In Progress

Noctalia Greeter sync settings disappear — overlay packages `/usr/bin` etc. as world-writable (777)

Reported by etrigan63 · assigned to Tohur
Report
September 25, 2026 4:49 AM

Summary

The "Noctalia Greeter" sync section in the Noctalia Settings app (reachable by searching "greet" or via **Settings → Security → Noctalia Greeter → Sync Now**  is missing. The Noctalia Shell daemon refuses to trust the greeter sync helper because its containing prefixes (`/usr/bin`, `/usr/lib`, `/usr/libexec`) are world-writable (mode `777`). RakuOS's ostree overlay produces these directories with mode `777` instead of the standard `755 root:root`. Restoring `755` fixes the issue.


Environment

  • OS: RakuOS (Fedora 44 immutable base, ostree overlay)
  • `/usr` is an overlay mount:
  • `lowerdir=/sysroot/usr`, `upperdir=/sysroot/ostree/deploy/default/var/lib/rakuos/overlay/upper`
  • Session: Niri (Wayland)
  • Noctalia Shell: v5.1.0
  • Noctalia Greeter: 1.5.0
  • Helper: `/usr/bin/noctalia-greeter-apply-appearance`
  • Polkit action: `org.noctalia.greeter.sync-appearance` (`/usr/share/polkit-1/actions/org.noctalia.greeter.apply-appearance.policy`)


Steps to reproduce

  1. Boot RakuOS and log in (Noctalia Shell on Niri).
  2. Open the Noctalia Settings panel and search for "greet".
  3. Observe: the greeter sync control does not appear (it did before this regression / on other systems).


Root cause

The overlay upper layer creates these directories as world-writable:

ls -ld /usr/bin /usr/lib /usr/libexec

drwxrwxrwx 1 root root ... /usr/bin

drwxrwxrwx 1 root root ... /usr/lib

drwxrwxrwx 1 root root ... /usr/libexec


(Confirmed directly in the overlay upper dir: `/sysroot/ostree/deploy/default/var/lib/rakuos/overlay/upper/bin` is mode `777`.)


The Noctalia docs state:


"Noctalia rejects a helper in a user-owned checkout or writable prefix; manual builds must be installed into a root-owned, non-user-writable system prefix."


Because `/usr/bin` is world-writable, the daemon refuses the helper and hides the whole Sync/Greeter settings section. Journal/daemon log (`~/.cache/noctalia/noctalia.log`):

[WRN] [greeter-sync] refusing untrusted greeter sync helper '/usr/bin/noctalia-greeter-apply-appearance'


Verification / workaround

Fix the directory modes in the overlay upper layer (survives the current boot; will need to be applied again after any repack/layering step that resets them):


sudo chmod 755 /usr/bin /usr/lib /usr/libexec


Then restart the Noctalia daemon (or log out and back in). After the fix:


  • `ls -ld /usr/bin` reports `drwxr-xr-x root root` (755).
  • The `[WRN] refusing untrusted greeter sync helper` line no longer appears in `~/.cache/noctalia/noctalia.log`.
  • The "greet" search in Noctalia Settings finds **Security → Noctalia Greeter → Sync Now** again.
  • `noctalia-greeter-apply-appearance --supports secure-sync-v1` returns `0`.


Requested upstream action

Ensure the overlay packaging creates `/usr/bin`, `/usr/lib`, `/usr/libexec` (and any other system binary/library prefixes) with mode `0755` owned by `root:root`, not `0777`. A world-writable system prefix is both a Noctalia-compat break and a general privilege-injection hazard (any local user could plant a binary that shadows a system one).


Privacy

No privacy-sensitive data included; all paths and outputs above are system-level and reproducible on any affected install.

Reply
September 25, 2026 4:51 AM

Alright thanks will fix and apply a fix for exsiting systems

Reply
September 25, 2026 5:00 AM

Glad I could help.

Reply
September 25, 2026 5:01 AM
etrigan63 wrote:
Glad I could help.

making fix now that should fix this for new and current installs :)

Reply