Skip to content

Config/integration batch: PAM, xkb paths, nix srcs, docs (5 verified + refutations noted) #2086

Description

@Swastik36

Summary

Batch of verified config/integration bugs (PAM, hardcoded paths, nix, docs). 5 confirmed, plus notes on partial claims so nothing is overstated. Verified at commit 4325418e. No fixes applied.

Environment

  • Shell commit: 4325418e (caelestia-dots/shell, Sep 2026)
  • OS: CachyOS Linux, Hyprland; also affects NixOS/HM users

Confirmed bugs

1. PAM nullok permits empty passwords (med, scoped)

  • File: assets/pam.d/passwd:4: auth [success=1 default=bad] pam_unix.so nullok. modules/lock/Pam.qml:48-49,93 sends buffer with no empty guard (respond("") reachable via Enter).
  • Null-password accounts unlock with one Enter. Note: does NOT bypass accounts with a real password; standard system-auth also uses nullok.

2. PAM stack from user-writable dir (high mechanism, scoped exploit)

  • Files: modules/lock/Pam.qml:80,230 (configDirectory: Quickshell.shellPath("assets/pam.d")), CMakeLists.txt:71-72 (installs assets → ${INSTALL_QSCONFDIR}).
  • Any writer as the user can swap in pam_permit.so → lock bypass. Scoped: already requires the victim user's write access; not a physical-only bypass. Suggest root-owned /etc/pam.d stack and/or permission hardening + docs warning.

3. KbLayoutModel hardcoded xkb paths + undeclared xmllint (med)

  • Files: modules/bar/popouts/kblayout/KbLayoutModel.qml:137,148 (xmllint ... /usr/share/X11/xkb/rules/base.xml, evdev.xml, no env fallback), absent from README.md:71-96 manual deps and nix/default.nix:40-54 runtimeDeps.
  • Breaks on NixOS (no /usr/share/X11…) / minimal Arch without libxml2 → _xkbMap={}, silent fallback to raw codes. Correction to an earlier broader claim: services/Hypr.qml:154 DOES have a CAELESTIA_XKB_RULES_PATH fallback (set by nix/flake), so only the KbLayoutModel half is broken.

4. Wallpaper silently no-ops without CLI (med)

  • Files: services/Wallpapers.qml:33,38,94,102,117 (unconditional execDetached(["caelestia","wallpaper",…]), no exists-check/fallback), nix/default.nix:33,54 (withCli ? false; default package per README excludes CLI).
  • All wallpaper changes silently no-op. Correction: no exec loop — handlers set actualCurrent once without re-triggering FileView.

5. Nix whole-repo src + dangling PAM .so (med)

  • File: nix/default.nix:112 (src = ./..) vs :74-76,92-95 (correct lib.fileset.toSource); :127-131 rewrites pam_fprintd/howdy.so to absolute /run/current-system/sw/lib/security/….
  • Ships .git/docs/build/ to store (bloat/hash churn); non-NixOS/HM-standalone gets dangling absolute .so → fprint/howdy always fail despite availCommand gating.

Investigated but NOT bugs (to avoid noise)

  • nix/hm-module.nix:31-36,86-89: no eval error — wayland.systemd.target is standard HM, mkIf content lazy, source exists when settings!={}. Only edge staleness (extraConfig!="" + settings=={} → no trigger).
  • README TIP sudo $HOME → /root: FALSE as written — cmake configure runs unprivileged (correct $HOME), only cmake --install runs under sudo with cached absolute path. TRUE half: update section (git pull only, no rebuild/reinstall) leaves stale install under /.
  • INSTALL_LIBDIR ignored at runtime (Paths.qml:24 fallback /usr/lib/caelestia, CMakeLists.txt:40 never baked in): TRUE, but "TIP verbatim breaks" FALSE — verbatim leaves default so sudo cmake --install still populates /usr/lib/caelestia. Breaks only when user sets INSTALL_LIBDIR without CAELESTIA_LIB_DIR.
  • shell.json values (maxVolume:1.5, favouriteApps:["thunar"], defaultPlayer:"mpv", weatherLocation:"lat,lon"): valid configs, not code bugs (ServicesPage.qml:171-179 allows to 200%; mpv matches mpv-mpris identity with list[0] fallback; coords are documented input). Only TRUE sub-claim: quickToggles vpn enabled with no utilities.vpn.provider is a dead toggle (filtered by Toggles.qml:31-32).

Expected / Actual

Expected: guarded PAM defaults, FHS-independent paths with declared deps, CLI presence check, tight nix srcs, accurate docs.
Actual: silent fallbacks/no-ops and user-writable PAM under triggers above.

Additional Context

Each re-verified by second pass on exact lines, including the refutations. Happy to split or PR per fix.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions