Commit Graph

284 Commits

Author SHA1 Message Date
Matt McHenry
2ecafd30f6 fscrypt: drop -experimental suffix and corresponding comment
upstream removed their warning in v0.3.1 (sept. 2021):
3f865a76c5

fixes #221731
2026-09-06 14:57:17 -04:00
Mikilio
a4d7562390 nixos/pam: add rosec
Adds security.pam.services.<name>.rosec.enable to automatically
unlock the user's rosec vault on login.
2026-08-22 16:00:45 +02:00
Eman Resu
5c483d4767 various: partially apply prefix/suffix/infix checks (#543869) 2026-07-26 21:41:24 +00:00
Martin Weinelt
2cc2d0808c nixos/pam: remove explicit hardcoded yescrypt (#541548) 2026-07-21 11:14:12 +00:00
Eman Resu
31043cff65 nixos/pam: partially apply hasInfix and replaceStrings 2026-07-20 10:30:09 -04:00
Eman Resu
153dc57d16 nixos/pam: Write all pam.d config in a single derivation (#525102) 2026-07-15 13:30:10 +00:00
Grimmauld
3d32e0705a nixos/pam: remove explicit hardcoded yescrypt
Both `pam_unix.so` and `pam_unix_ng.so` look at `ENCRYPT_METHOD` in
`/etc/login.defs` to determine the algorithm to use for password
encryption: 66fbd0382b/src/pam_unix_ng-common.c (L27-L62)
If this is not set, both already default to `YESCRYPT`.
The shadow module makes this configurable via
`security.loginDefs.settings.ENCRYPT_METHOD`, which also defaults to `YESCRYPT`.
Seeing as what was previously hardcoded is default anyways, with a global
configuration option to change it, there is no point to keep this.
2026-07-13 20:29:02 +02:00
Salva
0b7b877e9a pam: add support for oo7 2026-07-09 23:26:38 -06:00
夜坂雅
ec51ed1449 nixos/pam/u2f: add settings.{,cue_}prompt option 2026-07-01 15:38:40 +08:00
adisbladis
f072535eb2 nixos/pam: Write all pam.d config in a single derivation
Calling writeText in a loop is silly when we can use a single runCommand by passing all config as structured attrs.
2026-06-29 02:32:30 +12:00
Aaron Andersen
6986b21e85 nixos/pam: allow disabling entirely (#512541) 2026-06-24 21:27:51 +00:00
Grimmauld
ad462fc106 nixos/pam: introduce enableLegacySettings option 2026-06-24 10:49:40 +02:00
Grimmauld
9af57289b3 nixos/pam: allow changing pam_unix module path 2026-06-24 10:16:01 +02:00
adisbladis
4eb838f5d2 nixos/pam: Refactor with an eye for performance
This moves up some variables in scope, changes iteration patterns & and eliminates use of `lib.pipe`.
2026-05-28 14:30:14 +12:00
Sam Pointon
2c636c7616 nixos/pam: allow disabling entirely
In containers, it can be reasonable to have no interactive logins at all 
and to run the container entirely 'lights out'. In this setting, PAM is 
dead weight, and adds considerably to container image size (mostly by 
bringing other things in to the closure). However, presently, there's no 
way to get rid of it.

This change adds the coarse tool of entirely disabling PAM. There 
_could_ be a warning or even an assertion, but I reasoned that there 
might be odd cases where it's desired - and not having PAM is not 
something that entirely disables the system, so a hard assertion feels 
wrong, and there are plenty of other ways to misconfigure a system if 
you go looking for trouble. I am also trying not to get sucked in to the 
morass of reforming pam.nix more broadly to make it less cumbersome, 
hence the coarsity of the setting.
2026-05-19 12:16:16 +01:00
andre4ik3
3b2061fddb nixos/pam: rename updateWtmp to lastlog.enable, add silent option 2026-05-05 15:09:34 +00:00
Majiir Paktu
9d5a303cfb nixos/pam: filter include/substack paths from apparmor mr rules 2026-04-19 12:09:31 -04:00
Paul Haerle
5aa9012bb3 nixos: replace 'text' with structured PAM rules (#420889) 2026-04-14 21:22:07 +00:00
Majiir Paktu
2fb68fdb50 nixos/pam: add u2f.control option 2026-04-11 22:12:44 -04:00
Majiir Paktu
d0ea24542d nixos/pam: rename u2fAuth -> u2f.enable 2026-04-11 22:07:56 -04:00
Majiir Paktu
4b864991aa nixos: replace 'text' with structured PAM rules
Several modules define whole PAM service rule stacks by overwriting the
default value of the 'text' option. Instead, we disable useDefaultRules
for these services and declare a new set of rules using the 'rules'
option. This option is considered experimental and hidden from users,
but it is supported for use within nixpkgs.
2026-04-10 21:42:11 -04:00
Majiir Paktu
ab27ce1f96 nixos/pam: extract autoOrderRules to utils
This function is used to convert an ordered list of rules into an
attrset of rules with reasonable 'order' values. This reduces
boilerplate to define 'order' and makes it simple to switch how ordering
is managed in the future.
2026-04-10 20:55:34 -04:00
Majiir Paktu
a6144954c6 nixos/pam: add assertion for autoOrderRules 2026-04-10 20:47:24 -04:00
Majiir Paktu
6954501f53 nixos/pam: add useDefaultRules option
This option is enabled by default to preserve the current behavior when
a new service is declared. Users may disable this option to more easily
create a service without any rules. In nixpkgs, we can use this option
to eliminate usage of the 'text' option where the entire service rule
stack is replaced.
2026-04-10 20:47:24 -04:00
Majiir Paktu
e778520f71 nixos: use full path to PAM modules
PAM rules with non-absolute module paths are rejected when apparmor is
used. In general, it helps (aside from readability) for all the module
paths to be absolute, especially when the user overrides the PAM
package.
2026-04-10 20:47:24 -04:00
Edward Tjörnhammar
72ec3724b5 nixos/pam: add slurm_pam(_adopt) support 2026-03-14 17:20:35 +01:00
Adam C. Stephens
72a5cad11b kanidm: refactor option organization and integrate ssh (#485079) 2026-02-06 19:47:20 +00:00
Wolfgang Jeltsch
8a77a297cd pam: add missing article to the security.pam.enableUMask docs 2026-01-31 13:07:20 +02:00
rkuklik
7ae6c9bf88 kanidm: refactor option organization and integrate ssh
Change option names to be consistent with other NixOS modules and
option to integrate with Kanidm SSH keys when using the unix module.
2026-01-29 21:15:05 +01:00
Jo
e147f2f65d nixos/: remove references to the xorg namespace (#482828) 2026-01-26 14:00:06 +00:00
quantenzitrone
3e622a5110 nixos: remove references to the xorg namespace
this only creates the usual nixos module rebuilds
2026-01-25 22:58:40 +01:00
Mihai Fufezan
c29b9ef82a nixos/howdy: init 2026-01-20 17:21:05 +02:00
Sigmanificient
a939c13d89 ecryptfs: drop 2026-01-14 09:33:38 +01:00
Alex Ionescu
9f7a1598df nixos/pam: add rule for pam_umask 2026-01-01 21:04:16 +02:00
Sandro
4508148804 nixos/pam: add zfs.mountRecursively option (#414197) 2025-11-26 16:50:17 +00:00
Gregor Kleen
f94eec282e nixos/pam: fix infinite recursion 2025-11-09 13:58:38 +01:00
Sandro Jäckel
db80d03091 nixos/pam: do not define an empty supportedFilesystems list
this shows up in options.boot.supportedFilesystems.definitionsWithLocations and makes debugging harder
2025-10-07 01:38:49 +02:00
nixpkgs-ci[bot]
53fe08332e Merge master into staging-next 2025-08-21 20:43:13 +00:00
K900
35d0bafabf nixos/treewide: clean up Plasma 5 references
Preparing to drop.
2025-08-21 22:31:56 +03:00
Grimmauld
a1d47a4ca3 nixos/pam: fix lastlog2 import service 2025-08-11 10:37:49 +02:00
Grimmauld
f3cd67c5b7 nixos/pam: enable lastlog2 import service if any pam service uses lastlog 2025-08-10 18:55:04 +02:00
K900
801b363af8 nixos/pam: switch to lastlog2 (#429203) 2025-08-10 11:13:57 +03:00
Grimmauld
d30eeb3ef4 nixos/pam: switch to lastlog2
Adaptation of #282337 to use `util-linux` as `lastlog2` provider

Co-Authored-By: Maxine Aubrey <35892750+amaxine@users.noreply.github.com>
2025-07-31 16:58:55 +02:00
Grimmauld
9142cadd5e nixos/pam: point to systemd.settings.Manager 2025-07-28 11:24:16 +02:00
Wolfgang Walther
5a0711127c treewide: run nixfmt 1.0.0 2025-07-24 13:55:40 +02:00
Colin Hooper
76f5b40db7 nixos/pam: add zfs.mountRecursively option 2025-06-03 16:20:28 +01:00
Antonio
8331187976 Google Authenticator 2FA support over XRDP 2025-05-17 22:43:14 +02:00
Ryan Hendrickson
2ef165538a nixos/pam: conditional enabling of services 2025-04-15 23:19:42 -04:00
Silvan Mosberger
374e6bcc40 treewide: Format all Nix files
Format all Nix files using the officially approved formatter,
making the CI check introduced in the previous commit succeed:

  nix-build ci -A fmt.check

This is the next step of the of the [implementation](https://github.com/NixOS/nixfmt/issues/153)
of the accepted [RFC 166](https://github.com/NixOS/rfcs/pull/166).

This commit will lead to merge conflicts for a number of PRs,
up to an estimated ~1100 (~33%) among the PRs with activity in the past 2
months, but that should be lower than what it would be without the previous
[partial treewide format](https://github.com/NixOS/nixpkgs/pull/322537).

Merge conflicts caused by this commit can now automatically be resolved while rebasing using the
[auto-rebase script](8616af08d9/maintainers/scripts/auto-rebase).

If you run into any problems regarding any of this, please reach out to the
[formatting team](https://nixos.org/community/teams/formatting/) by
pinging @NixOS/nix-formatting.
2025-04-01 20:10:43 +02:00
Peder Bergebakken Sundt
953f72e76e nixos/*: tag manpage references 2025-01-27 02:47:01 +01:00