From 172948822a783df377d18fcd487830c1ac84b2d2 Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Wed, 30 Sep 2026 19:00:29 +0200 Subject: [PATCH] fedora-remote: fix GDM greeter so headless RDP renders The minimal base (recommends off) was missing session infrastructure and one maintained service actively broke the greeter, so RDP clients saw only a white screen: - add dbus-daemon: gdm-wayland-session runs it for the greeter session bus - add systemd-pam: pam_systemd starts the per-user systemd manager - nsswitch: shadow must include systemd so pam_unix can resolve GDM 50's dynamic gdm-greeter user (Fedora 44 ships 'files systemd') - mask uresourced: its resource tuning makes user@.service fail with 'Failed to spawn executor', leaving no systemd user bus for gnome-session --- images/fedora-remote/custom.yaml | 16 ++++++++++++++++ images/shared/files/kanidm-nsswitch.conf | 2 +- 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/images/fedora-remote/custom.yaml b/images/fedora-remote/custom.yaml index a9925c9..d337f23 100644 --- a/images/fedora-remote/custom.yaml +++ b/images/fedora-remote/custom.yaml @@ -26,6 +26,13 @@ packages: # grd-firstboot generates the RDP TLS certificate with the openssl CLI. - openssl + # GDM/gnome-session session infrastructure. The greeter needs the reference + # dbus-daemon for its session bus, and pam_systemd (systemd-pam) to start the + # per-user systemd manager; without them the greeter dies and RDP clients just + # get a white screen (base-atomic does not pull these in with recommends off). + - dbus-daemon + - systemd-pam + # Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients). - kanidm-unixd-clients @@ -76,6 +83,15 @@ postprocess: install -m 0644 /usr/share/fedora-remote/authselect/nsswitch.conf /etc/nsswitch.conf fi + # uresourced's resource tuning breaks the GDM greeter's systemd user manager + # here: user@.service fails with "Failed to spawn executor" (result + # 'resources'), so the greeter never registers and RDP clients get a white + # screen. It is optional, so mask it. + - | + #!/usr/bin/env bash + set -xeuo pipefail + ln -sf /dev/null /etc/systemd/system/uresourced.service + # Kanidm SELinux policy (same approach as fedora-cosmic). - | #!/usr/bin/env bash diff --git a/images/shared/files/kanidm-nsswitch.conf b/images/shared/files/kanidm-nsswitch.conf index c3857f5..f5ea5fc 100644 --- a/images/shared/files/kanidm-nsswitch.conf +++ b/images/shared/files/kanidm-nsswitch.conf @@ -1,6 +1,6 @@ passwd: kanidm compat systemd group: kanidm compat systemd -shadow: files +shadow: files systemd hosts: files dns myhostname services: files netgroup: files