nixos/oo7-service: init - #526624
Conversation
c590496 to
923819b
Compare
|
1 similar comment
|
|
Thanks @DaRacci for the time you put into review this pr. I'll see if we can get it merged |
|
Also add a NixOS release note for the module addition |
81aaac5 to
edc3eca
Compare
|
If it's not an issue for you could you take over/do your own take on #539086 it seems the author of that PR blindly vibecodes a lot of the PR as you can see here: |
b790ef3 to
6dfcfe0
Compare
isabelroses
left a comment
There was a problem hiding this comment.
im happy to merge if no one else has anything else to say
8c19ce7 to
d8fd046
Compare
Scrumplex
left a comment
There was a problem hiding this comment.
Changes LGTM. Haven't actually tested the module though
|
Fresh-login validation shows that the PAM plumbing works, but the packaged oo7 0.6.0 daemon still breaks kubelogin's Secret Service keyring backend. The default collection is unlocked after login. kubelogin's Linux backend first checks the hard-coded The generic fix belongs in this oo7 service/package PR, either by carrying the upstream patch until the next oo7 release or by updating to a release that contains it: server: Resolve aliases in set_locked. A useful regression test is a fresh PAM login followed by a Secret Service client write/read through the default collection alias. Assisted by: GPT-5.6 Luna |
Things done
passthru.tests.nixpkgs-reviewon this PR. See nixpkgs-review usage../result/bin/.