diff --git a/README.md b/README.md index 15524de..7aed8fe 100644 --- a/README.md +++ b/README.md @@ -48,6 +48,7 @@ source in the `PKGBUILD` (and drop the `-bin` suffix), or don't package it. | `concat-bin` | [jub0t/Concat](https://github.com/jub0t/Concat) — prebuilt release of `concat` | `.deb` | [concat-bin](https://aur.archlinux.org/packages/concat-bin) | | `concat-git` | [jub0t/Concat](https://github.com/jub0t/Concat) — `main` branch of `concat` | *built from source* | [concat-git](https://aur.archlinux.org/packages/concat-git) | | `face-unlock` | [LoonixTools/face-unlock](https://github.com/LoonixTools/face-unlock): Face ID for Linux, for the lock screen, sudo and admin prompts on Plasma, GNOME, Hyprland and Niri, with a photo check (C++/Qt6, OpenCV). Called `plasma-face-unlock` before 2.0.0 | *built from source* | [face-unlock](https://aur.archlinux.org/packages/face-unlock) | +| `face-unlock-bin` | [LoonixTools/face-unlock](https://github.com/LoonixTools/face-unlock): prebuilt release of `face-unlock`, with OpenCV linked in | tarball (built on Arch) | [face-unlock-bin](https://aur.archlinux.org/packages/face-unlock-bin) | | `faugus-launcher-bin` | [Faugus/faugus-launcher](https://github.com/Faugus/faugus-launcher) — launcher for Windows games via UMU-Launcher | `.deb` (`all`) | [faugus-launcher-bin](https://aur.archlinux.org/packages/faugus-launcher-bin) | | `fluxer-bin` | [fluxer.app](https://fluxer.app) — Fluxer desktop client (Electron) | tarball | [fluxer-bin](https://aur.archlinux.org/packages/fluxer-bin) | | `kitty-tune-bin` | [alan7383/KittyTuneDesktop](https://github.com/alan7383/KittyTuneDesktop) — SoundCloud and YouTube music player (Kotlin/Compose Multiplatform) | `.deb` | [kitty-tune-bin](https://aur.archlinux.org/packages/kitty-tune-bin) | @@ -117,7 +118,8 @@ Then create a directory named after the AUR package containing: - `AUR_PUBLISH` — optional; set to `false` to keep a package out of the AUR while it is still being prepared. Everything else still runs, so the `PKGBUILD` is kept current and test-built; only the publishing waits. - Flip it to `true` to go live (`moondeckbuddy-bin`). + Flip it to `true` to go live (`moondeckbuddy-bin`). `face-unlock-bin` sets it + itself: it goes live with the first release that has its tarball. Other local source files in the directory (`.desktop` files, patches, …) are pushed to the AUR alongside `PKGBUILD` and `.SRCINFO`. diff --git a/face-unlock-bin/.SRCINFO b/face-unlock-bin/.SRCINFO new file mode 100644 index 0000000..a7cb530 --- /dev/null +++ b/face-unlock-bin/.SRCINFO @@ -0,0 +1,44 @@ +pkgbase = face-unlock-bin + pkgdesc = Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary) + pkgver = 0 + pkgrel = 1 + url = https://github.com/LoonixTools/face-unlock + install = face-unlock-bin.install + arch = x86_64 + license = GPL-3.0-or-later + license = MIT + license = Apache-2.0 + license = BSD-3-Clause + license = IJG + license = Zlib + license = libpng-2.0 + depends = bash + depends = coreutils + depends = gawk + depends = grep + depends = sed + depends = gettext + depends = systemd + depends = systemd-libs + depends = pam + depends = polkit + depends = qt6-base + depends = qt6-declarative + depends = qt6-wayland + depends = wayland + depends = layer-shell-qt + depends = ki18n + depends = glibc + depends = libgcc + depends = libstdc++ + depends = hicolor-icon-theme + optdepends = hyprpolkitagent: password windows on Hyprland and Niri + provides = face-unlock + conflicts = face-unlock + conflicts = plasma-face-unlock + noextract = face-unlock-0-arch-x86_64.tar.zst + options = !debug + source = face-unlock-0-arch-x86_64.tar.zst::https://github.com/LoonixTools/face-unlock/releases/download/v0/face-unlock-0-arch-x86_64.tar.zst + sha256sums = SKIP + +pkgname = face-unlock-bin diff --git a/face-unlock-bin/PKGBUILD b/face-unlock-bin/PKGBUILD new file mode 100644 index 0000000..e33789f --- /dev/null +++ b/face-unlock-bin/PKGBUILD @@ -0,0 +1,38 @@ +# Maintainer: Felitendo +# This PKGBUILD is updated automatically: +# https://github.com/Felitendo/PKGBUILDS + +pkgname=face-unlock-bin +pkgver=0 +pkgrel=1 +pkgdesc="Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary)" +arch=('x86_64') +url="https://github.com/LoonixTools/face-unlock" +# The program is GPL, the two face networks are MIT (YuNet) and Apache-2.0 +# (SFace). The daemon has OpenCV (Apache-2.0) linked in, with its copies of +# protobuf, libjpeg-turbo, libpng and zlib. All texts are in the package. +license=('GPL-3.0-or-later' 'MIT' 'Apache-2.0' 'BSD-3-Clause' 'IJG' 'Zlib' 'libpng-2.0') +# What the binaries load, plus what the face-unlock command runs. No opencv: +# it is linked in. +depends=('bash' 'coreutils' 'gawk' 'grep' 'sed' 'gettext' 'systemd' 'systemd-libs' 'pam' 'polkit' + 'qt6-base' 'qt6-declarative' 'qt6-wayland' 'wayland' 'layer-shell-qt' 'ki18n' + 'glibc' 'libgcc' 'libstdc++' 'hicolor-icon-theme') +optdepends=('hyprpolkitagent: password windows on Hyprland and Niri') +provides=('face-unlock') +conflicts=('face-unlock' 'plasma-face-unlock') +install="${pkgname}.install" +options=('!debug') +# Upstream's release workflow builds this tarball on Arch: the make install +# tree of face-unlock, in one folder. The agent uses Qt's private API, so it +# fits the Qt that Arch had at the release. +_tarball="face-unlock-${pkgver}-arch-${CARCH}.tar.zst" +source=("${_tarball}::${url}/releases/download/v${pkgver}/${_tarball}") +noextract=("${_tarball}") +sha256sums=('SKIP') + +package() { + # extracted here and not by makepkg, so the files keep the root owner + # the tarball gives them + bsdtar -xpf "$srcdir/${_tarball}" -C "$pkgdir" --strip-components 1 + mv "$pkgdir/usr/share/licenses/face-unlock" "$pkgdir/usr/share/licenses/$pkgname" +} diff --git a/face-unlock-bin/face-unlock-bin.install b/face-unlock-bin/face-unlock-bin.install new file mode 100644 index 0000000..bd8370b --- /dev/null +++ b/face-unlock-bin/face-unlock-bin.install @@ -0,0 +1,34 @@ +post_install() { + # Faces, settings and PAM lines of plasma-face-unlock, the old name. + face-unlock --root migrate >/dev/null 2>&1 || true + cat <<'MSG' + + face-unlock is installed. Run it as your own user, not with sudo: + + face-unlock interactive menu + face-unlock enable set up your face and turn it on + + It asks for your password when it needs to. sudo and admin prompts stay + with the password until you switch them on under Settings. + +MSG +} + +post_upgrade() { + face-unlock --root migrate >/dev/null 2>&1 || true +} + +pre_remove() { + cat <<'MSG' + + Before removing this package, run + + face-unlock disable + + as each user that turned it on. That takes face unlock back out of sudo, + polkit and the lock screens. (Removing it without that is safe too: the PAM + line is written so that a missing module is skipped.) + +MSG + systemctl disable --now face-unlockd.socket face-unlockd.service >/dev/null 2>&1 || true +} diff --git a/face-unlock-bin/pkg.sh b/face-unlock-bin/pkg.sh new file mode 100644 index 0000000..743338f --- /dev/null +++ b/face-unlock-bin/pkg.sh @@ -0,0 +1,49 @@ +# face-unlock-bin - the Arch build of face-unlock +# (https://github.com/LoonixTools/face-unlock), made by upstream's release +# workflow: the same program as the face-unlock package, with OpenCV linked in +# statically, so an OpenCV update on Arch does not break it. +# +# Not every release has the tarball (2.0.0 and older do not), so the newest +# release that has it is tracked, not /releases/latest. The checksum is the +# digest GitHub keeps for every release asset. + +UPSTREAM_REPO="LoonixTools/face-unlock" + +# newest published release with an Arch tarball, as its tag +latest_tag() { + gh api "repos/$UPSTREAM_REPO/releases?per_page=30" \ + --jq '[.[] | select((.draft or .prerelease) | not) + | select(any(.assets[]; .name | endswith("-arch-x86_64.tar.zst")))] + | first | .tag_name // empty' +} + +# Kept off the AUR until a release has the tarball: until then the PKGBUILD +# has nothing to point at. The run that finds the first one updates the +# PKGBUILD and test-builds it before anything is pushed. +AUR_PUBLISH=false +if [[ -n "$(latest_tag)" ]]; then + AUR_PUBLISH=true +fi + +latest_version() { + local tag + tag="$(latest_tag)" + [[ -n "$tag" ]] || return 75 + echo "${tag#v}" +} + +# refresh_checksums +refresh_checksums() { + local ver="$1" pkgbuild="$2" + local name="face-unlock-$ver-arch-x86_64.tar.zst" sha + + sha="$(gh api "repos/$UPSTREAM_REPO/releases/tags/v$ver" \ + --jq ".assets[] | select(.name == \"$name\") | .digest // empty" \ + | sed -n 's/^sha256://p')" + if [[ ! "$sha" =~ ^[0-9a-f]{64}$ ]]; then + sha="$(curl -sfL "https://github.com/$UPSTREAM_REPO/releases/download/v$ver/$name" \ + | sha256sum | cut -d' ' -f1)" + fi + + sed -i "s|^sha256sums=.*|sha256sums=('$sha')|" "$pkgbuild" +}