Original Post
September 29, 2026 1:23 PM · edited
Here is a summary of what I had to do to get Niri, Noctalia 5, & Noctalia Greeter fully operational. Sorry about the formatting importing .md files doesn't work.
RakuOS: Niri + Noctalia fixes and changes (summary for devs)
Collected on a RakuOS (Fedora 44 ostree overlay) system, Niri session with Noctalia Shell v5.1.0 + Noctalia Greeter 1.5.0.
1. RakuOS packaging bug: /usr/bin,/usr/lib,/usr/libexec created world-writable (0777)
Impact: Noctalia Shell daemon refused the greeter sync helper and the Sync Greeter settings section disappeared (searching “greet” found nothing).
- The ostree overlay upper dir creates system binary prefixes as
0777: - Noctalia validates the helper prefix must be root-owned and non-user-writable; with 0777 it logged repeatedly:
[WRN] [greeter-sync] refusing untrusted greeter sync helper '/usr/bin/noctalia-greeter-apply-appearance' - Working fix applied:
chmod 755 /usr/bin /usr/lib /usr/libexec, then restartnoctalia. Sync section returns;/usr/binnow755 root:root. - Requested upstream: package these dirs as
0755 root:root, not0777. A world-writable/usr/binis also a general privilege-injection hazard. - Note: the overlay repack will reset them to 0777 again; this is a packaging defect, not a user-config issue.
2. Greeter cursor theme
- File:
/var/lib/noctalia-greeter/greeter.toml - Greeter now uses the shell cursor (Bibata) instead of the wlroots default.
3. Greeter auth: fingerprint disabled on the login screen, password-only
- File:
/etc/pam.d/greetd - Greeter PAM is a fingerprint-free
password-authsubstack, so login is password-only (fingerprint remains available for the desktop session/system-auth). Avoids the serialize-then-timeout fingerprint→password delay on the greeter. - Session/desktop sudo/fingerprint auth unchanged.
4. Greeter ↔ shell appearance sync (Noctalia Settings → Sync Now)
- Enabled and verified:
noctalia-greeter passwordless-syncactive for userguru(Polkit rule allows passwordless constrained sync). ~/.config/xdg-desktop-portaland the daemon host the sync path; sync writes into/var/lib/noctalia-greeter/sync.toml(scheme = "Synced", dark, palette, wallpaper per-connector), merging over declarative greeter.toml.- Depends on fix #1 (helper trust).
5. Portal FileChooser forced to GTK backend (Niri)
Impact: save dialogs (e.g. Chromium/Brave downloads) had the suggested filename stripped to just the extension (.rpm saved as ~/.rpm).
- Niri’s default portal config routes
org.freedesktop.impl.portal.FileChooserto the GNOME/Nautilus backend, which mis-handlescurrent_namewhen a single filter is active. - Working fix applied via user override:
- Verified:
xdg-desktop-portal --replace --verboseshowsPreferred portals for ... FileChooser: gtk; downloads save with full names. - Requested upstream: either honor
current_namein the GNOME/Nautilus FileChooser backend or shipFileChooser=gtkfor Niri in the RakuOS-provided/usr/share/xdg-desktop-portal/niri-portals.conf.
6. Niri keybindings (user-level, in ~/.config/niri/)
Mod+T→ Thunderbird (mail)Mod+O→ Cantata (MPD client)- Noctalia Shell generated bindings (Mod+Space launcher, Mod+S control-center, Mod+Shift+S settings, Mod+N notifications, Mod+V clipboard, Mod+E session, etc.); three bindings re-bound: “Open Resources” → flatpak
net.nokyan.Resources,Mod+F→ nautilus,Mod+Return→ ghostty.
7. Session services enabled (user systemd units)
mpd.serviceandmpDris2.serviceenabled (enables MPRIS/D-Bus for Cantata),syncthing.serviceenabled for file sync.- Disabled user units that double up with RakuOS/desktop services:
dms,dsearch,dcal(symlinked to/dev/null).
8. RakuOS Software Center tray autostart override
- File:
~/.config/autostart/rakuos-software-tray.desktop Hidden=true(+X-systemd-skip=true), executable corrected to the real/usr/libexec/rakuos/software/rakuos-software-tray, so a duplicate/stale tray icon no longer appears. (Shell/panel fix, not strictly Niri/Noctalia.)
Open items for the RakuOS team
- (1) overlay dir modes 0755; (5) FileChooser GTK routing for Niri; both are packaging/config defaults that users currently must fix by hand.
- Note on (3): choose your preferred greeting-auth model; the fingerprint-free greeter stack we applied is a documented, maintained pattern.