Same issue as plasma-login-manager: the ly-autologin PAM service uses
relative module paths which fail when AppArmor is enabled.
Change the 3 non-include PAM rules to use absolute store paths via
${config.security.pam.package}/lib/security/pam_*.so.
Several modules define whole PAM service rule stacks by overwriting the
default value of the 'text' option. Instead, we disable useDefaultRules
for these services and declare a new set of rules using the 'rules'
option. This option is considered experimental and hidden from users,
but it is supported for use within nixpkgs.
This reverts commit 678f9ce5b7, reversing
changes made to 87cc2ba491.
Ly currently can't gracefully handle the missing parent directory of the
log file. In the commit to be reverted, the session log path is set to
`~/.local/state/ly-session.log`. If `~/.local/state` doesn't exist,
which is common when a new user is created with an empty home directory,
Ly can't automatically create the parent directory for the log file,
instead it prints a rather vague `FileNotFound` error message,
potentially confusing nost users.
See also the issue in the upstream repository:
<https://codeberg.org/fairyglade/ly/issues/896>.
Some options in ly's config.ini can have null as their value (for example, session_log), but the settings option in the NixOS module accepted only str, int and bool types.