt.bufPrint(&want, "Shell {s}\n", .{config.defaultShell()})) != null); +} -- cgit v1.3