Skip to content

feat: ROOT_PASS=KEEP keeps the password set before the first boot - #42

Merged
marcos-mendez merged 1 commit into
masterfrom
feat/root-pass-keep
Oct 3, 2026
Merged

marcos-mendez merged 1 commit into
masterfrom
feat/root-pass-keep

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

An unattended first boot after pct create --password had to repeat the password in ROOT_PASS. ROOT_PASS=KEEP (any case) now keeps it.

  • setpass.py --pass=KEEP is accepted exactly when the screen would offer Keep, through the same keep_offer() (build date present, password usable and changed on or after it, not empty or the placeholder, not under keel-init). No logic is duplicated.
  • Otherwise: Error: ROOT_PASS=KEEP: ... on stderr and exit 1, the convention of fqdn.py / secalerts.py for an invalid preseed; run logs the failed hook and goes on. KEEP is never set as the password and no screen is drawn. The shadow field is never printed.
  • README preseed list and notes, 30rootpass comment, changelog 2.3.6+keel24.

Test plan

  • tests/test_setpass.py: new TestPreseededKeep (accepted after build, on build day, any case, outside a container; refused when locked, empty, older than the image, no build date, placeholder, keel-init; a password merely containing KEEP is set). Failed before the change, pass after.
  • Full pytest under coverage (99%), full bats suite, shellcheck.
  • Security review by the maintainer.
  • On a built image: pct create --password + ROOT_PASS=KEEP headless first boot keeps the password.

An unattended first boot after pct create --password had to repeat the
password in ROOT_PASS. setpass.py now takes --pass=KEEP, in any case,
and keeps the password exactly when the screen would offer Keep, by the
same keep_offer() check (build date, changed on or after it, usable, not
the placeholder, not keel-init). Otherwise it prints an error naming
ROOT_PASS=KEEP on stderr and exits 1, as other invalid preseeds do; KEEP
is never set as the password and nothing is asked.
@marcos-mendez
marcos-mendez merged commit f46b9c3 into master Oct 3, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant