summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDennis Kobert <dennis@kobert.dev>2026-03-10 20:39:54 +0100
committerDennis Kobert <dennis@kobert.dev>2026-03-10 20:39:54 +0100
commit3341e1e694ad64c12055c42008c4927c327950de (patch)
tree15a9ddbdcd7a4d64fb5263fac9b9653e210b7819
parent334625d069b0adf9d046703daf20215bbc83bc4e (diff)
Support config file path, add NixOS module with mode option
-rw-r--r--default.nix17
-rw-r--r--flake.nix14
l---------result2
3 files changed, 28 insertions, 5 deletions
diff --git a/default.nix b/default.nix
index fa9d521..4ae9a74 100644
--- a/default.nix
+++ b/default.nix
@@ -28,6 +28,23 @@ rustPlatform.buildRustPackage (finalAttrs: {
pam
];
+ # Support reading config from a file path instead of only inline JSON,
+ # since NixOS appends comments to PAM rule lines which breaks JSON parsing.
+ postPatch = ''
+ substituteInPlace src/lib.rs \
+ --replace-fail \
+ 'let arg_string = args.iter().map(|s| s.to_str().unwrap()).collect::<Vec<_>>().join(" ");' \
+ 'let arg_string = {
+ let joined = args.iter().map(|s| s.to_str().unwrap()).collect::<Vec<_>>().join(" ");
+ if joined.starts_with("/") {
+ std::fs::read_to_string(joined.split_whitespace().next().unwrap())
+ .unwrap_or(joined)
+ } else {
+ joined
+ }
+ };'
+ '';
+
# cdylib produces no binaries, only libpam_any.so
installPhase = ''
runHook preInstall
diff --git a/flake.nix b/flake.nix
index 9daf707..ee980c4 100644
--- a/flake.nix
+++ b/flake.nix
@@ -18,15 +18,21 @@
cfg = config.security.pam-any;
pam-any = self.packages.${pkgs.stdenv.hostPlatform.system}.default;
- pamAnyConfig = builtins.toJSON {
- mode = "One";
+ pamAnyConfigFile = pkgs.writeText "pam-any-config.json" (builtins.toJSON {
+ mode = cfg.mode;
modules = cfg.modules;
- };
+ });
in
{
options.security.pam-any = {
enable = lib.mkEnableOption "pam-any parallel authentication";
+ mode = lib.mkOption {
+ type = lib.types.enum [ "One" "All" ];
+ default = "One";
+ description = "\"One\" succeeds if any module succeeds, \"All\" requires all to succeed.";
+ };
+
modules = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
default = {
@@ -64,7 +70,7 @@
order = cfg.order;
control = "sufficient";
modulePath = "${pam-any}/lib/security/pam_any.so";
- args = [ pamAnyConfig ];
+ args = [ "${pamAnyConfigFile}" ];
};
});
};
diff --git a/result b/result
index c296cb9..26e2c1b 120000
--- a/result
+++ b/result
@@ -1 +1 @@
-/nix/store/bq84538wxa3jm4l3q5dbmqyfdanqgg7p-pam-any-0-unstable-2024-11-20 \ No newline at end of file
+/nix/store/455520syawyk79pvc9in9fjq5yxxr7ii-pam-any-0-unstable-2024-11-20 \ No newline at end of file