`crate::logind::is_available()` function was used despite `logind`
module being gated behind `logind` feature, `cfg!(feature = "logind")`
was used wrongly here as it doesn't remove surrounding code from
compilation.
Additionally initialized nix development shell and a nix package with
support for flakes and legacy nix, let me know if it's too complicated
for this repo.
- [x] I have disclosed use of any AI generated code in my commit
messages.
- If you are using an LLM, and do not fully understand the changes it is
making to the code base, do not create a PR.
- In our experience, AI generated code often results in overly complex
code that lacks enough context for a proper fix or feature inclusion.
This results in considerably longer code reviews. Due to this, AI
authored or partially authored PRs may be closed without comment.
- [x] I understand these changes in full and will be able to respond to
review comments.
- [x] My change is accurately described in the commit message.
- [x] My contribution is tested and working as described.
- [x] I have read the [Developer Certificate of
Origin](https://developercertificate.org/) and certify my contribution
under its conditions.
greetd delivers PAM_ERROR_MSG as an auth message of type Error, and ipc.rs
turned that into Message::Error, which cancels the greetd session. But such a
message describes the current attempt, not the end of the conversation:
pam_fprintd reports "Failed to match fingerprint" this way and then retries
until max-tries is reached.
The consequence at the login screen is that a single failed fingerprint press
ends the conversation. The greeter reconnects and immediately creates a new
session, whose PAM worker calls fprintd's Claim 14 ms later while the previous
worker still holds it, so the claim is denied and no fingerprint prompt ever
appears again. The previous worker only exits when it next tries to talk to the
greeter, which can be arbitrarily far in the future, so delaying the new session
does not help either.
Per the greetd protocol every auth message has to be acknowledged with
PostAuthMessageResponse, and for a non-interactive one the response is None,
which is what the Info arm already does. Route the Error message to its own
Message::AuthError that shows the text and acknowledges it. Message::Error and
the Response::Error path stay as they are, so a failed authentication still
cancels the session.
Drafted with AI assistance (Claude Code); the change and the measurements behind
it were reviewed and tested by me on real hardware.
Signed-off-by: chris-010 <10660568+chris-010@users.noreply.github.com>
Message::Auth is constructed in exactly one place, the .on_submit of the
password input, and it forwards whatever the field holds to greetd. An
empty field therefore sends PostAuthMessageResponse with response
Some(""), PAM rejects it, and greetd tears the session down; the greeter
then reconnects with a fresh CreateSession. Every stray Enter costs that
round trip, and while it runs the user is looking at the authenticating
spinner.
Non-interactive auth messages (AuthMessageType::Info) are acknowledged
separately with response None and never reach Message::Auth, so an empty
Some can only come from the user submitting an empty field.
This is the login-screen counterpart of the lock-screen fix in #509. The
two do not overlap; that one guards Message::Submit in locker.rs.
Drafted with AI assistance (Claude Code); the change was reviewed, built
and tested by me as described.
Signed-off-by: chris-010 <10660568+chris-010@users.noreply.github.com>
The greeter daemon runs as root without HOME set, so
xdg::BaseDirectories resolved the state dir against root's
environment and never found the user's cosmic-comp output layout.
The greeter therefore came up with the default monitor arrangement
instead of the saved one.
Resolve the home directory from the passwd entry of the user being
described, read ~/.local/state/cosmic-comp/outputs.ron directly, and
fall back to an empty list when the file is absent.
Also revert the two version fields that the 1.3.0 bulk bump rewrote by
mistake: greetd_ipc has no 1.3.0 release, and the crate version is kept
at 0.1.0 to stay consistent with Cargo.lock so --locked builds work.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Downstream distributions have optional logind, but the logind feature
must be defined at compile time. If cosmic-greeter is compiled with
logind support it fails to run on a host that's not running logind.
Detect whether logind is present at runtime, enabling the use of the
same binaries regardless of whether logind is installed or not.