# pam_fprintd_grosshack.so — fprintd's PAM module forked to accept the # password OR a fingerprint at the same prompt (upstream calls itself a # "gross hack"; it is also the field-standard answer to this PAM gap — # stock PAM cannot express parallel factors, linux-pam#301). # # Source reviewed before packaging (2026-07-12, v0.3.0 = fprintd 1.94.2 # base + ~60-line delta): every failure path — no reader, no enrolled # prints, fprintd absent, timeout, password typed — returns # PAM_AUTHINFO_UNAVAIL, i.e. the module FAILS and PAM falls through to # the password rule; a typed password is never validated here, only # ferried via PAM_AUTHTOK to pam_unix (try_first_pass). Accepted # quirks: installs a process-wide SIGUSR1 handler in the calling # process, pthread_cancels the prompt thread on fingerprint win, and # does not zeroize the prompt buffer. Consumed by # modules/nixos/hardware.nix (nomarchy.hardware.fingerprint.parallel). { lib, stdenv, fetchFromGitLab, meson, ninja, pkg-config, gettext, python3 , glib, libfprint, polkit, pam, systemd, dbus, libpam-wrapper }: stdenv.mkDerivation rec { pname = "pam-fprint-grosshack"; version = "0.3.0"; src = fetchFromGitLab { owner = "mishakmak"; repo = "pam-fprint-grosshack"; rev = "v${version}"; hash = "sha256-obczZbf/oH4xGaVvp3y3ZyDdYhZnxlCWvL0irgEYIi0="; }; # Only the PAM module is built (the fork disables every other fprintd # subdir), but the top-level meson still resolves the full fprintd # dependency set — hence libfprint/polkit in buildInputs. # pam_wrapper is only exercised by the (disabled) test suite, but the # top-level meson marks it required whenever the pam option is on. nativeBuildInputs = [ meson ninja pkg-config gettext python3 ]; buildInputs = [ glib libfprint polkit pam systemd dbus libpam-wrapper ]; mesonFlags = [ "-Dpam_modules_dir=${placeholder "out"}/lib/security" "-Dsystemd=false" "-Dman=false" ]; meta = { description = "PAM module accepting password or fingerprint in parallel (fprintd fork)"; homepage = "https://gitlab.com/mishakmak/pam-fprint-grosshack"; license = lib.licenses.gpl2Plus; platforms = lib.platforms.linux; }; }