From 116bd5a46adc7e9caa27f58b19cafe68d3e085f0 Mon Sep 17 00:00:00 2001 From: Dennis Kobert Date: Tue, 10 Mar 2026 21:09:32 +0100 Subject: Safe fallback: success=done for pam-any, keep unix without nullok --- flake.nix | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/flake.nix b/flake.nix index 6da2041..efe6a05 100644 --- a/flake.nix +++ b/flake.nix @@ -67,17 +67,22 @@ } // lib.genAttrs cfg.services (_name: { fprintAuth = false; rules.auth = { + # If pam-any succeeds (fingerprint or password in parallel), auth is done. + # If it fails/crashes, fall through to normal password prompt as safety net. pam-any = { order = cfg.order; - control = "required"; + control = "[success=done default=ignore]"; modulePath = "${pam-any}/lib/security/pam_any.so"; args = [ "${pamAnyConfigFile}" ]; }; - # Disable the default unix password auth since pam-any - # handles it via the pam-any-password helper service. - unix.enable = lib.mkForce false; - # Keep deny as a safety net (it won't be reached if - # pam-any is required and returns success/failure). + # Fallback: keep normal password auth but without nullok + # so empty passwords are never accepted. + unix = { + order = 11700; + control = "sufficient"; + modulePath = "${pkgs.linux-pam}/lib/security/pam_unix.so"; + args = lib.mkForce [ "likeauth" "try_first_pass" ]; + }; }; }); }; -- cgit v1.3.1