login greeter
git clone https://git.lucas.co/cce-display-manager.git
fix: the greeter no longer opens a PAM session of its own
authenticate() + acct_mgmt() is the whole credential check; the daemon's
session worker opens the real session. The greeter's open_session()
registered a throwaway logind session under cage and ran
pam_gnome_keyring's auto_start, which forks out of this multi-threaded
Vulkan process; that child could wedge before exec, and the login froze
on "Authenticating..." after the password had been accepted.
Written 2026-09-18 and deployed to /usr/bin since 2026-09-21 (the Sep 22
password login shows gkr-pam's auth-only "stashed password" and no
session opened from the greeter), but never committed until now.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
src/main.rs | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/src/main.rs b/src/main.rs
index 370ebd0..2df1f3e 100644
--- a/src/main.rs
+++ b/src/main.rs
@@ -1052,16 +1052,21 @@ fn authenticate_user(request_id: u64, username: String, password: String, sender
}
};
+ // authenticate() + acct_mgmt() is the whole credential check. Do NOT
+ // open a PAM session here: the daemon's session worker
+ // (launch_session) opens the real one. The greeter used to call
+ // open_session() too, which registered a throwaway logind session
+ // with this process as leader and ran pam_gnome_keyring's
+ // auto_start — a fork() out of this multi-threaded Vulkan process
+ // that then setuid()s and exec()s gnome-keyring-daemon. That child
+ // could wedge before exec (seen 2026-09-18), and gkr-pam waits on
+ // its pipes with no timeout, so the login froze on
+ // "Authenticating..." after the password had been accepted.
if let Err(e) = auth.authenticate() {
let _ = sender.send(AuthEvent::Failure { request_id, err_msg: format!("{:?}", e) });
return;
}
- if let Err(e) = auth.open_session() {
- let _ = sender.send(AuthEvent::Failure { request_id, err_msg: format!("{:?}", e) });
- return;
- }
-
let _ = sender.send(AuthEvent::Success { request_id, username });
});
}