From 19c544dd1ebda84d977fb4b2e8e7e690734c483b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marco=20Trevisan=20=28Trevi=C3=B1o=29?= Date: Sun, 19 Jul 2026 12:03:56 +0200 Subject: [PATCH] build: Install the gdm service files in the system pam config path Installing service files in /etc/pam.d it's not something that we should do since such path is meant to be used for configuration files and so potential sys admin overrides. As per this, install the service files in /usr/lib/pam.d by default and fallback to the /etc ones if none is found. Part-of: --- data/meson.build | 4 ++-- meson.build | 8 ++++++-- utils/gdm-config.c | 16 +++++++++++++--- 3 files changed, 21 insertions(+), 7 deletions(-) diff --git a/data/meson.build b/data/meson.build index 2fced1089..9c2496fa8 100644 --- a/data/meson.build +++ b/data/meson.build @@ -96,7 +96,7 @@ pam_data_files = pam_data_files_map.get(default_pam_config, []) foreach _pam_filename : pam_data_files install_data('pam-@0@/@1@.pam'.format(default_pam_config, _pam_filename), rename: _pam_filename, - install_dir: pam_config_services_dir, + install_dir: pam_sys_services_dir, ) endforeach @@ -115,7 +115,7 @@ if default_pam_config == 'redhat' output: 'gdm-@0@-substack'.format(service), configuration: pam_conf, install: true, - install_dir: pam_config_services_dir, + install_dir: pam_sys_services_dir, ) endforeach endif diff --git a/meson.build b/meson.build index 39d62578c..2587ff19b 100644 --- a/meson.build +++ b/meson.build @@ -34,7 +34,7 @@ gdm_private_dbus_dir = (get_option('private-dbus-dir') != '')? get_option('priva gdm_dyn_home_dir = (get_option('dyn-home-dir') != '')? get_option('dyn-home-dir') : gdm_run_dir / 'home' pam_prefix = (get_option('pam-prefix') != '')? get_option('pam-prefix') : gdm_prefix pam_mod_dir = (get_option('pam-mod-dir') != '')? get_option('pam-mod-dir') : pam_prefix / get_option('libdir') / 'security' -pam_sys_services_dir = pam_prefix / 'lib' / 'pam.d' +pam_sys_services_dir = (get_option('pam-services-dir') != '')? get_option('pam-services-dir') : pam_prefix / 'lib' / 'pam.d' pam_config_services_dir = pam_prefix / get_option('sysconfdir') / 'pam.d' have_x11_support = get_option('x11-support') # Common variables diff --git a/meson_options.txt b/meson_options.txt index c13fc0d50..1edac306b 100644 --- a/meson_options.txt +++ b/meson_options.txt @@ -13,6 +13,7 @@ option('lang-file', type: 'string', value: '', description: 'File containing def option('libaudit', type: 'feature', value: 'auto', description: 'Add Linux audit support.') option('logind-provider', type: 'combo', choices: ['systemd', 'elogind'], value: 'systemd', description: 'Which logind library to use.') option('log-dir', type: 'string', value: '/var/log/gdm', description: 'Log directory.') +option('pam-services-dir', type: 'string', value: '', description: 'Directory to install PAM services in.') option('pam-mod-dir', type: 'string', value: '', description: 'Directory to install PAM modules in.') option('pam-prefix', type: 'string', value: '', description: 'Specify where PAM files go.') option('pid-file', type: 'string', value: '', description: 'Pid file.') diff --git a/utils/gdm-config.c b/utils/gdm-config.c index c8fbbca23..ded899445 100644 --- a/utils/gdm-config.c +++ b/utils/gdm-config.c @@ -1438,11 +1438,21 @@ static gboolean have_pam_module (GdmAuthType auth_type) { g_autofree char *pam_service = NULL; + g_autofree char *pam_service_name = NULL; - pam_service = g_strdup_printf (PAM_CONFIG_SERVICES_DIR "/gdm-%s", - auth_type_to_string (auth_type)); + pam_service_name = g_strdup_printf ("/gdm-%s", + auth_type_to_string (auth_type)); + pam_service = g_build_filename (PAM_CONFIG_SERVICES_DIR, pam_service_name, NULL); - g_debug ("Checking for PAM profile “%s” existance", pam_service); + g_debug ("Checking for PAM profile “%s” existence", pam_service); + + if (g_file_test (pam_service, G_FILE_TEST_EXISTS | G_FILE_TEST_IS_REGULAR)) { + return TRUE; + } + + g_set_str (&pam_service, g_build_filename (PAM_SYS_SERVICES_DIR, pam_service_name, NULL)); + + g_debug ("Checking for PAM profile “%s” existence", pam_service); return g_file_test (pam_service, G_FILE_TEST_EXISTS | G_FILE_TEST_IS_REGULAR); } -- GitLab