nixos/users-groups: dump values of password options if multiple options have definitions #349308
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This was suggested since it might make it a little easier to identify the places where the definitions come from.
Retrieving the effective definitions from the module-system seems non-trivial, especially for submodules though, hence only the values are shown for now.
I'd argue that especially the
password
option are mostly a convenience thing for test setups. If the password is an actual secret, it should be treated as such, i.e.hashedPasswordFile
should be used.For the
shadow
VM test, the new section of the warning looks like this:cc @K900 who brought up the suggestion
cc @infinisil because I'd be curious if there's a reasonable way to obtain definition locations for use-cases like this from options in submodules. I haven't found any.
Things done
nix.conf
? (See Nix manual)sandbox = relaxed
sandbox = true
nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)Add a 👍 reaction to pull requests you find important.