diff options
| author | Dennis Kobert <dennis@kobert.dev> | 2026-03-10 20:39:54 +0100 |
|---|---|---|
| committer | Dennis Kobert <dennis@kobert.dev> | 2026-03-10 20:39:54 +0100 |
| commit | 3341e1e694ad64c12055c42008c4927c327950de (patch) | |
| tree | 15a9ddbdcd7a4d64fb5263fac9b9653e210b7819 | |
| parent | 334625d069b0adf9d046703daf20215bbc83bc4e (diff) | |
Support config file path, add NixOS module with mode option
| -rw-r--r-- | default.nix | 17 | ||||
| -rw-r--r-- | flake.nix | 14 | ||||
| l--------- | result | 2 |
3 files changed, 28 insertions, 5 deletions
diff --git a/default.nix b/default.nix index fa9d521..4ae9a74 100644 --- a/default.nix +++ b/default.nix @@ -28,6 +28,23 @@ rustPlatform.buildRustPackage (finalAttrs: { pam ]; + # Support reading config from a file path instead of only inline JSON, + # since NixOS appends comments to PAM rule lines which breaks JSON parsing. + postPatch = '' + substituteInPlace src/lib.rs \ + --replace-fail \ + 'let arg_string = args.iter().map(|s| s.to_str().unwrap()).collect::<Vec<_>>().join(" ");' \ + 'let arg_string = { + let joined = args.iter().map(|s| s.to_str().unwrap()).collect::<Vec<_>>().join(" "); + if joined.starts_with("/") { + std::fs::read_to_string(joined.split_whitespace().next().unwrap()) + .unwrap_or(joined) + } else { + joined + } + };' + ''; + # cdylib produces no binaries, only libpam_any.so installPhase = '' runHook preInstall @@ -18,15 +18,21 @@ cfg = config.security.pam-any; pam-any = self.packages.${pkgs.stdenv.hostPlatform.system}.default; - pamAnyConfig = builtins.toJSON { - mode = "One"; + pamAnyConfigFile = pkgs.writeText "pam-any-config.json" (builtins.toJSON { + mode = cfg.mode; modules = cfg.modules; - }; + }); in { options.security.pam-any = { enable = lib.mkEnableOption "pam-any parallel authentication"; + mode = lib.mkOption { + type = lib.types.enum [ "One" "All" ]; + default = "One"; + description = "\"One\" succeeds if any module succeeds, \"All\" requires all to succeed."; + }; + modules = lib.mkOption { type = lib.types.attrsOf lib.types.str; default = { @@ -64,7 +70,7 @@ order = cfg.order; control = "sufficient"; modulePath = "${pam-any}/lib/security/pam_any.so"; - args = [ pamAnyConfig ]; + args = [ "${pamAnyConfigFile}" ]; }; }); }; @@ -1 +1 @@ -/nix/store/bq84538wxa3jm4l3q5dbmqyfdanqgg7p-pam-any-0-unstable-2024-11-20
\ No newline at end of file +/nix/store/455520syawyk79pvc9in9fjq5yxxr7ii-pam-any-0-unstable-2024-11-20
\ No newline at end of file |
