From d0cd00069d0c9113bb2607921912f3b8f2e23bf6 Mon Sep 17 00:00:00 2001 From: Ryan Yin Date: Mon, 31 Aug 2026 12:22:32 +0800 Subject: [PATCH] fix(security): sync gnome login keyring password on passwd Enable gnomeKeyring for the passwd PAM service so pam_gnome_keyring updates the login keyring password when the login password changes. Fixes 'Unlock Login Keyring' prompt desync after changing the password via passwd (greetd session unlock alone does not update the keyring). --- modules/nixos/desktop/security.nix | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/modules/nixos/desktop/security.nix b/modules/nixos/desktop/security.nix index 3843101f..8458e520 100644 --- a/modules/nixos/desktop/security.nix +++ b/modules/nixos/desktop/security.nix @@ -14,12 +14,26 @@ gcr-ssh-agent.enable = false; }; # seahorse is a GUI App for GNOME Keyring. + # Pitfall: never use seahorse's "New -> Default keyring". pam_gnome_keyring + # hardcodes the keyring name "login" (unlocks/syncs only login.keyring), + # while Secret Service apps (gh, browsers) use the keyring named in + # ~/.local/share/keyrings/default. Creating a separate "Default keyring" + # forks secrets into a second container whose password never syncs with the + # login password, causing "Unlock Login Keyring" prompt desyncs. + # Keep everything in "login" and leave the `default` pointer unset (or + # pointing at "login"). programs.seahorse.enable = true; # The OpenSSH agent remembers private keys for you # so that you don’t have to type in passphrases every time you make an SSH connection. # Use `ssh-add` to add a key to the agent. programs.ssh.startAgent = true; security.pam.services.greetd.enableGnomeKeyring = true; + # Keep the login keyring password in sync with the login password when it is + # changed via `passwd`. Without this, pam_gnome_keyring only unlocks the + # keyring at login and a `passwd` change desyncs the two, causing + # "Unlock Login Keyring" prompt loops (and gh asking for a separate + # "keyring password"). + security.pam.services.passwd.enableGnomeKeyring = true; # gpg agent with pinentry programs.gnupg.agent = {