diff options
| author | Dennis Kobert <dennis@kobert.dev> | 2026-03-11 14:15:45 +0100 |
|---|---|---|
| committer | Dennis Kobert <dennis@kobert.dev> | 2026-03-11 14:16:07 +0100 |
| commit | a9a74679fbec07cf158f2295513e3d4c4adc2666 (patch) | |
| tree | 5dcac28283ef53c2869bdedb9badff0896900bb6 /default.nix | |
| parent | 116bd5a46adc7e9caa27f58b19cafe68d3e085f0 (diff) | |
The pam-bindings crate has a critical bug where pam_try! returns
PAM_SUCCESS on error in release builds (anowell/pam-rs#16), causing
authentication to always succeed. This replaces it with nonstick
and a custom pam_client module with raw PAM FFI for thread-safe
conversation forwarding.
Diffstat (limited to 'default.nix')
| -rw-r--r-- | default.nix | 27 |
1 files changed, 2 insertions, 25 deletions
diff --git a/default.nix b/default.nix index 4ae9a74..b9bd421 100644 --- a/default.nix +++ b/default.nix @@ -1,20 +1,14 @@ { lib, rustPlatform, - fetchFromGitHub, pam, }: rustPlatform.buildRustPackage (finalAttrs: { pname = "pam-any"; - version = "0-unstable-2024-11-20"; + version = "0.2.0"; - src = fetchFromGitHub { - owner = "ChocolateLoverRaj"; - repo = "pam-any"; - rev = "e77687709d092a6bb77e57a444403798855075c0"; - hash = "sha256-em/vifkse1Qp3iX/oE1vHQK6UAoJvbhBOowhFhgQ+qw="; - }; + src = ./src-repo; cargoLock = { lockFile = ./Cargo.lock; @@ -28,23 +22,6 @@ rustPlatform.buildRustPackage (finalAttrs: { pam ]; - # Support reading config from a file path instead of only inline JSON, - # since NixOS appends comments to PAM rule lines which breaks JSON parsing. - postPatch = '' - substituteInPlace src/lib.rs \ - --replace-fail \ - 'let arg_string = args.iter().map(|s| s.to_str().unwrap()).collect::<Vec<_>>().join(" ");' \ - 'let arg_string = { - let joined = args.iter().map(|s| s.to_str().unwrap()).collect::<Vec<_>>().join(" "); - if joined.starts_with("/") { - std::fs::read_to_string(joined.split_whitespace().next().unwrap()) - .unwrap_or(joined) - } else { - joined - } - };' - ''; - # cdylib produces no binaries, only libpam_any.so installPhase = '' runHook preInstall |
