- Reset an account that has an encrypted password but no plaintext line. The account's own password is reset correctly, but the tool then also wipes the plaintext password of the next account that has one, breaking that other account's password login
- Reset a key-only account while a later account still has a plaintext password. The account meant to be reset gets nothing and stays unrecoverable, while the password typed is planted on that later account, taking it over and killing its real password
- Reset a key-only account and no account anywhere has a plaintext password. The tool reports success and reboots but silently changes nothing
Partially a regression of T8346. The root cause seemingly is that sed ranges keyed on a field name aren't bounded to the user's block, so when that field is missing the edit runs past the user's closing brace into the next user.