Coming soon! The Kael'Nyrin Scrolls: The Atlas Edict

Captain Walker

New user setup in BigLinux (KDE Plasma)

biglinux, computers, setup, software, technology, troubleshooting

Estimated reading time at 200 wpm: 4 minutes

The Objective

This was to create a secure, dual-user environment on a single BigLinux machine where the primary user (CW) and a secondary user (User2) maintain complete session isolation. The secondary user requires access to their mobile hotspot (UX1) without viewing the primary user’s files or possessing administrative (root) privileges.

Whether or not you agree our Fat Disclaimer applies

The Core Bottlenecks & Hardware Limitations

  1. The GPU Handoff Deadlock: BigLinux uses a customised display manager (SDDM) and X-server. On this hardware, the GPU drivers (failing to identify the vendor correctly) could not handle two simultaneous “masters.” Attempting a “Switch User” resulted in total system freezes where even kernel-level escapes like Alt+Shift+F12 or TTY switching failed.
  2. The Network Manager “Ghosting” Bug: A KDE Plasma UI glitch caused neighbourhood networks (from neighbours’ wifi) signals to appear as “Connected.” Lagging UI services reported “garbage” data, indicating active connections to every router in range.
  3. The Credential Keyring Barrier: KDE Wallet isolates Wi-Fi passwords to the user who entered them. This rendered UX1 invisible to User2, even though the hardware was physically capable of detecting the signal.

Post-Mortem: The Failed Paths (What NOT to do)

To save others from system instability, here is the brutal detail on the code that failed and the rationale behind why we tried it.

1. Forcing Session Independence (The SDDM Trap)

Code:

[General]
ReuseSession=false
  • Location: /etc/sddm.conf
  • Rationale: We attempted to force SDDM to start a fresh, clean handoff for each user instead of “hot-swapping” them on the same seat.
  • Result: CRITICAL FAILURE. This made the login screen completely unresponsive. Mouse and keyboard focus were lost at the “gate,” necessitating a hard hardware shutdown and restart.

2. Aggressive Hardware “Blinding”

Code:

sudo nmcli device set wlp0s20f0u9 autoconnect no
  • Rationale: We tried to stop the “ghost” connections by telling the Wi-Fi card to stop looking for anything automatically.
  • Result: FAILURE. It “blinded” the card to volatile signals. While the main router (GCHQ) stayed visible, the mobile hotspot (UX1) vanished entirely from the scan results because the card was no longer proactively probing for SSIDs.

3. Total Permission Stripping

Code:

sudo gpasswd -d User2 network
  • Rationale: An attempt to ensure User2 had zero influence over system states or hardware.
  • Result: FAILURE. This removed User2’s right to even trigger a scan from the Wi-Fi hardware. The UI simply showed “No networks available,” making the machine useless for the secondary user.

The Final Solution (What Actually Worked)

The stable configuration relies on Session Isolation and moving credentials to the System Level.

1. File & Privilege Lockdown

We kept User2 out of the wheel group to prevent sudo access and locked the primary home directory:

chmod 700 /home/CW

2. Restoring Hardware Access (The “Driver’s Licence”)

We added User2 back to the network group so they could utilise the Wi-Fi hardware:

sudo gpasswd -a User2 network

3. Sharing the “Key” (The System-Level Fix)

The most critical fix was moving the password for UX1 out of CW’s private vault and into the system’s shared storage.

  • Action: In Network Connection settings for UX1, change password storage to “Store password for all users (not encrypted).”
  • Result: The Network Manager can now initiate the handshake for UX1 before User2 even logs in, as it no longer needs to unlock CW’s encrypted keyring.

4. The “Cold Start” Protocol

Because the “Switch User” logic is fundamentally broken on this GPU/Kernel combo, the permanent rule is:

Always Log Out of one account before Logging In to another.

Logging out flushes the GPU memory and resets the Network Manager, preventing the “10 connected networks” ghosting bug and ensuring the hardware is ready for a fresh session.

Easy-to-Understand Command Summary

CommandRationale
sudo gpasswd -a User2 networkRestores the ability to see/use Wi-Fi hardware without Admin rights.
nmcli connection modify "UX1" connection.permissions ""Makes the connection “Public” to the entire hardware, not just one user.
chmod 700 /home/CWThe “Front Door Lock” for the primary user’s data.

Summary for Users

If you face freezes on BigLinux, stop using “Switch User.” It is a “hot-swap” that many drivers cannot handle reliably. Use “Log Out” instead. If a network is missing for one user, move the password to “All Users” to bypass the encrypted keyring barrier.