Both `pam_unix.so` and `pam_unix_ng.so` look at `ENCRYPT_METHOD` in
`/etc/login.defs` to determine the algorithm to use for password
encryption: 66fbd0382b/src/pam_unix_ng-common.c (L27-L62)
If this is not set, both already default to `YESCRYPT`.
The shadow module makes this configurable via
`security.loginDefs.settings.ENCRYPT_METHOD`, which also defaults to `YESCRYPT`.
Seeing as what was previously hardcoded is default anyways, with a global
configuration option to change it, there is no point to keep this.
In containers, it can be reasonable to have no interactive logins at all
and to run the container entirely 'lights out'. In this setting, PAM is
dead weight, and adds considerably to container image size (mostly by
bringing other things in to the closure). However, presently, there's no
way to get rid of it.
This change adds the coarse tool of entirely disabling PAM. There
_could_ be a warning or even an assertion, but I reasoned that there
might be odd cases where it's desired - and not having PAM is not
something that entirely disables the system, so a hard assertion feels
wrong, and there are plenty of other ways to misconfigure a system if
you go looking for trouble. I am also trying not to get sucked in to the
morass of reforming pam.nix more broadly to make it less cumbersome,
hence the coarsity of the setting.
Several modules define whole PAM service rule stacks by overwriting the
default value of the 'text' option. Instead, we disable useDefaultRules
for these services and declare a new set of rules using the 'rules'
option. This option is considered experimental and hidden from users,
but it is supported for use within nixpkgs.
This function is used to convert an ordered list of rules into an
attrset of rules with reasonable 'order' values. This reduces
boilerplate to define 'order' and makes it simple to switch how ordering
is managed in the future.
This option is enabled by default to preserve the current behavior when
a new service is declared. Users may disable this option to more easily
create a service without any rules. In nixpkgs, we can use this option
to eliminate usage of the 'text' option where the entire service rule
stack is replaced.
PAM rules with non-absolute module paths are rejected when apparmor is
used. In general, it helps (aside from readability) for all the module
paths to be absolute, especially when the user overrides the PAM
package.
Format all Nix files using the officially approved formatter,
making the CI check introduced in the previous commit succeed:
nix-build ci -A fmt.check
This is the next step of the of the [implementation](https://github.com/NixOS/nixfmt/issues/153)
of the accepted [RFC 166](https://github.com/NixOS/rfcs/pull/166).
This commit will lead to merge conflicts for a number of PRs,
up to an estimated ~1100 (~33%) among the PRs with activity in the past 2
months, but that should be lower than what it would be without the previous
[partial treewide format](https://github.com/NixOS/nixpkgs/pull/322537).
Merge conflicts caused by this commit can now automatically be resolved while rebasing using the
[auto-rebase script](8616af08d9/maintainers/scripts/auto-rebase).
If you run into any problems regarding any of this, please reach out to the
[formatting team](https://nixos.org/community/teams/formatting/) by
pinging @NixOS/nix-formatting.