face-unlock-bin: new package

This commit is contained in:
Felitendo committed 2026-09-28 10:52:04 +02:00
1 parent 927c0a486b
commit 8e503c37f1
5 files changed
+168 -1

No files matched your search

+44
View File
@@ -0,0 +1,44 @@
pkgbase = face-unlock-bin
pkgdesc = Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary)
pkgver = 0
pkgrel = 1
url = https://github.com/LoonixTools/face-unlock
install = face-unlock-bin.install
arch = x86_64
license = GPL-3.0-or-later
license = MIT
license = Apache-2.0
license = BSD-3-Clause
license = IJG
license = Zlib
license = libpng-2.0
depends = bash
depends = coreutils
depends = gawk
depends = grep
depends = sed
depends = gettext
depends = systemd
depends = systemd-libs
depends = pam
depends = polkit
depends = qt6-base
depends = qt6-declarative
depends = qt6-wayland
depends = wayland
depends = layer-shell-qt
depends = ki18n
depends = glibc
depends = libgcc
depends = libstdc++
depends = hicolor-icon-theme
optdepends = hyprpolkitagent: password windows on Hyprland and Niri
provides = face-unlock
conflicts = face-unlock
conflicts = plasma-face-unlock
noextract = face-unlock-0-arch-x86_64.tar.zst
options = !debug
source = face-unlock-0-arch-x86_64.tar.zst::https://github.com/LoonixTools/face-unlock/releases/download/v0/face-unlock-0-arch-x86_64.tar.zst
sha256sums = SKIP
pkgname = face-unlock-bin
+38
View File
@@ -0,0 +1,38 @@
# Maintainer: Felitendo
# This PKGBUILD is updated automatically:
# https://github.com/Felitendo/PKGBUILDS
pkgname=face-unlock-bin
pkgver=0
pkgrel=1
pkgdesc="Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary)"
arch=('x86_64')
url="https://github.com/LoonixTools/face-unlock"
# The program is GPL, the two face networks are MIT (YuNet) and Apache-2.0
# (SFace). The daemon has OpenCV (Apache-2.0) linked in, with its copies of
# protobuf, libjpeg-turbo, libpng and zlib. All texts are in the package.
license=('GPL-3.0-or-later' 'MIT' 'Apache-2.0' 'BSD-3-Clause' 'IJG' 'Zlib' 'libpng-2.0')
# What the binaries load, plus what the face-unlock command runs. No opencv:
# it is linked in.
depends=('bash' 'coreutils' 'gawk' 'grep' 'sed' 'gettext' 'systemd' 'systemd-libs' 'pam' 'polkit'
'qt6-base' 'qt6-declarative' 'qt6-wayland' 'wayland' 'layer-shell-qt' 'ki18n'
'glibc' 'libgcc' 'libstdc++' 'hicolor-icon-theme')
optdepends=('hyprpolkitagent: password windows on Hyprland and Niri')
provides=('face-unlock')
conflicts=('face-unlock' 'plasma-face-unlock')
install="${pkgname}.install"
options=('!debug')
# Upstream's release workflow builds this tarball on Arch: the make install
# tree of face-unlock, in one folder. The agent uses Qt's private API, so it
# fits the Qt that Arch had at the release.
_tarball="face-unlock-${pkgver}-arch-${CARCH}.tar.zst"
source=("${_tarball}::${url}/releases/download/v${pkgver}/${_tarball}")
noextract=("${_tarball}")
sha256sums=('SKIP')
package() {
# extracted here and not by makepkg, so the files keep the root owner
# the tarball gives them
bsdtar -xpf "$srcdir/${_tarball}" -C "$pkgdir" --strip-components 1
mv "$pkgdir/usr/share/licenses/face-unlock" "$pkgdir/usr/share/licenses/$pkgname"
}
+34
View File
@@ -0,0 +1,34 @@
post_install() {
# Faces, settings and PAM lines of plasma-face-unlock, the old name.
face-unlock --root migrate >/dev/null 2>&1 || true
cat <<'MSG'
face-unlock is installed. Run it as your own user, not with sudo:
face-unlock interactive menu
face-unlock enable set up your face and turn it on
It asks for your password when it needs to. sudo and admin prompts stay
with the password until you switch them on under Settings.
MSG
}
post_upgrade() {
face-unlock --root migrate >/dev/null 2>&1 || true
}
pre_remove() {
cat <<'MSG'
Before removing this package, run
face-unlock disable
as each user that turned it on. That takes face unlock back out of sudo,
polkit and the lock screens. (Removing it without that is safe too: the PAM
line is written so that a missing module is skipped.)
MSG
systemctl disable --now face-unlockd.socket face-unlockd.service >/dev/null 2>&1 || true
}
+49
View File
@@ -0,0 +1,49 @@
# face-unlock-bin - the Arch build of face-unlock
# (https://github.com/LoonixTools/face-unlock), made by upstream's release
# workflow: the same program as the face-unlock package, with OpenCV linked in
# statically, so an OpenCV update on Arch does not break it.
#
# Not every release has the tarball (2.0.0 and older do not), so the newest
# release that has it is tracked, not /releases/latest. The checksum is the
# digest GitHub keeps for every release asset.
UPSTREAM_REPO="LoonixTools/face-unlock"
# newest published release with an Arch tarball, as its tag
latest_tag() {
gh api "repos/$UPSTREAM_REPO/releases?per_page=30" \
--jq '[.[] | select((.draft or .prerelease) | not)
| select(any(.assets[]; .name | endswith("-arch-x86_64.tar.zst")))]
| first | .tag_name // empty'
}
# Kept off the AUR until a release has the tarball: until then the PKGBUILD
# has nothing to point at. The run that finds the first one updates the
# PKGBUILD and test-builds it before anything is pushed.
AUR_PUBLISH=false
if [[ -n "$(latest_tag)" ]]; then
AUR_PUBLISH=true
fi
latest_version() {
local tag
tag="$(latest_tag)"
[[ -n "$tag" ]] || return 75
echo "${tag#v}"
}
# refresh_checksums <version> <pkgbuild-path>
refresh_checksums() {
local ver="$1" pkgbuild="$2"
local name="face-unlock-$ver-arch-x86_64.tar.zst" sha
sha="$(gh api "repos/$UPSTREAM_REPO/releases/tags/v$ver" \
--jq ".assets[] | select(.name == \"$name\") | .digest // empty" \
| sed -n 's/^sha256://p')"
if [[ ! "$sha" =~ ^[0-9a-f]{64}$ ]]; then
sha="$(curl -sfL "https://github.com/$UPSTREAM_REPO/releases/download/v$ver/$name" \
| sha256sum | cut -d' ' -f1)"
fi
sed -i "s|^sha256sums=.*|sha256sums=('$sha')|" "$pkgbuild"
}