diff --git a/images/fedora-remote/custom.yaml b/images/fedora-remote/custom.yaml index a9925c9..d337f23 100644 --- a/images/fedora-remote/custom.yaml +++ b/images/fedora-remote/custom.yaml @@ -26,6 +26,13 @@ packages: # grd-firstboot generates the RDP TLS certificate with the openssl CLI. - openssl + # GDM/gnome-session session infrastructure. The greeter needs the reference + # dbus-daemon for its session bus, and pam_systemd (systemd-pam) to start the + # per-user systemd manager; without them the greeter dies and RDP clients just + # get a white screen (base-atomic does not pull these in with recommends off). + - dbus-daemon + - systemd-pam + # Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients). - kanidm-unixd-clients @@ -76,6 +83,15 @@ postprocess: install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf fi + # uresourced's resource tuning breaks the GDM greeter's systemd user manager + # here: user@.service fails with "Failed to spawn executor" (result + # 'resources'), so the greeter never registers and RDP clients get a white + # screen. It is optional, so mask it. + - | + #!/usr/bin/env bash + set -xeuo pipefail + ln -sf /dev/null /etc/systemd/system/uresourced.service + # Kanidm SELinux policy (same approach as fedora-cosmic). - | #!/usr/bin/env bash diff --git a/images/shared/files/kanidm-nsswitch.conf b/images/shared/files/kanidm-nsswitch.conf index c3857f5..f5ea5fc 100644 --- a/images/shared/files/kanidm-nsswitch.conf +++ b/images/shared/files/kanidm-nsswitch.conf @@ -1,6 +1,6 @@ passwd: kanidm compat systemd group: kanidm compat systemd -shadow: files +shadow: files systemd hosts: files dns myhostname services: files netgroup: files