Ship postlogin too, the other half of the seam kscreenlocker expects
fingerprint-auth alone was not enough. /etc/pam.d/kde-fingerprint is written for a Fedora/authselect layout and its auth stack is two lines: a substack of fingerprint-auth followed by an include of postlogin. Alpine ships neither. With only the first supplied, the fingerprint MATCHED and PAM still answered Permission denied -- the include of a missing service failing after the match had already succeeded, which is a confusing way to be told a file is absent. The daemon's own log said MATCH while pamtester said no. On Fedora postlogin does lastlog and umask bookkeeping. Nothing here needs that; what is needed is that the seam exists and contributes nothing, so the stack's result stays the one the fingerprint substack produced. Hence four optional pam_permit lines and a comment explaining why it is deliberately empty rather than merely unfinished. Also observed while testing, and worth knowing before anyone calls this broken: the lock screen arms fingerprint ONCE when it appears, waits 30 seconds -- pam_fprintd's own timeout -- and then cancels and falls back to a password. Pressing outside that window reaches nothing at all, and the daemon records it as `verify: cancelled over 0 press(es)`.
This commit is contained in:
parent
93d7f96a63
commit
fd244238d0
4 changed files with 33 additions and 2 deletions
|
|
@ -68,7 +68,7 @@ namespace {
|
|||
|
||||
// Bumping this is what publishes a package: the registry answers 409 for a
|
||||
// version it already has, which a build treats as a no-op.
|
||||
constexpr const char* Version = "0.2.1";
|
||||
constexpr const char* Version = "0.2.2";
|
||||
|
||||
bool g_verbose = false;
|
||||
// 500 ms was the research harness's pace, chosen so a human could read the
|
||||
|
|
|
|||
Loading…
Reference in a new issue