fedora-remote: fix GDM greeter so headless RDP renders
Build containers / Compute changes (push) Successful in 2s
Build containers / fedora-cosmic (rawhide) (push) Failing after 48s
Build containers / fedora-remote (44) (push) Successful in 10m30s
Build containers / fedora-cosmic (44) (push) Successful in 14m21s
Build containers / Prune old releases and tags (push) Successful in 26s

The minimal base (recommends off) was missing session infrastructure and one
maintained service actively broke the greeter, so RDP clients saw only a white
screen:

- add dbus-daemon: gdm-wayland-session runs it for the greeter session bus
- add systemd-pam: pam_systemd starts the per-user systemd manager
- nsswitch: shadow must include systemd so pam_unix can resolve GDM 50's
  dynamic gdm-greeter user (Fedora 44 ships 'files systemd')
- mask uresourced: its resource tuning makes user@<uid>.service fail with
  'Failed to spawn executor', leaving no systemd user bus for gnome-session
This commit is contained in:
2026-09-30 19:00:29 +02:00
parent f2d7ad24ec
commit 172948822a
2 changed files with 17 additions and 1 deletions
+16
View File
@@ -26,6 +26,13 @@ packages:
# grd-firstboot generates the RDP TLS certificate with the openssl CLI.
- openssl
# GDM/gnome-session session infrastructure. The greeter needs the reference
# dbus-daemon for its session bus, and pam_systemd (systemd-pam) to start the
# per-user systemd manager; without them the greeter dies and RDP clients just
# get a white screen (base-atomic does not pull these in with recommends off).
- dbus-daemon
- systemd-pam
# Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients).
- kanidm-unixd-clients
@@ -76,6 +83,15 @@ postprocess:
install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf
fi
# uresourced's resource tuning breaks the GDM greeter's systemd user manager
# here: user@<uid>.service fails with "Failed to spawn executor" (result
# 'resources'), so the greeter never registers and RDP clients get a white
# screen. It is optional, so mask it.
- |
#!/usr/bin/env bash
set -xeuo pipefail
ln -sf /dev/null /etc/systemd/system/uresourced.service
# Kanidm SELinux policy (same approach as fedora-cosmic).
- |
#!/usr/bin/env bash
+1 -1
View File
@@ -1,6 +1,6 @@
passwd: kanidm compat systemd
group: kanidm compat systemd
shadow: files
shadow: files systemd
hosts: files dns myhostname
services: files
netgroup: files