r/archlinux • u/GodderDam • 21h ago
SUPPORT oo7 + COSMIC/greetd: pam_oo7 tries to launch /usr/bin/oo7-daemon, but Arch installs it in /usr/lib What should I do?
DISCLAIMER: a LLM helped me write this because I'm no expert and couldn't possibly provide all these info on my own
I'm trying to set up oo7 as my Secret Service implementation on Arch Linux with COSMIC.
My environment:
- COSMIC Wayland
- greetd + cosmic-greeter
oo7 0.6.0-3from the official Arch repositorieslibsecretinstalled- PAM authentication through
login
I followed the ArchWiki oo7 instructions and initially put the PAM entries in /etc/pam.d/greetd, but eventually discovered that my COSMIC Greeter configuration contains:
[general]
service = "login"
So I moved the PAM configuration to /etc/pam.d/login:
auth required pam_securetty.so
auth requisite pam_nologin.so
auth include system-local-login
auth optional pam_oo7.so
account include system-local-login
session include system-local-login
session optional pam_oo7.so
password include system-local-login
After rebooting, pam_oo7 is definitely being invoked during login. The journal shows:
greetd[1368]: Connecting to daemon socket at: /run/user/1000/oo7-pam.sock
greetd[1286]: Failed to send secret to oo7 daemon: Failed to connect to daemon socket: Child process failed with exit code 1
The interesting part is that the PAM module appears to try to start the daemon when the socket doesn't exist.
I inspected the installed pam_oo7.so and found these strings:
Socket not found, attempting to start daemon
Attempting to start oo7-daemon directly
/usr/bin/oo7-daemon
Started oo7-daemon with PID
Child process terminated abnormally
However, the installed package does not provide /usr/bin/oo7-daemon.
For example:
$ ls -l /usr/bin/oo7-daemon
ls: cannot access '/usr/bin/oo7-daemon': No such file or directory
But the package does provide:
/usr/lib/oo7-daemon
/usr/lib/security/pam_oo7.so
The systemd user service also points to the /usr/lib location:
ExecStart=/usr/lib/oo7-daemon
The service itself is currently disabled, as recommended for the PAM setup.
So as far as I can tell, the situation is:
pam_oo7
↓
/run/user/1000/oo7-pam.sock doesn't exist
↓
tries to start /usr/bin/oo7-daemon
↓
/usr/bin/oo7-daemon doesn't exist
↓
child exits with code 1
↓
PAM can't connect to the socket
I'm not going to create a symlink or otherwise modify the installation yet, because I don't know whether this is:
- a packaging bug in
oo7 0.6.0-3, - an intentional difference between the PAM module and the packaged daemon location,
- something specific to how
pam_oo7is expected to be configured with greetd/COSMIC, or - something I'm misunderstanding about the intended daemon startup mechanism.
What is the correct way to handle this? Should pam_oo7 be starting /usr/lib/oo7-daemon somehow, should the daemon be started separately, or is the /usr/bin/oo7-daemon path in pam_oo7.so indicative of a package/version bug?
I'd appreciate guidance before I make any workaround changes.