git.lucas.co / cce-display-manager
login greeter
git clone https://git.lucas.co/cce-display-manager.git

commit7ac64bc92c63264577ab1dfb62706f911f6833b5
parentd73bcbebd0
authorLucas Galante <lsgalante12@gmail.com>
date2026-09-25 14:56
fix: the greeter no longer opens a PAM session of its own

authenticate() + acct_mgmt() is the whole credential check; the daemon's
session worker opens the real session. The greeter's open_session()
registered a throwaway logind session under cage and ran
pam_gnome_keyring's auto_start, which forks out of this multi-threaded
Vulkan process; that child could wedge before exec, and the login froze
on "Authenticating..." after the password had been accepted.

Written 2026-09-18 and deployed to /usr/bin since 2026-09-21 (the Sep 22
password login shows gkr-pam's auth-only "stashed password" and no
session opened from the greeter), but never committed until now.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

 src/main.rs | 15 ++++++++++-----
 1 file changed, 10 insertions(+), 5 deletions(-)

diff --git a/src/main.rs b/src/main.rs
index 370ebd0..2df1f3e 100644
--- a/src/main.rs
+++ b/src/main.rs
@@ -1052,16 +1052,21 @@ fn authenticate_user(request_id: u64, username: String, password: String, sender
             }
         };
 
+        // authenticate() + acct_mgmt() is the whole credential check. Do NOT
+        // open a PAM session here: the daemon's session worker
+        // (launch_session) opens the real one. The greeter used to call
+        // open_session() too, which registered a throwaway logind session
+        // with this process as leader and ran pam_gnome_keyring's
+        // auto_start — a fork() out of this multi-threaded Vulkan process
+        // that then setuid()s and exec()s gnome-keyring-daemon. That child
+        // could wedge before exec (seen 2026-09-18), and gkr-pam waits on
+        // its pipes with no timeout, so the login froze on
+        // "Authenticating..." after the password had been accepted.
         if let Err(e) = auth.authenticate() {
             let _ = sender.send(AuthEvent::Failure { request_id, err_msg: format!("{:?}", e) });
             return;
         }
 
-        if let Err(e) = auth.open_session() {
-            let _ = sender.send(AuthEvent::Failure { request_id, err_msg: format!("{:?}", e) });
-            return;
-        }
-
         let _ = sender.send(AuthEvent::Success { request_id, username });
     });
 }